Uz som si myslel ze to je tak zle, že radšej ani nikto nenapiše
Dakujem že ste sa ozvali.
PC sa sprava pomerne normalne, az na zopar veci.
- Obcas ked som menil nejake nastavenia (nic s grafikou) alebo sa koncil nejaky proces (napr. v CCleaner) tak nabehla asi na 1 sekundu cierna obrazovka a potom sa to opravilo a vsetko islo OK
- Chcel som nainstalovat nejaky soft ale instalacia sa nespustila, no v procesoch si bral coraz viac pamäte. (je pravda ze podla jedneho antivira vnom mal byt trojan, no ostatni snim nemali problem, takze to nemusi byt chyba systemu)
- V nastaveniach bezpečnosti Win ( XP ) je Firewall zapnuty, no pri starte vzdy vyhodi bublinu ze je vypnuty.
-Neslo mi dnes spoustit program SpeedUpMyPC, len ukazal obrazok uvodny a nic (ani v procesoch to nebolo. Teraz pri pisani som pozeral nazov a som ho skusil pustit tak ide vpohode.
To je tak všetko. A este ten Log
Log z ComboFix
ComboFix 10-06-25.02 - user 29.06.2010 19:01:09.4.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.255.5 [GMT 2:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))
.
2010-06-28 11:24 . 2010-06-28 11:24 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\NokiaAccount
2010-06-28 11:06 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-06-28 11:05 . 2010-06-28 11:05 -------- d-----w- c:\program files\PC Connectivity Solution
2010-06-28 11:03 . 2010-06-28 11:03 12212040 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-06-28 11:03 . 2010-06-28 11:03 13930312 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-06-28 11:03 . 2010-06-28 11:03 77824 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2010-06-28 11:03 . 2010-06-28 11:03 50000 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer\CommonCustomActions\pcswpc.exe
2010-06-28 11:03 . 2010-06-28 11:03 38912 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-06-28 11:03 . 2010-06-28 11:03 38912 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-06-28 11:02 . 2010-06-28 10:41 103404272 ----a-w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\Installer.exe
2010-06-28 10:48 . 2010-06-28 11:39 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Nokia
2010-06-28 10:47 . 2010-06-28 14:31 -------- d-----w- c:\windows\Globalization
2010-06-28 10:45 . 2010-06-28 10:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NokiaMusic
2010-06-28 10:42 . 2010-06-28 10:42 -------- d-----w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache
2010-06-28 09:47 . 2010-06-28 09:24 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-06-28 09:44 . 2010-06-28 09:44 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-06-28 09:44 . 2010-06-28 09:44 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-06-28 09:44 . 2010-06-28 09:44 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
2010-06-28 09:41 . 2010-06-28 09:41 -------- d-----w- c:\program files\Common Files\PCSuite
2010-06-28 09:40 . 2010-06-29 16:43 -------- d-----w- c:\program files\Common Files\Nokia
2010-06-28 09:39 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-06-28 09:38 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-06-28 09:38 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-06-28 09:38 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-06-28 09:38 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-06-28 09:38 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-06-28 09:36 . 2010-06-28 09:29 36665824 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{18756A46-652E-4ED4-A029-C4940D59F09B}\Nokia_PC_Suite_slk_web.exe
2010-06-28 09:36 . 2010-06-28 09:36 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{18756A46-652E-4ED4-A029-C4940D59F09B}\Installer\CommonCustomActions\pcswpcsi.exe
2010-06-28 09:36 . 2010-06-28 09:36 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{18756A46-652E-4ED4-A029-C4940D59F09B}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-06-28 09:36 . 2010-06-28 09:36 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{18756A46-652E-4ED4-A029-C4940D59F09B}\Installer\CommonCustomActions\UninstPCS.exe
2010-06-28 09:36 . 2010-06-28 09:36 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{18756A46-652E-4ED4-A029-C4940D59F09B}\Installer\CommonCustomActions\UninstCCD.exe
2010-06-27 15:42 . 2010-06-27 15:43 -------- d-----w- c:\program files\VirtualDJ
2010-06-27 09:24 . 2010-06-27 10:49 -------- d-----w- c:\documents and settings\user\Application Data\DAEMON Tools Lite
2010-06-27 09:24 . 2010-06-27 09:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-06-26 10:59 . 2010-06-26 10:59 -------- d-----w- C:\_OTM
2010-06-17 12:56 . 2010-06-17 13:04 -------- d-----w- c:\documents and settings\user\Application Data\Hamachi
2010-06-17 12:55 . 2010-06-17 12:55 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-06-15 15:47 . 2010-06-18 13:27 -------- d-----w- c:\program files\Counter-Strike 1.6
2010-06-13 10:53 . 2010-06-13 10:56 -------- d-----w- c:\documents and settings\user\Application Data\ManyCam
2010-06-13 10:53 . 2010-06-24 13:44 -------- d-----w- c:\program files\ManyCam 2.4
2010-06-11 15:22 . 2010-06-11 15:22 -------- d-----w- c:\program files\Zoner
2010-06-11 12:20 . 2010-06-11 12:21 -------- d-----w- c:\program files\vbNFSMWMegaTrainer
2010-06-07 17:48 . 2010-06-07 17:48 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-07 17:24 . 2010-06-07 17:24 -------- d-----w- c:\program files\Kerio
2010-06-05 08:35 . 2010-06-05 08:36 -------- d-----w- c:\documents and settings\user\Application Data\Stella
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 16:40 . 2007-11-23 14:15 -------- d-----w- c:\documents and settings\user\Application Data\Nokia
2010-06-29 16:32 . 2007-04-30 16:39 -------- d-----w- c:\documents and settings\user\Application Data\Skype
2010-06-28 14:35 . 2006-07-31 23:06 94576 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-28 14:32 . 2009-10-05 18:27 -------- d-----w- c:\program files\Nokia
2010-06-28 10:15 . 2010-06-28 10:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
2010-06-28 10:15 . 2010-06-28 10:15 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf
2010-06-28 10:13 . 2007-11-23 14:15 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-06-28 10:13 . 2010-06-28 10:13 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-06-28 10:13 . 2010-06-28 10:13 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-06-28 09:50 . 2007-11-23 14:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-06-28 09:40 . 2007-11-23 14:14 -------- d-----w- c:\program files\DIFX
2010-06-27 11:30 . 2009-12-27 11:50 2656 ----a-w- c:\documents and settings\user\Local Settings\Application Data\config.dat
2010-06-24 13:42 . 2006-08-09 18:18 -------- d-----w- c:\program files\EA GAMES
2010-06-24 13:42 . 2006-07-28 19:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-23 12:11 . 2010-04-16 13:21 -------- d-----w- c:\documents and settings\user\Application Data\ICQ
2010-06-23 11:47 . 2010-04-16 13:21 -------- d-----w- c:\program files\ICQ7.1
2010-06-13 09:55 . 2010-05-14 15:05 138968 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-13 09:54 . 2010-05-14 15:04 214592 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-06-13 09:21 . 2007-04-24 12:38 -------- d-----w- c:\program files\Google
2010-06-12 14:44 . 2006-08-09 16:10 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-11 12:20 . 2009-11-16 18:44 249856 ------w- c:\windows\Setup1.exe
2010-06-11 12:20 . 2009-11-16 18:44 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-06-09 15:35 . 2008-03-03 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-08 08:31 . 2006-12-24 18:19 -------- d-----w- c:\program files\Lx_cats
2010-06-07 17:44 . 2010-06-07 17:26 3219 ----a-w- c:\windows\system32\drivers\kwfupper.log
2010-06-07 17:25 . 2010-06-07 17:25 5255 ----a-w- c:\windows\system32\drivers\kwflower.log
2010-06-05 20:49 . 2008-08-03 13:53 -------- d-----w- c:\documents and settings\user\Application Data\Thinstall
2010-06-05 08:23 . 2008-05-20 14:07 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-29 08:34 . 2010-05-14 15:04 139152 ----a-w- c:\documents and settings\user\Application Data\PnkBstrK.sys
2010-05-29 08:34 . 2010-05-14 15:04 139152 ----a-w- c:\documents and settings\user\Application Data\PnkBstrK.sys
2010-05-29 08:33 . 2010-05-29 08:33 794408 ----a-w- c:\windows\system32\pbsvc.exe
2010-05-29 08:33 . 2006-08-09 15:22 -------- d-----w- c:\program files\EA SPORTS
2010-05-20 17:15 . 2009-05-04 17:22 -------- d-----w- c:\documents and settings\user\Application Data\Any Video Converter Professional
2010-05-19 16:34 . 2010-01-30 14:28 -------- d-----w- c:\program files\Lexmark 3300 Series
2010-05-19 16:26 . 2010-05-19 16:25 -------- d-----w- c:\program files\Lexmark Fax Solutions
2010-05-17 18:58 . 2010-05-17 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-05-17 18:57 . 2010-05-17 18:57 -------- d-----w- c:\program files\NVIDIA Corporation
2010-05-15 16:42 . 2009-01-04 17:18 -------- d-----w- c:\documents and settings\user\Application Data\dvdcss
2010-05-14 15:04 . 2009-07-05 16:49 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-05-14 15:04 . 2010-05-14 15:04 2427248 ----a-w- c:\windows\system32\pbsvc_heroes.exe
2010-05-09 14:34 . 2009-07-06 16:44 -------- d-----w- c:\documents and settings\user\Application Data\vlc
2010-05-06 18:22 . 2010-05-06 18:22 -------- d-----w- c:\documents and settings\user\Application Data\eTeks
2010-05-05 16:47 . 2010-05-05 16:46 -------- d-----w- c:\program files\Sweet Home 3D
2010-05-02 05:22 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-05-01 19:23 . 2010-05-01 19:08 -------- d-----w- c:\program files\trend micro
2010-05-01 12:46 . 2010-05-01 12:46 -------- d-----w- c:\program files\Uniblue1
2010-05-01 12:26 . 2009-05-12 18:14 -------- d-----w- c:\documents and settings\user\Application Data\Uniblue
2010-04-20 05:30 . 2004-08-04 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-14 08:26 . 2010-04-14 08:26 1837296 ----a-w- c:\windows\system32\WUDFUpdate_01009.dll
2010-04-10 17:08 . 2006-08-04 00:19 12134 ----a-w- c:\documents and settings\user\Application Data\wklnhst.dat
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:23 . 2010-04-03 17:23 229376 ----a-w- c:\windows\system32\nvrszhc.dll
2010-04-03 17:23 . 2010-04-03 17:23 126976 ----a-w- c:\windows\system32\nvrszht.dll
2008-03-05 17:22 . 2008-03-05 17:22 0 -c--a-w- c:\program files\temp01
2007-10-19 17:33 . 2007-10-19 17:33 2686551 ----a-w- c:\program files\PNTSE.exe
2007-08-20 11:12 . 2007-08-20 11:12 15505200 ----a-w- c:\program files\IE7-WindowsXP-x86-enu.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-06-26_10.44.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2009-07-11 23:07 . 2009-07-11 23:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-11 23:19 . 2009-07-11 23:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2010-06-29 10:52 . 2010-06-29 10:52 16384 c:\windows\temp\Perflib_Perfdata_7c0.dat
+ 2006-09-28 16:56 . 2009-07-13 16:16 64512 c:\windows\system32\WudfSvc.dll
+ 2006-09-28 18:13 . 2009-07-13 16:16 39936 c:\windows\system32\WUDFCoinstaller.dll
- 2007-08-19 19:15 . 2008-10-13 12:55 26144 c:\windows\system32\spupdsvc.exe
+ 2007-08-19 19:15 . 2008-11-07 16:55 26144 c:\windows\system32\spupdsvc.exe
+ 2009-02-09 14:19 . 2008-11-07 16:55 16928 c:\windows\system32\spmsgXP_2k3.dll
+ 2009-06-26 15:35 . 2008-11-07 16:55 16928 c:\windows\system32\spmsg.dll
+ 2004-08-04 12:00 . 2010-06-28 14:30 68156 c:\windows\system32\perfc009.dat
- 2004-08-04 12:00 . 2010-06-24 13:59 68156 c:\windows\system32\perfc009.dat
+ 2007-11-23 14:13 . 2010-02-26 12:32 92672 c:\windows\system32\nmwcdcls.dll
- 2009-02-09 13:55 . 2008-08-26 08:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
+ 2010-06-28 11:06 . 2008-08-26 08:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
+ 2010-06-28 09:38 . 2010-02-26 12:32 22528 c:\windows\system32\DRVSTORE\ccdcmbo_86369E3C3E199189C5EAD7421471A08D93A69835\ccdcmbo.sys
+ 2010-06-28 09:38 . 2010-02-26 12:32 92672 c:\windows\system32\DRVSTORE\ccdcmb_86369E3C3E199189C5EAD7421471A08D93A69835\nmwcdcls.dll
+ 2010-06-28 09:38 . 2010-02-26 12:32 18176 c:\windows\system32\DRVSTORE\ccdcmb_86369E3C3E199189C5EAD7421471A08D93A69835\ccdcmb.sys
+ 2006-09-28 16:55 . 2009-07-13 14:50 91904 c:\windows\system32\drivers\WudfPf.sys
+ 2008-03-27 15:27 . 2009-07-14 08:35 37608 c:\windows\system32\drivers\wdfldr.sys
+ 2010-06-28 11:04 . 2010-06-28 11:04 78336 c:\windows\Installer\3e1d54.msi
+ 2010-06-28 10:45 . 2010-06-28 10:45 10134 c:\windows\Installer\{70B31335-50EE-4834-8431-27412CDE62BD}\ARPPRODUCTICON.exe
+ 2010-06-28 09:42 . 2010-06-28 09:42 15086 c:\windows\Installer\{18756A46-652E-4ED4-A029-C4940D59F09B}\ARPPRODUCTICON.exe
+ 2010-06-28 09:49 . 2010-06-28 09:49 10134 c:\windows\Installer\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\ARPPRODUCTICON.exe
+ 2010-06-28 11:06 . 2010-06-28 11:06 10134 c:\windows\Installer\{089DD780-DB3F-4CDB-A0C2-111360247298}\ARPPRODUCTICON.exe
+ 2010-06-28 09:39 . 2010-02-26 12:21 8320 c:\windows\system32\DRVSTORE\nmwcdnsuc_86369E3C3E199189C5EAD7421471A08D93A69835\nmwcdnsuc.sys
+ 2010-06-28 09:38 . 2010-02-26 12:32 8192 c:\windows\system32\DRVSTORE\ccdcmbm_86369E3C3E199189C5EAD7421471A08D93A69835\usbser_lowerflt.sys
+ 2010-06-28 09:39 . 2010-02-26 12:32 8192 c:\windows\system32\DRVSTORE\ccdcmbcj_86369E3C3E199189C5EAD7421471A08D93A69835\usbser_lowerfltj.sys
+ 2010-06-28 09:39 . 2010-06-28 09:39 3262 c:\windows\Installer\{1B9B5B3B-28E7-4E59-A80D-D670AA984514}\ARPPRODUCTICON.exe
+ 2010-06-28 09:49 . 2010-06-28 09:49 8854 c:\windows\Installer\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Uninstall_QA_OTI_H_FE5D756F71E147C4972AD6775344B40B.exe
+ 2010-06-28 09:49 . 2010-06-28 09:49 8854 c:\windows\Installer\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NewShortcut35_E2CBBE559A074AF98E8596196B075190.exe
+ 2010-06-28 09:49 . 2010-06-28 09:49 8854 c:\windows\Installer\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NewShortcut2_1C7B7089989A424FB39D41A32581C775.exe
+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-11 23:12 . 2009-07-11 23:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-11 23:09 . 2009-07-11 23:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-11 23:08 . 2009-07-11 23:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2006-09-28 16:56 . 2009-07-13 16:16 567808 c:\windows\system32\WUDFx.dll
+ 2006-09-28 16:56 . 2009-07-13 14:50 148480 c:\windows\system32\WudfPlatform.dll
+ 2006-09-28 16:56 . 2009-07-13 16:14 195584 c:\windows\system32\WudfHost.exe
+ 2004-08-04 12:00 . 2010-06-28 14:30 435260 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2010-06-24 13:59 435260 c:\windows\system32\perfh009.dat
+ 2010-06-28 11:06 . 2010-04-14 09:40 590848 c:\windows\system32\DRVSTORE\pccswpddri_8FC79B5C76B12B345CB05ADB7D73AF7091A57405\PCCSWpdDriver.dll
+ 2010-06-28 09:39 . 2010-02-26 12:21 137344 c:\windows\system32\DRVSTORE\nmwcdnsu_86369E3C3E199189C5EAD7421471A08D93A69835\nmwcdnsu.sys
+ 2010-06-28 09:38 . 2010-02-26 12:32 662016 c:\windows\system32\DRVSTORE\ccdcmb_86369E3C3E199189C5EAD7421471A08D93A69835\nmwcdcocls.dll
+ 2006-09-28 17:00 . 2009-07-13 14:50 132224 c:\windows\system32\drivers\WudfRd.sys
+ 2008-03-27 15:27 . 2009-07-14 08:35 444136 c:\windows\system32\drivers\wdf01000.sys
+ 2010-04-14 09:40 . 2010-04-14 09:40 590848 c:\windows\system32\drivers\UMDF\PCCSWpdDriver.dll
+ 2010-06-28 11:06 . 2010-06-28 11:06 495616 c:\windows\Installer\3e1d88.msi
+ 2010-06-28 09:46 . 2010-06-28 09:46 424960 c:\windows\Installer\258403.msi
+ 2010-06-28 09:42 . 2010-06-28 09:42 860160 c:\windows\Installer\2583fa.msi
+ 2010-06-28 09:39 . 2010-06-28 09:39 331776 c:\windows\Installer\2583c1.msi
+ 2010-06-28 09:37 . 2010-06-28 09:37 215552 c:\windows\Installer\2583a7.msi
+ 2010-06-28 10:36 . 2010-06-28 10:36 228352 c:\windows\Installer\23685b.msi
+ 2010-06-28 09:49 . 2010-06-28 09:49 458752 c:\windows\Installer\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NewShortcut20_F7578A24A4B240E4BA057EF931EB25B5.exe
+ 2010-06-28 09:49 . 2010-06-28 09:49 458752 c:\windows\Installer\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NewShortcut16_F7578A24A4B240E4BA057EF931EB25B5.exe
+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2009-07-11 18:46 . 2009-07-11 18:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 18:46 . 2009-07-11 18:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2006-07-28 10:55 . 2010-06-29 10:52 1608472 c:\windows\system32\FNTCACHE.DAT
+ 2010-06-28 11:06 . 2010-04-14 08:26 1837296 c:\windows\system32\DRVSTORE\pccswpddri_8FC79B5C76B12B345CB05ADB7D73AF7091A57405\WUDFUpdate_01009.dll
+ 2010-06-28 09:38 . 2010-02-26 12:19 1461992 c:\windows\system32\DRVSTORE\ccdcmb_86369E3C3E199189C5EAD7421471A08D93A69835\wdfcoinstaller01009.dll
+ 2010-06-28 09:49 . 2010-06-28 09:49 1633792 c:\windows\Installer\258408.msi
+ 2010-06-28 10:45 . 2010-06-28 10:45 5863424 c:\windows\Installer\236872.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-08-17 949376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2005-07-12 09:36 299008 ----a-w- c:\program files\Lexmark Fax Solutions\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxccmon.exe]
2005-07-21 00:16 192512 ----a-w- c:\program files\Lexmark 3300 Series\LXCCmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
2010-01-18 07:23 459032 ----a-w- c:\windows\system32\Adobe\Shockwave 11\SwHelper_1156606.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Softick\\PPP\\Bin\\pppgate.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"c:\\Documents and Settings\\user\\Desktop\\marvolo\\Mobil\\Hry\\instal java\\Uploader.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Documents and Settings\\user\\Local Settings\\Application Data\\AntikVirtualSTB\\AntikVirtualSTB.exe"=
"c:\\Games\\Paintball2\\paintball2.exe"=
"c:\\Program Files\\Antik Phone\\AntikSIPsoftPhone.atk"=
"c:\\Program Files\\Antik Phone\\AntikSIPsoftPhone.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\EA GAMES\\Need for Speed Underground 2\\speed2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA Online\\NFE.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hlds.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [31.7.2008 20:45 20616]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [30.4.2010 18:44 64288]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [17.8.2007 20:04 15424]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\ACEDRV11.sys [23.1.2008 10:19 501560]
S3 A368;A368 Filter;c:\windows\system32\drivers\A368.sys [24.12.2006 21:58 28864]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2.7.2008 14:58 26248]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys --> c:\windows\system32\DRIVERS\ManyCam.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-06-29 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 17:41]
2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 17:41]
2009-09-12 c:\windows\Tasks\NeroLiveEpgUpdate-YOUR-C8536FD031_user.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 12:51]
2010-06-29 c:\windows\Tasks\User_Feed_Synchronization-{C6C29FDB-6BC2-4ACF-BACC-00C0D686AF8B}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 01:01]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.zoznam.sk/
uSearchMigratedDefaultURL = hxxp://
www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://
www.winamp.com/plugins
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
LSP: c:\windows\system32\imon.dll
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://
www.battlefieldheroes.com/static/update ... 0.53.0.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\kqt5yk9q.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.zoznam.sk/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\kqt5yk9q.default\extensions\
battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\user\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-NokiaMusic FastStart - c:\program files\Nokia\Ovi Player\NokiaOviPlayer.exe
MSConfigStartUp-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-29 19:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2803272282-1147624186-4157288278-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2803272282-1147624186-4157288278-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{385A3904-A1D4-225C-B927-7FD7C1C76FA0}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oabjaooholmhaeldbaeheofnoeaema"=hex:6a,61,6e,6d,6d,70,6d,61,6f,67,6b,6c,6d,70,
70,6f,6e,6f,61,70,00,ee
"nalioopiehoaihaobamkmbhgclkm"=hex:6b,61,6e,6d,63,61,63,6e,68,6c,66,65,6c,6c,
63,61,63,6c,63,62,6a,6f,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(788)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(4708)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-29 19:24:40
ComboFix-quarantined-files.txt 2010-06-29 17:24
ComboFix2.txt 2010-06-26 10:51
ComboFix3.txt 2010-05-07 14:35
ComboFix4.txt 2010-05-02 18:27
Pre-Run: 5 754 150 912 bytes free
Post-Run: 6 109 024 256 bytes free
- - End Of File - - D0873E05B334499170DFED28A8DB7111