ComboFix 10-08-04.05 - Hanka 05.08.2010 11:45:52.3.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.1023.579 [GMT 2:00]
Running from: c:\documents and settings\Hanka\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Hanka\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100804-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Kerio Personal Firewall *enabled* {333BECA0-DED8-4139-A516-8D9E44E22669}
file zipped: c:\windows\SE632CF17.tmp
file zipped: c:\windows\system32\mmf.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\SE632CF17.tmp
c:\windows\system32\mmf.sys
.
((((((((((((((((((((((((( Files Created from 2010-07-05 to 2010-08-05 )))))))))))))))))))))))))))))))
.
2010-08-05 04:48 . 2010-08-05 09:38 119648 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-03 21:31 . 2010-08-03 21:32 3749567 ----a-r- C:\ComboFix.exe
2010-08-03 08:57 . 2010-08-03 08:58 -------- d-----w- c:\program files\trend micro
2010-08-03 08:57 . 2010-08-03 09:16 -------- d-----w- C:\rsit
2010-08-01 17:31 . 2010-08-01 17:31 -------- d-----w- c:\documents and settings\Hanka\Moje dokumenty
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-03 21:26 . 2010-05-25 06:26 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-03 20:44 . 2010-03-15 15:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-03 20:39 . 2004-11-12 08:19 48856 ----a-w- c:\documents and settings\Hanka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-01 17:33 . 2006-06-02 07:30 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-23 15:22 . 2010-07-29 04:38 1496064 ----a-w- c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\cgkboggk.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-07-23 15:22 . 2010-07-29 04:38 43008 ----a-w- c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\cgkboggk.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-07-23 15:22 . 2010-07-29 04:38 338944 ----a-w- c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\cgkboggk.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-07-23 15:22 . 2010-07-29 04:38 346112 ----a-w- c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\cgkboggk.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-07-23 10:30 . 2005-12-03 23:30 -------- d-----w- c:\documents and settings\Hanka\Application Data\Skype
2010-07-23 10:17 . 2008-02-25 14:31 -------- d-----w- c:\documents and settings\Hanka\Application Data\skypePM
2010-07-01 11:11 . 2007-09-29 10:45 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-07-01 08:40 . 2010-07-01 07:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Soluto
2010-07-01 08:21 . 2009-02-15 07:19 5112 ----a-w- c:\windows\GPCIDrv.sys
2010-07-01 08:21 . 2008-05-14 19:42 17962 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2010-07-01 08:14 . 2010-07-01 08:14 -------- d-----w- c:\program files\Soluto
2010-07-01 08:11 . 2010-07-01 08:11 -------- d-----w- c:\program files\MSBuild
2010-07-01 07:15 . 2010-07-01 07:56 926568 ----a-w- c:\documents and settings\All Users\Application Data\Soluto\Installer\SolutoInstaller.exe
2010-06-28 07:05 . 2010-07-01 08:14 179656 ----a-w- c:\windows\system32\drivers\PCGenFAM.sys
2010-06-23 07:20 . 2010-06-23 07:20 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtbA.tmp.exe
2010-04-23 17:46 . 2006-07-08 14:56 4270 ----a-w- c:\program files\Rekorde.dsv
2010-04-23 17:46 . 2006-07-08 14:52 3581 ----a-w- c:\program files\Config119.dsv
2010-04-23 17:27 . 2006-07-08 14:54 4709 ----a-w- c:\program files\TEAMs.dsv
2010-01-31 07:34 . 2010-01-31 07:24 280651484 ----a-w- c:\program files\cs16full.rar
2010-01-31 07:26 . 2010-01-31 07:25 13895018 ----a-w- c:\program files\fy2.rar
2010-01-31 07:26 . 2010-01-31 07:25 3750445 ----a-w- c:\program files\awp.rar
2010-01-31 07:25 . 2010-01-31 07:25 1438018 ----a-w- c:\program files\fy.rar
2010-01-31 07:25 . 2010-01-31 07:25 4424343 ----a-w- c:\program files\aim.rar
2010-01-30 21:36 . 2010-01-30 17:05 397857244 ----a-w- c:\program files\steaminstall_cs.exe
2009-02-06 20:28 . 2006-11-21 20:03 569344 ----a-w- c:\program files\AutoRun.exe
2008-08-31 16:30 . 2008-03-23 20:18 32 ------w- c:\program files\Default.fil
2008-04-18 15:59 . 2008-04-18 16:00 774144 ------w- c:\program files\RngInterstitial.dll
2008-04-08 11:55 . 2008-04-04 14:08 169720 ------w- c:\program files\replay.rp3
2008-04-04 14:08 . 2008-04-04 14:08 24042 ------w- c:\program files\ghost.gst
2008-04-04 14:02 . 2008-04-04 14:02 579 ------w- c:\program files\install.win
2006-11-21 20:15 . 2006-08-15 09:24 5632 ------w- c:\program files\Thumbs.db
2006-10-25 13:17 . 2006-11-21 20:03 528384 ------w- c:\program files\AutoRunGUI.dll
2006-10-25 13:17 . 2006-11-21 20:03 258 ------w- c:\program files\dat.bin
2006-10-25 13:17 . 2006-11-21 20:03 253952 ------w- c:\program files\eauninstall.exe
2005-09-15 09:28 . 2005-09-15 09:28 3584 ------w- c:\program files\1033.MST
2005-01-24 18:51 . 2005-01-24 18:51 63696 ------w- c:\program files\slovencina.xml
2004-12-30 21:27 . 2008-09-25 15:37 14648 ------w- c:\program files\rg.nfo
2004-06-30 11:20 . 2006-05-08 15:28 160768 ------w- c:\program files\fmod.dll
2003-12-21 05:44 . 2003-12-21 05:42 696 ------w- c:\program files\index.html
2003-07-22 20:28 . 2003-07-22 20:28 5 ------w- c:\program files\DISK1.ID
2003-07-22 20:27 . 2003-07-22 20:27 206906 ------w- c:\program files\_SETUP.LIB
2002-10-10 19:32 . 2002-10-10 19:32 542368 ------w- c:\program files\QuickTimeInstaller.exe
2002-10-10 19:26 . 2002-10-10 19:26 10570062 ------w- c:\program files\QuickTimeInstallCache.qdat
2002-06-04 08:59 . 2002-06-04 08:59 204800 ------w- c:\program files\Restoration.exe
1998-09-24 07:48 . 2008-01-03 14:21 925 ------w- c:\program files\BENCH.EPD
1998-08-11 11:15 . 2008-01-03 14:21 3121 ------w- c:\program files\BS75
1998-02-24 14:26 . 2008-01-03 14:21 1339 ------w- c:\program files\BS50
1997-10-03 10:52 . 2008-01-03 14:21 3408 ------w- c:\program files\TSR.EXE
1997-07-14 19:22 . 2008-03-23 20:16 66382 ------w- c:\program files\H_SIGNS.PIC
1997-07-08 10:10 . 2008-03-23 20:16 106318 ------w- c:\program files\N_SYSGFX.PIC
1997-07-05 20:01 . 2008-03-23 20:16 89028 ------w- c:\program files\POKAL.PIC
1997-07-04 19:58 . 2008-03-23 20:16 62363 ------w- c:\program files\N_PANGFX.PIC
1997-07-03 14:08 . 2008-03-23 20:16 82766 ------w- c:\program files\H_PAN2.PIC
1997-07-01 15:01 . 2008-03-23 20:16 17943 ------w- c:\program files\S_PANGFX.PIC
1997-05-31 23:45 . 2008-03-23 20:16 39642 ------w- c:\program files\FLAGGOR.PIC
1997-05-23 13:16 . 2008-03-23 20:16 776 ------w- c:\program files\SYS.COL
1997-05-23 10:21 . 2008-03-23 20:16 13390 ------w- c:\program files\N_SIGNS.PIC
1997-05-23 10:17 . 2008-03-23 20:16 3982 ------w- c:\program files\S_SIGNS.PIC
1997-05-23 10:10 . 2008-03-23 20:16 42470 ------w- c:\program files\N_SYSG_2.PIC
1997-05-07 10:31 . 2008-03-23 20:16 66382 ------w- c:\program files\H_PAN1.PIC
1997-04-24 16:26 . 2008-03-23 20:16 37720 ------w- c:\program files\MENUBKG.DAT
1996-10-03 10:19 . 1996-10-03 10:19 65999 ------w- c:\program files\SETUP.INS
1996-07-24 03:00 . 1996-07-24 03:00 316789 ------w- c:\program files\_INST32I.EX_
1996-04-29 07:25 . 1996-04-29 07:25 5984 ------w- c:\program files\_SETUP.DLL
1995-09-07 19:22 . 1995-09-07 19:22 8192 ------w- c:\program files\_ISDEL.EXE
1993-12-16 08:11 . 2008-01-03 14:21 4647 ------w- c:\program files\BOOK.TRX
1993-11-16 08:56 . 2008-01-03 14:21 1048 ------w- c:\program files\FRAGILE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2003-03-31 59392]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-3-8 184320]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^All Users^start menu^programs^startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\All Users\start menu\programs\startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
2006-10-17 01:20 398944 ------w- c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-09-26 15:57 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ------w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2006-01-30 19:13 35328 ------w- c:\program files\Winamp\winampa.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Soluto\\Soluto.exe"=
"c:\\Program Files\\Soluto\\SolutoService.exe"=
"c:\\Program Files\\Soluto\\SolutoConsole.exe"=
"c:\\Program Files\\Soluto\\SolutoUpdateService.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 VOBID;VOBID;c:\windows\system32\drivers\vobid.sys [1.8.2003 15:47 29239]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6.8.2008 13:45 114768]
R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [26.9.2005 11:05 286720]
R1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [26.9.2005 11:05 81920]
R1 SSHDRV82;SSHDRV82;c:\windows\system32\drivers\SSHDRV82.sys [25.12.2006 12:12 76288]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [22.2.2007 22:30 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.8.2008 13:45 20560]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [28.6.2010 14:14 339520]
R3 PAC207;VideoCAM GE111;c:\windows\system32\drivers\PFC027.sys [8.4.2005 10:46 162176]
S0 PCGenFAM;PCGenFAM;c:\windows\system32\drivers\PCGenFAM.sys [1.7.2010 10:14 179656]
S2 LicCtrlService;LicCtrl Service;rundll32.exe c:\windows\mmfs.dll,Service --> rundll32.exe c:\windows\mmfs.dll,Service [?]
S3 GPCIDrv;GPCIDrv;c:\windows\GPCIDrv.sys [15.2.2009 9:19 5112]
S3 gupdate1c9869f5644a592;Google Update Service (gupdate1c9869f5644a592);c:\program files\Google\Update\GoogleUpdate.exe [4.2.2009 10:05 133104]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [14.5.2008 21:42 17962]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [4.8.2005 23:52 32782]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6.1.2007 20:39 639224]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 15:53 451872 ------w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-08-04 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 17:13]
2010-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 08:04]
2010-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 08:04]
2010-08-05 c:\windows\Tasks\User_Feed_Synchronization-{627239F6-56A3-4121-ADB1-B8C10B573123}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.tipos.sk/Default.aspx?CatID=38
uSearchMigratedDefaultURL = hxxp://
www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uInternet Settings,ProxyServer = proxy.telecom.sk:3128
uInternet Settings,ProxyOverride = 127.0.0.1; *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} -
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} -
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\cgkboggk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://
www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://zoznam.sk
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Hanka\Application Data\Mozilla\Firefox\Profiles\cgkboggk.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-05 11:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1202660629-1500820517-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1202660629-1500820517-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:87,cf,e6,55,71,be,53,7b,bc,58,97,99,e4,e8,e1,64,99,58,fc,70,ca,
a7,f9,5a,0b,cd,b8,cb,3e,5c,8c,41,65,37,b7,48,8e,48,15,1a,c1,a4,d5,4a,41,98,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="REMOVED"
.
Completion time: 2010-08-05 12:06:58
ComboFix-quarantined-files.txt 2010-08-05 10:06
ComboFix2.txt 2010-08-04 18:32
ComboFix3.txt 2010-08-03 22:10
Pre-Run: 43 673 362 432 bytes free
Post-Run: 24 adresárov, 43 656 339 456 voľných bajtov
- - End Of File - - BE17C6A0E01F447A1994A677F87024FB
Upload was successful