tak sa mi to podarilo nejak opravit a ComboFix uz slape, hned som spustil scan a tu je vysledok -
http://kooo.ssdd.cz/log.txt
este prikladam RSIT log
Logfile of random's system information tool 1.09 (written by random/random)
Run by heRoo at 2011-10-05 17:16:52
Microsoft Windows XP Professional Service Pack 3
System drive C: has 293 MB (2%) free of 13 GB
Total RAM: 2047 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:16:58, on 5.10.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\19.1.1.3\ccSvcHst.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tunngle\TnglCtrl.exe
C:\Program Files\Norton AntiVirus\Engine\19.1.1.3\ccSvcHst.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\EslWire\wire.exe
C:\Program Files\EslWire\inGame32.exe
C:\Program Files\EslWire\dbus-daemon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Hry\cs\steamapps\heroo16\counter-strike\cstrike\RSIT.exe
C:\Program Files\trend micro\heRoo.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.1.1.3\IPS\IPSBHO.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ESL Wire] "C:\Program Files\EslWire\wire.exe" --tray
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\19.1.1.3\ccSvcHst.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)
--
End of file - 5989 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\cron.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default
prefs.js - "browser.startup.homepage" - "google.sk"
prefs.js - "extensions.enabledItems" - "{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,
jqs@sun.com:1.0, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:2.5.6.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1, {ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}:0.3.8.1,
personas@christopher.beard:1.6.1, {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9,
firebug@software.joehewitt.com:1.6.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"
jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{BBDA0591-3099-440a-AA10-41764D9DB4DB}"=C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.0.0.128\IPSFFPlgn\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=G:\Programy\Media go\npmediago.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default\extensions\
engine@conduit.com
{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
{c45c406e-ab73-11d8-be73-000a95be3b12}
{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files\Norton AntiVirus\Engine\19.1.1.3\IPS\IPSBHO.DLL [2011-07-26 210872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC7E636D-39AA-49b6-B511-65413DA137A1}]
IE Developer Toolbar BHO - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2007-03-01 623992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-16 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-05-16 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"=D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe []
"P17Helper"=Rundll32 P17.dll,P17Helper []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ESL Wire"=C:\Program Files\EslWire\wire.exe [2011-09-20 1981952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-08-04 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"G:\Programy\xampp\xampp\apache\bin\httpd.exe"="G:\Programy\xampp\xampp\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"G:\Programy\xampp\xampp\mysql\bin\mysqld.exe"="G:\Programy\xampp\xampp\mysql\bin\mysqld.exe:*:Enabled:The MySQL Server"
"D:\Program Files\HLSW\hlsw.exe"="D:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"E:\Warcraft III\Warcraft III\war3.exe"="E:\Warcraft III\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"G:\Games\dsadas\hltv.exe"="G:\Games\dsadas\hltv.exe:*:Enabled:HLTV Launcher"
"G:\Games\dsadas\hl.exe"="G:\Games\dsadas\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Mineserver Project\Mineserver\mineserver.exe"="C:\Program Files\Mineserver Project\Mineserver\mineserver.exe:*:Enabled:mineserver"
"G:\Games\AoE2\age2_x1\age2_x1.exe"="G:\Games\AoE2\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"G:\Games\Age Of Empires II Conquerors\age2_x1\age2_x1.exe"="G:\Games\Age Of Empires II Conquerors\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"G:\Games\StarCraft II\StarCraft II.exe"="G:\Games\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"G:\Games\StarCraft II\Versions\Base15405\SC2.exe"="G:\Games\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"D:\Program Files\Garena\Garena.exe"="D:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"C:\Program Files\Webteh\BSplayer\bsplayer.exe"="C:\Program Files\Webteh\BSplayer\bsplayer.exe:*:Enabled:BS.Player"
"C:\Program Files\gta2gh\gta2gh.exe"="C:\Program Files\gta2gh\gta2gh.exe:*:Enabled:gta2gh"
"G:\Programy\xampp\xampp\FileZillaFTP\FileZilla Server.exe"="G:\Programy\xampp\xampp\FileZillaFTP\FileZilla Server.exe:*:Enabled:FileZilla Server"
"G:\Games\dsadas\hlds.exe"="G:\Games\dsadas\hlds.exe:*:Enabled:HLDS Launcher"
"G:\Games\CaC\Hra\ZH\game.dat"="G:\Games\CaC\Hra\ZH\game.dat:*:Enabled:game"
"C:\Program Files\Tunngle\TnglCtrl.exe"="C:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service"
"G:\Games\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe"="G:\Games\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"E:\Warcraft III\Warcraft III\gproxy.exe"="E:\Warcraft III\Warcraft III\gproxy.exe:*:Enabled:gproxy"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Hry\cs\steamapps\heroo16\dedicated server\hltv.exe"="D:\Hry\cs\steamapps\heroo16\dedicated server\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\EslWire\wire.exe"="C:\Program Files\EslWire\wire.exe:*:Enabled:ESL Wire Client"
"G:\Games\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="G:\Games\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Hry\cs\Steam.exe"="D:\Hry\cs\Steam.exe:*:Enabled:Steam"
"G:\Games\Left.4.Dead.Full-Rip.Skullptura\Left 4 Dead\left4dead.exe"="G:\Games\Left.4.Dead.Full-Rip.Skullptura\Left 4 Dead\left4dead.exe:*:Disabled:left4dead"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Hry\cs\steamapps\heroo16\counter-strike\hl.exe"="D:\Hry\cs\steamapps\heroo16\counter-strike\hl.exe:*:Enabled:Counter-Strike"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.WMV3"=wmv9vcm.dll
"vidc.VP60"=C:\WINDOWS\System32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\System32\vp6vfw.dll
"vidc.iv50"=ir50_32.dll
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"VIDC.IV41"=IR41_32.AX
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-10-05 17:13:07 ----A---- C:\ComboFix.txt
2011-10-05 16:51:46 ----A---- C:\WINDOWS\system32\userinit.exe
2011-10-05 16:49:38 ----N---- C:\WINDOWS\regedit.exe
2011-10-05 16:19:47 ----A---- C:\WINDOWS\system32\extrac32.exe
2011-10-05 16:19:39 ----A---- C:\WINDOWS\system32\findstr.exe
2011-10-05 16:19:08 ----A---- C:\WINDOWS\system32\fontview.exe
2011-10-05 16:18:58 ----A---- C:\WINDOWS\system32\forcedos.exe
2011-10-05 16:18:39 ----A---- C:\WINDOWS\system32\ftp.exe
2011-10-05 16:18:32 ----A---- C:\WINDOWS\system32\getmac.exe
2011-10-05 16:17:56 ----A---- C:\WINDOWS\system32\grpconv.exe
2011-10-05 16:17:48 ----A---- C:\WINDOWS\system32\help.exe
2011-10-05 16:17:42 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2011-10-05 16:17:32 ----A---- C:\WINDOWS\system32\iexpress.exe
2011-10-05 16:17:25 ----A---- C:\WINDOWS\system32\imapi.exe
2011-10-05 16:17:11 ----A---- C:\WINDOWS\system32\ipv6.exe
2011-10-05 16:16:44 ----A---- C:\WINDOWS\system32\ipxroute.exe
2011-10-05 16:16:37 ----A---- C:\WINDOWS\system32\locator.exe
2011-10-05 16:16:29 ----A---- C:\WINDOWS\system32\logman.exe
2011-10-05 16:16:23 ----A---- C:\WINDOWS\system32\logonui.exe
2011-10-05 16:16:12 ----A---- C:\WINDOWS\system32\magnify.exe
2011-10-05 16:16:04 ----A---- C:\WINDOWS\system32\makecab.exe
2011-10-05 16:15:41 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-10-05 16:15:29 ----A---- C:\WINDOWS\system32\mobsync.exe
2011-10-05 16:15:21 ----A---- C:\WINDOWS\system32\mqbkup.exe
2011-10-05 16:15:12 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2011-10-05 16:15:03 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-10-05 16:14:54 ----A---- C:\WINDOWS\system32\mshta.exe
2011-10-05 16:14:51 ----A---- C:\WINDOWS\system32\msht.exe
2011-10-05 16:12:33 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-10-05 16:12:23 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-10-05 16:12:04 ----A---- C:\WINDOWS\system32\narrator.exe
2011-10-05 16:11:58 ----A---- C:\WINDOWS\system32\nddeapir.exe
2011-10-05 16:11:49 ----A---- C:\WINDOWS\system32\net.exe
2011-10-05 16:11:43 ----A---- C:\WINDOWS\system32\net1.exe
2011-10-05 16:11:36 ----A---- C:\WINDOWS\system32\netdde.exe
2011-10-05 16:11:27 ----A---- C:\WINDOWS\system32\netstat.exe
2011-10-05 16:11:20 ----A---- C:\WINDOWS\system32\nslookup.exe
2011-10-05 16:11:10 ----A---- C:\WINDOWS\system32\ntbackup.exe
2011-10-05 16:11:01 ----A---- C:\WINDOWS\system32\ntvdm.exe
2011-10-05 16:10:55 ----A---- C:\WINDOWS\system32\odbcad32.exe
2011-10-05 16:10:45 ----A---- C:\WINDOWS\system32\odbcconf.exe
2011-10-05 16:10:14 ----A---- C:\WINDOWS\system32\osk.exe
2011-10-05 16:10:08 ----A---- C:\WINDOWS\system32\packager.exe
2011-10-05 16:09:59 ----A---- C:\WINDOWS\system32\perfmon.exe
2011-10-05 16:09:05 ----A---- C:\WINDOWS\system32\proquota.exe
2011-10-05 16:08:56 ----A---- C:\WINDOWS\system32\proxycfg.exe
2011-10-05 16:08:42 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-10-05 16:08:34 ----A---- C:\WINDOWS\system32\rasphone.exe
2011-10-05 16:08:25 ----A---- C:\WINDOWS\system32\rcimlby.exe
2011-10-05 16:08:14 ----A---- C:\WINDOWS\system32\rcp.exe
2011-10-05 16:08:00 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-10-05 16:07:37 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-10-05 16:07:28 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-10-05 16:07:18 ----A---- C:\WINDOWS\system32\reg.exe
2011-10-05 16:07:13 ----A---- C:\WINDOWS\system32\regsvr32.exe
2011-10-05 16:06:56 ----A---- C:\WINDOWS\system32\rexec.exe
2011-10-05 16:06:47 ----A---- C:\WINDOWS\system32\rsh.exe
2011-10-05 16:06:20 ----A---- C:\WINDOWS\system32\rsnotify.exe
2011-10-05 16:06:12 ----A---- C:\WINDOWS\system32\rtcshare.exe
2011-10-05 16:06:05 ----A---- C:\WINDOWS\system32\runonce.exe
2011-10-05 16:05:58 ----A---- C:\WINDOWS\system32\savedump.exe
2011-10-05 16:05:51 ----A---- C:\WINDOWS\system32\scardvr.exe
2011-10-05 16:05:27 ----A---- C:\WINDOWS\system32\sdbinst.exe
2011-10-05 16:05:17 ----A---- C:\WINDOWS\system32\secedit.exe
2011-10-05 16:05:10 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-10-05 16:05:03 ----A---- C:\WINDOWS\system32\sethc.exe
2011-10-05 16:04:56 ----A---- C:\WINDOWS\system32\setup.exe
2011-10-05 16:04:41 ----A---- C:\WINDOWS\system32\shmgrate.exe
2011-10-05 16:04:31 ----A---- C:\WINDOWS\system32\shrpubw.exe
2011-10-05 16:04:18 ----A---- C:\WINDOWS\system32\shutdown.exe
2011-10-05 16:04:08 ----A---- C:\WINDOWS\system32\sigverif.exe
2011-10-05 16:03:58 ----A---- C:\WINDOWS\system32\skeys.exe
2011-10-05 16:03:19 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2011-10-05 16:03:04 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-10-05 16:02:55 ----A---- C:\WINDOWS\system32\sort.exe
2011-10-05 16:02:48 ----A---- C:\WINDOWS\system32\spider.exe
2011-10-05 16:02:42 ----A---- C:\WINDOWS\system32\spiisupd.exe
2011-10-05 16:02:11 ----A---- C:\WINDOWS\system32\stimon.exe
2011-10-05 16:02:05 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2011-10-05 16:01:27 ----A---- C:\WINDOWS\system32\taskkill.exe
2011-10-05 16:01:20 ----A---- C:\WINDOWS\system32\tasklist.exe
2011-10-05 16:01:06 ----A---- C:\WINDOWS\system32\telnet.exe
2011-10-05 16:00:49 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2011-10-05 16:00:39 ----A---- C:\WINDOWS\system32\tlntsess.exe
2011-10-05 16:00:29 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2011-10-05 16:00:06 ----A---- C:\WINDOWS\system32\tracerpt.exe
2011-10-05 15:59:58 ----A---- C:\WINDOWS\system32\tracert.exe
2011-10-05 15:59:48 ----A---- C:\WINDOWS\system32\upnpcont.exe
2011-10-05 15:59:34 ----A---- C:\WINDOWS\system32\ups.exe
2011-10-05 15:59:28 ----A---- C:\WINDOWS\system32\utilman.exe
2011-10-05 15:59:17 ----A---- C:\WINDOWS\system32\vssvc.exe
2011-10-05 15:59:09 ----A---- C:\WINDOWS\system32\wextract.exe
2011-10-05 15:59:01 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2011-10-05 15:58:35 ----A---- C:\WINDOWS\system32\wpabaln.exe
2011-10-05 15:58:23 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2011-10-05 15:58:07 ----A---- C:\WINDOWS\system32\wscript.exe
2011-10-05 15:57:56 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-10-05 15:56:39 ----A---- C:\WINDOWS\system32\xcopy.exe
2011-10-05 15:53:53 ----A---- C:\WINDOWS\system32\usmtload.exe
2011-10-04 14:16:03 ----A---- C:\WINDOWS\ntbtlog.txt
2011-10-04 14:12:06 ----A---- C:\WINDOWS\system32\drivers\hidusbf.sys
2011-09-24 18:22:54 ----A---- C:\WINDOWS\system32\mmc.exe
2011-09-24 00:27:50 ----D---- C:\Program Files\EslWire
2011-09-24 00:27:50 ----D---- C:\Documents and Settings\All Users\Application Data\ESL Wire
2011-09-20 15:19:52 ----A---- C:\WINDOWS\system32\ipconfig.exe
2011-09-20 15:17:48 ----A---- C:\WINDOWS\system32\ping.exe
2011-09-20 14:00:35 ----A---- C:\WINDOWS\system32\winver.exe
2011-09-18 01:01:16 ----ASH---- C:\pagefile.sys
2011-09-18 00:45:07 ----A---- C:\WINDOWS\system32\eudcedit.exe
2011-09-18 00:44:29 ----A---- C:\WINDOWS\system32\dxdiag.exe
2011-09-18 00:44:20 ----A---- C:\WINDOWS\system32\dwwin.exe
2011-09-18 00:44:13 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2011-09-18 00:43:40 ----A---- C:\WINDOWS\system32\dumprep.exe
2011-09-18 00:43:09 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2011-09-18 00:42:57 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2011-09-18 00:42:48 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2011-09-18 00:42:38 ----A---- C:\WINDOWS\system32\dmremote.exe
2011-09-18 00:42:32 ----A---- C:\WINDOWS\system32\dmadmin.exe
2011-09-18 00:42:18 ----A---- C:\WINDOWS\system32\dllhost.exe
2011-09-18 00:42:10 ----A---- C:\WINDOWS\system32\diskpart.exe
2011-09-18 00:42:01 ----A---- C:\WINDOWS\system32\diantz.exe
2011-09-18 00:41:53 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2011-09-18 00:41:39 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2011-09-18 00:41:23 ----A---- C:\WINDOWS\system32\defrag.exe
2011-09-18 00:41:17 ----A---- C:\WINDOWS\system32\ddeshare.exe
2011-09-18 00:41:06 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-09-18 00:40:53 ----A---- C:\WINDOWS\system32\ctfmon.exe
2011-09-18 00:40:44 ----A---- C:\WINDOWS\system32\cscript.exe
2011-09-18 00:40:25 ----A---- C:\WINDOWS\system32\conime.exe
2011-09-18 00:40:16 ----A---- C:\WINDOWS\system32\cmstp.exe
2011-09-18 00:40:08 ----A---- C:\WINDOWS\system32\cmmon32.exe
2011-09-18 00:39:48 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-09-18 00:39:20 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2011-09-18 00:39:08 ----A---- C:\WINDOWS\system32\cisvc.exe
2011-09-18 00:38:54 ----A---- C:\WINDOWS\system32\cipher.exe
2011-09-18 00:38:46 ----A---- C:\WINDOWS\system32\cacls.exe
2011-09-18 00:38:30 ----A---- C:\WINDOWS\system32\bootcfg.exe
2011-09-18 00:36:42 ----A---- C:\WINDOWS\system32\attrib.exe
2011-09-18 00:36:31 ----A---- C:\WINDOWS\system32\atmadm.exe
2011-09-18 00:36:21 ----A---- C:\WINDOWS\system32\at.exe
2011-09-18 00:36:10 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2011-09-18 00:35:53 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2011-09-18 00:35:34 ----A---- C:\WINDOWS\system32\ahui.exe
2011-09-18 00:35:11 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-09-18 00:33:46 ----A---- C:\WINDOWS\system32\taskmgr.exe
2011-09-18 00:32:56 ----A---- C:\WINDOWS\system32\actmovie.exe
2011-09-18 00:30:44 ----A---- C:\WINDOWS\system32\cmd.exe
2011-09-18 00:27:49 ----A---- C:\WINDOWS\system32\AGENTSVR.EXE
2011-09-16 20:45:44 ----D---- C:\Program Files\Common Files\Steam
2011-09-16 16:47:17 ----A---- C:\cf.txt
2011-09-15 19:58:09 ----A---- C:\WINDOWS\system32\SETAE2.tmp
2011-09-15 18:31:23 ----D---- C:\Program Files\Symantec
2011-09-15 18:31:23 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-09-15 18:31:23 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
2011-09-15 18:31:23 ----A---- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2011-09-15 18:30:30 ----D---- C:\WINDOWS\system32\drivers\NAV
2011-09-15 18:30:28 ----D---- C:\Program Files\Windows Sidebar
2011-09-15 18:30:28 ----D---- C:\Program Files\Norton AntiVirus
2011-09-15 18:30:28 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2011-09-15 18:07:36 ----D---- C:\Program Files\NortonInstaller
2011-09-15 18:07:36 ----D---- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2011-09-15 17:31:48 ----A---- C:\WINDOWS\zip.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\SWSC.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\SWREG.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\sed.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\PEV.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\NIRCMD.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\MBR.exe
2011-09-15 17:31:48 ----A---- C:\WINDOWS\grep.exe
2011-09-15 17:31:07 ----D---- C:\WINDOWS\ERDNT
2011-09-15 17:31:04 ----AD---- C:\Qoobox
2011-09-12 21:26:53 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2011-09-12 21:26:38 ----D---- C:\WINDOWS\system32\Data
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\VDLL.DLL
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\system32\runouce.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\rundll16.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\RUNDL132.EXE
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\logo1_.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\logo_1.exe
2011-09-12 15:10:02 ----A---- C:\WINDOWS\system32\msvcr80.dll
2011-09-12 15:10:01 ----A---- C:\WINDOWS\system32\msvcp80.dll
2011-09-12 15:09:57 ----A---- C:\WINDOWS\system32\T.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\R.COM
2011-09-12 15:09:55 ----D---- C:\Program Files\Common Files\MicroWorld
2011-09-12 15:09:48 ----D---- C:\Documents and Settings\All Users\Application Data\MicroWorld
2011-09-11 13:44:11 ----D---- C:\Documents and Settings\heRoo\Application Data\Download Manager
======List of files/folders modified in the last 1 month======
2011-10-05 17:16:56 ----D---- C:\Program Files\trend micro
2011-10-05 17:13:10 ----D---- C:\WINDOWS\system32\drivers
2011-10-05 17:12:07 ----D---- C:\WINDOWS\system32\CatRoot2
2011-10-05 17:08:40 ----D---- C:\WINDOWS
2011-10-05 17:08:40 ----A---- C:\WINDOWS\system.ini
2011-10-05 17:08:21 ----D---- C:\WINDOWS\system32\drivers\etc
2011-10-05 17:02:21 ----D---- C:\WINDOWS\Temp
2011-10-05 17:00:42 ----SHD---- C:\System Volume Information
2011-10-05 16:57:38 ----D---- C:\WINDOWS\system32\config
2011-10-05 16:56:36 ----D---- C:\WINDOWS\system32
2011-10-05 16:56:36 ----D---- C:\Program Files\Common Files
2011-10-05 16:55:21 ----D---- C:\WINDOWS\AppPatch
2011-10-05 16:50:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-10-05 16:46:31 ----D---- C:\WINDOWS\Prefetch
2011-10-05 16:21:48 ----SHD---- C:\WINDOWS\Installer
2011-10-05 15:56:30 ----D---- C:\WINDOWS\system32\Com
2011-10-05 15:55:58 ----D---- C:\WINDOWS\system32\npp
2011-10-05 15:55:40 ----D---- C:\WINDOWS\system32\oobe
2011-10-05 15:54:51 ----D---- C:\WINDOWS\system32\Restore
2011-10-05 15:54:31 ----D---- C:\WINDOWS\system32\usmt
2011-10-05 15:53:27 ----D---- C:\WINDOWS\system32\wbem
2011-10-04 14:23:57 ----HD---- C:\WINDOWS\inf
2011-10-03 22:49:03 ----D---- C:\Documents and Settings\heRoo\Application Data\HLSW
2011-09-30 21:40:37 ----D---- C:\Program Files\Mozilla Firefox
2011-09-28 23:27:39 ----D---- C:\Documents and Settings\heRoo\Application Data\Skype
2011-09-25 11:54:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-24 00:27:50 ----RD---- C:\Program Files
2011-09-23 23:35:45 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-09-20 18:32:11 ----A---- C:\WINDOWS\win.ini
2011-09-18 00:31:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-17 23:32:37 ----D---- C:\Documents and Settings\heRoo\Application Data\DAEMON Tools Lite
2011-09-16 21:16:16 ----D---- C:\Program Files\DOSBox-0.74
2011-09-16 16:42:06 ----ASH---- C:\boot.ini
2011-09-15 20:45:48 ----D---- C:\WINDOWS\msagent
2011-09-15 20:38:03 ----D---- C:\WINDOWS\mui
2011-09-15 20:35:41 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2011-09-15 20:30:33 ----D---- C:\Program Files\Outlook Express
2011-09-15 19:37:11 ----D---- C:\Program Files\Windows NT
2011-09-15 19:35:53 ----SD---- C:\WINDOWS\Tasks
2011-09-15 19:33:23 ----D---- C:\WINDOWS\WinSxS
2011-09-15 19:25:00 ----D---- C:\WINDOWS\system32\XPSViewer
2011-09-15 19:22:27 ----D---- C:\Program Files\Messenger
2011-09-15 19:22:17 ----D---- C:\Program Files\Movie Maker
2011-09-15 19:22:13 ----D---- C:\Program Files\Microsoft IntelliPoint
2011-09-15 19:21:15 ----D---- C:\Program Files\AMX Mod X
2011-09-15 19:20:46 ----D---- C:\Program Files\Defraggler
2011-09-15 19:20:36 ----D---- C:\Program Files\NetMeeting
2011-09-15 19:20:12 ----D---- C:\Program Files\7-Zip
2011-09-15 19:19:26 ----D---- C:\WINDOWS\system32\ZoneLabs
2011-09-15 18:44:03 ----D---- C:\Program Files\WinRAR
2011-09-15 18:42:36 ----D---- C:\Program Files\Windows Media Player
2011-09-15 18:40:51 ----D---- C:\Program Files\UltraISO
2011-09-15 18:39:08 ----D---- C:\Program Files\Tunngle
2011-09-15 18:38:54 ----D---- C:\Program Files\Tunatic
2011-09-15 18:38:42 ----D---- C:\Program Files\Internet Explorer
2011-09-15 18:34:13 ----D---- C:\Program Files\QIP
2011-09-15 18:33:58 ----D---- C:\Program Files\PSPad editor
2011-09-15 18:33:41 ----D---- C:\Program Files\Presentation Assistant
2011-09-15 18:33:29 ----D---- C:\Program Files\PHLTV
2011-09-15 17:46:05 ----D---- C:\WINDOWS\Internet Logs
2011-09-12 21:27:45 ----D---- C:\Program Files\Creative
2011-09-12 21:26:53 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2011-09-12 21:26:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-12 15:18:46 ----D---- C:\Program Files\Cheat Engine
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-06-17 691696]
R0 SymDS;Symantec Data Store; C:\WINDOWS\system32\drivers\NAV\1301010.003\SYMDS.SYS [2011-05-16 340088]
R0 SymEFA;Symantec Extended File Attributes; C:\WINDOWS\system32\drivers\NAV\1301010.003\SYMEFA.SYS [2011-07-29 897656]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 BHDrvx86;BHDrvx86; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.0.0.128\Definitions\BASHDefs\20110929.001\BHDrvx86.sys []
R1 ccSet_NAV;Norton AntiVirus Settings Manager; C:\WINDOWS\system32\drivers\NAV\1301010.003\ccSetx86.sys [2011-08-09 132744]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 SRTSP;Symantec Real Time Storage Protection; C:\WINDOWS\System32\Drivers\NAV\1301010.003\SRTSP.SYS [2011-08-03 566904]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\WINDOWS\system32\drivers\NAV\1301010.003\SRTSPX.SYS [2011-08-03 31864]
R1 SymIRON;Symantec Iron Driver; C:\WINDOWS\system32\drivers\NAV\1301010.003\Ironx86.SYS [2011-07-26 149624]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\WINDOWS\System32\Drivers\NAV\1301010.003\SYMTDI.SYS [2011-07-26 387192]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2010-05-13 532224]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 ESLWireAC;ESLWireAC; \??\C:\WINDOWS\system32\drivers\ESLWireACD.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2010-08-04 5243392]
R3 BTCAMDRV;Mobiola Web Camera driver; C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 219264]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 DCamUSBSQTECH;Dual-Mode DSC(2770); C:\WINDOWS\System32\Drivers\SQcaptur.sys [2003-01-10 30921]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 ESLvnic1;ESLvnic Virtual Network 32 Bit; C:\WINDOWS\system32\DRIVERS\ESLvnic.sys [2011-08-08 24504]
R3 gbridge;Gbridge Virtual Miniport; C:\WINDOWS\system32\DRIVERS\gbridge.sys [2009-05-10 41216]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 hidusbf;USB Mouse Rate Adjuster Lower Filter by SweetLow; C:\WINDOWS\system32\DRIVERS\hidusbf.sys [2006-11-08 4544]
R3 IDSxpx86;IDSxpx86; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.0.0.128\Definitions\IPSDefs\20111004.030\IDSxpx86.sys []
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NAVENG;NAVENG; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.0.0.128\Definitions\VirusDefs\20111004.033\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.0.0.128\Definitions\VirusDefs\20111004.033\NAVEX15.SYS []
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2007-11-17 54016]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2007-11-17 22016]
R3 nvsmu;nvsmu; C:\WINDOWS\System32\DRIVERS\nvsmu.sys [2007-10-12 13312]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\System32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2007-06-15 1127936]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\System32\DRIVERS\point32.sys [2007-08-21 21760]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-08-22 27632]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\WINDOWS\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 a2lgc1xz;a2lgc1xz; C:\WINDOWS\system32\drivers\a2lgc1xz.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpnmouse;cpnmouse; C:\WINDOWS\system32\DRIVERS\cpnmouse.sys [2003-11-28 5162]
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2010-08-22 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2010-08-22 25512]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 mbr;mbr; \??\C:\DOCUME~1\heRoo\LOCALS~1\Temp\mbr.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\WINDOWS\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\WINDOWS\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\WINDOWS\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\WINDOWS\system32\DRIVERS\s1039bus.sys [2009-11-19 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s1039mdfl.sys [2009-11-19 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s1039mdm.sys [2009-11-19 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s1039mgmt.sys [2009-11-19 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\s1039nd5.sys [2009-11-19 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s1039obex.sys [2009-11-19 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\s1039unic.sys [2009-11-19 123504]
S3 se32;EnTech softEngine; C:\WINDOWS\system32\drivers\se32.sys [2007-05-03 12112]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\System32\DRIVERS\VBoxNetAdp.sys [2010-02-12 99152]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-08-04 606208]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-16 153376]
R2 NAV;Norton AntiVirus; C:\Program Files\Norton AntiVirus\Engine\19.1.1.3\ccSvcHst.exe [2011-08-10 138760]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2010-11-22 718072]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service []
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-09-28 419624]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2011-09-15 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------