((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ADOBEFLASHPLAYERUPDATESVC
-------\Legacy_GUPDATE
-------\Legacy_GUPDATEM
-------\Service_AdobeFlashPlayerUpdateSvc
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_jjurwobc
-------\Service_jumevbvq
-------\Service_kcqaeceo
-------\Service_kxpiynog
-------\Service_mwdopgwd
-------\Service_pacxsuhn
-------\Service_swegkubb
.
.
((((((((((((((((((((((((( Files Created from 2012-07-13 to 2012-08-13 )))))))))))))))))))))))))))))))
.
.
2012-08-12 15:01 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8650BCC9-DE40-4C74-AC31-F8AD17A0FA68}\mpengine.dll
2012-08-10 10:13 . 2012-06-29 08:44 6891424 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-06 13:15 . 2012-08-06 13:15 1544704 ----a-w- c:\windows\is-MU3M6.exe
2012-08-06 10:45 . 2012-08-06 10:45 -------- d-----w- c:\documents and settings\Andrea\Application Data\Canneverbe Limited
2012-08-06 10:45 . 2012-08-06 10:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2012-08-03 19:31 . 2012-08-03 19:31 -------- d-----w- c:\documents and settings\Andrea\Application Data\ESET
2012-08-03 19:29 . 2012-08-03 19:29 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2012-08-03 19:24 . 2012-08-03 19:24 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2012-08-03 16:54 . 2012-08-03 16:54 -------- d-----w- c:\documents and settings\Andrea\Local Settings\Application Data\Sun
2012-08-03 16:43 . 2012-08-03 16:43 -------- d-----w- c:\program files\Oracle
2012-08-03 16:43 . 2012-08-03 16:43 -------- d-----w- c:\documents and settings\Andrea\Application Data\Oracle
2012-08-03 16:43 . 2012-07-05 20:06 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-03 15:45 . 2012-08-03 20:37 -------- d-----w- c:\program files\OpenApp
2012-08-03 15:42 . 2012-08-03 15:46 -------- d-----w- c:\program files\smartdl
2012-08-01 17:13 . 2012-08-01 17:13 184700 ----a-w- C:\torrent.exe
2012-07-29 18:37 . 2012-08-12 21:35 -------- d-----w- c:\documents and settings\Andrea\Local Settings\Application Data\NCH_EN
2012-07-29 18:36 . 2012-07-29 18:37 -------- d-----w- c:\program files\NCH_EN
2012-07-29 18:29 . 2012-08-05 18:32 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2012-07-29 18:29 . 2012-07-29 18:31 -------- d-----w- c:\program files\NCH Software
2012-07-29 18:29 . 2012-08-05 18:31 -------- d-----w- c:\documents and settings\Andrea\Application Data\NCH Software
2012-07-29 18:12 . 2012-07-29 18:12 -------- d-----w- c:\program files\Ashampoo
2012-07-29 15:13 . 2012-07-29 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\IBUpdaterService
2012-07-29 15:10 . 2012-07-29 15:10 -------- d-----w- c:\documents and settings\Andrea\Local Settings\Application Data\Savings Sidekick
2012-07-29 15:09 . 2012-04-08 22:40 79360 ----a-w- c:\windows\system32\ff_vfw.dll
2012-07-29 15:09 . 2012-07-29 15:10 -------- d-----w- c:\program files\ffdshow
2012-07-29 15:09 . 2012-07-29 15:09 -------- d-----w- c:\windows\system32\searchplugins
2012-07-29 15:08 . 2012-07-29 15:08 -------- d-----w- c:\program files\Haali
2012-07-29 15:07 . 2012-08-06 16:50 -------- d-----w- c:\program files\Savings Sidekick
2012-07-29 15:07 . 2012-07-29 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Codecs Pack
2012-07-29 14:48 . 2012-07-29 18:35 -------- d-----w- c:\documents and settings\Andrea\Local Settings\Application Data\CRE
2012-07-29 14:48 . 2012-07-29 14:48 -------- d-----w- c:\program files\Conduit
2012-07-29 14:46 . 2012-07-30 07:29 -------- d-----w- c:\program files\BitTorrent
2012-07-29 14:46 . 2012-08-13 12:56 -------- d-----w- c:\documents and settings\Andrea\Application Data\BitTorrent
2012-07-29 14:46 . 2012-07-29 14:46 -------- d-----w- c:\documents and settings\Andrea\Local Settings\Application Data\BitTorrent
2012-07-29 14:01 . 2012-07-29 15:16 608 ----a-w- C:\user.js
2012-07-29 13:59 . 2012-07-29 13:59 -------- d-----w- c:\program files\GotClip
2012-07-19 11:37 . 2011-08-15 14:43 102936 ----a-w- c:\windows\AdbWinApi.dll
2012-07-19 11:37 . 2011-08-15 14:43 584584 ----a-w- c:\windows\adb.exe
2012-07-19 11:37 . 2012-07-19 11:38 -------- d-----w- c:\program files\Handset USB Driver
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-13 09:48 . 2011-04-11 21:39 1409 ----a-w- c:\windows\QTFont.for
2012-08-03 09:20 . 2012-05-12 10:58 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-03 09:20 . 2012-02-07 18:06 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-05 20:07 . 2012-04-24 10:34 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-07-05 20:06 . 2012-01-09 16:18 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-02 13:15 . 2007-06-13 18:50 20480 ----a-w- c:\windows\system32\ANGELVDD.DLL
2012-07-02 13:15 . 2007-06-13 18:50 11520 ----a-w- c:\windows\system32\drivers\angelusb.sys
2012-07-02 13:15 . 2007-06-13 18:50 51072 ----a-w- c:\windows\system32\drivers\ANGELNT.SYS
2012-06-14 08:10 . 2012-06-14 08:10 261383 ----a-w- C:\mzdy0006_20120614.zip
2012-06-13 13:19 . 2001-08-23 11:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-10-12 21:07 1372672 ------w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2001-08-23 11:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2001-08-23 11:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-03 08:44 . 2008-10-12 16:36 5504 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2012-06-02 13:19 . 2007-06-19 19:38 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2007-06-19 19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2007-06-01 19:11 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2007-06-01 19:11 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2007-06-01 19:11 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2007-06-19 19:38 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2007-06-01 19:11 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2007-06-01 18:47 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2005-05-26 02:16 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2001-08-23 11:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2007-06-19 19:38 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2007-06-01 19:11 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2007-06-01 18:47 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2010-12-21 08:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2010-12-21 08:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 13:18 . 2010-12-21 08:58 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2001-08-23 11:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-28 07:21 . 2012-05-28 07:21 312430 ----a-w- C:\mzdy0005_120528.zip
2012-05-16 07:58 . 2001-08-23 11:00 667136 ----a-w- c:\windows\system32\wininet.dll
2004-10-01 13:00 . 2007-06-01 20:04 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2012-07-14 00:17 . 2012-08-03 15:57 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AROReminder"="c:\program files\ARO 2012\ARO.exe" [2012-07-06 2553752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2006-07-12 1397760]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 16248320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
R1 MpKsldb491116;MpKsldb491116;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8650BCC9-DE40-4C74-AC31-F8AD17A0FA68}\MpKsldb491116.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 ghsmdm;Handset USB Modem;c:\windows\system32\DRIVERS\ghsmdm.sys [x]
R3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [x]
R3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\w300mgmt.sys [x]
R3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\w300obex.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 Angelnt;Angelnt;c:\windows\System32\Drivers\ANGELNT.SYS [x]
S2 Codecs Pack;Codecs Pack;c:\documents and settings\All Users\Application Data\Codecs Pack\2.2.529.166\{16cdff19-861d-48e3-a751-d99a27784753}\codecmngr.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [x]
S2 PWSYSDRV;PWSYSDRV;c:\windows\system32\drivers\PWSYSDRV.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-1292428093-725345543-1003Core.job
- c:\documents and settings\Andrea\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-18 10:37]
.
.
------- Supplementary Scan -------
.
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Andrea\Application Data\Mozilla\Firefox\Profiles\97t7ufki.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.5.29.1\uninstall.exe
AddRemove-MyAshampoo Toolbar - c:\progra~1\MYASHA~1\UNWISE.EXE
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-13 18:56
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2552)
c:\documents and settings\All Users\Application Data\Codecs Pack\2.2.529.166\{16cdff19-861d-48e3-a751-d99a27784753}\codecmngr.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\msi.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Ahead\InCD\InCDsrv.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\documents and settings\Andrea\My Documents\PROGRAMY\CDBurnerXP\NMSAccessU.exe
c:\windows\RTHDCPL.EXE
c:\program files\HP\Digital Imaging\bin\hpqtra08.exe
c:\windows\system32\wscntfy.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
.
**************************************************************************
.
Completion time: 2012-08-13 19:40:28 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-13 17:39
ComboFix2.txt 2012-08-13 10:11
ComboFix3.txt 2012-08-12 20:20
.
Pre-Run: 84 934 107 136 bytes free
Post-Run: 29 adresárov, 84 894 224 384 voľných bajtov
.
- - End Of File - - 43A3A5C5810F7B3C00C2F7ADA451B5D5