Re: Prosim o kontrolu pc
Napsal: 13 pro 2009 12:21
Tak tu je z comba
ComboFix 09-12-11.04 - Dodo . 12. 2009 11:09:15.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3070.1644 [GMT 0:00]
Running from: c:\users\Dodo\Desktop\ComboFix.exe
Command switches used :: c:\users\Dodo\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\Autorun.inf"
"D:\Autorun.inf"
"E:\Autorun.inf"
"F:\Autorun.inf"
"G:\Autorun.inf"
"H:\Autorun.inf"
"I:\Autorun.inf"
"K:\Autorun.inf"
"L:\Autorun.inf"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin
d:\$recycle.bin
.
((((((((((((((((((((((((( Files Created from 2009-11-13 to 2009-12-13 )))))))))))))))))))))))))))))))
.
2009-12-13 11:14 . 2009-12-13 11:14 -------- d-----w- c:\users\Dodo\AppData\Local\temp
2009-12-13 11:14 . 2009-12-13 11:14 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-13 11:14 . 2009-12-13 11:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-13 11:07 . 2009-12-13 11:07 -------- d-----w- C:\32788R22FWJFW
2009-12-12 10:07 . 2009-12-12 10:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-11 18:43 . 2009-12-11 18:43 -------- d-----w- c:\program files\trend micro
2009-12-11 18:43 . 2009-12-11 18:43 -------- d-----w- C:\rsit
2009-12-11 17:48 . 2009-12-11 17:48 -------- d-----w- c:\users\Dodo\AppData\Roaming\CyberLink
2009-12-11 17:48 . 2009-12-11 17:48 -------- d-----w- c:\users\Public\CyberLink
2009-12-11 08:04 . 2009-12-11 08:04 -------- d-----w- c:\users\Dodo\AppData\Local\Power2Go
2009-12-10 19:21 . 2009-12-10 19:21 -------- d-----w- c:\programdata\CyberLink
2009-12-10 19:21 . 2008-07-24 11:38 29992 ----a-w- c:\programdata\CyberLink\Power2Go\P2GoGadget.dll
2009-12-10 19:20 . 2009-12-10 19:20 36864 ----a-w- c:\programdata\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2009-12-10 19:19 . 2009-12-10 19:19 -------- d-----w- c:\program files\Common Files\LightScribe
2009-12-10 19:19 . 2007-03-22 21:28 1053232 ------w- c:\windows\system32\MFC71u.dll
2009-12-10 19:18 . 2009-12-10 19:22 -------- d-----w- c:\program files\CyberLink
2009-12-10 19:18 . 2009-12-10 19:17 53319 ----a-w- c:\programdata\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2009-12-09 08:39 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-09 08:39 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-09 08:39 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 08:04 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-09 08:04 . 2009-10-27 14:11 834048 ----a-w- c:\windows\system32\wininet.dll
2009-12-09 08:03 . 2009-10-27 13:16 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-09 08:03 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-03 10:47 . 2009-12-03 11:02 -------- d-----w- c:\users\Dodo\AppData\Local\Adobe
2009-12-03 10:45 . 2009-12-03 10:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-27 08:09 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 21:49 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 21:49 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-20 11:28 . 2009-11-20 11:28 -------- d-----w- c:\programdata\Martau
2009-11-16 18:36 . 2009-11-16 18:36 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-16 18:33 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-16 18:33 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-11-16 18:33 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-11-16 18:33 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-16 18:33 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-11-16 18:33 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-16 18:33 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-11-16 18:33 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-11-16 18:33 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-16 18:33 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-11-16 18:33 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-16 18:33 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-16 18:32 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-11-16 18:32 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-16 18:32 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-11-15 11:01 . 2009-11-15 11:01 -------- d-----w- c:\windows\system32\ca-ES
2009-11-15 11:01 . 2009-11-15 11:01 -------- d-----w- c:\windows\system32\eu-ES
2009-11-15 11:01 . 2009-11-15 11:01 -------- d-----w- c:\windows\system32\vi-VN
2009-11-15 09:06 . 2009-11-15 09:06 -------- d-----w- c:\windows\system32\EventProviders
2009-11-15 08:57 . 2009-11-15 08:57 -------- d-----w- c:\windows\system32\ErrorLogs
2009-11-15 08:41 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-11-15 08:41 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2009-11-15 08:41 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2009-11-15 08:41 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-11-15 08:41 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2009-11-15 08:41 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-11-15 08:41 . 2009-04-11 06:28 1480704 ----a-w- c:\windows\system32\mssrch.dll
2009-11-15 08:38 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-11-15 08:38 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-11-15 08:38 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-11-15 08:38 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-11-14 16:27 . 2001-09-20 23:00 67584 ------w- c:\windows\system32\WNASPINT.DLL
2009-11-14 16:27 . 1999-12-07 05:00 565760 ----a-w- c:\windows\system32\msvcp50.dll
2009-11-14 16:27 . 1996-08-20 20:37 15840 ------w- c:\windows\system32\Machnm1.exe
2009-11-14 16:26 . 2009-11-14 16:26 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-14 15:45 . 2003-01-25 22:32 523264 ----a-w- c:\windows\system32\AviProcessor.dll
2009-11-14 15:45 . 2002-11-05 08:40 42496 ----a-w- c:\windows\system32\picn20.dll
2009-11-14 15:45 . 2001-07-18 06:02 98816 ----a-w- c:\windows\system32\FGWVB32.DLL
2009-11-14 15:45 . 2001-07-17 12:30 1718576 ------w- c:\windows\system32\gdiplus.dll
2009-11-14 15:45 . 2000-11-22 14:38 532480 ----a-w- c:\windows\system32\imagx5.dll
2009-11-14 15:45 . 2000-11-06 12:18 507904 ----a-w- c:\windows\system32\imagr5.dll
2009-11-14 15:45 . 2000-10-20 11:21 271216 ----a-w- c:\windows\system32\ImagXpr5.dll
2009-11-14 15:45 . 2003-03-13 12:51 51200 ----a-w- c:\windows\system32\camcodec.dll
2009-11-14 15:45 . 2000-09-20 00:14 114688 ----a-w- c:\windows\system32\avizlib.dll
2009-11-14 15:45 . 2000-08-23 17:00 33280 ----a-w- c:\windows\system32\Huffyuv.dll
2009-11-13 11:18 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-11-13 11:18 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-11-13 11:18 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-11-13 11:18 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-11-13 11:17 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-11-13 11:17 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-11-13 11:17 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-11-13 11:17 . 2009-08-06 19:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-11-13 11:17 . 2009-08-06 18:44 33792 ----a-w- c:\windows\system32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-13 11:14 . 2009-11-10 17:06 -------- d-----w- c:\users\Dodo\AppData\Roaming\Skype
2009-12-13 10:39 . 2009-11-10 17:14 -------- d-----w- c:\users\Dodo\AppData\Roaming\skypePM
2009-12-12 19:13 . 2009-11-10 22:13 12 ----a-w- c:\windows\bthservsdp.dat
2009-12-12 09:38 . 2009-11-10 17:25 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-12-10 19:25 . 2009-11-10 15:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-09 18:38 . 2009-11-10 17:41 -------- d-----w- c:\program files\BS_Player
2009-12-09 08:42 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-11-24 23:54 . 2009-11-10 14:44 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-11-10 14:44 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-11-10 14:44 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-11-10 14:44 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-16 18:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-16 18:36 . 2009-11-16 18:36 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-11-12 10:10 . 2009-11-12 10:10 -------- dc-h--w- c:\programdata\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-11-11 20:26 . 2009-11-11 20:26 -------- d-----w- c:\program files\MSXML 4.0
2009-11-11 19:15 . 2009-11-10 14:37 100256 ----a-w- c:\users\Dodo\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-11 17:11 . 2009-11-11 17:11 -------- d-----w- c:\program files\Total Video Converter
2009-11-11 15:56 . 2009-11-11 15:56 -------- d-----w- c:\programdata\Apple Computer
2009-11-11 15:56 . 2009-11-11 15:54 -------- d-----w- c:\users\Dodo\AppData\Roaming\Vso
2009-11-11 15:54 . 2009-11-11 15:54 81920 ----a-w- c:\users\Dodo\AppData\Roaming\ezpinst.exe
2009-11-11 15:54 . 2009-11-11 15:54 81920 ----a-w- c:\users\Dodo\AppData\Roaming\ezpinst.exe
2009-11-11 15:54 . 2009-11-11 15:54 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-11 15:54 . 2009-11-11 15:54 47360 ----a-w- c:\users\Dodo\AppData\Roaming\pcouffin.sys
2009-11-11 15:54 . 2009-11-11 15:54 47360 ----a-w- c:\users\Dodo\AppData\Roaming\pcouffin.sys
2009-11-11 13:30 . 2009-11-10 17:40 -------- d-----w- c:\users\Dodo\AppData\Roaming\Ahead
2009-11-11 11:57 . 2009-11-10 15:43 -------- d-----w- c:\program files\Atheros
2009-11-11 11:56 . 2009-11-11 11:54 -------- d--h--w- c:\program files\Temp
2009-11-11 11:54 . 2009-11-11 11:54 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-11-11 11:54 . 2009-11-11 11:54 -------- d-----w- c:\program files\Realtek
2009-11-11 11:47 . 2009-11-11 11:47 -------- d-----w- c:\program files\Driver-Soft
2009-11-11 10:41 . 2009-11-11 10:40 -------- d-----w- c:\programdata\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-11-11 10:35 . 2009-11-11 10:35 -------- d-----w- c:\users\Dodo\AppData\Roaming\uniblue
2009-11-11 09:55 . 2009-11-11 09:46 -------- d-----w- c:\programdata\Microsoft Help
2009-11-11 09:52 . 2009-11-11 09:51 -------- d-----w- c:\program files\Microsoft Works
2009-11-11 09:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-11 09:50 . 2009-11-11 09:50 -------- d-----w- c:\program files\Microsoft.NET
2009-11-11 09:48 . 2009-11-11 09:48 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-10 22:29 . 2009-11-10 22:29 0 ----a-w- c:\windows\ativpsrm.bin
2009-11-10 22:27 . 2009-11-10 22:27 -------- d-----w- c:\programdata\ATI
2009-11-10 22:26 . 2009-11-10 22:25 -------- d-----w- c:\program files\ATK
2009-11-10 22:17 . 2009-11-10 22:14 -------- d-----w- c:\program files\ATI Technologies
2009-11-10 22:14 . 2009-11-10 22:14 -------- d-----w- c:\program files\ATI
2009-11-10 18:17 . 2009-11-10 17:41 -------- d-----w- c:\users\Dodo\AppData\Roaming\BSplayer
2009-11-10 17:41 . 2009-11-10 17:41 -------- d-----w- c:\program files\Conduit
2009-11-10 17:41 . 2009-11-10 17:41 -------- d-----w- c:\users\Dodo\AppData\Roaming\BSplayer Pro
2009-11-10 17:40 . 2009-11-10 17:40 -------- d-----w- c:\programdata\Ahead
2009-11-10 17:39 . 2009-11-10 17:37 -------- d-----w- c:\program files\Common Files\Ahead
2009-11-10 17:37 . 2009-11-10 17:37 -------- d-----w- c:\programdata\Nero
2009-11-10 17:37 . 2009-11-10 17:37 -------- d-----w- c:\program files\Nero
2009-11-10 17:28 . 2009-11-10 17:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-11-10 17:17 . 2009-11-10 17:17 -------- d-----w- c:\users\Dodo\AppData\Roaming\Malwarebytes
2009-11-10 17:16 . 2009-11-10 17:16 -------- d-----w- c:\programdata\Malwarebytes
2009-11-10 17:01 . 2009-11-10 17:01 -------- d-----w- c:\program files\Skype
2009-11-10 17:01 . 2009-11-10 17:01 -------- d-----w- c:\programdata\Skype
2009-11-10 17:01 . 2009-11-10 17:01 -------- d-----w- c:\program files\Common Files\Skype
2009-11-10 15:43 . 2009-11-10 15:42 -------- d-----w- c:\programdata\Atheros
2009-11-10 15:42 . 2009-11-10 15:42 -------- d-----w- c:\program files\Cisco
2009-11-10 15:42 . 2009-11-10 15:42 -------- d-----w- c:\users\Dodo\AppData\Roaming\InstallShield
2009-11-10 14:44 . 2009-11-10 14:44 -------- d-----w- c:\program files\Alwil Software
2009-11-10 14:38 . 2009-11-10 14:38 -------- d-----w- c:\users\Dodo\AppData\Roaming\ATI
2009-11-02 20:42 . 2009-11-10 17:04 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-07 16:56 . 2009-11-10 17:00 872960 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-10-07 16:56 . 2009-11-10 17:00 43008 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-10-07 16:56 . 2009-11-10 17:00 340480 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-10-07 16:55 . 2009-11-10 17:00 346624 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-09-30 14:53 . 2009-11-10 15:43 1184768 ----a-w- c:\windows\system32\drivers\athr.sys
2009-09-30 14:53 . 2009-11-10 15:43 1184768 ----a-w- c:\windows\system32\athr.sys
2009-09-25 10:34 . 2009-11-11 11:54 2968608 ----a-w- c:\windows\system32\RtkHDMI.dll
2009-09-25 10:34 . 2009-11-11 11:54 53280 ----a-w- c:\windows\system32\RHCoInst.dll
2009-09-25 10:34 . 2009-11-11 11:54 1352224 ----a-w- c:\windows\system32\RHDMIExt.dll
2009-09-25 10:13 . 2009-11-11 11:54 159232 ----a-w- c:\windows\system32\drivers\RtHDMIV.sys
2009-09-25 02:10 . 2009-11-16 18:34 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-16 18:34 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-16 18:34 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-16 18:34 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-16 18:34 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-16 18:34 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-16 18:34 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-16 18:34 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-16 18:34 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-16 18:34 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-16 18:34 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-16 18:34 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-16 18:34 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-16 18:34 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-16 18:34 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-16 18:34 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-16 18:34 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-16 18:34 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-16 18:34 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-16 18:34 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-16 18:34 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-16 18:34 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-16 18:34 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-16 18:34 1064448 ----a-w- c:\windows\system32\DWrite.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-07-02 10:18 2215960 ----a-w- c:\program files\BS_Player\tbBS_P.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-30 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-18 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniblueSpeedUpMyPC]
2009-04-29 09:45 614696 ----a-w- d:\program files\Uniblue\Uniblue\SpeedUpMyPC\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):1d,1e,b7,72,e3,65,ca,01
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [10. 11. 2009 14:44 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [10. 11. 2009 14:44 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [10. 11. 2009 14:44 53328]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\Spybot - Search & Destroy\SDWinSec.exe [10. 11. 2009 17:25 1153368]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\System32\drivers\SiSGB6.sys [10. 11. 2009 22:54 48128]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21. 1. 2008 2:23 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 10:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q=
FF - component: c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: d:\program files\Magic Video Converter\codec\real\browser\plugins\nppl3260.dll
FF - plugin: d:\program files\Magic Video Converter\codec\real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-13 11:14
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-12-13 11:16:38
ComboFix-quarantined-files.txt 2009-12-13 11:16
ComboFix2.txt 2009-12-12 09:55
Pre-Run: 191 500 709 888 bytes free
Post-Run: 191 459 667 968 bytes free
- - End Of File - - 06D1CCF54450DD31A697198C7FE9EE02
ComboFix 09-12-11.04 - Dodo . 12. 2009 11:09:15.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3070.1644 [GMT 0:00]
Running from: c:\users\Dodo\Desktop\ComboFix.exe
Command switches used :: c:\users\Dodo\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\Autorun.inf"
"D:\Autorun.inf"
"E:\Autorun.inf"
"F:\Autorun.inf"
"G:\Autorun.inf"
"H:\Autorun.inf"
"I:\Autorun.inf"
"K:\Autorun.inf"
"L:\Autorun.inf"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin
d:\$recycle.bin
.
((((((((((((((((((((((((( Files Created from 2009-11-13 to 2009-12-13 )))))))))))))))))))))))))))))))
.
2009-12-13 11:14 . 2009-12-13 11:14 -------- d-----w- c:\users\Dodo\AppData\Local\temp
2009-12-13 11:14 . 2009-12-13 11:14 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-13 11:14 . 2009-12-13 11:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-13 11:07 . 2009-12-13 11:07 -------- d-----w- C:\32788R22FWJFW
2009-12-12 10:07 . 2009-12-12 10:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-11 18:43 . 2009-12-11 18:43 -------- d-----w- c:\program files\trend micro
2009-12-11 18:43 . 2009-12-11 18:43 -------- d-----w- C:\rsit
2009-12-11 17:48 . 2009-12-11 17:48 -------- d-----w- c:\users\Dodo\AppData\Roaming\CyberLink
2009-12-11 17:48 . 2009-12-11 17:48 -------- d-----w- c:\users\Public\CyberLink
2009-12-11 08:04 . 2009-12-11 08:04 -------- d-----w- c:\users\Dodo\AppData\Local\Power2Go
2009-12-10 19:21 . 2009-12-10 19:21 -------- d-----w- c:\programdata\CyberLink
2009-12-10 19:21 . 2008-07-24 11:38 29992 ----a-w- c:\programdata\CyberLink\Power2Go\P2GoGadget.dll
2009-12-10 19:20 . 2009-12-10 19:20 36864 ----a-w- c:\programdata\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2009-12-10 19:19 . 2009-12-10 19:19 -------- d-----w- c:\program files\Common Files\LightScribe
2009-12-10 19:19 . 2007-03-22 21:28 1053232 ------w- c:\windows\system32\MFC71u.dll
2009-12-10 19:18 . 2009-12-10 19:22 -------- d-----w- c:\program files\CyberLink
2009-12-10 19:18 . 2009-12-10 19:17 53319 ----a-w- c:\programdata\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2009-12-09 08:39 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-09 08:39 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-09 08:39 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 08:04 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-09 08:04 . 2009-10-27 14:11 834048 ----a-w- c:\windows\system32\wininet.dll
2009-12-09 08:03 . 2009-10-27 13:16 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-09 08:03 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-03 10:47 . 2009-12-03 11:02 -------- d-----w- c:\users\Dodo\AppData\Local\Adobe
2009-12-03 10:45 . 2009-12-03 10:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-27 08:09 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 21:49 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 21:49 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-20 11:28 . 2009-11-20 11:28 -------- d-----w- c:\programdata\Martau
2009-11-16 18:36 . 2009-11-16 18:36 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-16 18:33 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-16 18:33 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-11-16 18:33 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-11-16 18:33 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-16 18:33 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-11-16 18:33 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-16 18:33 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-11-16 18:33 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-11-16 18:33 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-16 18:33 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-11-16 18:33 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-16 18:33 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-16 18:32 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-11-16 18:32 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-16 18:32 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-11-15 11:01 . 2009-11-15 11:01 -------- d-----w- c:\windows\system32\ca-ES
2009-11-15 11:01 . 2009-11-15 11:01 -------- d-----w- c:\windows\system32\eu-ES
2009-11-15 11:01 . 2009-11-15 11:01 -------- d-----w- c:\windows\system32\vi-VN
2009-11-15 09:06 . 2009-11-15 09:06 -------- d-----w- c:\windows\system32\EventProviders
2009-11-15 08:57 . 2009-11-15 08:57 -------- d-----w- c:\windows\system32\ErrorLogs
2009-11-15 08:41 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-11-15 08:41 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2009-11-15 08:41 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2009-11-15 08:41 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-11-15 08:41 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2009-11-15 08:41 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-11-15 08:41 . 2009-04-11 06:28 1480704 ----a-w- c:\windows\system32\mssrch.dll
2009-11-15 08:38 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-11-15 08:38 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-11-15 08:38 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-11-15 08:38 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-11-14 16:27 . 2001-09-20 23:00 67584 ------w- c:\windows\system32\WNASPINT.DLL
2009-11-14 16:27 . 1999-12-07 05:00 565760 ----a-w- c:\windows\system32\msvcp50.dll
2009-11-14 16:27 . 1996-08-20 20:37 15840 ------w- c:\windows\system32\Machnm1.exe
2009-11-14 16:26 . 2009-11-14 16:26 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-14 15:45 . 2003-01-25 22:32 523264 ----a-w- c:\windows\system32\AviProcessor.dll
2009-11-14 15:45 . 2002-11-05 08:40 42496 ----a-w- c:\windows\system32\picn20.dll
2009-11-14 15:45 . 2001-07-18 06:02 98816 ----a-w- c:\windows\system32\FGWVB32.DLL
2009-11-14 15:45 . 2001-07-17 12:30 1718576 ------w- c:\windows\system32\gdiplus.dll
2009-11-14 15:45 . 2000-11-22 14:38 532480 ----a-w- c:\windows\system32\imagx5.dll
2009-11-14 15:45 . 2000-11-06 12:18 507904 ----a-w- c:\windows\system32\imagr5.dll
2009-11-14 15:45 . 2000-10-20 11:21 271216 ----a-w- c:\windows\system32\ImagXpr5.dll
2009-11-14 15:45 . 2003-03-13 12:51 51200 ----a-w- c:\windows\system32\camcodec.dll
2009-11-14 15:45 . 2000-09-20 00:14 114688 ----a-w- c:\windows\system32\avizlib.dll
2009-11-14 15:45 . 2000-08-23 17:00 33280 ----a-w- c:\windows\system32\Huffyuv.dll
2009-11-13 11:18 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-11-13 11:18 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-11-13 11:18 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-11-13 11:18 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-11-13 11:17 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-11-13 11:17 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-11-13 11:17 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-11-13 11:17 . 2009-08-06 19:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-11-13 11:17 . 2009-08-06 18:44 33792 ----a-w- c:\windows\system32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-13 11:14 . 2009-11-10 17:06 -------- d-----w- c:\users\Dodo\AppData\Roaming\Skype
2009-12-13 10:39 . 2009-11-10 17:14 -------- d-----w- c:\users\Dodo\AppData\Roaming\skypePM
2009-12-12 19:13 . 2009-11-10 22:13 12 ----a-w- c:\windows\bthservsdp.dat
2009-12-12 09:38 . 2009-11-10 17:25 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-12-10 19:25 . 2009-11-10 15:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-09 18:38 . 2009-11-10 17:41 -------- d-----w- c:\program files\BS_Player
2009-12-09 08:42 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-11-24 23:54 . 2009-11-10 14:44 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-11-10 14:44 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-11-10 14:44 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-11-10 14:44 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-16 18:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-16 18:36 . 2009-11-16 18:36 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-11-15 11:01 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-11-12 10:10 . 2009-11-12 10:10 -------- dc-h--w- c:\programdata\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-11-11 20:26 . 2009-11-11 20:26 -------- d-----w- c:\program files\MSXML 4.0
2009-11-11 19:15 . 2009-11-10 14:37 100256 ----a-w- c:\users\Dodo\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-11 17:11 . 2009-11-11 17:11 -------- d-----w- c:\program files\Total Video Converter
2009-11-11 15:56 . 2009-11-11 15:56 -------- d-----w- c:\programdata\Apple Computer
2009-11-11 15:56 . 2009-11-11 15:54 -------- d-----w- c:\users\Dodo\AppData\Roaming\Vso
2009-11-11 15:54 . 2009-11-11 15:54 81920 ----a-w- c:\users\Dodo\AppData\Roaming\ezpinst.exe
2009-11-11 15:54 . 2009-11-11 15:54 81920 ----a-w- c:\users\Dodo\AppData\Roaming\ezpinst.exe
2009-11-11 15:54 . 2009-11-11 15:54 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-11 15:54 . 2009-11-11 15:54 47360 ----a-w- c:\users\Dodo\AppData\Roaming\pcouffin.sys
2009-11-11 15:54 . 2009-11-11 15:54 47360 ----a-w- c:\users\Dodo\AppData\Roaming\pcouffin.sys
2009-11-11 13:30 . 2009-11-10 17:40 -------- d-----w- c:\users\Dodo\AppData\Roaming\Ahead
2009-11-11 11:57 . 2009-11-10 15:43 -------- d-----w- c:\program files\Atheros
2009-11-11 11:56 . 2009-11-11 11:54 -------- d--h--w- c:\program files\Temp
2009-11-11 11:54 . 2009-11-11 11:54 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-11-11 11:54 . 2009-11-11 11:54 -------- d-----w- c:\program files\Realtek
2009-11-11 11:47 . 2009-11-11 11:47 -------- d-----w- c:\program files\Driver-Soft
2009-11-11 10:41 . 2009-11-11 10:40 -------- d-----w- c:\programdata\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-11-11 10:35 . 2009-11-11 10:35 -------- d-----w- c:\users\Dodo\AppData\Roaming\uniblue
2009-11-11 09:55 . 2009-11-11 09:46 -------- d-----w- c:\programdata\Microsoft Help
2009-11-11 09:52 . 2009-11-11 09:51 -------- d-----w- c:\program files\Microsoft Works
2009-11-11 09:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-11 09:50 . 2009-11-11 09:50 -------- d-----w- c:\program files\Microsoft.NET
2009-11-11 09:48 . 2009-11-11 09:48 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-10 22:29 . 2009-11-10 22:29 0 ----a-w- c:\windows\ativpsrm.bin
2009-11-10 22:27 . 2009-11-10 22:27 -------- d-----w- c:\programdata\ATI
2009-11-10 22:26 . 2009-11-10 22:25 -------- d-----w- c:\program files\ATK
2009-11-10 22:17 . 2009-11-10 22:14 -------- d-----w- c:\program files\ATI Technologies
2009-11-10 22:14 . 2009-11-10 22:14 -------- d-----w- c:\program files\ATI
2009-11-10 18:17 . 2009-11-10 17:41 -------- d-----w- c:\users\Dodo\AppData\Roaming\BSplayer
2009-11-10 17:41 . 2009-11-10 17:41 -------- d-----w- c:\program files\Conduit
2009-11-10 17:41 . 2009-11-10 17:41 -------- d-----w- c:\users\Dodo\AppData\Roaming\BSplayer Pro
2009-11-10 17:40 . 2009-11-10 17:40 -------- d-----w- c:\programdata\Ahead
2009-11-10 17:39 . 2009-11-10 17:37 -------- d-----w- c:\program files\Common Files\Ahead
2009-11-10 17:37 . 2009-11-10 17:37 -------- d-----w- c:\programdata\Nero
2009-11-10 17:37 . 2009-11-10 17:37 -------- d-----w- c:\program files\Nero
2009-11-10 17:28 . 2009-11-10 17:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-11-10 17:17 . 2009-11-10 17:17 -------- d-----w- c:\users\Dodo\AppData\Roaming\Malwarebytes
2009-11-10 17:16 . 2009-11-10 17:16 -------- d-----w- c:\programdata\Malwarebytes
2009-11-10 17:01 . 2009-11-10 17:01 -------- d-----w- c:\program files\Skype
2009-11-10 17:01 . 2009-11-10 17:01 -------- d-----w- c:\programdata\Skype
2009-11-10 17:01 . 2009-11-10 17:01 -------- d-----w- c:\program files\Common Files\Skype
2009-11-10 15:43 . 2009-11-10 15:42 -------- d-----w- c:\programdata\Atheros
2009-11-10 15:42 . 2009-11-10 15:42 -------- d-----w- c:\program files\Cisco
2009-11-10 15:42 . 2009-11-10 15:42 -------- d-----w- c:\users\Dodo\AppData\Roaming\InstallShield
2009-11-10 14:44 . 2009-11-10 14:44 -------- d-----w- c:\program files\Alwil Software
2009-11-10 14:38 . 2009-11-10 14:38 -------- d-----w- c:\users\Dodo\AppData\Roaming\ATI
2009-11-02 20:42 . 2009-11-10 17:04 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-07 16:56 . 2009-11-10 17:00 872960 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-10-07 16:56 . 2009-11-10 17:00 43008 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-10-07 16:56 . 2009-11-10 17:00 340480 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-10-07 16:55 . 2009-11-10 17:00 346624 ----a-w- c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-09-30 14:53 . 2009-11-10 15:43 1184768 ----a-w- c:\windows\system32\drivers\athr.sys
2009-09-30 14:53 . 2009-11-10 15:43 1184768 ----a-w- c:\windows\system32\athr.sys
2009-09-25 10:34 . 2009-11-11 11:54 2968608 ----a-w- c:\windows\system32\RtkHDMI.dll
2009-09-25 10:34 . 2009-11-11 11:54 53280 ----a-w- c:\windows\system32\RHCoInst.dll
2009-09-25 10:34 . 2009-11-11 11:54 1352224 ----a-w- c:\windows\system32\RHDMIExt.dll
2009-09-25 10:13 . 2009-11-11 11:54 159232 ----a-w- c:\windows\system32\drivers\RtHDMIV.sys
2009-09-25 02:10 . 2009-11-16 18:34 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-16 18:34 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-16 18:34 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-16 18:34 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-16 18:34 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-16 18:34 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-16 18:34 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-16 18:34 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-16 18:34 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-16 18:34 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-16 18:34 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-16 18:34 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-16 18:34 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-16 18:34 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-16 18:34 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-16 18:34 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-16 18:34 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-16 18:34 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-16 18:34 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-16 18:34 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-16 18:34 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-16 18:34 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-16 18:34 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-16 18:34 1064448 ----a-w- c:\windows\system32\DWrite.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-07-02 10:18 2215960 ----a-w- c:\program files\BS_Player\tbBS_P.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-30 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-18 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniblueSpeedUpMyPC]
2009-04-29 09:45 614696 ----a-w- d:\program files\Uniblue\Uniblue\SpeedUpMyPC\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):1d,1e,b7,72,e3,65,ca,01
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [10. 11. 2009 14:44 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [10. 11. 2009 14:44 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [10. 11. 2009 14:44 53328]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\Spybot - Search & Destroy\SDWinSec.exe [10. 11. 2009 17:25 1153368]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\System32\drivers\SiSGB6.sys [10. 11. 2009 22:54 48128]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21. 1. 2008 2:23 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 10:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q=
FF - component: c:\users\Dodo\AppData\Roaming\Mozilla\Firefox\Profiles\pec2pk04.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: d:\program files\Magic Video Converter\codec\real\browser\plugins\nppl3260.dll
FF - plugin: d:\program files\Magic Video Converter\codec\real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-13 11:14
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-12-13 11:16:38
ComboFix-quarantined-files.txt 2009-12-13 11:16
ComboFix2.txt 2009-12-12 09:55
Pre-Run: 191 500 709 888 bytes free
Post-Run: 191 459 667 968 bytes free
- - End Of File - - 06D1CCF54450DD31A697198C7FE9EE02