Re: Prosim o kontrolu logu. podozrenie na USBManager.exe
Napsal: 25 úno 2010 18:48
pocas priebehu vybehla tabulka ze ochrana systemu windows, predpokladam ze ten skript nahradil nejaku jeho sucast tak som mu to povolil. alebo sem nemnel ???
ComboFix 10-02-24.03 - User . 02. 2010 18:42:22.5.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3062.2537 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\sfcfiles.dll --> c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.
2010-02-25 17:39 . 2009-08-17 14:26 1571840 ------w- C:\sfcfiles.dll
2010-02-25 16:56 . 2010-02-25 16:56 -------- d-----w- c:\windows\system32\1029
2010-02-25 15:23 . 2010-02-25 15:24 -------- d-----w- c:\program files\trend micro
2010-02-25 15:23 . 2010-02-25 15:24 -------- d-----w- C:\rsit
2010-02-22 16:41 . 2010-02-22 16:41 52224 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-22 16:40 . 2010-02-22 16:40 117760 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-22 16:38 . 2010-02-22 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-22 16:38 . 2010-02-22 16:38 -------- d-----w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com
2010-02-21 23:18 . 2010-02-23 16:25 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Windows Update
2010-01-28 10:04 . 2006-05-19 13:55 81920 ----a-w- c:\windows\system32\SynTPCo2.dll
2010-01-28 10:04 . 2006-05-19 13:52 69721 ----a-w- c:\windows\system32\SynTPFcs.dll
2010-01-28 10:04 . 2006-05-19 13:30 94297 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-01-28 10:04 . 2006-05-19 13:24 193088 ----a-w- c:\windows\system32\drivers\SynTP.sys
2010-01-28 10:04 . 2006-05-19 13:29 114688 ----a-w- c:\windows\system32\SynCtrl.dll
2010-01-28 10:04 . 2006-05-19 13:29 82012 ----a-w- c:\windows\system32\SynCOM.dll
2010-01-28 10:04 . 2010-01-28 10:04 -------- d-----w- c:\program files\Synaptics
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-22 21:00 . 2009-07-18 15:53 -------- d-----w- c:\documents and settings\User\Application Data\Skype
2010-02-22 17:57 . 2009-07-18 15:56 -------- d-----w- c:\documents and settings\User\Application Data\skypePM
2010-02-22 16:28 . 2009-07-19 12:46 -------- d-----w- c:\documents and settings\User\Application Data\ICQ
2010-02-19 08:39 . 2009-07-08 19:27 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-17 18:18 . 2009-07-09 15:32 66960 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-10 21:19 . 2009-07-19 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-28 10:10 . 2009-07-08 19:54 -------- d-----w- c:\program files\Lenovo
2010-01-28 10:10 . 2009-07-08 19:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-22 13:45 . 2009-07-19 12:45 -------- d-----w- c:\program files\ICQ6.5
2010-01-22 09:26 . 2010-01-22 09:26 475136 ------w- c:\windows\Setup1.exe
2010-01-22 09:26 . 2010-01-22 09:26 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-01-05 08:15 . 2009-10-25 16:22 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2010-01-04 12:50 . 2010-01-04 11:55 -------- d-----w- c:\program files\Google
2010-01-04 11:52 . 2009-08-17 16:11 -------- d-----w- c:\program files\ALFA
2010-01-04 11:51 . 2009-08-17 16:17 -------- d-----w- c:\program files\OLYMP
2010-01-04 11:44 . 2010-01-04 11:44 -------- d-----w- c:\program files\Elcom
2010-01-04 11:42 . 2009-08-17 16:11 51072 ----a-w- c:\windows\system32\drivers\ANGELNT.SYS
2010-01-04 11:42 . 2009-08-17 16:11 405 ----a-w- c:\windows\system32\ANGELDOS.SYS
2010-01-04 11:42 . 2009-08-17 16:11 20480 ----a-w- c:\windows\system32\ANGELVDD.DLL
2010-01-04 11:42 . 2009-08-17 16:11 11520 ----a-w- c:\windows\system32\drivers\angelusb.sys
2009-12-31 16:50 . 2008-04-13 22:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2008-05-13 10:38 916480 ------w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2009-07-08 18:55 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2008-04-14 03:41 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2008-04-13 22:54 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2008-04-14 00:01 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2008-04-13 22:47 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 17:49 . 2009-12-03 17:49 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-03 17:48 . 2009-12-03 17:48 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-03 17:47 . 2009-12-03 17:47 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.
------- Sigcheck -------
[-] 2009-08-17 . 56A6034E7764E23D9114223EB3523925 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-02-25_15.49.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-25 16:56 . 2010-02-25 16:56 16384 c:\windows\Temp\Perflib_Perfdata_764.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-20 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-20 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-20 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-03 149280]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6. 2. 2009 13:23 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6. 2. 2009 13:24 93336]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [17. 8. 2009 17:11 51072]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6. 2. 2009 13:23 727720]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.sme.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\3u55bg5k.default\
FF - prefs.js: browser.startup.homepage - www.sme.sk
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-25 18:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3476)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-25 18:45:39
ComboFix-quarantined-files.txt 2010-02-25 17:45
ComboFix2.txt 2010-02-25 17:33
ComboFix3.txt 2010-02-25 16:27
ComboFix4.txt 2010-02-25 15:50
Pre-Run: 28 118 953 984 bytes free
Post-Run: 28 103 819 264 bytes free
- - End Of File - - 5EB5BB8AB27C1A2D6D1BB905709406D9
ComboFix 10-02-24.03 - User . 02. 2010 18:42:22.5.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3062.2537 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\sfcfiles.dll --> c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.
2010-02-25 17:39 . 2009-08-17 14:26 1571840 ------w- C:\sfcfiles.dll
2010-02-25 16:56 . 2010-02-25 16:56 -------- d-----w- c:\windows\system32\1029
2010-02-25 15:23 . 2010-02-25 15:24 -------- d-----w- c:\program files\trend micro
2010-02-25 15:23 . 2010-02-25 15:24 -------- d-----w- C:\rsit
2010-02-22 16:41 . 2010-02-22 16:41 52224 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-22 16:40 . 2010-02-22 16:40 117760 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-22 16:38 . 2010-02-22 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-22 16:38 . 2010-02-22 16:38 -------- d-----w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com
2010-02-21 23:18 . 2010-02-23 16:25 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Windows Update
2010-01-28 10:04 . 2006-05-19 13:55 81920 ----a-w- c:\windows\system32\SynTPCo2.dll
2010-01-28 10:04 . 2006-05-19 13:52 69721 ----a-w- c:\windows\system32\SynTPFcs.dll
2010-01-28 10:04 . 2006-05-19 13:30 94297 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-01-28 10:04 . 2006-05-19 13:24 193088 ----a-w- c:\windows\system32\drivers\SynTP.sys
2010-01-28 10:04 . 2006-05-19 13:29 114688 ----a-w- c:\windows\system32\SynCtrl.dll
2010-01-28 10:04 . 2006-05-19 13:29 82012 ----a-w- c:\windows\system32\SynCOM.dll
2010-01-28 10:04 . 2010-01-28 10:04 -------- d-----w- c:\program files\Synaptics
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-22 21:00 . 2009-07-18 15:53 -------- d-----w- c:\documents and settings\User\Application Data\Skype
2010-02-22 17:57 . 2009-07-18 15:56 -------- d-----w- c:\documents and settings\User\Application Data\skypePM
2010-02-22 16:28 . 2009-07-19 12:46 -------- d-----w- c:\documents and settings\User\Application Data\ICQ
2010-02-19 08:39 . 2009-07-08 19:27 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-17 18:18 . 2009-07-09 15:32 66960 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-10 21:19 . 2009-07-19 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-28 10:10 . 2009-07-08 19:54 -------- d-----w- c:\program files\Lenovo
2010-01-28 10:10 . 2009-07-08 19:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-22 13:45 . 2009-07-19 12:45 -------- d-----w- c:\program files\ICQ6.5
2010-01-22 09:26 . 2010-01-22 09:26 475136 ------w- c:\windows\Setup1.exe
2010-01-22 09:26 . 2010-01-22 09:26 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-01-05 08:15 . 2009-10-25 16:22 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2010-01-04 12:50 . 2010-01-04 11:55 -------- d-----w- c:\program files\Google
2010-01-04 11:52 . 2009-08-17 16:11 -------- d-----w- c:\program files\ALFA
2010-01-04 11:51 . 2009-08-17 16:17 -------- d-----w- c:\program files\OLYMP
2010-01-04 11:44 . 2010-01-04 11:44 -------- d-----w- c:\program files\Elcom
2010-01-04 11:42 . 2009-08-17 16:11 51072 ----a-w- c:\windows\system32\drivers\ANGELNT.SYS
2010-01-04 11:42 . 2009-08-17 16:11 405 ----a-w- c:\windows\system32\ANGELDOS.SYS
2010-01-04 11:42 . 2009-08-17 16:11 20480 ----a-w- c:\windows\system32\ANGELVDD.DLL
2010-01-04 11:42 . 2009-08-17 16:11 11520 ----a-w- c:\windows\system32\drivers\angelusb.sys
2009-12-31 16:50 . 2008-04-13 22:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2008-05-13 10:38 916480 ------w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2009-07-08 18:55 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2008-04-14 03:41 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2008-04-13 22:54 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2008-04-14 00:01 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2008-04-13 22:47 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 17:49 . 2009-12-03 17:49 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-03 17:48 . 2009-12-03 17:48 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-03 17:47 . 2009-12-03 17:47 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.
------- Sigcheck -------
[-] 2009-08-17 . 56A6034E7764E23D9114223EB3523925 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-02-25_15.49.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-25 16:56 . 2010-02-25 16:56 16384 c:\windows\Temp\Perflib_Perfdata_764.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-20 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-20 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-20 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-03 149280]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6. 2. 2009 13:23 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6. 2. 2009 13:24 93336]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [17. 8. 2009 17:11 51072]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6. 2. 2009 13:23 727720]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.sme.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\3u55bg5k.default\
FF - prefs.js: browser.startup.homepage - www.sme.sk
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-25 18:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3476)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-25 18:45:39
ComboFix-quarantined-files.txt 2010-02-25 17:45
ComboFix2.txt 2010-02-25 17:33
ComboFix3.txt 2010-02-25 16:27
ComboFix4.txt 2010-02-25 15:50
Pre-Run: 28 118 953 984 bytes free
Post-Run: 28 103 819 264 bytes free
- - End Of File - - 5EB5BB8AB27C1A2D6D1BB905709406D9