Re: Prosím o kontrolu logu
Napsal: 19 led 2010 16:05
Tak konečne mám:
ComboFix 10-01-18.03 - Milan a Silvia . 01. 2010 15:41:56.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1033.18.1013.86 [GMT 1:00]
Running from: c:\users\Milan a Silvia.SilviaaMilan-PC\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-12-19 to 2010-01-19 )))))))))))))))))))))))))))))))
.
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\MILANA~1~SIL\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Milan a Silvia\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-18 17:36 . 2010-01-18 17:36 -------- d-----w- C:\zaloha
2010-01-18 16:47 . 2010-01-18 16:47 -------- d-----w- c:\program files\CCleaner
2010-01-18 12:43 . 2010-01-18 12:43 -------- d-----w- c:\programdata\Spamihilator
2010-01-18 12:43 . 2010-01-19 14:35 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\Spamihilator
2010-01-18 12:41 . 2010-01-18 12:41 -------- d-----w- c:\program files\Spamihilator
2010-01-18 12:10 . 2010-01-18 13:50 -------- d-----w- c:\program files\trend micro
2010-01-18 09:35 . 2010-01-18 09:37 -------- d-----w- c:\program files\Ultimate Process Manager
2010-01-14 14:13 . 2010-01-14 14:13 273205 ----a-w- c:\windows\PC Image Editor Uninstaller.exe
2010-01-14 14:13 . 2010-01-14 14:20 -------- d-----w- c:\program files\PC Image Editor
2010-01-14 14:13 . 2010-01-14 14:13 -------- d-----w- c:\program files\Common Files\Program4Pc
2010-01-13 18:03 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 18:03 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-12-26 17:59 . 2010-01-10 18:22 230432 ----a-w- C:\PA207.DAT
2009-12-26 17:55 . 2009-12-26 17:55 -------- d-----w- c:\windows\PixArt
2009-12-21 17:02 . 2007-03-14 10:21 61440 ----a-w- c:\windows\system32\vsnpx32.dll
2009-12-21 16:57 . 2007-02-12 13:50 20480 ----a-w- c:\windows\FixCamera.exe
2009-12-21 16:57 . 2006-04-18 15:53 135168 ----a-w- c:\windows\amcap.exe
2009-12-21 16:57 . 2006-10-10 14:49 270336 ----a-w- c:\windows\tsnp325.exe
2009-12-21 16:57 . 2006-10-10 13:11 827392 ----a-w- c:\windows\vsnp325.exe
2009-12-21 16:57 . 2007-04-03 12:55 10251904 ----a-w- c:\windows\system32\drivers\snp325.sys
2009-12-21 16:57 . 2009-12-21 17:02 -------- d-----w- c:\program files\Common Files\snp325
2009-12-21 16:57 . 2007-03-14 10:21 61440 ----a-w- c:\windows\system32\vsnp325.dll
2009-12-21 16:57 . 2006-04-12 11:11 147456 ----a-w- c:\windows\system32\rsnp325.dll
2009-12-21 16:57 . 2005-11-23 12:55 53248 ----a-w- c:\windows\system32\csnp325.dll
2009-12-21 16:56 . 2009-12-21 16:56 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 14:35 . 2009-09-08 15:28 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\Skype
2010-01-19 14:35 . 2009-09-08 15:29 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\skypePM
2010-01-19 13:19 . 2009-09-08 13:45 1356 ----a-w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Local\d3d9caps.dat
2010-01-19 13:04 . 2009-09-07 16:22 87120 ----a-w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-14 10:12 . 2009-10-04 14:51 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-14 09:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-14 09:13 . 2009-09-24 15:13 1 ----a-w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-07 15:47 . 2009-09-21 15:23 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-23 09:48 . 2009-09-21 15:23 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-23 09:48 . 2009-09-21 15:23 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-23 09:48 . 2009-09-21 15:23 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-23 09:48 . 2009-10-18 08:45 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-23 09:48 . 2009-09-21 15:23 194104 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-23 09:48 . 2009-09-21 15:23 370744 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-23 09:47 . 2009-09-21 15:23 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-23 09:47 . 2009-09-21 15:23 816272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-23 09:47 . 2009-09-21 15:23 822904 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-23 09:47 . 2009-09-21 15:23 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-23 09:47 . 2009-09-21 15:23 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-23 09:47 . 2009-09-21 15:23 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-21 16:56 . 2007-04-26 14:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-18 18:24 . 2009-12-18 18:24 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-25 18:26 . 2009-11-25 18:26 -------- d-----w- c:\programdata\WindowsSearch
2009-11-22 14:04 . 2009-09-21 15:23 163728 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-22 14:04 . 2009-09-21 15:23 87496 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-22 14:04 . 2009-09-21 15:23 327000 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-22 14:04 . 2009-09-21 15:23 641632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-22 08:50 . 2009-09-08 15:27 -------- d-----r- c:\program files\Skype
2009-11-22 08:50 . 2009-11-22 08:50 -------- d-----w- c:\program files\Common Files\Skype
2009-11-22 08:50 . 2009-09-08 15:27 -------- d-----w- c:\programdata\Skype
2009-11-21 06:40 . 2009-12-09 14:09 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 14:09 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 14:09 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 14:09 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 09:51 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-15 09:48 . 2009-11-15 09:49 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-15 09:48 . 2009-11-15 09:48 93360 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-15 09:48 . 2009-11-15 09:48 554280 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-15 09:48 . 2009-09-21 15:23 15880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-11-15 09:48 . 2009-09-11 11:04 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-15 09:48 . 2009-11-15 09:48 212480 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-15 09:48 . 2009-11-15 09:48 283944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-15 09:48 . 2009-11-15 09:48 1223976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-15 09:48 . 2009-11-15 09:48 242984 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-09 12:31 . 2009-12-09 16:51 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 16:51 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 16:51 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-26 15:59 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-19_13.40.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-19 14:33 . 2010-01-19 14:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-01-19 13:18 . 2010-01-19 13:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-01-19 14:33 . 2010-01-19 14:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-01-19 13:18 . 2010-01-19 13:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-12-02 167936]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-10 46704]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-04-26 77824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-18 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-18 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-18 133656]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"snpstd3"="c:\windows\vsnpstd3.exe" [2005-09-05 339968]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-12 20480]
"tsnp325"="c:\windows\tsnp325.exe" [2006-10-10 270336]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2007-12-10 323584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]
Spamihilator.lnk - c:\program files\Spamihilator\spamihilator.exe [2010-1-18 1504768]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):df,79,91,f8,97,34,ca,01
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [18. 10. 2009 9:45 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24. 9. 2009 12:17 1181328]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [11. 9. 2009 9:45 21504]
S3 PAC207;PC Camer@;c:\windows\System32\drivers\PFC027.SYS [13. 2. 2008 17:17 618112]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\System32\drivers\snp325.sys [21. 12. 2009 17:57 10251904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-01-19 c:\windows\Tasks\User_Feed_Synchronization-{998B468C-9444-443B-BAD5-61D1D44652AF}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zoznam.sk/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-19 15:52
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-19 15:56:39
ComboFix-quarantined-files.txt 2010-01-19 14:56
ComboFix2.txt 2010-01-19 13:43
Pre-Run: 12 960 583 680 bytes free
Post-Run: 12 937 437 184 bytes free
- - End Of File - - 17DA5EF26902EF638D3699FA7EDA8C70
ComboFix 10-01-18.03 - Milan a Silvia . 01. 2010 15:41:56.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1033.18.1013.86 [GMT 1:00]
Running from: c:\users\Milan a Silvia.SilviaaMilan-PC\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-12-19 to 2010-01-19 )))))))))))))))))))))))))))))))
.
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\MILANA~1~SIL\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Milan a Silvia\AppData\Local\temp
2010-01-19 14:52 . 2010-01-19 14:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-18 17:36 . 2010-01-18 17:36 -------- d-----w- C:\zaloha
2010-01-18 16:47 . 2010-01-18 16:47 -------- d-----w- c:\program files\CCleaner
2010-01-18 12:43 . 2010-01-18 12:43 -------- d-----w- c:\programdata\Spamihilator
2010-01-18 12:43 . 2010-01-19 14:35 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\Spamihilator
2010-01-18 12:41 . 2010-01-18 12:41 -------- d-----w- c:\program files\Spamihilator
2010-01-18 12:10 . 2010-01-18 13:50 -------- d-----w- c:\program files\trend micro
2010-01-18 09:35 . 2010-01-18 09:37 -------- d-----w- c:\program files\Ultimate Process Manager
2010-01-14 14:13 . 2010-01-14 14:13 273205 ----a-w- c:\windows\PC Image Editor Uninstaller.exe
2010-01-14 14:13 . 2010-01-14 14:20 -------- d-----w- c:\program files\PC Image Editor
2010-01-14 14:13 . 2010-01-14 14:13 -------- d-----w- c:\program files\Common Files\Program4Pc
2010-01-13 18:03 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 18:03 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-12-26 17:59 . 2010-01-10 18:22 230432 ----a-w- C:\PA207.DAT
2009-12-26 17:55 . 2009-12-26 17:55 -------- d-----w- c:\windows\PixArt
2009-12-21 17:02 . 2007-03-14 10:21 61440 ----a-w- c:\windows\system32\vsnpx32.dll
2009-12-21 16:57 . 2007-02-12 13:50 20480 ----a-w- c:\windows\FixCamera.exe
2009-12-21 16:57 . 2006-04-18 15:53 135168 ----a-w- c:\windows\amcap.exe
2009-12-21 16:57 . 2006-10-10 14:49 270336 ----a-w- c:\windows\tsnp325.exe
2009-12-21 16:57 . 2006-10-10 13:11 827392 ----a-w- c:\windows\vsnp325.exe
2009-12-21 16:57 . 2007-04-03 12:55 10251904 ----a-w- c:\windows\system32\drivers\snp325.sys
2009-12-21 16:57 . 2009-12-21 17:02 -------- d-----w- c:\program files\Common Files\snp325
2009-12-21 16:57 . 2007-03-14 10:21 61440 ----a-w- c:\windows\system32\vsnp325.dll
2009-12-21 16:57 . 2006-04-12 11:11 147456 ----a-w- c:\windows\system32\rsnp325.dll
2009-12-21 16:57 . 2005-11-23 12:55 53248 ----a-w- c:\windows\system32\csnp325.dll
2009-12-21 16:56 . 2009-12-21 16:56 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 14:35 . 2009-09-08 15:28 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\Skype
2010-01-19 14:35 . 2009-09-08 15:29 -------- d-----w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\skypePM
2010-01-19 13:19 . 2009-09-08 13:45 1356 ----a-w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Local\d3d9caps.dat
2010-01-19 13:04 . 2009-09-07 16:22 87120 ----a-w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-14 10:12 . 2009-10-04 14:51 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-14 09:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-14 09:13 . 2009-09-24 15:13 1 ----a-w- c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-07 15:47 . 2009-09-21 15:23 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-23 09:48 . 2009-09-21 15:23 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-23 09:48 . 2009-09-21 15:23 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-23 09:48 . 2009-09-21 15:23 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-23 09:48 . 2009-10-18 08:45 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-23 09:48 . 2009-09-21 15:23 194104 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-23 09:48 . 2009-09-21 15:23 370744 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-23 09:47 . 2009-09-21 15:23 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-23 09:47 . 2009-09-21 15:23 816272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-23 09:47 . 2009-09-21 15:23 822904 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-23 09:47 . 2009-09-21 15:23 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-23 09:47 . 2009-09-21 15:23 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-23 09:47 . 2009-09-21 15:23 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-21 16:56 . 2007-04-26 14:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-18 18:24 . 2009-12-18 18:24 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-25 18:26 . 2009-11-25 18:26 -------- d-----w- c:\programdata\WindowsSearch
2009-11-22 14:04 . 2009-09-21 15:23 163728 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-22 14:04 . 2009-09-21 15:23 87496 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-22 14:04 . 2009-09-21 15:23 327000 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-22 14:04 . 2009-09-21 15:23 641632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-22 08:50 . 2009-09-08 15:27 -------- d-----r- c:\program files\Skype
2009-11-22 08:50 . 2009-11-22 08:50 -------- d-----w- c:\program files\Common Files\Skype
2009-11-22 08:50 . 2009-09-08 15:27 -------- d-----w- c:\programdata\Skype
2009-11-21 06:40 . 2009-12-09 14:09 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 14:09 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 14:09 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 14:09 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 09:51 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-15 09:48 . 2009-11-15 09:49 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-15 09:48 . 2009-11-15 09:48 93360 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-15 09:48 . 2009-11-15 09:48 554280 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-15 09:48 . 2009-09-21 15:23 15880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-11-15 09:48 . 2009-09-11 11:04 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-15 09:48 . 2009-11-15 09:48 212480 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-15 09:48 . 2009-11-15 09:48 283944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-15 09:48 . 2009-11-15 09:48 1223976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-15 09:48 . 2009-11-15 09:48 242984 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-09 12:31 . 2009-12-09 16:51 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 16:51 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 16:51 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-26 15:59 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-19_13.40.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-19 14:33 . 2010-01-19 14:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-01-19 13:18 . 2010-01-19 13:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-01-19 14:33 . 2010-01-19 14:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-01-19 13:18 . 2010-01-19 13:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-12-02 167936]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-10 46704]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-04-26 77824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-18 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-18 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-18 133656]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"snpstd3"="c:\windows\vsnpstd3.exe" [2005-09-05 339968]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-12 20480]
"tsnp325"="c:\windows\tsnp325.exe" [2006-10-10 270336]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2007-12-10 323584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Milan a Silvia.SilviaaMilan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]
Spamihilator.lnk - c:\program files\Spamihilator\spamihilator.exe [2010-1-18 1504768]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):df,79,91,f8,97,34,ca,01
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [18. 10. 2009 9:45 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24. 9. 2009 12:17 1181328]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [11. 9. 2009 9:45 21504]
S3 PAC207;PC Camer@;c:\windows\System32\drivers\PFC027.SYS [13. 2. 2008 17:17 618112]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\System32\drivers\snp325.sys [21. 12. 2009 17:57 10251904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-01-19 c:\windows\Tasks\User_Feed_Synchronization-{998B468C-9444-443B-BAD5-61D1D44652AF}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zoznam.sk/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-19 15:52
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-19 15:56:39
ComboFix-quarantined-files.txt 2010-01-19 14:56
ComboFix2.txt 2010-01-19 13:43
Pre-Run: 12 960 583 680 bytes free
Post-Run: 12 937 437 184 bytes free
- - End Of File - - 17DA5EF26902EF638D3699FA7EDA8C70