nemožnost přihlášení+vypadávající explorer
Napsal: 20 kvě 2010 16:26
Mám problémy s přihlášením na počítač, po zadání hesla se nic neděje, zadám tedy ctrl alt delete a přes task managera se dostanu konečně na plochu. Bezdůvodně začal vypadávat internet explorer, vyskočí vždy okno, jestli chci pokračovat v připojení online a do třetice všeho dobrého mi windows mail hlásí nemožnost připojení k mému mailu a žádá donekonečna potvrzení hesla a adresy.
Trvá to asi měsíc a stupňuje se to.
Přikládám tedy scan OS a děkuji za případnou pomoc. Lenka
ComboFix 10-05-20.07 - oskar 21/05/2010 0:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.353.1033.18.2038.1201 [GMT 1:00]
Running from: c:\users\oskar\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\oskar\AppData\Local\Microsoft\Windows\Temporary Internet Files\WebInst.exe
c:\users\oskar\AppData\Roaming\Microsoft\Windows\Recent\Finan?ní poradna Pot?ebujete v?tší byt Nezbavujte se toho p?vodního – Novinky.cz.url
.
((((((((((((((((((((((((( Files Created from 2010-04-20 to 2010-05-20 )))))))))))))))))))))))))))))))
.
2010-05-20 23:33 . 2010-05-20 23:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-20 21:39 . 2010-05-20 21:39 -------- d-----w- c:\programdata\avg8
2010-05-20 14:15 . 2010-05-20 14:15 -------- d-----w- C:\rsit
2010-05-20 14:05 . 2010-05-20 14:07 -------- d-----w- c:\program files\Ultimate Process Manager
2010-05-20 13:55 . 2010-05-20 17:13 -------- d-----w- c:\program files\Trend Micro
2010-05-19 23:36 . 2010-05-19 23:36 -------- d-----w- c:\program files\Windows Portable Devices
2010-05-19 20:34 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-05-19 20:34 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-05-19 20:34 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-05-19 20:31 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-05-19 20:31 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-05-19 20:31 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-05-19 20:20 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-05-19 20:20 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll
2010-05-19 20:20 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-05-19 20:20 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-05-19 20:20 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-05-19 20:20 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-05-19 20:20 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-05-19 20:20 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-05-19 20:20 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-05-19 20:20 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-05-19 20:20 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-05-19 20:20 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-05-12 12:32 . 2010-05-12 12:32 -------- d-----w- c:\program files\Bonjour
2010-05-12 12:09 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-11 14:02 . 2010-05-11 14:02 352513 ----a-w- c:\windows\system32\savapi3.dll
2010-05-11 14:02 . 2010-05-11 14:02 1380403 ----a-w- c:\windows\system32\avgsdk.dll
2010-04-21 16:38 . 2010-04-12 16:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-21 08:09 . 2010-04-21 08:09 242696 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-04-21 08:07 . 2010-04-21 08:07 1689952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-20 22:22 . 2010-05-20 22:22 -------- d-----w- c:\program files\Reimage
2010-05-20 21:55 . 2007-12-20 05:46 12 ----a-w- c:\windows\bthservsdp.dat
2010-05-20 21:39 . 2009-08-19 12:30 -------- d-----w- c:\program files\AVG
2010-05-20 12:07 . 2007-12-20 06:21 -------- d-----w- c:\program files\Google
2010-05-19 23:43 . 2008-01-04 15:33 121656 ----a-w- c:\users\oskar\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-19 23:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-05-19 23:36 . 2010-05-19 23:36 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-05-19 23:35 . 2010-05-19 23:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-05-19 20:22 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-14 13:02 . 2010-04-16 15:32 -------- d-----w- c:\program files\Seznam.cz
2010-05-12 12:31 . 2008-10-10 15:46 -------- d-----w- c:\program files\Common Files\Apple
2010-04-21 16:38 . 2007-12-20 06:00 -------- d-----w- c:\program files\Java
2010-04-21 08:09 . 2009-08-19 12:30 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-13 04:46 . 2009-09-18 21:42 680 ----a-w- c:\users\oskar\AppData\Local\d3d9caps.dat
2010-04-08 12:20 . 2010-04-08 12:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-07 20:46 . 2010-04-07 20:46 303104 ----a-w- c:\windows\sttray.exe
2010-04-07 09:20 . 2009-08-19 12:30 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-07 09:20 . 2009-08-19 12:30 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-07 09:20 . 2009-08-19 12:30 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-07 09:20 . 2009-08-19 12:30 -------- d-----w- c:\programdata\AVG Security Toolbar
2010-04-07 09:17 . 2010-04-07 09:16 -------- d-----w- c:\programdata\avg9
2010-04-07 07:43 . 2007-12-20 06:00 -------- d-----w- c:\program files\Common Files\Java
2010-03-23 12:57 . 2010-02-11 13:29 -------- d-----w- c:\programdata\Microsoft Help
2010-03-05 14:01 . 2010-04-14 09:04 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 10:16 . 2009-10-02 19:45 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 11:10 . 2010-04-14 09:04 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-14 09:04 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-14 09:04 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-03-31 09:23 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 09:23 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-03-31 09:23 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-03-31 09:23 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-10 20:14 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 20:14 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 20:14 411648 ----a-w- c:\windows\system32\drivers\http.sys
2007-12-20 13:38 . 2007-12-20 13:25 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 08:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-15 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-15 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-15 81920]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-13 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"DeStatusMon"="c:\program files\Dell\MFP_DELL\deDvcStatus.exe" [2007-06-28 286720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2008-08-15 1473536]
"SigmatelSysTrayApp"="sttray.exe" [2010-04-07 303104]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-05-20 2007832]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-20 50688]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-12-20 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):f7,36,11,db,6c,64,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2859803321-1419006059-3018575030-1000]
"EnableNotificationsRef"=dword:00000001
R2 gupdate1ca15b7b85fc110;Google Update Service (gupdate1ca15b7b85fc110);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-05 133104]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-02-23 369920]
R3 DESVUSB;Dell service driver;c:\windows\system32\DRIVERS\desrvusb.sys [2007-05-11 17536]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-13 30192]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-07 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-04-21 242896]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2010-05-20 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2010-05-20 297752]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-07 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-07 308064]
S2 deMntrService;Dell AIO Center Service;c:\program files\Dell\MFP_DELL\deMntrService.exe [2007-06-28 131072]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CPUZ132
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-05-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-20 08:40]
2010-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-05 10:29]
2010-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-05 10:29]
2010-05-19 c:\windows\Tasks\User_Feed_Synchronization-{E64F82FD-BC3B-4CF5-A21A-E4DDDE30E36F}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-CmUsbSound - cmcnfgu.cpl
AddRemove-HDMI - c:\windows\system32\igxpun.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-21 00:33
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-05-21 00:36:25
ComboFix-quarantined-files.txt 2010-05-20 23:36
Pre-Run: 86,274,756,608 bytes free
Post-Run: 87,994,470,400 bytes free
- - End Of File - - 27982D9083DF5BC0D50A408E4A3DC201
Trvá to asi měsíc a stupňuje se to.
Přikládám tedy scan OS a děkuji za případnou pomoc. Lenka
ComboFix 10-05-20.07 - oskar 21/05/2010 0:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.353.1033.18.2038.1201 [GMT 1:00]
Running from: c:\users\oskar\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\oskar\AppData\Local\Microsoft\Windows\Temporary Internet Files\WebInst.exe
c:\users\oskar\AppData\Roaming\Microsoft\Windows\Recent\Finan?ní poradna Pot?ebujete v?tší byt Nezbavujte se toho p?vodního – Novinky.cz.url
.
((((((((((((((((((((((((( Files Created from 2010-04-20 to 2010-05-20 )))))))))))))))))))))))))))))))
.
2010-05-20 23:33 . 2010-05-20 23:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-20 21:39 . 2010-05-20 21:39 -------- d-----w- c:\programdata\avg8
2010-05-20 14:15 . 2010-05-20 14:15 -------- d-----w- C:\rsit
2010-05-20 14:05 . 2010-05-20 14:07 -------- d-----w- c:\program files\Ultimate Process Manager
2010-05-20 13:55 . 2010-05-20 17:13 -------- d-----w- c:\program files\Trend Micro
2010-05-19 23:36 . 2010-05-19 23:36 -------- d-----w- c:\program files\Windows Portable Devices
2010-05-19 20:34 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-05-19 20:34 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-05-19 20:34 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-05-19 20:31 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-05-19 20:31 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-05-19 20:31 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-05-19 20:20 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-05-19 20:20 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll
2010-05-19 20:20 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-05-19 20:20 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-05-19 20:20 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-05-19 20:20 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-05-19 20:20 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-05-19 20:20 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-05-19 20:20 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-05-19 20:20 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-05-19 20:20 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-05-19 20:20 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-05-12 12:32 . 2010-05-12 12:32 -------- d-----w- c:\program files\Bonjour
2010-05-12 12:09 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-11 14:02 . 2010-05-11 14:02 352513 ----a-w- c:\windows\system32\savapi3.dll
2010-05-11 14:02 . 2010-05-11 14:02 1380403 ----a-w- c:\windows\system32\avgsdk.dll
2010-04-21 16:38 . 2010-04-12 16:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-21 08:09 . 2010-04-21 08:09 242696 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-04-21 08:07 . 2010-04-21 08:07 1689952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-20 22:22 . 2010-05-20 22:22 -------- d-----w- c:\program files\Reimage
2010-05-20 21:55 . 2007-12-20 05:46 12 ----a-w- c:\windows\bthservsdp.dat
2010-05-20 21:39 . 2009-08-19 12:30 -------- d-----w- c:\program files\AVG
2010-05-20 12:07 . 2007-12-20 06:21 -------- d-----w- c:\program files\Google
2010-05-19 23:43 . 2008-01-04 15:33 121656 ----a-w- c:\users\oskar\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-19 23:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-05-19 23:36 . 2010-05-19 23:36 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-05-19 23:35 . 2010-05-19 23:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-05-19 20:22 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-14 13:02 . 2010-04-16 15:32 -------- d-----w- c:\program files\Seznam.cz
2010-05-12 12:31 . 2008-10-10 15:46 -------- d-----w- c:\program files\Common Files\Apple
2010-04-21 16:38 . 2007-12-20 06:00 -------- d-----w- c:\program files\Java
2010-04-21 08:09 . 2009-08-19 12:30 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-13 04:46 . 2009-09-18 21:42 680 ----a-w- c:\users\oskar\AppData\Local\d3d9caps.dat
2010-04-08 12:20 . 2010-04-08 12:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-07 20:46 . 2010-04-07 20:46 303104 ----a-w- c:\windows\sttray.exe
2010-04-07 09:20 . 2009-08-19 12:30 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-07 09:20 . 2009-08-19 12:30 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-07 09:20 . 2009-08-19 12:30 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-07 09:20 . 2009-08-19 12:30 -------- d-----w- c:\programdata\AVG Security Toolbar
2010-04-07 09:17 . 2010-04-07 09:16 -------- d-----w- c:\programdata\avg9
2010-04-07 07:43 . 2007-12-20 06:00 -------- d-----w- c:\program files\Common Files\Java
2010-03-23 12:57 . 2010-02-11 13:29 -------- d-----w- c:\programdata\Microsoft Help
2010-03-05 14:01 . 2010-04-14 09:04 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 10:16 . 2009-10-02 19:45 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 11:10 . 2010-04-14 09:04 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-14 09:04 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-14 09:04 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-03-31 09:23 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 09:23 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-03-31 09:23 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-03-31 09:23 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-10 20:14 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 20:14 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 20:14 411648 ----a-w- c:\windows\system32\drivers\http.sys
2007-12-20 13:38 . 2007-12-20 13:25 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 08:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-15 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-15 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-15 81920]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-13 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"DeStatusMon"="c:\program files\Dell\MFP_DELL\deDvcStatus.exe" [2007-06-28 286720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2008-08-15 1473536]
"SigmatelSysTrayApp"="sttray.exe" [2010-04-07 303104]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-05-20 2007832]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-20 50688]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-12-20 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):f7,36,11,db,6c,64,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2859803321-1419006059-3018575030-1000]
"EnableNotificationsRef"=dword:00000001
R2 gupdate1ca15b7b85fc110;Google Update Service (gupdate1ca15b7b85fc110);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-05 133104]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-02-23 369920]
R3 DESVUSB;Dell service driver;c:\windows\system32\DRIVERS\desrvusb.sys [2007-05-11 17536]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-13 30192]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-07 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-04-21 242896]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2010-05-20 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2010-05-20 297752]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-07 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-07 308064]
S2 deMntrService;Dell AIO Center Service;c:\program files\Dell\MFP_DELL\deMntrService.exe [2007-06-28 131072]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CPUZ132
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-05-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-20 08:40]
2010-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-05 10:29]
2010-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-05 10:29]
2010-05-19 c:\windows\Tasks\User_Feed_Synchronization-{E64F82FD-BC3B-4CF5-A21A-E4DDDE30E36F}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-CmUsbSound - cmcnfgu.cpl
AddRemove-HDMI - c:\windows\system32\igxpun.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-21 00:33
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-05-21 00:36:25
ComboFix-quarantined-files.txt 2010-05-20 23:36
Pre-Run: 86,274,756,608 bytes free
Post-Run: 87,994,470,400 bytes free
- - End Of File - - 27982D9083DF5BC0D50A408E4A3DC201