spustil som znovu, tentoraz nabehol a normalne presiel, tu je LOG:
ComboFix 10-08-24.0A - rolly 25.08.2010 14:33:24.1.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1509 [GMT 2:00]
Running from: c:\documents and settings\rolly\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\2ul.exe
c:\documents and settings\rolly\Application Data\inst.exe
C:\eyruu.exe
C:\g6jk.exe
C:\MK28SP.EXE
D:\2ul.exe
D:\g6jk.exe
D:\mk28sp.exe
G:\2ul.exe
G:\g6jk.exe
G:\mk28sp.exe
G:\xcr.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-25 to 2010-08-25 )))))))))))))))))))))))))))))))
.
2010-08-25 11:19 . 2010-08-25 12:29 -------- d-----w- c:\program files\trend micro
2010-08-25 11:19 . 2010-08-25 11:19 -------- d-----w- C:\rsit
2010-08-25 10:19 . 2010-08-25 10:19 -------- d-----w- c:\documents and settings\rolly\Application Data\Malwarebytes
2010-08-25 10:19 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-25 10:19 . 2010-08-25 10:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-25 10:19 . 2010-08-25 10:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-25 10:19 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-17 20:22 . 2010-08-17 20:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-08-16 17:41 . 2005-04-26 12:00 40960 ----a-w- c:\windows\IGLobbyReg.exe
2010-08-16 14:23 . 2010-08-16 14:32 -------- d-----w- c:\program files\IObit
2010-08-16 14:23 . 2010-08-16 14:32 -------- d-----w- c:\documents and settings\rolly\Application Data\IObit
2010-08-15 10:33 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-08-15 10:33 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-08-15 10:33 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-08-15 10:33 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-08-15 10:33 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-08-15 10:33 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-08-15 10:33 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-08-15 10:33 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-08-14 19:03 . 2010-08-14 19:03 -------- d-----w- c:\program files\Recuva
2010-08-14 18:06 . 2010-08-14 18:06 -------- d-----w- c:\documents and settings\rolly\Application Data\The Creative Assembly
2010-08-11 17:33 . 2010-08-11 17:33 503808 ----a-w- c:\documents and settings\rolly\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4546c833-n\msvcp71.dll
2010-08-11 17:33 . 2010-08-11 17:33 499712 ----a-w- c:\documents and settings\rolly\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4546c833-n\jmc.dll
2010-08-11 17:33 . 2010-08-11 17:33 348160 ----a-w- c:\documents and settings\rolly\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4546c833-n\msvcr71.dll
2010-08-11 17:33 . 2010-08-11 17:33 61440 ----a-w- c:\documents and settings\rolly\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-488a5989-n\decora-sse.dll
2010-08-11 17:33 . 2010-08-11 17:33 12800 ----a-w- c:\documents and settings\rolly\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-488a5989-n\decora-d3d.dll
2010-08-07 16:21 . 2010-08-07 16:21 -------- d-----w- c:\documents and settings\rolly\Application Data\Megaupload
2010-08-03 13:17 . 2010-08-03 13:18 -------- d-----w- c:\program files\USBInfo
2010-08-03 13:17 . 2010-08-03 13:17 249856 ------w- c:\windows\Setup1.exe
2010-08-03 13:17 . 2010-08-03 13:17 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-08-03 13:07 . 2010-08-03 13:07 -------- d-----w- c:\windows\system32\NtmsData
2010-07-30 19:08 . 2010-07-30 19:08 -------- d-----w- c:\documents and settings\rolly\Local Settings\Application Data\capcom
2010-07-30 10:12 . 2010-07-30 10:12 -------- d-----w- c:\documents and settings\rolly\Application Data\Thinstall
2010-07-30 09:33 . 2010-07-30 09:33 -------- d-----w- c:\documents and settings\rolly\Application Data\TeamViewer
2010-07-30 09:33 . 2010-07-30 09:33 -------- d-----w- c:\program files\TeamViewer
2010-07-30 08:03 . 2010-07-30 08:03 -------- d-----w- c:\documents and settings\rolly\Application Data\My Battle for Middle-earth Files
2010-07-29 09:42 . 2010-07-29 09:43 -------- d-----w- c:\documents and settings\rolly\Application Data\RadioBar
2010-07-29 09:42 . 2010-07-30 19:02 -------- d-----w- c:\program files\RadioBar
2010-07-27 13:03 . 2010-07-27 13:03 -------- d-----w- c:\documents and settings\rolly\Application Data\Subversion
2010-07-27 12:53 . 2010-08-25 12:23 -------- d-----w- c:\documents and settings\rolly\Local Settings\Application Data\TSVNCache
2010-07-27 12:51 . 2010-07-27 12:51 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2010-07-27 12:22 . 2010-07-27 12:22 -------- d-----w- c:\documents and settings\rolly\Application Data\syntevo
2010-07-27 12:20 . 2010-07-27 12:20 -------- d-----w- c:\program files\Sun
2010-07-27 12:20 . 2010-07-27 12:20 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-27 12:13 . 2010-07-27 12:13 -------- d-----w- c:\documents and settings\All Users\Application Data\syntevo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-25 09:39 . 2010-04-05 14:10 -------- d-----w- c:\documents and settings\rolly\Application Data\Skype
2010-08-25 08:23 . 2010-04-30 16:27 2150 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-08-25 06:29 . 2010-05-08 18:55 3296 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-08-25 06:29 . 2010-05-08 18:55 3296 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-08-25 06:29 . 2010-05-08 18:55 88 --sh--r- c:\documents and settings\All Users\Application Data\071233707D.sys
2010-08-25 06:29 . 2010-05-08 18:55 88 --sh--r- c:\documents and settings\All Users\Application Data\071233707D.sys
2010-08-25 06:05 . 2008-03-16 09:59 -------- d-----w- c:\documents and settings\rolly\Application Data\skypePM
2010-08-25 01:05 . 2010-04-05 19:41 -------- d-----w- c:\program files\Trillian
2010-08-24 14:54 . 2010-03-25 07:15 -------- d-----w- c:\documents and settings\rolly\Application Data\uTorrent
2010-08-24 10:01 . 2010-04-25 10:16 -------- d-----w- c:\documents and settings\rolly\Application Data\vlc
2010-08-24 06:18 . 2010-04-25 10:17 -------- d-----w- c:\documents and settings\rolly\Application Data\dvdcss
2010-08-19 15:14 . 2010-07-24 15:38 -------- d-----w- c:\program files\Steam
2010-08-19 01:13 . 2008-03-16 08:25 118912 ----a-w- c:\documents and settings\rolly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-18 15:10 . 2008-03-16 07:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-17 20:22 . 2010-03-24 21:15 -------- d-----w- c:\program files\ESET
2010-08-16 17:50 . 2010-04-04 18:03 -------- d-----w- c:\program files\GameShadow
2010-08-16 17:41 . 2010-04-04 18:04 8854 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{EBB11C78-68A6-42D7-84FC-517F9DBF9D55}\Uninstall_GameShadow_BAB1DDFC9AE64358B0AD15DC2FDBA636.exe
2010-08-16 17:41 . 2010-04-04 18:04 45056 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{EBB11C78-68A6-42D7-84FC-517F9DBF9D55}\GameShadow.exe1_BAB1DDFC9AE64358B0AD15DC2FDBA636.exe
2010-08-16 17:41 . 2010-04-04 18:04 45056 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{EBB11C78-68A6-42D7-84FC-517F9DBF9D55}\GameShadow.exe_BAB1DDFC9AE64358B0AD15DC2FDBA636.exe
2010-08-16 17:41 . 2010-04-04 18:04 40960 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{EBB11C78-68A6-42D7-84FC-517F9DBF9D55}\GSDR.exe_BAB1DDFC9AE64358B0AD15DC2FDBA636.exe
2010-08-16 17:41 . 2010-04-04 18:04 40960 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{EBB11C78-68A6-42D7-84FC-517F9DBF9D55}\ARPPRODUCTICON.exe
2010-08-02 18:12 . 2008-03-16 10:00 -------- d-----w- c:\documents and settings\rolly\Application Data\Winamp
2010-07-30 18:55 . 2010-04-04 16:42 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-07-28 18:46 . 2010-03-27 19:11 -------- d-----w- c:\documents and settings\rolly\Application Data\Hamachi
2010-07-27 12:58 . 2010-07-08 12:49 5 ----a-w- c:\windows\treeskp.sys
2010-07-27 12:58 . 2010-07-08 12:49 5 ----a-w- c:\windows\sbacknt.bin
2010-07-27 12:21 . 2008-03-16 09:12 -------- d-----w- c:\program files\Common Files\Java
2010-07-27 12:19 . 2008-03-16 09:13 -------- d-----w- c:\program files\Java
2010-07-27 11:40 . 2010-07-08 12:49 152904 ----a-w- c:\windows\system32\vghd.scr
2010-07-26 17:20 . 2010-03-26 17:47 -------- d-----w- c:\documents and settings\rolly\Application Data\ICQ
2010-07-26 17:18 . 2010-03-26 17:47 -------- d-----w- c:\program files\ICQ7.1
2010-07-24 15:01 . 2010-07-24 15:00 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-07-21 12:44 . 2010-07-21 12:44 15360 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
2010-07-21 12:44 . 2010-07-21 12:44 11264 ----a-r- c:\documents and settings\rolly\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
2010-07-13 09:57 . 2010-07-13 09:57 -------- d-----w- c:\program files\Common Files\PocketSoft
2010-07-11 15:47 . 2010-03-25 17:18 -------- d-----w- c:\documents and settings\rolly\Application Data\Ubisoft
2010-07-11 15:47 . 2010-06-20 07:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Tages
2010-07-11 15:42 . 2010-04-05 13:43 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-07-11 15:42 . 2010-04-05 13:43 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-07-09 22:02 . 2010-07-09 22:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Softland
2010-07-09 06:28 . 2008-03-16 10:57 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-08 18:48 . 2010-07-08 18:48 -------- d-----w- c:\documents and settings\rolly\Application Data\Softland
2010-07-08 18:48 . 2010-07-08 18:48 -------- d-----w- c:\documents and settings\LocalService\Application Data\Softland
2010-07-08 18:47 . 2010-07-08 18:47 -------- d-----w- c:\program files\Softland
2010-07-08 12:52 . 2010-07-08 12:49 -------- d-----w- c:\documents and settings\rolly\Application Data\vghd
2010-07-05 15:20 . 2010-07-05 15:20 49152 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-07-05 15:20 . 2010-07-05 15:20 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-07-05 15:20 . 2010-07-05 15:20 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-07-05 15:20 . 2010-07-05 15:20 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-07-05 15:20 . 2010-07-05 15:20 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-07-05 15:20 . 2010-07-05 15:20 40960 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-07-05 15:20 . 2010-07-05 15:20 308808 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-07-05 15:20 . 2010-07-05 15:20 14848 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-07-05 15:20 . 2010-07-05 15:20 341600 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-07-05 15:20 . 2010-07-05 15:18 -------- d-----w- c:\program files\Common Files\Real
2010-07-05 15:19 . 2010-07-05 15:18 -------- d-----w- c:\program files\Real
2010-07-05 15:19 . 2010-07-05 15:19 -------- d-----w- c:\program files\Common Files\xing shared
2010-07-05 15:18 . 2008-03-16 08:45 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-07-05 15:18 . 2008-03-16 08:45 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-07-02 10:43 . 2010-07-02 10:43 95896 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2010-07-02 10:43 . 2010-07-02 10:43 140752 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-07-01 11:44 . 2010-07-01 11:42 -------- d-----w- c:\program files\NCSoft
2010-06-30 12:31 . 2003-03-31 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-26 17:24 . 2010-06-26 17:24 50354 ----a-w- c:\documents and settings\rolly\Application Data\Facebook\uninstall.exe
2010-06-26 17:24 . 2010-06-26 17:24 -------- d-----w- c:\documents and settings\rolly\Application Data\Facebook
2010-06-26 08:21 . 2010-06-26 07:28 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-06-26 08:21 . 2010-06-26 07:28 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-06-24 12:22 . 2006-06-23 10:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2003-03-31 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2003-03-31 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2003-03-31 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-03-16 07:38 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-14 07:41 . 2010-03-25 13:42 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 09:39 . 2010-06-06 12:59 14 ----a-w- c:\windows\system32\nvModes.dat
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\documents and settings\rolly\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-02 10:58 . 2010-07-08 18:47 23368 ----a-w- c:\windows\system32\novamnl7.dll
2010-06-02 10:58 . 2010-07-08 18:47 20808 ----a-w- c:\windows\system32\novamil7.dll
2010-04-30 16:27 . 2010-04-30 16:27 8 --sh--r- c:\windows\system32\071233707D.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B291E6C-9A74-4034-971B-A4B007A0B315}]
2010-01-11 10:18 451808 ----a-w- c:\program files\RadioBar\toolbar.ni.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5B291E6C-9A74-4034-971B-A4B007A0B315}"= "c:\program files\RadioBar\toolbar.ni.dll" [2010-01-11 451808]
[HKEY_CLASSES_ROOT\clsid\{5b291e6c-9a74-4034-971b-a4b007a0b315}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{810FCC0F-2CA3-414a-B8C8-550910C8B664}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5B291E6C-9A74-4034-971B-A4B007A0B315}"= "c:\program files\RadioBar\toolbar.ni.dll" [2010-01-11 451808]
[HKEY_CLASSES_ROOT\clsid\{5b291e6c-9a74-4034-971b-a4b007a0b315}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{810FCC0F-2CA3-414a-B8C8-550910C8B664}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 06:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN1]
@="{CC8811D1-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D1-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN2]
@="{CC8811D2-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D2-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN3]
@="{CC8811D3-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D3-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN4]
@="{CC8811D4-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D4-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN5]
@="{CC8811D5-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D5-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN6]
@="{CC8811D6-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D6-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartSVN7]
@="{CC8811D7-1B32-4f3d-A9BF-D21C8F3C0366}"
[HKEY_CLASSES_ROOT\CLSID\{CC8811D7-1B32-4f3d-A9BF-D21C8F3C0366}]
2010-07-07 08:41 249856 ----a-w- g:\svn\lib\shellext32.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
"Google Update"="c:\documents and settings\rolly\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-25 136176]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-08-29 143360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-07-02 2202704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-3-16 113664]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartSVN 6.5 (background).lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SmartSVN 6.5 (background).lnk
backup=c:\windows\pss\SmartSVN 6.5 (background).lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
2010-08-10 13:10 2349776 ----a-w- c:\program files\IObit\Advanced SystemCare 3\AWC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mega Manager]
2010-07-28 13:57 2106880 ----a-w- h:\programy\Mega Manager\MegaManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 01:08 2512392 ----a-w- c:\windows\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-07-24 15:39 1238352 ----a-w- c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniblueRegistryBooster]
2010-03-16 15:25 60208 ----a-w- c:\program files\Uniblue\RegistryBooster\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2008-01-15 22:54 37376 ----a-w- c:\program files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"g:\\torrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"h:\\Programy\\Ventrilo\\Ventrilo.exe"=
"h:\\Programy\\Ventriloserver\\ventrilo_srv.exe"=
"h:\\Programy\\TS-server\\teamspeak3-server_win32\\ts3server_win32.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\Europa 1400 - Gold Edition\\Europa1400Gold_TL.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\prenos\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"d:\\Hellgate London\\Launcher.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\Warhammer\\Warhammer.exe"=
"g:\\AION_Emulator_by_CriticalError\\AIONEmulator\\usr\\local\\apache2\\bin\\Apache_16.exe"=
"g:\\AION_Emulator_by_CriticalError\\AIONEmulator\\usr\\local\\mysql\\bin\\mysqld-opt.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"g:\\L P\\LostPlanetColoniesDX9.exe"=
"g:\\L P\\LostPlanetColoniesDX10.exe"=
"h:\\Medal of Honor\\MOHAA.exe"=
"h:\\Imperial Glory\\ImperialGlory.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [28.4.2010 8:17 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2.7.2010 12:43 95896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2.7.2010 12:43 810144]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.3.2010 19:47 246520]
R2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [6.7.2010 17:03 173352]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [11.3.2010 11:17 25088]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [20.5.2010 14:29 136176]
S2 statuscached;SmartSVN Status Cache;g:\svn\bin\statuscached.exe [7.7.2010 10:41 216576]
S3 ptiusbf;PTI USB Filter;c:\windows\system32\drivers\ptiusbf.sys [14.4.2001 0:22 22474]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [17.4.2010 15:05 256512]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [17.4.2010 15:05 398720]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.3.2010 17:11 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-20 12:29]
2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-20 12:29]
2010-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-813497703-839522115-1004Core.job
- c:\documents and settings\rolly\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-25 15:09]
2010-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-813497703-839522115-1004UA.job
- c:\documents and settings\rolly\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-25 15:09]
2010-08-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-813497703-839522115-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2010-08-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-813497703-839522115-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://radiobar.toolbarhome.com?hp=df
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
Handler: toolbarchrome - {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - c:\program files\RadioBar\toolbar.ni.dll
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\documents and settings\rolly\Application Data\Mozilla\Firefox\Profiles\jhx6myu1.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.2&q=
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\rolly\Application Data\Mozilla\Firefox\Profiles\jhx6myu1.default\extensions\
DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\rolly\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\rolly\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: g:\jdk\bin\new_plugin\npdeployJava1.dll
FF - plugin: g:\jdk\bin\new_plugin\npjp2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Turbine Download Manager Tray Icon - d:\turbine download manager\TurbineDownloadManagerIcon.exe
AddRemove-Unlocker - h:\my documents\Programy\un\Unlocker\uninst.exe
AddRemove-_{05D60953-9012-44DF-A1A6-9DD97AD6580A} - g:\cp xi\MSILauncher {05D60953-9012-44DF-A1A6-9DD97AD6580A}
AddRemove-Third Age - Total War 1.0 Part1 - h:\medieval ii-total war\Uninstal.exe
AddRemove-Third Age - Total War 1.0 Part2 - h:\medieval ii-total war\Uninstal.exe
AddRemove-Third Age - Total War Hotfix1 - h:\medieval ii-total war\Uninstal.exe
AddRemove-Third Age - Total War Patch 1.1 - h:\medieval ii-total war\Uninstal.exe
AddRemove-Third Age - Total War Patch 1.2 - h:\medieval ii-total war\Uninstal.exe
AddRemove-Third Age - Total War Patch 1.3 - h:\medieval ii-total war\Uninstal.exe
AddRemove-Third Age - Total War Patch 1.4 - h:\medieval ii-total war\Uninstal.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-25 14:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1606980848-813497703-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Electronic Arts\B*a*t*t*l*e*F*o*r*g*e*"!\Oxin's Style!]
"Order"=hex:08,00,00,00,02,00,00,00,84,00,00,00,01,00,00,00,01,00,00,00,78,00,
00,00,00,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,31,\
[HKEY_USERS\S-1-5-21-1606980848-813497703-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Electronic Arts\B*a*t*t*l*e*F*o*r*g*e*"!\Oxin's Style!\3D SexVilla 2]
"Order"=hex:08,00,00,00,02,00,00,00,e6,01,00,00,01,00,00,00,03,00,00,00,8a,00,
00,00,00,00,00,00,7c,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,6a,00,32,\
[HKEY_USERS\S-1-5-21-1606980848-813497703-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:21,51,82,51,87,a5,84,a3,05,38,05,d0,f9,75,db,4d,30,af,19,a0,f3,
2c,ed,94,91,2a,7d,0a,60,4d,8d,f2,2f,3a,86,f0,7e,03,21,10,ee,44,00,25,c7,1a,\
"rkeysecu"=hex:91,e0,fa,8a,75,55,82,82,18,01,f7,f6,87,94,dd,a7
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="B82DEEC4D3927BCFEB4ADAA22CC135248A547C30104786A6455078EB3959A7A6D3CA2C41EE9ADA63E1F2D405FD1EDF371E8DC94DD1BBF20F4A2ACB890838E335E733D87BA735356669CA9C70D8F6D03FFA77E7D5B97A486F589C3A18B8D8A843354EDE54017C5EFE316517D87F23A487607252F36DB60A565EF7FA156F6C84C4FAF54E3FC03E8C266B494CC7782EDB2E11D3AAE454D624A8527C67141556E78480FAD9C2717C5DAA4EF3E6D710555BA6D464B6F91AF7621EAB61FC39D82F2C1E8F9F57FA606CCD2C95D438B9D30BE9B579625D18306876C268505E41AAC38982741AFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74CFEBC9E127BECC74CC038D530D6EB34522D4B2B41FE2B8947B514DBF2E045EE8580C0FA64F545BC16437823891BE83536AC93301C28908091E879A1053D4D8710BE51050BAC37F2F3BC84F7DC659130C1EE8B31E0F9CB0404AB8FA7DCB44036516E5FB768B3D4422CC0A8E732A5E024AC3710B696FDDF2C01F909767F578661B6E00F3B1D480E7F5A192160E8DF66F8DE69920D78A2A68D5D712CDA261CDD72250C9E7F0188248610B73E0F137E0A9A358E98C3F63749C864D3D367BC5F5557710D5BB69BF7AC354FAE6366764C867782523C3035F2C9FBD3066D70E3DCD2826722A7D5AAFD916E92B7091F0E7AEB050908A9690AED7ACB5D93FA0F70B78FE747AD7D189FE58F18C32D3DB3099D9A3A8523A1CB02A60362A6A993A06A78970241B666F9A15F3A1EC3101E62492D4B1221BC7B76DB7D60EBCA1961C68E874B4FFEE703BF887DF56EE682602FE506080C7F139ECF0B3961185759A264CD3261511B9084ED63B77DFBF4CE4D622969302DB404097EB8022B9CCD84A9264CAD600BA4A4B3CFF0EA5EBD2A5F3F85907A767C49964CEE3E66B33124D65C76E10FA50A1DB8EA73A95479ADB5C42867CFC1DF05BB730CD12C554714C5B3B5089C5063597C091B2A369786C9BB320D9C4DACC857FBE78499462785848F2043CE3B509B8BAE75C50AF23E0D175581847BA38A60866F6300018214E34754C7A7053451AA36127E036EF2B0EB990EAB3A9F2090A8AAEE7CE1818F39282558F518A62EF93AF1F84DFDF4FB41545EE5D1F0E7C7D5F85FC7EA1EDDC999EEEA571DE0F58754CCDEABAA767F05A1CD72CF38FB77CED8FAC33A8C3E98461828E90055DE774F4FB69C64083E343E68AF68B547423620F82F7CFC60E0F94C7F9775F1D584F54A3D2150D1763FFD089329D7F289414DDA7A66AF370E350FD67C54E6C47ED87BF1D307A5182CF10A7880BC5B56B0892ED184C80A865D02A617A24B1C83CFF5DAF1AD3BC9CD86E6CA5873BE90A50EBD8B0BA5CFBAFCBA20566EE33B7329F0892AAA4AE2"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3756)
c:\windows\system32\WININET.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
g:\tortoisesvn\bin\TortoiseStub.dll
g:\tortoisesvn\bin\TortoiseSVN.dll
g:\tortoisesvn\bin\intl3_tsvn.dll
g:\svn\lib\shellext32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-25 14:38:57
ComboFix-quarantined-files.txt 2010-08-25 12:38
Pre-Run: 16 165 543 936 bytes free
Post-Run: 16 121 536 512 bytes free
- - End Of File - - 0C338DCF780D81C2EDD5645063C7D87E