Stránka 1 z 2

Win32/Yimfoca.AA

Napsal: 15 led 2011 16:01
od casualties
Včera a aj dnes som dostal tento vírus...je síce vyliečený, ale predsa len dám log:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Peter at 2011-01-15 15:27:14
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 33 GB (64%) free of 51 GB
Total RAM: 1023 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:27:19, on 15.1.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\THEKMP~1\KMPlayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Peter\Desktop\RSIT.exe
C:\Program Files\trend micro\Peter.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2786678
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.sk/OnlineScanner.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 3855522859
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://212.80.66.25/activex/AxisCamControl.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crl ... crlocx.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7434 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5424BEA9-A10A-4D48-AC65-CB94681185C6}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-22 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-09-11 2054360]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-10-16 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-10-16 13851752]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-06 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2008-06-24 132392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverScanner]
C:\Program Files\Uniblue\DriverScanner\launcher.exe delay 20000 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Peter\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MultiScreen]
C:\Program Files\MultiScreen\MultiScreen.exe [2008-06-30 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-08-26 1753192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe [2006-05-16 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp]
C:\Program Files\Zrychleni Pocitace\PCSpeedUp.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-09-08 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe [2007-12-14 132624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-06-20 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
C:\PROGRA~1\ATITEC~1\ATI.ACE\CLI.exe [2005-08-06 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\MSI\BTOESB~1\BTTray.exe [2005-05-31 577597]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2005-05-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"lanmanworkstation"=2
"W32Time"=2
"upnphost"=3
"LmHosts"=2
"lanmanserver"=2
"seclogon"=2
"WmdmPmSN"=3
"CiSvc"=3
"PolicyAgent"=2
"FastUserSwitchingCompatibility"=3
"TrkWks"=2
"Browser"=2
"ClipSrv"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-04 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Disabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:PowerDVD"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe:*:Enabled:Nero ControlCenter"
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Disabled:Google Earth"
"C:\Documents and Settings\Peter\Desktop\facebook-pic000934519.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-01-15 15:27:15 ----D---- C:\Program Files\trend micro
2011-01-15 15:27:14 ----D---- C:\rsit
2011-01-12 14:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-01-10 17:29:12 ----A---- C:\WINDOWS\Setup.INI
2011-01-10 17:29:09 ----A---- C:\WINDOWS\Uninstall_tkexe.exe
2011-01-07 17:09:04 ----D---- C:\Documents and Settings\Peter\Application Data\Ahead
2011-01-07 15:19:00 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2011-01-07 15:19:00 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2011-01-07 15:18:57 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2011-01-07 15:18:57 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2011-01-07 15:18:55 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2011-01-07 15:18:55 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2011-01-07 15:18:51 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2011-01-07 15:18:49 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2011-01-07 15:18:49 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2011-01-07 15:18:49 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2011-01-07 15:18:48 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2011-01-07 15:18:47 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2011-01-07 15:18:47 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2011-01-07 15:18:46 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2011-01-05 14:29:28 ----D---- C:\Program Files\AutoPlan
2011-01-02 01:41:49 ----D---- C:\Program Files\Ask.com
2010-12-30 17:20:39 ----A---- C:\WINDOWS\system32\nvhdap32.dll
2010-12-30 17:20:39 ----A---- C:\WINDOWS\system32\drivers\nvhda32.sys
2010-12-30 17:20:38 ----A---- C:\WINDOWS\system32\nvgenco32.dll
2010-12-30 17:20:38 ----A---- C:\WINDOWS\system32\nvdispco32.dll
2010-12-30 17:19:56 ----D---- C:\NVIDIA
2010-12-30 12:52:10 ----A---- C:\WINDOWS\system32\drivers\cpuz135_x32.sys
2010-12-29 22:46:19 ----D---- C:\Documents and Settings\Peter\Application Data\uTorrent
2010-12-28 02:19:00 ----A---- C:\WINDOWS\avisplitter.ini
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\x264vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\lagarith.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\huffyuv.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\DivXc32f.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\DivXc32.dll
2010-12-28 02:18:57 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-12-28 02:18:54 ----D---- C:\Program Files\K-Lite Codec Pack
2010-12-24 09:15:44 ----A---- C:\WINDOWS\system32\frapsvid.dll
2010-12-20 19:34:35 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2010-12-20 19:34:20 ----D---- C:\Program Files\NVIDIA Corporation
2010-12-16 12:37:53 ----D---- C:\WINDOWS\system32\NtmsData

======List of files/folders modified in the last 1 months======

2011-01-15 15:27:15 ----D---- C:\WINDOWS\temp
2011-01-15 15:27:15 ----D---- C:\Program Files
2011-01-15 15:19:38 ----D---- C:\Program Files\Mozilla Firefox
2011-01-15 14:59:26 ----A---- C:\WINDOWS\wincmd.ini
2011-01-15 13:33:02 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-01-15 09:45:26 ----D---- C:\WINDOWS\system32\ias
2011-01-14 23:11:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-14 22:46:30 ----D---- C:\WINDOWS\Prefetch
2011-01-14 20:35:59 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-14 19:49:10 ----D---- C:\WINDOWS
2011-01-14 10:29:01 ----A---- C:\WINDOWS\NeroDigital.ini
2011-01-12 14:42:29 ----D---- C:\WINDOWS\system32
2011-01-12 14:39:44 ----D---- C:\WINDOWS\Debug
2011-01-12 14:39:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-01-12 14:39:39 ----SHD---- C:\WINDOWS\Installer
2011-01-12 14:39:39 ----SHD---- C:\Config.Msi
2011-01-12 14:39:37 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-01-12 14:38:52 ----HD---- C:\WINDOWS\inf
2011-01-12 14:38:46 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-12 14:28:48 ----HD---- C:\WINDOWS\$hf_mig$
2011-01-08 18:42:56 ----A---- C:\WINDOWS\win.ini
2011-01-07 15:19:18 ----A---- C:\WINDOWS\system32\everest_cpl.ini
2011-01-07 15:19:00 ----D---- C:\WINDOWS\system32\DirectX
2011-01-06 19:40:01 ----D---- C:\Documents and Settings
2011-01-06 19:39:14 ----D---- C:\Program Files\The KMPlayer
2011-01-06 19:22:43 ----D---- C:\WINDOWS\system32\drivers
2011-01-06 18:42:10 ----RSD---- C:\WINDOWS\assembly
2011-01-06 18:33:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-05 15:32:34 ----D---- C:\Program Files\Common Files\ACD Systems
2011-01-02 01:41:53 ----SD---- C:\WINDOWS\Tasks
2010-12-31 10:55:11 ----D---- C:\Program Files\Google
2010-12-31 10:46:34 ----RASH---- C:\boot.ini
2010-12-31 10:46:32 ----A---- C:\WINDOWS\system.ini
2010-12-30 17:22:44 ----D---- C:\WINDOWS\Help
2010-12-30 17:20:46 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-12-30 12:52:10 ----D---- C:\Program Files\CPUID
2010-12-28 02:38:12 ----D---- C:\Program Files\TV JOJ Media Player
2010-12-28 02:20:06 ----D---- C:\Documents and Settings\Peter\Application Data\Media Player Classic
2010-12-28 01:02:09 ----D---- C:\Documents and Settings\Peter\Application Data\GetRightToGo
2010-12-23 15:53:40 ----A---- C:\WINDOWS\RtlRack.ini
2010-12-22 23:43:09 ----D---- C:\Program Files\ESET
2010-12-22 23:24:30 ----A---- C:\clicapi.dll
2010-12-22 23:21:08 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
2010-12-22 23:20:53 ----D---- C:\Program Files\Nokia
2010-12-22 23:20:51 ----D---- C:\Program Files\Common Files\Nokia
2010-12-22 23:20:51 ----D---- C:\Program Files\Common Files
2010-12-22 23:20:38 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-22 23:09:47 ----D---- C:\Documents and Settings\Peter\Application Data\Winamp
2010-12-22 16:51:10 ----D---- C:\Program Files\CCleaner

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MMRTKRNL;MMRTKRNL; C:\WINDOWS\system32\drivers\mmrtkrnl.sys [2005-01-11 92672]
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-22 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 cdrbsdrv;cdrbsdrv; C:\WINDOWS\system32\drivers\cdrbsdrv.sys [2008-07-17 33408]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-09-11 55768]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1997-12-23 23936]
R2 cpuz134;cpuz134; \??\C:\WINDOWS\system32\drivers\cpuz134_x32.sys []
R2 cpuz135;cpuz135; \??\C:\WINDOWS\system32\drivers\cpuz135_x32.sys []
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-06-20 2324480]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2005-05-31 1341466]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-10-22 9623680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2008-08-01 54784]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-09-07 100712]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2008-08-01 22016]
R3 Pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\Pcouffin.sys [2007-12-13 47360]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S0 TfFsMon;TfFsMon; C:\WINDOWS\system32\drivers\TfFsMon.sys []
S0 TfSysMon;TfSysMon; C:\WINDOWS\system32\drivers\TfSysMon.sys []
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S2 BTSERIAL;Bluetooth Serial Driver; \??\C:\WINDOWS\system32\drivers\btserial.sys []
S2 BTSLBCSP;Bluetooth Port Client Driver; \??\C:\WINDOWS\system32\drivers\btslbcsp.sys []
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys []
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-04 1273344]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2005-05-31 401152]
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2005-05-31 30363]
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2005-05-31 148040]
S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys []
S3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2005-05-31 30189]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2005-05-31 56648]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Peter\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 n558;N558 Bluetooth USB Filter Driver; C:\WINDOWS\System32\Drivers\n558.sys [2007-08-15 9600]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 OlyCamComm;OLYMPUS USB Communication Device; C:\WINDOWS\system32\DRIVERS\OlyCamComm.sys [2009-09-10 21648]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 s125bus;Sony Ericsson Device 125 driver (WDM); C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-05-01 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-05-01 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-05-01 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-05-01 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-05-01 18704]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-05-01 90800]
S3 speccy;speccy; \??\C:\DOCUME~1\Peter\LOCALS~1\Temp\0222f37d-ca69-44c2-a890-7f63dd31c53d []
S3 SRS_SSCFilter;SRS Labs Audio Sandbox (WDM); C:\WINDOWS\system32\drivers\srs_sscfilter_i386.sys [2007-07-26 39808]
S3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]
S4 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 btwdins;Bluetooth Service; C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe [2005-05-31 258103]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-10-16 156776]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-04 380928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-15 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-09-11 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-01-30 107832]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-09-29 616448]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-08-05 516096]
S4 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe []
S4 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -k runservice []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe []
S4 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe []
S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]

Re: Win32/Yimfoca.AA

Napsal: 15 led 2011 16:57
od motji
Hezké odpoledne :)

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Win32/Yimfoca.AA

Napsal: 15 led 2011 17:12
od casualties
ComboFix 11-01-10.04 - Peter 15.01.2011 17:04:24.18.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.1023.501 [GMT 1:00]
Running from: c:\documents and settings\Peter\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall Pro *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: NVIDIA Firewall *Enabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ICQ6.5\ICQLRun.exe
c:\windows\d.ini
c:\windows\system32\muzapp.exe

.
((((((((((((((((((((((((( Files Created from 2010-12-15 to 2011-01-15 )))))))))))))))))))))))))))))))
.

2011-01-15 14:27 . 2011-01-15 14:27 -------- d-----w- c:\program files\trend micro
2011-01-15 14:27 . 2011-01-15 14:27 -------- d-----w- C:\rsit
2011-01-10 16:29 . 2009-07-28 10:13 303104 ----a-w- c:\windows\Uninstall_tkexe.exe
2011-01-07 22:21 . 2011-01-07 22:21 -------- d-----w- c:\documents and settings\Peter\Bluetooth Software
2011-01-07 16:09 . 2011-01-07 16:09 -------- d-----w- c:\documents and settings\Peter\Application Data\Ahead
2011-01-07 14:19 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-01-07 14:19 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-01-05 13:29 . 2011-01-05 13:30 -------- d-----w- c:\program files\AutoPlan
2011-01-02 00:41 . 2011-01-02 00:41 -------- d-----w- c:\program files\Ask.com
2010-12-30 16:20 . 2010-09-07 20:09 26216 ----a-w- c:\windows\system32\nvhdap32.dll
2010-12-30 16:20 . 2010-09-07 20:08 100712 ----a-w- c:\windows\system32\drivers\nvhda32.sys
2010-12-30 16:20 . 2010-10-22 06:23 888424 ----a-w- c:\windows\system32\nvdispco32.dll
2010-12-30 16:20 . 2010-09-07 20:08 813672 ----a-w- c:\windows\system32\nvgenco32.dll
2010-12-30 16:19 . 2010-12-30 16:19 -------- d-----w- C:\NVIDIA
2010-12-30 11:52 . 2010-11-09 13:35 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x32.sys
2010-12-29 21:47 . 2011-01-06 18:44 -------- d-----w- c:\documents and settings\Peter\Local Settings\Application Data\Conduit
2010-12-29 21:46 . 2011-01-06 17:18 -------- d-----w- c:\documents and settings\Peter\Application Data\uTorrent
2010-12-24 08:15 . 2010-12-24 08:15 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-12-20 18:34 . 2010-12-20 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-12-20 18:34 . 2011-01-02 01:27 241448 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-12-20 18:34 . 2011-01-02 01:27 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-12-20 18:34 . 2010-12-30 16:28 241448 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-12-20 18:34 . 2010-12-30 16:22 -------- d-----w- c:\program files\NVIDIA Corporation

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-14 18:50 . 2007-01-29 20:36 60416 ----a-w- c:\windows\ALCFDRTM.VER
2010-12-22 22:24 . 2006-10-25 18:09 131072 ----a-w- C:\clicapi.dll
2010-11-18 23:29 . 2007-08-11 11:29 737280 ----a-w- c:\windows\iun6002.exe
2010-11-18 18:12 . 2007-01-27 15:05 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-11 17:58 . 2010-11-11 17:58 60416 ------w- c:\windows\ALCFDRTM.EXE
2010-11-11 17:55 . 2010-11-11 17:55 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-11-09 14:52 . 2004-08-04 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-22 06:23 . 2010-07-10 04:38 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-10-22 06:23 . 2010-07-10 04:38 14532608 ----a-w- c:\windows\system32\nvoglnt.dll
2010-10-22 06:23 . 2010-07-10 04:38 4882432 ----a-w- c:\windows\system32\nvcuda.dll
2010-10-22 06:23 . 2010-07-10 04:38 2932840 ----a-w- c:\windows\system32\nvcuvid.dll
2010-10-22 06:23 . 2010-07-10 04:38 2666600 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-10-22 06:23 . 2010-07-10 04:38 1462272 ----a-w- c:\windows\system32\nvapi.dll
2010-10-22 06:23 . 2010-07-10 04:38 13012992 ----a-w- c:\windows\system32\nvcompiler.dll
2010-10-22 06:23 . 2007-11-07 10:49 9623680 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-10-22 06:23 . 2007-11-07 10:49 6359552 ----a-w- c:\windows\system32\nv4_disp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-09-11 2054360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
backup=c:\windows\pss\ATI CATALYST System Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2005-08-06 00:07 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 14:05 132392 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 110592 ----a-w- c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 14:06 1840424 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MultiScreen]
2008-06-30 09:41 114688 ----a-w- c:\program files\MultiScreen\MultiScreen.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 07:31 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-06-19 07:53 570664 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2010-08-25 23:12 1753192 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
2006-05-16 16:51 57344 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
2007-12-14 15:19 132624 ------w- c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-06-20 20:42 77824 ----a-w- c:\windows\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"lanmanworkstation"=2 (0x2)
"W32Time"=2 (0x2)
"upnphost"=3 (0x3)
"LmHosts"=2 (0x2)
"lanmanserver"=2 (0x2)
"seclogon"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"CiSvc"=3 (0x3)
"PolicyAgent"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"TrkWks"=2 (0x2)
"Browser"=2 (0x2)
"ClipSrv"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8.7.2008 13:29 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [11.9.2009 7:23 108792]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [24.11.2010 21:49 20328]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [30.12.2010 12:52 21992]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [11.9.2009 7:24 735960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [30.12.2010 17:20 100712]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15.12.2010 14:50 136176]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [23.9.2010 10:13 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [23.9.2010 10:13 8320]
S3 OlyCamComm;OLYMPUS USB Communication Device;c:\windows\system32\drivers\OlyCamComm.sys [31.7.2010 11:31 21648]
S3 speccy;speccy;\??\c:\docume~1\Peter\LOCALS~1\Temp\0222f37d-ca69-44c2-a890-7f63dd31c53d --> c:\docume~1\Peter\LOCALS~1\Temp\0222f37d-ca69-44c2-a890-7f63dd31c53d [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4.8.2004 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder

2011-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-15 13:50]

2011-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-15 13:50]

2011-01-15 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 21:44]

2011-01-15 c:\windows\Tasks\User_Feed_Synchronization-{5424BEA9-A10A-4D48-AC65-CB94681185C6}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2786678
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-DriverScanner - c:\program files\Uniblue\DriverScanner\launcher.exe
MSConfigStartUp-Google Update - c:\documents and settings\Peter\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-PCSpeedUp - c:\program files\Zrychleni Pocitace\PCSpeedUp.exe
AddRemove-Handy Recovery 4.0 - c:\progra~1\SOFTLO~1\HANDYR~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-15 17:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\speccy]
"ImagePath"="\??\c:\docume~1\Peter\LOCALS~1\Temp\0222f37d-ca69-44c2-a890-7f63dd31c53d"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2000478354-1364589140-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-2000478354-1364589140-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:f2,31,62,31,1f,93,b7,e2,41,46,ea,aa,4b,cb,1f,b8,98,8d,fb,2e,c6,
8d,17,92,8a,2a,ae,8d,2a,b8,8e,ef,90,81,45,ce,55,18,25,0e,95,37,5c,90,81,f7,\
"rkeysecu"=hex:d9,e0,75,ab,5d,b5,0e,d4,42,22,b6,51,ac,89,d4,3e

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="17DB12C71B85235D2D6147ED8FD1A4E144F0D209CA23A39B3F184B886CDE1E8E21A6DB2B6BF438547DB8921A579F98968B1ABF4A2C61CCD8BB77E031B1E83C9A635EA4C6F0AF353FF88CF461B7F5FDCB5B9116D2258F7EF42E3FD86055F474F946E954058BB2BD501FF8B50A771BA7A36BC8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74C9DB7CE019D40AA5C9DB7CE019D40AA5C4CC5F754BC4E3E29FEA336704F9B858FCD214B3B508BB02DD790A237DFB199C3ECC77A7FA81FEB31DCADA6832D622E4CD19FE189B4D0DF9B44ABAF0A40259E4DF40E505B8D6C66117E0A44A3B241D6B1F30D5CA741D813098B23DC5EFE5FA74061B9315CA823855DC4B9AE8C4E14902893E5E2B5B28D35563010FCD74AF41691F6A2BACD3923C6405270EA4DEE26902ED75806AACB4855F578404870556D7548BB52EB4F82C34AF60F93E34A8ABCB1D5294BB6CC4F5826EF6E365AF757C56F837B0729D1CCCCD5D22A4066BB980BF047B356CBBA0A01005F6126310F89ECD47045B3BB9EE27B533810C5232D17BCF03AE9470064C7F8DAF161F931AA2CC819D56C7FD0CE1580CC22F728B0FD056FF67E001DF00E5B6C576DC4CF229580AFD48A884476513680F41CD79E07E2E8B46DF5EF0CA15219783927A7F8ADECCD6D42F97310A3691F1621486C9305E1CA136297757DF71CDA31658BE6F9E5A35EC2C227CC272F2D2ACCC85C3627EAD7B60508EB148E3F2D809E6898A40E3C7D81E359A3F87ED48838268A20F92EDEF4BDF7B2148E8EA41A693AF063472208950AF8AF1A1D4037B82D97A6F2BEAEE93D744D5E3F6F83BBCBFAF25091795606DACD9C8FC4A64CD8D1EE88004450E47A86735C273504A4FAFD202D005FA882D40CA6E0E9F4C1B4A3BAEA59A21AC04060FE57EE50CF5C5E3B42C63F191C06AE77C175C8530EE4BF622D8F573A0EE26452A441413E7E4F51BBFEDE73DAAA891856659BCB010AC4E8463951C9174DCE2868CBD5087CC1F353A06ADE8928826DB0BBB27F5752735DDDE3BF28E8AE18E018A11DBC673832A86B6E12423508AE2E1FD73D0D4A456BEE80B3F80E6299C5B8F2DC1224FA43F70ED68E57831CA54E0FBB3D6A32F87DA67A68116F83D615BDBB2CE2FDBA4F13520A85D16E27DA4F1616946474E0AA436C49DFBD020DDA027D916CDA8137E6C192C59C6960B07EF7CA8DE929688F1D031964655D62B177E517260ED19550380EA0ADF5EA0AAA8C38C98333C8A7BA7F4D9E1D2C79997CAAE72FA9213B86442C5AF4739AD29CA2794882C999E7E9DFF554FE05987C007EE4D5FE10696B72D222AA9F8B4EFD1C2BB188F5F6780FB6819870D37347B846CA8AA15512DC1BCF41EBA9C1AF04AFE058147C3DE4E3276D2772"
"OODEFRAG08.00.00.01WORKSTATION"="7B25A8EF5C5A36912B3AA0E5532E62A5F731987EC5E89ECC10562E57777B5CD5A1C02B5E42E67E8A7C7527E7DF56638A8212F850036148FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74C9DB7CE019D40AA5C9DB7CE019D40AA5CB943DEF6045B1732FED8F3AD8FE0D0BD4E3880CD858FF0CB06661E9C57390B7FA60E38FA019846C72CF93C50B36C1EB07C4B5954FD55211ADB8E4BA2161C49ADFD1C3E20A8AF63AD194AB5AC3D810812186914A926AF1B74511820CE077968CA4E622DCE618BC8F6AB323F48BD95D7A28291CF90D9B53A67DC389D416BAD7452C9EB87A375ECD2AB703479DD27EC5D14BDDAF0FED2D05F739D37874DE8E57F314755116E13E9E3C595614CD9D2A0EA11F1EA1E1FB140ED0F53F365F908A81D4B3ED254B3CD6AE1346C6160DD7A9FD6356CFE43D0FB184D21E1DE848238CCE5F4CF2A1EAD9A2AB5DAEDEF253FBDABFA0F9B670DA41ABDE88954FC7358487D76783A357EC6D3BCCC90B45CCC09A0D9B8A39409F1E3D7ECB09656E7081D6E3BEF94E6E14CA0B984991F7E894CF70A146F6C0FDAA68665B3180FB94DD8A8C5D977FADD341F906CBA12C6AF6F5EFB451988D16569A63C57F4172BF16DC387490134514CC0D41DF3EB2FBACD1801BC02F8EB3719D6336726672919191FE7785CACD3B106328E04397A6E2105237792D31B8BEE4E554C1FAE16CE786B4A296E432B86AA00C7B1368C19D19623C4C50BB1385742CB2DBA2CB0DF0A5EC96CB092A6A1813FD3D267579FD2DEA71B4438E8F6DEC6EBFD3C0A8ED1F6E3D3BA96693F16087C6240B89C400882205A06FB5B2064EFD51C74F089799863E657E46F8304812AB501267582FCC0D822A29B5B02DB9BA1807763D04BD0F27EA358952EF424BE276B770C968DCE285CF5ED3CE6437725FD4B16A2F326323077AC3CBF2374980773E4181CBEF72A01E4B3996BB3F7066BE23D832F86B6EA85D11B5D752C7D0BF755E92A24243E38709E7179CEEE3FCC3F02603F2749DBFB8AE38A86F1BFD15D92E9466615112254828AD0D4B25679C5D261C23FCE0FB71EBCD719F910E875A03C214B7B85E2A70FA47EEF6605BECE1E3D59F6698F42323BFBACEA6D52422F9DBFBE4D8AB08C19AC29A177DCD78E28B67B19941CF25D76F08B37A9885D7F8C4F48D8252AF1940427C7720F5B64C1B426EB22B6242BEF7392161A7DE8F9E35CE568DDAF654D95382A19C0647904E666B4524A7A480A21DBA6A654991F944A3444968B4D38673CCB161D312AC1B52072E0553A833F892828E72EB2AF313E1E6B822A7663960A4D1700B43D16341DA7545B81F17736C4CF92C40057F6972CE21EEB628559E4A49C38AFA73160C20046480BC44182CBF9799ADED5B92C4037"
"OODEFRAG11.00.00.01WORKSTATION"="ECA0B56A1CC63E9A0E60D2B7B9289982FAFB6E59B0082374DE0131EDE7719240D4FDCCC245B0E5C1E58E5E359B2C5F47CEF2A11B58C46608A53F6B458AC52E2B4111800EB4EA2BDC745C3076786F5E769EC7CA560135ECB484915E984FF2897DFE11478BCBF62B37763D113D2BFC18ACB144A9EE228E3B096DBC5C0C6BF3CED7CDDC293F1CBAD5A199445F0FC443E00D43568F09EA67AA18C927CF05CBAAFDDEE4F346F2ED7E6E72FDAC0DB38993623B81FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E6675D575E7D6A3B9808FEBC9E127BECC74CA2C352430A5DCCDD0FFA6E1759B857EE993AD0C0C4B89B375C0708D3CBB7038841FA23F50063CFB1112F0EC75D420B4809E77E94268FF2C60996F8DADDDD077BCB29571CC1961D3E32AAE886E2BB06869C3629E4470647BED9B070E79AC960761BE44E356F329DDD0358E34F964606103F824F4BFC43C93132492F519FC64EDC2CD72EF311C6C45E3BB522540655CB408041BA957CBF2BA799683F22EC731682A0BCDE410E378601B4D50D7822B29EE4917AF244E1CAA29DBBA9E818E7427E303DE78AB7B3BBDA7D6CDCD1D4C3FBC6434AC7C68D2D04EB8269BEBDA556795224E93DA32635603F7B848762B6A3A01311A5DA49DAC1E2C33A95EA0FF2E6B4E20EB3B5DC11A605B49CC324729C61E6D47843F4504A66B0ED1ED88674D8A9628294CCDE2F3081DBBEEE92127C3EFD65E01A64EDF42C478BB179EE7EC9E512C5894E885AD6EEA3EDE5FA7FCABC01E00B9109F13196077365D90D38512EDDF975D34A61DD53ECCD9739B9BC573503D39744CA74BE56145D83338A371683B61D5B400973B168FB2708C519A0552B94069E5B5B1DA79B405EFE119C94F2F21A1A38337F7EB21FA63643237CA3F726B90A8B3CAABD160F2F30C6CADE9D2565E7789C93176954C3266AA0E7B8658574AB541ACF194D432033731C3B5FBF7C0CB11F70CDAB3C99E5EA154BB297A5D728D641D9838065FE0158A915BF2411DD583E5A6DD010241D5A186A44A258CCDD935B0FB04A2AC7AC275B3C9A3CA548408287DA249008F08A380585DEDC2C6398D38EDE5799565543CC2EF56C964D40B186BDB4F5844C19255C3EE1430A39961FC1F7B8DAE9B6954FEFF5871A3A7D7B51A1C1609B290A34416782E2EC5798B91C8254861B3A7333ED538B818A94099C53D7AB3A1C7D630048BCC4CBAA745A42CDF815154E8B26FD547CFCDCF79939EA7F70C404D905ECDC3705AD48A11700C906CDDD197B63DF6749B58C746EBF4953B4760BDF0748AF50A0AB9864C876FD8EAAEF87A7804C2286A78DAE89D10168E4DFB832572851278228619512ECD0BF7236109EBB0ED264175ED58DBC56DCBBD388CA21571BB1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-01-15 17:11:29
ComboFix-quarantined-files.txt 2011-01-15 16:11

Pre-Run: 34 214 166 528 bytes free
Post-Run: 34 311 487 488 bytes free

- - End Of File - - 42B7591D7A31787FA4159235F69A9A35

Re: Win32/Yimfoca.AA

Napsal: 15 led 2011 17:25
od motji
Máte tu nějak moc antivirů a firewallů, co z toho používáte?
AV: ESET Smart Security 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall Pro *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: NVIDIA Firewall *Enabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}

Re: Win32/Yimfoca.AA

Napsal: 15 led 2011 17:31
od casualties
zasa tam je ten COMODO? veď som ho dával preč a v počítači som ho nenašiel...používam asi len ESS

edit: NVIDIA Firewall by mal byť už odstránený, ale tie ostatné neviem ako odstrániť

Re: Win32/Yimfoca.AA

Napsal: 15 led 2011 20:41
od motji
:arrow: Tento program používáte?
speccy

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 00:57
od casualties
o takomto programe neviem

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 01:26
od motji
:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Regnull::
[HKEY_USERS\S-1-5-21-2000478354-1364589140-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

Driver::
speccy

File::
c:\docume~1\Peter\LOCALS~1\Temp\0222f37d-ca69-44c2-a890-7f63dd31c53d
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
c:\windows\Uninstall_tkexe.exe

DDS::
uStart Page = hxxp://search.conduit.com?SearchSource= ... =CT2786678

Firefox::
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2786678&q=
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com

Folder::
c:\program files\Ask.com

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

SecCenter::
{EDC10449-64D1-46c7-A59A-EC20D662F26D}
{043803A3-4F86-4ef6-AFC5-F6E02A79969B}
-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 01:51
od casualties
ComboFix 11-01-14.01 - Peter 16.01.2011 1:37.19.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.1023.569 [GMT 1:00]
Running from: c:\documents and settings\Peter\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Peter\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\docume~1\Peter\LOCALS~1\Temp\0222f37d-ca69-44c2-a890-7f63dd31c53d"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
"c:\windows\Uninstall_tkexe.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.xpt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.idl
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitToolbar.xpt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.dll
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.xpt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\alertSettingsComponent.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\appContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\engineContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\engineSettings.json
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\fbAlert.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\getAppsContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\postAppsContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\toolbarContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\unsharedAppsContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome.manifest
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome\utorrentbar.jar
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\install.rdf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\lib\xpcom.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\manifest.mf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.rsa
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.sf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.gif
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.ico
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.PNG
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.src
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\setup.ini
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\version.txt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\ConduitToolbar.idl
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\ConduitToolbar.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\ConduitToolbar.xpt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\RadioWMPCore.dll
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\RadioWMPCore.xpt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\alertSettingsComponent.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\appContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\engineContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\engineSettings.json
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\fbAlert.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\getAppsContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\postAppsContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\toolbarContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\DualPackage\install.rdf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\chrome.manifest
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\chrome\conduitengine.jar
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\install.rdf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\lib\xpcom.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\META-INF\manifest.mf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\META-INF\zigbert.rsa
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\META-INF\zigbert.sf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\searchplugin\conduit.gif
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\searchplugin\conduit.ico
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\searchplugin\conduit.PNG
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\searchplugin\conduit.src
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\searchplugin\conduit.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\setup.ini
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\engine@conduit.com\version.txt
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\datastore\cache.sqlite
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\defaults.js.bak
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\defaults\preferences\defaults.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome.manifest
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\about.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\about.xul
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\cache.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\constants.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\core.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\custom-command-listener.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\events.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\feeds.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\json.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\lifecycle.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\listeners.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\locale.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\logger.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\network.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\observer.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\options.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\options.xul
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\preferences.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\prefetch.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\ss-popup-bindings.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\suggestions.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\update.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\utilities.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\webframe-bindings.xml
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\webframe-manager.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\widget-controller.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\widget-popup.xul
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\content\widgets.js
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\ask_16x16.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\ask_32x32.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\ask_browser_ff_chrome.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\asklogo.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\bg.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\blogs.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\dictionary.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\globe_18x.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\gripper.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\highlighter_off.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\highlighter_on.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\chevron.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\images.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-de.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-en.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-es.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-fr.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-it.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-nl.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-pt.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\labels-ru.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-BR.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-DE.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-ES.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-EU.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-FR.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-IT.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-NL.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-RU.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-UK.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\links-US.properties
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\logo_32x32.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\magnify_search.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\maps.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\news.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\preferences.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_de.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_es.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_fr.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_it.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_nl.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_pl.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_pt.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ask_ru.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_cobrand.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_current_site.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_de.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_es.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_fr.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_grey_73x24.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_it.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_nl.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_pl.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_pt.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\search_ru.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\shopping.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\stocks.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\toolbar.css
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\toolbar.xul
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\weather.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\web.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\chrome\skin\zoomall.png
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\install.rdf
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295101179094.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295103555995.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295106115813.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295107942429.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295111352073.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295112113438.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295113116487.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295116272025.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295117889681.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295119399031.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295120292230.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295120492438.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295121267758.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295121586549.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295122929221.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295123171466.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295123600290.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295125575679.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295133483547.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295135704889.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295136230719.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295136509476.html
c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\extensions\toolbar@ask.com\logs\asktb-log-1295136963540.html
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_3a48.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
c:\windows\Uninstall_tkexe.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SPECCY
-------\Service_speccy


((((((((((((((((((((((((( Files Created from 2010-12-16 to 2011-01-16 )))))))))))))))))))))))))))))))
.

2011-01-15 14:27 . 2011-01-15 14:27 -------- d-----w- c:\program files\trend micro
2011-01-15 14:27 . 2011-01-15 14:27 -------- d-----w- C:\rsit
2011-01-07 22:21 . 2011-01-07 22:21 -------- d-----w- c:\documents and settings\Peter\Bluetooth Software
2011-01-07 16:09 . 2011-01-07 16:09 -------- d-----w- c:\documents and settings\Peter\Application Data\Ahead
2011-01-07 14:19 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-01-07 14:19 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-01-05 13:29 . 2011-01-05 13:30 -------- d-----w- c:\program files\AutoPlan
2010-12-30 16:20 . 2010-09-07 20:09 26216 ----a-w- c:\windows\system32\nvhdap32.dll
2010-12-30 16:20 . 2010-09-07 20:08 100712 ----a-w- c:\windows\system32\drivers\nvhda32.sys
2010-12-30 16:20 . 2010-10-22 06:23 888424 ----a-w- c:\windows\system32\nvdispco32.dll
2010-12-30 16:20 . 2010-09-07 20:08 813672 ----a-w- c:\windows\system32\nvgenco32.dll
2010-12-30 16:19 . 2010-12-30 16:19 -------- d-----w- C:\NVIDIA
2010-12-29 21:47 . 2011-01-06 18:44 -------- d-----w- c:\documents and settings\Peter\Local Settings\Application Data\Conduit
2010-12-29 21:46 . 2011-01-06 17:18 -------- d-----w- c:\documents and settings\Peter\Application Data\uTorrent
2010-12-24 08:15 . 2010-12-24 08:15 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-12-20 18:34 . 2010-12-20 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-12-20 18:34 . 2011-01-02 01:27 241448 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-12-20 18:34 . 2011-01-02 01:27 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-12-20 18:34 . 2010-12-30 16:28 241448 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-12-20 18:34 . 2010-12-30 16:22 -------- d-----w- c:\program files\NVIDIA Corporation

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-14 18:50 . 2007-01-29 20:36 60416 ----a-w- c:\windows\ALCFDRTM.VER
2010-12-22 22:24 . 2006-10-25 18:09 131072 ----a-w- C:\clicapi.dll
2010-11-18 23:29 . 2007-08-11 11:29 737280 ----a-w- c:\windows\iun6002.exe
2010-11-18 18:12 . 2007-01-27 15:05 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-11 17:58 . 2010-11-11 17:58 60416 ------w- c:\windows\ALCFDRTM.EXE
2010-11-11 17:55 . 2010-11-11 17:55 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-11-09 14:52 . 2004-08-04 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-22 06:23 . 2010-07-10 04:38 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-10-22 06:23 . 2010-07-10 04:38 14532608 ----a-w- c:\windows\system32\nvoglnt.dll
2010-10-22 06:23 . 2010-07-10 04:38 4882432 ----a-w- c:\windows\system32\nvcuda.dll
2010-10-22 06:23 . 2010-07-10 04:38 2932840 ----a-w- c:\windows\system32\nvcuvid.dll
2010-10-22 06:23 . 2010-07-10 04:38 2666600 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-10-22 06:23 . 2010-07-10 04:38 1462272 ----a-w- c:\windows\system32\nvapi.dll
2010-10-22 06:23 . 2010-07-10 04:38 13012992 ----a-w- c:\windows\system32\nvcompiler.dll
2010-10-22 06:23 . 2007-11-07 10:49 9623680 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-10-22 06:23 . 2007-11-07 10:49 6359552 ----a-w- c:\windows\system32\nv4_disp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-09-11 2054360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
backup=c:\windows\pss\ATI CATALYST System Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2005-08-06 00:07 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 14:05 132392 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 110592 ----a-w- c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 14:06 1840424 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MultiScreen]
2008-06-30 09:41 114688 ----a-w- c:\program files\MultiScreen\MultiScreen.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 07:31 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-06-19 07:53 570664 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2010-08-25 23:12 1753192 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
2006-05-16 16:51 57344 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
2007-12-14 15:19 132624 ------w- c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-06-20 20:42 77824 ----a-w- c:\windows\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"lanmanworkstation"=2 (0x2)
"W32Time"=2 (0x2)
"upnphost"=3 (0x3)
"LmHosts"=2 (0x2)
"lanmanserver"=2 (0x2)
"seclogon"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"CiSvc"=3 (0x3)
"PolicyAgent"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"TrkWks"=2 (0x2)
"Browser"=2 (0x2)
"ClipSrv"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8.7.2008 13:29 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [11.9.2009 7:23 108792]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [11.9.2009 7:24 735960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [30.12.2010 17:20 100712]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15.12.2010 14:50 136176]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [23.9.2010 10:13 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [23.9.2010 10:13 8320]
S3 OlyCamComm;OLYMPUS USB Communication Device;c:\windows\system32\drivers\OlyCamComm.sys [31.7.2010 11:31 21648]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4.8.2004 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder

2011-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-15 13:50]

2011-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-15 13:50]

2011-01-15 c:\windows\Tasks\User_Feed_Synchronization-{5424BEA9-A10A-4D48-AC65-CB94681185C6}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\bgvefcv4.Mozilla\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-16 01:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2000478354-1364589140-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-2000478354-1364589140-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:f2,31,62,31,1f,93,b7,e2,41,46,ea,aa,4b,cb,1f,b8,98,8d,fb,2e,c6,
8d,17,92,8a,2a,ae,8d,2a,b8,8e,ef,90,81,45,ce,55,18,25,0e,95,37,5c,90,81,f7,\
"rkeysecu"=hex:d9,e0,75,ab,5d,b5,0e,d4,42,22,b6,51,ac,89,d4,3e

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="17DB12C71B85235D2D6147ED8FD1A4E144F0D209CA23A39B3F184B886CDE1E8E21A6DB2B6BF438547DB8921A579F98968B1ABF4A2C61CCD8BB77E031B1E83C9A635EA4C6F0AF353FF88CF461B7F5FDCB5B9116D2258F7EF42E3FD86055F474F946E954058BB2BD501FF8B50A771BA7A36BC8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74C9DB7CE019D40AA5C9DB7CE019D40AA5C4CC5F754BC4E3E29FEA336704F9B858FCD214B3B508BB02DD790A237DFB199C3ECC77A7FA81FEB31DCADA6832D622E4CD19FE189B4D0DF9B44ABAF0A40259E4DF40E505B8D6C66117E0A44A3B241D6B1F30D5CA741D813098B23DC5EFE5FA74061B9315CA823855DC4B9AE8C4E14902893E5E2B5B28D35563010FCD74AF41691F6A2BACD3923C6405270EA4DEE26902ED75806AACB4855F578404870556D7548BB52EB4F82C34AF60F93E34A8ABCB1D5294BB6CC4F5826EF6E365AF757C56F837B0729D1CCCCD5D22A4066BB980BF047B356CBBA0A01005F6126310F89ECD47045B3BB9EE27B533810C5232D17BCF03AE9470064C7F8DAF161F931AA2CC819D56C7FD0CE1580CC22F728B0FD056FF67E001DF00E5B6C576DC4CF229580AFD48A884476513680F41CD79E07E2E8B46DF5EF0CA15219783927A7F8ADECCD6D42F97310A3691F1621486C9305E1CA136297757DF71CDA31658BE6F9E5A35EC2C227CC272F2D2ACCC85C3627EAD7B60508EB148E3F2D809E6898A40E3C7D81E359A3F87ED48838268A20F92EDEF4BDF7B2148E8EA41A693AF063472208950AF8AF1A1D4037B82D97A6F2BEAEE93D744D5E3F6F83BBCBFAF25091795606DACD9C8FC4A64CD8D1EE88004450E47A86735C273504A4FAFD202D005FA882D40CA6E0E9F4C1B4A3BAEA59A21AC04060FE57EE50CF5C5E3B42C63F191C06AE77C175C8530EE4BF622D8F573A0EE26452A441413E7E4F51BBFEDE73DAAA891856659BCB010AC4E8463951C9174DCE2868CBD5087CC1F353A06ADE8928826DB0BBB27F5752735DDDE3BF28E8AE18E018A11DBC673832A86B6E12423508AE2E1FD73D0D4A456BEE80B3F80E6299C5B8F2DC1224FA43F70ED68E57831CA54E0FBB3D6A32F87DA67A68116F83D615BDBB2CE2FDBA4F13520A85D16E27DA4F1616946474E0AA436C49DFBD020DDA027D916CDA8137E6C192C59C6960B07EF7CA8DE929688F1D031964655D62B177E517260ED19550380EA0ADF5EA0AAA8C38C98333C8A7BA7F4D9E1D2C79997CAAE72FA9213B86442C5AF4739AD29CA2794882C999E7E9DFF554FE05987C007EE4D5FE10696B72D222AA9F8B4EFD1C2BB188F5F6780FB6819870D37347B846CA8AA15512DC1BCF41EBA9C1AF04AFE058147C3DE4E3276D2772"
"OODEFRAG08.00.00.01WORKSTATION"="7B25A8EF5C5A36912B3AA0E5532E62A5F731987EC5E89ECC10562E57777B5CD5A1C02B5E42E67E8A7C7527E7DF56638A8212F850036148FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74C9DB7CE019D40AA5C9DB7CE019D40AA5CB943DEF6045B1732FED8F3AD8FE0D0BD4E3880CD858FF0CB06661E9C57390B7FA60E38FA019846C72CF93C50B36C1EB07C4B5954FD55211ADB8E4BA2161C49ADFD1C3E20A8AF63AD194AB5AC3D810812186914A926AF1B74511820CE077968CA4E622DCE618BC8F6AB323F48BD95D7A28291CF90D9B53A67DC389D416BAD7452C9EB87A375ECD2AB703479DD27EC5D14BDDAF0FED2D05F739D37874DE8E57F314755116E13E9E3C595614CD9D2A0EA11F1EA1E1FB140ED0F53F365F908A81D4B3ED254B3CD6AE1346C6160DD7A9FD6356CFE43D0FB184D21E1DE848238CCE5F4CF2A1EAD9A2AB5DAEDEF253FBDABFA0F9B670DA41ABDE88954FC7358487D76783A357EC6D3BCCC90B45CCC09A0D9B8A39409F1E3D7ECB09656E7081D6E3BEF94E6E14CA0B984991F7E894CF70A146F6C0FDAA68665B3180FB94DD8A8C5D977FADD341F906CBA12C6AF6F5EFB451988D16569A63C57F4172BF16DC387490134514CC0D41DF3EB2FBACD1801BC02F8EB3719D6336726672919191FE7785CACD3B106328E04397A6E2105237792D31B8BEE4E554C1FAE16CE786B4A296E432B86AA00C7B1368C19D19623C4C50BB1385742CB2DBA2CB0DF0A5EC96CB092A6A1813FD3D267579FD2DEA71B4438E8F6DEC6EBFD3C0A8ED1F6E3D3BA96693F16087C6240B89C400882205A06FB5B2064EFD51C74F089799863E657E46F8304812AB501267582FCC0D822A29B5B02DB9BA1807763D04BD0F27EA358952EF424BE276B770C968DCE285CF5ED3CE6437725FD4B16A2F326323077AC3CBF2374980773E4181CBEF72A01E4B3996BB3F7066BE23D832F86B6EA85D11B5D752C7D0BF755E92A24243E38709E7179CEEE3FCC3F02603F2749DBFB8AE38A86F1BFD15D92E9466615112254828AD0D4B25679C5D261C23FCE0FB71EBCD719F910E875A03C214B7B85E2A70FA47EEF6605BECE1E3D59F6698F42323BFBACEA6D52422F9DBFBE4D8AB08C19AC29A177DCD78E28B67B19941CF25D76F08B37A9885D7F8C4F48D8252AF1940427C7720F5B64C1B426EB22B6242BEF7392161A7DE8F9E35CE568DDAF654D95382A19C0647904E666B4524A7A480A21DBA6A654991F944A3444968B4D38673CCB161D312AC1B52072E0553A833F892828E72EB2AF313E1E6B822A7663960A4D1700B43D16341DA7545B81F17736C4CF92C40057F6972CE21EEB628559E4A49C38AFA73160C20046480BC44182CBF9799ADED5B92C4037"
"OODEFRAG11.00.00.01WORKSTATION"="ECA0B56A1CC63E9A0E60D2B7B9289982FAFB6E59B0082374DE0131EDE7719240D4FDCCC245B0E5C1E58E5E359B2C5F47CEF2A11B58C46608A53F6B458AC52E2B4111800EB4EA2BDC745C3076786F5E769EC7CA560135ECB484915E984FF2897DFE11478BCBF62B37763D113D2BFC18ACB144A9EE228E3B096DBC5C0C6BF3CED7CDDC293F1CBAD5A199445F0FC443E00D43568F09EA67AA18C927CF05CBAAFDDEE4F346F2ED7E6E72FDAC0DB38993623B81FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E6675D575E7D6A3B9808FEBC9E127BECC74CA2C352430A5DCCDD0FFA6E1759B857EE993AD0C0C4B89B375C0708D3CBB7038841FA23F50063CFB1112F0EC75D420B4809E77E94268FF2C60996F8DADDDD077BCB29571CC1961D3E32AAE886E2BB06869C3629E4470647BED9B070E79AC960761BE44E356F329DDD0358E34F964606103F824F4BFC43C93132492F519FC64EDC2CD72EF311C6C45E3BB522540655CB408041BA957CBF2BA799683F22EC731682A0BCDE410E378601B4D50D7822B29EE4917AF244E1CAA29DBBA9E818E7427E303DE78AB7B3BBDA7D6CDCD1D4C3FBC6434AC7C68D2D04EB8269BEBDA556795224E93DA32635603F7B848762B6A3A01311A5DA49DAC1E2C33A95EA0FF2E6B4E20EB3B5DC11A605B49CC324729C61E6D47843F4504A66B0ED1ED88674D8A9628294CCDE2F3081DBBEEE92127C3EFD65E01A64EDF42C478BB179EE7EC9E512C5894E885AD6EEA3EDE5FA7FCABC01E00B9109F13196077365D90D38512EDDF975D34A61DD53ECCD9739B9BC573503D39744CA74BE56145D83338A371683B61D5B400973B168FB2708C519A0552B94069E5B5B1DA79B405EFE119C94F2F21A1A38337F7EB21FA63643237CA3F726B90A8B3CAABD160F2F30C6CADE9D2565E7789C93176954C3266AA0E7B8658574AB541ACF194D432033731C3B5FBF7C0CB11F70CDAB3C99E5EA154BB297A5D728D641D9838065FE0158A915BF2411DD583E5A6DD010241D5A186A44A258CCDD935B0FB04A2AC7AC275B3C9A3CA548408287DA249008F08A380585DEDC2C6398D38EDE5799565543CC2EF56C964D40B186BDB4F5844C19255C3EE1430A39961FC1F7B8DAE9B6954FEFF5871A3A7D7B51A1C1609B290A34416782E2EC5798B91C8254861B3A7333ED538B818A94099C53D7AB3A1C7D630048BCC4CBAA745A42CDF815154E8B26FD547CFCDCF79939EA7F70C404D905ECDC3705AD48A11700C906CDDD197B63DF6749B58C746EBF4953B4760BDF0748AF50A0AB9864C876FD8EAAEF87A7804C2286A78DAE89D10168E4DFB832572851278228619512ECD0BF7236109EBB0ED264175ED58DBC56DCBBD388CA21571BB1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(924)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2356)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\MSI\BToes Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
Completion time: 2011-01-16 01:50:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-16 00:50
ComboFix2.txt 2011-01-15 16:11

Pre-Run: 34 806 308 864 bytes free
Post-Run: 34 688 360 448 bytes free

- - End Of File - - 3076847651E98BE6F1A6031B05718ED9

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 02:06
od motji
Co počítač?

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 02:07
od casualties
V poriadku....čiže malo by byť už vetko OK ? Netreba ešte log z RSIT-u?

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 09:27
od motji
:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 17:38
od casualties
No myslím, že sa chová OK, akurát keď som dával OTC sa reštartoval (to je OK) a pri spustení bol na obrazovke dlhšie logo ESS, ale to je asi normálne... a tu je log:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Peter at 2011-01-16 17:36:09
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 32 GB (63%) free of 51 GB
Total RAM: 1023 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:36:32, on 16.1.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Peter\Desktop\RSIT.exe
C:\Program Files\trend micro\Peter.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.sk/OnlineScanner.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 3855522859
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://212.80.66.25/activex/AxisCamControl.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crl ... crlocx.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7034 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5424BEA9-A10A-4D48-AC65-CB94681185C6}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-22 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-09-11 2054360]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-10-16 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-10-16 13851752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-06 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2008-06-24 132392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MultiScreen]
C:\Program Files\MultiScreen\MultiScreen.exe [2008-06-30 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-08-26 1753192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe [2006-05-16 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-09-08 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe [2007-12-14 132624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-06-20 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
C:\PROGRA~1\ATITEC~1\ATI.ACE\CLI.exe [2005-08-06 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\MSI\BTOESB~1\BTTray.exe [2005-05-31 577597]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2005-05-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"lanmanworkstation"=2
"W32Time"=2
"upnphost"=3
"LmHosts"=2
"lanmanserver"=2
"seclogon"=2
"WmdmPmSN"=3
"CiSvc"=3
"PolicyAgent"=2
"FastUserSwitchingCompatibility"=3
"TrkWks"=2
"Browser"=2
"ClipSrv"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-04 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Disabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe:*:Enabled:Nero ControlCenter"
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Disabled:Google Earth"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-01-16 17:36:09 ----D---- C:\rsit
2011-01-16 02:33:48 ----SHD---- C:\RECYCLER
2011-01-15 15:27:15 ----D---- C:\Program Files\trend micro
2011-01-12 14:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-01-07 17:09:04 ----D---- C:\Documents and Settings\Peter\Application Data\Ahead
2011-01-07 15:19:00 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2011-01-07 15:19:00 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2011-01-07 15:18:59 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2011-01-07 15:18:58 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2011-01-07 15:18:57 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2011-01-07 15:18:57 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2011-01-07 15:18:55 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2011-01-07 15:18:55 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2011-01-07 15:18:54 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2011-01-07 15:18:53 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2011-01-07 15:18:52 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2011-01-07 15:18:51 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2011-01-07 15:18:49 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2011-01-07 15:18:49 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2011-01-07 15:18:49 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2011-01-07 15:18:48 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2011-01-07 15:18:47 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2011-01-07 15:18:47 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2011-01-07 15:18:46 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2011-01-05 14:29:28 ----D---- C:\Program Files\AutoPlan
2010-12-30 17:20:39 ----A---- C:\WINDOWS\system32\nvhdap32.dll
2010-12-30 17:20:39 ----A---- C:\WINDOWS\system32\drivers\nvhda32.sys
2010-12-30 17:20:38 ----A---- C:\WINDOWS\system32\nvgenco32.dll
2010-12-30 17:20:38 ----A---- C:\WINDOWS\system32\nvdispco32.dll
2010-12-30 17:19:56 ----D---- C:\NVIDIA
2010-12-29 22:46:19 ----D---- C:\Documents and Settings\Peter\Application Data\uTorrent
2010-12-28 02:19:00 ----A---- C:\WINDOWS\avisplitter.ini
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\x264vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\lagarith.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\huffyuv.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\DivXc32f.dll
2010-12-28 02:18:58 ----A---- C:\WINDOWS\system32\DivXc32.dll
2010-12-28 02:18:57 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-12-28 02:18:54 ----D---- C:\Program Files\K-Lite Codec Pack
2010-12-24 09:15:44 ----A---- C:\WINDOWS\system32\frapsvid.dll
2010-12-20 19:34:35 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2010-12-20 19:34:20 ----D---- C:\Program Files\NVIDIA Corporation

======List of files/folders modified in the last 1 months======

2011-01-16 17:36:17 ----D---- C:\WINDOWS\Prefetch
2011-01-16 17:36:11 ----D---- C:\WINDOWS\temp
2011-01-16 17:35:08 ----D---- C:\Program Files\Mozilla Firefox
2011-01-16 17:34:38 ----D---- C:\WINDOWS\system32\ias
2011-01-16 17:33:43 ----SHD---- C:\System Volume Information
2011-01-16 17:33:43 ----D---- C:\WINDOWS\system32\Restore
2011-01-16 17:33:41 ----D---- C:\WINDOWS
2011-01-16 17:32:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-16 17:31:31 ----D---- C:\Program Files\CCleaner
2011-01-16 17:30:45 ----D---- C:\WINDOWS\Debug
2011-01-16 17:30:45 ----D---- C:\Documents and Settings\Peter\Application Data\Winamp
2011-01-16 17:30:45 ----D---- C:\Documents and Settings\Peter\Application Data\Media Player Classic
2011-01-16 15:45:53 ----A---- C:\WINDOWS\wincmd.ini
2011-01-16 15:32:01 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-01-16 01:50:11 ----D---- C:\WINDOWS\system32\drivers
2011-01-16 01:48:38 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-16 01:44:54 ----A---- C:\WINDOWS\system.ini
2011-01-16 01:44:22 ----D---- C:\WINDOWS\system32\drivers\etc
2011-01-16 01:43:00 ----D---- C:\WINDOWS\system32\config
2011-01-16 01:42:18 ----D---- C:\Program Files
2011-01-16 01:42:17 ----SD---- C:\WINDOWS\Tasks
2011-01-16 01:40:30 ----D---- C:\WINDOWS\system32
2011-01-16 01:40:30 ----D---- C:\WINDOWS\AppPatch
2011-01-16 01:40:29 ----D---- C:\Program Files\Common Files
2011-01-16 01:03:07 ----D---- C:\Program Files\CPUID
2011-01-15 17:08:46 ----D---- C:\Program Files\ICQ6.5
2011-01-14 10:29:01 ----A---- C:\WINDOWS\NeroDigital.ini
2011-01-12 14:39:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-01-12 14:39:39 ----SHD---- C:\WINDOWS\Installer
2011-01-12 14:39:39 ----D---- C:\Config.Msi
2011-01-12 14:39:37 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-01-12 14:38:52 ----HD---- C:\WINDOWS\inf
2011-01-12 14:38:46 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-12 14:28:48 ----HD---- C:\WINDOWS\$hf_mig$
2011-01-08 18:42:56 ----A---- C:\WINDOWS\win.ini
2011-01-07 15:19:18 ----A---- C:\WINDOWS\system32\everest_cpl.ini
2011-01-07 15:19:00 ----D---- C:\WINDOWS\system32\DirectX
2011-01-06 19:40:01 ----D---- C:\Documents and Settings
2011-01-06 19:39:14 ----D---- C:\Program Files\The KMPlayer
2011-01-06 18:42:10 ----RSD---- C:\WINDOWS\assembly
2011-01-06 18:33:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-05 15:32:34 ----D---- C:\Program Files\Common Files\ACD Systems
2010-12-31 10:55:11 ----D---- C:\Program Files\Google
2010-12-31 10:46:34 ----RASH---- C:\boot.ini
2010-12-30 17:22:44 ----D---- C:\WINDOWS\Help
2010-12-30 17:20:46 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-12-28 02:38:12 ----D---- C:\Program Files\TV JOJ Media Player
2010-12-28 01:02:09 ----D---- C:\Documents and Settings\Peter\Application Data\GetRightToGo
2010-12-23 15:53:40 ----A---- C:\WINDOWS\RtlRack.ini
2010-12-22 23:43:09 ----D---- C:\Program Files\ESET
2010-12-22 23:24:30 ----A---- C:\clicapi.dll
2010-12-22 23:21:08 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
2010-12-22 23:20:53 ----D---- C:\Program Files\Nokia
2010-12-22 23:20:51 ----D---- C:\Program Files\Common Files\Nokia
2010-12-22 23:20:38 ----DC---- C:\WINDOWS\system32\DRVSTORE

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MMRTKRNL;MMRTKRNL; C:\WINDOWS\system32\drivers\mmrtkrnl.sys [2005-01-11 92672]
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-22 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 cdrbsdrv;cdrbsdrv; C:\WINDOWS\system32\drivers\cdrbsdrv.sys [2008-07-17 33408]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-09-11 55768]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1997-12-23 23936]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-06-20 2324480]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2005-05-31 1341466]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-10-22 9623680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2008-08-01 54784]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-09-07 100712]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2008-08-01 22016]
R3 Pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\Pcouffin.sys [2007-12-13 47360]
S0 TfFsMon;TfFsMon; C:\WINDOWS\system32\drivers\TfFsMon.sys []
S0 TfSysMon;TfSysMon; C:\WINDOWS\system32\drivers\TfSysMon.sys []
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S2 BTSERIAL;Bluetooth Serial Driver; \??\C:\WINDOWS\system32\drivers\btserial.sys []
S2 BTSLBCSP;Bluetooth Port Client Driver; \??\C:\WINDOWS\system32\drivers\btslbcsp.sys []
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys []
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-04 1273344]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2005-05-31 401152]
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2005-05-31 30363]
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2005-05-31 148040]
S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys []
S3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2005-05-31 30189]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2005-05-31 56648]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Peter\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 n558;N558 Bluetooth USB Filter Driver; C:\WINDOWS\System32\Drivers\n558.sys [2007-08-15 9600]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 OlyCamComm;OLYMPUS USB Communication Device; C:\WINDOWS\system32\DRIVERS\OlyCamComm.sys [2009-09-10 21648]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 s125bus;Sony Ericsson Device 125 driver (WDM); C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-05-01 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-05-01 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-05-01 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-05-01 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-05-01 18704]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-05-01 90800]
S3 SRS_SSCFilter;SRS Labs Audio Sandbox (WDM); C:\WINDOWS\system32\drivers\srs_sscfilter_i386.sys [2007-07-26 39808]
S3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]
S4 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 btwdins;Bluetooth Service; C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe [2005-05-31 258103]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-10-16 156776]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-04 380928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-15 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-09-11 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-01-30 107832]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-09-29 616448]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-08-05 516096]
S4 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe []
S4 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -k runservice []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe []
S4 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe []
S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]

-----------------EOF-----------------

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 17:39
od casualties
INFO:

info.txt logfile of random's system information tool 1.08 2011-01-16 17:36:35

======Uninstall list======

-->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ACDSee 5.0 - slovenské prostredie-->C:\WINDOWS\iun506.exe C:\Program Files\ACD Systems\irunin.ini
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10l_Plugin.exe -maintain plugin
Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
Aktualizácia Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {9A8C39B0-D27F-4F81-BE74-2FECF164707E}
Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {CE23B3DC-18CC-46FC-A309-81D6670F8D3D}
Aktualizácia Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {D6DBF512-87C0-4F6A-8FB9-AC3A389D9DE5}
Ask Toolbar-->MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE}
ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center-->MsiExec.exe /I{86EC42B5-346E-4BAB-948D-58E021EA4BD1}
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI HYDRAVISION-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe"
AUTOPLAN 2011 ŠTART verzia-->"C:\Program Files\AutoPlan\unins000.exe"
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
DivX Setup-->C:\Documents and Settings\All Users\Application Data\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
ESET Online Scanner-->C:\WINDOWS\system32\OnlineScannerUninstaller.exe
eShopper-->C:\WINDOWS\system32\eshopperuninstall.exe
EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Flatcast 4.16 RC1-->C:\WINDOWS\unins000.exe
Fraunhofer MP3 ACM CODEC v1.2 Professional-->RunDLL32.exe advpack.dll,LaunchINFSection L3CODECP.inf, UnInstall
Free CD Ripper 3.1-->"C:\Program Files\FreeCDRipper\unins000.exe"
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
GPS2GE-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{39BE506D-101F-4494-BB91-5836521F1AF8}
Hotfix for Windows XP (KB2158563)-->"C:\WINDOWS\$NtUninstallKB2158563$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB2443685)-->"C:\WINDOWS\$NtUninstallKB2443685$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)-->"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB942288-v3)-->"C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB954708)-->"C:\WINDOWS\$NtUninstallKB954708$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB981793)-->"C:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
HP Document Viewer 5.3-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Extended Capabilities 5.3-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 5.3-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
HP Solution Center & Imaging Support Tools 5.3-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
ImageMixer VCD/DVD2 for OLYMPUS-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}\Setup.exe" -l0x9 UNINSTALL
J2SE Runtime Environment 5.0 Update 22-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150220}
Java(TM) 6 Update 22-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216021FF}
K-Lite Mega Codec Pack 6.6.6-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Last.fm 1.5.4.27091-->"C:\Program Files\Last.fm\unins000.exe"
Microsoft .NET Framework 1.1 Security Update (KB2416447)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp"
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 4 Client Profile-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft .NET Framework 4 Extended-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
Microsoft Base Smart Card Cryptographic Service Provider Package-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9-->"C:\WINDOWS\$NtUninstallWdf01009$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-041B-0000-0000000FF1CE} /uninstall {8AF3A9EB-FBB9-449F-AC11-94CE39930037}
Microsoft Office Excel MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0016-041B-0000-0000000FF1CE}
Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0122-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001A-041B-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0018-041B-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF0405-6000-11D3-8CFE-0150048383C9}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Hungarian) 2007-->MsiExec.exe /X{90120000-001F-040E-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2007-->MsiExec.exe /X{90120000-002C-041B-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040E-0000-0000000FF1CE} /uninstall {573CA1BB-C8A3-46C4-993E-DB4043D9BFCD}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Shared MUI (Slovak) 2007-->MsiExec.exe /X{90120000-006E-041B-0000-0000000FF1CE}
Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Microsoft Office Standard 2007-->MsiExec.exe /X{90120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001B-041B-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.9-->"C:\WINDOWS\$NtUninstallWudf01009$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
MioTransfer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F6DA398-707F-4D52-AE6A-7E812D1662D6}\Setup.exe" -l0x1b
Mozilla Firefox (3.5.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSVC80_x86_v2-->MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}
MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
MSXML 4.0 SP3 Parser (KB973685)-->MsiExec.exe /I{859DFA95-E4A6-48CD-B88E-A3E483E89B44}
MSXML 4.0 SP3 Parser-->MsiExec.exe /I{196467F1-C11F-4F76-858B-5812ADC83B94}
MSXML 4.0-->MsiExec.exe /I{428102E6-8A39-48B9-8389-847F5A44A600}
MSXML 4.0-->MsiExec.exe /I{54BB0384-1C33-488F-A95B-877E480D3EDC}
Nero 8-->MsiExec.exe /X{6D45EF03-E8EE-4355-81C3-F918CBCF1033}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Next Generation Visualisations-->MsiExec.exe /I{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B}
Nokia Multimedia Common Components 2.4-->MsiExec.exe /I{6EB6C056-02BB-453E-8448-EC90B9794180}
Nokia Software Updater-->MsiExec.exe /X{650E2ABD-270A-499C-BA9F-09180DDDDA16}
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
OLYMPUS Digital Camera Updater-->MsiExec.exe /X{7CC978FD-AE31-419D-A7AB-2A137689AE1F}
OLYMPUS Master-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{BA820A24-704B-428D-9904-71A10DAC1372} /l1033 /zUNINSTALL
OLYMPUS Viewer 2-->MsiExec.exe /X{643CC22D-0994-41A8-ACE8-CF11A2ACDC1C}
Picasa 3-->"D:\Google\Picasa3\Uninstall.exe"
PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
Rhapsody Player Engine-->MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2289158)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {210B16C0-CEBD-4DE9-B474-04A7E8735E16}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {7A2C18A1-D2A2-3177-82F1-5FE9CC08ECB0} /parameterfolder Extended
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {3DED0A62-44C8-4E00-A785-5212F297A9D9}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2183461)-->"C:\WINDOWS\ie8updates\KB2183461-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2360131)-->"C:\WINDOWS\ie8updates\KB2360131-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB2416400)-->"C:\WINDOWS\ie8updates\KB2416400-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB981332)-->"C:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB982381)-->"C:\WINDOWS\ie8updates\KB982381-IE8\spuninst\spuninst.exe"
Security Update for Windows Media Encoder (KB2447961)-->"C:\WINDOWS\$NtUninstallKB2447961_WM9L$\spuninst\spuninst.exe"
Security Update for Windows Media Encoder (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
Security Update for Windows Media Encoder (KB979332)-->"C:\WINDOWS\$NtUninstallKB979332_WM9L$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB2378111)-->"C:\WINDOWS\$NtUninstallKB2378111_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB975558)-->"C:\WINDOWS\$NtUninstallKB975558_WM8$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB978695)-->"C:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Search 4 - KB963093-->"C:\WINDOWS\$NtUninstallKB963093$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2079403)-->"C:\WINDOWS\$NtUninstallKB2079403$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2115168)-->"C:\WINDOWS\$NtUninstallKB2115168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2121546)-->"C:\WINDOWS\$NtUninstallKB2121546$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2160329)-->"C:\WINDOWS\$NtUninstallKB2160329$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2229593)-->"C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2259922)-->"C:\WINDOWS\$NtUninstallKB2259922$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2279986)-->"C:\WINDOWS\$NtUninstallKB2279986$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2286198)-->"C:\WINDOWS\$NtUninstallKB2286198$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2296011)-->"C:\WINDOWS\$NtUninstallKB2296011$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2296199)-->"C:\WINDOWS\$NtUninstallKB2296199$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2347290)-->"C:\WINDOWS\$NtUninstallKB2347290$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2360937)-->"C:\WINDOWS\$NtUninstallKB2360937$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2387149)-->"C:\WINDOWS\$NtUninstallKB2387149$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2419632)-->"C:\WINDOWS\$NtUninstallKB2419632$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2423089)-->"C:\WINDOWS\$NtUninstallKB2423089$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2436673)-->"C:\WINDOWS\$NtUninstallKB2436673$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2440591)-->"C:\WINDOWS\$NtUninstallKB2440591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2443105)-->"C:\WINDOWS\$NtUninstallKB2443105$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975562)-->"C:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978542)-->"C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979482)-->"C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979559)-->"C:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979687)-->"C:\WINDOWS\$NtUninstallKB979687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980195)-->"C:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980218)-->"C:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980436)-->"C:\WINDOWS\$NtUninstallKB980436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981322)-->"C:\WINDOWS\$NtUninstallKB981322$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981852)-->"C:\WINDOWS\$NtUninstallKB981852$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981957)-->"C:\WINDOWS\$NtUninstallKB981957$\spuninst\spuninst.exe"
Security Update for Windows XP (KB981997)-->"C:\WINDOWS\$NtUninstallKB981997$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982132)-->"C:\WINDOWS\$NtUninstallKB982132$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982214)-->"C:\WINDOWS\$NtUninstallKB982214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982665)-->"C:\WINDOWS\$NtUninstallKB982665$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982802)-->"C:\WINDOWS\$NtUninstallKB982802$\spuninst\spuninst.exe"
SHOUTcast Source DSP 1.9.0 (remove only)-->C:\Program Files\Winamp\uninst-dsp.exe
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
The KMPlayer (remove only)-->"C:\Program Files\The KMPlayer\uninstall.exe"
Total Commander (Remove or Repair)-->C:\Program Files\totalcmd\tcuninst.exe
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft Office Outlook 2007 (KB2412171)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {752A0B7C-BD24-4362-AC86-AB63FEE6F46F}
Update for Microsoft Windows (KB971513)-->"C:\WINDOWS\$NtUninstallKB971513$\spuninst\spuninst.exe"
Update for Outlook 2007 Junk Email Filter (KB2483110)-->msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {592B47F5-D305-431A-9781-ED6CBB44FA8B}
Update for Windows Internet Explorer 8 (KB2362765)-->"C:\WINDOWS\ie8updates\KB2362765-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB2447568)-->"C:\WINDOWS\ie8updates\KB2447568-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB975364)-->"C:\WINDOWS\ie8updates\KB975364-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB980182)-->"C:\WINDOWS\ie8updates\KB980182-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB982632)-->"C:\WINDOWS\ie8updates\KB982632-IE8\spuninst\spuninst.exe"
Update for Windows Internet Explorer 8 (KB982664)-->"C:\WINDOWS\ie8updates\KB982664-IE8\spuninst\spuninst.exe"
Update for Windows XP (KB2141007)-->"C:\WINDOWS\$NtUninstallKB2141007$\spuninst\spuninst.exe"
Update for Windows XP (KB2345886)-->"C:\WINDOWS\$NtUninstallKB2345886$\spuninst\spuninst.exe"
Update for Windows XP (KB2467659)-->"C:\WINDOWS\$NtUninstallKB2467659$\spuninst\spuninst.exe"
Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Video ToolBox 2.0 Home Edition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F9CFBD8-8F77-4DCD-8CB5-CDD5F653C872}\setup.exe" -l0x9
Visual C++ 8.0 CRT (x86) WinSXS MSM-->MsiExec.exe /I{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}
WIDCOMM Bluetooth Software-->MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679}
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\B4723E9A0713E5B1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0)-->C:\PROGRA~1\DIFX\25C232B9F73C1237\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\olycamcomm_443826FC96EF44DB802C7D7FD82451DA7A0ABB86\olycamcomm.inf
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray-->"C:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Management Framework Core-->"C:\WINDOWS\$968930Uinstall_KB968930$\spuninst\spuninst.exe"
Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows Rights Management Client with Service Pack 2-->MsiExec.exe /X{62BFB4C2-8C4E-4D91-BD7D-81C06EAAC3C0}
Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archivátor-->C:\Program Files\WinRAR\uninstall.exe

======Security center information======

AV: ESET Smart Security 4.0
FW: ESET personal firewall

======System event log======

Computer Name: PETER-A3K
Event Code: 51
Message: Na zariadení \Device\Harddisk0\D sa zistila chyba počas stránkovania.

Record Number: 435547
Source Name: Disk
Time Written: 20101227120233.000000+060
Event Type: upozornenie
User:

Computer Name: PETER-A3K
Event Code: 51
Message: Na zariadení \Device\Harddisk0\D sa zistila chyba počas stránkovania.

Record Number: 435546
Source Name: Disk
Time Written: 20101227120233.000000+060
Event Type: upozornenie
User:

Computer Name: PETER-A3K
Event Code: 51
Message: Na zariadení \Device\Harddisk0\D sa zistila chyba počas stránkovania.

Record Number: 435545
Source Name: Disk
Time Written: 20101227120233.000000+060
Event Type: upozornenie
User:

Computer Name: PETER-A3K
Event Code: 51
Message: Na zariadení \Device\Harddisk0\D sa zistila chyba počas stránkovania.

Record Number: 435544
Source Name: Disk
Time Written: 20101227120233.000000+060
Event Type: upozornenie
User:

Computer Name: PETER-A3K
Event Code: 51
Message: Na zariadení \Device\Harddisk0\D sa zistila chyba počas stránkovania.

Record Number: 435543
Source Name: Disk
Time Written: 20101227120233.000000+060
Event Type: upozornenie
User:

=====Application event log=====

Computer Name: PETER-A3K
Event Code: 1035
Message: Inštalátor systému Windows rekonfiguroval produkt. Názov produktu: Microsoft Office Standard 2007. Verzia produktu: 12.0.6425.1000. Jazyk produktu: 0. Stav úspešnej alebo neúspešnej rekonfigurácie: 0.

Record Number: 5242
Source Name: MsiInstaller
Time Written: 20101109214441.000000+060
Event Type: informácie
User: PETER-A3K\Peter

Computer Name: PETER-A3K
Event Code: 11728
Message: Produkt: Microsoft Office Standard 2007 -- Konfigurácia sa úspešne dokončila.

Record Number: 5241
Source Name: MsiInstaller
Time Written: 20101109214441.000000+060
Event Type: informácie
User: PETER-A3K\Peter

Computer Name: PETER-A3K
Event Code: 1036
Message: Inštalátor systému Windows nainštaloval aktualizáciu. Názov produktu: Microsoft Office Standard 2007. Verzia produktu: 12.0.6425.1000. Jazyk produktu: 0. Názov aktualizácie: Security Update for Microsoft Office PowerPoint Viewer (KB2413381). Stav úspešnej alebo neúspešnej inštalácie: 0.

Record Number: 5240
Source Name: MsiInstaller
Time Written: 20101109214441.000000+060
Event Type: informácie
User: PETER-A3K\Peter

Computer Name: PETER-A3K
Event Code: 1022
Message: Produkt: Microsoft Office Standard 2007 – Aktualizácia Security Update for Microsoft Office PowerPoint Viewer (KB2413381) sa bola úspešne nainštalovaná.

Record Number: 5239
Source Name: MsiInstaller
Time Written: 20101109214441.000000+060
Event Type: informácie
User: PETER-A3K\Peter

Computer Name: PETER-A3K
Event Code: 1040
Message: Spustenie transakcie Inštalátora systému Windows: {90120000-0012-0000-0000-0000000FF1CE}. ID procesu klienta: 1720.

Record Number: 5238
Source Name: MsiInstaller
Time Written: 20101109214432.000000+060
Event Type: informácie
User: PETER-A3K\Peter

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\NVIDIA Corporation\PhysX\Common;C:\Program Files\PC Connectivity Solution;C:\Program Files\ATI Technologies\ATI.ACE;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727;C:\WINDOWS\system32\WindowsPowerShell\v1.0
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.PSC1;.PSC1
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"PSModulePath"=C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\

-----------------EOF-----------------

Re: Win32/Yimfoca.AA

Napsal: 16 led 2011 20:45
od motji
Ještě otestujte na www.virustotal.com
C:\clicapi.dll