Stránka 1 z 1

Pro Vyosek

Napsal: 27 úno 2011 13:20
od Peter
Dobrý deň momentálne som na svojom druhom PC (mam Windows XP) a je na tom dosť zle fungujem len v núdzovom režime, pretože normálne po prihlásení je nehorázne pomalý po čase akonáhle kliknem na ikonu mozila alebo explorer tak automaticky zmrzne úplne stíchne pokúšal som sa dostať do správcu úloh ale neúspešne pretože mi potom ostane len prázdna modrá plocha.

A tu je ten RSIT bez spustenie combofixu ešte:

Logfile of random's system information tool 1.08 (written by random/random)
Run by User at 2011-02-27 13:20:45
Systém Microsoft Windows XP Professional Service Pack 3
System drive H: has 33 GB (14%) free of 238 GB
Total RAM: 1022 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:20:58, on 27.2.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Documents and Settings\User\My Documents\Preberanie\RSIT.exe
H:\Program Files\trend micro\User.exe
H:\Program Files\Mozilla Firefox\plugin-container.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - H:\Program Files\Dealio Toolbar\SearchSettings.dll (file missing)
R3 - URLSearchHook: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - H:\Program Files\PHPNukeEN\tbPHP1.dll
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - H:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll (file missing)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - H:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - H:\Program Files\ConduitEngine\ConduitEngin1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - H:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - H:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: (no name) - {b23920f4-4c2f-412b-9450-1d7028d5454e} - (no file)
O2 - BHO: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - H:\Program Files\PHPNukeEN\tbPHP1.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - H:\Program Files\Dealio Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - H:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll (file missing)
O3 - Toolbar: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - H:\Program Files\PHPNukeEN\tbPHP1.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - H:\Program Files\ConduitEngine\ConduitEngin1.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - H:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [services.exe] H:\WINDOWS\services.exe
O4 - HKLM\..\Run: [StatusClient 2.6] H:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] H:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [HPLJ Config] H:\Program Files\Hewlett-Packard\hp LaserJet 3015_3020_3030_3380\SetConfig.exe -c Direct -p DOT4_001 -pn "" -n 1 -l 1033 -sl 120000
O4 - HKLM\..\Run: [HP Software Update] H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Z810SysStart] H:\Program Files\Connection Manager\sysctrl.exe
O4 - HKLM\..\Run: [Z810PNP] H:\Program Files\Connection Manager\SamsungPnPServiceManager.exe
O4 - HKLM\..\Run: [mspaint] "H:\WINDOWS\system32\Paint.exe" -autocheck
O4 - HKLM\..\Run: [NokiaMServer] H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DivXUpdate] "H:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [USBToolTip] H:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [egui] "H:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "H:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKCU\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "H:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [services.exe] H:\WINDOWS\services.exe
O4 - HKCU\..\Run: [swg] "H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "H:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [BitComet] H:\Program Files\BitComet\BitComet.exe /tray
O4 - HKCU\..\Run: [Z810SysStart] H:\Program Files\Connection Manager\sysctrl.exe
O4 - HKCU\..\Run: [Z810PNP] H:\Program Files\Connection Manager\SamsungPnPServiceManager.exe
O4 - HKCU\..\Run: [Google Update] "H:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] H:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [eehl] H:\Documents and Settings\User\Application Data\eehl\eehl.exe
O4 - HKCU\..\Run: [EA Core] "H:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [svchosts.exe] H:\Documents and Settings\User\Application Data\Microsoft\svchosts.exe
O4 - HKCU\..\Run: [RegistryBooster] "H:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKCU\..\Run: [WMPNSCFG] H:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RGSC] H:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: OpenOffice.org 3.0.lnk = H:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: OpenOffice.org 3.0.lnk = H:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 3.0.lnk = H:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = H:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://H:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - H:\Program Files\PartyGaming\PartyCasino\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - H:\Program Files\PartyGaming\PartyCasino\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - H:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: h:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d ... o-eula.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - H:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - H:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - H:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - H:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - H:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - H:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - H:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - H:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate1ca3af1a336b4e2) (gupdate1ca3af1a336b4e2) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Unknown owner - H:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - H:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - H:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - H:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - H:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - H:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - H:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 12773 bytes

======Scheduled tasks folder======

H:\WINDOWS\tasks\AppleSoftwareUpdate.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
Dealio Toolbar - H:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - H:\PROGRA~1\ICQTOO~1\toolbaru.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - H:\Program Files\ConduitEngine\ConduitEngin1.dll [2011-01-07 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - H:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-05 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - H:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-26 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b23920f4-4c2f-412b-9450-1d7028d5454e}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - H:\Program Files\PHPNukeEN\tbPHP1.dll [2011-01-07 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
H:\Program Files\Dealio Toolbar\SearchSettings.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Dealio Toolbar - H:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll []
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - H:\Program Files\PHPNukeEN\tbPHP1.dll [2011-01-07 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - H:\Program Files\ConduitEngine\ConduitEngin1.dll [2011-01-07 3911776]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - H:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-05 297648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=H:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=H:\WINDOWS\system32\NvMcTray.dll [2007-04-19 86016]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2007-04-12 16132608]
"Alcmtr"=H:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"services.exe"=H:\WINDOWS\services.exe []
"StatusClient 2.6"=H:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe [2003-10-03 61440]
"TomcatStartup 2.5"=H:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe [2003-07-25 155648]
"HPLJ Config"=H:\Program Files\Hewlett-Packard\hp LaserJet 3015_3020_3030_3380\SetConfig.exe [2003-03-31 28672]
"HP Software Update"=H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe [2002-12-17 49152]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"Z810SysStart"=H:\Program Files\Connection Manager\sysctrl.exe [2008-09-01 307200]
"Z810PNP"=H:\Program Files\Connection Manager\SamsungPnPServiceManager.exe [2008-09-09 122880]
"mspaint"=H:\WINDOWS\system32\Paint.exe -autocheck []
"NokiaMServer"=H:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"iTunesHelper"=H:\Program Files\iTunes\iTunesHelper.exe [2010-06-15 141624]
"DivXUpdate"=H:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]
"USBToolTip"=H:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"QuickTime Task"=H:\Program Files\QuickTime\qttask.exe [2010-08-10 421888]
"egui"=H:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
"Adobe Reader Speed Launcher"=H:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10 932288]
"USB2Check"=H:\WINDOWS\system32\PCLECoInst.dll [2006-11-06 81920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=H:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"services.exe"=H:\WINDOWS\services.exe []
"swg"=H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-15 68856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=H:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-02-28 1828136]
"BitComet"=H:\Program Files\BitComet\BitComet.exe /tray []
"Z810SysStart"=H:\Program Files\Connection Manager\sysctrl.exe [2008-09-01 307200]
"Z810PNP"=H:\Program Files\Connection Manager\SamsungPnPServiceManager.exe [2008-09-09 122880]
"Google Update"=H:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-30 133104]
"Uniblue RegistryBooster 2009"=H:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S []
"eehl"=H:\Documents and Settings\User\Application Data\eehl\eehl.exe []
"EA Core"=H:\Program Files\Electronic Arts\EADM\Core.exe -silent []
""= []
"svchosts.exe"=H:\Documents and Settings\User\Application Data\Microsoft\svchosts.exe []
"RegistryBooster"=H:\Program Files\Uniblue\RegistryBooster\launcher.exe delay 20000 []
"WMPNSCFG"=H:\Program Files\Windows Media Player\WMPNSCFG.exe [2007-01-05 204288]
"RGSC"=H:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent []

H:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
InterVideo WinCinema Manager.lnk - H:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
McAfee Security Scan Plus.lnk - H:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

H:\Documents and Settings\User\Start Menu\Programs\Startup
Adobe Gamma.lnk - H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
OpenOffice.org 3.0.lnk - H:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
H:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\Program Files\ICQ6\ICQ.exe"="H:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"H:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe"="H:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe:*:Enabled:javaw"
"H:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="H:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"H:\Program Files\GameSpy Arcade\Aphex.exe"="H:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"H:\Program Files\Nero\Nero8\Nero ShowTime\ShowTime.exe"="H:\Program Files\Nero\Nero8\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"H:\Program Files\LimeWire\LimeWire.exe"="H:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"H:\Program Files\BitTornado\btdownloadgui.exe"="H:\Program Files\BitTornado\btdownloadgui.exe:*:Enabled:btdownloadgui"
"H:\Program Files\Bethesda Softworks\BitTornado\btdownloadgui.exe"="H:\Program Files\Bethesda Softworks\BitTornado\btdownloadgui.exe:*:Enabled:btdownloadgui"
"H:\Program Files\BitComet\BitComet.exe"="H:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"H:\Program Files\uTorrent\uTorrent.exe"="H:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\Program Files\Valve\hl.exe"="H:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\Counter-Strike Source\hl2.exe"="H:\Program Files\Counter-Strike Source\hl2.exe:*:Disabled:hl2"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.594\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.594\pickup.listchecker.exe:*:Disabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX45.656\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX45.656\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX63.015\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX63.015\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.906\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.906\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.203\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.203\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX03.500\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX03.500\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Program Files\ICQ6.5\ICQ.exe"="H:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.609\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.609\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.313\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.313\pickup.listchecker.exe:*:Enabled:pickup.listchecker"
"H:\Program Files\Warcraft III\Warcraft III\war3.exe"="H:\Program Files\Warcraft III\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"H:\Program Files\Warcraft III\Warcraft III.exe"="H:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"H:\Program Files\Warcraft III\ftinst.tmp\Warcraft III.exe"="H:\Program Files\Warcraft III\ftinst.tmp\Warcraft III.exe:*:Enabled:Warcraft III"
"H:\Program Files\Messenger\msmsgs.exe"="H:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"H:\Program Files\Garena\Garena.exe"="H:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.531\pickup.listchecker.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX00.531\pickup.listchecker.exe:*:Disabled:pickup.listchecker"
"H:\Documents and Settings\User\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll"="H:\Documents and Settings\User\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"H:\Documents and Settings\User\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe"="H:\Documents and Settings\User\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"H:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe"="H:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe:*:Enabled:BF1942"
"H:\Program Files\Warcraft III\Warcraft III\Warcraft III.exe"="H:\Program Files\Warcraft III\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"H:\Program Files\Valve\hltv.exe"="H:\Program Files\Valve\hltv.exe:*:Enabled:HLTV Launcher"
"H:\Program Files\Counter-Strike 1.6\hl.exe"="H:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"H:\Documents and Settings\User\My Documents\Downloads\Counter-Strike 1.6 + Half-Life\hl.exe"="H:\Documents and Settings\User\My Documents\Downloads\Counter-Strike 1.6 + Half-Life\hl.exe:*:Enabled:Half-Life Launcher"
"H:\Program Files\Valve\toto_smazte\hltv.exe"="H:\Program Files\Valve\toto_smazte\hltv.exe:*:Enabled:HLTV Launcher"
"H:\Program Files\Steam\Steam.exe"="H:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"H:\Program Files\Garena\Garena Host Bot v1.0\GarenaHostBot.exe"="H:\Program Files\Garena\Garena Host Bot v1.0\GarenaHostBot.exe:*:Enabled:Garena Host Bot - advanced hosting bot for garena"
"H:\Program Files\Garena\Garena Host Bot v1.0\ghost.exe"="H:\Program Files\Garena\Garena Host Bot v1.0\ghost.exe:*:Enabled:ghost"
"H:\Program Files\PFPortChecker\PFPortChecker.exe"="H:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded."
"H:\WINDOWS\system32\PnkBstrA.exe"="H:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"H:\WINDOWS\system32\PnkBstrB.exe"="H:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="H:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Documents and Settings\User\My Documents\Preberanie\MeGa Garena ExP hacK.exe"="H:\Documents and Settings\User\My Documents\Preberanie\MeGa Garena ExP hacK.exe:*:Enabled:MeGa Garena ExP hacK"
"H:\Documents and Settings\User\Local Settings\Temp\Rar$EX05.875\Garena HostEdition\Garena.exe"="H:\Documents and Settings\User\Local Settings\Temp\Rar$EX05.875\Garena HostEdition\Garena.exe:*:Enabled:Garena"
"H:\Documents and Settings\All Users\Application Data\NexonEU\NGM\NGM.exe"="H:\Documents and Settings\All Users\Application Data\NexonEU\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"H:\Program Files\Combat Arms EU\CombatArms.exe"="H:\Program Files\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"H:\Program Files\Combat Arms EU\Engine.exe"="H:\Program Files\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"H:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="H:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine"
"H:\Nexon\Combat Arms EU\CombatArms.exe"="H:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"H:\Nexon\Combat Arms EU\Engine.exe"="H:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"H:\Program Files\Bonjour\mDNSResponder.exe"="H:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"H:\Program Files\iTunes\iTunes.exe"="H:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\Pinnacle\Studio 14\Programs\RM.exe"="H:\Program Files\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager"
"H:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe"="H:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio"
"H:\Program Files\Pinnacle\Studio 14\Programs\umi.exe"="H:\Program Files\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi"
"H:\Program Files\Garena HostBot\GarenaHostBot.exe"="H:\Program Files\Garena HostBot\GarenaHostBot.exe:*:Enabled:Garena Host Bot - advanced hosting bot for garena"
"H:\Program Files\Garena HostBot\ghost.exe"="H:\Program Files\Garena HostBot\ghost.exe:*:Enabled:ghost"
"H:\Program Files\Opera\opera.exe"="H:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"H:\Program Files\Goiceasoft Studios\Counter Strike 1.8 Goiceasoft\cstrike.exe"="H:\Program Files\Goiceasoft Studios\Counter Strike 1.8 Goiceasoft\cstrike.exe:*:Enabled:CS 1.8 Goiceasoft"
"H:\Program Files\www.Cstr1k3rs.uCoz.Com\CarbonCS v1.1\cstrike.exe"="H:\Program Files\www.Cstr1k3rs.uCoz.Com\CarbonCS v1.1\cstrike.exe:*:Enabled:CarbonCS v1.1"
"H:\Program Files\Pando Networks\Media Booster\PMB.exe"="H:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"H:\Riot Games\League of Legends\air\LolClient.exe"="H:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"H:\Riot Games\League of Legends\game\League of Legends.exe"="H:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\Combat Arms EU\CombatArms.exe"="H:\Program Files\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"H:\Program Files\Combat Arms EU\Engine.exe"="H:\Program Files\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"H:\Nexon\Combat Arms EU\CombatArms.exe"="H:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"H:\Nexon\Combat Arms EU\Engine.exe"="H:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"H:\Program Files\Pando Networks\Media Booster\PMB.exe"="H:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

======File associations======

.scr - open - H:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-02-27 13:20:45 ----D---- H:\rsit
2011-02-27 13:20:45 ----D---- H:\Program Files\trend micro
2011-02-27 13:13:13 ----D---- H:\WINDOWS\CSC
2011-02-26 08:31:44 ----D---- H:\Documents and Settings\User\Application Data\LolClient
2011-02-26 08:13:15 ----A---- H:\WINDOWS\system32\XAudio2_2.dll
2011-02-26 08:13:15 ----A---- H:\WINDOWS\system32\XAPOFX1_1.dll
2011-02-26 08:13:12 ----A---- H:\WINDOWS\system32\D3DCompiler_39.dll
2011-02-26 08:00:55 ----D---- H:\Riot Games
2011-02-25 23:16:33 ----D---- H:\Documents and Settings\All Users\Application Data\PMB Files
2011-02-25 23:15:56 ----D---- H:\Program Files\Pando Networks
2011-02-25 07:52:23 ----HDC---- H:\WINDOWS\$NtUninstallKB971029$
2011-02-09 03:11:11 ----HDC---- H:\WINDOWS\$NtUninstallKB2478971$
2011-02-09 03:10:57 ----HDC---- H:\WINDOWS\$NtUninstallKB2485376$
2011-02-09 03:10:37 ----HDC---- H:\WINDOWS\$NtUninstallKB2479628$
2011-02-09 03:09:53 ----HDC---- H:\WINDOWS\$NtUninstallKB2483185$
2011-02-09 03:03:54 ----HDC---- H:\WINDOWS\$NtUninstallKB2476687$
2011-02-09 03:03:12 ----HDC---- H:\WINDOWS\$NtUninstallKB2482017$
2011-02-09 03:02:01 ----HDC---- H:\WINDOWS\$NtUninstallKB2478960$
2011-02-09 03:01:31 ----HDC---- H:\WINDOWS\$NtUninstallKB2393802$

======List of files/folders modified in the last 1 months======

2011-02-27 13:20:45 ----RD---- H:\Program Files
2011-02-27 13:13:37 ----A---- H:\WINDOWS\ntbtlog.txt
2011-02-27 13:13:13 ----D---- H:\WINDOWS
2011-02-27 13:11:09 ----D---- H:\WINDOWS\Temp
2011-02-27 13:08:46 ----D---- H:\Program Files\Connection Manager
2011-02-27 13:03:45 ----D---- H:\WINDOWS\Prefetch
2011-02-27 12:24:09 ----D---- H:\Program Files\Warcraft III
2011-02-27 08:33:30 ----D---- H:\Program Files\Garena
2011-02-27 07:57:02 ----D---- H:\WINDOWS\system32\CatRoot2
2011-02-26 22:38:28 ----A---- H:\WINDOWS\SchedLgU.Txt
2011-02-26 21:45:51 ----D---- H:\Documents and Settings\User\Application Data\Skype
2011-02-26 20:55:35 ----SHD---- H:\WINDOWS\Installer
2011-02-26 20:55:22 ----D---- H:\Documents and Settings\All Users\Application Data\Skype
2011-02-26 08:13:16 ----D---- H:\WINDOWS\system32
2011-02-26 08:13:15 ----HD---- H:\WINDOWS\inf
2011-02-26 08:12:56 ----D---- H:\WINDOWS\system32\DirectX
2011-02-26 08:00:53 ----HD---- H:\Program Files\InstallShield Installation Information
2011-02-25 07:52:27 ----RSHDC---- H:\WINDOWS\system32\dllcache
2011-02-25 07:49:27 ----HD---- H:\WINDOWS\$hf_mig$
2011-02-19 12:56:26 ----SHD---- H:\Config.Msi
2011-02-19 12:56:24 ----D---- H:\Documents and Settings\User\Application Data\Mozilla
2011-02-18 21:24:41 ----A---- H:\WINDOWS\NeroDigital.ini
2011-02-15 10:57:06 ----D---- H:\Documents and Settings\User\Application Data\skypePM
2011-02-12 15:21:44 ----D---- H:\Program Files\Mozilla Firefox
2011-02-09 03:11:20 ----A---- H:\WINDOWS\imsins.BAK
2011-02-09 03:04:29 ----A---- H:\WINDOWS\system32\MRT.exe
2011-02-09 03:02:59 ----D---- H:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-02-09 03:01:57 ----A---- H:\WINDOWS\iis6.BAK
2011-01-30 16:40:30 ----D---- H:\Documents and Settings\User\Application Data\uTorrent

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347scsi;a347scsi; H:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 PxHelp20;PxHelp20; H:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2010-06-10 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); H:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); H:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x); H:\WINDOWS\System32\drivers\sfsync03.sys [2005-10-13 35328]
R0 sptd;sptd; H:\WINDOWS\System32\Drivers\sptd.sys [2010-03-30 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; H:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 epfwtdir;epfwtdir; H:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R3 appliandMP;appliandMP; H:\WINDOWS\system32\DRIVERS\appliand.sys [2010-06-24 28256]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; H:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 MarvinBus;Pinnacle Marvin Bus; H:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 mouhid;Mouse HID Driver; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2007-07-27 12160]
R3 Pfc;Padus ASPI Shell; H:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-03-01 90496]
R3 usbstor;USB Mass Storage Driver; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 a347bus;a347bus; H:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
S1 ehdrv;ehdrv; H:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S1 intelppm;Intel Processor Driver; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
S1 kbdhid;Keyboard HID Driver; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S2 eamon;eamon; H:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
S2 Hardlock;Hardlock; \??\H:\WINDOWS\system32\drivers\hardlock.sys []
S2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; H:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
S2 NwlnkNb;NWLink NetBIOS; H:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2007-07-27 63232]
S2 NwlnkSpx;NWLink SPX/SPXII Protocol; H:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2007-07-27 55936]
S3 appliand;Applian Network Service; H:\WINDOWS\system32\DRIVERS\appliand.sys [2010-06-24 28256]
S3 BthEnum;Bluetooth Enumerator Service; H:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); H:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; H:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; H:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 CCDECODE;Closed Caption Decoder; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 DCamUSBEMPIA;Dazzle DVC Video Device; H:\WINDOWS\system32\DRIVERS\emDevice.sys [2005-12-21 100957]
S3 dot4;MS IEEE-1284.4 Driver; H:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; H:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; H:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 EagleNT;EagleNT; \??\H:\WINDOWS\system32\drivers\EagleNT.sys []
S3 emAudio;Dazzle DVC Audio Device; H:\WINDOWS\system32\drivers\emAudio.sys [2006-12-12 22528]
S3 FiltUSBEMPIA;USB Device Lower Filter; H:\WINDOWS\system32\DRIVERS\emFilter.sys [2005-12-21 5245]
S3 GarenaPEngine;GarenaPEngine; \??\H:\DOCUME~1\User\LOCALS~1\Temp\SVQCD0.tmp []
S3 gdrv;gdrv; \??\H:\WINDOWS\gdrv.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\H:\Program Files\Garena\safedrv.sys []
S3 hamachi;Hamachi Network Interface; H:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-01-01 25280]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-04-23 4402176]
S3 MPE;BDA MPE Filter; H:\WINDOWS\system32\DRIVERS\MPE.sys [2004-07-09 15104]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-11 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nm;Network Monitor Driver; H:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 nmwcd;Nokia USB Phone Parent; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-01-21 18048]
S3 nmwcdc;Nokia USB Generic; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-12-30 22016]
S3 NuidFltr;NUID filter driver; H:\WINDOWS\system32\DRIVERS\NuidFltr.sys [2009-05-09 14736]
S3 nv;nv; H:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-19 3988384]
S3 NWRDR;NetWare Rdr; H:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); H:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 ScanUSBEMPIA;USB Still Image Capture Device; H:\WINDOWS\system32\DRIVERS\emScan.sys [2005-12-21 4493]
S3 scrcap;scrcap; H:\WINDOWS\system32\DRIVERS\scrcap.sys []
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); H:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; H:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; H:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 sscdserd;SAMSUNG Mobile Modem Diagnostic Serial Port (WDM); H:\WINDOWS\system32\DRIVERS\sscdserd.sys [2008-02-22 94336]
S3 StillCam;Still Serial Digital Camera Driver; H:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-17 6784]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-12-30 7936]
S3 usb_rndisx;USB RNDIS Adapter; H:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 USBAAPL;Apple Mobile USB Driver; H:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbccgp;Microsoft USB Generic Parent Driver; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;USB Scanner Driver; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-12-30 7936]
S3 wceusbsh;Windows CE USB Serial Host Driver; H:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; H:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; H:\WINDOWS\System32\drivers\ws2ifsl.sys [2007-07-27 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 Apple Mobile Device;Apple Mobile Device; H:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
S2 Application Updater;Application Updater; H:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
S2 Bonjour Service;Bonjour Service; H:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
S2 BthServ;Bluetooth Support Service; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ekrn;ESET Service; H:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
S2 gupdate1ca3af1a336b4e2;Služba Google Update (gupdate1ca3af1a336b4e2); H:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-21 133104]
S2 MDM;Machine Debug Manager; H:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; H:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-02-18 877864]
S2 NVSvc;NVIDIA Display Driver Service; H:\WINDOWS\system32\nvsvc32.exe [2007-04-19 159810]
S2 NWCWorkstation;Client Service for NetWare; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 NwSapAgent;SAP Agent; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; H:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
S2 PnkBstrA;PnkBstrA; H:\WINDOWS\system32\PnkBstrA.exe [2008-03-24 66872]
S2 PnkBstrB;PnkBstrB; H:\WINDOWS\system32\PnkBstrB.exe [2010-04-04 189248]
S2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 Adobe LM Service;Adobe LM Service; H:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-08-06 72704]
S3 aspnet_state;ASP.NET State Service; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; H:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-03-30 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; H:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 33584]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; H:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-11-06 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-26 182768]
S3 IDriverT;InstallDriver Table Manager; H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Imapi Helper;Imapi Helper; H:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe []
S3 iPod Service;iPod Service; H:\Program Files\iPod\bin\iPodService.exe [2010-06-15 540472]
S3 McComponentHostService;McAfee Security Scan Component Host Service; H:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 NMIndexingService;NMIndexingService; H:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S3 odserv;Microsoft Office Diagnostics Service; H:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2003-10-22 65536]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-01-26 652800]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Pro Vyosek

Napsal: 27 úno 2011 14:12
od vyosek
Zdravim a pekny den preji :)

:arrow: Tam toho je :arcisit:

:arrow: Zustante v nouzovem rezimu

:arrow: Pri stahovani ComboFixu - navod a postup nize - jej prejmenujte na Beruska.com

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Pro Vyosek

Napsal: 04 bře 2011 00:17
od Peter
tu je log z combofixu :

ComboFix 11-03-03.01 - User 03.03.2011 23:43:39.1.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1022.781 [GMT 1:00]
Running from: h:\documents and settings\User\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

h:\documents and settings\Poriadok\Desktop\SE\100MSDCF\Desktop_.ini
h:\documents and settings\Poriadok\Desktop\SE\picture\Desktop_.ini
h:\documents and settings\Poriadok\Desktop\SE\video\Desktop_.ini
h:\documents and settings\User\Application Data\Dealio
h:\documents and settings\User\Application Data\Dealio\res\widgets.xml
h:\documents and settings\User\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
h:\documents and settings\User\Application Data\eehl
h:\documents and settings\User\Desktop\hudba ipod\KF\Desktop_.ini
h:\documents and settings\User\Desktop\hudba\Desktop_.ini
h:\documents and settings\User\Desktop\hudba\hip hop\KF\Desktop_.ini
h:\documents and settings\User\Desktop\hudba\popRockSka\red hot chili pepers(master of pupets)\Desktop_.ini
h:\documents and settings\User\Desktop\hudba\popRockSka\red hot chili pepers(master of pupets)\Red Hot Chili Peppers- greatest hits\Desktop_.ini
h:\documents and settings\User\Desktop\hudba\popRockSka\red hot chili pepers(master of pupets)\Red Hot Chili Peppers - Stadium Arcadium (2006)-2albumy\CD 1 - Jupiter\Desktop_.ini
h:\documents and settings\User\Desktop\hudba\popRockSka\red hot chili pepers(master of pupets)\Red Hot Chili Peppers - Stadium Arcadium (2006)-2albumy\Desktop_.ini
h:\documents and settings\User\Desktop\SE\100MSDCF\Desktop_.ini
h:\documents and settings\User\Desktop\SE\DCIM\Desktop_.ini
h:\documents and settings\User\Desktop\SE\Nahravky\Desktop_.ini
h:\documents and settings\User\Desktop\see\DCIM\100XPRIA\100MSDCF\Desktop_.ini
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\bg.jpg
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\CurrentVersion.xml
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data\ProductInfo.mx
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\icon.ico
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\productinfo.dll
h:\documents and settings\User\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Setup.exe
h:\program files\Dealio Toolbar
h:\program files\Dealio Toolbar\FF\components\config.ini
h:\program files\Dealio Toolbar\FF\components\dealioToolbarFF.dll
h:\program files\Dealio Toolbar\FF\components\IFBHOHelperWidgiToolbar.xpt
h:\program files\Dealio Toolbar\FF\components\IFBHOWidgiToolbar.xpt
h:\program files\Dealio Toolbar\FF\chrome.manifest
h:\program files\Dealio Toolbar\FF\chrome\content\chevron.js
h:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
h:\program files\Dealio Toolbar\FF\chrome\content\login.js
h:\program files\Dealio Toolbar\FF\chrome\content\login.xul
h:\program files\Dealio Toolbar\FF\chrome\content\parser.js
h:\program files\Dealio Toolbar\FF\chrome\content\RssTickerWidget.js
h:\program files\Dealio Toolbar\FF\chrome\content\searchbox.js
h:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
h:\program files\Dealio Toolbar\FF\chrome\content\widgicomm.js
h:\program files\Dealio Toolbar\FF\chrome\content\widgihandling.js
h:\program files\Dealio Toolbar\FF\chrome\content\widgichevron.js
h:\program files\Dealio Toolbar\FF\chrome\content\widgilisteners.js
h:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.js
h:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
h:\program files\Dealio Toolbar\FF\chrome\content\widgiui.js
h:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
h:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
h:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
h:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\yahoo-search.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
h:\program files\Dealio Toolbar\FF\chrome\skin\separator.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
h:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
h:\program files\Dealio Toolbar\FF\install.rdf
h:\program files\Dealio Toolbar\IE\4.0.2\config.ini
h:\program files\Dealio Toolbar\Res\amazon.gif
h:\program files\Dealio Toolbar\Res\apple.gif
h:\program files\Dealio Toolbar\Res\barnes.gif
h:\program files\Dealio Toolbar\Res\bestbuy.gif
h:\program files\Dealio Toolbar\Res\dealio_logo.gif
h:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
h:\program files\Dealio Toolbar\Res\ebay.gif
h:\program files\Dealio Toolbar\Res\icon_settings.gif
h:\program files\Dealio Toolbar\Res\macys.gif
h:\program files\Dealio Toolbar\Res\newegg.gif
h:\program files\Dealio Toolbar\Res\overstock.gif
h:\program files\Dealio Toolbar\Res\search-button-hover.gif
h:\program files\Dealio Toolbar\Res\search-button.gif
h:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
h:\program files\Dealio Toolbar\Res\search-chevron.gif
h:\program files\Dealio Toolbar\Res\search_amazon.gif
h:\program files\Dealio Toolbar\Res\search_dealio.gif
h:\program files\Dealio Toolbar\Res\search_ebay.gif
h:\program files\Dealio Toolbar\Res\search_yahoo.gif
h:\program files\Dealio Toolbar\Res\target.gif
h:\program files\Dealio Toolbar\Res\walmart.gif
h:\program files\Dealio Toolbar\Res\widgets.xml
h:\program files\Dealio Toolbar\sscfg.ini
h:\program files\Dealio Toolbar\SSFF\components\IFBHOSearch.xpt
h:\program files\Dealio Toolbar\SSFF\components\IFBHOSearchHelperEngine.xpt
h:\program files\Dealio Toolbar\SSFF\components\IFHelperPreferences.xpt
h:\program files\Dealio Toolbar\SSFF\components\SearchSettingsFF.dll
h:\program files\Dealio Toolbar\SSFF\components\sscfg.ini
h:\program files\Dealio Toolbar\SSFF\chrome.manifest
h:\program files\Dealio Toolbar\SSFF\chrome\content\plugin.js
h:\program files\Dealio Toolbar\SSFF\chrome\content\plugin.xul
h:\program files\Dealio Toolbar\SSFF\chrome\content\protection.js
h:\program files\Dealio Toolbar\SSFF\chrome\content\utils.js
h:\program files\Dealio Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.dtd
h:\program files\Dealio Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.properties
h:\program files\Dealio Toolbar\SSFF\chrome\skin\yahoo.xml
h:\program files\Dealio Toolbar\SSFF\install.rdf
h:\program files\SoftwareRevenue.org
h:\program files\SoftwareRevenue.org\as.bmp
h:\program files\SoftwareRevenue.org\gle.bmp
H:\setup.exe
h:\windows\Fonts\mskntbb.sys
h:\windows\system32\Thumbs.db
h:\windows\system32\twunk_32.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2011-02-03 to 2011-03-03 )))))))))))))))))))))))))))))))
.

2011-03-01 16:16 . 2011-03-01 16:16 -------- d-----w- h:\windows\system32\wbem\Repository
2011-02-27 12:20 . 2011-02-27 12:21 -------- d-----w- H:\rsit
2011-02-27 12:20 . 2011-02-27 12:20 -------- d-----w- h:\program files\trend micro
2011-02-26 07:31 . 2011-02-26 07:31 -------- d-----w- h:\documents and settings\User\Application Data\LolClient
2011-02-26 07:13 . 2008-07-31 09:41 68616 ----a-w- h:\windows\system32\XAPOFX1_1.dll
2011-02-26 07:13 . 2008-07-31 09:40 509448 ----a-w- h:\windows\system32\XAudio2_2.dll
2011-02-26 07:13 . 2008-07-12 07:18 1493528 ----a-w- h:\windows\system32\D3DCompiler_39.dll
2011-02-26 07:00 . 2011-02-27 16:15 -------- d-----w- H:\Riot Games
2011-02-25 22:16 . 2011-02-26 07:50 -------- d-----w- h:\documents and settings\User\Local Settings\Application Data\PMB Files
2011-02-25 22:16 . 2011-02-25 22:16 -------- d-----w- h:\documents and settings\All Users\Application Data\PMB Files
2011-02-25 22:15 . 2011-02-25 22:15 -------- d-----w- h:\program files\Pando Networks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2007-07-27 12:00 439296 ----a-w- h:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2007-07-27 12:00 290048 ----a-w- h:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2007-07-27 12:00 1854976 ----a-w- h:\windows\system32\win32k.sys
2010-12-22 12:34 . 2007-07-27 12:00 301568 ----a-w- h:\windows\system32\kerberos.dll
2010-12-20 22:15 . 2007-07-27 12:00 667136 ----a-w- h:\windows\system32\wininet.dll
2010-12-20 22:15 . 2007-07-27 12:00 61952 ----a-w- h:\windows\system32\tdc.ocx
2010-12-20 22:15 . 2007-07-27 12:00 81920 ----a-w- h:\windows\system32\ieencode.dll
2010-12-20 17:26 . 2007-07-27 12:00 730112 ----a-w- h:\windows\system32\lsasrv.dll
2010-12-20 15:30 . 2007-07-27 12:00 369664 ----a-w- h:\windows\system32\html.iec
2010-12-09 15:15 . 2007-07-27 12:00 718336 ----a-w- h:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2007-07-27 12:00 33280 ----a-w- h:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2007-07-27 12:00 2148864 ----a-w- h:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-03 22:59 2027008 ----a-w- h:\windows\system32\ntkrnlpa.exe
2010-07-01 12:34 . 2010-07-01 12:34 1080658342 ----a-w- h:\program files\Combatarms_eu.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{dd02a4eb-4afd-4d60-99d8-e67f964ca813}"= "h:\program files\PHPNukeEN\tbPHP1.dll" [2011-01-07 3911776]

[HKEY_CLASSES_ROOT\clsid\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-07 16:33 3911776 ----a-w- h:\program files\ConduitEngine\ConduitEngin1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
2011-01-07 16:33 3911776 ----a-w- h:\program files\PHPNukeEN\tbPHP1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{dd02a4eb-4afd-4d60-99d8-e67f964ca813}"= "h:\program files\PHPNukeEN\tbPHP1.dll" [2011-01-07 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "h:\program files\ConduitEngine\ConduitEngin1.dll" [2011-01-07 3911776]

[HKEY_CLASSES_ROOT\clsid\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DD02A4EB-4AFD-4D60-99D8-E67F964CA813}"= "h:\program files\PHPNukeEN\tbPHP1.dll" [2011-01-07 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "h:\program files\ConduitEngine\ConduitEngin1.dll" [2011-01-07 3911776]

[HKEY_CLASSES_ROOT\clsid\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="h:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-15 68856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="h:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"Z810SysStart"="h:\program files\Connection Manager\sysctrl.exe" [2008-09-01 307200]
"Z810PNP"="h:\program files\Connection Manager\SamsungPnPServiceManager.exe" [2008-09-09 122880]
"Google Update"="h:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-30 133104]
"WMPNSCFG"="h:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="h:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="h:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]
"StatusClient 2.6"="h:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2003-10-03 61440]
"TomcatStartup 2.5"="h:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2003-07-25 155648]
"HPLJ Config"="h:\program files\Hewlett-Packard\hp LaserJet 3015_3020_3030_3380\SetConfig.exe" [2003-03-31 28672]
"HP Software Update"="h:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Z810SysStart"="h:\program files\Connection Manager\sysctrl.exe" [2008-09-01 307200]
"Z810PNP"="h:\program files\Connection Manager\SamsungPnPServiceManager.exe" [2008-09-09 122880]
"iTunesHelper"="h:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"DivXUpdate"="h:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"USBToolTip"="h:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"QuickTime Task"="h:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"egui"="h:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
"Adobe Reader Speed Launcher"="h:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="h:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"USB2Check"="h:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

h:\documents and settings\User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - h:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-21 113664]
OpenOffice.org 3.0.lnk - h:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-13 393216]

h:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - h:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-21 113664]
InterVideo WinCinema Manager.lnk - h:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-4-4 184320]
McAfee Security Scan Plus.lnk - h:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"h:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"h:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"h:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\Program Files\\ICQ6.5\\ICQ.exe"=
"h:\\Program Files\\Messenger\\msmsgs.exe"=
"h:\\Documents and Settings\\User\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"h:\\Documents and Settings\\User\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"h:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"h:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"h:\\WINDOWS\\system32\\PnkBstrA.exe"=
"h:\\WINDOWS\\system32\\PnkBstrB.exe"=
"h:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"h:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"h:\\Documents and Settings\\User\\My Documents\\Preberanie\\MeGa Garena ExP hacK.exe"=
"h:\\Documents and Settings\\All Users\\Application Data\\NexonEU\\NGM\\NGM.exe"=
"h:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"h:\\Program Files\\iTunes\\iTunes.exe"=
"h:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"h:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"h:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"h:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"h:\\Program Files\\Goiceasoft Studios\\Counter Strike 1.8 Goiceasoft\\cstrike.exe"=
"h:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"h:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25381:TCP"= 25381:TCP:BitComet 25381 TCP
"25381:UDP"= 25381:UDP:BitComet 25381 UDP
"58999:TCP"= 58999:TCP:Pando Media Booster
"58999:UDP"= 58999:UDP:Pando Media Booster
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"6996:TCP"= 6996:TCP:League of Legends Launcher
"6996:UDP"= 6996:UDP:League of Legends Launcher
"6970:TCP"= 6970:TCP:League of Legends Launcher
"6970:UDP"= 6970:UDP:League of Legends Launcher

R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);h:\windows\system32\drivers\sfsync03.sys [13.10.2005 14:46 35328]
R0 sptd;sptd;h:\windows\system32\drivers\sptd.sys [30.3.2010 14:04 691696]
R1 ehdrv;ehdrv;h:\windows\system32\drivers\ehdrv.sys [29.3.2010 16:12 115008]
R1 epfwtdir;epfwtdir;h:\windows\system32\drivers\epfwtdir.sys [29.3.2010 16:13 95896]
R2 Application Updater;Application Updater;h:\program files\Application Updater\ApplicationUpdater.exe [8.1.2010 0:51 380928]
R2 ekrn;ESET Service;h:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.8.2010 13:16 810144]
R3 appliandMP;appliandMP;h:\windows\system32\drivers\appliand.sys [24.6.2010 12:46 28256]
S2 gupdate1ca3af1a336b4e2;Služba Google Update (gupdate1ca3af1a336b4e2);h:\program files\Google\Update\GoogleUpdate.exe [21.9.2009 20:28 133104]
S3 appliand;Applian Network Service;h:\windows\system32\drivers\appliand.sys [24.6.2010 12:46 28256]
S3 GarenaPEngine;GarenaPEngine;\??\h:\docume~1\User\LOCALS~1\Temp\SVQCD0.tmp --> h:\docume~1\User\LOCALS~1\Temp\SVQCD0.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\h:\program files\Garena\safedrv.sys --> h:\program files\Garena\safedrv.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;h:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 scrcap;scrcap;h:\windows\system32\DRIVERS\scrcap.sys --> h:\windows\system32\DRIVERS\scrcap.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2011-02-25 h:\windows\Tasks\AppleSoftwareUpdate.job
- h:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

2011-03-03 h:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- h:\program files\Google\Update\GoogleUpdate.exe [2009-09-21 19:27]

2011-03-03 h:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- h:\program files\Google\Update\GoogleUpdate.exe [2009-09-21 19:27]

2011-03-03 h:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003Core.job
- h:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-10 21:48]

2011-03-03 h:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003UA.job
- h:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-10 21:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovať do programu Microsoft Excel - h:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - h:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - h:\program files\PartyGaming\PartyCasino\RunApp.exe
FF - ProfilePath - h:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h95c5kbz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2086743&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2086743&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2086743&q=
FF - Ext: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - h:\program files\Mozilla Firefox\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - h:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Russian spellchecking dictionary: ru@dictionaries.addons.mozilla.org - %profile%\extensions\ru@dictionaries.addons.mozilla.org
FF - Ext: ToggleEN Community Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - %profile%\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: PHPNukeEN Community Toolbar: {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - %profile%\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - h:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

BHO-{b23920f4-4c2f-412b-9450-1d7028d5454e} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-services.exe - h:\windows\services.exe
HKCU-Run-BitComet - h:\program files\BitComet\BitComet.exe
HKCU-Run-Uniblue RegistryBooster 2009 - h:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKCU-Run-eehl - h:\documents and settings\User\Application Data\eehl\eehl.exe
HKCU-Run-EA Core - h:\program files\Electronic Arts\EADM\Core.exe
HKCU-Run-svchosts.exe - h:\documents and settings\User\Application Data\Microsoft\svchosts.exe
HKCU-Run-RegistryBooster - h:\program files\Uniblue\RegistryBooster\launcher.exe
HKCU-Run-RGSC - h:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
HKLM-Run-mspaint - h:\windows\system32\Paint.exe
AddRemove-Nero - Burning Rom!UninstallKey - h:\program files\Nero\Nero8\\nero\uninstall\UNNERO.exe
AddRemove-RNCompiler 6.0 - h:\program files\Adobe\Premiere 6.0\Plug-ins\RNCompiler\rnuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-04 00:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Z810SysStart = h:\program files\Connection Manager\sysctrl.exe??p=??????????????9?Z}??????Z????????????59?Z?p=??p=?<?A?I:?Z????<?A?????????????<?A?????4?A~????}??????????????????????????????? ?B~??A~????????Z?A~@???*?A~???????????????????????????????????????????????????
Z810PNP = h:\program files\Connection Manager\SamsungPnPServiceManager.exe???|???|????h???l????@??X???????@???`???@???`??????|????X???????X???????????????????????????????????d??????????|0???0???A??||??????????|P???H???A??|????]??|????X??????|????????=??w????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Z810SysStart = h:\program files\Connection Manager\sysctrl.exe??p=??????????????9?Z}??????Z????????????59?Z?p=??p=?<?A?I:?Z????<?A?????????????<?A?????4?A~????}??????????????????????????????? ?B~??A~????????Z?A~@???*?A~???????????????????????????????????????????????????
Z810PNP = h:\program files\Connection Manager\SamsungPnPServiceManager.exe???|???|????h???l????@??X???????@???`???@???`??????|????X???????X???????????????????????????????????d??????????|0???0???A??||??????????|P???H???A??|????]??|????X??????|????????=??w????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\h:\docume~1\User\LOCALS~1\Temp\SVQCD0.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1960408961-413027322-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:7a,16,3e,ea,9c,cb,a5,1d,63,e7,33,01,72,69,6b,05,3b,96,50,3d,0b,
8c,24,6b,54,fa,25,93,aa,0b,bc,d0,95,ec,0f,97,a4,dc,07,1d,89,68,16,4d,01,94,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2224)
h:\windows\system32\msi.dll
h:\windows\system32\WPDShServiceObj.dll
h:\windows\system32\PortableDeviceTypes.dll
h:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
h:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
h:\program files\Bonjour\mDNSResponder.exe
h:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
h:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
h:\windows\system32\nvsvc32.exe
h:\windows\system32\IoctlSvc.exe
h:\windows\system32\PnkBstrA.exe
h:\windows\system32\PnkBstrB.exe
h:\windows\RTHDCPL.EXE
h:\windows\system32\rundll32.exe
h:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
h:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
h:\program files\OpenOffice.org 3\program\soffice.exe
h:\program files\OpenOffice.org 3\program\soffice.bin
h:\windows\system32\wscntfy.exe
h:\program files\Windows Media Player\WMPNetwk.exe
h:\program files\Common Files\Nero\Lib\NMIndexingService.exe
h:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-03-04 00:16:24 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-03 23:16

Pre-Run: 43 570 233 344 bytes free
Post-Run: 50 641 723 392 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 5EDC3C9622FF4FAB7A2B917B11C197EE

Re: Pro Vyosek

Napsal: 04 bře 2011 07:49
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    "Google Update"=-
    "WMPNSCFG"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NokiaMServer"=-
    "HP Software Update"=-
    "iTunesHelper"=-
    "DivXUpdate"=-
    "QuickTime Task"=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    
    File::
    H:\WINDOWS\tasks\AppleSoftwareUpdate.job
    H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003Core.job
    H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003UA.job
    
    Firefox::
    FF - ProfilePath - h:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h95c5kbz.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT20867 ... hSource=13
    FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2086743&q=
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Pro Vyosek

Napsal: 04 bře 2011 13:53
od Peter
Dobrý deň tu je ten log po vložení txt. súboru do combofixu. Len PC sa ešte viac pokazil dáko zas keď som ho ráno zapínal lebo hneď pri zapnutí akoby cez text bielo-žlté čiary nabehli, potom keď mi načitávalo XP už to kde máte logo windowsu a pod tým vám tie kocky v obĺžniku behajú tak po načítaní len čierna plocha ostala a nefungovalo nič ani správca tak som stále v núdzovom režime. No neviem olatí sa s tým ešte párať či už radšej reinstal to celé.

ComboFix 11-03-03.01 - User 04.03.2011 13:30:56.2.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1022.776 [GMT 1:00]
Running from: h:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: h:\documents and settings\User\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

FILE ::
"h:\windows\tasks\AppleSoftwareUpdate.job"
"h:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"h:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"h:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003Core.job"
"h:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003UA.job"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

h:\windows\tasks\AppleSoftwareUpdate.job
h:\windows\tasks\GoogleUpdateTaskMachineCore.job
h:\windows\tasks\GoogleUpdateTaskMachineUA.job
h:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003Core.job
h:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-413027322-725345543-1003UA.job

.
((((((((((((((((((((((((( Files Created from 2011-02-04 to 2011-03-04 )))))))))))))))))))))))))))))))
.

2011-03-01 16:16 . 2011-03-01 16:16 -------- d-----w- h:\windows\system32\wbem\Repository
2011-02-27 12:20 . 2011-02-27 12:21 -------- d-----w- H:\rsit
2011-02-27 12:20 . 2011-02-27 12:20 -------- d-----w- h:\program files\trend micro
2011-02-26 07:31 . 2011-02-26 07:31 -------- d-----w- h:\documents and settings\User\Application Data\LolClient
2011-02-26 07:13 . 2008-07-31 09:41 68616 ----a-w- h:\windows\system32\XAPOFX1_1.dll
2011-02-26 07:13 . 2008-07-31 09:40 509448 ----a-w- h:\windows\system32\XAudio2_2.dll
2011-02-26 07:13 . 2008-07-12 07:18 1493528 ----a-w- h:\windows\system32\D3DCompiler_39.dll
2011-02-26 07:00 . 2011-02-27 16:15 -------- d-----w- H:\Riot Games
2011-02-25 22:16 . 2011-02-26 07:50 -------- d-----w- h:\documents and settings\User\Local Settings\Application Data\PMB Files
2011-02-25 22:16 . 2011-02-25 22:16 -------- d-----w- h:\documents and settings\All Users\Application Data\PMB Files
2011-02-25 22:15 . 2011-02-25 22:15 -------- d-----w- h:\program files\Pando Networks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 23:19 . 2010-11-18 10:46 0 ----a-w- h:\windows\system32\ConduitEngine.tmp
2011-01-21 14:44 . 2007-07-27 12:00 439296 ----a-w- h:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2007-07-27 12:00 290048 ----a-w- h:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2007-07-27 12:00 1854976 ----a-w- h:\windows\system32\win32k.sys
2010-12-22 12:34 . 2007-07-27 12:00 301568 ----a-w- h:\windows\system32\kerberos.dll
2010-12-20 22:15 . 2007-07-27 12:00 667136 ----a-w- h:\windows\system32\wininet.dll
2010-12-20 22:15 . 2007-07-27 12:00 61952 ----a-w- h:\windows\system32\tdc.ocx
2010-12-20 22:15 . 2007-07-27 12:00 81920 ----a-w- h:\windows\system32\ieencode.dll
2010-12-20 17:26 . 2007-07-27 12:00 730112 ----a-w- h:\windows\system32\lsasrv.dll
2010-12-20 15:30 . 2007-07-27 12:00 369664 ----a-w- h:\windows\system32\html.iec
2010-12-09 15:15 . 2007-07-27 12:00 718336 ----a-w- h:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2007-07-27 12:00 33280 ----a-w- h:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2007-07-27 12:00 2148864 ----a-w- h:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-03 22:59 2027008 ----a-w- h:\windows\system32\ntkrnlpa.exe
2010-07-01 12:34 . 2010-07-01 12:34 1080658342 ----a-w- h:\program files\Combatarms_eu.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{dd02a4eb-4afd-4d60-99d8-e67f964ca813}"= "h:\program files\PHPNukeEN\prxtbPHP2.dll" [2011-01-17 175912]

[HKEY_CLASSES_ROOT\clsid\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- h:\program files\ConduitEngine\prxConduitEngine.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
2011-01-17 14:54 175912 ----a-w- h:\program files\PHPNukeEN\prxtbPHP2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{dd02a4eb-4afd-4d60-99d8-e67f964ca813}"= "h:\program files\PHPNukeEN\prxtbPHP2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "h:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]

[HKEY_CLASSES_ROOT\clsid\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DD02A4EB-4AFD-4D60-99D8-E67F964CA813}"= "h:\program files\PHPNukeEN\prxtbPHP2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "h:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]

[HKEY_CLASSES_ROOT\clsid\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Z810SysStart"="h:\program files\Connection Manager\sysctrl.exe" [2008-09-01 307200]
"Z810PNP"="h:\program files\Connection Manager\SamsungPnPServiceManager.exe" [2008-09-09 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="h:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]
"StatusClient 2.6"="h:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2003-10-03 61440]
"TomcatStartup 2.5"="h:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2003-07-25 155648]
"HPLJ Config"="h:\program files\Hewlett-Packard\hp LaserJet 3015_3020_3030_3380\SetConfig.exe" [2003-03-31 28672]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Z810SysStart"="h:\program files\Connection Manager\sysctrl.exe" [2008-09-01 307200]
"Z810PNP"="h:\program files\Connection Manager\SamsungPnPServiceManager.exe" [2008-09-09 122880]
"USBToolTip"="h:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"egui"="h:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
"USB2Check"="h:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

h:\documents and settings\User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - h:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-21 113664]
OpenOffice.org 3.0.lnk - h:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-13 393216]

h:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - h:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-21 113664]
InterVideo WinCinema Manager.lnk - h:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-4-4 184320]
McAfee Security Scan Plus.lnk - h:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"h:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"h:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"h:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\Program Files\\ICQ6.5\\ICQ.exe"=
"h:\\Program Files\\Messenger\\msmsgs.exe"=
"h:\\Documents and Settings\\User\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"h:\\Documents and Settings\\User\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"h:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"h:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"h:\\WINDOWS\\system32\\PnkBstrA.exe"=
"h:\\WINDOWS\\system32\\PnkBstrB.exe"=
"h:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"h:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"h:\\Documents and Settings\\User\\My Documents\\Preberanie\\MeGa Garena ExP hacK.exe"=
"h:\\Documents and Settings\\All Users\\Application Data\\NexonEU\\NGM\\NGM.exe"=
"h:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"h:\\Program Files\\iTunes\\iTunes.exe"=
"h:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"h:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"h:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"h:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"h:\\Program Files\\Goiceasoft Studios\\Counter Strike 1.8 Goiceasoft\\cstrike.exe"=
"h:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"h:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25381:TCP"= 25381:TCP:BitComet 25381 TCP
"25381:UDP"= 25381:UDP:BitComet 25381 UDP
"58999:TCP"= 58999:TCP:Pando Media Booster
"58999:UDP"= 58999:UDP:Pando Media Booster
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"6996:TCP"= 6996:TCP:League of Legends Launcher
"6996:UDP"= 6996:UDP:League of Legends Launcher
"6970:TCP"= 6970:TCP:League of Legends Launcher
"6970:UDP"= 6970:UDP:League of Legends Launcher

R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);h:\windows\system32\drivers\sfsync03.sys [13.10.2005 14:46 35328]
R1 epfwtdir;epfwtdir;h:\windows\system32\drivers\epfwtdir.sys [29.3.2010 16:13 95896]
R3 appliandMP;appliandMP;h:\windows\system32\drivers\appliand.sys [24.6.2010 12:46 28256]
S0 sptd;sptd;h:\windows\system32\drivers\sptd.sys [30.3.2010 14:04 691696]
S1 ehdrv;ehdrv;h:\windows\system32\drivers\ehdrv.sys [29.3.2010 16:12 115008]
S2 Application Updater;Application Updater;h:\program files\Application Updater\ApplicationUpdater.exe [8.1.2010 0:51 380928]
S2 ekrn;ESET Service;h:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.8.2010 13:16 810144]
S2 gupdate1ca3af1a336b4e2;Služba Google Update (gupdate1ca3af1a336b4e2);h:\program files\Google\Update\GoogleUpdate.exe [21.9.2009 20:28 133104]
S3 appliand;Applian Network Service;h:\windows\system32\drivers\appliand.sys [24.6.2010 12:46 28256]
S3 GarenaPEngine;GarenaPEngine;\??\h:\docume~1\User\LOCALS~1\Temp\SVQCD0.tmp --> h:\docume~1\User\LOCALS~1\Temp\SVQCD0.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\h:\program files\Garena\safedrv.sys --> h:\program files\Garena\safedrv.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;h:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 scrcap;scrcap;h:\windows\system32\DRIVERS\scrcap.sys --> h:\windows\system32\DRIVERS\scrcap.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovať do programu Microsoft Excel - h:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - h:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - h:\program files\PartyGaming\PartyCasino\RunApp.exe
FF - ProfilePath - h:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h95c5kbz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - Ext: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - h:\program files\Mozilla Firefox\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - h:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Russian spellchecking dictionary: ru@dictionaries.addons.mozilla.org - %profile%\extensions\ru@dictionaries.addons.mozilla.org
FF - Ext: ToggleEN Community Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - %profile%\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: PHPNukeEN Community Toolbar: {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - %profile%\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - h:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-04 13:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Z810SysStart = h:\program files\Connection Manager\sysctrl.exe??p=??????????????9?Z}??????Z????????????59?Z?p=??p=?<?A?I:?Z????<?A?????????????<?A?????4?A~????}??????????????????????????????? ?B~??A~????????Z?A~@???*?A~???????????????????????????????????????????????????
Z810PNP = h:\program files\Connection Manager\SamsungPnPServiceManager.exe????????????L??|???????|????]??|`??w???????????????????????????????????|????`???\???6 ?|t???`???????d??????????|0???0???A??||??????????|P???H???A??|????]??|????X??????|????????=??w?@?????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Z810SysStart = h:\program files\Connection Manager\sysctrl.exe??p=??????????????9?Z}??????Z????????????59?Z?p=??p=?<?A?I:?Z????<?A?????????????<?A?????4?A~????}??????????????????????????????? ?B~??A~????????Z?A~@???*?A~???????????????????????????????????????????????????
Z810PNP = h:\program files\Connection Manager\SamsungPnPServiceManager.exe????????????L??|???????|????]??|`??w???????????????????????????????????|????`???\???6 ?|t???`???????d??????????|0???0???A??||??????????|P???H???A??|????]??|????X??????|????????=??w?@?????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\h:\docume~1\User\LOCALS~1\Temp\SVQCD0.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1960408961-413027322-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:7a,16,3e,ea,9c,cb,a5,1d,63,e7,33,01,72,69,6b,05,3b,96,50,3d,0b,
8c,24,6b,54,fa,25,93,aa,0b,bc,d0,95,ec,0f,97,a4,dc,07,1d,89,68,16,4d,01,94,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2032)
h:\windows\system32\msi.dll
.
Completion time: 2011-03-04 13:48:03 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-04 12:48
ComboFix2.txt 2011-03-03 23:16

Pre-Run: 50 423 980 032 bytes free
Post-Run: 25 adresárov, 50 506 129 408 voľných bajtov

- - End Of File - - CDF9F47EA7298A247CE7698189424988

Re: Pro Vyosek

Napsal: 04 bře 2011 20:28
od vyosek
Vypada to na hodne naboreny system, pokud mate chut muzem se v tom rypat dal, nebo jestli Vam reinstal nevadi :o

Re: Pro Vyosek

Napsal: 05 bře 2011 01:06
od Peter
veď to práve neviem lebo nemám tam čo stratiť reinstalom ale na druhej strane zas formátovať celý disk ešte som to priamo ja nerobim nemám to dáko viac zmáknuté a nechcem zas robiť zbytočné chyby ale napíšte či sa to oplatí ešte zachraňovať alebo to bude len odialenie nezbytného :) lebo ak áno tak to asi radšej reinstalnem potom dáko. A ak by ste mi vedeli dať dáke rady k tomu reinstalu čo a ako, nejaký postup tak budem len rád :P .

Re: Pro Vyosek

Napsal: 05 bře 2011 08:58
od vyosek
Dle meho je ten system hodne naboreny a jeho oprava by byla hodne zdlouhava a nevim, zda-li uspesna...

Navod na reinstal je zde http://viry.cz/forum/viewtopic.php?f=46&t=2787

Re: Pro Vyosek

Napsal: 05 bře 2011 16:07
od Peter
Oukej tak ja to teda reinstallnem ale ajtak dík za ochotu a pomoc :)

Re: Pro Vyosek

Napsal: 05 bře 2011 17:25
od vyosek
Nemate zac :)