pro Motji,
Napsal: 18 lis 2011 12:59
LOG ComboFix
ComboFix 11-11-18.01 - Luky . 11. 2011 12:51:44.2.3 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.4093.2633 [GMT 1:00]
Running from: c:\users\Luky\Desktop\ComboFix.exe
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Spyware Doctor *Disabled/Outdated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-- Previous Run --
.
Infected copy of c:\windows\SysWow64\userinit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
.
--------
.
.
((((((((((((((((((((((((( Files Created from 2011-10-18 to 2011-11-18 )))))))))))))))))))))))))))))))
.
.
2011-11-18 11:56 . 2011-11-18 11:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-17 14:17 . 2011-11-17 14:17 -------- d-----w- C:\_OTL
2011-11-17 13:20 . 2011-11-17 13:20 -------- d-----w- c:\programdata\ATI
2011-11-17 13:20 . 2011-11-17 13:20 -------- d-----w- c:\program files (x86)\AMD APP
2011-11-16 09:43 . 2011-11-16 09:43 -------- d-----w- c:\windows\system32\Macromed
2011-11-12 10:50 . 2010-12-16 03:06 47232 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2011-11-12 10:50 . 2011-11-12 10:50 -------- dc----w- c:\windows\system32\DRVSTORE
2011-11-12 10:08 . 2011-04-27 14:37 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-11-12 10:08 . 2011-04-27 14:37 2074576 ----a-w- c:\windows\PCTBDCore.dll
2011-11-12 10:08 . 2011-04-27 14:37 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-11-12 10:08 . 2011-04-27 14:36 767952 ----a-w- c:\windows\BDTSupport.dll
2011-11-12 10:00 . 2010-07-16 13:53 816016 ----a-w- c:\windows\system32\drivers\pctEFA64.sys
2011-11-12 10:00 . 2010-06-29 09:35 452872 ----a-w- c:\windows\system32\drivers\pctDS64.sys
2011-11-12 10:00 . 2011-03-24 11:39 140800 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-11-12 10:00 . 2011-01-17 08:09 334976 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-11-12 10:00 . 2011-03-10 09:07 282440 ----a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-11-12 10:00 . 2011-03-10 08:08 279344 ----a-w- c:\windows\system32\drivers\PCTSD64.sys
2011-11-12 10:00 . 2010-12-16 06:46 92896 ----a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-11-12 09:59 . 2011-11-16 22:21 -------- d-----w- c:\program files (x86)\PC Tools Security
2011-11-12 09:59 . 2011-11-16 22:03 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2011-11-12 09:59 . 2011-11-12 10:00 -------- d-----w- c:\programdata\PC Tools
2011-11-10 18:29 . 2011-10-01 05:45 886784 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-10 18:29 . 2011-10-01 04:37 708608 ----a-w- c:\program files (x86)\Common Files\System\wab32.dll
2011-11-10 18:29 . 2011-09-29 04:03 3144704 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 18:29 . 2011-09-29 16:29 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-06 02:18 . 2011-11-06 02:18 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2011-11-05 16:48 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2011-11-05 16:14 . 2011-11-05 16:14 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-11-05 16:12 . 2010-12-17 11:40 715776 ----a-w- c:\windows\system32\kerberos.dll
2011-11-05 16:12 . 2010-12-17 07:07 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-11-05 16:12 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 16:12 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 16:09 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-11-05 16:08 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-11-05 16:07 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-11-05 15:30 . 2011-11-05 15:30 -------- d-----w- c:\programdata\Malwarebytes
2011-11-05 15:30 . 2010-11-29 16:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-11-05 15:30 . 2011-11-16 22:01 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-11-05 15:30 . 2010-11-29 16:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-05 15:20 . 2011-11-05 15:20 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-11-05 15:20 . 2011-11-05 15:20 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-11-05 15:19 . 2011-11-09 09:50 -------- d-----w- c:\windows\system32\drivers\NISx64
2011-11-05 15:19 . 2011-11-05 15:19 -------- d-----w- c:\program files (x86)\Norton Internet Security
2011-11-05 15:19 . 2011-11-05 17:44 -------- d-----w- c:\programdata\Norton
2011-11-05 15:19 . 2011-11-05 15:19 -------- d-----w- c:\program files (x86)\NortonInstaller
2011-11-03 22:46 . 2011-11-05 14:43 -------- d-----w- c:\program files (x86)\Vuze
2011-11-03 22:46 . 2011-11-03 22:46 -------- d-----w- c:\program files (x86)\Conduit
2011-11-01 20:00 . 2011-11-01 11:08 -------- d-----w- c:\windows\Panther
2011-11-01 20:00 . 2011-11-05 14:55 -------- d-----w- C:\Boot
2011-11-01 19:59 . 2011-11-01 19:59 -------- d-----w- c:\windows\system32\OEM
2011-11-01 15:25 . 2011-11-17 12:51 -------- d-----w- C:\Downloads
2011-11-01 15:16 . 2011-11-01 15:16 525544 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-01 15:16 . 2011-11-01 15:16 -------- d-----w- c:\program files\Java
2011-11-01 15:04 . 2011-11-01 15:04 -------- d-----w- c:\program files (x86)\VideoLAN
2011-11-01 14:48 . 2011-11-17 14:17 -------- d-----w- c:\program files (x86)\Ask.com
2011-11-01 14:47 . 2011-11-01 14:48 -------- d-----w- c:\program files (x86)\The KMPlayer
2011-11-01 14:45 . 2011-11-01 14:45 -------- d-----w- c:\program files (x86)\Free Download Manager
2011-11-01 14:19 . 2011-11-16 09:43 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\programdata\Ahead
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\program files (x86)\Common Files\Ahead
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\programdata\Nero
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\program files (x86)\Nero
2011-11-01 13:56 . 2011-11-01 13:56 -------- d-----w- c:\programdata\FLEXnet
2011-11-01 13:55 . 2011-11-01 13:55 -------- d-----w- c:\program files (x86)\Common Files\Macrovision Shared
2011-11-01 13:55 . 2008-04-07 04:38 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll
2011-11-01 13:53 . 2011-11-01 13:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-11-01 13:47 . 2011-11-01 13:47 -------- d-----w- c:\program files (x86)\AIMP2
2011-11-01 13:41 . 2003-06-12 22:25 7062 ----a-w- c:\windows\SysWow64\audiopid.vxd
2011-11-01 13:39 . 2005-06-15 10:09 10752 ----a-w- c:\windows\system32\INRES.DLL
2011-11-01 13:39 . 2005-06-15 10:07 11264 ----a-w- c:\windows\SysWow64\INRES.DLL
2011-11-01 13:39 . 2011-11-01 13:40 -------- d-----w- c:\program files (x86)\Creative
2011-11-01 13:39 . 2011-11-01 13:41 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2011-11-01 13:39 . 2011-11-01 13:39 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-11-01 13:33 . 2011-11-01 13:33 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2011-11-01 13:32 . 2011-11-05 18:17 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-11-01 13:32 . 2011-11-01 13:32 -------- d-----w- c:\windows\PCHEALTH
2011-11-01 13:32 . 2011-11-01 13:32 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2011-11-01 13:32 . 2011-11-01 13:32 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-11-01 13:06 . 2011-11-01 13:06 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-11-01 13:05 . 2011-11-01 13:05 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-11-01 13:05 . 2011-11-01 13:35 -------- d-----w- c:\programdata\Microsoft Help
2011-11-01 13:05 . 2011-11-01 13:05 -------- d-----r- C:\MSOCache
2011-11-01 13:00 . 2011-11-01 13:00 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-11-01 13:00 . 2011-11-01 13:00 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2011-11-01 13:00 . 2011-11-17 13:20 -------- d-----w- c:\programdata\AMD
2011-11-01 13:00 . 2010-02-18 08:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
2011-11-01 13:00 . 2011-11-01 13:00 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-11-01 12:59 . 2011-11-17 13:20 -------- d-----w- c:\program files\ATI Technologies
2011-11-01 12:59 . 2011-11-01 12:59 -------- d-----w- c:\program files\ATI
2011-11-01 12:59 . 2011-11-01 12:59 -------- d-----w- C:\ATI
2011-11-01 12:49 . 2011-11-01 12:49 -------- d-----w- c:\windows\SysWow64\Macromed
2011-11-01 12:26 . 2011-11-01 12:26 -------- d-----w- c:\windows\system32\SPReview
2011-11-01 12:17 . 2010-11-20 04:13 6144 ----a-w- c:\windows\system32\drivers\en-US\rdvgkmd.sys.mui
2011-11-01 12:17 . 2010-11-20 04:01 2560 ----a-w- c:\windows\system32\drivers\en-US\rdpwd.sys.mui
2011-11-01 12:17 . 2010-11-20 04:11 4096 ----a-w- c:\windows\system32\drivers\en-US\tsusbhub.sys.mui
2011-11-01 12:17 . 2010-11-20 03:57 3072 ----a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui
2011-11-01 12:17 . 2010-11-20 04:11 6144 ----a-w- c:\windows\system32\drivers\en-US\IPMIDrv.sys.mui
2011-11-01 12:17 . 2010-11-20 04:10 4608 ----a-w- c:\windows\system32\drivers\en-US\kbdclass.sys.mui
2011-11-01 12:10 . 2010-11-20 04:33 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\rdvgkmd.sys.mui
2011-11-01 12:10 . 2010-11-20 04:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2011-11-01 12:10 . 2010-11-20 04:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2011-11-01 12:10 . 2010-11-20 04:25 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbhub.sys.mui
2011-11-01 12:10 . 2010-11-20 04:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2011-11-01 12:10 . 2010-11-20 04:32 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2011-11-01 12:07 . 2010-11-20 04:32 2217856 ----a-w- c:\windows\system32\bootres.dll
2011-11-01 11:52 . 2011-10-18 01:27 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E2E05AA-D908-4085-A18F-958B52EDF55F}\mpengine.dll
2011-11-01 11:52 . 2011-05-24 18:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-11-01 11:35 . 2011-11-01 11:35 -------- d-----w- c:\windows\system32\EventProviders
2011-11-01 11:26 . 2011-11-01 11:26 -------- d-----w- c:\windows\system32\oodag
2011-11-01 11:25 . 2011-11-01 11:25 -------- d-----w- c:\program files\OO Software
2011-11-01 11:21 . 2011-11-01 11:21 -------- d-----w- c:\program files\CCleaner
2011-11-01 11:15 . 2011-11-01 11:15 -------- d-----w- c:\program files (x86)\Yamicsoft
2011-11-01 11:11 . 2011-08-15 12:19 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-11-01 11:11 . 2011-08-15 12:13 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-11-01 11:11 . 2011-08-15 12:13 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-11-01 11:11 . 2011-08-15 12:13 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-11-01 11:11 . 2011-08-15 12:13 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-11-01 11:10 . 2011-11-01 11:11 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011
2011-11-01 11:10 . 2011-11-01 11:11 -------- d-----w- c:\programdata\TuneUp Software
2011-11-01 11:10 . 2011-11-17 13:20 -------- d-sh--w- c:\windows\Installer
2011-11-01 11:10 . 2011-11-01 11:10 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-11-01 11:09 . 2011-11-05 14:56 -------- d-----w- c:\users\Luky
2011-11-01 11:07 . 2011-11-01 11:07 -------- d-----w- C:\Recovery
2011-11-01 11:03 . 2011-11-01 11:03 0 ----a-w- c:\windows\ativpsrm.bin
2011-10-26 03:05 . 2011-10-26 03:05 10496512 ----a-w- c:\windows\system32\drivers\atikmdag.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-05 17:26 . 2011-11-05 17:26 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-11-05 17:26 . 2011-11-05 17:26 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-11-01 12:22 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-01 12:22 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-10-26 02:05 . 2011-10-12 20:14 748544 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-10-26 02:04 . 2011-10-12 20:13 892416 ----a-w- c:\windows\system32\aticfx64.dll
2011-10-26 02:01 . 2011-10-12 20:10 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-10-26 01:55 . 2011-10-12 20:04 4292096 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-10-26 01:46 . 2009-07-13 21:59 5041664 ----a-w- c:\windows\system32\atidxx64.dll
2011-10-26 01:43 . 2011-10-12 19:44 4044288 ----a-w- c:\windows\system32\atiumd6a.dll
2011-10-26 01:29 . 2011-10-12 19:38 5510144 ----a-w- c:\windows\system32\atiumd64.dll
2011-10-26 01:29 . 2011-10-12 19:39 58880 ----a-w- c:\windows\system32\coinst.dll
2011-10-26 01:22 . 2011-10-12 19:31 486912 ----a-w- c:\windows\system32\atiadlxx.dll
2011-10-26 01:21 . 2011-10-12 19:29 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-10-26 01:21 . 2011-10-12 19:29 31744 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2011-10-26 01:21 . 2011-10-12 19:29 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-10-12 15:14 . 2011-10-12 15:14 51200 ----a-w- c:\windows\system32\OpenCL.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 15:54 175912 ----a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 15:54 175912 ----a-w- c:\program files (x86)\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"Free Download Manager"="c:\program files (x86)\Free Download Manager\fdm.exe" [2011-08-24 4197376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"P17RunE"="P17RunE.dll" [2008-03-28 14848]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-08-23 887976]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-11-29 443728]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-25 343168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
.
R0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\System32\drivers\SMR210.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-11-29 363344]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-11-01 79360]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2011-02-18 371472]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x]
S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1302000.00A\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1302000.00A\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20111114.002\BHDrvx64.sys [2011-11-14 1156216]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1302000.00A\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20111116.030_f0c\IDSvia64.sys [2011-11-04 488568]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1302000.00A\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1302000.00A\SYMNETS.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-10-25 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-04-27 337872]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.2.0.10\ccSvcHst.exe [2011-08-10 138760]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-06-29 3246920]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-08-15 2027840]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-17 138360]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-06-06 11856]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-06-29 3992904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Prevziať pomocou FDM - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: Prevziať video pomocou FDM - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Prevziať vybrané pomocou FDM - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Prevziať všetko pomocou FDM - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: Prevést cíl vazby do Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Prevést cíl vazby do existujícího PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Prevést do Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Pridat do stávajícího PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.10.1
FF - ProfilePath - c:\users\Luky\AppData\Roaming\Mozilla\Firefox\Profiles\w5p03w8b.default\
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.2.0.10\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.2.0.10\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="46235A41A522204D87A6F7EBBC5FB1DF1F951F6B0A21477DD6AE312E0D91EDDCFDB2E62B76D8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC7933A6171C11EC38DE3D9DB7CE019D40AA5CFD05CEED7B3E78A8FBA78A56644425D49D209D7CCEE0D66C1CF6BDD3BB918896BA3002314B05F9B8D983B06FDF3AC6399FEB19E248F7049C2B84FB917E8E76EC5D338A4D796FD3EFB1A5EB8C089015311F1C5B1DC09E575B930ACEA7800653DEF581367D79C2DAEDC36BC3B851086D40AD9844AD4E3359AF571E8D2C1891EF9A18FDF68D84F44928D3A7E018761413C160C2582D4D4673F6FD4DB44BE18000A35A03DE5F16B13CE32A2113DFF2DD2CDF51ED3C46D89CF6E51196E4473AD59CD0585D2AE76D58B43E9690C9DB09C2C21D9D5FBCB855B1160120EF60F146C642CA334DB2AF8FFD192765A49BE8BDD2C5CD6753C7D667B169A03DBF90B66D3ED0938D08FB56C4E8B2E16F7F44F9D952089AD3F76F89FA7EEBF301627F8E595B8BFB0FB7A90B19952D0689379E15E93ABF7F0DF16C4ABCAC7C7C82295F8BFA701DAAE3798414DC319B0193D4AF55C0B506CD41D698299E87DE90E2D602510503901A3BDBF94AA3A1F310EB589B6872A65A2C21B1F2C9588C3A59C42361196DCED69BC8E6191B477E0DC8F7B1AB8F58A19F1162829EE2E26B1AD3CDBB972E6F4244CEC391998760112792A0C7CF228F6E9BC83F3AE140FC0BEDD2A9BE64F08B7F112CE84A54A4D25BE1285375988AF989F776F443A8C0280409FB0741AD5684DD597EF770439DC010439BFE863CC6BBA3C40DC47501D72CA4A249974AF966E0E61F64335B89AD9395354E99BF9469BD2273D5F4221E8C8FEED68891D7753D6CD844D063D16BA5F50984799A551F97AD9D596ECE8AD6F9A497255AB058EF8AB6A692895392D1EC59B8622800F17E0E7D6033C6216627D07B88EF3534B05D9390F7372A534DCAFAF0A9643B4A33F798E06D1E243C612CD26ADD7FE35D38D5301426C021B627055E35128364FC2C759A52789C1E76992AD78B6B7E03F33B95CC9ABFA532D5BAD7B862DD1E2D21E085090EE994A329A2864BBD35FC05C179FAE944873CF28B93B9BCF82CF4F0C34DDA70955D52F2B1834E2CA1F56DAF16A70B9AF274C24EB7B2C9B63D51ADDFF55FC86DAEA402A272B6AD0D1F99A89B436DEE084F30D884BD0EC7023654D17DCB77CA336145B61ACFAB7A97DEC269B720E56FEE43198226860E189131F04F21DD6D7F877A75669735C52A845047CE4506237F9F7F43A79B7B8FC468BD967576C90B28C48CA2ED2B10DB5724A5AFDCDAD628317DF473169E0F637AA130E87B7DAE8C29D96C6D88395038C1D9D3B9F9E0F0EB3D01DC26FD3E33CF89E82040FA0B3126"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-18 12:58:45
ComboFix-quarantined-files.txt 2011-11-18 11:58
.
Pre-Run: 35 869 782 016 bytes free
Post-Run: 35 660 824 576 bytes free
.
- - End Of File - - 8E06FC675087944D67FE99C44DBE31A2
ComboFix 11-11-18.01 - Luky . 11. 2011 12:51:44.2.3 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.4093.2633 [GMT 1:00]
Running from: c:\users\Luky\Desktop\ComboFix.exe
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Spyware Doctor *Disabled/Outdated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-- Previous Run --
.
Infected copy of c:\windows\SysWow64\userinit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
.
--------
.
.
((((((((((((((((((((((((( Files Created from 2011-10-18 to 2011-11-18 )))))))))))))))))))))))))))))))
.
.
2011-11-18 11:56 . 2011-11-18 11:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-17 14:17 . 2011-11-17 14:17 -------- d-----w- C:\_OTL
2011-11-17 13:20 . 2011-11-17 13:20 -------- d-----w- c:\programdata\ATI
2011-11-17 13:20 . 2011-11-17 13:20 -------- d-----w- c:\program files (x86)\AMD APP
2011-11-16 09:43 . 2011-11-16 09:43 -------- d-----w- c:\windows\system32\Macromed
2011-11-12 10:50 . 2010-12-16 03:06 47232 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2011-11-12 10:50 . 2011-11-12 10:50 -------- dc----w- c:\windows\system32\DRVSTORE
2011-11-12 10:08 . 2011-04-27 14:37 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-11-12 10:08 . 2011-04-27 14:37 2074576 ----a-w- c:\windows\PCTBDCore.dll
2011-11-12 10:08 . 2011-04-27 14:37 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-11-12 10:08 . 2011-04-27 14:36 767952 ----a-w- c:\windows\BDTSupport.dll
2011-11-12 10:00 . 2010-07-16 13:53 816016 ----a-w- c:\windows\system32\drivers\pctEFA64.sys
2011-11-12 10:00 . 2010-06-29 09:35 452872 ----a-w- c:\windows\system32\drivers\pctDS64.sys
2011-11-12 10:00 . 2011-03-24 11:39 140800 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-11-12 10:00 . 2011-01-17 08:09 334976 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-11-12 10:00 . 2011-03-10 09:07 282440 ----a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-11-12 10:00 . 2011-03-10 08:08 279344 ----a-w- c:\windows\system32\drivers\PCTSD64.sys
2011-11-12 10:00 . 2010-12-16 06:46 92896 ----a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-11-12 09:59 . 2011-11-16 22:21 -------- d-----w- c:\program files (x86)\PC Tools Security
2011-11-12 09:59 . 2011-11-16 22:03 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2011-11-12 09:59 . 2011-11-12 10:00 -------- d-----w- c:\programdata\PC Tools
2011-11-10 18:29 . 2011-10-01 05:45 886784 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-10 18:29 . 2011-10-01 04:37 708608 ----a-w- c:\program files (x86)\Common Files\System\wab32.dll
2011-11-10 18:29 . 2011-09-29 04:03 3144704 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 18:29 . 2011-09-29 16:29 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-06 02:18 . 2011-11-06 02:18 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2011-11-05 16:48 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2011-11-05 16:14 . 2011-11-05 16:14 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-11-05 16:12 . 2010-12-17 11:40 715776 ----a-w- c:\windows\system32\kerberos.dll
2011-11-05 16:12 . 2010-12-17 07:07 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-11-05 16:12 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 16:12 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 16:09 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-11-05 16:08 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-11-05 16:07 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-11-05 15:30 . 2011-11-05 15:30 -------- d-----w- c:\programdata\Malwarebytes
2011-11-05 15:30 . 2010-11-29 16:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-11-05 15:30 . 2011-11-16 22:01 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-11-05 15:30 . 2010-11-29 16:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-05 15:20 . 2011-11-05 15:20 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-11-05 15:20 . 2011-11-05 15:20 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-11-05 15:19 . 2011-11-09 09:50 -------- d-----w- c:\windows\system32\drivers\NISx64
2011-11-05 15:19 . 2011-11-05 15:19 -------- d-----w- c:\program files (x86)\Norton Internet Security
2011-11-05 15:19 . 2011-11-05 17:44 -------- d-----w- c:\programdata\Norton
2011-11-05 15:19 . 2011-11-05 15:19 -------- d-----w- c:\program files (x86)\NortonInstaller
2011-11-03 22:46 . 2011-11-05 14:43 -------- d-----w- c:\program files (x86)\Vuze
2011-11-03 22:46 . 2011-11-03 22:46 -------- d-----w- c:\program files (x86)\Conduit
2011-11-01 20:00 . 2011-11-01 11:08 -------- d-----w- c:\windows\Panther
2011-11-01 20:00 . 2011-11-05 14:55 -------- d-----w- C:\Boot
2011-11-01 19:59 . 2011-11-01 19:59 -------- d-----w- c:\windows\system32\OEM
2011-11-01 15:25 . 2011-11-17 12:51 -------- d-----w- C:\Downloads
2011-11-01 15:16 . 2011-11-01 15:16 525544 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-01 15:16 . 2011-11-01 15:16 -------- d-----w- c:\program files\Java
2011-11-01 15:04 . 2011-11-01 15:04 -------- d-----w- c:\program files (x86)\VideoLAN
2011-11-01 14:48 . 2011-11-17 14:17 -------- d-----w- c:\program files (x86)\Ask.com
2011-11-01 14:47 . 2011-11-01 14:48 -------- d-----w- c:\program files (x86)\The KMPlayer
2011-11-01 14:45 . 2011-11-01 14:45 -------- d-----w- c:\program files (x86)\Free Download Manager
2011-11-01 14:19 . 2011-11-16 09:43 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\programdata\Ahead
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\program files (x86)\Common Files\Ahead
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\programdata\Nero
2011-11-01 14:03 . 2011-11-01 14:03 -------- d-----w- c:\program files (x86)\Nero
2011-11-01 13:56 . 2011-11-01 13:56 -------- d-----w- c:\programdata\FLEXnet
2011-11-01 13:55 . 2011-11-01 13:55 -------- d-----w- c:\program files (x86)\Common Files\Macrovision Shared
2011-11-01 13:55 . 2008-04-07 04:38 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll
2011-11-01 13:53 . 2011-11-01 13:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-11-01 13:47 . 2011-11-01 13:47 -------- d-----w- c:\program files (x86)\AIMP2
2011-11-01 13:41 . 2003-06-12 22:25 7062 ----a-w- c:\windows\SysWow64\audiopid.vxd
2011-11-01 13:39 . 2005-06-15 10:09 10752 ----a-w- c:\windows\system32\INRES.DLL
2011-11-01 13:39 . 2005-06-15 10:07 11264 ----a-w- c:\windows\SysWow64\INRES.DLL
2011-11-01 13:39 . 2011-11-01 13:40 -------- d-----w- c:\program files (x86)\Creative
2011-11-01 13:39 . 2011-11-01 13:41 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2011-11-01 13:39 . 2011-11-01 13:39 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-11-01 13:33 . 2011-11-01 13:33 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2011-11-01 13:32 . 2011-11-05 18:17 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-11-01 13:32 . 2011-11-01 13:32 -------- d-----w- c:\windows\PCHEALTH
2011-11-01 13:32 . 2011-11-01 13:32 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2011-11-01 13:32 . 2011-11-01 13:32 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-11-01 13:06 . 2011-11-01 13:06 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-11-01 13:05 . 2011-11-01 13:05 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-11-01 13:05 . 2011-11-01 13:35 -------- d-----w- c:\programdata\Microsoft Help
2011-11-01 13:05 . 2011-11-01 13:05 -------- d-----r- C:\MSOCache
2011-11-01 13:00 . 2011-11-01 13:00 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-11-01 13:00 . 2011-11-01 13:00 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2011-11-01 13:00 . 2011-11-17 13:20 -------- d-----w- c:\programdata\AMD
2011-11-01 13:00 . 2010-02-18 08:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
2011-11-01 13:00 . 2011-11-01 13:00 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-11-01 12:59 . 2011-11-17 13:20 -------- d-----w- c:\program files\ATI Technologies
2011-11-01 12:59 . 2011-11-01 12:59 -------- d-----w- c:\program files\ATI
2011-11-01 12:59 . 2011-11-01 12:59 -------- d-----w- C:\ATI
2011-11-01 12:49 . 2011-11-01 12:49 -------- d-----w- c:\windows\SysWow64\Macromed
2011-11-01 12:26 . 2011-11-01 12:26 -------- d-----w- c:\windows\system32\SPReview
2011-11-01 12:17 . 2010-11-20 04:13 6144 ----a-w- c:\windows\system32\drivers\en-US\rdvgkmd.sys.mui
2011-11-01 12:17 . 2010-11-20 04:01 2560 ----a-w- c:\windows\system32\drivers\en-US\rdpwd.sys.mui
2011-11-01 12:17 . 2010-11-20 04:11 4096 ----a-w- c:\windows\system32\drivers\en-US\tsusbhub.sys.mui
2011-11-01 12:17 . 2010-11-20 03:57 3072 ----a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui
2011-11-01 12:17 . 2010-11-20 04:11 6144 ----a-w- c:\windows\system32\drivers\en-US\IPMIDrv.sys.mui
2011-11-01 12:17 . 2010-11-20 04:10 4608 ----a-w- c:\windows\system32\drivers\en-US\kbdclass.sys.mui
2011-11-01 12:10 . 2010-11-20 04:33 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\rdvgkmd.sys.mui
2011-11-01 12:10 . 2010-11-20 04:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2011-11-01 12:10 . 2010-11-20 04:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2011-11-01 12:10 . 2010-11-20 04:25 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbhub.sys.mui
2011-11-01 12:10 . 2010-11-20 04:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2011-11-01 12:10 . 2010-11-20 04:32 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2011-11-01 12:07 . 2010-11-20 04:32 2217856 ----a-w- c:\windows\system32\bootres.dll
2011-11-01 11:52 . 2011-10-18 01:27 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E2E05AA-D908-4085-A18F-958B52EDF55F}\mpengine.dll
2011-11-01 11:52 . 2011-05-24 18:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-11-01 11:35 . 2011-11-01 11:35 -------- d-----w- c:\windows\system32\EventProviders
2011-11-01 11:26 . 2011-11-01 11:26 -------- d-----w- c:\windows\system32\oodag
2011-11-01 11:25 . 2011-11-01 11:25 -------- d-----w- c:\program files\OO Software
2011-11-01 11:21 . 2011-11-01 11:21 -------- d-----w- c:\program files\CCleaner
2011-11-01 11:15 . 2011-11-01 11:15 -------- d-----w- c:\program files (x86)\Yamicsoft
2011-11-01 11:11 . 2011-08-15 12:19 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-11-01 11:11 . 2011-08-15 12:13 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-11-01 11:11 . 2011-08-15 12:13 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-11-01 11:11 . 2011-08-15 12:13 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-11-01 11:11 . 2011-08-15 12:13 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-11-01 11:10 . 2011-11-01 11:11 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011
2011-11-01 11:10 . 2011-11-01 11:11 -------- d-----w- c:\programdata\TuneUp Software
2011-11-01 11:10 . 2011-11-17 13:20 -------- d-sh--w- c:\windows\Installer
2011-11-01 11:10 . 2011-11-01 11:10 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-11-01 11:09 . 2011-11-05 14:56 -------- d-----w- c:\users\Luky
2011-11-01 11:07 . 2011-11-01 11:07 -------- d-----w- C:\Recovery
2011-11-01 11:03 . 2011-11-01 11:03 0 ----a-w- c:\windows\ativpsrm.bin
2011-10-26 03:05 . 2011-10-26 03:05 10496512 ----a-w- c:\windows\system32\drivers\atikmdag.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-05 17:26 . 2011-11-05 17:26 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-11-05 17:26 . 2011-11-05 17:26 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2011-11-01 12:22 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-01 12:22 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-10-26 02:05 . 2011-10-12 20:14 748544 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-10-26 02:04 . 2011-10-12 20:13 892416 ----a-w- c:\windows\system32\aticfx64.dll
2011-10-26 02:01 . 2011-10-12 20:10 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-10-26 01:55 . 2011-10-12 20:04 4292096 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-10-26 01:46 . 2009-07-13 21:59 5041664 ----a-w- c:\windows\system32\atidxx64.dll
2011-10-26 01:43 . 2011-10-12 19:44 4044288 ----a-w- c:\windows\system32\atiumd6a.dll
2011-10-26 01:29 . 2011-10-12 19:38 5510144 ----a-w- c:\windows\system32\atiumd64.dll
2011-10-26 01:29 . 2011-10-12 19:39 58880 ----a-w- c:\windows\system32\coinst.dll
2011-10-26 01:22 . 2011-10-12 19:31 486912 ----a-w- c:\windows\system32\atiadlxx.dll
2011-10-26 01:21 . 2011-10-12 19:29 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-10-26 01:21 . 2011-10-12 19:29 31744 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2011-10-26 01:21 . 2011-10-12 19:29 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-10-12 15:14 . 2011-10-12 15:14 51200 ----a-w- c:\windows\system32\OpenCL.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 15:54 175912 ----a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 15:54 175912 ----a-w- c:\program files (x86)\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"Free Download Manager"="c:\program files (x86)\Free Download Manager\fdm.exe" [2011-08-24 4197376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"P17RunE"="P17RunE.dll" [2008-03-28 14848]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-08-23 887976]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-11-29 443728]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-25 343168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
.
R0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\System32\drivers\SMR210.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-11-29 363344]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-11-01 79360]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2011-02-18 371472]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x]
S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1302000.00A\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1302000.00A\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20111114.002\BHDrvx64.sys [2011-11-14 1156216]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1302000.00A\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20111116.030_f0c\IDSvia64.sys [2011-11-04 488568]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1302000.00A\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1302000.00A\SYMNETS.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-10-25 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-04-27 337872]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.2.0.10\ccSvcHst.exe [2011-08-10 138760]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-06-29 3246920]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-08-15 2027840]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-17 138360]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-06-06 11856]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-06-29 3992904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Prevziať pomocou FDM - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: Prevziať video pomocou FDM - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Prevziať vybrané pomocou FDM - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Prevziať všetko pomocou FDM - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: Prevést cíl vazby do Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Prevést cíl vazby do existujícího PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Prevést do Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Pridat do stávajícího PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.10.1
FF - ProfilePath - c:\users\Luky\AppData\Roaming\Mozilla\Firefox\Profiles\w5p03w8b.default\
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.2.0.10\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.2.0.10\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="46235A41A522204D87A6F7EBBC5FB1DF1F951F6B0A21477DD6AE312E0D91EDDCFDB2E62B76D8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC7933A6171C11EC38DE3D9DB7CE019D40AA5CFD05CEED7B3E78A8FBA78A56644425D49D209D7CCEE0D66C1CF6BDD3BB918896BA3002314B05F9B8D983B06FDF3AC6399FEB19E248F7049C2B84FB917E8E76EC5D338A4D796FD3EFB1A5EB8C089015311F1C5B1DC09E575B930ACEA7800653DEF581367D79C2DAEDC36BC3B851086D40AD9844AD4E3359AF571E8D2C1891EF9A18FDF68D84F44928D3A7E018761413C160C2582D4D4673F6FD4DB44BE18000A35A03DE5F16B13CE32A2113DFF2DD2CDF51ED3C46D89CF6E51196E4473AD59CD0585D2AE76D58B43E9690C9DB09C2C21D9D5FBCB855B1160120EF60F146C642CA334DB2AF8FFD192765A49BE8BDD2C5CD6753C7D667B169A03DBF90B66D3ED0938D08FB56C4E8B2E16F7F44F9D952089AD3F76F89FA7EEBF301627F8E595B8BFB0FB7A90B19952D0689379E15E93ABF7F0DF16C4ABCAC7C7C82295F8BFA701DAAE3798414DC319B0193D4AF55C0B506CD41D698299E87DE90E2D602510503901A3BDBF94AA3A1F310EB589B6872A65A2C21B1F2C9588C3A59C42361196DCED69BC8E6191B477E0DC8F7B1AB8F58A19F1162829EE2E26B1AD3CDBB972E6F4244CEC391998760112792A0C7CF228F6E9BC83F3AE140FC0BEDD2A9BE64F08B7F112CE84A54A4D25BE1285375988AF989F776F443A8C0280409FB0741AD5684DD597EF770439DC010439BFE863CC6BBA3C40DC47501D72CA4A249974AF966E0E61F64335B89AD9395354E99BF9469BD2273D5F4221E8C8FEED68891D7753D6CD844D063D16BA5F50984799A551F97AD9D596ECE8AD6F9A497255AB058EF8AB6A692895392D1EC59B8622800F17E0E7D6033C6216627D07B88EF3534B05D9390F7372A534DCAFAF0A9643B4A33F798E06D1E243C612CD26ADD7FE35D38D5301426C021B627055E35128364FC2C759A52789C1E76992AD78B6B7E03F33B95CC9ABFA532D5BAD7B862DD1E2D21E085090EE994A329A2864BBD35FC05C179FAE944873CF28B93B9BCF82CF4F0C34DDA70955D52F2B1834E2CA1F56DAF16A70B9AF274C24EB7B2C9B63D51ADDFF55FC86DAEA402A272B6AD0D1F99A89B436DEE084F30D884BD0EC7023654D17DCB77CA336145B61ACFAB7A97DEC269B720E56FEE43198226860E189131F04F21DD6D7F877A75669735C52A845047CE4506237F9F7F43A79B7B8FC468BD967576C90B28C48CA2ED2B10DB5724A5AFDCDAD628317DF473169E0F637AA130E87B7DAE8C29D96C6D88395038C1D9D3B9F9E0F0EB3D01DC26FD3E33CF89E82040FA0B3126"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-18 12:58:45
ComboFix-quarantined-files.txt 2011-11-18 11:58
.
Pre-Run: 35 869 782 016 bytes free
Post-Run: 35 660 824 576 bytes free
.
- - End Of File - - 8E06FC675087944D67FE99C44DBE31A2