Tu je výpis:
ComboFix 12-12-01.02 - SlavoK 02.12.2012 10:29:09.16.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1554 [GMT 1:00]
Running from: c:\documents and settings\SlavoK\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\SlavoK\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\admintool.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\client.ini
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\ControlPanel.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\CplTasks.xml
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\euc_state.json
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\extraroot.pem
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\guid.ini
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\installer.txt
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\installer_no_upload_silent.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\csy.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\dan.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\deu.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\esp.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\fin.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\fra.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\chs.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\cht.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\ita.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\jpn.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\kor.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\nld.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\nor.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\plk.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\ptb.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\ptg.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\rus.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\sve.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Languages\trk.dll
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121125_233014.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121126_095926.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121127_051516.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121127_055755.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121127_104907.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121128_070751.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121128_231353.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121129_082447.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121129_232504.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121130_090639.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121130_153407.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121201_094349.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121201_163801.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121201_170446.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon.debug.log.121202_092315.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\daemon1.debug.log
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_104623.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_114623.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_124624.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_134625.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_144625.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_154626.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_164626.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_174627.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_184627.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_194628.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_204628.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_214629.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_224630.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121125_233015.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_095930.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_105930.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_115931.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_125931.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_135931.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_145931.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_155932.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121126_162625.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_051520.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_055756.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_104914.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_114915.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_124915.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_134916.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_144916.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_154916.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_164917.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_174918.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_184918.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_194919.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_204919.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_214920.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_224920.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121127_232033.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_070757.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_080757.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_090757.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_100758.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_110758.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_120759.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_130759.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_140759.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_150800.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_160800.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_170800.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_180800.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_190801.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_200801.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_210801.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_220802.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_230802.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121128_231355.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_082456.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_092457.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_102458.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_112458.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_122458.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_132458.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_142459.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_152459.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_162459.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_172500.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_182500.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_192501.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_202501.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_212502.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_222502.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121129_232502.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_090649.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_100649.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_110649.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_120650.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_130650.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_140650.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_150651.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121130_153408.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_094355.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_104356.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_114356.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_124357.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_134358.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_144358.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_154358.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121201_170452.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\Logs\debug.log.121202_092320.sent
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\netsession_installer.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\netsession_win.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\readme.txt
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\root.pem
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\rswinui.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\uninstall.exe
c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\user.dat
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA400
-------\Service_XDva400
.
.
((((((((((((((((((((((((( Files Created from 2012-11-02 to 2012-12-02 )))))))))))))))))))))))))))))))
.
.
2012-12-01 16:56 . 2012-12-01 16:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-12-01 16:56 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-01 16:28 . 2012-12-01 16:30 -------- d-----w- c:\documents and settings\All Users\Application Data\A4C975D6A60F7E4F0000A4C8D11282FD
2012-12-01 12:03 . 2012-12-01 12:06 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Adobe
2012-11-29 18:30 . 2012-11-29 18:30 -------- d-----w- c:\documents and settings\Guest\Application Data\Avira
2012-11-29 18:25 . 2012-11-29 18:25 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2012-11-27 12:09 . 2012-11-27 12:09 -------- d-----w- c:\documents and settings\SlavoK\Local Settings\Application Data\FLT
2012-11-26 18:59 . 2012-11-26 18:59 1409 ----a-w- c:\windows\QTFont.for
2012-11-21 10:24 . 2012-11-21 10:24 -------- d-----w- c:\documents and settings\SlavoK\Application Data\RenPy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-14 14:13 . 2012-10-17 10:38 83432 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-11-14 14:13 . 2012-10-17 10:38 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-11-14 14:13 . 2012-10-17 10:38 133824 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-10-08 20:45 . 2012-03-29 07:58 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-08 20:45 . 2011-08-12 12:34 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-24 21:16 . 2012-10-23 15:03 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-05 06:24 . 2012-06-07 15:07 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-05 06:24 . 2010-05-21 13:40 746984 ----a-w- c:\windows\system32\deployJava1.dll
2007-02-13 15:22 . 2010-01-09 13:34 947472 ----a-w- c:\program files\msjava.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2012-04-21 01:18 . 2012-05-03 15:26 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 73728]
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe" [2005-07-21 192512]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-11-26 384800]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoAutorun"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoRecentDocsNetHood"= 01000000
"NoSMMyDocs"= 01000000
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 03:42 110592 ----a-w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-10-08 04:50 1632360 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\Games\\Blur\\Blur.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58220:TCP"= 58220:TCP:Pando Media Booster
"58220:UDP"= 58220:UDP:Pando Media Booster
"1052:TCP"= 1052:TCP:Akamai NetSession Interface
.
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [17.10.2012 11:38 36552]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [17.10.2012 11:38 85280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1.12.2012 17:56 22856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1.12.2012 17:56 676936]
S3 1394hub;1394 Enabled Hub;c:\windows\system32\svchost.exe -k netsvcs [7.12.2009 13:52 14336]
S3 apf003;apf003;c:\windows\system32\apf003.sys [11.8.2012 17:19 13232]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\SlavoK\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\SlavoK\LOCALS~1\Temp\CFcatchme.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [5.4.2010 18:22 12416]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [8.5.2010 9:37 36608]
S3 ncvet.dll;ncvet.dll;\??\c:\windows\Temp\ncvet.dll --> c:\windows\Temp\ncvet.dll [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [24.2.2005 12:29 508288]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [8.5.2010 9:37 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [8.5.2010 9:37 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [8.5.2010 9:37 121856]
S3 USTOR2K;USB Mass Storage Windows Driver;c:\windows\system32\drivers\ustor2k.sys [5.4.2010 18:17 28928]
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 20:45]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = <local>
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\SlavoK\Application Data\Mozilla\Firefox\Profiles\ne6hvnge.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2012-10-15 10:19; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\documents and settings\SlavoK\Application Data\Mozilla\Firefox\Profiles\ne6hvnge.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2012-10-15 10:19;
adblockpopups@jessehakanen.net; c:\documents and settings\SlavoK\Application Data\Mozilla\Firefox\Profiles\ne6hvnge.default\extensions\
adblockpopups@jessehakanen.net.xpi
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
.
Supplementary scan did not complete!
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Akamai - c:\documents and settings\SlavoK\Local Settings\Application Data\Akamai\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-12-02 10:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3444)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\RunDLL32.exe
c:\windows\system32\rundll32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\nvsvc32.exe
c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\lxcccoms.exe
.
**************************************************************************
.
Completion time: 2012-12-02 10:45:15 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-07 17:21
ComboFix2.txt 2012-06-07 16:30
.
Pre-Run: 4 024 868 864 bytes free
Post-Run: 3 967 516 672 voľných bajtov
.
- - End Of File - - 23C96430F5487AE0C328C80EDA3F5EE4