Prosím o kontrolu
Napsal: 24 led 2013 15:14
Prosím o kontrolu logu.
Notebook bol dlho bez AntiViru, samozrejme pripojený na internet... Kamarát mi ho dal, lebo mu "sekal". Po nainštalovaní Aviry našlo nejaké malware a vírusy. No notebook stále seká, už nejde ani wifi.Nič sa s ním nedá robiť
Ďakujem
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.11.2
Run by doma at 15:01:13 on 2013-01-24
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1029.18.765.181 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\ProgramData\DatacardService\HWDeviceService.exe
C:\Windows\system32\srvany.exe
C:\Windows\KMService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
C:\Windows\system32\conhost.exe
C:\Program Files\PC Speed Maximizer\SPMSmartScan.exe
C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.0\ToolbarUpdater.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Protected Search\ProtectedSearch.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\WUDFHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\System32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k SDRSVC
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
uSearch Bar = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
uSearch Page = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mStart Page = hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
mSearch Bar = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mSearch Page = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mDefault_Search_URL = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mSearchAssistant = hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=c8931605000000000000000000000000&tlver=1.4.19.19&affID=19404
uURLSearchHooks: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
mURLSearchHooks: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
BHO: Certified Toolbar: {0de094f5-e894-48c7-b16f-338d64674721} - c:\users\doma\appdata\roaming\certifiedtoolbar\CertifiedToolbar.dll
BHO: Complitly: {0FB6A909-6086-458F-BD92-1F8EE10042A0} -
BHO: Conduit Engine : {30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: DealPly: {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - c:\program files\dealply\DealPlyIE.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll
BHO: delta Helper Object: {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - c:\program files\delta\delta\1.8.8.8\bh\delta.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: SFT_eng7 Toolbar: {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - c:\program files\sft_eng7\prxtbSFT0.dll
TB: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
TB: Conduit Engine : {30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files\conduitengine\prxConduitEngine.dll
TB: Certified Toolbar: {0de094f5-e894-48c7-b16f-338d64674721} - c:\users\doma\appdata\roaming\certifiedtoolbar\CertifiedToolbar.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Delta Toolbar: {82E1477C-B154-48D3-9891-33D83C26BCD3} - c:\program files\delta\delta\1.8.8.8\deltaTlbr.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMBgMonitor.exe"
uRun: [Google Update] "c:\users\doma\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
uRun: [PC Speed Maximizer] c:\program files\pc speed maximizer\SPMLauncher.exe
uRun: [Smart Driver Updater] c:\program files\smart driver updater\SDULauncher.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRun: [PrivitizeVPN] c:\program files\privitizevpn\PrivitizeVPN.exe /autorun
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {a9ff5a45-b433-4940-9299-de737a9c11f6} - {0de094f5-e894-48c7-b16f-338d64674721}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{55ED05D1-97D8-4977-83FB-4CBF5B24C3B2}\2656C6B696E6E233833616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{55ED05D1-97D8-4977-83FB-4CBF5B24C3B2}\D4C4C4C4 : DHCPNameServer = 10.54.0.1 8.8.8.8
TCP: Interfaces\{6ADF80B0-0BFC-412A-A92B-9732A8B9FD46} : NameServer = 213.151.200.31 213.151.208.162
TCP: Interfaces\{80375C5F-02ED-49DE-8423-76FC0CBBEB83} : NameServer = 213.151.200.31 213.151.208.162
TCP: Interfaces\{EDE079EC-AE80-4701-B1A8-A55AA0B1A39D} : NameServer = 213.151.200.31 213.151.208.162
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\13.3.0\ViProtocol.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= c:\progra~2\browse~2\261095~1.52\{c16c1~1\browse~1.dll c:\progra~1\zoomex\sprote~1.dll
SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 genuine.microsoft.com
Hosts: 127.0.0.1 mpa.one.microsoft.com
Hosts: 127.0.0.1 sls.microsoft.com
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\doma\appdata\roaming\mozilla\firefox\profiles\e1e7zuul.default\
FF - prefs.js: keyword.URL - hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd&q=
FF - prefs.js: browser.startup.homepage - hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
FF - prefs.js: browser.search.selectedEngine - Privitize VPN);
FF - prefs.js: browser.startup.homepage - hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
FF - prefs.js: browser.search.selectedEngine - Privitize VPNFF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\13.3.0\npsitesafety.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_11.dll
FF - plugin: c:\program files\java\jre7\bin\npoji610.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\users\doma\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extentions.y2layers.installId - cfe308f9-8172-472e-81e0-4ffcaacde0b8
FF - user.js: extentions.y2layers.defaultEnableAppsList - TwitTube,toprelatedtopics,dropdowndeals,ezlooker,bestvideodownloader,contenko
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=c8931605000000000000002100b6db25&q=
FF - user.js: extensions.BabylonToolbar.id - c8931605000000000000002100b6db25
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15678
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.4.9
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.4.9
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.4.916:26:54
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar_i.excTlbr - false
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=4912_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar.rvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - c8931605000000000000002100b6db25
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15727
FF - user.js: extensions.delta.vrsn - 1.8.8.8
FF - user.js: extensions.delta.vrsni - 1.8.8.8
FF - user.js: extensions.delta_i.vrsnTs - 1.8.8.820:39:06
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta_i.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta_i.excTlbr - false
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta_i.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-12-4 26984]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2013-1-16 36552]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2013-1-16 83944]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2012-9-20 73984]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2012-9-20 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [2012-9-20 11136]
S3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\drivers\ew_jucdcacm.sys [2012-9-20 89856]
S3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\drivers\ew_juextctrl.sys [2012-9-20 26624]
S3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\drivers\ew_juwwanecm.sys [2012-9-20 190976]
.
=============== File Associations ===============
.
FileExt: .txt: opendocument.WriterDocument.1 - HKCR\Unknown\Shell=c:\windows\system32\rundll32.exe c:\windows\system32\shell32.dll,OpenAs_RunDLL %1 [UserChoice] [default=openas]
.
=============== Created Last 30 ================
.
2013-01-23 20:06:29 -------- d-sh--w- c:\windows\system32\%APPDATA%
2013-01-23 18:12:18 -------- d-----w- c:\program files\PrivitizeVPN
2013-01-23 18:12:07 -------- d-----w- c:\programdata\CLSoft LTD
2013-01-23 18:11:52 -------- d-----w- c:\program files\ZoomEx
2013-01-23 18:10:54 -------- d-----w- c:\programdata\InstallMate
2013-01-22 19:39:41 -------- d-----w- c:\programdata\BrowserProtect
2013-01-22 19:39:41 -------- d-----w- c:\program files\DealPly
2013-01-22 19:39:22 -------- d-----w- c:\users\doma\appdata\roaming\Smart Driver Updater
2013-01-22 19:39:21 -------- d-----w- c:\program files\Smart Driver Updater
2013-01-22 19:39:16 -------- d-----w- c:\users\doma\appdata\roaming\CRDeltaTB
2013-01-22 19:39:05 -------- d-----w- c:\program files\Delta
2013-01-22 19:38:59 -------- d-----w- c:\users\doma\appdata\roaming\Delta
2013-01-22 19:38:13 -------- d-----w- c:\users\doma\appdata\roaming\PC Speed Maximizer
2013-01-22 19:37:49 -------- d-----w- c:\program files\PC Speed Maximizer
2013-01-22 19:37:18 -------- d-----w- c:\programdata\Babylon
2013-01-22 19:37:16 -------- d-----w- c:\users\doma\appdata\roaming\Babylon
2013-01-22 19:33:14 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-01-22 18:38:11 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2013-01-22 18:36:44 -------- d-----w- c:\users\doma\appdata\local\Apple
2013-01-22 18:34:55 -------- d-----w- c:\program files\Bonjour
2013-01-20 21:55:51 768512 ----a-w- c:\windows\system32\localspl.dll
2013-01-19 20:48:12 139264 ----a-w- c:\windows\system32\cryptsvc.dll
2013-01-19 20:48:12 1157632 ----a-w- c:\windows\system32\crypt32.dll
2013-01-19 20:48:12 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-01-19 20:46:08 177152 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-01-19 20:44:27 987136 ----a-w- c:\program files\common files\system\ado\msado15.dll
2013-01-19 20:43:32 1388544 ----a-w- c:\windows\system32\msxml6.dll
2013-01-19 20:42:19 627712 ----a-w- c:\windows\system32\usp10.dll
2013-01-19 20:42:13 316928 ----a-w- c:\windows\system32\spoolsv.exe
2013-01-19 20:40:33 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2013-01-19 20:40:32 1686016 ----a-w- c:\windows\system32\esent.dll
2013-01-19 20:40:32 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2013-01-19 20:40:30 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2013-01-19 20:40:30 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2013-01-19 20:40:29 74240 ----a-w- c:\windows\system32\fsutil.exe
2013-01-19 20:40:29 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2013-01-19 20:40:29 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2013-01-19 20:40:05 417792 ----a-w- c:\windows\system32\msdri.dll
2013-01-19 20:39:42 478208 ----a-w- c:\windows\system32\timedate.cpl
2013-01-19 20:36:28 1328640 ----a-w- c:\windows\system32\quartz.dll
2013-01-19 20:36:27 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-01-19 20:36:21 541184 ----a-w- c:\windows\system32\kerberos.dll
2013-01-19 20:36:16 2342400 ----a-w- c:\windows\system32\msi.dll
2013-01-19 20:36:10 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2013-01-19 20:34:57 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2013-01-19 20:34:56 57856 ----a-w- c:\windows\system32\rdpwsx.dll
2013-01-19 20:34:56 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2013-01-19 20:32:21 690688 ----a-w- c:\windows\system32\msvcrt.dll
2013-01-19 20:32:11 163328 ----a-w- c:\windows\system32\profsvc.dll
2013-01-19 20:32:05 78336 ----a-w- c:\windows\system32\synceng.dll
2013-01-19 20:31:57 204288 ----a-w- c:\windows\system32\upnp.dll
2013-01-19 20:31:49 204800 ----a-w- c:\windows\system32\WebClnt.dll
2013-01-19 20:31:48 80384 ----a-w- c:\windows\system32\davclnt.dll
2013-01-19 20:31:48 51200 ----a-w- c:\windows\system32\wscapi.dll
2013-01-19 20:31:48 350720 ----a-w- c:\windows\system32\winhttp.dll
2013-01-19 20:31:47 73728 ----a-w- c:\windows\system32\wscsvc.dll
2013-01-19 20:31:47 14336 ----a-w- c:\windows\system32\slwga.dll
2013-01-19 20:31:30 442880 ----a-w- c:\windows\system32\ntshrui.dll
2013-01-19 20:31:13 802304 ----a-w- c:\windows\system32\FntCache.dll
2013-01-19 08:25:35 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-01-19 08:25:35 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-01-19 08:11:31 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-01-19 08:11:31 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-01-19 08:11:31 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-01-19 08:08:10 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-01-19 08:08:10 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-01-19 08:08:07 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-01-19 08:08:07 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-01-19 08:08:02 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-01-19 08:08:01 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-01-19 08:08:00 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-01-19 08:06:20 5120 ----a-w- c:\windows\system32\wmi.dll
2013-01-19 08:06:20 19312 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-01-19 08:06:19 158720 ----a-w- c:\windows\system32\imagehlp.dll
2013-01-19 07:58:44 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-01-19 07:58:43 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2013-01-19 07:58:37 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2013-01-19 07:58:35 3181568 ----a-w- c:\windows\system32\mf.dll
2013-01-19 07:58:34 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-01-19 07:49:02 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2013-01-19 07:49:02 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-01-19 07:43:13 276992 ----a-w- c:\windows\system32\wcncsvc.dll
2013-01-18 20:34:06 3958128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-18 20:34:04 3902832 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-18 19:47:18 2344960 ----a-w- c:\windows\system32\win32k.sys
2013-01-18 19:35:05 2614784 ----a-w- c:\windows\explorer.exe
2013-01-18 17:58:31 1210736 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-01-18 17:57:00 400896 ----a-w- c:\windows\system32\srcore.dll
2013-01-18 17:50:58 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2013-01-18 17:50:58 369152 ----a-w- c:\windows\system32\secproc.dll
2013-01-18 17:50:58 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2013-01-18 17:50:58 320512 ----a-w- c:\windows\system32\RMActivate.exe
2013-01-18 17:50:58 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2013-01-18 17:50:57 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-01-18 17:50:57 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2013-01-18 17:50:57 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-01-18 17:50:40 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-01-18 17:50:17 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-01-18 17:49:59 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-01-18 17:49:55 31232 ----a-w- c:\windows\system32\prevhost.exe
2013-01-18 17:48:40 492032 ----a-w- c:\windows\system32\win32spl.dll
2013-01-18 17:45:23 219136 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-18 17:44:20 739840 ----a-w- c:\windows\system32\d2d1.dll
2013-01-18 17:44:20 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2013-01-18 17:44:18 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-01-18 17:44:18 1074176 ----a-w- c:\windows\system32\DWrite.dll
2013-01-18 17:44:17 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2013-01-18 17:44:10 245616 ----a-w- c:\windows\system32\drivers\volsnap.sys
2013-01-18 17:41:51 26496 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2013-01-18 17:09:46 -------- d-----w- c:\program files\bitComposer Games
2013-01-18 13:16:24 2048 ----a-w- c:\windows\system32\tzres.dll
2013-01-18 13:14:18 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-01-18 13:14:17 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-01-18 13:14:17 107520 ----a-w- c:\windows\system32\cdd.dll
2013-01-18 13:07:31 826368 ----a-w- c:\windows\system32\rdpcore.dll
2013-01-18 13:07:30 24064 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-01-18 12:21:33 2422272 ----a-w- c:\windows\system32\wucltux.dll
2013-01-18 12:21:06 88576 ----a-w- c:\windows\system32\wudriver.dll
2013-01-18 12:20:38 33792 ----a-w- c:\windows\system32\wuapp.exe
2013-01-18 12:20:38 171904 ----a-w- c:\windows\system32\wuwebv.dll
2013-01-16 14:00:21 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-01-16 13:59:39 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-01-16 13:59:21 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-01-16 13:56:53 -------- d-----w- c:\users\doma\appdata\local\Programs
2013-01-16 13:38:25 -------- d-----w- c:\windows\system32\appmgmt
2013-01-16 13:29:17 859552 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-16 13:28:36 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-16 13:15:27 -------- d-----w- c:\program files\Sony
2013-01-16 09:50:46 -------- d-----w- c:\program files\CCleaner
2013-01-16 09:28:45 -------- d-----w- c:\users\doma\appdata\roaming\Avira
2013-01-16 09:22:21 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-01-16 09:22:20 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-01-16 09:22:17 -------- d-----w- c:\programdata\Avira
2013-01-16 09:22:17 -------- d-----w- c:\program files\Avira
2013-01-07 12:55:22 -------- d-----w- c:\program files\Data Design Interactive
.
==================== Find3M ====================
.
2013-01-19 08:03:01 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-01-19 08:03:01 161792 ----a-w- c:\windows\system32\msls31.dll
2013-01-19 08:03:00 86528 ----a-w- c:\windows\system32\iesysprep.dll
2013-01-19 08:03:00 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-01-19 08:03:00 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-01-19 08:03:00 1129472 ----a-w- c:\windows\system32\wininet.dll
2013-01-19 08:03:00 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-01-16 13:28:15 780192 ----a-w- c:\windows\system32\deployJava1.dll
2012-12-07 05:04:20 308736 ----a-w- c:\windows\system32\Wpc.dll
2012-12-07 04:57:38 2576384 ----a-w- c:\windows\system32\gameux.dll
2012-12-04 15:02:56 26984 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-11-30 05:06:15 169984 ----a-w- c:\windows\system32\winsrv.dll
2012-11-30 05:00:06 293376 ----a-w- c:\windows\system32\KernelBase.dll
2012-11-30 03:07:41 271360 ----a-w- c:\windows\system32\conhost.exe
2012-11-30 02:51:41 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:51:41 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:51:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:51:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-25 11:54:06 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2012-11-25 11:54:06 110592 ----a-w- c:\windows\system32\OpenAL32.dll
.
============= FINISH: 15:03:26,82 ===============
Notebook bol dlho bez AntiViru, samozrejme pripojený na internet... Kamarát mi ho dal, lebo mu "sekal". Po nainštalovaní Aviry našlo nejaké malware a vírusy. No notebook stále seká, už nejde ani wifi.Nič sa s ním nedá robiť

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.11.2
Run by doma at 15:01:13 on 2013-01-24
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1029.18.765.181 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\ProgramData\DatacardService\HWDeviceService.exe
C:\Windows\system32\srvany.exe
C:\Windows\KMService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
C:\Windows\system32\conhost.exe
C:\Program Files\PC Speed Maximizer\SPMSmartScan.exe
C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.0\ToolbarUpdater.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Protected Search\ProtectedSearch.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\WUDFHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\System32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k SDRSVC
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
uSearch Bar = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
uSearch Page = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mStart Page = hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
mSearch Bar = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mSearch Page = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mDefault_Search_URL = hxxp://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
mSearchAssistant = hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=c8931605000000000000000000000000&tlver=1.4.19.19&affID=19404
uURLSearchHooks: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
mURLSearchHooks: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
BHO: Certified Toolbar: {0de094f5-e894-48c7-b16f-338d64674721} - c:\users\doma\appdata\roaming\certifiedtoolbar\CertifiedToolbar.dll
BHO: Complitly: {0FB6A909-6086-458F-BD92-1F8EE10042A0} -
BHO: Conduit Engine : {30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: DealPly: {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - c:\program files\dealply\DealPlyIE.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll
BHO: delta Helper Object: {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - c:\program files\delta\delta\1.8.8.8\bh\delta.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: SFT_eng7 Toolbar: {08D6B0B4-C132-470D-A8E2-AA2E9C3851C9} - c:\program files\sft_eng7\prxtbSFT0.dll
TB: SFT_eng7 Toolbar: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - c:\program files\sft_eng7\prxtbSFT0.dll
TB: Conduit Engine : {30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files\conduitengine\prxConduitEngine.dll
TB: Certified Toolbar: {0de094f5-e894-48c7-b16f-338d64674721} - c:\users\doma\appdata\roaming\certifiedtoolbar\CertifiedToolbar.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Delta Toolbar: {82E1477C-B154-48D3-9891-33D83C26BCD3} - c:\program files\delta\delta\1.8.8.8\deltaTlbr.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMBgMonitor.exe"
uRun: [Google Update] "c:\users\doma\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
uRun: [PC Speed Maximizer] c:\program files\pc speed maximizer\SPMLauncher.exe
uRun: [Smart Driver Updater] c:\program files\smart driver updater\SDULauncher.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRun: [PrivitizeVPN] c:\program files\privitizevpn\PrivitizeVPN.exe /autorun
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {a9ff5a45-b433-4940-9299-de737a9c11f6} - {0de094f5-e894-48c7-b16f-338d64674721}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{55ED05D1-97D8-4977-83FB-4CBF5B24C3B2}\2656C6B696E6E233833616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{55ED05D1-97D8-4977-83FB-4CBF5B24C3B2}\D4C4C4C4 : DHCPNameServer = 10.54.0.1 8.8.8.8
TCP: Interfaces\{6ADF80B0-0BFC-412A-A92B-9732A8B9FD46} : NameServer = 213.151.200.31 213.151.208.162
TCP: Interfaces\{80375C5F-02ED-49DE-8423-76FC0CBBEB83} : NameServer = 213.151.200.31 213.151.208.162
TCP: Interfaces\{EDE079EC-AE80-4701-B1A8-A55AA0B1A39D} : NameServer = 213.151.200.31 213.151.208.162
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\13.3.0\ViProtocol.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= c:\progra~2\browse~2\261095~1.52\{c16c1~1\browse~1.dll c:\progra~1\zoomex\sprote~1.dll
SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 genuine.microsoft.com
Hosts: 127.0.0.1 mpa.one.microsoft.com
Hosts: 127.0.0.1 sls.microsoft.com
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\doma\appdata\roaming\mozilla\firefox\profiles\e1e7zuul.default\
FF - prefs.js: keyword.URL - hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd&q=
FF - prefs.js: browser.startup.homepage - hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
FF - prefs.js: browser.search.selectedEngine - Privitize VPN);
FF - prefs.js: browser.startup.homepage - hxxp://searchab.com/?aff=7&uid=55f88916-6587-11e2-80c9-00248145e0dd
FF - prefs.js: browser.search.selectedEngine - Privitize VPNFF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\13.3.0\npsitesafety.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_11.dll
FF - plugin: c:\program files\java\jre7\bin\npoji610.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\users\doma\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extentions.y2layers.installId - cfe308f9-8172-472e-81e0-4ffcaacde0b8
FF - user.js: extentions.y2layers.defaultEnableAppsList - TwitTube,toprelatedtopics,dropdowndeals,ezlooker,bestvideodownloader,contenko
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=c8931605000000000000002100b6db25&q=
FF - user.js: extensions.BabylonToolbar.id - c8931605000000000000002100b6db25
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15678
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.4.9
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.4.9
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.4.916:26:54
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar_i.excTlbr - false
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=4912_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar.rvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - c8931605000000000000002100b6db25
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15727
FF - user.js: extensions.delta.vrsn - 1.8.8.8
FF - user.js: extensions.delta.vrsni - 1.8.8.8
FF - user.js: extensions.delta_i.vrsnTs - 1.8.8.820:39:06
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta_i.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta_i.excTlbr - false
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta_i.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-12-4 26984]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2013-1-16 36552]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2013-1-16 83944]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2012-9-20 73984]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2012-9-20 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [2012-9-20 11136]
S3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\drivers\ew_jucdcacm.sys [2012-9-20 89856]
S3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\drivers\ew_juextctrl.sys [2012-9-20 26624]
S3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\drivers\ew_juwwanecm.sys [2012-9-20 190976]
.
=============== File Associations ===============
.
FileExt: .txt: opendocument.WriterDocument.1 - HKCR\Unknown\Shell=c:\windows\system32\rundll32.exe c:\windows\system32\shell32.dll,OpenAs_RunDLL %1 [UserChoice] [default=openas]
.
=============== Created Last 30 ================
.
2013-01-23 20:06:29 -------- d-sh--w- c:\windows\system32\%APPDATA%
2013-01-23 18:12:18 -------- d-----w- c:\program files\PrivitizeVPN
2013-01-23 18:12:07 -------- d-----w- c:\programdata\CLSoft LTD
2013-01-23 18:11:52 -------- d-----w- c:\program files\ZoomEx
2013-01-23 18:10:54 -------- d-----w- c:\programdata\InstallMate
2013-01-22 19:39:41 -------- d-----w- c:\programdata\BrowserProtect
2013-01-22 19:39:41 -------- d-----w- c:\program files\DealPly
2013-01-22 19:39:22 -------- d-----w- c:\users\doma\appdata\roaming\Smart Driver Updater
2013-01-22 19:39:21 -------- d-----w- c:\program files\Smart Driver Updater
2013-01-22 19:39:16 -------- d-----w- c:\users\doma\appdata\roaming\CRDeltaTB
2013-01-22 19:39:05 -------- d-----w- c:\program files\Delta
2013-01-22 19:38:59 -------- d-----w- c:\users\doma\appdata\roaming\Delta
2013-01-22 19:38:13 -------- d-----w- c:\users\doma\appdata\roaming\PC Speed Maximizer
2013-01-22 19:37:49 -------- d-----w- c:\program files\PC Speed Maximizer
2013-01-22 19:37:18 -------- d-----w- c:\programdata\Babylon
2013-01-22 19:37:16 -------- d-----w- c:\users\doma\appdata\roaming\Babylon
2013-01-22 19:33:14 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-01-22 18:38:11 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2013-01-22 18:36:44 -------- d-----w- c:\users\doma\appdata\local\Apple
2013-01-22 18:34:55 -------- d-----w- c:\program files\Bonjour
2013-01-20 21:55:51 768512 ----a-w- c:\windows\system32\localspl.dll
2013-01-19 20:48:12 139264 ----a-w- c:\windows\system32\cryptsvc.dll
2013-01-19 20:48:12 1157632 ----a-w- c:\windows\system32\crypt32.dll
2013-01-19 20:48:12 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-01-19 20:46:08 177152 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-01-19 20:44:27 987136 ----a-w- c:\program files\common files\system\ado\msado15.dll
2013-01-19 20:43:32 1388544 ----a-w- c:\windows\system32\msxml6.dll
2013-01-19 20:42:19 627712 ----a-w- c:\windows\system32\usp10.dll
2013-01-19 20:42:13 316928 ----a-w- c:\windows\system32\spoolsv.exe
2013-01-19 20:40:33 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2013-01-19 20:40:32 1686016 ----a-w- c:\windows\system32\esent.dll
2013-01-19 20:40:32 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2013-01-19 20:40:30 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2013-01-19 20:40:30 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2013-01-19 20:40:29 74240 ----a-w- c:\windows\system32\fsutil.exe
2013-01-19 20:40:29 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2013-01-19 20:40:29 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2013-01-19 20:40:05 417792 ----a-w- c:\windows\system32\msdri.dll
2013-01-19 20:39:42 478208 ----a-w- c:\windows\system32\timedate.cpl
2013-01-19 20:36:28 1328640 ----a-w- c:\windows\system32\quartz.dll
2013-01-19 20:36:27 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-01-19 20:36:21 541184 ----a-w- c:\windows\system32\kerberos.dll
2013-01-19 20:36:16 2342400 ----a-w- c:\windows\system32\msi.dll
2013-01-19 20:36:10 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2013-01-19 20:34:57 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2013-01-19 20:34:56 57856 ----a-w- c:\windows\system32\rdpwsx.dll
2013-01-19 20:34:56 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2013-01-19 20:32:21 690688 ----a-w- c:\windows\system32\msvcrt.dll
2013-01-19 20:32:11 163328 ----a-w- c:\windows\system32\profsvc.dll
2013-01-19 20:32:05 78336 ----a-w- c:\windows\system32\synceng.dll
2013-01-19 20:31:57 204288 ----a-w- c:\windows\system32\upnp.dll
2013-01-19 20:31:49 204800 ----a-w- c:\windows\system32\WebClnt.dll
2013-01-19 20:31:48 80384 ----a-w- c:\windows\system32\davclnt.dll
2013-01-19 20:31:48 51200 ----a-w- c:\windows\system32\wscapi.dll
2013-01-19 20:31:48 350720 ----a-w- c:\windows\system32\winhttp.dll
2013-01-19 20:31:47 73728 ----a-w- c:\windows\system32\wscsvc.dll
2013-01-19 20:31:47 14336 ----a-w- c:\windows\system32\slwga.dll
2013-01-19 20:31:30 442880 ----a-w- c:\windows\system32\ntshrui.dll
2013-01-19 20:31:13 802304 ----a-w- c:\windows\system32\FntCache.dll
2013-01-19 08:25:35 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-01-19 08:25:35 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-01-19 08:11:31 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-01-19 08:11:31 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-01-19 08:11:31 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-01-19 08:08:10 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-01-19 08:08:10 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-01-19 08:08:07 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-01-19 08:08:07 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-01-19 08:08:02 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-01-19 08:08:01 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-01-19 08:08:00 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-01-19 08:06:20 5120 ----a-w- c:\windows\system32\wmi.dll
2013-01-19 08:06:20 19312 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-01-19 08:06:19 158720 ----a-w- c:\windows\system32\imagehlp.dll
2013-01-19 07:58:44 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-01-19 07:58:43 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2013-01-19 07:58:37 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2013-01-19 07:58:35 3181568 ----a-w- c:\windows\system32\mf.dll
2013-01-19 07:58:34 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-01-19 07:49:02 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2013-01-19 07:49:02 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-01-19 07:43:13 276992 ----a-w- c:\windows\system32\wcncsvc.dll
2013-01-18 20:34:06 3958128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-18 20:34:04 3902832 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-18 19:47:18 2344960 ----a-w- c:\windows\system32\win32k.sys
2013-01-18 19:35:05 2614784 ----a-w- c:\windows\explorer.exe
2013-01-18 17:58:31 1210736 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-01-18 17:57:00 400896 ----a-w- c:\windows\system32\srcore.dll
2013-01-18 17:50:58 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2013-01-18 17:50:58 369152 ----a-w- c:\windows\system32\secproc.dll
2013-01-18 17:50:58 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2013-01-18 17:50:58 320512 ----a-w- c:\windows\system32\RMActivate.exe
2013-01-18 17:50:58 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2013-01-18 17:50:57 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-01-18 17:50:57 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2013-01-18 17:50:57 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-01-18 17:50:40 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-01-18 17:50:17 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-01-18 17:49:59 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-01-18 17:49:55 31232 ----a-w- c:\windows\system32\prevhost.exe
2013-01-18 17:48:40 492032 ----a-w- c:\windows\system32\win32spl.dll
2013-01-18 17:45:23 219136 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-18 17:44:20 739840 ----a-w- c:\windows\system32\d2d1.dll
2013-01-18 17:44:20 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2013-01-18 17:44:18 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-01-18 17:44:18 1074176 ----a-w- c:\windows\system32\DWrite.dll
2013-01-18 17:44:17 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2013-01-18 17:44:10 245616 ----a-w- c:\windows\system32\drivers\volsnap.sys
2013-01-18 17:41:51 26496 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2013-01-18 17:09:46 -------- d-----w- c:\program files\bitComposer Games
2013-01-18 13:16:24 2048 ----a-w- c:\windows\system32\tzres.dll
2013-01-18 13:14:18 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-01-18 13:14:17 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-01-18 13:14:17 107520 ----a-w- c:\windows\system32\cdd.dll
2013-01-18 13:07:31 826368 ----a-w- c:\windows\system32\rdpcore.dll
2013-01-18 13:07:30 24064 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-01-18 12:21:33 2422272 ----a-w- c:\windows\system32\wucltux.dll
2013-01-18 12:21:06 88576 ----a-w- c:\windows\system32\wudriver.dll
2013-01-18 12:20:38 33792 ----a-w- c:\windows\system32\wuapp.exe
2013-01-18 12:20:38 171904 ----a-w- c:\windows\system32\wuwebv.dll
2013-01-16 14:00:21 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-01-16 13:59:39 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-01-16 13:59:21 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-01-16 13:56:53 -------- d-----w- c:\users\doma\appdata\local\Programs
2013-01-16 13:38:25 -------- d-----w- c:\windows\system32\appmgmt
2013-01-16 13:29:17 859552 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-16 13:28:36 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-16 13:15:27 -------- d-----w- c:\program files\Sony
2013-01-16 09:50:46 -------- d-----w- c:\program files\CCleaner
2013-01-16 09:28:45 -------- d-----w- c:\users\doma\appdata\roaming\Avira
2013-01-16 09:22:21 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-01-16 09:22:20 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-01-16 09:22:17 -------- d-----w- c:\programdata\Avira
2013-01-16 09:22:17 -------- d-----w- c:\program files\Avira
2013-01-07 12:55:22 -------- d-----w- c:\program files\Data Design Interactive
.
==================== Find3M ====================
.
2013-01-19 08:03:01 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-01-19 08:03:01 161792 ----a-w- c:\windows\system32\msls31.dll
2013-01-19 08:03:00 86528 ----a-w- c:\windows\system32\iesysprep.dll
2013-01-19 08:03:00 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-01-19 08:03:00 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-01-19 08:03:00 1129472 ----a-w- c:\windows\system32\wininet.dll
2013-01-19 08:03:00 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-01-16 13:28:15 780192 ----a-w- c:\windows\system32\deployJava1.dll
2012-12-07 05:04:20 308736 ----a-w- c:\windows\system32\Wpc.dll
2012-12-07 04:57:38 2576384 ----a-w- c:\windows\system32\gameux.dll
2012-12-04 15:02:56 26984 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-11-30 05:06:15 169984 ----a-w- c:\windows\system32\winsrv.dll
2012-11-30 05:00:06 293376 ----a-w- c:\windows\system32\KernelBase.dll
2012-11-30 03:07:41 271360 ----a-w- c:\windows\system32\conhost.exe
2012-11-30 02:51:41 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:51:41 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:51:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:51:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-25 11:54:06 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2012-11-25 11:54:06 110592 ----a-w- c:\windows\system32\OpenAL32.dll
.
============= FINISH: 15:03:26,82 ===============