Ano , to mi je jasne , len ten log mal viac ako 60000 znakov , preto som to musel rozdelit... prepacte . a davam log z combofix:
ComboFix 10-01-14.02 - jarka . 01. 2010 9:08.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.421.1051.18.1975.839 [GMT 1:00]
Running from: c:\users\jarka\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\components\config.ini
c:\program files\Dealio Toolbar\FF\components\dealioToolbarFF.dll
c:\program files\Dealio Toolbar\FF\components\IFBHOHelperWidgiToolbar.xpt
c:\program files\Dealio Toolbar\FF\components\IFBHOWidgiToolbar.xpt
c:\program files\Dealio Toolbar\FF\chrome.manifest
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
c:\program files\Dealio Toolbar\FF\chrome\content\login.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.xul
c:\program files\Dealio Toolbar\FF\chrome\content\parser.js
c:\program files\Dealio Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgicomm.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgihandling.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgichevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgilisteners.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgiui.js
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\yahoo-search.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
c:\program files\Dealio Toolbar\FF\chrome\skin\separator.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\IE\4.0.2\config.ini
c:\program files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\SeARchsettings.dll
c:\program files\Dealio Toolbar\SearchSettings.exe
c:\program files\Dealio Toolbar\SearchSettingsRes409.dll
c:\program files\Dealio Toolbar\sscfg.ini
c:\program files\Dealio Toolbar\SSFF\components\IFBHOSearch.xpt
c:\program files\Dealio Toolbar\SSFF\components\IFBHOSearchHelperEngine.xpt
c:\program files\Dealio Toolbar\SSFF\components\IFHelperPreferences.xpt
c:\program files\Dealio Toolbar\SSFF\components\SearchSettingsFF.dll
c:\program files\Dealio Toolbar\SSFF\components\sscfg.ini
c:\program files\Dealio Toolbar\SSFF\chrome.manifest
c:\program files\Dealio Toolbar\SSFF\chrome\content\plugin.js
c:\program files\Dealio Toolbar\SSFF\chrome\content\plugin.xul
c:\program files\Dealio Toolbar\SSFF\chrome\content\protection.js
c:\program files\Dealio Toolbar\SSFF\chrome\content\utils.js
c:\program files\Dealio Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\Dealio Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\Dealio Toolbar\SSFF\chrome\skin\yahoo.xml
c:\program files\Dealio Toolbar\SSFF\install.rdf
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
.
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.
2010-01-15 08:06 . 2010-01-15 08:07 -------- d-----w- C:\32788R22FWJFW
2010-01-14 17:06 . 2010-01-14 17:06 -------- d-----w- c:\users\jarka\AppData\Local\ESET
2010-01-13 06:52 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 06:52 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-12 10:00 . 2010-01-12 10:00 -------- d-----w- C:\rsit
2010-01-12 10:00 . 2010-01-12 10:00 -------- d-----w- c:\program files\trend micro
2010-01-11 13:46 . 2010-01-14 18:40 -------- d-----w- C:\BARDIWIN
2010-01-11 08:13 . 2008-05-14 19:06 17664 ----a-w- c:\windows\system32\drivers\EMP_UDAU.sys
2010-01-11 08:13 . 2010-01-11 08:13 -------- d-----w- c:\program files\EPSON Projector
2010-01-08 19:32 . 2010-01-08 19:32 -------- d-----w- c:\program files\Pivot Stickfigure Animator
2010-01-08 19:07 . 2010-01-08 19:07 -------- d-----w- c:\users\jarka\imagine_dipl_1
2010-01-08 18:11 . 2010-01-08 18:11 -------- d-----w- c:\users\jarka\Čítanie s porozumením
2010-01-08 17:17 . 2010-01-08 17:17 -------- d-----w- c:\users\jarka\Kde žijú živočíchy_
2010-01-05 18:12 . 2010-01-05 18:12 -------- d-----w- c:\program files\Common Files\Apple
2010-01-05 18:11 . 2010-01-05 18:11 -------- d-----w- c:\users\jarka\AppData\Local\Apple
2010-01-05 18:11 . 2010-01-05 18:11 -------- d-----w- c:\program files\Apple Software Update
2010-01-05 18:11 . 2010-01-05 18:11 -------- d-----w- c:\programdata\Apple
2010-01-01 18:52 . 2010-01-01 18:52 -------- d-----w- c:\program files\Drawing for Children
2010-01-01 18:31 . 2010-01-02 19:45 -------- d-----w- c:\program files\HotPotatoes6
2010-01-01 14:57 . 2010-01-03 09:51 -------- d-----w- c:\program files\Ahead
2009-12-31 18:12 . 2009-12-31 18:12 -------- d-----w- c:\programdata\Recisio
2009-12-31 18:12 . 2009-12-31 18:12 -------- d-----w- c:\program files\KaraFun
2009-12-31 17:57 . 2009-12-31 17:57 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-12-31 17:52 . 2009-12-31 18:21 -------- d-----w- c:\programdata\Norton
2009-12-31 17:52 . 2009-12-31 17:56 -------- d-----w- c:\programdata\Symantec
2009-12-31 17:52 . 2009-12-31 17:52 -------- d-----w- c:\programdata\NortonInstaller
2009-12-31 17:45 . 2009-12-31 17:45 -------- d-----w- c:\windows\system32\Adobe
2009-12-31 11:55 . 2009-12-31 11:55 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-31 11:38 . 2010-01-12 06:33 -------- d-----w- c:\users\Public\Ticket
2009-12-31 11:38 . 2009-12-31 11:38 -------- d-----w- c:\users\jarka\AppData\Roaming\Configuration
2009-12-31 11:38 . 2009-12-31 11:38 -------- d-----w- c:\program files\Luidia
2009-12-31 11:38 . 2009-11-30 10:18 106496 ----a-w- c:\windows\system32\BuEResNT.dll
2009-12-31 11:38 . 2008-03-28 02:46 165176 ----a-w- c:\windows\system32\BuEAppNT.exe
2009-12-31 11:38 . 2008-03-28 02:46 251192 ----a-w- c:\windows\system32\BuERmvNT.dll
2009-12-31 11:38 . 2008-03-28 02:46 359232 ----a-w- c:\windows\system32\BuEMonNT.dll
2009-12-31 11:38 . 2008-03-28 02:37 230712 ----a-w- c:\windows\system32\BiImgUser.dll
2009-12-31 11:38 . 2008-03-28 02:37 165168 ----a-w- c:\windows\system32\JPEG32.dll
2009-12-31 11:38 . 2008-03-28 02:37 374064 ----a-w- c:\windows\system32\Tiff32.dll
2009-12-31 11:38 . 2008-03-28 02:46 25928 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\BuEProNT.dll
2009-12-30 07:05 . 2009-12-30 07:05 -------- d-----w- C:\ConvertTemp
2009-12-30 05:48 . 2009-12-30 05:48 -------- d-----w- c:\users\jarka\AppData\Roaming\Samsung
2009-12-30 05:28 . 2006-07-24 15:05 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-12-30 05:26 . 2007-07-03 16:00 9256 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2009-12-30 05:26 . 2007-07-03 16:00 9256 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2009-12-30 05:26 . 2007-07-03 15:58 106792 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2009-12-30 05:26 . 2007-07-03 15:57 11944 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2009-12-30 05:26 . 2007-07-03 15:56 9256 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2009-12-30 05:26 . 2007-07-03 15:56 9256 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2009-12-30 05:26 . 2007-07-03 15:54 80552 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2009-12-30 05:26 . 2009-12-30 05:29 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-12-30 05:25 . 2009-12-30 05:25 -------- d-----w- c:\program files\Samsung
2009-12-29 15:24 . 2009-12-29 15:24 -------- d-----w- c:\program files\WorldUnlock Codes Calculator
2009-12-29 14:23 . 2009-12-30 11:47 -------- d-----w- c:\users\jarka\AppData\Local\Microsoft Games
2009-12-29 13:32 . 2009-12-29 13:32 -------- d-----w- C:\Sounds
2009-12-29 13:19 . 2010-01-14 18:52 -------- d-----w- c:\program files\LG Electronics
2009-12-29 13:19 . 2009-12-29 13:19 -------- d-----w- c:\users\jarka\AppData\Roaming\LG Electronics
2009-12-29 04:59 . 2009-12-29 04:59 -------- d-----w- c:\program files\Windows Portable Devices
2009-12-29 04:54 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-12-29 04:54 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-12-29 04:54 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-12-29 04:52 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-12-29 04:51 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-12-29 04:51 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-12-29 04:51 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-12-29 02:51 . 2010-01-15 07:07 76596 ----a-w- c:\windows\system32\perfh01B.dat
2009-12-29 02:51 . 2010-01-15 07:07 23444 ----a-w- c:\windows\system32\perfc01B.dat
2009-12-29 02:36 . 2009-12-29 02:39 -------- d-----w- c:\windows\system32\ca-ES
2009-12-29 02:36 . 2009-12-29 02:38 -------- d-----w- c:\windows\system32\eu-ES
2009-12-29 02:36 . 2009-12-29 02:38 -------- d-----w- c:\windows\system32\vi-VN
2009-12-29 02:07 . 2009-12-29 02:07 -------- d-----w- c:\windows\system32\EventProviders
2009-12-28 23:36 . 2009-12-28 23:36 -------- d-----w- c:\program files\Microsoft Games
2009-12-28 18:46 . 2009-12-28 18:46 -------- d-----w- c:\users\jarka\AppData\Local\Real
2009-12-28 18:46 . 2009-04-02 14:21 84480 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-28 18:46 . 2008-06-08 22:58 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2009-12-28 18:46 . 2010-01-05 18:14 -------- d-----w- c:\programdata\Apple Computer
2009-12-28 18:45 . 2009-12-31 19:19 -------- d-----w- c:\users\jarka\AppData\Roaming\Any Audio Converter
2009-12-28 18:38 . 2009-12-28 18:46 -------- d-----w- c:\program files\Any Audio Converter
2009-12-28 17:33 . 2009-12-28 17:33 -------- d-----w- c:\program files\Application Updater
2009-12-28 17:33 . 2009-12-28 17:33 -------- d-----w- c:\program files\YouTube Downloader
2009-12-28 17:23 . 2009-12-28 17:23 -------- d-----w- c:\program files\Conduit
2009-12-28 17:23 . 2009-12-28 17:23 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-12-28 17:23 . 2009-12-28 17:23 -------- d-----w- c:\program files\DVDVideoSoft
2009-12-28 15:12 . 2010-01-15 07:00 -------- d-----w- c:\users\jarka\AppData\Roaming\skypePM
2009-12-28 15:07 . 2010-01-15 08:16 -------- d-----w- c:\users\jarka\AppData\Roaming\Skype
2009-12-28 14:57 . 2009-12-28 14:57 -------- d-----w- c:\program files\Common Files\Skype
2009-12-28 14:57 . 2009-12-28 14:58 -------- d-----r- c:\program files\Skype
2009-12-28 14:57 . 2009-12-28 14:57 -------- d-----w- c:\programdata\Skype
2009-12-27 16:18 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-12-27 16:16 . 2009-04-11 06:28 88064 ----a-w- c:\windows\system32\fdBth.dll
2009-12-27 16:15 . 2009-04-11 06:28 618496 ----a-w- c:\windows\system32\mswstr10.dll
2009-12-27 16:13 . 2009-04-11 06:28 342528 ----a-w- c:\windows\system32\zipfldr.dll
2009-12-27 16:12 . 2009-04-11 06:28 45056 ----a-w- c:\windows\system32\dataclen.dll
2009-12-27 16:11 . 2009-04-11 04:46 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2009-12-27 16:11 . 2009-04-11 04:46 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2009-12-27 16:11 . 2009-04-11 06:22 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-12-27 16:11 . 2009-04-11 04:27 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-12-27 16:09 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-12-27 16:09 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-12-27 16:09 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-12-27 16:09 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-12-27 16:09 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-12-27 16:09 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-12-27 16:09 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-12-27 16:09 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-12-27 16:08 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-12-27 16:08 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-12-27 16:07 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-12-27 14:58 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-12-27 14:48 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-27 14:48 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-27 14:48 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-27 14:40 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-12-27 14:40 . 2009-06-10 11:42 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-12-27 14:39 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-12-27 14:39 . 2009-04-11 06:28 53248 ----a-w- c:\windows\system32\tsgqec.dll
2009-12-27 14:39 . 2009-04-11 06:28 136192 ----a-w- c:\windows\system32\aaclient.dll
2009-12-27 14:20 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-12-27 14:20 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
2009-12-27 14:20 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2009-12-27 14:20 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-12-27 14:20 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
2009-12-27 14:20 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-12-27 14:20 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-12-27 14:20 . 2009-04-11 06:28 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2009-12-27 14:20 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-15 07:00 . 2009-06-18 10:10 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2010-01-14 20:58 . 2009-06-05 16:12 4195 ----a-w- c:\windows\bthservsdp.dat
2010-01-13 22:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-30 05:27 . 2008-08-04 11:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-30 05:24 . 2009-06-17 20:49 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-30 05:09 . 2009-12-30 05:09 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-29 07:49 . 2009-12-29 07:49 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2009-12-29 05:44 . 2009-12-29 05:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-12-29 05:32 . 2009-12-29 05:32 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-12-29 04:58 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-29 02:40 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-12-29 02:40 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-29 02:39 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-12-29 02:39 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-12-29 02:39 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-12-29 02:39 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-12-29 02:31 . 2008-08-04 11:38 -------- d-----w- c:\program files\Java
2009-12-29 02:04 . 2008-04-18 16:13 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2009-11-21 06:40 . 2009-12-27 14:17 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-27 14:17 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-27 14:17 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-27 14:17 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-16 08:06 . 2009-11-16 08:06 38240 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2009-11-16 08:06 . 2009-11-16 08:06 135048 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-11-16 08:03 . 2009-11-16 08:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-11-16 07:56 . 2009-11-16 07:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-10-21 16:45 . 2008-10-10 06:36 33792 ----a-w- c:\windows\system32\identprv.dll
2003-03-21 12:45 . 2010-01-03 10:22 250544 ----a-w- c:\program files\Common Files\keyhelp.ocx
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2009-11-09 17:38 2331672 ----a-w- c:\program files\DVDVideoSoft\tbDVDV.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-18 2289664]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-18 178712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-04 141848]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 293168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1045800]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-31 177456]
"WatchDog"="c:\program files\InterVideo\DVD Check\DVDCheck.exe" [2008-04-21 197904]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-11-16 2054360]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-04 1314816]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"EPSON_UD_START"="c:\program files\EPSON Projector\EPSON USB Display V1.4\EMP_UD.exe" [2009-04-15 329632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2008-8-4 197904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):13,5e,c8,2b,31,88,ca,01
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [16. 11. 2009 9:03 108792]
R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [16. 5. 2007 0:08 182576]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [16. 12. 2009 17:38 375296]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [10. 5. 2008 0:09 1168632]
R2 eBeam Device Service;eBeam Device Service;c:\program files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe [31. 12. 2009 12:38 180224]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [16. 11. 2009 9:04 735960]
R2 EMP_UDSA;EMP_UDSA;c:\program files\EPSON Projector\EPSON USB Display V1.4\EMP_UDSA.exe [11. 1. 2010 9:13 98304]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [16. 11. 2009 9:06 38240]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [7. 4. 2008 19:13 24936]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\System32\drivers\ATSwpWDF.sys [13. 5. 2008 16:30 475520]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [4. 8. 2008 12:38 193840]
R3 eppvad_simple;EPSON Projector UD Audio Device;c:\windows\System32\drivers\EMP_UDAU.sys [11. 1. 2010 9:13 17664]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\System32\drivers\lgbtport.sys [19. 6. 2009 12:59 12032]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\System32\drivers\lgbtbus.sys [19. 6. 2009 12:59 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\System32\drivers\lgvmodem.sys [19. 6. 2009 12:59 12928]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\System32\drivers\NETw5v32.sys [28. 4. 2008 7:29 3658752]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [29. 11. 2007 18:56 181760]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21. 1. 2008 3:24 21504]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [8. 4. 2008 13:12 1112560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-03-18 00:56 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-01-15 c:\windows\Tasks\User_Feed_Synchronization-{36307756-7FEF-4428-87D2-AF9BC4797554}.job
- c:\windows\system32\msfeedssync.exe [2009-12-27 04:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sk_us&c=83&bd=all&pf=cmnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sk_us&c=83&bd=all&pf=cmnb
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\jarka\AppData\Roaming\Mozilla\Firefox\Profiles\ks774m93.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=966134&p=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -
BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
HKLM-Run-SearchSettings - c:\program files\Dealio Toolbar\SearchSettings.exe
HKLM-Run-QuickTime Task - c:\program files\Magic Video Converter\codec\quicktime\QTTask.exe
AddRemove-ffdshow_is1 - c:\program files\Magic Video Converter\codec\ffdshow\unins000.exe
AddRemove-QuicktimeAlt_is1 - c:\program files\Magic Video Converter\codec\quicktime\unins000.exe
AddRemove-RealAlt_is1 - c:\program files\Magic Video Converter\codec\real\unins000.exe
AddRemove-WorldUnlock Codes Calculator - c:\users\jarka\Documents\k počítaču\WorldUnlock Codes Calculator\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-15 09:16
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-15 09:18:48
ComboFix-quarantined-files.txt 2010-01-15 08:18
Pre-Run: 22 602 514 432 bytes free
Post-Run: 22 661 943 296 bytes free
- - End Of File - - D2309C14EBB70ADFFAC9040B242C9289