RelevantKnowledge odstránený, script na ComboFix
Napsal: 20 bře 2010 21:46
ževraj treba pc dočistit ešte dalším scriptom
tu je log z combofixu:
Prosim prichystat script na combofix
ComboFix 10-03-19.08 - Tomas . 03. 2010 19:52:20.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.2047.1569 [GMT 1:00]
Running from: c:\documents and settings\Tomas\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\RelevantKnowledge
c:\program files\RelevantKnowledge\components\rlxg.dll
c:\program files\RelevantKnowledge\install.rdf
c:\program files\RelevantKnowledge\MSVCP71.DLL
c:\program files\RelevantKnowledge\MSVCR71.DLL
c:\program files\RelevantKnowledge\rlls.dll
c:\program files\RelevantKnowledge\rlls64.dll
c:\program files\RelevantKnowledge\rloci.bin
c:\program files\RelevantKnowledge\rlph.dll
c:\program files\RelevantKnowledge\rlservice.exe
c:\program files\RelevantKnowledge\rlvknlg.exe
c:\program files\RelevantKnowledge\rlvknlg64.exe
c:\program files\RelevantKnowledge\rlxf.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\d3d10core.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\ReadMe.txt
.
((((((((((((((((((((((((( Files Created from 2010-02-20 to 2010-03-20 )))))))))))))))))))))))))))))))
.
2010-03-20 18:55 . 2010-03-20 18:55 -------- d-----w- c:\windows\system32\xircom
2010-03-20 18:55 . 2010-03-20 18:55 -------- d-----w- c:\windows\system32\wbem\snmp
2010-03-20 18:39 . 2010-03-20 18:41 -------- d-----w- c:\program files\Unlocker
2010-03-20 17:11 . 2010-03-20 17:27 -------- d-----w- c:\program files\trend micro
2010-03-20 17:11 . 2010-03-20 17:11 -------- d-----w- C:\rsit
2010-03-10 12:14 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-10 12:13 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-07 01:50 . 2010-03-07 01:50 -------- d-----w- c:\program files\ICQ6Toolbar
2010-03-07 01:49 . 2010-03-07 01:51 -------- d-----w- c:\program files\ICQ7.0
2010-03-06 22:54 . 2010-03-06 22:54 -------- d-----w- c:\program files\Gamesload Spiele
2010-03-02 00:03 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-03-02 00:03 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-03-02 00:03 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-03-01 23:36 . 2010-03-01 23:36 -------- d-----w- c:\windows\system32\LogFiles
2010-03-01 16:31 . 2010-03-01 16:31 -------- d-----w- c:\windows\Sun
2010-02-26 23:36 . 2010-02-27 20:52 -------- d-----w- c:\program files\uTorrent
2010-02-26 00:20 . 2010-02-26 00:21 -------- d-----w- c:\program files\Media Player Classic
2010-02-22 17:51 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-02-22 17:51 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-02-22 17:51 . 2007-03-30 15:07 267864 ----a-r- c:\windows\system32\hpzids01.dll
2010-02-22 17:51 . 2007-03-28 13:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2010-02-22 17:51 . 2007-03-28 12:57 274944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5ha.dll
2010-02-22 17:51 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-02-22 17:50 . 2008-04-13 21:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-22 17:50 . 2007-03-17 16:11 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2010-02-22 17:50 . 2007-03-17 16:11 303104 ----a-r- c:\windows\system32\hpovst10.dll
2010-02-22 17:50 . 2007-03-17 16:11 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2010-02-22 17:50 . 2007-03-08 04:20 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-02-22 17:50 . 2007-03-08 04:20 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-02-22 17:48 . 2010-02-22 17:48 -------- d-----w- c:\program files\Common Files\HP
2010-02-22 17:48 . 2010-02-22 17:48 -------- d-----w- c:\program files\Hewlett-Packard
2010-02-22 17:48 . 2010-02-22 17:48 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-02-22 17:47 . 2010-02-22 17:50 -------- d-----w- c:\program files\HP
2010-02-22 17:47 . 2008-04-13 21:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-02-22 17:46 . 2010-02-22 17:52 141186 ----a-w- c:\windows\hpoins14.dat
2010-02-22 17:46 . 2007-06-05 23:07 2000 ------w- c:\windows\hpomdl14.dat
2010-02-21 22:09 . 2010-02-21 22:09 -------- d-----w- c:\program files\CountDown ShutDown PC
2010-02-19 16:57 . 2010-02-19 16:58 -------- d-----w- c:\program files\Ares
2010-02-19 09:17 . 2010-02-19 09:17 -------- d-----w- c:\program files\Rockstar Games
2010-02-19 09:16 . 2010-02-19 09:16 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-02-19 09:14 . 2010-02-19 09:19 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-02-19 09:14 . 2010-02-19 09:14 -------- d-----w- c:\windows\system32\xlive
2010-02-19 06:25 . 2010-02-19 06:30 -------- d-----w- c:\windows\SxsCaPendDel
2010-02-18 20:20 . 2010-03-20 18:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-18 20:03 . 2010-02-18 20:03 -------- d-----w- c:\windows\system32\KB905474
2010-02-18 20:03 . 2009-03-10 21:26 1435008 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2010-02-18 20:03 . 2009-03-10 21:18 454024 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2010-02-18 19:58 . 2008-04-14 06:52 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-02-18 19:55 . 2010-02-24 19:18 -------- d-----w- c:\windows\ie8updates
2010-02-18 19:32 . 2009-10-15 16:32 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-02-18 19:32 . 2009-10-15 16:32 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-02-18 19:32 . 2009-12-04 17:25 456832 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-18 19:32 . 2010-01-01 07:58 353792 ------w- c:\windows\system32\dllcache\srv.sys
2010-02-18 19:32 . 2009-06-21 21:48 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-02-18 19:27 . 2009-12-14 07:10 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
2010-02-18 19:27 . 2009-09-04 21:05 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2010-02-18 19:26 . 2008-05-01 14:37 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-02-18 19:26 . 2009-07-31 04:30 1447424 ------w- c:\windows\system32\dllcache\msxml6.dll
2010-02-18 19:26 . 2009-07-31 04:30 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-02-18 19:26 . 2009-07-10 13:28 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-02-18 19:26 . 2009-12-09 05:55 726528 ------w- c:\windows\system32\dllcache\jscript.dll
2010-02-18 19:24 . 2009-12-09 14:33 2191488 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-02-18 19:24 . 2009-12-09 10:03 2147328 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-18 19:24 . 2009-12-09 10:03 2025984 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-18 19:23 . 2009-10-13 10:34 271360 ------w- c:\windows\system32\dllcache\oakley.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-20 18:55 . 2010-03-20 18:55 -------- d-----w- c:\program files\microsoft frontpage
2010-03-13 11:29 . 2001-10-25 12:00 79086 ----a-w- c:\windows\system32\perfc005.dat
2010-03-13 11:29 . 2001-10-25 12:00 432208 ----a-w- c:\windows\system32\perfh005.dat
2010-03-09 11:24 . 2010-02-17 20:36 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-09 11:12 . 2010-02-17 20:36 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-09 11:12 . 2010-02-17 20:36 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-09 11:09 . 2010-02-17 20:36 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-09 11:08 . 2010-02-17 20:36 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-09 11:08 . 2010-02-17 20:36 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-09 11:08 . 2010-02-17 20:36 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-09 11:08 . 2010-02-17 20:36 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-07 01:50 . 2002-01-20 03:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-06 22:28 . 2002-01-20 03:40 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-23 20:22 . 2002-01-20 03:18 -------- d-----w- c:\program files\Windows Media Connect 2
2010-02-18 23:41 . 2010-02-17 23:02 -------- d-----w- c:\program files\Microsoft Works
2010-02-18 18:21 . 2010-02-18 18:21 53167 ----a-w- c:\windows\BricoPackUninst.cmd
2010-02-18 18:21 . 2010-02-18 18:20 6114 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-02-18 18:21 . 2008-04-14 06:52 219648 ----a-w- c:\windows\system32\uxtheme.dll
2010-02-18 17:17 . 2010-02-18 17:17 -------- d-----w- c:\program files\VideoInspector
2010-02-18 12:02 . 2010-02-18 12:02 -------- d-----w- c:\program files\Common Files\SRS
2010-02-18 12:02 . 2010-02-18 12:02 -------- d-----w- c:\program files\SRSLabs
2010-02-17 23:23 . 2010-02-17 21:36 -------- d-----w- c:\program files\EVEREST Ultimate Edition
2010-02-17 23:02 . 2010-02-17 21:01 -------- d-----w- c:\program files\MSBuild
2010-02-17 23:02 . 2010-02-17 23:02 -------- d-----w- c:\program files\Microsoft.NET
2010-02-17 23:00 . 2010-02-17 23:00 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-02-17 21:55 . 2010-02-17 21:55 -------- d-----w- c:\program files\CCleaner
2010-02-17 21:32 . 2010-02-17 21:32 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-17 21:17 . 2010-02-17 21:17 728858 ----a-w- c:\program files\Common Files\unins000.exe
2010-02-17 21:02 . 2010-02-17 21:02 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-17 21:02 . 2010-02-17 21:02 -------- d-----w- c:\program files\Java
2010-02-17 21:01 . 2010-02-17 21:01 -------- d-----w- c:\program files\Reference Assemblies
2010-02-17 20:50 . 2010-02-17 20:50 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-17 20:49 . 2010-02-17 20:49 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-17 20:46 . 2010-02-17 20:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-17 20:41 . 2010-02-17 20:41 0 ----a-w- c:\windows\nsreg.dat
2010-02-17 20:36 . 2010-02-17 20:36 -------- d-----w- c:\program files\Alwil Software
2010-02-17 19:42 . 2002-01-20 03:21 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-17 19:42 . 2002-01-20 03:21 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-02-17 19:38 . 2002-01-20 03:21 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-02-11 18:53 . 2010-02-17 20:36 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-02 18:00 . 2010-02-17 21:32 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-01 07:58 . 2009-06-04 12:13 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2009-06-04 12:06 916480 ----a-w- c:\windows\system32\wininet.dll
.
------- Sigcheck -------
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2008-04-14 . 13E794E5591776CBC71055A7B3CC1D5F . 976384 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RGSC"="e:\hry\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe" [2010-02-19 306088]
"GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2009-05-12 2181672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"SkyTel"="SkyTel.EXE" [2007-04-04 1822720]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-03-09 15872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-06-04 128512]
c:\documents and settings\Tomas\Nabˇdka Start\Programy\Po spuçtŘnˇ\
UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-21 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Hry\\GTA IV\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"e:\\Hry\\GTA IV\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Hry\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"e:\\Hry\\GTA IV\\Grand Theft Auto IV\\GTAIV.exe"=
"e:\\Hry\\Far Cry\\Bin32\\FarCry.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [17. 2. 2010 21:36 162640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17. 2. 2010 21:36 19024]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [7. 3. 2010 2:50 246520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-03-20 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-02-18 21:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\program files\ICQ7.0\ICQ.exe
FF - ProfilePath - c:\documents and settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\ye9lrv6d.default\
FF - prefs.js: browser.search.selectedEngine - Azet
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - prefs.js: keyword.URL -
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files\RelevantKnowledge\rlvknlg.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2860)
c:\windows\system32\SHDOCVW.dll
c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.dll
c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Completion time: 2010-03-20 19:56:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-20 18:56
Pre-Run: Volných bajtů: 114 612 760 576
Post-Run: Volných bajtů: 114 600 976 384
- - End Of File - - 54B8DC7F1735CF5607A00C828E0387BB
tu je log z combofixu:
Prosim prichystat script na combofix
ComboFix 10-03-19.08 - Tomas . 03. 2010 19:52:20.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.2047.1569 [GMT 1:00]
Running from: c:\documents and settings\Tomas\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\RelevantKnowledge
c:\program files\RelevantKnowledge\components\rlxg.dll
c:\program files\RelevantKnowledge\install.rdf
c:\program files\RelevantKnowledge\MSVCP71.DLL
c:\program files\RelevantKnowledge\MSVCR71.DLL
c:\program files\RelevantKnowledge\rlls.dll
c:\program files\RelevantKnowledge\rlls64.dll
c:\program files\RelevantKnowledge\rloci.bin
c:\program files\RelevantKnowledge\rlph.dll
c:\program files\RelevantKnowledge\rlservice.exe
c:\program files\RelevantKnowledge\rlvknlg.exe
c:\program files\RelevantKnowledge\rlvknlg64.exe
c:\program files\RelevantKnowledge\rlxf.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\d3d10core.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\ReadMe.txt
.
((((((((((((((((((((((((( Files Created from 2010-02-20 to 2010-03-20 )))))))))))))))))))))))))))))))
.
2010-03-20 18:55 . 2010-03-20 18:55 -------- d-----w- c:\windows\system32\xircom
2010-03-20 18:55 . 2010-03-20 18:55 -------- d-----w- c:\windows\system32\wbem\snmp
2010-03-20 18:39 . 2010-03-20 18:41 -------- d-----w- c:\program files\Unlocker
2010-03-20 17:11 . 2010-03-20 17:27 -------- d-----w- c:\program files\trend micro
2010-03-20 17:11 . 2010-03-20 17:11 -------- d-----w- C:\rsit
2010-03-10 12:14 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-10 12:13 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-07 01:50 . 2010-03-07 01:50 -------- d-----w- c:\program files\ICQ6Toolbar
2010-03-07 01:49 . 2010-03-07 01:51 -------- d-----w- c:\program files\ICQ7.0
2010-03-06 22:54 . 2010-03-06 22:54 -------- d-----w- c:\program files\Gamesload Spiele
2010-03-02 00:03 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-03-02 00:03 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-03-02 00:03 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-03-02 00:03 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-03-01 23:36 . 2010-03-01 23:36 -------- d-----w- c:\windows\system32\LogFiles
2010-03-01 16:31 . 2010-03-01 16:31 -------- d-----w- c:\windows\Sun
2010-02-26 23:36 . 2010-02-27 20:52 -------- d-----w- c:\program files\uTorrent
2010-02-26 00:20 . 2010-02-26 00:21 -------- d-----w- c:\program files\Media Player Classic
2010-02-22 17:51 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-02-22 17:51 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-02-22 17:51 . 2007-03-30 15:07 267864 ----a-r- c:\windows\system32\hpzids01.dll
2010-02-22 17:51 . 2007-03-28 13:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2010-02-22 17:51 . 2007-03-28 12:57 274944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5ha.dll
2010-02-22 17:51 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-02-22 17:50 . 2008-04-13 21:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-22 17:50 . 2007-03-17 16:11 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2010-02-22 17:50 . 2007-03-17 16:11 303104 ----a-r- c:\windows\system32\hpovst10.dll
2010-02-22 17:50 . 2007-03-17 16:11 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2010-02-22 17:50 . 2007-03-08 04:20 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-02-22 17:50 . 2007-03-08 04:20 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-02-22 17:48 . 2010-02-22 17:48 -------- d-----w- c:\program files\Common Files\HP
2010-02-22 17:48 . 2010-02-22 17:48 -------- d-----w- c:\program files\Hewlett-Packard
2010-02-22 17:48 . 2010-02-22 17:48 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-02-22 17:47 . 2010-02-22 17:50 -------- d-----w- c:\program files\HP
2010-02-22 17:47 . 2008-04-13 21:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-02-22 17:46 . 2010-02-22 17:52 141186 ----a-w- c:\windows\hpoins14.dat
2010-02-22 17:46 . 2007-06-05 23:07 2000 ------w- c:\windows\hpomdl14.dat
2010-02-21 22:09 . 2010-02-21 22:09 -------- d-----w- c:\program files\CountDown ShutDown PC
2010-02-19 16:57 . 2010-02-19 16:58 -------- d-----w- c:\program files\Ares
2010-02-19 09:17 . 2010-02-19 09:17 -------- d-----w- c:\program files\Rockstar Games
2010-02-19 09:16 . 2010-02-19 09:16 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-02-19 09:14 . 2010-02-19 09:19 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-02-19 09:14 . 2010-02-19 09:14 -------- d-----w- c:\windows\system32\xlive
2010-02-19 06:25 . 2010-02-19 06:30 -------- d-----w- c:\windows\SxsCaPendDel
2010-02-18 20:20 . 2010-03-20 18:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-18 20:03 . 2010-02-18 20:03 -------- d-----w- c:\windows\system32\KB905474
2010-02-18 20:03 . 2009-03-10 21:26 1435008 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2010-02-18 20:03 . 2009-03-10 21:18 454024 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2010-02-18 19:58 . 2008-04-14 06:52 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-02-18 19:55 . 2010-02-24 19:18 -------- d-----w- c:\windows\ie8updates
2010-02-18 19:32 . 2009-10-15 16:32 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-02-18 19:32 . 2009-10-15 16:32 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-02-18 19:32 . 2009-12-04 17:25 456832 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-18 19:32 . 2010-01-01 07:58 353792 ------w- c:\windows\system32\dllcache\srv.sys
2010-02-18 19:32 . 2009-06-21 21:48 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-02-18 19:27 . 2009-12-14 07:10 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
2010-02-18 19:27 . 2009-09-04 21:05 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2010-02-18 19:26 . 2008-05-01 14:37 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-02-18 19:26 . 2009-07-31 04:30 1447424 ------w- c:\windows\system32\dllcache\msxml6.dll
2010-02-18 19:26 . 2009-07-31 04:30 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-02-18 19:26 . 2009-07-10 13:28 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-02-18 19:26 . 2009-12-09 05:55 726528 ------w- c:\windows\system32\dllcache\jscript.dll
2010-02-18 19:24 . 2009-12-09 14:33 2191488 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-02-18 19:24 . 2009-12-09 10:03 2147328 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-18 19:24 . 2009-12-09 10:03 2025984 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-18 19:23 . 2009-10-13 10:34 271360 ------w- c:\windows\system32\dllcache\oakley.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-20 18:55 . 2010-03-20 18:55 -------- d-----w- c:\program files\microsoft frontpage
2010-03-13 11:29 . 2001-10-25 12:00 79086 ----a-w- c:\windows\system32\perfc005.dat
2010-03-13 11:29 . 2001-10-25 12:00 432208 ----a-w- c:\windows\system32\perfh005.dat
2010-03-09 11:24 . 2010-02-17 20:36 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-09 11:12 . 2010-02-17 20:36 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-09 11:12 . 2010-02-17 20:36 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-09 11:09 . 2010-02-17 20:36 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-09 11:08 . 2010-02-17 20:36 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-09 11:08 . 2010-02-17 20:36 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-09 11:08 . 2010-02-17 20:36 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-09 11:08 . 2010-02-17 20:36 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-07 01:50 . 2002-01-20 03:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-06 22:28 . 2002-01-20 03:40 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-23 20:22 . 2002-01-20 03:18 -------- d-----w- c:\program files\Windows Media Connect 2
2010-02-18 23:41 . 2010-02-17 23:02 -------- d-----w- c:\program files\Microsoft Works
2010-02-18 18:21 . 2010-02-18 18:21 53167 ----a-w- c:\windows\BricoPackUninst.cmd
2010-02-18 18:21 . 2010-02-18 18:20 6114 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-02-18 18:21 . 2008-04-14 06:52 219648 ----a-w- c:\windows\system32\uxtheme.dll
2010-02-18 17:17 . 2010-02-18 17:17 -------- d-----w- c:\program files\VideoInspector
2010-02-18 12:02 . 2010-02-18 12:02 -------- d-----w- c:\program files\Common Files\SRS
2010-02-18 12:02 . 2010-02-18 12:02 -------- d-----w- c:\program files\SRSLabs
2010-02-17 23:23 . 2010-02-17 21:36 -------- d-----w- c:\program files\EVEREST Ultimate Edition
2010-02-17 23:02 . 2010-02-17 21:01 -------- d-----w- c:\program files\MSBuild
2010-02-17 23:02 . 2010-02-17 23:02 -------- d-----w- c:\program files\Microsoft.NET
2010-02-17 23:00 . 2010-02-17 23:00 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-02-17 21:55 . 2010-02-17 21:55 -------- d-----w- c:\program files\CCleaner
2010-02-17 21:32 . 2010-02-17 21:32 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-17 21:17 . 2010-02-17 21:17 728858 ----a-w- c:\program files\Common Files\unins000.exe
2010-02-17 21:02 . 2010-02-17 21:02 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-17 21:02 . 2010-02-17 21:02 -------- d-----w- c:\program files\Java
2010-02-17 21:01 . 2010-02-17 21:01 -------- d-----w- c:\program files\Reference Assemblies
2010-02-17 20:50 . 2010-02-17 20:50 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-17 20:49 . 2010-02-17 20:49 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-17 20:46 . 2010-02-17 20:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-17 20:41 . 2010-02-17 20:41 0 ----a-w- c:\windows\nsreg.dat
2010-02-17 20:36 . 2010-02-17 20:36 -------- d-----w- c:\program files\Alwil Software
2010-02-17 19:42 . 2002-01-20 03:21 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-17 19:42 . 2002-01-20 03:21 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-02-17 19:38 . 2002-01-20 03:21 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-02-11 18:53 . 2010-02-17 20:36 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-02 18:00 . 2010-02-17 21:32 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-01 07:58 . 2009-06-04 12:13 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2009-06-04 12:06 916480 ----a-w- c:\windows\system32\wininet.dll
.
------- Sigcheck -------
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2008-04-14 . 13E794E5591776CBC71055A7B3CC1D5F . 976384 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RGSC"="e:\hry\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe" [2010-02-19 306088]
"GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2009-05-12 2181672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"SkyTel"="SkyTel.EXE" [2007-04-04 1822720]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-03-09 15872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-06-04 128512]
c:\documents and settings\Tomas\Nabˇdka Start\Programy\Po spuçtŘnˇ\
UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-21 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Hry\\GTA IV\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"e:\\Hry\\GTA IV\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Hry\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"e:\\Hry\\GTA IV\\Grand Theft Auto IV\\GTAIV.exe"=
"e:\\Hry\\Far Cry\\Bin32\\FarCry.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [17. 2. 2010 21:36 162640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17. 2. 2010 21:36 19024]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [7. 3. 2010 2:50 246520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-03-20 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-02-18 21:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\program files\ICQ7.0\ICQ.exe
FF - ProfilePath - c:\documents and settings\Tomas\Data aplikací\Mozilla\Firefox\Profiles\ye9lrv6d.default\
FF - prefs.js: browser.search.selectedEngine - Azet
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - prefs.js: keyword.URL -
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files\RelevantKnowledge\rlvknlg.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2860)
c:\windows\system32\SHDOCVW.dll
c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.dll
c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Completion time: 2010-03-20 19:56:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-20 18:56
Pre-Run: Volných bajtů: 114 612 760 576
Post-Run: Volných bajtů: 114 600 976 384
- - End Of File - - 54B8DC7F1735CF5607A00C828E0387BB