LOG z USB fix:
############################## | UsbFix V6.103 |
User : danhill (Administrators) # MARTIN
Update on 12/04/2010 by El Desaparecido , C_XX & Chimay8
Start at: 14:29:59 | 13. 4. 2010
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact :
FindyKill.Contact@gmail.com
Intel(R) Celeron(R) M processor 1.40GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 7.0.5730.11
Windows Firewall Status : Enabled
C:\ -> Místní pevný disk # 37,25 Go (6,55 Go free) # NTFS
D:\ -> Disk CD-ROM
E:\ -> Vyměnitelný disk # 1,83 Go (1,83 Go free) # FAT32
################## | Files # Infected Folders |
Deleted ! C:\WINDOWS\regedit.com
Deleted ! C:\WINDOWS\rundl132.exe
Deleted ! C:\DOCUME~1\danhill\LOCALS~1\Temp\ptu1_tmp.exe
Deleted ! C:\Recycler\S-1-5-21-1482476501-606747145-682003330-1003
Deleted ! E:\autorun.inf
Deleted ! E:\killVBS.vbs
################## | Registry |
################## | Mountpoints2 |
Deleted ! HKCU\...\Explorer\MountPoints2\{28cb8628-2162-11db-9052-00904ba4c272}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{4c9e02b0-78c0-11dc-91c6-00904ba4c272}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{7dcdadde-00ca-11de-945c-00904ba4c272}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{8fa3ef9a-46f7-11df-a06b-001279c3fa2c}\Shell\AutoRun\Command
################## | Listing of the present files |
[28. 04. 2006 14:03|--a------|0] C:\AUTOEXEC.BAT
[28. 04. 2006 14:32|--a------|166] C:\bcmwl5.log
[10. 04. 2010 20:34|---hs----|211] C:\boot.ini
[18. 08. 2004 14:00|-rahs----|4952] C:\Bootfont.bin
[28. 04. 2006 14:32|--a------|90] C:\chpst.log
[28. 04. 2006 14:03|--a------|0] C:\CONFIG.SYS
[?|?|?] C:\hiberfil.sys
[28. 04. 2006 14:03|-rahs----|0] C:\IO.SYS
[28. 04. 2006 14:03|-rahs----|0] C:\MSDOS.SYS
[18. 08. 2004 14:00|-rahs----|47564] C:\NTDETECT.COM
[18. 08. 2004 14:00|-rahs----|250048] C:\ntldr
[?|?|?] C:\pagefile.sys
[18. 02. 2010 12:15|--a------|13030] C:\PDOXUSRS.NET
[28. 04. 2006 14:26|--a------|161] C:\sedinst.log
[28. 04. 2006 14:26|--a------|200] C:\sedinst2.log
[28. 04. 2006 14:32|--a------|190] C:\setup.log
[28. 04. 2006 14:27|--a------|20944] C:\sunjava.log
[28. 04. 2006 14:22|--a------|191] C:\syntp.log
[28. 04. 2006 14:21|--a------|32] C:\ticrdbus.log
[28. 03. 2010 11:33|---h-----|133848] C:\TREEINFO.WC
[13. 04. 2010 14:32|--a------|2448] C:\UsbFix.txt
################## | Vaccination |
# C:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).
################## | Upload |
Please send the file : C:\UsbFix_Upload_Me_MARTIN.zip :
http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution .
################## | ! End of report # UsbFix V6.103 ! |
OTL logfile created on: 13. 4. 2010 14:40:47 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\danhill\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy
247,00 Mb Total Physical Memory | 24,00 Mb Available Physical Memory | 10,00% Memory free
606,00 Mb Paging File | 398,00 Mb Available in Paging File | 66,00% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,25 Gb Total Space | 6,61 Gb Free Space | 17,74% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,83 Gb Total Space | 1,83 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MARTIN
Current User Name: danhill
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.04.13 14:40:35 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\danhill\Plocha\OTL.exe
PRC - [2010.04.02 10:40:10 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2004.08.18 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002.09.20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Modules (SafeList) ==========
MOD - [2010.04.13 14:40:35 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\danhill\Plocha\OTL.exe
MOD - [2004.08.18 14:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (aspnet_state)
SRV - [2005.08.25 18:55:56 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2002.09.20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
========== Driver Services (SafeList) ==========
DRV - [2010.02.17 10:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010.02.17 10:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.02.17 10:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2007.06.12 13:15:10 | 000,051,040 | ---- | M] (IPWireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipw3gnet.sys -- (IpwP)
DRV - [2006.10.23 10:36:38 | 000,093,440 | ---- | M] (AnyDATA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adusbser.sys -- (adusbser)
DRV - [2006.04.28 17:35:49 | 000,016,021 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PCMCARD.sys -- (PCMCARD)
DRV - [2006.04.28 14:32:39 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2005.11.03 16:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005.09.27 10:21:54 | 000,095,440 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipw_mdm.sys -- (ipw_mdm) Wireless Broadband Modem (WDM)
DRV - [2005.09.27 10:21:50 | 000,008,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipw_mdfl.sys -- (ipw_mdfl)
DRV - [2005.09.27 10:21:28 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipw_bus.sys -- (ipw_bus)
DRV - [2005.09.08 01:18:54 | 000,009,728 | ---- | M] (Gemfor s.r.o.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ethpdrv.sys -- (Ethpdrv)
DRV - [2005.08.10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.06.17 11:20:20 | 000,119,424 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2005.05.16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2004.11.04 20:26:42 | 000,186,016 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004.10.29 09:53:14 | 000,342,912 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004.08.24 13:20:08 | 001,268,204 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004.06.24 04:54:12 | 000,023,552 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tap0801.sys -- (tap0801)
DRV - [2004.05.26 15:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004.04.20 11:05:10 | 000,057,404 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2004.04.20 11:04:56 | 000,024,209 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2004.03.24 04:12:34 | 000,017,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\nsndis5.sys -- (NSNDIS5)
DRV - [2003.08.08 10:07:08 | 000,040,788 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ulink.sys -- (Usblink)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.aktualne.cz/?ms=ae
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.centrum.cz/?ms=ae [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.centrum.cz/?ms=ae [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.aktualne.cz/?ms=ae
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.centrum.cz/?ms=ae [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {08c834b4-e025-44a3-9b95-e9885adc4be0}:3.5
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.02 11:05:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.02 11:05:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 1.5.0.14\Extensions\\Components: C:\Program Files\Mozilla Thunderbird\components\ [2010.04.02 11:05:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 1.5.0.14\Extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins\ [2010.04.02 11:05:20 | 000,000,000 | ---D | M]
[2009.01.10 16:12:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\danhill\Data aplikací\Mozilla\Extensions
[2010.04.11 17:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\danhill\Data aplikací\Mozilla\Firefox\Profiles\76nsf2kj.default\extensions
[2010.01.14 15:40:49 | 000,000,000 | ---D | M] (iFox Metal) -- C:\Documents and Settings\danhill\Data aplikací\Mozilla\Firefox\Profiles\76nsf2kj.default\extensions\{08c834b4-e025-44a3-9b95-e9885adc4be0}
[2007.08.03 14:34:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\danhill\Data aplikací\Mozilla\Firefox\Profiles\76nsf2kj.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2006.04.29 20:26:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\danhill\Data aplikací\Mozilla\Firefox\Profiles\76nsf2kj.default\extensions\
blueshift@shift.themes
[2008.06.14 22:56:27 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.01.14 10:50:10 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.14 10:50:10 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.14 10:50:10 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.14 10:50:10 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.14 10:50:10 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2004.08.18 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MNM] C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\MNetMgr.exe (GlobeSoft AB)
O4 - HKLM..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B}
http://messenger.zone.msn.com/binary/Mi ... b31267.cab (Minesweeper Flags Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565}
http://messenger.zone.msn.com/binary/So ... b56986.cab (Solitaire Showdown Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zone.msn.com/binary/Me ... b31267.cab (MessengerStatsClient Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/Mi ... b56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.146.11 195.146.100.5 195.146.99.4
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\mnmwlxchain: DllName - NTGlobeBTA.dll - C:\WINDOWS\System32\NTGlobeBTA.dll (GlobeSoft AB)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\danhill\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\danhill\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.04.28 14:03:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.13 14:32:57 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.04.13 14:40:34 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\danhill\Plocha\OTL.exe
[2010.04.13 14:32:57 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2010.04.13 14:26:58 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.13 09:08:48 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.13 09:08:37 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.12 15:25:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\danhill\Data aplikací\Uniblue
[2010.04.12 15:20:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\danhill\Plocha\Music
[2010.04.10 09:50:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
[2010.04.10 09:49:06 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010.04.10 09:49:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\danhill\Data aplikací\SUPERAntiSpyware.com
[2010.04.10 09:47:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010.04.08 10:45:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\VDLL.DLL
[2010.04.08 10:45:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\runouce.exe
[2010.04.08 10:45:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\rundll16.exe
[2010.04.08 10:45:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\logo1_.exe
[2010.04.08 10:45:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\logo_1.exe
[2010.04.08 10:41:27 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.04.08 10:41:26 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.04.08 10:41:25 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.04.08 10:41:17 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TASKMGR.COM
[2010.04.08 10:41:17 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\T.COM
[2010.04.08 10:41:16 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\R.COM
[2010.04.08 10:41:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MicroWorld
[2010.04.08 10:41:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010.04.06 15:23:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3
[2010.04.06 15:20:57 | 000,000,000 | ---D | C] -- C:\Program Files\Alawar
[2010.04.06 11:24:57 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.04.02 11:03:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010.04.02 11:02:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\danhill\Local Settings\Data aplikací\Apple
[2010.04.02 11:02:46 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010.04.02 11:02:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Apple
[2010.03.31 08:53:43 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\danhill\Local Settings\Data aplikací\SJphone 1.65
[2010.03.17 21:53:42 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.03.17 21:53:42 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2009.12.18 17:11:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.12.18 17:01:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2009.12.18 17:01:26 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.03.20 19:30:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2009.03.20 09:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2006.04.29 13:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\ApplicationHistory
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.04.13 14:40:35 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\danhill\Plocha\OTL.exe
[2010.04.13 14:37:58 | 000,568,814 | ---- | M] () -- C:\UsbFix_Upload_Me_MARTIN.zip
[2010.04.13 14:34:50 | 000,402,972 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.13 14:34:50 | 000,400,840 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.04.13 14:34:50 | 000,073,276 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.04.13 14:34:50 | 000,061,884 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.13 14:34:48 | 000,949,268 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.04.13 14:29:31 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.13 14:29:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.13 14:29:26 | 259,444,736 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.13 14:28:42 | 004,718,592 | ---- | M] () -- C:\Documents and Settings\danhill\ntuser.dat
[2010.04.13 14:28:42 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\danhill\ntuser.ini
[2010.04.13 14:26:42 | 001,777,455 | ---- | M] () -- C:\Documents and Settings\danhill\Plocha\UsbFix.exe
[2010.04.13 10:05:26 | 000,000,666 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.04.13 10:05:24 | 000,001,015 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2010.04.10 20:34:48 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010.04.10 20:34:47 | 000,000,592 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.04.10 20:34:47 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.10 10:29:19 | 003,354,336 | -H-- | M] () -- C:\Documents and Settings\danhill\Local Settings\Data aplikací\IconCache.db
[2010.04.10 09:49:21 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2010.04.10 09:41:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.08 11:54:51 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\danhill\Dokumenty\pinfect.zip
[2010.04.08 10:45:26 | 000,000,054 | ---- | M] () -- C:\WINDOWS\Lic.xxx
[2010.04.08 10:41:26 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.04.08 10:41:25 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.04.08 10:41:24 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.04.03 18:42:48 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.03.28 11:33:57 | 000,133,848 | -H-- | M] () -- C:\TREEINFO.WC
[2010.03.17 21:53:42 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010.03.17 21:53:42 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.04.13 14:37:58 | 000,568,814 | ---- | C] () -- C:\UsbFix_Upload_Me_MARTIN.zip
[2010.04.13 14:26:41 | 001,777,455 | ---- | C] () -- C:\Documents and Settings\danhill\Plocha\UsbFix.exe
[2010.04.10 09:49:21 | 000,000,780 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2010.04.08 11:54:51 | 000,001,542 | ---- | C] () -- C:\Documents and Settings\danhill\Dokumenty\pinfect.zip
[2010.04.08 10:42:03 | 000,000,054 | ---- | C] () -- C:\WINDOWS\Lic.xxx
[2010.04.08 10:41:25 | 000,000,522 | ---- | C] () -- C:\WINDOWS\System32\Microsoft.VC80.CRT.manifest
[2009.06.01 10:09:50 | 000,002,260 | ---- | C] () -- C:\Program Files\uninstal.log
[2008.04.10 14:37:27 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\danhill\PUTTY.RND
[2007.10.12 14:42:13 | 000,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI
[2007.06.29 18:01:17 | 000,000,381 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2007.01.17 10:15:11 | 000,000,092 | ---- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2006.10.19 14:52:00 | 000,001,763 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2006.10.05 20:55:42 | 004,718,592 | ---- | C] () -- C:\Documents and Settings\danhill\ntuser.dat
[2006.06.05 13:50:08 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Udetect.dll
[2006.06.05 13:49:58 | 000,040,788 | ---- | C] () -- C:\WINDOWS\System32\drivers\ulink.sys
[2006.06.05 12:18:42 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\ntuser.dat
[2006.06.05 12:18:42 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\ntuser.dat.LOG
[2006.05.19 22:51:45 | 000,000,342 | ---- | C] () -- C:\WINDOWS\Jelly.ini
[2006.04.29 13:49:09 | 000,002,048 | ---- | C] () -- C:\WINDOWS\MNMGM32.DLL
[2006.04.29 13:43:26 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\fusioncache.dat
[2006.04.29 13:14:35 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\danhill\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.04.29 13:00:29 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006.04.28 18:20:49 | 000,007,241 | ---- | C] () -- C:\Documents and Settings\danhill\AdobeFnt10.lst
[2006.04.28 17:22:48 | 000,001,015 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2006.04.28 17:20:55 | 000,000,666 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006.04.28 15:05:17 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2006.04.28 14:30:31 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006.04.28 14:30:31 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006.04.28 14:30:31 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006.04.28 14:30:31 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006.04.28 14:30:31 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006.04.28 14:30:31 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006.04.28 14:28:59 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\danhill\Local Settings\Data aplikací\fusioncache.dat
[2006.04.28 14:25:39 | 000,094,274 | R--- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2006.04.28 14:09:46 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\danhill\ntuser.ini
[2006.04.28 14:09:45 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\danhill\ntuser.dat.LOG
[2006.04.13 11:30:06 | 001,073,152 | ---- | C] () -- C:\WINDOWS\System32\libmysql_c.dll
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.10.14 11:56:48 | 003,223,552 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2005.10.14 11:56:48 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2005.10.14 11:56:48 | 000,266,240 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2005.10.14 11:56:48 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2005.10.14 11:56:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2003.03.12 16:01:48 | 000,110,592 | ---- | C] () -- C:\Program Files\iperf.exe
[2001.09.21 06:00:38 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\InTouchViewer.dll
[2001.09.21 05:59:38 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\InTouchCOMClient.dll
[2001.09.17 09:49:22 | 000,421,888 | R--- | C] () -- C:\WINDOWS\System32\XMLParser.dll
[2001.09.17 09:49:20 | 000,573,440 | R--- | C] () -- C:\WINDOWS\System32\dbsock.dll
[2001.09.17 09:49:20 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\Transport.dll
[2001.09.17 09:48:54 | 000,503,808 | R--- | C] () -- C:\WINDOWS\System32\lt_xtrans.dll
[2001.09.17 09:48:54 | 000,286,720 | R--- | C] () -- C:\WINDOWS\System32\MrSIDD.dll
[2001.09.17 09:48:54 | 000,163,840 | R--- | C] () -- C:\WINDOWS\System32\lt_common.dll
[2001.09.17 09:48:54 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\lt_trans.dll
[2001.09.17 09:48:54 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\lt_meta.dll
[2001.09.17 09:48:54 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\lt_encrypt.dll
[2001.09.17 09:48:54 | 000,020,480 | R--- | C] () -- C:\WINDOWS\System32\lt_messagetext.dll
< End of report >