Dobrý večer.
Mám problém s PC - prehliadače padajú a keď sa spustí video, ktoré využíva Flash Player (mám ho aktuálny), PC úplne zamrzne, naskočí modrá smrť a po reštarte sa objaví hláška, že systém bol obnovený po vážnej chybe. Viď. prílohy.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrátor at 2011-10-01 18:29:58
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 17 GB (34%) free of 50 GB
Total RAM: 2559 MB (69% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:30:02, on 1.10.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Administrátor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrátor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrátor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrátor\My Documents\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Administrátor.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/?pc=AVBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0072022843
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8986734897
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://195.113.207.238/activex/AMC.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F33D40E8-EF2E-4363-AE62-9697D889F64F}: NameServer = 172.22.13.254,217.119.117.170
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\bin32\nSvcAppFlt.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\bin32\nSvcIp.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
--
End of file - 6624 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1004.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1005.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1004.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1005.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default
prefs.js - "browser.startup.homepage" - "chrome://google-toolbar/content/new-tab.html"
prefs.js - "extensions.enabledItems" - "personas@christopher.beard:1.6.2, {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.19, {3112ca9c-de6d-4884-a869-9855de68056c}:7.1.20110512W, {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110704, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666]
"Description"=12.0.1.666
"Path"=c:\program files\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npnul32.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default\extensions\
personas@christopher.beard
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{3112ca9c-de6d-4884-a869-9855de68056c}
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-09-17 414416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23 115072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-06 3076144]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-09-05 35736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
C:\Program Files\FileHippo.com\UpdateChecker.exe /background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Administrátor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2008-05-14 29831168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-14 169984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
NvMCTray.dll,NvTaskbarInit -login []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerArchiver Tray]
C:\Program Files\PowerArchiver\PASTARTER.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\program files\real\realplayer\update\realsched.exe -osboot []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Waiting1690]
C:\Windows\stid1690.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-10-01 18:29:58 ----D---- C:\rsit
2011-10-01 18:29:58 ----D---- C:\Program Files\trend micro
2011-09-19 22:37:46 ----D---- C:\Documents and Settings\Administrátor\Application Data\NVIDIA
2011-09-18 16:57:45 ----D---- C:\Documents and Settings\Administrátor\Application Data\Bandoo
2011-09-18 16:57:01 ----D---- C:\Program Files\iLivid
2011-09-17 23:24:43 ----N---- C:\WINDOWS\system32\write.exe
2011-09-17 23:23:44 ----N---- C:\WINDOWS\system32\sndvol32.exe
2011-09-17 23:23:44 ----N---- C:\WINDOWS\system32\hticons.dll
2011-09-17 23:23:43 ----N---- C:\WINDOWS\system32\avwav.dll
2011-09-17 23:23:43 ----N---- C:\WINDOWS\system32\avmeter.dll
2011-09-17 23:23:42 ----N---- C:\WINDOWS\system32\avtapi.dll
2011-09-17 23:23:41 ----N---- C:\WINDOWS\system32\winchat.exe
2011-09-17 23:23:16 ----N---- C:\WINDOWS\system32\charmap.exe
2011-09-17 23:23:16 ----N---- C:\WINDOWS\system32\getuname.dll
2011-09-17 23:23:16 ----N---- C:\WINDOWS\system32\calc.exe
2011-09-17 23:23:15 ----N---- C:\WINDOWS\system32\winmine.exe
2011-09-17 23:23:15 ----N---- C:\WINDOWS\system32\sol.exe
2011-09-17 23:23:15 ----N---- C:\WINDOWS\system32\mshearts.exe
2011-09-17 23:23:15 ----N---- C:\WINDOWS\system32\freecell.exe
2011-09-17 23:23:14 ----N---- C:\WINDOWS\system32\accwiz.exe
2011-09-17 23:23:13 ----N---- C:\WINDOWS\system32\sndrec32.exe
2011-09-17 23:23:13 ----N---- C:\WINDOWS\system32\mplay32.exe
2011-09-17 23:23:13 ----N---- C:\WINDOWS\system32\hypertrm.dll
2011-09-17 23:23:03 ----N---- C:\WINDOWS\system32\mspaint.exe
2011-09-17 23:23:03 ----N---- C:\WINDOWS\system32\clipbrd.exe
2011-09-17 23:22:59 ----N---- C:\WINDOWS\system32\spider.exe
2011-09-17 13:05:08 ----D---- C:\Program Files\Common Files\xing shared
2011-09-17 12:53:43 ----D---- C:\Documents and Settings\All Users\Application Data\Caphyon
2011-09-17 12:38:39 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2011-09-17 12:38:33 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA
2011-09-17 12:38:03 ----N---- C:\WINDOWS\system32\easyupdatusapiu.dll
2011-09-17 12:37:43 ----N---- C:\WINDOWS\system32\nvhdap32.dll
2011-09-17 12:37:42 ----N---- C:\WINDOWS\system32\nvhdagenco322040.dll
2011-09-17 12:37:41 ----N---- C:\WINDOWS\system32\OpenCL.dll
2011-09-17 12:37:40 ----N---- C:\WINDOWS\system32\nvgenco32.dll
2011-09-17 12:37:40 ----N---- C:\WINDOWS\system32\nvdispco32.dll
2011-09-17 12:37:40 ----N---- C:\WINDOWS\system32\nvcuvid.dll
2011-09-17 12:37:40 ----N---- C:\WINDOWS\system32\nvcuvenc.dll
2011-09-17 12:37:40 ----N---- C:\WINDOWS\system32\nvcompiler.dll
2011-09-17 12:37:04 ----D---- C:\Program Files\NVIDIA Corporation
2011-09-17 12:36:50 ----D---- C:\NVIDIA
2011-09-17 12:36:43 ----D---- C:\Program Files\Common Files\Java
2011-09-16 13:52:39 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2011-09-15 20:56:09 ----D---- C:\Documents and Settings\Administrátor\Application Data\Avant Downloader
2011-09-15 15:02:31 ----D---- C:\Documents and Settings\Administrátor\Application Data\ESET
2011-09-15 14:56:41 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-15 14:07:25 ----D---- C:\Documents and Settings\Administrátor\Application Data\Thunderbird
2011-09-15 14:07:17 ----D---- C:\Program Files\Mozilla Thunderbird
2011-09-15 14:06:02 ----D---- C:\Program Files\Mozilla Firefox
2011-09-15 09:18:50 ----A---- C:\WINDOWS\eSellerateEngine.dll
2011-09-15 09:18:48 ----D---- C:\Documents and Settings\All Users\Application Data\TEMP
2011-09-15 09:12:51 ----D---- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2011-09-15 09:12:45 ----D---- C:\Documents and Settings\Administrátor\Application Data\AVS4YOU
2011-09-15 09:10:11 ----D---- C:\Documents and Settings\Administrátor\Application Data\avidemux
2011-09-15 09:03:03 ----D---- C:\Program Files\DebugMode
2011-09-15 08:57:37 ----D---- C:\Program Files\Solveig Multimedia
2011-09-15 08:55:36 ----N---- C:\WINDOWS\system32\Unicows.dll
2011-09-15 08:51:41 ----D---- C:\Program Files\Common Files\AVSMedia
2011-09-15 08:51:25 ----N---- C:\WINDOWS\system32\msxml3a.dll
2011-09-15 08:51:25 ----N---- C:\WINDOWS\system32\GdiPlus.dll
2011-09-15 08:51:25 ----D---- C:\Program Files\AVS4YOU
2011-09-15 08:29:34 ----D---- C:\Documents and Settings\All Users\Application Data\NCH Software
2011-09-15 08:29:25 ----D---- C:\Program Files\NCH Software
2011-09-15 08:29:22 ----D---- C:\Documents and Settings\Administrátor\Application Data\NCH Software
2011-09-14 06:39:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-14 06:35:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-11 11:54:06 ----D---- C:\Program Files\QuickTime
2011-09-11 11:54:06 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2011-09-11 11:53:26 ----D---- C:\Program Files\Common Files\Apple
2011-09-11 11:53:16 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2011-09-10 22:24:21 ----D---- C:\Program Files\Windows Media Encoder Studio Edition
2011-09-07 07:07:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2607712$
2011-09-02 23:17:52 ----RD---- C:\Program Files\Skype
2011-09-02 22:59:03 ----D---- C:\Program Files\ICQ7.6
======List of files/folders modified in the last 1 month======
2011-10-01 18:29:58 ----RD---- C:\Program Files
2011-10-01 18:29:54 ----D---- C:\WINDOWS\Prefetch
2011-10-01 18:26:22 ----D---- C:\WINDOWS\temp
2011-10-01 18:13:41 ----D---- C:\WINDOWS\system32
2011-10-01 18:13:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-01 18:12:52 ----D---- C:\Documents and Settings\Administrátor\Application Data\Skype
2011-10-01 18:09:17 ----D---- C:\WINDOWS\Minidump
2011-10-01 18:09:11 ----D---- C:\WINDOWS
2011-10-01 11:44:18 ----D---- C:\Program Files\PowerArchiver
2011-09-28 08:14:14 ----SD---- C:\WINDOWS\Tasks
2011-09-28 08:12:40 ----D---- C:\WINDOWS\Debug
2011-09-28 08:12:38 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-25 22:36:48 ----D---- C:\Documents and Settings\Administrátor\Application Data\Winamp
2011-09-25 11:26:19 ----D---- C:\Program Files\Common Files
2011-09-25 11:23:29 ----SHD---- C:\WINDOWS\Installer
2011-09-25 11:22:39 ----D---- C:\WINDOWS\WinSxS
2011-09-25 11:21:54 ----D---- C:\Config.Msi
2011-09-25 11:12:45 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-18 19:37:33 ----D---- C:\Program Files\Adobe
2011-09-18 18:40:44 ----HD---- C:\WINDOWS\inf
2011-09-18 07:49:58 ----D---- C:\WINDOWS\system32\CatRoot
2011-09-18 07:48:34 ----DC---- C:\WINDOWS\system32\dllcache
2011-09-18 00:09:13 ----D---- C:\WINDOWS\security
2011-09-17 23:24:52 ----D---- C:\WINDOWS\Help
2011-09-17 23:24:17 ----D---- C:\WINDOWS\Cursors
2011-09-17 23:23:43 ----D---- C:\Program Files\Windows NT
2011-09-17 23:19:29 ----D---- C:\Program Files\Online Services
2011-09-17 13:13:04 ----D---- C:\Program Files\FileHippo.com
2011-09-17 13:05:13 ----D---- C:\Program Files\Real
2011-09-17 13:04:56 ----N---- C:\WINDOWS\system32\rmoc3260.dll
2011-09-17 13:04:44 ----N---- C:\WINDOWS\system32\pndx5032.dll
2011-09-17 13:04:44 ----N---- C:\WINDOWS\system32\pndx5016.dll
2011-09-17 13:04:41 ----N---- C:\WINDOWS\system32\pncrt.dll
2011-09-17 13:04:38 ----N---- C:\WINDOWS\system32\msvcr71.dll
2011-09-17 13:04:38 ----N---- C:\WINDOWS\system32\msvcp71.dll
2011-09-17 12:38:33 ----D---- C:\Documents and Settings
2011-09-17 12:38:12 ----D---- C:\WINDOWS\system32\drivers
2011-09-17 12:36:19 ----N---- C:\WINDOWS\system32\javaws.exe
2011-09-17 12:36:19 ----N---- C:\WINDOWS\system32\javaw.exe
2011-09-17 12:36:19 ----N---- C:\WINDOWS\system32\java.exe
2011-09-17 12:36:19 ----N---- C:\WINDOWS\system32\deployJava1.dll
2011-09-17 12:36:17 ----D---- C:\Program Files\Java
2011-09-17 11:06:15 ----D---- C:\WINDOWS\system32\wbem
2011-09-16 13:52:39 ----D---- C:\Program Files\Eset
2011-09-16 13:47:36 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-09-15 18:49:51 ----D---- C:\Program Files\Messenger
2011-09-15 14:57:36 ----D---- C:\WINDOWS\SoftwareDistribution
2011-09-15 14:06:06 ----D---- C:\Documents and Settings\Administrátor\Application Data\Mozilla
2011-09-15 13:24:54 ----D---- C:\WINDOWS\SxsCaPendDel
2011-09-15 12:56:15 ----D---- C:\Program Files\CDBurnerXP
2011-09-15 08:52:09 ----RSD---- C:\WINDOWS\Fonts
2011-09-14 17:35:39 ----D---- C:\Documents and Settings\Administrátor\Application Data\ICQ
2011-09-14 06:39:20 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-09-14 06:35:26 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-09 11:12:13 ----N---- C:\WINDOWS\system32\crypt32.dll
2011-09-02 23:17:51 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2011-09-02 22:59:44 ----HD---- C:\Program Files\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-02-28 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R2 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-11-12 5504]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-23 36496]
R3 CAM1690;ANTIK PC Camera; C:\WINDOWS\System32\Drivers\cam1690.sys [2007-10-31 180864]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2011-08-04 39824]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 monfilt;monfilt; C:\WINDOWS\system32\drivers\monfilt.sys [2008-02-14 1389056]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-02-28 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-12 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-08-03 12542592]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2008-01-29 54016]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2011-05-10 119528]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2008-01-29 22016]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-10-12 13312]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2006-02-28 5888]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\WINDOWS\system32\drivers\viahduaa.sys [2008-05-08 238080]
S1 MpKslacfc70ff;MpKslacfc70ff; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-05-23 16272]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys []
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WimFltr;WimFltr; C:\WINDOWS\system32\DRIVERS\wimfltr.sys [2008-01-19 131000]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-09-06 974944]
S2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\bin32\nSvcAppFlt.exe []
S2 nSvcIp;ForceWare IP service; C:\Program Files\bin32\nSvcIp.exe []
S2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Modrá smrť
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin
- Příspěvky: 118715
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrť
Zdravím!
Poprosím o log z ComboFix.
Poprosím o log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se
jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine
aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,
pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k
nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- graupel
- Návštěvník
- Příspěvky: 133
- Registrován: 13 bře 2010 15:44
- Bydliště: Košické Oľšany, Slovensko
Re: Modrá smrť
ComboFix 11-10-01.03 - Administrátor 01.10.2011 20:56:59.4.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2559.1972 [GMT 2:00]
Running from: c:\documents and settings\Administrßtor\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\d3d9caps.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 17:18 . 2008-01-11 05:02 31392 ----a-r- c:\windows\system32\drivers\nvhda32.sys
2011-10-01 17:06 . 2011-10-01 17:06 -------- d-----w- c:\windows\nview
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- C:\rsit
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- c:\program files\trend micro
2011-09-19 20:37 . 2011-09-19 20:37 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NVIDIA
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Ilivid Player
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Bandoo
2011-09-18 14:57 . 2011-09-18 15:13 -------- d-----w- c:\program files\iLivid
2011-09-18 04:52 . 2011-09-18 04:52 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2011-09-17 21:23 . 2006-02-28 12:00 44544 ------w- c:\windows\system32\hticons.dll
2011-09-17 21:22 . 2008-04-14 03:42 538624 -c----w- c:\windows\system32\dllcache\spider.exe
2011-09-17 21:22 . 2008-04-14 03:42 538624 ------w- c:\windows\system32\spider.exe
2011-09-17 11:05 . 2011-09-17 11:05 -------- d-----w- c:\program files\Common Files\xing shared
2011-09-17 10:53 . 2011-09-17 10:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Caphyon
2011-09-17 10:45 . 2011-09-17 10:45 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Sun
2011-09-17 10:36 . 2011-09-17 10:36 -------- d-----w- C:\NVIDIA
2011-09-17 10:36 . 2011-09-17 10:36 -------- d-----w- c:\program files\Common Files\Java
2011-09-16 11:52 . 2011-09-16 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-09-15 18:56 . 2011-09-15 18:56 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Avant Downloader
2011-09-15 16:44 . 2011-09-15 16:44 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Identities
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\ESET
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Application Data\ESET
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\Thunderbird
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-15 12:07 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\program files\Mozilla Thunderbird
2011-09-15 07:18 . 2011-09-15 07:18 356352 ----a-w- c:\windows\eSellerateEngine.dll
2011-09-15 07:18 . 2011-09-15 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\Administrátor\Application Data\AVS4YOU
2011-09-15 07:10 . 2011-09-15 07:10 -------- d-----w- c:\documents and settings\Administrátor\Application Data\avidemux
2011-09-15 07:03 . 2011-09-15 07:23 -------- d-----w- c:\program files\DebugMode
2011-09-15 06:57 . 2011-09-15 07:24 -------- d-----w- c:\program files\Solveig Multimedia
2011-09-15 06:55 . 2004-12-07 08:11 258352 ------w- c:\windows\system32\Unicows.dll
2011-09-15 06:55 . 2004-03-08 22:00 224016 ------w- c:\windows\system32\TABCTL32.OCX
2011-09-15 06:55 . 2001-02-20 01:47 140288 ------w- c:\windows\system32\COMDLG32.OCX
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\Common Files\AVSMedia
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\AVS4YOU
2011-09-15 06:51 . 2011-04-06 13:13 1700352 ------w- c:\windows\system32\GdiPlus.dll
2011-09-15 06:51 . 2011-04-06 13:13 24576 ------w- c:\windows\system32\msxml3a.dll
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2011-09-15 06:29 . 2011-09-15 10:58 -------- d-----w- c:\program files\NCH Software
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NCH Software
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-09-11 09:54 . 2011-09-11 10:02 -------- d-----w- c:\program files\QuickTime
2011-09-11 09:54 . 2011-09-11 09:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\program files\Common Files\Apple
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2011-09-10 20:24 . 2011-09-10 20:24 -------- d-----w- c:\program files\Windows Media Encoder Studio Edition
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2011-09-02 21:17 . 2011-09-16 21:09 -------- d-----r- c:\program files\Skype
2011-09-02 20:59 . 2011-09-02 21:00 -------- d-----w- c:\program files\ICQ7.6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-23 16:45 . 2011-05-19 03:57 404640 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-17 11:04 . 2011-07-08 21:08 499712 ------w- c:\windows\system32\msvcp71.dll
2011-09-17 11:04 . 2011-07-08 21:08 348160 ------w- c:\windows\system32\msvcr71.dll
2011-09-17 10:36 . 2011-03-01 16:37 544656 ------w- c:\windows\system32\deployJava1.dll
2011-09-17 10:36 . 2011-03-01 16:37 128000 ------w- c:\windows\system32\javacpl.cpl
2011-09-09 09:12 . 2008-04-14 03:41 599040 ------w- c:\windows\system32\crypt32.dll
2011-08-09 11:57 . 2011-08-09 11:57 154136 ----a-w- c:\windows\system32\drivers\eamon.sys
2011-08-06 17:00 . 2011-08-06 16:02 165232 ---ha-w- c:\documents and settings\Administrátor\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2011-08-04 07:20 . 2011-08-04 07:20 61936 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2011-08-04 07:20 . 2011-08-04 07:20 39824 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2011-08-04 07:20 . 2011-08-04 07:20 147480 ----a-w- c:\windows\system32\drivers\epfw.sys
2011-08-04 07:20 . 2011-08-04 07:20 118104 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-07-28 17:42 . 2011-07-28 17:42 4284535 ----a-w- c:\documents and settings\Administrátor\Application Data\ffdshow.exe
2011-07-28 17:42 . 2011-07-28 17:42 642685 ----a-w- c:\documents and settings\Administrátor\Application Data\xvid.exe
2011-07-28 17:42 . 2011-07-28 17:41 5514668 ----a-w- c:\documents and settings\Administrátor\Application Data\Imgburn.exe
2011-07-28 17:41 . 2011-07-28 17:41 4182178 ----a-w- c:\documents and settings\Administrátor\Application Data\Avisynth.exe
2011-07-27 09:34 . 2011-03-01 16:46 112640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-07-27 09:34 . 2011-03-01 16:46 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-07-15 13:29 . 2008-04-13 22:47 456320 ------w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut3_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 14:02 . 2008-04-13 22:27 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 16:37 . 2011-07-05 16:37 94208 ------w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37 69632 ------w- c:\windows\system32\QuickTime.qts
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-06 3076144]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-02 13570048]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-05 17:04 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 03:42 110592 ------w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 03:42 15360 ------w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-05-14 03:16 29831168 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
2008-04-14 00:12 169984 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-08-02 04:20 13570048 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-08-02 04:20 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-08-02 04:20 1657376 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 03:42 136704 ------w- c:\windows\system32\sti_ci.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 9:20 118104]
R2 ekrn;ESET Service;c:\program files\Eset\ESET Smart Security\ekrn.exe [6.9.2011 18:16 974944]
R3 CAM1690;ANTIK PC Camera;c:\windows\system32\drivers\cam1690.sys [31.10.2007 14:34 180864]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1.10.2011 19:18 31392]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1.3.2011 15:23 238080]
S1 MpKslacfc70ff;MpKslacfc70ff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-09-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-09-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: Interfaces\{F33D40E8-EF2E-4363-AE62-9697D889F64F}: NameServer = 172.22.13.254,217.119.117.170
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://195.113.207.238/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default\
FF - prefs.js: browser.startup.homepage - chrome://google-toolbar/content/new-tab.html
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-FileHippo - c:\program files\FileHippo.com\UpdateChecker.exe
MSConfigStartUp-Google Update - c:\documents and settings\Administrátor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-GrooveMonitor - c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
MSConfigStartUp-PowerArchiver Tray - c:\program files\PowerArchiver\PASTARTER.EXE
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-TkBellExe - c:\program files\real\realplayer\update\realsched.exe
MSConfigStartUp-USBToolTip - c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
MSConfigStartUp-Waiting1690 - c:\windows\stid1690.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 20:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-10-01 21:00:40
ComboFix-quarantined-files.txt 2011-10-01 19:00
.
Pre-Run: 19 410 178 048 bytes free
Post-Run: 19 434 848 256 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 99B7A11D5889944355E18C1A6C91B7C2
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2559.1972 [GMT 2:00]
Running from: c:\documents and settings\Administrßtor\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\d3d9caps.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 17:18 . 2008-01-11 05:02 31392 ----a-r- c:\windows\system32\drivers\nvhda32.sys
2011-10-01 17:06 . 2011-10-01 17:06 -------- d-----w- c:\windows\nview
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- C:\rsit
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- c:\program files\trend micro
2011-09-19 20:37 . 2011-09-19 20:37 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NVIDIA
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Ilivid Player
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Bandoo
2011-09-18 14:57 . 2011-09-18 15:13 -------- d-----w- c:\program files\iLivid
2011-09-18 04:52 . 2011-09-18 04:52 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2011-09-17 21:23 . 2006-02-28 12:00 44544 ------w- c:\windows\system32\hticons.dll
2011-09-17 21:22 . 2008-04-14 03:42 538624 -c----w- c:\windows\system32\dllcache\spider.exe
2011-09-17 21:22 . 2008-04-14 03:42 538624 ------w- c:\windows\system32\spider.exe
2011-09-17 11:05 . 2011-09-17 11:05 -------- d-----w- c:\program files\Common Files\xing shared
2011-09-17 10:53 . 2011-09-17 10:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Caphyon
2011-09-17 10:45 . 2011-09-17 10:45 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Sun
2011-09-17 10:36 . 2011-09-17 10:36 -------- d-----w- C:\NVIDIA
2011-09-17 10:36 . 2011-09-17 10:36 -------- d-----w- c:\program files\Common Files\Java
2011-09-16 11:52 . 2011-09-16 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-09-15 18:56 . 2011-09-15 18:56 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Avant Downloader
2011-09-15 16:44 . 2011-09-15 16:44 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Identities
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\ESET
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Application Data\ESET
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\Thunderbird
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-15 12:07 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\program files\Mozilla Thunderbird
2011-09-15 07:18 . 2011-09-15 07:18 356352 ----a-w- c:\windows\eSellerateEngine.dll
2011-09-15 07:18 . 2011-09-15 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\Administrátor\Application Data\AVS4YOU
2011-09-15 07:10 . 2011-09-15 07:10 -------- d-----w- c:\documents and settings\Administrátor\Application Data\avidemux
2011-09-15 07:03 . 2011-09-15 07:23 -------- d-----w- c:\program files\DebugMode
2011-09-15 06:57 . 2011-09-15 07:24 -------- d-----w- c:\program files\Solveig Multimedia
2011-09-15 06:55 . 2004-12-07 08:11 258352 ------w- c:\windows\system32\Unicows.dll
2011-09-15 06:55 . 2004-03-08 22:00 224016 ------w- c:\windows\system32\TABCTL32.OCX
2011-09-15 06:55 . 2001-02-20 01:47 140288 ------w- c:\windows\system32\COMDLG32.OCX
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\Common Files\AVSMedia
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\AVS4YOU
2011-09-15 06:51 . 2011-04-06 13:13 1700352 ------w- c:\windows\system32\GdiPlus.dll
2011-09-15 06:51 . 2011-04-06 13:13 24576 ------w- c:\windows\system32\msxml3a.dll
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2011-09-15 06:29 . 2011-09-15 10:58 -------- d-----w- c:\program files\NCH Software
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NCH Software
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-09-11 09:54 . 2011-09-11 10:02 -------- d-----w- c:\program files\QuickTime
2011-09-11 09:54 . 2011-09-11 09:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\program files\Common Files\Apple
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2011-09-10 20:24 . 2011-09-10 20:24 -------- d-----w- c:\program files\Windows Media Encoder Studio Edition
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2011-09-02 21:17 . 2011-09-16 21:09 -------- d-----r- c:\program files\Skype
2011-09-02 20:59 . 2011-09-02 21:00 -------- d-----w- c:\program files\ICQ7.6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-23 16:45 . 2011-05-19 03:57 404640 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-17 11:04 . 2011-07-08 21:08 499712 ------w- c:\windows\system32\msvcp71.dll
2011-09-17 11:04 . 2011-07-08 21:08 348160 ------w- c:\windows\system32\msvcr71.dll
2011-09-17 10:36 . 2011-03-01 16:37 544656 ------w- c:\windows\system32\deployJava1.dll
2011-09-17 10:36 . 2011-03-01 16:37 128000 ------w- c:\windows\system32\javacpl.cpl
2011-09-09 09:12 . 2008-04-14 03:41 599040 ------w- c:\windows\system32\crypt32.dll
2011-08-09 11:57 . 2011-08-09 11:57 154136 ----a-w- c:\windows\system32\drivers\eamon.sys
2011-08-06 17:00 . 2011-08-06 16:02 165232 ---ha-w- c:\documents and settings\Administrátor\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2011-08-04 07:20 . 2011-08-04 07:20 61936 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2011-08-04 07:20 . 2011-08-04 07:20 39824 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2011-08-04 07:20 . 2011-08-04 07:20 147480 ----a-w- c:\windows\system32\drivers\epfw.sys
2011-08-04 07:20 . 2011-08-04 07:20 118104 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-07-28 17:42 . 2011-07-28 17:42 4284535 ----a-w- c:\documents and settings\Administrátor\Application Data\ffdshow.exe
2011-07-28 17:42 . 2011-07-28 17:42 642685 ----a-w- c:\documents and settings\Administrátor\Application Data\xvid.exe
2011-07-28 17:42 . 2011-07-28 17:41 5514668 ----a-w- c:\documents and settings\Administrátor\Application Data\Imgburn.exe
2011-07-28 17:41 . 2011-07-28 17:41 4182178 ----a-w- c:\documents and settings\Administrátor\Application Data\Avisynth.exe
2011-07-27 09:34 . 2011-03-01 16:46 112640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-07-27 09:34 . 2011-03-01 16:46 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-07-15 13:29 . 2008-04-13 22:47 456320 ------w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut3_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 14:02 . 2008-04-13 22:27 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 16:37 . 2011-07-05 16:37 94208 ------w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37 69632 ------w- c:\windows\system32\QuickTime.qts
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-06 3076144]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-02 13570048]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-05 17:04 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 03:42 110592 ------w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 03:42 15360 ------w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-05-14 03:16 29831168 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
2008-04-14 00:12 169984 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-08-02 04:20 13570048 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-08-02 04:20 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-08-02 04:20 1657376 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 03:42 136704 ------w- c:\windows\system32\sti_ci.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 9:20 118104]
R2 ekrn;ESET Service;c:\program files\Eset\ESET Smart Security\ekrn.exe [6.9.2011 18:16 974944]
R3 CAM1690;ANTIK PC Camera;c:\windows\system32\drivers\cam1690.sys [31.10.2007 14:34 180864]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1.10.2011 19:18 31392]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1.3.2011 15:23 238080]
S1 MpKslacfc70ff;MpKslacfc70ff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-09-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-09-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: Interfaces\{F33D40E8-EF2E-4363-AE62-9697D889F64F}: NameServer = 172.22.13.254,217.119.117.170
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://195.113.207.238/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default\
FF - prefs.js: browser.startup.homepage - chrome://google-toolbar/content/new-tab.html
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-FileHippo - c:\program files\FileHippo.com\UpdateChecker.exe
MSConfigStartUp-Google Update - c:\documents and settings\Administrátor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-GrooveMonitor - c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
MSConfigStartUp-PowerArchiver Tray - c:\program files\PowerArchiver\PASTARTER.EXE
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-TkBellExe - c:\program files\real\realplayer\update\realsched.exe
MSConfigStartUp-USBToolTip - c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
MSConfigStartUp-Waiting1690 - c:\windows\stid1690.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 20:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-10-01 21:00:40
ComboFix-quarantined-files.txt 2011-10-01 19:00
.
Pre-Run: 19 410 178 048 bytes free
Post-Run: 19 434 848 256 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 99B7A11D5889944355E18C1A6C91B7C2
- Rudy
- Site Admin
- Příspěvky: 118715
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrť
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
Firefox::
FF - ProfilePath - c:\documents and settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default\
FF - prefs.js: browser.startup.homepage - chrome://google-toolbar/content/new-tab.html
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- graupel
- Návštěvník
- Příspěvky: 133
- Registrován: 13 bře 2010 15:44
- Bydliště: Košické Oľšany, Slovensko
Re: Modrá smrť
Do logu CF som dal na vymazanie len ten Kernel v registry, tie doplnky vo Firefoxe používam, takže som ich nemazal.
ComboFix 11-10-01.03 - Administrátor 01.10.2011 22:15:22.5.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2559.1903 [GMT 2:00]
Running from: c:\documents and settings\Administrátor\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrátor\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 19:09 . 2011-10-01 19:09 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Malwarebytes
2011-10-01 19:09 . 2011-10-01 19:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-01 17:18 . 2008-01-11 05:02 31392 ----a-r- c:\windows\system32\drivers\nvhda32.sys
2011-10-01 17:06 . 2011-10-01 17:06 -------- d-----w- c:\windows\nview
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- C:\rsit
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- c:\program files\trend micro
2011-09-19 20:37 . 2011-09-19 20:37 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NVIDIA
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Ilivid Player
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Bandoo
2011-09-18 14:57 . 2011-09-18 15:13 -------- d-----w- c:\program files\iLivid
2011-09-18 04:52 . 2011-09-18 04:52 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2011-09-17 21:23 . 2006-02-28 12:00 44544 ------w- c:\windows\system32\hticons.dll
2011-09-17 21:22 . 2008-04-14 03:42 538624 -c----w- c:\windows\system32\dllcache\spider.exe
2011-09-17 21:22 . 2008-04-14 03:42 538624 ------w- c:\windows\system32\spider.exe
2011-09-17 11:05 . 2011-09-17 11:05 -------- d-----w- c:\program files\Common Files\xing shared
2011-09-17 10:53 . 2011-09-17 10:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Caphyon
2011-09-17 10:45 . 2011-09-17 10:45 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Sun
2011-09-17 10:36 . 2011-09-17 10:36 -------- d-----w- C:\NVIDIA
2011-09-16 11:52 . 2011-09-16 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-09-15 18:56 . 2011-09-15 18:56 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Avant Downloader
2011-09-15 16:44 . 2011-09-15 16:44 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Identities
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\ESET
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Application Data\ESET
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\Thunderbird
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-15 12:07 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\program files\Mozilla Thunderbird
2011-09-15 07:18 . 2011-09-15 07:18 356352 ----a-w- c:\windows\eSellerateEngine.dll
2011-09-15 07:18 . 2011-09-15 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\Administrátor\Application Data\AVS4YOU
2011-09-15 07:10 . 2011-09-15 07:10 -------- d-----w- c:\documents and settings\Administrátor\Application Data\avidemux
2011-09-15 07:03 . 2011-09-15 07:23 -------- d-----w- c:\program files\DebugMode
2011-09-15 06:57 . 2011-09-15 07:24 -------- d-----w- c:\program files\Solveig Multimedia
2011-09-15 06:55 . 2004-12-07 08:11 258352 ------w- c:\windows\system32\Unicows.dll
2011-09-15 06:55 . 2004-03-08 22:00 224016 ------w- c:\windows\system32\TABCTL32.OCX
2011-09-15 06:55 . 2001-02-20 01:47 140288 ------w- c:\windows\system32\COMDLG32.OCX
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\Common Files\AVSMedia
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\AVS4YOU
2011-09-15 06:51 . 2011-04-06 13:13 1700352 ------w- c:\windows\system32\GdiPlus.dll
2011-09-15 06:51 . 2011-04-06 13:13 24576 ------w- c:\windows\system32\msxml3a.dll
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2011-09-15 06:29 . 2011-09-15 10:58 -------- d-----w- c:\program files\NCH Software
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NCH Software
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-09-11 09:54 . 2011-09-11 10:02 -------- d-----w- c:\program files\QuickTime
2011-09-11 09:54 . 2011-09-11 09:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\program files\Common Files\Apple
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2011-09-10 20:24 . 2011-09-10 20:24 -------- d-----w- c:\program files\Windows Media Encoder Studio Edition
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2011-09-02 21:17 . 2011-09-16 21:09 -------- d-----r- c:\program files\Skype
2011-09-02 20:59 . 2011-09-02 21:00 -------- d-----w- c:\program files\ICQ7.6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-23 16:45 . 2011-05-19 03:57 404640 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-17 11:04 . 2011-07-08 21:08 499712 ------w- c:\windows\system32\msvcp71.dll
2011-09-17 11:04 . 2011-07-08 21:08 348160 ------w- c:\windows\system32\msvcr71.dll
2011-09-17 10:36 . 2011-03-01 16:37 544656 ------w- c:\windows\system32\deployJava1.dll
2011-09-09 09:12 . 2008-04-14 03:41 599040 ------w- c:\windows\system32\crypt32.dll
2011-08-09 11:57 . 2011-08-09 11:57 154136 ----a-w- c:\windows\system32\drivers\eamon.sys
2011-08-06 17:00 . 2011-08-06 16:02 165232 ---ha-w- c:\documents and settings\Administrátor\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2011-08-04 07:20 . 2011-08-04 07:20 61936 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2011-08-04 07:20 . 2011-08-04 07:20 39824 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2011-08-04 07:20 . 2011-08-04 07:20 147480 ----a-w- c:\windows\system32\drivers\epfw.sys
2011-08-04 07:20 . 2011-08-04 07:20 118104 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-07-28 17:42 . 2011-07-28 17:42 4284535 ----a-w- c:\documents and settings\Administrátor\Application Data\ffdshow.exe
2011-07-28 17:42 . 2011-07-28 17:42 642685 ----a-w- c:\documents and settings\Administrátor\Application Data\xvid.exe
2011-07-28 17:42 . 2011-07-28 17:41 5514668 ----a-w- c:\documents and settings\Administrátor\Application Data\Imgburn.exe
2011-07-28 17:41 . 2011-07-28 17:41 4182178 ----a-w- c:\documents and settings\Administrátor\Application Data\Avisynth.exe
2011-07-27 09:34 . 2011-03-01 16:46 112640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-07-27 09:34 . 2011-03-01 16:46 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-07-15 13:29 . 2008-04-13 22:47 456320 ------w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut3_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 14:02 . 2008-04-13 22:27 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 16:37 . 2011-07-05 16:37 94208 ------w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37 69632 ------w- c:\windows\system32\QuickTime.qts
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-06 3076144]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-02 13570048]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-05 17:04 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 03:42 110592 ------w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 03:42 15360 ------w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-05-14 03:16 29831168 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
2008-04-14 00:12 169984 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-08-02 04:20 13570048 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-08-02 04:20 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-08-02 04:20 1657376 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 03:42 136704 ------w- c:\windows\system32\sti_ci.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 9:20 118104]
R2 ekrn;ESET Service;c:\program files\Eset\ESET Smart Security\ekrn.exe [6.9.2011 18:16 974944]
R3 CAM1690;ANTIK PC Camera;c:\windows\system32\drivers\cam1690.sys [31.10.2007 14:34 180864]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1.10.2011 19:18 31392]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1.3.2011 15:23 238080]
S1 MpKslacfc70ff;MpKslacfc70ff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-10-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-09-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: Interfaces\{F33D40E8-EF2E-4363-AE62-9697D889F64F}: NameServer = 172.22.13.254,217.119.117.170
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://195.113.207.238/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default\
FF - prefs.js: browser.startup.homepage - chrome://google-toolbar/content/new-tab.html
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 22:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2304)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-10-01 22:19:10
ComboFix-quarantined-files.txt 2011-10-01 20:19
ComboFix2.txt 2011-10-01 19:00
.
Pre-Run: 19 462 696 960 bytes free
Post-Run: 12 adresárov, 19 450 830 848 voľných bajtov
.
- - End Of File - - 9F691D336D7D200A65D50CDF69E04D88
Kód: Vybrat vše
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2559.1903 [GMT 2:00]
Running from: c:\documents and settings\Administrátor\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrátor\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 19:09 . 2011-10-01 19:09 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Malwarebytes
2011-10-01 19:09 . 2011-10-01 19:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-01 17:18 . 2008-01-11 05:02 31392 ----a-r- c:\windows\system32\drivers\nvhda32.sys
2011-10-01 17:06 . 2011-10-01 17:06 -------- d-----w- c:\windows\nview
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- C:\rsit
2011-10-01 16:29 . 2011-10-01 16:30 -------- d-----w- c:\program files\trend micro
2011-09-19 20:37 . 2011-09-19 20:37 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NVIDIA
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Ilivid Player
2011-09-18 14:57 . 2011-09-18 14:57 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Bandoo
2011-09-18 14:57 . 2011-09-18 15:13 -------- d-----w- c:\program files\iLivid
2011-09-18 04:52 . 2011-09-18 04:52 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2011-09-17 21:23 . 2006-02-28 12:00 44544 ------w- c:\windows\system32\hticons.dll
2011-09-17 21:22 . 2008-04-14 03:42 538624 -c----w- c:\windows\system32\dllcache\spider.exe
2011-09-17 21:22 . 2008-04-14 03:42 538624 ------w- c:\windows\system32\spider.exe
2011-09-17 11:05 . 2011-09-17 11:05 -------- d-----w- c:\program files\Common Files\xing shared
2011-09-17 10:53 . 2011-09-17 10:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Caphyon
2011-09-17 10:45 . 2011-09-17 10:45 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Sun
2011-09-17 10:36 . 2011-09-17 10:36 -------- d-----w- C:\NVIDIA
2011-09-16 11:52 . 2011-09-16 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-09-15 18:56 . 2011-09-15 18:56 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Avant Downloader
2011-09-15 16:44 . 2011-09-15 16:44 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Identities
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\ESET
2011-09-15 13:09 . 2011-09-15 13:09 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\ESET
2011-09-15 13:02 . 2011-09-15 13:02 -------- d-----w- c:\documents and settings\Administrátor\Application Data\ESET
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Local Settings\Application Data\Thunderbird
2011-09-15 12:14 . 2011-09-15 12:14 -------- d-----w- c:\documents and settings\Bežný používateľ\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\documents and settings\Administrátor\Local Settings\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-15 12:07 -------- d-----w- c:\documents and settings\Administrátor\Application Data\Thunderbird
2011-09-15 12:07 . 2011-09-22 15:02 -------- d-----w- c:\program files\Mozilla Thunderbird
2011-09-15 07:18 . 2011-09-15 07:18 356352 ----a-w- c:\windows\eSellerateEngine.dll
2011-09-15 07:18 . 2011-09-15 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2011-09-15 07:12 . 2011-09-15 07:12 -------- d-----w- c:\documents and settings\Administrátor\Application Data\AVS4YOU
2011-09-15 07:10 . 2011-09-15 07:10 -------- d-----w- c:\documents and settings\Administrátor\Application Data\avidemux
2011-09-15 07:03 . 2011-09-15 07:23 -------- d-----w- c:\program files\DebugMode
2011-09-15 06:57 . 2011-09-15 07:24 -------- d-----w- c:\program files\Solveig Multimedia
2011-09-15 06:55 . 2004-12-07 08:11 258352 ------w- c:\windows\system32\Unicows.dll
2011-09-15 06:55 . 2004-03-08 22:00 224016 ------w- c:\windows\system32\TABCTL32.OCX
2011-09-15 06:55 . 2001-02-20 01:47 140288 ------w- c:\windows\system32\COMDLG32.OCX
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\Common Files\AVSMedia
2011-09-15 06:51 . 2011-09-15 10:00 -------- d-----w- c:\program files\AVS4YOU
2011-09-15 06:51 . 2011-04-06 13:13 1700352 ------w- c:\windows\system32\GdiPlus.dll
2011-09-15 06:51 . 2011-04-06 13:13 24576 ------w- c:\windows\system32\msxml3a.dll
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2011-09-15 06:29 . 2011-09-15 10:58 -------- d-----w- c:\program files\NCH Software
2011-09-15 06:29 . 2011-09-15 06:29 -------- d-----w- c:\documents and settings\Administrátor\Application Data\NCH Software
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-09-11 09:54 . 2011-09-11 09:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-09-11 09:54 . 2011-09-11 10:02 -------- d-----w- c:\program files\QuickTime
2011-09-11 09:54 . 2011-09-11 09:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\program files\Common Files\Apple
2011-09-11 09:53 . 2011-09-11 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2011-09-10 20:24 . 2011-09-10 20:24 -------- d-----w- c:\program files\Windows Media Encoder Studio Edition
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2011-09-02 21:17 . 2011-09-16 21:09 -------- d-----r- c:\program files\Skype
2011-09-02 20:59 . 2011-09-02 21:00 -------- d-----w- c:\program files\ICQ7.6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-23 16:45 . 2011-05-19 03:57 404640 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-17 11:04 . 2011-07-08 21:08 499712 ------w- c:\windows\system32\msvcp71.dll
2011-09-17 11:04 . 2011-07-08 21:08 348160 ------w- c:\windows\system32\msvcr71.dll
2011-09-17 10:36 . 2011-03-01 16:37 544656 ------w- c:\windows\system32\deployJava1.dll
2011-09-09 09:12 . 2008-04-14 03:41 599040 ------w- c:\windows\system32\crypt32.dll
2011-08-09 11:57 . 2011-08-09 11:57 154136 ----a-w- c:\windows\system32\drivers\eamon.sys
2011-08-06 17:00 . 2011-08-06 16:02 165232 ---ha-w- c:\documents and settings\Administrátor\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2011-08-04 07:20 . 2011-08-04 07:20 61936 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2011-08-04 07:20 . 2011-08-04 07:20 39824 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2011-08-04 07:20 . 2011-08-04 07:20 147480 ----a-w- c:\windows\system32\drivers\epfw.sys
2011-08-04 07:20 . 2011-08-04 07:20 118104 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-07-28 17:42 . 2011-07-28 17:42 4284535 ----a-w- c:\documents and settings\Administrátor\Application Data\ffdshow.exe
2011-07-28 17:42 . 2011-07-28 17:42 642685 ----a-w- c:\documents and settings\Administrátor\Application Data\xvid.exe
2011-07-28 17:42 . 2011-07-28 17:41 5514668 ----a-w- c:\documents and settings\Administrátor\Application Data\Imgburn.exe
2011-07-28 17:41 . 2011-07-28 17:41 4182178 ----a-w- c:\documents and settings\Administrátor\Application Data\Avisynth.exe
2011-07-27 09:34 . 2011-03-01 16:46 112640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-07-27 09:34 . 2011-03-01 16:46 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-07-15 13:29 . 2008-04-13 22:47 456320 ------w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut3_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 17:48 . 2011-03-01 15:19 40960 ----a-r- c:\documents and settings\Administrátor\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe
2011-07-08 14:02 . 2008-04-13 22:27 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2011-07-05 16:37 . 2011-07-05 16:37 94208 ------w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37 69632 ------w- c:\windows\system32\QuickTime.qts
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-06 3076144]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-02 13570048]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-05 17:04 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 03:42 110592 ------w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 03:42 15360 ------w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2008-05-14 03:16 29831168 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
2008-04-14 00:12 169984 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-08-02 04:20 13570048 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-08-02 04:20 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-08-02 04:20 1657376 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 03:42 136704 ------w- c:\windows\system32\sti_ci.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 9:20 118104]
R2 ekrn;ESET Service;c:\program files\Eset\ESET Smart Security\ekrn.exe [6.9.2011 18:16 974944]
R3 CAM1690;ANTIK PC Camera;c:\windows\system32\drivers\cam1690.sys [31.10.2007 14:34 180864]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [1.10.2011 19:18 31392]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1.3.2011 15:23 238080]
S1 MpKslacfc70ff;MpKslacfc70ff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AB3D53E8-B9BA-4495-82BC-61EE3A0F858B}\MpKslacfc70ff.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-10-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-10-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
2011-09-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-57989841-725345543-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 13:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: Interfaces\{F33D40E8-EF2E-4363-AE62-9697D889F64F}: NameServer = 172.22.13.254,217.119.117.170
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://195.113.207.238/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Administrátor\Application Data\Mozilla\Firefox\Profiles\rmwxrtfw.default\
FF - prefs.js: browser.startup.homepage - chrome://google-toolbar/content/new-tab.html
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 22:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2304)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-10-01 22:19:10
ComboFix-quarantined-files.txt 2011-10-01 20:19
ComboFix2.txt 2011-10-01 19:00
.
Pre-Run: 19 462 696 960 bytes free
Post-Run: 12 adresárov, 19 450 830 848 voľných bajtov
.
- - End Of File - - 9F691D336D7D200A65D50CDF69E04D88
- Rudy
- Site Admin
- Příspěvky: 118715
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrť
OK. Log již vypadá čistý. Ještě maličkost. Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako oprava.reg a dvouklikem ho rozbalte.Regedit4
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"=dword:00000001
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- graupel
- Návštěvník
- Příspěvky: 133
- Registrován: 13 bře 2010 15:44
- Bydliště: Košické Oľšany, Slovensko
Re: Modrá smrť
Ďakujem.
- Rudy
- Site Admin
- Příspěvky: 118715
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrť
Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.