
RSIT - HJT ... nic neskoncilo svoju pracu.ComboFix som po spusteni z pracovnej plochy zrazu stratil.Musel som stiahúť znova - spustit z nudzoveho.PC sa restartol a dokoncil skenovanie.Tu je log a viem,ze je poriadne este zasvineny.Prosim o dalsie rady.
Ďakujem !
ComboFix 10-02-08.02 - Krylias 08.02.2010 22:07:23.3.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3327.2863 [GMT 1:00]
Running from: c:\documents and settings\Krylias\Desktop\ComboFix.exe
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
ADS - svchost.exe: deleted 35328 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\docume~1\Krylias\LOCALS~1\Temp\init.exe
c:\documents and settings\Krylias\Application Data\Microsoft\~DFK796ebb.tmp
c:\documents and settings\Krylias\Application Data\Microsoft\1eaadjc.dll
c:\documents and settings\Krylias\Application Data\Microsoft\bass.dll
c:\documents and settings\Krylias\Application Data\Microsoft\kfgresk.dll
c:\documents and settings\Krylias\Application Data\Microsoft\mjcriu.dll
c:\documents and settings\Krylias\Application Data\Microsoft\peaadje.dll
c:\documents and settings\Krylias\Application Data\Microsoft\qwadjb.dll
c:\documents and settings\Krylias\Application Data\Microsoft\rsaadjd.dll
c:\documents and settings\Krylias\Local Settings\temp\init.exe
c:\documents and settings\Krylias\oashdihasidhasuidhiasdhiashdiuasdhasd
C:\lsass.exe
c:\program files\Adobe\acrotray .exe
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
c:\recycler\S-1-5-21-0243936033-3052116371-381863308-1811
c:\recycler\S-1-5-21-1240283750-1518874365-927648591-1245
c:\recycler\S-1-5-21-1362918446-2525656442-491318994-8672
c:\recycler\S-1-5-21-3107540501-4096314710-189190828-1088
c:\recycler\S-1-5-21-4772001906-1010738014-193359545-0425
c:\recycler\S-1-5-21-9365767676-3310523789-870391701-0558
c:\recycler\S-1-5-21-9527775185-7985083491-438596722-5582
c:\windows\ccdrive32.exe
c:\windows\logfile32.txt
c:\windows\system\update.exe
c:\windows\system32\app_dll.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\gyuu .exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mssrv32.exe
c:\windows\system32\regedit .exe
c:\windows\system32\regedit.exe
c:\windows\system32\sdra64.exe
c:\windows\system32\twain_32.dll
D:\AUTORUN.INF
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICF
-------\Legacy_MSUPDATE
-------\Service_ICF
-------\Service_msupdate
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.
2010-02-08 20:39 . 2010-02-08 20:56 22528 ----a-w- C:\hfhhhml.exe
2010-02-08 20:22 . 2010-02-08 20:57 23552 ----a-w- C:\ecjew.exe
2010-02-08 20:22 . 2010-02-08 20:56 202752 ----a-w- C:\uipcafn.exe
2010-02-08 20:22 . 2010-02-08 20:56 121344 ----a-w- C:\rkfo.exe
2010-02-08 20:22 . 2010-02-08 20:56 132096 ----a-w- C:\brhpxf.exe
2010-02-08 20:22 . 2010-02-08 20:28 23552 ----a-w- C:\ecjew .exe
2010-02-08 20:21 . 2010-02-08 21:07 200704 ----a-w- C:\dxayligu.exe
2010-02-08 20:21 . 2010-02-08 20:21 43520 --sh--r- c:\windows\updated7.exe
2010-02-08 20:21 . 2010-02-08 20:27 43520 ---h--w- c:\windows\system32\gyuu.exe
2010-02-08 20:14 . 2010-02-08 20:14 118284 ----a-w- c:\windows\system32\CwaZD-_CV5.exe
2010-02-08 20:13 . 2010-02-08 21:19 791552 ----a-w- c:\windows\system32\drivers\uzmvr.sys
2010-02-08 20:10 . 2010-02-08 21:07 129536 ----a-w- C:\xkmd.exe
2010-02-08 20:10 . 2010-02-08 21:07 118784 ----a-w- C:\xbxpi.exe
2010-02-08 20:10 . 2010-02-08 21:07 58368 ----a-w- C:\khlo.exe
2010-02-08 20:10 . 2010-02-08 21:07 20480 ----a-w- C:\bkxov.exe
2010-02-08 20:10 . 2010-02-08 20:27 37888 ----a-w- C:\jvgf.exe
2010-02-08 19:26 . 2010-02-08 19:26 866160 ----a-w- c:\documents and settings\Krylias\Application Data\Hide IP NG\hideipng-update.exe
2010-02-08 19:25 . 2010-02-08 19:34 -------- d-----w- c:\documents and settings\Krylias\Application Data\Hide IP NG
2010-02-08 19:13 . 2010-02-08 19:12 196608 ----a-w- c:\windows\system32\HMIPCore.dll
2010-02-08 19:12 . 2009-01-27 00:56 168256 ----a-w- c:\windows\system32\SecureNet.dll
2010-02-08 00:00 . 2010-02-08 00:00 -------- d-----w- c:\documents and settings\All Users\Application Data\SRSLabs
2010-02-07 23:59 . 2010-02-07 23:59 -------- d-----w- c:\program files\SRSLabs
2010-02-07 23:59 . 2010-02-07 23:59 -------- d-----w- c:\program files\Common Files\SRS
2010-02-05 20:24 . 2010-02-05 20:25 -------- d-----w- C:\AUTORUN
2010-02-04 15:51 . 2010-02-08 21:15 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 08:04 . 2010-02-08 20:25 12815360 ----a-w- C:\MP10Setup.exe
2010-01-24 11:34 . 2010-01-24 11:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2010-01-24 11:34 . 2010-02-04 16:17 171552 ----a-w- c:\windows\system32\guard32.dll
2010-01-24 11:34 . 2010-02-04 16:17 134344 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-01-24 11:34 . 2010-01-29 07:21 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-01-24 11:34 . 2010-01-29 07:21 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-01-24 11:34 . 2010-01-24 11:34 -------- d-----w- c:\program files\COMODO
2010-01-22 19:33 . 2009-12-23 19:54 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-22 19:31 . 2010-01-22 19:38 -------- d-----w- c:\program files\Combined Community Codec Pack
2010-01-21 16:02 . 2010-01-21 16:02 -------- d-----w- c:\program files\CoffeeCup Software
2010-01-21 00:10 . 2010-01-21 00:10 -------- d-----w- c:\program files\Zoner
2010-01-20 00:37 . 2010-01-20 00:37 -------- d-----w- c:\documents and settings\Krylias\Application Data\SteelBytes
2010-01-19 22:03 . 2010-01-19 22:03 -------- d-----w- c:\program files\IObit
2010-01-17 19:20 . 2010-01-17 19:20 -------- d-----w- c:\documents and settings\Krylias\Application Data\Imagenomic
2010-01-17 19:19 . 2010-01-17 19:19 -------- d-----w- c:\program files\Imagenomic
2010-01-13 22:29 . 2010-01-13 22:29 -------- d-----w- c:\documents and settings\Krylias\Application Data\BackTalk
2010-01-13 22:29 . 2004-07-26 03:16 598086 ----a-w- c:\documents and settings\Krylias\Application Data\BackTalk\Helper.exe
2010-01-13 22:28 . 2010-01-13 22:28 -------- d-----w- c:\program files\DVD Shrink Pro
2010-01-11 20:42 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-01-11 18:16 . 2010-01-11 18:16 -------- d-----w- c:\program files\Silabs
2010-01-11 18:16 . 2009-10-08 12:41 63488 ----a-w- c:\windows\system32\drivers\silabser.sys
2010-01-11 18:16 . 2009-10-08 12:41 17920 ----a-w- c:\windows\system32\drivers\silabenm.sys
2010-01-11 18:16 . 2009-10-08 12:41 1112288 ----a-w- c:\windows\system32\WdfCoinstaller01007.dll
2010-01-11 18:13 . 2010-01-11 18:13 -------- d-----w- c:\windows\system32\Silabs
2010-01-11 18:13 . 2010-01-11 18:13 -------- d-----w- C:\SiLabs
2010-01-10 23:00 . 2010-01-10 23:29 -------- d-----w- c:\documents and settings\Krylias\Local Settings\Application Data\AskToolbar
2010-01-10 22:57 . 2010-01-10 22:57 -------- d-----w- c:\program files\PFPortChecker
2010-01-10 22:38 . 2010-02-07 16:27 -------- d-----w- c:\documents and settings\Krylias\Application Data\uTorrent
2010-01-10 22:38 . 2010-01-10 22:37 697965 ----a-w- c:\documents and settings\Krylias\Application Data\uTorrent\unins000.exe
2010-01-10 22:38 . 2009-11-30 19:00 289584 ----a-w- c:\documents and settings\Krylias\Application Data\uTorrent\utorrent.exe
2010-01-10 22:38 . 2009-09-12 21:20 245248 ----a-w- c:\documents and settings\Krylias\Application Data\uTorrent\half-open-fix.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 21:19 . 2009-10-04 13:54 -------- d-----w- c:\program files\SPAMfighter
2010-02-08 20:57 . 2009-10-07 12:25 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-08 20:28 . 2008-04-14 03:42 14336 ----a-w- c:\windows\system32\svchost.exe
2010-02-08 20:22 . 2009-09-20 00:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-08 20:12 . 2009-12-08 17:16 -------- d-----w- c:\program files\QuickTime Alternative
2010-02-08 20:12 . 2009-09-18 22:51 -------- d-----w- c:\program files\iTunes
2010-02-08 20:12 . 2009-11-29 13:02 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-02-08 20:12 . 2009-12-25 20:52 -------- d-----w- c:\program files\FirefoxPreloader
2010-02-08 20:11 . 2009-09-18 20:38 -------- d-----w- c:\program files\Rainlendar2
2010-02-08 19:48 . 2009-09-17 22:59 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-02-08 19:26 . 2009-09-18 15:43 -------- d-----w- c:\documents and settings\Krylias\Application Data\Skype
2010-02-08 15:03 . 2009-09-18 15:44 -------- d-----w- c:\documents and settings\Krylias\Application Data\skypePM
2010-02-08 12:21 . 2009-10-29 18:15 -------- d-----w- c:\documents and settings\Krylias\Application Data\dvdcss
2010-02-08 00:54 . 2009-10-30 23:19 -------- d-----w- c:\program files\ABBYY FineReader 9.0
2010-02-06 11:24 . 2009-09-20 23:57 -------- d-----w- c:\program files\BitComet
2010-02-04 18:54 . 2009-09-18 18:21 -------- d-----w- c:\documents and settings\Krylias\Application Data\XnView
2010-02-04 16:02 . 2009-09-18 22:50 -------- d-----w- c:\program files\Common Files\Apple
2010-02-04 10:39 . 2009-12-28 16:10 -------- d-----w- c:\program files\e-TRAYz
2010-02-04 10:17 . 2009-09-19 21:04 -------- d-----w- c:\documents and settings\Krylias\Application Data\Audacity
2010-01-28 14:02 . 2009-09-18 01:32 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-01-22 20:12 . 2009-09-26 21:48 -------- d-----w- c:\program files\Replay Media Catcher
2010-01-22 19:49 . 2009-09-26 21:51 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2010-01-22 19:49 . 2009-09-26 21:51 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2010-01-22 19:49 . 2009-09-26 21:51 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2010-01-21 18:00 . 2009-09-22 01:04 117760 ----a-w- c:\documents and settings\Krylias\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-21 15:46 . 2009-09-30 19:47 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-19 22:32 . 2009-09-20 21:05 -------- d-----w- c:\program files\AV Vcs 6.0 DIAMOND
2010-01-19 04:54 . 2009-09-24 01:50 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SolidDocuments
2010-01-18 15:17 . 2009-09-17 23:00 100296 ----a-w- c:\documents and settings\Krylias\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-15 16:04 . 2009-09-20 11:06 -------- d-----w- c:\documents and settings\Krylias\Application Data\Thinstall
2010-01-13 22:29 . 2009-09-19 00:37 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-01-13 08:59 . 2009-09-18 13:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-11 20:42 . 2010-01-11 20:42 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_silabser_01007.Wdf
2010-01-11 20:42 . 2010-01-11 20:42 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-01-11 18:13 . 2009-09-17 23:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 11:27 . 2009-11-07 16:52 -------- d-----w- c:\program files\MP3MyMP3 3.0
2010-01-06 23:08 . 2009-09-18 01:00 -------- d-----w- c:\program files\Google
2010-01-05 19:36 . 2010-01-05 19:35 -------- d-----w- c:\program files\Dude
2010-01-03 03:12 . 2010-01-03 01:14 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2010-01-02 21:57 . 2010-01-02 21:57 -------- d-----w- c:\program files\Windows Media Connect 2
2010-01-02 14:22 . 2010-01-02 14:18 -------- d-----w- c:\documents and settings\Krylias\Application Data\MiniDm
2010-01-02 13:59 . 2010-01-02 13:59 -------- d-----w- c:\program files\MPC HomeCinema
2010-01-02 13:41 . 2010-01-02 13:40 -------- d-----w- c:\program files\MediaInfo
2010-01-02 12:49 . 2010-01-02 12:49 52224 ----a-w- c:\documents and settings\Krylias\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-02 01:07 . 2009-09-18 15:10 -------- d-----w- c:\program files\Common Files\Common Share
2009-12-31 20:01 . 2009-09-21 14:36 -------- d-----w- c:\documents and settings\Krylias\Application Data\SolidDocuments
2009-12-31 18:40 . 2009-12-31 18:38 -------- d-----w- c:\documents and settings\Krylias\Application Data\IEPro
2009-12-31 18:38 . 2009-12-31 18:38 -------- d-----w- c:\program files\IEPro
2009-12-30 08:42 . 2009-12-30 08:42 -------- d-----w- c:\documents and settings\Krylias\Application Data\Nero
2009-12-29 19:16 . 2009-12-04 00:30 -------- d-----w- c:\documents and settings\Krylias\Application Data\Ahead
2009-12-29 19:16 . 2009-12-04 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-12-29 00:49 . 2009-09-19 21:19 -------- d-----w- c:\documents and settings\Krylias\Application Data\Xilisoft Corporation
2009-12-29 00:49 . 2009-09-19 21:19 -------- d-----w- c:\program files\Xilisoft
2009-12-28 21:16 . 2009-12-28 21:16 18432 ----a-w- c:\windows\system32\drivers\nethddim.sys
2009-12-24 01:33 . 2009-12-24 01:32 -------- d-----w- c:\program files\Inpaint
2009-12-21 19:14 . 2008-04-14 03:42 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 13:03 . 2009-12-18 13:03 17542 ----a-r- c:\documents and settings\Krylias\Application Data\Microsoft\Installer\{F343FA04-CFC0-487C-A617-A5E8CF4D7B10}\_96E62DE38A7F692104A23B.exe
2009-12-18 13:03 . 2009-12-18 13:03 17542 ----a-r- c:\documents and settings\Krylias\Application Data\Microsoft\Installer\{F343FA04-CFC0-487C-A617-A5E8CF4D7B10}\_640ECEF665E5906E76DC9D.exe
2009-12-18 12:38 . 2009-09-21 20:36 -------- d-----w- c:\program files\CyberLink
2009-12-18 12:36 . 2009-12-17 00:41 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe
2009-12-18 10:19 . 2009-12-25 20:42 545280 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-12-18 10:19 . 2009-12-25 20:42 344064 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-12-18 10:19 . 2009-12-25 20:42 153600 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2009-12-18 10:19 . 2009-12-25 20:42 103424 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-12-18 10:19 . 2009-12-25 20:42 57856 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com-trash\components\coolirisstub.dll
2009-12-18 10:19 . 2009-12-25 20:42 4726272 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com-trash\libs\cooliris190.dll
2009-12-18 10:19 . 2009-12-25 20:42 57856 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-12-18 10:19 . 2009-12-25 20:42 4726272 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2009-12-17 15:48 . 2009-12-17 15:48 -------- d-----w- c:\program files\Streamripper
2009-12-17 15:43 . 2009-09-18 21:02 -------- d-----w- c:\documents and settings\Krylias\Application Data\Winamp
2009-12-17 00:52 . 2009-09-21 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-12-17 00:45 . 2009-09-21 20:45 -------- d-----w- c:\documents and settings\Krylias\Application Data\CyberLink
2009-12-16 13:42 . 2009-12-25 20:42 872960 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 13:42 . 2009-12-25 20:42 43008 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 13:42 . 2009-12-25 20:42 340480 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 13:41 . 2009-12-25 20:42 346624 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-12 17:23 . 2009-09-18 01:32 -------- d-----w- c:\documents and settings\Krylias\Application Data\Thunderbird
2009-12-12 15:32 . 2009-12-12 15:30 -------- d-----w- c:\program files\Your Uninstaller
2009-12-12 15:30 . 2009-09-20 01:13 -------- d-----w- c:\documents and settings\Krylias\Application Data\URSoft
2009-12-12 14:15 . 2010-01-02 02:39 178176 ----a-w- c:\windows\system32\unrar.dll
2009-11-27 14:56 . 2009-11-27 14:56 1773568 ----a-w- c:\windows\system32\msgdiplus.dll
2009-11-24 10:53 . 2009-12-25 20:43 57344 ----a-w- c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}\components\nsCatcher.dll
2009-11-21 15:51 . 2008-04-14 03:41 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-21 15:08 . 2009-11-21 15:08 155136 ----a-w- c:\windows\system32\RemoteControl.dll
2009-11-19 21:32 . 2009-11-19 21:32 25 ----a-w- c:\windows\system32\sysfsaver.dat
.
Kód: Vybrat vše
<pre>
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\COMODO\COMODO Internet Security\cfp .exe
c:\program files\FirefoxPreloader\firefoxpreloader .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\Google\Quick Search Box\googlequicksearchbox .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Microsoft ActiveSync\wcescomm .exe
c:\program files\Microsoft Office\Office12\groovemonitor .exe
c:\program files\QuickTime Alternative\qttask .exe
c:\program files\Rainlendar2\rainlendar2 .exe
c:\program files\SPAMfighter\sfagent .exe
</pre>
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . D9F19E78F98834CB411D6AD3C68D181A . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\CeTRAYz_OverlayIcon_Share]
@="{B00DFEC8-C278-40FD-8832-76A9409991F3}"
[HKEY_CLASSES_ROOT\CLSID\{B00DFEC8-C278-40FD-8832-76A9409991F3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\CeTRAYz_OverlayIcon_ShareSync]
@="{2022959D-8296-427A-9D9F-E59CC016F006}"
[HKEY_CLASSES_ROOT\CLSID\{2022959D-8296-427A-9D9F-E59CC016F006}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\CeTRAYz_OverlayIcon_Sync]
@="{B2483E28-1631-4E80-AA62-29B35EFEC7F0}"
[HKEY_CLASSES_ROOT\CLSID\{B2483E28-1631-4E80-AA62-29B35EFEC7F0}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Krylias\Start Menu\Programs\Startup\
Kalend r.lnk - c:\windows\MENINY.EXE [2009-9-18 49312]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^Krylias^Start Menu^Programs^Startup^Yahoo! Widgets.lnk]
backup=c:\windows\pss\Yahoo! Widgets.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\365dni]
2007-01-06 16:16 753664 ----a-w- c:\program files\365dníNET\365dniNET.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ai Nap]
2008-05-26 16:34 1423360 ----a-w- c:\program files\ASUS\Ai Suite\AiNap\AiNap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-04-02 04:00 203928 ----a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
2009-02-27 16:04 278016 ----a-w- c:\program files\IVT Corporation\BlueSoleil\BtTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
2009-01-29 22:20 57344 ----a-w- c:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
2005-10-27 16:00 299008 ------w- c:\program files\Creative\Shared Files\CamTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DudeServer]
2009-12-11 15:49 4100096 ----a-w- c:\program files\Dude\dude.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InstantBurn]
2007-06-04 16:24 599600 ----a-w- c:\progra~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-11-20 13:30 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2009-09-10 12:54 420176 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:42 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-18 01:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-02-08 20:12 55296 ----a-w- c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2009-10-26 07:33 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Documents and Settings\\Krylias\\Application Data\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19390:TCP"= 19390:TCP:BitComet 19390 TCP
"19390:UDP"= 19390:UDP:BitComet 19390 UDP
"12895:TCP"= 12895:TCP:BitComet 12895 TCP
"12895:UDP"= 12895:UDP:BitComet 12895 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"14376:TCP"= 14376:TCP:BitComet 14376 TCP
"14376:UDP"= 14376:UDP:BitComet 14376 UDP
"21094:TCP"= 21094:TCP:BitComet 21094 TCP(ED2K)
"21094:UDP"= 21094:UDP:BitComet 21094 UDP(ED2K)
"23713:TCP"= 23713:TCP:BitComet 23713 TCP
"23713:UDP"= 23713:UDP:BitComet 23713 UDP
"6890:TCP"= 6890:TCP:BitComet 6890 TCP
"6890:UDP"= 6890:UDP:BitComet 6890 UDP
"12376:TCP"= 12376:TCP:BitComet 12376 TCP
"12376:UDP"= 12376:UDP:BitComet 12376 UDP
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [7.1.2009 22:39 20744]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [20.9.2009 1:38 206256]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.9.2009 1:41 717296]
R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [21.9.2009 21:43 16048]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [24.1.2010 12:34 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [24.1.2010 12:34 25160]
R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [27.2.2009 16:40 143467]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [21.9.2009 21:43 162096]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [26.11.2008 9:36 323584]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?]
R2 NETHDD;NETHDD Service;c:\program files\e-TRAYz\NETHDD.exe [28.12.2009 22:16 249376]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [20.10.2009 19:19 50704]
R2 sensorsview32;sensorsview32;c:\windows\system32\drivers\sensorsview32.sys [20.9.2009 0:53 14416]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\SPAMfighter\sfus.exe [27.8.2009 8:24 189064]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [7.12.2008 11:44 30088]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2.7.2008 13:58 26248]
R3 NETHDDIM;NETHDD NDIS IM Service;c:\windows\system32\drivers\nethddim.sys [28.12.2009 22:16 18432]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [18.9.2009 0:08 1684736]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [22.9.2009 2:44 19160]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS --> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\i:\ntglm7x.sys --> i:\NTGLM7X.sys [?]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [11.1.2010 19:16 17920]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\drivers\silabser.sys [11.1.2010 19:16 63488]
S3 V0060VID;Creative WebCam Live! Ultra;c:\windows\system32\drivers\V0060Vid.sys [18.9.2009 13:19 196409]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [27.10.2008 18:03 759072]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [22.9.2009 2:44 269648]
--- Other Services/Drivers In Memory ---
*Deregistered* - uphcleanhlp
*Deregistered* - uzmvr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-11-20 13:28 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-02-08 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-01-19 12:51]
2010-02-01 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-01-19 12:51]
.
.
------- Supplementary Scan -------
.
mWindow Title =
uInternet Settings,ProxyServer = socks=
IE: &Save Flash In This Page by Flash Saver - c:\progra~1\FLASHS~1\save.htm
IE: Add to &Teleport - c:\program files\Teleport Pro\teleport.htm
IE: Download ALL with IDA - c:\program files\IDA\idaieall.htm
IE: Download with IDA - c:\program files\IDA\idaie.htm
IE: E&xport to Microsoft Excel
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
TCP: {8E98A099-47E1-473D-A262-E605F64321CE} = 192.168.200.17,213.151.233.220
FF - ProfilePath - c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www3.iamwired.net/websearch.php?src=tops&search=
FF - prefs.js: browser.startup.homepage - hxxp://www3.iamwired.net/
FF - prefs.js: keyword.URL - hxxp://www3.iamwired.net/websearch.php?src=tops&search=
FF - component: c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{4b06c587-17dc-1680-5def-3864f40f0f9b}\components\6-6v_L.dll
FF - plugin: c:\documents and settings\Krylias\Application Data\Mozilla\Firefox\Profiles\kjzhis9d.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-SLABCOMM&10C4&EA60 - c:\windows\system32\Silabs\DriverUninstaller.exe VCP CP210x Cardinal\SLABCOMM&10C4&EA60
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-08 22:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spgg.sys >>UNKNOWN [0x8B17F938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9e67cb8
\Driver\atapi -> atapi.sys @ 0xb9cceb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uzmvr]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-854245398-1035525444-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{56B5E449-B6BE-A830-1AA5-629DD18ED87D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"fangfmmkloem"=hex:66,61,61,6c,61,6f,6b,67,64,6b,70,70,00,f5
"jangfmmkaofjkddpolbj"=hex:61,61,00,00
"kangfmmkgoodlihhggplob"=hex:61,61,00,00
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="6296A71333B237F51F5F6EFB6DC027000191484C4CCE10C21FEEC7C5C08717E7B12D3A3C086D6360AAA40905789CE3991AA1656A0518E33CEAAD4441A8276C816A01ACF89047FC921EF24DCA9F241001EF0475F2BCAE69C0A5F0C47DF3B3C3C0A75CC09E688EBB0E1A032B1D14E81E7F4884B44D5704F382D936F11C5B1CE9615A8D2EA83E568933959507F01B3C3542BFF25407514B8316E7FC69E2AD97DF81486621375674824B5B6BB65D8AB52FD743A2F852357E51F482CBBDBCCD9E59A2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB34528EDD5E5BE2F6E6679DB7CE019D40AA5CD73D481993C4E4F117CDEAF400AFF785263E516843D103E208318DD28BB725EBF08785DE37A3650DFC37F60BBBEF9E153C2F3CC350F6AD1208D0ED0F7398F8C72CF14EC53443462F607B07605C15DB0E0F06324FD78B771470973866FABE130D71687F5610B1752AEA36E4B7BBB11C4C2DAF88A727C16C6C5666EFEE051DB9897A59683DE34497B19D88CC77C7987F0C7C9D8D8AA10F4902A39E8D5E8C6B676DD5394F4CDC9203E0CB1872278465DB713545FCDAC0AE7F2115A6FC131B254BCCE780ECF73B79C4331E8CFA778672B80165228C200D1DB378BDE91D8B5208C720E5296FD856199A0C8F92813978E352276CAEE084A89D429B03D6C4EB669873C4DA33752D16D4FA30EE5A13E1191D1A31FE6F9757443635029E5FB87B201D97F8A4A21754F7550AC76199B10C394734D026E8BC0CA83150861F7A3727DA21B562F8005A538D86A5E1DF0853F4C150781EBF245538AF1C08EA64236FFD86F27C8A5B553E53FA195C6FB2E263FEAA69F3927BAFD897CA4A864FA5D886B42827555BA9B3B2A27B0072C57C6A3EAF0386E78CDE9D310A7B51A9BD6C1C12A2D715D9A610AE9DAFDA74DE1EB0E337316DE1C7CEC0023D10598A021F96752143C2D5D7A1925CD7117AF1CC16959793D120783D7F5078CFD29095D445566E31382849D2630759ADFED0B99BAE48520D83640B24290D9CB11BDFD29DE1B096B7C3DB1581E79945E057E4CF604DB8E4D1DA9A9F8C3BCC911B5A99E9088D7F801CCDC61CCC91C7C42719D6FAE03DA9A20593B27E3B8537FBBE222745F54370423A63658DD4A3657DA7EAD5489AA833663B8934B4A94049863C288191FC62857663334855EB46981D809528083A23C18AFEC039940306D4DEAC49B941672E153C5A9213A91806DCD14285A6CDA5229471CE5DEEB1A8D3FCB51A04720B33CDC7B4D6787DFE94D37F50734B3FF1F47D3F009CAA1AE62F0EBB40847AE1690F4D1D0A067F5691CF0325CE0B9C719170742A1D4D160F4FDEF85DBA5EF35599639B6463876A7AE1EACC438A7851550C9AA710B5BB31384EB3C0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1292)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2008)
c:\windows\system32\WININET.dll
c:\progra~1\e-TRAYz\ETRAYZ~2.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\BsMobileSDK.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\Office12\1051\GrooveIntlResource.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe
c:\program files\IVT Corporation\BlueSoleil\BsHelpCS.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-08 22:22:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-08 21:22
Pre-Run: 69 860 663 296 bytes free
Post-Run: 20 adresárov, 69 626 302 464 voľných bajtov
- - End Of File - - 9F66510664AA5006FFFA4EF613739A3E