Tak hádam do tretice všetko dobré...
ComboFix 09-12-23.02 - Biker 25.12.2009 19:15:45.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2046.1698 [GMT 1:00]
Running from: D:\ComboFix.exe
Command switches used :: c:\documents and settings\Biker\Desktop\CFScript.txt.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICQ_SERVICE
-------\Legacy_IWUXAV
-------\Service_ICQ Service
-------\Service_iwuxav
((((((((((((((((((((((((( Files Created from 2009-11-25 to 2009-12-25 )))))))))))))))))))))))))))))))
.
2009-12-24 10:34 . 2009-12-24 10:34 -------- d-----w- c:\program files\R-Studio
2009-12-24 10:20 . 2006-12-19 15:53 24072 ----a-w- c:\windows\system32\uxtuneup.dll
2009-12-24 10:20 . 2009-12-24 10:21 -------- d-----w- c:\program files\TuneUp Utilities 2007
2009-12-23 15:03 . 2009-12-23 15:03 -------- d-----w- c:\program files\Trend Micro
2009-12-21 15:31 . 2009-12-22 15:35 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-21 15:31 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-12-21 15:31 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-12-21 15:31 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-12-21 15:31 . 2009-12-21 15:31 -------- d-----w- c:\program files\Avira
2009-12-21 15:31 . 2009-12-21 15:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-21 13:58 . 2009-12-21 13:58 61440 ----a-r- c:\documents and settings\Biker\Application Data\Microsoft\Installer\{750B9AD1-4C63-4143-94C5-6FB304199BAD}\ARPPRODUCTICON.exe
2009-12-20 13:56 . 2009-12-20 13:56 -------- d-----w- c:\documents and settings\Biker\Application Data\dvdcss
2009-12-20 12:36 . 2009-12-20 12:39 -------- d-----w- c:\program files\Doom 3
2009-12-20 11:19 . 2009-12-20 12:16 967 ----a-w- c:\windows\ScUnin.pif
2009-12-20 11:19 . 2009-12-20 12:16 94208 ----a-w- c:\windows\ScUnin.exe
2009-12-20 11:19 . 2009-12-20 12:16 35382 ----a-w- c:\windows\scunin.dat
2009-12-20 11:16 . 2009-12-20 12:16 -------- d-----w- c:\program files\Starcraft
2009-12-19 13:41 . 2009-10-29 10:48 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-17 16:10 . 2009-12-17 16:10 -------- d-----w- C:\DriveKey
2009-12-15 18:52 . 1998-09-02 08:28 38160 ----a-w- c:\windows\system32\LMRTREND.dll
2009-12-15 18:52 . 1998-08-27 04:51 182032 ----a-w- c:\windows\system32\dxtmsft3.dll
2009-12-15 18:52 . 1998-09-02 08:28 63488 ----a-w- c:\windows\system32\unam4ie.exe
2009-12-15 18:52 . 1998-09-02 08:02 194320 ----a-w- c:\windows\system32\qcut.dll
2009-12-15 18:52 . 1998-08-17 09:21 11776 ----a-w- c:\windows\system32\mciqtz.drv
2009-12-15 18:52 . 2009-12-15 18:52 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-12-15 18:52 . 2009-12-15 18:52 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-12-15 18:49 . 2009-12-15 18:57 -------- d-----w- C:\Truckrace
2009-12-15 18:48 . 1998-07-30 11:51 305152 ----a-w- c:\windows\IsUninst.exe
2009-12-15 18:48 . 2009-12-15 18:48 -------- d-----w- c:\documents and settings\Biker\WINDOWS
2009-12-12 22:07 . 2009-12-12 22:07 -------- d--h--w- c:\windows\PIF
2009-12-11 09:58 . 2009-12-11 09:58 -------- d-----w- c:\program files\Common Files\Skype
2009-12-04 16:48 . 2009-12-25 16:44 -------- d-----w- c:\program files\SpeedFan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-25 13:47 . 2009-10-29 10:13 -------- d-----w- c:\documents and settings\Biker\Application Data\Skype
2009-12-25 11:11 . 2009-10-29 10:14 -------- d-----w- c:\documents and settings\Biker\Application Data\skypePM
2009-12-24 10:49 . 2009-10-29 10:06 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-24 10:49 . 2009-10-29 10:06 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-24 10:49 . 2009-10-29 10:06 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-24 10:49 . 2009-10-29 10:48 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-24 10:49 . 2009-10-29 10:06 194104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-24 10:49 . 2009-10-29 10:06 370744 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-24 10:48 . 2009-10-29 10:06 6296864 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-24 10:48 . 2009-10-29 10:06 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-24 10:48 . 2009-10-29 10:06 816272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-24 10:48 . 2009-10-29 10:06 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-24 10:48 . 2009-10-29 10:06 1643272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-24 10:48 . 2009-10-29 10:06 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-24 10:48 . 2009-10-29 10:06 1181328 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-24 10:20 . 2009-10-28 09:11 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-23 17:17 . 2009-10-28 09:50 -------- d-----w- c:\program files\Opera
2009-12-21 13:39 . 2009-12-21 13:39 16 ----a-w- c:\documents and settings\Biker\Application Data\fvgqad.dat
2009-12-20 14:02 . 2009-11-24 10:17 -------- d-----w- c:\documents and settings\Biker\Application Data\vlc
2009-12-19 22:59 . 2009-10-31 23:20 -------- d-----w- c:\program files\HappyFoto
2009-12-19 08:36 . 2009-10-29 09:53 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-19 08:35 . 2009-10-29 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-17 16:10 . 2009-10-28 08:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-12 15:28 . 2009-12-12 15:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-11 09:58 . 2009-10-29 10:13 -------- d-----r- c:\program files\Skype
2009-12-11 09:58 . 2009-10-29 10:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-09 08:13 . 2009-10-28 09:32 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 16:23 . 2009-10-31 18:25 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-12-03 17:30 . 2009-10-28 09:27 521376 ----a-w- c:\documents and settings\Biker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-03 16:50 . 2009-10-28 10:27 -------- d-----w- c:\program files\TuneUp Utilities 2006
2009-12-03 16:38 . 2009-10-29 10:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-03 16:38 . 2009-10-31 15:52 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-11-26 10:48 . 2009-10-29 10:06 163728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-26 10:48 . 2009-10-29 10:06 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-26 10:48 . 2009-10-29 10:06 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-26 10:48 . 2009-10-29 10:06 641632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-24 10:17 . 2009-11-24 10:17 -------- d-----w- c:\program files\VideoLAN
2009-11-24 09:56 . 2009-11-24 09:56 -------- d-----w- c:\program files\MSECache
2009-11-22 12:02 . 2009-11-22 12:00 -------- d-----w- c:\program files\Software Informer
2009-11-22 11:07 . 2009-11-01 10:45 -------- d-----w- c:\documents and settings\Biker\Application Data\PC Suite
2009-11-12 09:23 . 2009-10-28 09:07 -------- d-----w- c:\program files\Creative
2009-11-12 09:22 . 2009-11-12 09:22 -------- d-----w- c:\program files\Common Files\Creative
2009-11-12 09:22 . 2009-10-28 10:08 -------- d--h--w- c:\program files\Creative Installation Information
2009-11-11 20:27 . 2009-11-11 20:27 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2009-11-06 16:16 . 2009-11-06 16:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-06 16:15 . 2009-11-01 10:42 -------- d-----w- c:\program files\MSBuild
2009-11-05 17:59 . 2009-11-05 17:59 -------- d-----w- c:\documents and settings\Biker\Application Data\CyberLink
2009-11-05 17:58 . 2009-11-05 17:58 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-11-05 17:57 . 2009-11-05 17:57 -------- d-----w- c:\program files\CyberLink
2009-11-02 18:56 . 2009-11-02 18:56 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2009-11-02 16:09 . 2009-10-28 08:57 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-01 12:16 . 2009-11-01 11:23 -------- d-----w- c:\program files\Common Files\Nokia
2009-11-01 12:15 . 2009-11-01 10:45 -------- d-----w- c:\program files\Nokia
2009-11-01 12:15 . 2009-11-01 11:23 -------- d-----w- c:\program files\Common Files\PCSuite
2009-11-01 11:41 . 2009-11-01 10:46 -------- d-----w- c:\documents and settings\Biker\Application Data\Nokia
2009-11-01 11:41 . 2009-11-01 11:41 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-11-01 11:41 . 2009-11-01 11:41 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-11-01 11:40 . 2009-11-01 11:40 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-11-01 11:40 . 2009-11-01 11:40 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-11-01 11:36 . 2009-11-01 10:45 -------- d-----w- c:\program files\DIFX
2009-11-01 11:36 . 2009-11-01 11:36 -------- d-----w- c:\program files\PC Connectivity Solution
2009-11-01 11:36 . 2009-11-01 11:36 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-11-01 11:36 . 2009-11-01 11:36 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-11-01 11:36 . 2009-11-01 11:36 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-11-01 11:36 . 2009-11-01 11:36 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-11-01 11:35 . 2009-11-01 10:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-01 11:34 . 2009-11-01 11:36 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng_web.exe
2009-11-01 11:03 . 2009-11-01 11:01 -------- d-----w- c:\documents and settings\Biker\Application Data\NSeries
2009-11-01 11:02 . 2009-11-01 10:46 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-11-01 11:00 . 2009-11-01 11:00 -------- d-----w- c:\program files\Windows Media Connect 2
2009-11-01 10:40 . 2009-11-01 10:40 -------- d-----w- c:\program files\Reference Assemblies
2009-10-31 23:20 . 2009-10-31 23:20 -------- d-----w- c:\documents and settings\Biker\Application Data\Happy Foto
2009-10-31 18:29 . 2003-03-28 03:24 86016 ----a-w- c:\windows\system32\OpenAL32.dll
2009-10-31 18:28 . 2009-10-31 18:28 -------- d-----w- c:\program files\Futuremark
2009-10-31 18:19 . 2009-10-31 15:47 -------- d-----w- c:\program files\Uniblue
2009-10-31 18:06 . 2009-10-28 09:11 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-31 17:51 . 2009-10-31 17:51 -------- d-----w- c:\program files\oZone3D
2009-10-31 16:50 . 2009-10-31 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Codemasters
2009-10-31 16:48 . 2009-10-31 16:48 -------- d-----w- c:\program files\OpenAL
2009-10-31 16:48 . 2009-10-31 16:48 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-31 16:36 . 2009-10-31 16:36 -------- d-----w- c:\program files\Codemasters
2009-10-31 15:53 . 2009-10-31 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-10-31 15:52 . 2009-10-31 15:47 -------- d-----w- c:\documents and settings\Biker\Application Data\Uniblue
2009-10-30 18:28 . 2009-10-29 10:11 -------- d-----w- c:\documents and settings\Biker\Application Data\ICQ
2009-10-30 09:39 . 2009-10-29 10:10 -------- d-----w- c:\program files\ICQ6.5
2009-10-29 20:26 . 2009-10-29 20:26 -------- d-----w- c:\documents and settings\Biker\Application Data\Apple Computer
2009-10-29 11:12 . 2009-10-29 11:09 54743966 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource Player_Organizer 3.30.21__\CMS_PCAPP_LB_3_30_21.exe
2009-10-29 11:09 . 2009-10-29 11:07 37406376 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.25.02__\CMS5_PCAPP_LB_5_25_02.exe
2009-10-29 11:02 . 2009-10-29 11:01 12846328 ----a-w- c:\documents and settings\All Users\Application Data\Creative\Software Update\cache\Creative WaveStudio 7.11.00__\WAVESTD_PCAPP_LB_7_11_00.exe
2009-10-29 10:48 . 2009-10-29 10:48 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-29 10:48 . 2009-10-29 10:48 93360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-10-29 10:48 . 2009-10-29 10:48 554280 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2009-10-29 10:48 . 2009-10-29 10:06 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-10-29 10:48 . 2009-10-29 10:48 212480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-10-29 10:48 . 2009-10-29 10:48 283944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-10-29 10:48 . 2009-10-29 10:48 1223976 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-10-29 10:48 . 2009-10-29 10:48 242984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-10-29 10:34 . 2009-10-28 08:40 5938 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-10-29 10:34 . 2009-10-28 08:40 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-29 10:17 . 2009-10-29 10:17 -------- d-----w- c:\program files\MSXML 4.0
.
((((((((((((((((((((((((((((( SnapShot@2009-12-25_09.08.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-27 12:00 . 2009-12-25 08:56 67312 c:\windows\system32\perfc009.dat
+ 2007-07-27 12:00 . 2009-12-25 18:18 67312 c:\windows\system32\perfc009.dat
+ 2007-07-27 12:00 . 2009-12-25 18:18 432356 c:\windows\system32\perfh009.dat
- 2007-07-27 12:00 . 2009-12-25 08:56 432356 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-03 64512]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-25 13680640]
"nwiz"="nwiz.exe" [2008-12-25 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-25 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-12-24 788880]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24\RivaTuner.exe" [2009-02-25 2781184]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-30 113664]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [28.10.2009 10:42 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.10.2009 10:35 717296]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [21.12.2009 16:31 108289]
S3 cpuz130;cpuz130;\??\c:\docume~1\Biker\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Biker\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24.9.2009 12:17 1181328]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 16:53 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://start.icq.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-25 19:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spsh.sys >>UNKNOWN [0x8A3FE938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba10cf28
\Driver\ACPI -> ACPI.sys @ 0xb9e67cb8
\Driver\atapi -> atapi.sys @ 0xb9ce8b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xb9bdebb0
PacketIndicateHandler -> NDIS.sys @ 0xb9bcda0d
SendHandler -> NDIS.sys @ 0xb9be1b40
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2452)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Completion time: 2009-12-25 19:23:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-25 18:23
ComboFix2.txt 2009-12-25 09:09
Pre-Run: 90 696 183 808 bytes free
Post-Run: 12 adresárov, 90 609 512 448 voľných bajtov
- - End Of File - - 78224814943D60D673EAB5B0D81C7DC8
Je to už v poriadku?????