ComboFix 09-11-28.04 - Owner 29.11.2009 15:24.1.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.511.328 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
ADS - WINDOWS: deleted 48 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\inst.exe
D:\install.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-29 )))))))))))))))))))))))))))))))
.
2009-11-28 15:46 . 2009-08-13 14:40 43008 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0syirrhg.Predvolený používateľ\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-28 15:46 . 2009-08-13 14:39 340480 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0syirrhg.Predvolený používateľ\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-28 15:46 . 2009-08-13 14:39 346112 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0syirrhg.Predvolený používateľ\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-28 13:44 . 2009-11-28 18:44 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\AskToolbar
2009-11-28 13:14 . 2009-11-28 18:44 -------- d-----w- c:\program files\Ask.com
2009-11-28 12:41 . 2009-11-28 18:34 -------- d-----w- c:\program files\GetTubeVideo
2009-11-28 09:36 . 2009-11-28 18:36 -------- d-----w- c:\program files\ImTOO
2009-11-27 20:52 . 2009-09-02 15:41 65602 ----a-w- c:\windows\system32\cook3260.dll
2009-11-27 20:52 . 2009-09-02 15:41 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2009-11-27 20:52 . 2009-09-02 15:41 217127 ----a-w- c:\windows\system32\drv43260.dll
2009-11-27 20:52 . 2009-09-02 15:41 208935 ----a-w- c:\windows\system32\drv33260.dll
2009-11-27 20:52 . 2009-09-02 15:41 176165 ----a-w- c:\windows\system32\drv23260.dll
2009-11-27 20:52 . 2009-09-02 15:41 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2009-11-27 20:52 . 2009-09-02 15:41 102439 ----a-w- c:\windows\system32\sipr3260.dll
2009-11-27 06:16 . 2009-11-27 06:16 -------- d-----w- C:\found.000
2009-11-25 07:22 . 2009-11-25 07:22 -------- d-----w- c:\program files\MSXML 4.0
2009-11-23 14:24 . 2009-11-23 14:24 1924440 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-11-17 09:16 . 2009-11-17 09:16 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS
2009-11-17 09:16 . 2009-11-17 09:16 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\eSupport.com
2009-11-12 14:59 . 2009-11-14 13:31 -------- d-----w- c:\program files\AVI to 3GP
2009-11-10 12:06 . 2009-11-02 19:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-09 16:18 . 2009-08-29 07:36 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-11-09 16:16 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-09 16:16 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-09 10:29 . 2009-11-09 10:29 -------- d-----w- c:\documents and settings\Owner\Application Data\Janes_Realty
2009-11-09 10:29 . 2009-11-09 10:29 -------- d-----w- c:\program files\Realore
2009-11-07 16:05 . 2009-11-07 16:06 -------- d-----w- c:\program files\Na scene(TM)
2009-11-04 12:57 . 2009-11-04 13:15 -------- d-----w- c:\documents and settings\Owner\AbiSuite
2009-11-04 12:57 . 2009-11-04 13:29 -------- d-----w- c:\program files\AbiWord
2009-11-04 12:46 . 2009-11-04 13:30 -------- d-----w- c:\program files\csWord
2009-11-02 08:56 . 2009-11-02 08:56 -------- d-----w- c:\program files\ESET
2009-10-30 17:13 . 2009-11-25 07:06 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-29 14:19 . 2008-08-12 17:30 34496 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-28 18:45 . 2009-03-12 16:49 -------- d-----w- c:\program files\Yahoo!
2009-11-28 18:41 . 2008-08-13 12:09 -------- d-----w- c:\program files\Pinnacle
2009-11-28 18:39 . 2008-08-12 13:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-28 13:42 . 2008-12-09 14:04 1 ----a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-27 21:11 . 2008-11-27 18:05 -------- d-----w- c:\documents and settings\Owner\Application Data\Vso
2009-11-27 21:11 . 2008-11-27 18:05 47360 ----a-w- c:\documents and settings\Owner\Application Data\pcouffin.sys
2009-11-27 21:11 . 2008-11-27 18:05 47360 ----a-w- c:\documents and settings\Owner\Application Data\pcouffin.sys
2009-11-27 20:52 . 2008-11-27 18:05 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-27 20:52 . 2008-12-23 17:25 -------- d-----w- c:\program files\VSO
2009-11-27 17:11 . 2009-05-14 11:18 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-23 23:03 . 2008-11-14 12:18 -------- d-----w- c:\program files\Techland
2009-11-23 09:19 . 2008-12-21 11:06 -------- d-----w- c:\program files\AviSynth 2.5
2009-11-23 09:19 . 2008-12-22 21:07 -------- d-----w- c:\program files\Avi2Dvd
2009-11-22 20:00 . 2008-11-14 11:15 -------- d-----w- c:\program files\Google
2009-11-20 11:24 . 2008-08-13 12:14 -------- d-----w- c:\program files\DivX
2009-11-13 13:41 . 2008-11-14 11:42 -------- d-----w- c:\program files\Burn4Free
2009-11-11 08:55 . 2008-08-16 08:17 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2009-11-08 19:34 . 2008-11-23 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-07 16:06 . 2008-12-04 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Vivendi Universal Games
2009-11-05 12:12 . 2009-04-28 21:02 -------- d-----w- c:\documents and settings\Owner\Application Data\DMCache
2009-11-05 07:55 . 2009-05-18 20:37 -------- d-----w- c:\program files\ATI
2009-11-05 07:53 . 2008-11-19 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems
2009-11-05 07:52 . 2008-11-14 12:04 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-11-03 12:35 . 2008-12-20 08:59 -------- d-----w- c:\documents and settings\Owner\Application Data\dvdcss
2009-10-28 20:37 . 2009-03-28 22:40 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-10-28 08:46 . 2008-12-11 13:23 -------- d-----w- c:\program files\SystemRequirementsLab
2009-10-26 17:12 . 2008-12-24 19:48 -------- d-----w- c:\documents and settings\Owner\Application Data\AVI ReComp
2009-10-26 07:17 . 2008-11-14 11:37 -------- d-----w- c:\program files\JetAudio
2009-09-25 05:37 . 2006-02-28 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-11 14:18 . 2006-02-28 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 06:26 . 2009-09-11 06:26 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-09-11 06:26 . 2009-09-11 06:26 135048 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-09-11 06:23 . 2009-09-11 06:23 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-09-11 06:17 . 2009-09-11 06:17 116008 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-09-04 21:03 . 2006-02-28 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2008-09-02 14:05 398776 ----a-w- c:\program files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"HideShutdownScripts"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideClock"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Jump and Ride Riding Academy 3D\\RidingAcademy3D.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\GIGABYTE\\VGA Utility Manager\\G-VGA.exe"=
"c:\\Program Files\\PRTG Traffic Grapher\\PRTG Traffic Grapher.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [11.9.2009 7:23 108792]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [11.9.2009 7:24 735960]
R2 PRTGService;PRTG Service;c:\program files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe [4.2.2009 12:43 3814728]
R3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;c:\windows\system32\drivers\3xHybrid.sys [13.8.2008 13:12 1121536]
S2 gupdate1c9b37c8c56ee56;Google Update Service (gupdate1c9b37c8c56ee56);c:\program files\Google\Update\GoogleUpdate.exe [2.4.2009 11:19 133104]
S2 prtgwatchservice;PRTG Watchdog;c:\program files\PRTG Traffic Grapher\watchdog\prtgwatchdog.exe [4.2.2009 12:43 443904]
S2 TVicHW64;TVicHW64;c:\windows\system32\drivers\TVicHW64.sys [28.12.2008 14:19 21200]
S3 esihdrv;esihdrv;\??\c:\docume~1\Owner\LOCALS~1\Temp\esihdrv.sys --> c:\docume~1\Owner\LOCALS~1\Temp\esihdrv.sys [?]
S3 PctvVirtualNdis;Pinnacle Virtual Miniport;c:\windows\system32\drivers\PctvVirtualNdis.sys [21.11.2008 17:50 13696]
S3 se46bus;Sony Ericsson Device 070 driver (WDM);c:\windows\system32\drivers\se46bus.sys [16.11.2008 20:47 61536]
S3 se46mdfl;Sony Ericsson Device 070 USB WMC Modem Filter;c:\windows\system32\drivers\se46mdfl.sys [16.11.2008 20:51 9360]
S3 se46mdm;Sony Ericsson Device 070 USB WMC Modem Driver;c:\windows\system32\drivers\se46mdm.sys [16.11.2008 20:51 97088]
S3 se46mgmt;Sony Ericsson Device 070 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se46mgmt.sys [17.11.2008 10:50 88624]
S3 se46nd5;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (NDIS);c:\windows\system32\drivers\se46nd5.sys [17.11.2008 19:56 18704]
S3 se46obex;Sony Ericsson Device 070 USB WMC OBEX Interface;c:\windows\system32\drivers\se46obex.sys [17.11.2008 10:50 86432]
S3 se46unic;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (WDM);c:\windows\system32\drivers\se46unic.sys [17.11.2008 19:56 90800]
S3 TVICHW32;TVICHW32;c:\windows\system32\drivers\TVICHW32.SYS [17.11.2009 10:16 23600]
S3 ZSMC0305;VIMICRO USB PC Camera VC0305;c:\windows\system32\drivers\usbVM305.sys [21.2.2009 20:17 391615]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 10:19]
2009-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 10:19]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.azet.sk/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar =
hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
TCP: {688E047F-13A0-4C97-AA9A-197C62EFA91B} = 213.151.202.130,213.151.208.161
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} -
hxxp://www.nvidia.com/content/DriverDow ... ab_nvd.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0syirrhg.Predvolený používateľ\
FF - prefs.js: browser.startup.homepage -
hxxp://www.azet.sk/
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -
BHO-{D187A56B-A33F-4CBE-9D77-459FC0BAE012} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuide.exe UninstallGUI
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-29 15:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):4a,30,f1,05,0e,54,ce,ed,cb,e0,a3,fd,4c,9e,d5,14,c4,b0,9e,8a,8a,
a0,24,ba,31,23,a7,68,2d,c6,63,b8,6b,eb,c9,f7,74,2a,18,da,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{a6677398-7403-4998-b533-c6dcea849d71}]
@Denied: (Full) (Everyone)
"Model"=dword:00000092
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-11-29 15:34
ComboFix-quarantined-files.txt 2009-11-29 14:34
Pre-Run: 41 776 930 816 bytes free
Post-Run: 44 487 249 920 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 1B8F7C99712FB122DA3B748DAC9F20CC
toto vyhodilo a co sa tyka security check tak ten je hore vypisalo len toto co je.