Csökkentett módban végigment és nem is indult újra a gép.
ComboFix 12-04-28.01 - Pali 012.04.29. 10:38:03.17.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1250.36.1038.18.3071.2631 [GMT 2:00]
Running from: c:\documents and settings\Pali\Asztal\ComboFix.exe
AV: AVG Internet Security *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: PC Tools Firewall Plus *Enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Pali\EULA.txt
c:\windows\system32\aac_parser.ax
c:\windows\system32\ac3DX.ax
c:\windows\system32\ac3filter.ax
c:\windows\system32\acelpdec.ax
c:\windows\system32\AVCDX.ax
c:\windows\system32\bsrmdec.ax
c:\windows\system32\CoreAAC.ax
c:\windows\system32\declrds.ax
c:\windows\system32\DiracSplitter.ax
c:\windows\system32\divxdec.ax
c:\windows\system32\DivXMedia.ax
c:\windows\system32\dtsac3source.ax
c:\windows\system32\ffdshow.ax
c:\windows\system32\FLACDX.ax
c:\windows\system32\GplMpgDec.ax
c:\windows\system32\HT_Asyn.ax
c:\windows\system32\ht_dein.ax
c:\windows\system32\HT_INVER.AX
c:\windows\system32\htAudioT.ax
c:\windows\system32\HTM1_REC.ax
c:\windows\system32\HTMPEG2E.ax
c:\windows\system32\HTMpegAE.ax
c:\windows\system32\HTMPG2VI.ax
c:\windows\system32\iac25_32.ax
c:\windows\system32\ir41_32.ax
c:\windows\system32\ivfsrc.ax
c:\windows\system32\l3codecx.ax
c:\windows\system32\MatroskaDX.ax
c:\windows\system32\mp4sds32.ax
c:\windows\system32\MPCDx.ax
c:\windows\system32\Mpeg2DecFilter.ax
c:\windows\system32\Mpeg2Decoder.ax
c:\windows\system32\Mpeg2Parser.ax
c:\windows\system32\MpegSplitter.ax
c:\windows\system32\RealMediaDX.ax
c:\windows\system32\RealMediaSplitter.ax
c:\windows\system32\RLAPEDec.ax
c:\windows\system32\RLMPCDec.ax
c:\windows\system32\RLOgg.ax
c:\windows\system32\RLSpeexDec.ax
c:\windows\system32\RLTheoraDec.ax
c:\windows\system32\RLVorbisDec.ax
c:\windows\system32\TTADSDecoder.ax
c:\windows\system32\TTADSSplitter.ax
c:\windows\system32\urttemp
c:\windows\system32\urttemp\regtlib.exe
c:\windows\system32\vumeter.ax
c:\windows\system32\wavdest.ax
c:\windows\system32\WMAVDS32.ax
c:\windows\system32\xvid.ax
.
.
((((((((((((((((((((((((( Files Created from 2012-03-28 to 2012-04-29 )))))))))))))))))))))))))))))))
.
.
2012-04-20 06:43 . 2012-04-20 06:43 -------- d-----w- c:\documents and settings\Pali\Application Data\Digital Red
2012-04-13 19:31 . 2012-04-13 19:31 -------- d-----w- c:\documents and settings\Pali\Application Data\XBMC
2012-04-13 19:30 . 2012-04-13 19:30 -------- d-----w- c:\program files\XBMC
2012-04-13 18:36 . 2012-04-13 18:36 -------- d-----w- c:\program files\Emicsoft Studio
2012-04-13 18:34 . 2012-04-13 18:34 -------- d-----w- c:\program files\AliveMedia
2012-04-13 07:31 . 2012-04-13 07:31 -------- d-----w- c:\documents and settings\Pali\Local Settings\Application Data\EZSoftMagic
2012-04-13 06:15 . 2012-04-13 06:15 -------- d-----w- c:\program files\AD MP3 Cutter
2012-04-13 06:15 . 2012-04-13 06:15 -------- d-----w- c:\documents and settings\Pali\Application Data\AD MP3 Cutter
2012-04-12 08:48 . 2012-04-12 08:48 -------- d-----w- c:\program files\Direct WAV MP3 Splitter2.7
2012-04-05 08:16 . 2012-04-14 16:26 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 08:20 . 2012-04-02 08:20 -------- d-----w- c:\program files\MSXML 4.0
2012-04-01 20:57 . 2012-04-01 20:57 -------- d-----w- c:\program files\Batch Photo Factory
2012-03-31 13:50 . 2012-03-31 13:50 -------- d-----w- c:\program files\Traction Software
2012-03-31 13:42 . 2012-03-31 13:42 -------- d-----w- c:\program files\BatchPhoto
2012-03-31 12:52 . 2012-04-29 00:12 -------- d-----w- C:\$AVG8.VAULT$
2012-03-31 11:54 . 2012-03-31 11:54 -------- d-----w- c:\windows\system32\winevt
2012-03-31 11:54 . 2012-03-31 11:54 -------- d-----w- c:\windows\ServiceProfiles
2012-03-31 10:25 . 2012-03-31 10:25 -------- d-----w- c:\program files\Új mappa (2)
2012-03-31 10:23 . 2012-03-31 10:23 -------- d-----w- c:\program files\ThePluginSite
2012-03-31 10:23 . 2012-03-31 10:23 -------- d-----w- c:\documents and settings\Pali\Application Data\ThePluginSite
2012-03-31 09:29 . 2012-03-31 09:29 -------- d-----w- c:\program files\AMS Photo Effects
2012-03-31 09:13 . 2012-03-31 09:13 -------- d-----w- c:\program files\PhotoZoom Pro 4
2012-03-31 08:33 . 2012-03-31 09:03 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2012-03-31 08:33 . 2012-03-31 08:33 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2012-03-31 08:33 . 2012-03-31 08:33 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2012-03-31 08:33 . 2012-03-31 09:03 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2012-03-31 08:33 . 2012-03-31 09:03 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-03-31 08:33 . 2012-04-28 23:49 -------- d-----w- c:\windows\system32\drivers\Avg
2012-03-31 08:33 . 2012-03-31 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2012-03-31 08:32 . 2012-04-21 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2012-03-31 08:22 . 2012-03-31 08:22 -------- d-----w- c:\program files\Photo Stamp Remover
2012-03-30 21:27 . 2012-03-30 21:27 -------- d-----w- c:\documents and settings\Pali\Local Settings\Application Data\photoOptimizeHistoryDataBase
2012-03-30 21:27 . 2012-03-31 09:21 -------- d-----w- c:\documents and settings\Pali\Local Settings\Application Data\Ashampoo Photo Optimizer 4
2012-03-30 21:05 . 2012-03-31 18:30 -------- d-----w- c:\documents and settings\Pali\Application Data\ObviousIdea
2012-03-30 21:04 . 2012-03-30 21:04 -------- d-----w- c:\program files\ObviousIdea
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 16:26 . 2011-07-17 11:11 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-25 16:30 . 2009-07-18 23:59 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-03-07 00:15 . 2012-03-18 21:33 41184 ----a-w- c:\windows\avastSS.scr
2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 11:38 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2009-11-15 33120]
"Alcohol.exe Autorun"="c:\program files\Alcohol Soft\Alcohol 120\Alcohol.exe" [2010-02-01 2036576]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-29 399736]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2011-08-13 102400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-03 16116224]
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe" [2005-07-20 192512]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 73728]
"ChrisTV Agent"="c:\program files\ChrisTV\ChrisTV_Agent.exe" [2005-05-02 187392]
"CClipboard"="c:\program files\ComfortClipboard\CClipboard.exe" [2010-06-14 2906952]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2011-04-07 2672600]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2009-02-27 552960]
"3170 Scan2PC"="c:\windows\Twain_32\Samsung\CLX3170\Scan2pc.exe" [2009-01-30 503808]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2012-03-25 185896]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2012-03-31 2042208]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2012-03-31 09:03 11952 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoBiMouse]
F:\Programok [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-10-30 19:07 140568 ----a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-30 19:11 909208 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
2011-08-13 12:33 102400 ----a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaGet2]
2011-08-25 19:12 8250368 ----a-w- c:\documents and settings\Pali\Local Settings\Application Data\MediaGet2\mediaget.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TeamViewer]
2009-03-26 15:37 4066600 ----a-w- c:\program files\TeamViewer\Version4\TeamViewer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-10-30 19:06 2595616 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USIUDF_Eject_Monitor]
2004-12-23 15:27 81920 ----a-w- c:\program files\Common Files\Ulead Systems\DVD\USISrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
2007-03-03 12:12 341488 ----a-w- c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\concept design\\onlineTV 3\\onlineTV.exe"=
"c:\\Program Files\\Voipwise.com\\Voipwise\\Voipwise.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\River Past\\Video Slice\\VideoSlice.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\XpressUpdate\\XPressUpdate.exe"=
"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\ScanMgr.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\CLX3170\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\CLX3170\\Sscan2io.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
.
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2012.03.31. 10:33 12552]
R0 hotcore;hotcore;c:\windows\system32\drivers\hotcore.sys [2010.12.21. 12:15 30820]
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2011.10.17. 14:36 39472]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2009.09.19. 9:23 33792]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011.07.21. 21:00 218688]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2011.10.31. 23:21 27632]
S0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2012.03.31. 10:33 335240]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2012.03.31. 10:33 108552]
S1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007.04.23. 13:03 82200]
S1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2012.03.18. 23:18 251560]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2012.03.31. 10:32 297752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010.03.18. 14:16 130384]
S2 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\drivers\DLPORTIO.sys [2011.11.10. 10:26 3584]
S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\Freemake\CaptureLib\CaptureLibService.exe [2011.11.20. 22:27 8704]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010.08.20. 19:52 233472]
S2 inpout32;inpout32;c:\windows\system32\drivers\inpout32.sys [2011.11.14. 10:31 11936]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2011.02.11. 23:23 35088]
S2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2012.03.18. 23:18 160576]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012.04.05. 10:16 253088]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011.10.17. 14:34 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011.10.17. 14:34 8456]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010.08.20. 19:52 36608]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [2009.07.19. 20:21 47360]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2012.03.18. 23:17 89472]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2012.03.18. 23:17 57536]
S3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2012.03.18. 23:17 57536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2012.03.18. 23:17 125248]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2011.10.31. 23:20 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2011.10.31. 23:20 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2011.10.31. 23:20 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2011.10.31. 23:20 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2011.10.31. 23:20 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2011.10.31. 23:20 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2011.10.31. 23:20 115752]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2010.09.06. 8:47 356920]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011.10.31. 23:43 155344]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010.08.20. 19:53 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010.08.20. 19:53 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010.08.20. 19:53 121856]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [2008.01.25. 11:12 25088]
S3 TNPacket;T-Systems Nova Packet Capture Driver;c:\progra~1\MATVAD~1\TNPACKET.SYS [2002.10.09. 13:38 9376]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010.03.18. 14:16 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 16:26]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://start.facemoods.com/?a=ostplmStart Page = about:blank
IE: Az összes letöltése Free Download Managerrel -
file://c:\program files\Free Download Manager\dlall.htm
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Kijelölés letöltése Free Download Managerrel -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Letöltés Free Download Managerrel -
file://c:\program files\Free Download Manager\dllink.htm
IE: SmarThru4 Capture Selection - c:\program files\SmarThru 4\WebCapture.dll2.htm
IE: SmarThru4 Save as HTML - c:\program files\SmarThru 4\WebCapture.dll1.htm
IE: SmarThru4 Save Selected Text - c:\program files\SmarThru 4\WebCapture.dll.htm
IE: SmarThru4 Web Capture - c:\program files\SmarThru 4\WebCapture.dll
IE: Video letöltése a Free Download Manager-rel -
file://c:\program files\Free Download Manager\dlfvideo.htm
TCP: DhcpNameServer = 213.46.246.54 213.46.246.53
FF - ProfilePath - c:\documents and settings\Pali\Application Data\Mozilla\Firefox\Profiles\trkpvxdy.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
hxxp://home.sweetim.comFF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=green ... =937811&p=FF - prefs.js: network.proxy.type - 458765
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: AutoPager:
autopager@mozilla.org - %profile%\extensions\autopager@mozilla.org
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\AVG\AVG8\Firefox
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-29 10:50
Windows 5.1.2600 Szervizcsomag 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-796845957-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{34A15073-41AE-8EEF-A16E-D2280D030580}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oanoicgkbgiopefcnmjgnokmikaked"=hex:64,61,6e,6d,68,6d,65,64,00,85
"oabjimbnhlhjhoancifcdjldhjipie"=hex:6a,61,61,6f,6b,6d,6e,6e,66,66,66,62,6a,69,
63,64,62,61,6f,66,00,02
"naphkfkhodflengmgiefodoakloe"=hex:6a,61,61,6f,6b,6d,6e,6e,66,66,66,62,6a,69,
63,64,62,61,6f,66,00,02
"eajhickfpn"=hex:68,62,6e,69,61,64,66,66,68,69,63,64,6e,63,69,6e,6e,69,6e,6e,
66,67,6f,65,6a,64,61,6c,61,64,67,67,63,6b,6c,66,66,6d,6d,6b,69,6f,61,6f,64,\
"cacich"=hex:64,62,63,69,65,70,6b,65,6f,6f,6a,6a,6c,69,6e,66,68,70,70,6e,64,62,
68,6a,6a,63,6e,6b,6e,66,6b,63,66,70,70,62,63,6d,6c,6a,00,6f
.
[HKEY_USERS\S-1-5-21-796845957-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5CA0E303-E239-9636-805C-4ED16EC7CC6F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hacgdllpoffoopma"=hex:6c,61,67,66,6d,6f,63,65,68,67,6f,6d,68,6f,6b,6f,70,62,
6b,6b,6c,65,61,62,00,b5
"jabgimhpabmmhoopoooc"=hex:6b,61,66,66,64,61,6a,6d,6c,63,6a,65,62,6c,63,61,6f,
6b,70,65,67,6b,00,62
.
[HKEY_USERS\S-1-5-21-796845957-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AAE1DC12-FED9-5CE3-FC66-3D095C51EF3A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaonpdckffenleachjblhdffcdmakb"=hex:64,61,66,61,67,63,64,6e,00,85
"oacnpkbpipdoabfbfdhnlcledjfcda"=hex:6a,61,66,61,63,63,6f,6b,62,69,63,6b,69,70,
61,68,70,65,63,6e,00,0f
"naanbmcdmncioechfefejjjplbib"=hex:6a,61,66,61,63,63,6f,6b,62,69,63,6b,69,70,
61,68,70,65,63,6e,00,0f
"eakpplglbf"=hex:65,61,65,6d,6e,63,64,63,64,70,00,00
"capnpc"=hex:6b,62,69,70,6c,6c,64,64,64,6a,64,6c,62,6c,62,6c,6c,66,6a,68,6c,6d,
65,6d,70,65,62,68,6a,67,61,66,6c,6c,66,6f,6b,66,6f,6b,70,6a,64,6c,6f,6b,70,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|˙˙˙˙"•€|ţ»Ów*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OOPM02.00.00.01PRO"="675E45C435A1B3861728437D047AC79D348020D07C3E791BFB13B0B0E3C43F92B20432EC36D590B425F3B95DA91A18163156B6FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC79335D575E7D6A3B98088EDD5E5BE2F6E667724EFA267A73ECCD14C4B29CF54BDE800219DE96088313D80EED444C8C119A46F2815E98FBD6CE38F8B84F36C3B6A320F02E1A0D62A947067861B006D6F51C2A19E6D079E3E87FB52B2F2EAB1F2754FE10E07253508971DD3E3C05B6A40DD2881193AD552F521B0C7BCFF820B6296CCBF8877EC856310C15DA266518F007D1BF5DA2C35BEE84F5629145CCDCD10F1D9616FE496D8FF1414621CCE704C9D46413D3335861C63216C66842B84F496AC8D5A7A94EE82BE0727134E317F8522C862B1D68245C6E51B6284EF74387891486E1416A81056AD635F60E1E731AC3086B9339E8D06BB21DC45CE51EE43A95A8A2794BAB49AE2571D01F7937ED2EE6A5773AF7DC004CF495E49BA7710C4201879CBB01D77DF6439141921A6C70201E0844737F76C5E3287E6B805C31179A76D5A73171616E16C35C3961627F537ED9741FF5CAE52A39535D648CA2A05EE4B2FB2C4102BCDC653A3A9BFC9DB4677DA2F50BDD256229F8167E0EA46F87A76586A44439E8E17F61CC59803C65D76E7292D9BB2BB327B1729DEFD99107B1320658C140CA33CDFEADB3AB35D8AB359F5A5B331BBF6972A81AAF86707D07EEADD39F05A30C3F027C8E3F643BF1379F2751BD5848639107668725D8AAFBDB1240FD6B6925F5C28106EF517D45899DEA231D126213C249ABB676E8C017FDC7F3825BDBA9B26543D4A4DDDF34BD85CEF026A14430016C03ABD9477C5F795F64EE016327C5E89D1E8BD08A740ABF318912B8EC5363CC520354827EF29547599A643D3416011DC103B2F84D2E441CBAE22DD42BD062634E65F75A42F58CAA8E2937AC8E8565D5DBF5E17F1EC0EAD6B4C2A8E831E658E51B16EE7D60402E040323CDB755683F4FD9CCAE3A9CEF4BA995E86ED9F4CEB0AA57D713F9C623AA649EEF163B14C19CF88D36397288967780B6E26C7D12D7A0B907BEC2D50B02F3122EC97D08762CD376AA2F20E74A24C4FB5817131E46669CD21137610964564287613E7964CD53FB1ECC8D87CA6999CAF01BBDD87B75705F6541FCD4FD2EAB11F44DB201888E7B717DEE781942168F686786E4B84926036698C6A3881669229DBB6ADB0F22D17753D2746A0268212DBE9B83EB2DAD83BB75C4350FE9A439EE6D721445A351D4B1079122B5F14980B131FEE2873B45DBCE10778379ECF2665945E20CCCC22B7727B4E1A0FB9D6ACDF069B555C0E61DA20303F30EF1083BDBBDB20DF6A7F4B8C069C71F7E36BDBE4750D59771F4B8386E33"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(496)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(552)
c:\windows\system32\relog_ap.dll
.
Completion time: 2012-04-29 10:53:57
ComboFix-quarantined-files.txt 2012-04-29 08:53
.
Pre-Run: 6 457 327 616 bájt szabad
Post-Run: 6 408 306 688 bájt szabad
.
- - End Of File - - 78A78FC8FACDCFFAC3431C9E70B0C209