Ten panacek co ti pali na ikone by mel roztrilet Combofixa.
Vypnul jsem Spybot Residend (pokrocile nastaveni - nastroje, a zruseni, i zrusil 'zamecek-resident protection' na liste), srejne tak Zone Alarm (jednak vypnul ZA, a take v nastaveni Prefernce zrusil, hlidani klienta ZA),
..a stejen to hlasi, ze je to aktivni.
Ale je to poprve co CF bezi bez problemu, jinak jsem si s nim uz uzil dost a dost, jakoze nedojel do konce, shodil system, apod. (Mozna by to chtelo po zruseni rezidenta restartovat, ale uz to nebudu mucit, uz tak jsem rad, ze CF nedela to co jsem uz popsal.)
Mam dotaz nad timto souborem XnView instaloval jsem ta jiny program a v
AppData - Roaming - XnView stale visi 8MB slozka.
2009-05-11 22:15 . 2008-07-20 08:42 -------- d-----w- c:\users\Dell\AppData\Roaming\XnView

Vysledek druheho testu (opet s aktivni rezidentni ochranou):
...
ComboFix 09-06-11.05 - Dell 11/06/2009 23:25.6 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.44.1033.18.893.426 [GMT 2:00]
Running from: c:\users\Dell\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
.
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.
2009-06-11 20:39 . 2009-06-11 21:32 -------- d-----w- c:\users\Dell\AppData\Local\temp
2009-06-10 23:38 . 2009-06-10 23:38 -------- d---a-w- c:\windows\system32\runouce.exe
2009-06-10 20:55 . 2004-05-04 10:53 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2009-06-09 23:19 . 2009-04-21 11:39 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-06-08 12:30 . 2007-01-12 08:51 303104 ----a-w- c:\windows\sttray.exe
2009-06-08 12:28 . 2007-01-12 08:52 647680 ----a-w- c:\windows\system32\drivers\stwrt.sys
2009-06-08 12:28 . 2007-01-12 08:51 238592 ----a-w- c:\windows\system32\stapi32.dll
2009-06-08 12:28 . 2009-06-08 12:28 -------- d-----w- c:\program files\SigmaTel
2009-06-08 12:28 . 2006-11-22 12:16 45568 ----a-w- c:\windows\system32\ctppld.dll
2009-06-06 15:22 . 2009-06-06 15:23 -------- d-----w- c:\program files\QuickTime
2009-06-06 15:22 . 2009-06-06 15:22 -------- d-----w- c:\programdata\Apple Computer
2009-05-30 14:26 . 2009-05-30 14:26 -------- d-----w- c:\windows\system32\QuickTime
2009-05-28 16:46 . 2009-05-28 16:48 -------- d-----w- c:\windows\system32\ca-ES
2009-05-28 16:46 . 2009-05-28 16:47 -------- d-----w- c:\windows\system32\eu-ES
2009-05-28 16:46 . 2009-05-28 16:47 -------- d-----w- c:\windows\system32\vi-VN
2009-05-28 16:26 . 2009-05-28 16:26 -------- d-----w- c:\windows\system32\EventProviders
2009-05-28 16:24 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-05-28 16:22 . 2009-04-11 06:28 56320 ----a-w- c:\windows\system32\xmlfilter.dll
2009-05-28 16:21 . 2009-04-11 06:28 547840 ----a-w- c:\windows\system32\wiaaut.dll
2009-05-28 16:20 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-05-19 17:44 . 2009-05-19 17:46 -------- d-----w- c:\users\Dell\AppData\Local\SeeToo
2009-05-19 17:41 . 2008-12-24 15:46 221184 ----a-w- c:\users\Dell\AppData\Roaming\Mozilla\Firefox\Profiles\lsgpyp9t.default\extensions\seetooaddon@seetoo.com\plugins\npSeeTooAddon.dll
2009-05-19 17:27 . 2008-12-18 09:19 1796096 ----a-w- c:\users\Dell\AppData\Roaming\Mozilla\Firefox\Profiles\lsgpyp9t.default\extensions\justintvpublisher@justin.tv\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll
2009-05-17 11:30 . 2009-05-17 11:30 -------- d-----w- c:\program files\TVAnts
2009-05-13 21:24 . 2009-05-13 21:24 -------- d-----w- c:\users\Dell\AppData\Local\Apple Computer
2009-05-13 20:49 . 2009-05-13 20:49 -------- d-----w- c:\program files\Apple Software Update
2009-05-13 20:49 . 2009-05-13 20:49 -------- d-----w- c:\programdata\Apple
2009-05-13 20:49 . 2009-05-13 20:49 -------- d-----w- c:\users\Dell\AppData\Local\Apple
2009-05-13 20:26 . 2009-05-13 20:26 -------- d-----w- c:\users\Dell\AppData\Roaming\GRETECH
2009-05-13 15:23 . 2009-05-16 21:24 -------- d-----w- c:\users\Dell\AppData\Local\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 21:24 . 2009-04-15 10:19 350192 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-06-11 20:25 . 2008-07-18 01:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-11 15:22 . 2008-10-27 20:23 1 ----a-w- c:\users\Dell\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-11 12:38 . 2008-07-18 02:28 -------- d-----w- c:\users\Dell\AppData\Roaming\Skype
2009-06-11 12:20 . 2008-07-18 02:32 -------- d-----w- c:\users\Dell\AppData\Roaming\skypePM
2009-06-10 23:21 . 2008-12-11 19:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-10 23:20 . 2009-01-10 00:57 3371383 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-10 20:55 . 2009-02-07 17:23 -------- d-----w- c:\program files\BurnAware Free
2009-06-10 17:50 . 2008-08-04 17:58 -------- d-----w- c:\users\Dell\AppData\Roaming\uTorrent
2009-06-07 13:23 . 2009-03-21 09:14 117760 ----a-w- c:\users\Dell\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-02 18:07 . 2008-07-18 00:59 -------- d-----w- c:\program files\ATI
2009-05-30 20:02 . 2008-12-05 22:58 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-28 16:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-05-28 16:48 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-28 16:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-05-28 16:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-05-28 16:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-05-28 16:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-05-28 16:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-05-28 16:46 . 2008-12-11 15:55 -------- d-----w- c:\program files\Microsoft Games
2009-05-28 16:46 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-26 11:20 . 2008-12-11 19:40 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2008-12-11 19:40 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-22 15:49 . 2009-03-22 17:52 -------- d-----w- c:\program files\Call of Duty
2009-05-13 20:34 . 2009-03-29 21:38 -------- d-----w- c:\program files\Real Alternative
2009-05-13 20:24 . 2009-04-25 13:08 -------- d-----w- c:\program files\GRETECH
2009-05-11 22:15 . 2008-07-20 08:42 -------- d-----w- c:\users\Dell\AppData\Roaming\XnView
2009-05-11 15:28 . 2009-05-11 15:28 -------- d-----w- c:\program files\MSXML 4.0
2009-05-11 15:28 . 2009-05-11 15:28 -------- d-----w- c:\program files\OLYMPUS
2009-05-09 05:50 . 2009-06-09 23:18 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-09 23:18 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-06 13:15 . 2009-05-06 13:15 234 ----a-w- c:\users\Dell\AppData\Roaming\JLC's Software\Internet TV\Update.exe
2009-05-05 19:43 . 2009-01-04 13:46 -------- d-----w- c:\users\Dell\AppData\Roaming\gtk-2.0
2009-04-29 18:37 . 2009-04-29 18:37 -------- d-----w- c:\programdata\Avira
2009-04-29 18:37 . 2009-04-29 18:37 -------- d-----w- c:\program files\Avira
2009-04-23 12:15 . 2009-06-09 23:18 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:14 . 2009-06-09 23:18 623616 ----a-w- c:\windows\system32\localspl.dll
2009-04-11 06:33 . 2009-05-28 16:23 986600 ----a-w- c:\windows\system32\winload.exe
2009-04-11 06:33 . 2009-05-28 16:22 926184 ----a-w- c:\windows\system32\winresume.exe
2009-04-11 06:33 . 2009-05-28 16:22 292840 ----a-w- c:\windows\system32\drivers\volmgrx.sys
2009-04-11 06:33 . 2009-05-28 16:23 897000 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-04-11 06:33 . 2009-05-28 16:23 614376 ----a-w- c:\windows\system32\ci.dll
2009-04-11 06:28 . 2009-05-28 16:22 342528 ----a-w- c:\windows\system32\zipfldr.dll
2009-04-11 06:27 . 2009-05-28 16:23 441344 ----a-w- c:\windows\system32\SearchIndexer.exe
2009-04-11 06:22 . 2009-05-28 16:21 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-04-11 06:21 . 2009-05-28 16:21 37376 ----a-w- c:\windows\system32\cdd.dll
2009-04-11 05:42 . 2009-05-28 16:21 93696 ----a-w- c:\windows\system32\drivers\bridge.sys
2009-04-11 05:03 . 2009-05-28 16:23 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-04-11 04:57 . 2009-05-28 16:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-11 04:54 . 2009-05-28 16:21 2048 ----a-w- c:\windows\system32\mferror.dll
2009-04-11 04:52 . 2009-05-28 16:22 248320 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2009-04-11 04:51 . 2009-05-28 16:21 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2009-04-11 04:47 . 2009-05-28 16:21 273920 ----a-w- c:\windows\system32\drivers\afd.sys
2009-04-11 04:46 . 2009-05-28 16:21 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2009-04-11 04:46 . 2009-05-28 16:21 121344 ----a-w- c:\windows\system32\drivers\ndiswan.sys
2009-04-11 04:46 . 2009-05-28 16:21 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2009-04-11 04:46 . 2009-05-28 16:21 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2009-04-11 04:46 . 2009-05-28 16:21 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2009-04-11 04:46 . 2009-05-28 16:22 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-04-11 04:45 . 2009-05-28 16:21 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2009-04-11 04:45 . 2009-05-28 16:21 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-04-11 04:45 . 2009-05-28 16:22 185856 ----a-w- c:\windows\system32\drivers\netbt.sys
2009-04-11 04:45 . 2009-05-28 16:22 401408 ----a-w- c:\windows\system32\drivers\http.sys
2009-04-11 04:45 . 2009-05-28 16:21 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-04-11 04:45 . 2009-05-28 16:21 66560 ----a-w- c:\windows\system32\drivers\smb.sys
2009-04-11 04:43 . 2009-05-28 16:21 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2009-04-11 04:43 . 2009-05-28 16:22 196096 ----a-w- c:\windows\system32\drivers\usbhub.sys
2009-04-11 04:42 . 2009-05-28 16:22 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2009-04-11 04:42 . 2009-05-28 16:22 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys
2009-04-11 04:42 . 2009-05-28 16:22 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys
2009-04-11 04:42 . 2009-05-28 16:22 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-04-11 04:42 . 2009-05-28 16:21 19456 ----a-w- c:\windows\system32\drivers\usbohci.sys
2009-04-11 04:42 . 2009-05-28 16:22 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-04-11 04:42 . 2009-05-28 16:21 12800 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-04-11 04:42 . 2009-05-28 16:21 39424 ----a-w- c:\windows\system32\drivers\hidclass.sys
2009-04-11 04:42 . 2009-05-28 16:21 52992 ----a-w- c:\windows\system32\drivers\stream.sys
2009-04-11 04:42 . 2009-05-28 16:23 561152 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2009-04-11 04:39 . 2009-05-28 16:21 16384 ----a-w- c:\windows\system32\iscsilog.dll
2009-04-11 04:39 . 2009-05-28 16:21 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2009-04-11 04:39 . 2009-05-28 16:21 11776 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2009-04-11 04:39 . 2009-05-28 16:21 19456 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2009-04-11 04:38 . 2009-05-28 16:22 149504 ----a-w- c:\windows\system32\drivers\ks.sys
2009-04-11 04:27 . 2009-05-28 16:21 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-04-11 04:23 . 2009-05-28 16:23 626176 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-04-11 04:23 . 2009-05-28 16:21 76288 ----a-w- c:\windows\system32\drivers\dxg.sys
2009-04-11 04:23 . 2009-05-28 16:21 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-11 04:22 . 2009-05-28 16:21 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2009-04-11 04:19 . 2009-05-28 16:22 89088 ----a-w- c:\windows\system32\drivers\sdbus.sys
2009-04-11 04:15 . 2009-05-28 16:22 288768 ----a-w- c:\windows\system32\drivers\srv.sys
2009-04-11 04:15 . 2009-05-28 16:22 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-04-11 04:15 . 2009-05-28 16:22 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-04-11 04:14 . 2009-05-28 16:22 351744 ----a-w- c:\windows\system32\drivers\csc.sys
2009-04-11 04:14 . 2009-05-28 16:22 114688 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-04-11 04:14 . 2009-05-28 16:22 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-11 04:14 . 2009-05-28 16:23 225280 ----a-w- c:\windows\system32\drivers\rdbss.sys
2009-04-11 04:14 . 2009-05-28 16:22 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-04-11 04:14 . 2009-05-28 16:22 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-04-11 04:14 . 2009-05-28 16:21 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2009-04-11 04:14 . 2009-05-28 16:21 35328 ----a-w- c:\windows\system32\drivers\npfs.sys
2009-04-11 04:13 . 2009-05-28 16:21 226816 ----a-w- c:\windows\system32\drivers\udfs.sys
2007-02-21 19:48 . 2007-02-21 19:48 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-06-11_20.37.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-17 08:56 . 2009-06-11 19:10 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-17 08:56 . 2009-06-11 20:40 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-17 08:56 . 2009-06-11 20:40 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-07-17 08:56 . 2009-06-11 19:10 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-17 08:56 . 2009-06-11 20:40 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-07-17 08:56 . 2009-06-11 19:10 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 06:28 114176 ----a-w- c:\windows\System32\EhStorShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Live! Cam Manager"="c:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-05-31 143360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-09-04 95536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"V0250Mon.exe"="c:\windows\V0250Mon.exe" [2006-06-07 32768]
"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-08 24576]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2007-09-04 54576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-30 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"V0250Cfg.exe"="V0250Cfg.exe" - c:\windows\V0250Cfg.exe [2005-12-16 20480]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-12 303104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2008-12-27 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001
"VistaSp2"=hex(b):06,b9,15,e9,b4,df,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4FE7EC16-90C3-4DF6-A550-035F37455790}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{DA9A6868-810D-437D-8E1A-B2E91910966F}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{7252612B-BA6E-4980-A8F1-C97A7E3447C6}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{13C78979-3DEF-43ED-A09B-F96C2D32B829}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent (TCP-In)
"{0674E638-0F9B-4BE9-A9FE-625C23D43839}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent (UDP-In)
"TCP Query User{12F775D1-2767-4B23-BBE2-BD9425317C11}c:\\program files\\icq6\\icq.exe"= UDP:c:\program files\icq6\icq.exe:ICQ Library
"UDP Query User{7123CB8B-60B5-46CD-BA49-6D12DC57DD81}c:\\program files\\icq6\\icq.exe"= TCP:c:\program files\icq6\icq.exe:ICQ Library
"{3E7C58D1-1F01-4E2F-87B5-8A03E0CB2072}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{733154CC-D232-4C3A-BDDE-306E37896347}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [15/01/2009 17:17 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15/01/2009 17:17 55024]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [29/04/2009 20:37 108289]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [23/02/2009 13:36 1153368]
R3 V0250Dev;Live! Cam Notebook Pro;c:\windows\System32\drivers\V0250Dev.sys [23/07/2008 11:44 169696]
R3 V0250Vfx;V0250Vfx;c:\windows\System32\drivers\V0250Vfx.sys [23/07/2008 11:44 6272]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\System32\drivers\s115bus.sys [23/04/2007 13:54 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\System32\drivers\s115mdfl.sys [23/04/2007 13:54 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\System32\drivers\s115mdm.sys [23/04/2007 13:54 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s115mgmt.sys [23/04/2007 13:54 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\System32\drivers\s115obex.sys [23/04/2007 13:54 98568]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15/01/2009 17:17 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Dell\AppData\Roaming\Mozilla\Firefox\Profiles\lsgpyp9t.default\
FF - prefs.js: browser.startup.homepage -
hxxp://uk.yahoo.com/FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Dell\AppData\Roaming\Mozilla\Firefox\Profiles\lsgpyp9t.default\extensions\justintvpublisher@justin.tv\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll
FF - plugin: c:\users\Dell\AppData\Roaming\Mozilla\Firefox\Profiles\lsgpyp9t.default\extensions\seetooaddon@seetoo.com\plugins\npSeeTooAddon.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-11 23:32
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
[0] 0x89E45D8B
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-11 23:34
ComboFix-quarantined-files.txt 2009-06-11 21:34
ComboFix2.txt 2009-06-11 20:39
Pre-Run: 10,604,564,480 bytes free
Post-Run: 10,462,900,224 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=15 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15
281 --- E O F --- 2009-06-09 23:24