Tak jsem provedl oba testy a posilam vypisy a dekuju za predchozi radu. Mam jeste neco udelat? Nemel jsem take zkontrolovat externi disk? mam na nem fotky a nejaky filmy a zalohu veci do skoly (plno rozbalenych zdrojovych kodu z C++ open source projektu - tak 10.000 files, tak nevim, jestli by se tam taky mohlo neco ukryvat - aby se pak neco neprehralo po pripojeni disku zpatky do pocitace?)
==================================================================================================================
COMBOFIX:
ComboFix 10-01-18.03 - Dejv 10/26/2009 5:13.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.510 [GMT 1:00]
Running from: c:\documents and settings\Dejv\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dejv\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FILE ::
"c:\windows\ildasmfnt.bin"
"c:\windows\system32\eEmpty.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Symantec
c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\Settings.LiveUpdate
c:\documents and settings\Dejv\.fop
c:\documents and settings\Dejv\.fop\fop-fonts.cache
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.htm
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
c:\program files\Common Files\Symantec Shared\SPManifests\eraser.grd
c:\program files\Common Files\Symantec Shared\SPManifests\eraser.sig
c:\program files\Common Files\Symantec Shared\SPManifests\eraser.spm
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\CATALOG.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\CCERASER.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ECBOOTIL.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ECMSVR32.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\EECTRL.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ERASER.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ERASER.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ERASER.SPM
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ERASER.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ESRDEF.BIN
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\HH
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVENG.EXP
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVENG.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVENG.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVENG32.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVEX15.EXP
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVEX15.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVEX15.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NAVEX32A.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\NCSACERT.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\SCRAUTH.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\SYMAVENG.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\SYMAVENG.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\SYMERASE.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\SYMERASE.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TCDEFS.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TCSCAN7.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TCSCAN8.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TCSCAN9.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TECHNOTE.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TINF.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TINFIDX.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TINFL.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TSCAN1.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\TSCAN1HD.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\UPDATE.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\V.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\V.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN1.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN2.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN3.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN4.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN5.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN6.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN7.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN8.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCAN9.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\VIRSCANT.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\WHATSNEW.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090607.004\ZDONE.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\CATALOG.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\CCERASER.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ECBOOTIL.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ECMSVR32.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\EECTRL.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ERASER.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ERASER.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ERASER.SPM
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ERASER.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ESRDEF.BIN
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\HH
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVENG.EXP
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVENG.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVENG.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVENG32.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVEX15.EXP
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVEX15.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVEX15.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NAVEX32A.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\NCSACERT.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\SCRAUTH.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\SYMAVENG.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\SYMAVENG.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\SYMERASE.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\SYMERASE.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TCDEFS.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TCSCAN7.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TCSCAN8.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TCSCAN9.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TECHNOTE.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TINF.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TINFIDX.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TINFL.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TSCAN1.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\TSCAN1HD.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\UPDATE.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\V.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\V.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN1.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN2.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN3.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN4.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN5.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN6.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN7.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN8.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCAN9.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\VIRSCANT.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\WHATSNEW.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090630.002\ZDONE.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\CATALOG.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\CCERASER.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ECBOOTIL.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ECMSVR32.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\EECTRL.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ERASER.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ERASER.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ERASER.SPM
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ERASER.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ESRDEF.BIN
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\HH
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVENG.EXP
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVENG.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVENG.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVENG32.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVEX15.EXP
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVEX15.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVEX15.VXD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NAVEX32A.DLL
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\NCSACERT.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\SCRAUTH.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\SYMAVENG.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\SYMAVENG.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\SYMERASE.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\SYMERASE.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TCDEFS.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TCSCAN7.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TCSCAN8.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TCSCAN9.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TECHNOTE.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TINF.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TINFIDX.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TINFL.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TSCAN1.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\TSCAN1HD.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\UPDATE.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\V.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\V.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN1.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN2.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN3.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN4.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN5.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN6.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN7.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN8.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCAN9.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\VIRSCANT.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\vscanmsx.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\WHATSNEW.TXT
c:\program files\Common Files\Symantec Shared\VirusDefs\20090707.003\ZDONE.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\catalog.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\cceraser.dll
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ecbootil.vxd
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ecmsvr32.dll
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\EECTRL.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.GRD
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.SIG
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.SPM
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.SYS
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\esrdef.bin
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\hh
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.exp
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.sys
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.vxd
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng32.dll
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.exp
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.sys
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.vxd
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\navex32a.dll
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\ncsacert.txt
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\scrauth.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.cat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.inf
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\SYMERASE.CAT
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\SYMERASE.INF
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tcdefs.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan7.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan8.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan9.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\technote.txt
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tinf.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfidx.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfl.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1hd.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\v.grd
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\v.sig
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan.inf
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan1.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan2.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan3.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan4.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan5.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan6.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan7.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan8.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan9.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\VIRSCANT.DAT
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\whatsnew.txt
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub\zdone.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\definfo.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\TextHub\virscant.dat
c:\program files\Common Files\Symantec Shared\VirusDefs\usage.dat
c:\program files\Symantec
c:\windows\ildasmfnt.bin
c:\windows\logo_1.exe
c:\windows\logo1_.exe
c:\windows\RUNDL132.EXE
c:\windows\rundll16.exe
c:\windows\system32\eEmpty.exe
c:\windows\system32\runouce.exe
c:\windows\VDLL.DLL
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_eeCtrl
-------\Service_eeCtrl
((((((((((((((((((((((((( Files Created from 2009-09-26 to 2009-10-26 )))))))))))))))))))))))))))))))
.
2009-11-09 13:24 . 2009-10-23 15:43 -------- d-----w- C:\lint
2009-11-08 22:29 . 2008-04-14 03:41 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2009-11-08 22:25 . 2009-11-08 22:25 -------- d-----w- c:\windows\EHome
2009-10-26 00:21 . 2009-10-26 00:21 -------- d-----w- c:\documents and settings\Dejv\Application Data\Malwarebytes
2009-10-26 00:21 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-26 00:21 . 2009-10-26 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-26 00:21 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-26 00:21 . 2009-10-26 00:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-25 23:24 . 2009-10-25 23:24 388096 ----a-r- c:\documents and settings\Dejv\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2009-10-25 23:24 . 2009-10-25 23:24 -------- d-----w- c:\program files\HiJack-SpywareScanner
2009-10-25 23:13 . 2008-04-13 23:15 26112 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-10-25 23:13 . 2008-04-13 23:15 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-10-25 23:09 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-10-25 23:09 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-10-25 23:09 . 2009-02-09 05:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-10-25 23:09 . 2009-02-09 05:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-10-25 23:09 . 2009-02-09 05:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-10-25 23:09 . 2009-02-09 05:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-10-25 09:32 . 2009-10-25 09:32 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-10-25 09:32 . 2009-10-25 09:32 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-10-25 09:32 . 2008-04-14 03:42 135680 ----a-w- c:\windows\system32\T.COM
2009-10-25 09:32 . 2008-04-14 03:42 146432 ----a-w- c:\windows\R.COM
2009-10-25 09:32 . 2009-10-25 09:32 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-10-25 09:31 . 2009-10-25 09:31 -------- d-----w- c:\documents and settings\All Users\Application Data\MicroWorld
2009-10-25 08:36 . 2009-10-24 21:31 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-10-25 08:36 . 2009-10-24 21:31 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-10-25 08:36 . 2009-10-24 21:31 1260312 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-10-25 08:35 . 2009-10-24 21:32 3776280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-10-25 08:35 . 2009-10-24 21:31 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2009-10-25 08:35 . 2009-10-24 21:31 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-10-25 08:34 . 2009-10-24 21:31 3967256 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-10-24 21:33 . 2009-10-24 21:33 -------- d-----w- C:\$AVG
2009-10-24 21:33 . 2009-10-24 21:33 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-24 21:33 . 2009-10-24 21:33 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-24 21:33 . 2009-10-24 21:33 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-24 21:33 . 2009-10-24 21:33 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-24 21:32 . 2009-10-26 02:01 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-24 21:31 . 2009-10-24 21:31 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-24 18:02 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2009-10-24 13:01 . 2009-10-24 13:01 -------- d-----w- c:\program files\starsi Office
2009-10-24 12:33 . 2008-03-21 11:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-10-23 22:40 . 2009-10-22 23:42 -------- d-----w- c:\program files\FileZilla2009-Verze9-34 Nepouzivam - nejnovejsi verze - jen na zkousku
2009-10-23 19:15 . 2009-10-23 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\FreeRIP
2009-10-23 19:15 . 2009-10-23 19:20 -------- d-----w- c:\program files\AudioFreeRIP3-CD to MP3
2009-10-23 18:43 . 2009-10-23 18:44 -------- d-----w- c:\program files\FileZilla2004-07-Verze9-2 Nepouzivam
2009-10-23 16:50 . 2009-10-23 06:31 -------- d-----w- c:\program files\SopCast
2009-10-23 15:43 . 2009-10-23 15:43 -------- d--h--w- c:\windows\PIF
2009-10-23 12:30 . 2009-10-23 01:07 -------- d-----w- c:\program files\FileZilla2005-03-Verze9-6
2009-10-23 12:18 . 2009-10-21 22:02 -------- d-----w- c:\program files\FileZilla2009-06-Verze9-32
2009-10-23 11:33 . 2009-10-21 02:56 -------- d-----w- c:\program files\StopWatch
2009-10-23 11:27 . 2009-10-23 11:31 -------- d--h--w- c:\documents and settings\All Users\Application Data\{4748A871-C4A6-4850-9FB2-30F269897E32}
2009-10-23 11:27 . 2009-09-10 06:58 2397551 ----a-w- c:\documents and settings\All Users\Application Data\{4748A871-C4A6-4850-9FB2-30F269897E32}\VisualLintAddInSetup.exe
2009-10-23 11:27 . 2009-10-23 11:27 -------- d-----w- c:\program files\Common Files\Steema Software
2009-10-23 11:27 . 2009-10-23 11:27 -------- d-----w- c:\program files\Riverblade
2009-10-23 11:25 . 2009-10-23 03:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-23 11:09 . 2009-10-25 22:22 -------- d-----w- c:\documents and settings\Dejv\Application Data\JLC's Software
2009-10-23 11:09 . 2009-10-25 22:22 -------- d-----w- c:\program files\JLC's Software
2009-10-23 10:03 . 2009-10-23 10:08 -------- d-----w- c:\program files\vanBasco's Karaoke Player
2009-10-23 09:45 . 2009-10-23 09:45 -------- d-----w- c:\documents and settings\LocalService\Application Data\AdobeUM
2009-10-23 09:44 . 2009-10-23 09:44 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-10-23 09:41 . 2009-10-23 09:41 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\WMTools Downloaded Files
2009-10-23 08:51 . 2009-10-23 09:29 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\Fortify
2009-10-23 08:32 . 2009-10-23 08:32 -------- d-----w- c:\program files\Fortify Software
2009-10-23 08:03 . 2009-10-23 08:05 -------- d-----w- c:\program files\FortifySourceCodeAnalyser
2009-10-23 07:54 . 2009-10-23 07:54 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\Downloaded Installations
2009-10-23 03:41 . 2009-10-23 03:41 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-23 03:40 . 2009-10-23 03:41 -------- d-----w- c:\program files\DivX
2009-10-23 03:36 . 2009-10-21 23:46 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\Readon_Technology
2009-10-23 03:13 . 2009-10-23 03:13 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\Shareaza
2009-10-23 03:07 . 2009-10-23 03:14 -------- d-----w- c:\documents and settings\Dejv\Application Data\Shareaza
2009-10-23 03:06 . 2009-10-23 03:14 -------- d-----w- c:\program files\Shareaza
2009-10-23 01:02 . 2009-10-23 01:02 112928 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-10-23 01:02 . 2009-10-23 01:02 -------- d-----w- c:\program files\FileZilla2006-05-Verze9-16c - Jenom vyzkousim
2009-10-22 23:53 . 2009-10-22 23:55 -------- d-----w- c:\program files\FileZilla2006-04-Verze9-15
2009-10-22 23:08 . 2009-10-22 23:08 -------- d-----w- c:\program files\Common Files\Skype
2009-10-22 17:38 . 2009-10-22 17:41 -------- d-----w- c:\documents and settings\Dejv\Application Data\Nseries
2009-10-22 17:28 . 2009-10-22 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2009-10-22 17:08 . 2009-10-22 17:08 -------- d-----w- c:\documents and settings\Dejv\Bluetooth Software
2009-10-22 17:06 . 2009-10-22 17:06 -------- d-----w- c:\documents and settings\Dejv\Application Data\Leadertech
2009-10-22 17:05 . 2005-10-05 10:00 47104 ----a-w- c:\windows\system32\drivers\vserial.sys
2009-10-22 17:05 . 2005-10-05 10:00 18167 ----a-w- c:\windows\system32\drivers\vsb.sys
2009-10-22 17:04 . 2009-10-25 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-10-22 16:56 . 2007-12-14 14:13 53248 ----a-w- c:\windows\system32\LBTCoIns.DLL
2009-10-22 16:52 . 2006-12-04 12:33 106557 ----a-w- c:\windows\system32\btw_ci.dll
2009-10-22 16:52 . 2006-12-04 12:33 67672 ----a-w- c:\windows\system32\drivers\btwusb.sys
2009-10-22 16:52 . 2006-12-04 12:33 30285 ----a-w- c:\windows\system32\drivers\btwmodem.sys
2009-10-22 16:52 . 2006-12-04 12:33 47907 ----a-w- c:\windows\system32\drivers\btwhid.sys
2009-10-22 16:52 . 2006-12-04 12:33 30459 ----a-w- c:\windows\system32\drivers\btport.sys
2009-10-22 16:52 . 2006-12-04 12:33 863402 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2009-10-22 16:52 . 2006-12-04 12:33 329901 ----a-w- c:\windows\system32\drivers\btaudio.sys
2009-10-22 16:51 . 2009-10-22 16:51 -------- d-----w- c:\program files\WIDCOMM
2009-10-22 16:49 . 2009-10-22 16:49 -------- d-----w- C:\WTLHeaderForCplusPlusWindowsDevelopment
2009-10-22 16:03 . 2009-10-22 16:03 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\Logitech-LS
2009-10-22 15:56 . 2009-10-25 22:28 -------- d-----w- c:\program files\Common Files\Logitech
2009-10-22 15:56 . 2003-03-18 19:44 57344 ----a-w- c:\windows\system32\MFC71ENU.DLL
2009-10-22 15:56 . 2003-03-18 19:44 49152 ----a-w- c:\windows\system32\MFC71KOR.DLL
2009-10-22 15:56 . 2003-03-18 19:44 61440 ----a-w- c:\windows\system32\MFC71ITA.DLL
2009-10-22 15:56 . 2003-03-18 19:44 61440 ----a-w- c:\windows\system32\MFC71ESP.DLL
2009-10-22 15:56 . 2003-03-18 19:44 45056 ----a-w- c:\windows\system32\MFC71CHT.DLL
2009-10-22 15:56 . 2003-03-18 19:44 40960 ----a-w- c:\windows\system32\MFC71CHS.DLL
2009-10-22 15:56 . 2003-03-18 19:44 65536 ----a-w- c:\windows\system32\MFC71DEU.DLL
2009-10-22 15:56 . 2003-03-18 19:44 49152 ----a-w- c:\windows\system32\MFC71JPN.DLL
2009-10-22 15:55 . 2009-10-25 23:39 -------- d-----w- c:\program files\Logitech
2009-10-22 08:00 . 2009-10-22 08:00 -------- d-----w- c:\program files\7-Zip
2009-10-22 05:02 . 2009-10-22 06:01 -------- d-----w- c:\program files\FileZilla2004-08-Verze9-3 Nepouzivam - moc stary nejde compilovat
2009-10-21 23:43 . 2009-10-21 23:43 -------- d-----w- c:\program files\Readon Technology
2009-10-21 05:38 . 2009-10-21 05:38 75776 -c----w- c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 05:38 . 2009-10-21 05:38 25088 -c----w- c:\windows\system32\dllcache\httpapi.dll
2009-10-21 03:32 . 2009-10-21 03:32 -------- d-----w- c:\program files\Nsasoft
2009-10-21 02:56 . 2009-10-22 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-10-21 02:47 . 2009-10-21 02:47 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\IsolatedStorage
2009-10-21 02:47 . 2009-10-23 01:41 -------- d-----w- c:\documents and settings\Dejv\Application Data\PC Suite
2009-10-21 02:46 . 2009-10-22 21:42 -------- d-----w- c:\documents and settings\Dejv\Local Settings\Application Data\Nokia
2009-10-21 02:41 . 2009-10-25 23:05 -------- d-----w- c:\documents and settings\Dejv\Application Data\Nokia
2009-10-21 02:27 . 2009-10-21 02:27 -------- d-----w- c:\documents and settings\All Users\Application Data\NokiaMusic
2009-10-21 02:25 . 2009-10-21 02:25 -------- d-----w- c:\windows\system32\muveeInstall
2009-10-21 02:23 . 2009-10-21 02:34 -------- d-----w- c:\windows\Globalization
2009-10-21 02:07 . 2009-10-21 02:07 -------- d-----w- c:\program files\DIFX
2009-10-21 02:06 . 2009-10-25 23:18 -------- d-----w- c:\program files\Nokia
2009-10-21 02:06 . 2009-02-09 05:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-10-21 02:02 . 2009-10-25 23:13 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-10-21 02:02 . 2009-10-21 02:02 -------- d-----w- c:\windows\system32\LogFiles
2009-10-20 16:20 . 2009-10-20 16:20 265728 -c----w- c:\windows\system32\dllcache\http.sys
2009-10-13 10:30 . 2009-10-13 10:30 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2009-10-12 13:38 . 2009-10-12 13:38 149504 -c----w- c:\windows\system32\dllcache\rastls.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 15:51 . 2006-03-02 06:20 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-10 09:57 . 2009-11-10 09:57 53 ----a-w- C:\_LINT.TMP
2009-11-10 09:56 . 2009-11-10 09:56 0 ----a-w- c:\documents and settings\Dejv\_LINT.TMP
2009-11-08 22:37 . 2006-03-02 07:38 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-29 07:45 . 2006-03-02 06:21 916480 ------w- c:\windows\system32\wininet.dll
2009-10-25 06:11 . 2009-05-26 12:47 -------- d-----w- c:\program files\Common Files\logishrd
2009-10-24 21:31 . 2009-09-09 17:57 -------- d-----w- c:\program files\AVG
2009-10-24 12:34 . 2009-10-24 12:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-10-24 12:34 . 2009-10-24 12:34 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-10-23 22:07 . 2009-05-19 13:29 -------- d-----w- c:\documents and settings\Dejv\Application Data\skypePM
2009-10-23 20:36 . 2009-05-19 13:28 -------- d-----w- c:\documents and settings\Dejv\Application Data\Skype
2009-10-23 19:38 . 2009-09-14 22:37 -------- d-----w- c:\program files\ICQ6.5
2009-10-23 09:00 . 2009-09-05 10:55 1680128 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-10-23 03:08 . 2009-05-16 20:16 56104 ----a-w- c:\documents and settings\Dejv\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-23 01:32 . 2009-08-20 16:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-23 00:09 . 2009-09-14 22:38 -------- d-----w- c:\documents and settings\Dejv\Application Data\ICQ
2009-10-22 23:08 . 2009-05-19 13:28 -------- d-----r- c:\program files\Skype
2009-10-22 23:08 . 2009-05-19 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-10-22 17:05 . 2006-03-02 08:11 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-22 17:02 . 2009-10-22 17:02 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-10-22 17:00 . 2009-10-22 17:00 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-10-22 17:00 . 2009-10-22 17:00 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-10-22 00:01 . 2009-05-19 14:33 -------- d-----w- c:\documents and settings\Dejv\Application Data\vlc
2009-10-21 05:38 . 2006-03-02 06:21 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-03-02 06:21 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-15 16:28 . 2006-03-02 06:21 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-10-15 16:28 . 2006-03-02 06:21 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-10-13 10:30 . 2006-03-02 06:21 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-03-02 06:21 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-03-02 06:21 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-01 10:02 . 2009-09-02 17:53 -------- d-----w- c:\documents and settings\Dejv\Application Data\Template
2009-09-27 22:20 . 2009-09-06 20:48 -------- d-----w- c:\documents and settings\Dejv\Application Data\PVS-Studio
2009-09-23 13:51 . 2009-09-23 13:51 -------- d-----w- c:\program files\WordWeb
2009-09-17 21:23 . 2009-09-02 15:24 -------- d-----w- c:\program files\Parasoft
2009-09-16 23:04 . 2009-06-30 04:05 -------- d-----w- c:\documents and settings\Dejv\Application Data\dvdcss
2009-09-16 23:01 . 2009-09-16 23:01 -------- d-----w- c:\documents and settings\Dejv\Application Data\InterVideo
2009-09-15 18:30 . 2009-09-15 18:16 -------- d-----w- c:\program files\TranslatorPC
2009-09-11 14:18 . 2006-03-02 06:21 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-08 19:55 . 2009-09-08 19:43 -------- d-----w- c:\program files\eMule
2009-09-08 19:54 . 2009-06-23 00:56 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-09-08 19:32 . 2009-05-16 19:39 -------- d-----w- c:\program files\Microsoft Works
2009-09-07 07:52 . 2009-09-02 17:53 130 ----a-w- c:\documents and settings\Dejv\Application Data\wklnhst.dat
2009-09-06 20:46 . 2009-08-25 20:50 -------- d-----w- c:\program files\PVS-Studio
2009-09-05 11:16 . 2009-09-05 11:16 -------- d-----w- c:\program files\MSDN
2009-09-05 11:02 . 2009-08-20 16:02 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2009-09-05 11:02 . 2009-09-05 11:02 -------- d-----w- c:\program files\Business Objects
2009-09-05 11:01 . 2009-09-05 11:01 -------- d-----w- c:\program files\Microsoft Device Emulator
2009-09-05 11:01 . 2009-09-05 11:00 -------- d-----w- c:\program files\Windows Mobile 5.0 SDK R2
2009-09-05 10:59 . 2009-09-05 10:59 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-09-05 10:59 . 2009-09-05 10:59 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-05 10:57 . 2009-05-16 19:41 -------- d-----w- c:\program files\Microsoft.NET
2009-09-05 10:55 . 2009-09-05 10:55 18368 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-09-05 10:49 . 2009-08-20 16:02 -------- d-----w- c:\program files\Common Files\Merge Modules
2009-09-05 10:49 . 2009-09-05 10:49 -------- d-----w- c:\documents and settings\All Users\Application Data\PreEmptive Solutions
2009-09-05 10:46 . 2009-09-05 10:42 -------- d-----w- c:\program files\HTML Help Workshop
2009-09-05 10:45 . 2009-08-20 15:59 -------- d-----w- c:\program files\MSBuild
2009-09-05 10:42 . 2009-09-05 10:42 -------- d-----w- c:\program files\CE Remote Tools
2009-09-04 22:37 . 2009-09-04 22:36 -------- d-----w- c:\program files\Microsoft Web Designer Tools
2009-09-04 22:10 . 2009-09-04 22:01 -------- d-----w- c:\program files\WinTar
2009-09-04 22:01 . 2009-09-04 22:01 -------- d-----w- c:\documents and settings\Dejv\Application Data\WinTar
2009-09-04 22:00 . 2009-09-04 21:59 -------- d-----w- c:\documents and settings\Dejv\Application Data\GetRightToGo
2009-09-04 21:59 . 2009-09-04 21:59 -------- d-----w- c:\program files\TarBall
2009-09-04 21:03 . 2006-03-02 06:21 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 17:05 . 2009-09-04 13:59 -------- d-----w- c:\program files\MinGW-DebuggerForEclipse
2009-09-02 15:24 . 2009-09-02 15:24 -------- d-----w- c:\documents and settings\Dejv\Application Data\InstallShield
2009-09-01 22:10 . 2009-09-01 22:10 -------- d-----w- c:\program files\Nitro PDF
2009-08-26 08:00 . 2006-03-02 06:22 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 09:17 . 2006-03-02 06:21 354816 ----a-w- c:\windows\system32\winhttp.dll
2009-08-20 16:07 . 2009-08-20 16:07 112640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2009-08-20 16:06 . 2009-08-20 16:06 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2009-08-14 13:21 . 2006-03-02 06:21 1850624 ----a-w- c:\windows\system32\win32k.sys
2009-08-06 17:24 . 2006-03-02 07:36 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2006-03-02 07:36 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2008-10-16 12:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2006-03-02 07:36 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2006-03-02 07:36 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2006-03-02 06:20 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2006-03-02 07:36 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2006-03-02 07:36 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2006-03-02 06:21 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 18:44 . 2006-03-02 06:21 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-31 08:05 . 2008-08-29 18:06 1372672 ----a-w- c:\windows\system32\msxml6.dll
2009-07-31 04:35 . 2006-03-02 06:21 1172480 ----a-w- c:\windows\system32\msxml3.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"PartSeal"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-25 2033432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-24 21:33 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 01:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dejv^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\documents and settings\Dejv\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Dejv^Start Menu^Programs^Startup^WordWeb.lnk]
path=c:\documents and settings\Dejv\Start Menu\Programs\Startup\WordWeb.lnk
backup=c:\windows\pss\WordWeb.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bluetooth Connection Assistant]
LBTWIZ.EXE -silent [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-04 01:43 69632 ----a-w- c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2003-11-08 00:21 114688 ----a-w- c:\program files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2005-04-29 21:56 45056 ----a-w- c:\program files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2005-11-04 21:25 159832 ----a-w- c:\program files\Common Files\AOL\1242503654\ee\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-08-05 17:56 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-08-05 17:56 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-08-05 17:57 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
2004-02-20 22:12 32768 ----a-w- c:\program files\Sony\ISB Utility\ISBMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2004-01-07 18:15 155648 ----a-r- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-06-29 20:25 14720000 ----a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonyPowerCfg]
2005-10-20 06:07 184320 ----a-w- c:\program files\Sony\VAIO Power Management\SPMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
2005-10-12 05:36 151552 ----a-w- c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
2005-06-13 22:42 258048 ----a-w- c:\program files\Sony\VAIO Survey\SurveySA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Drive Manager]
2008-07-24 13:22 450560 ----a-w- c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Logitech Easy Synchronization"=2 (0x2)
"LBTServ"=2 (0x2)
"FileZilla Server"=2 (0x2)
"btwdins"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Parasoft\\C++test7.2\\plugins\\com.parasoft.eclipse.api.win32_7.2.13.43\\cpptest\\Jre\\1.5\\bin\\javaw.exe"=
"c:\\Program Files\\Nitro PDF\\PrimoPDF\\PrimoPDF.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft Visual Studio 9.0\\Common7\\IDE\\devenv.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Dejv\\My Documents\\Visual Studio 2008\\Projects\\ClientServerZplanet-source-codeCom\\alServer\\Debug\\alServer.exe"=
"c:\\Documents and Settings\\Dejv\\My Documents\\Visual Studio 2008\\Projects\\ClientServerZplanet-source-codeCom\\alServer\\.cpptest\\alServer\\unit-data\\current_tubf179707\\alServerTest.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/24/2009 10:33 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/24/2009 10:33 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/24/2009 10:31 PM 285392]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [7/24/2008 2:22 PM 102400]
S3 FortifyBuildMonitor;Fortify Build Monitor;c:\program files\Fortify Software\Fortify SCA 5.2\Core\private-bin\sca\FortifyBuildMonitorService.exe [11/4/2008 4:25 PM 24576]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/11/2008 1:28 AM 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 1:49 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/11/2008 1:28 AM 369688]
.
Contents of the 'Scheduled Tasks' folder
2009-11-10 c:\windows\Tasks\User_Feed_Synchronization-{5AB07CB9-DE86-4B09-84D5-1AD69752FB73}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.sony.com/vaiopeopleuInternet Connection Wizard,ShellNext =
hxxp://www.sony.com/vaiopeopleIE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\program files\TranslatorPC\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\program files\TranslatorPC\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\program files\TranslatorPC\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\program files\TranslatorPC\WEBIE.DLL
FF - ProfilePath - c:\documents and settings\Dejv\Application Data\Mozilla\Firefox\Profiles\73p4clcx.default\
FF - prefs.js: browser.startup.homepage -
www.gmx.netFF - component: c:\documents and settings\Dejv\Application Data\Mozilla\Firefox\Profiles\73p4clcx.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\documents and settings\Dejv\Application Data\Mozilla\Firefox\Profiles\73p4clcx.default\extensions\firedownload@mozilla.org\components\firedownload.dll
FF - component: c:\documents and settings\Dejv\Application Data\Mozilla\Firefox\Profiles\73p4clcx.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Dejv\Application Data\Mozilla\Firefox\Profiles\73p4clcx.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-26 05:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(820)
c:\windows\system32\VESWinlogon.dll
- - - - - - - > 'explorer.exe'(2304)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-26 05:50:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-26 04:50
ComboFix2.txt 2009-10-26 02:34
Pre-Run: 37,118,541,824 bytes free
Post-Run: 36,926,824,448 bytes free
- - End Of File - - 338D8B7B7AEBAEBDAB81D3F1C17E8932
====================================================================================================================