Ето лог от ComboFix:
ComboFix 09-02-12.03 - VASIL 2009-02-14 9:26:33.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1251.1.1033.18.1918.1084 [GMT 2:00]
Running from: c:\users\VASIL\Desktop\combofix.exe
Command switches used :: /killall
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\restore\S-1-5-21-1482476501-1644491937-682003330-1013
c:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-01-14 to 2009-02-14 )))))))))))))))))))))))))))))))
.
2009-02-13 20:42 . 2009-02-13 20:43 <DIR> d-------- C:\HiJackThis
2009-02-13 19:15 . 2009-02-13 19:16 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-13 17:32 . 2009-02-14 02:50 <DIR> d-------- c:\windows\System32\drivers\Avg
2009-02-13 17:32 . 2009-02-13 17:32 325,128 --a------ c:\windows\System32\drivers\avgldx86.sys
2009-02-13 17:32 . 2009-02-13 17:32 107,272 --a------ c:\windows\System32\drivers\avgtdix.sys
2009-02-13 17:32 . 2009-02-13 17:32 12,552 --a------ c:\windows\System32\drivers\avgrkx86.sys
2009-02-13 17:32 . 2009-02-13 17:32 10,520 --a------ c:\windows\System32\avgrsstx.dll
2009-02-13 17:31 . 2009-02-13 17:31 <DIR> d-------- c:\users\All Users\avg8
2009-02-13 17:31 . 2009-02-13 17:31 <DIR> d-------- c:\programdata\avg8
2009-02-13 17:31 . 2009-02-13 17:31 23,832 --a------ c:\windows\System32\drivers\avgfwd6x.sys
2009-02-13 17:27 . 2008-06-20 03:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-13 17:27 . 2008-06-20 03:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-13 17:27 . 2008-06-20 03:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-13 17:27 . 2008-06-20 03:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-13 17:27 . 2008-06-20 03:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-13 17:27 . 2008-06-20 03:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-13 17:27 . 2008-06-20 03:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-13 17:27 . 2008-06-20 03:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-13 17:22 . 2008-07-27 20:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-13 17:22 . 2008-07-27 20:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-13 17:22 . 2008-07-27 20:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-13 17:22 . 2008-07-27 20:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-13 17:22 . 2008-07-27 20:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-13 17:21 . 2008-12-05 06:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-13 17:21 . 2008-12-05 06:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-13 17:21 . 2008-12-05 06:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-13 17:21 . 2008-12-05 06:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-13 17:21 . 2008-12-05 06:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-13 15:51 . 2009-02-13 15:51 <DIR> d-------- c:\users\VASIL\AppData\Roaming\Malwarebytes
2009-02-13 15:51 . 2009-02-13 15:51 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-13 15:51 . 2009-02-13 15:51 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-13 15:51 . 2009-02-13 15:51 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:51 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-13 15:51 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-13 14:36 . 2009-02-13 14:36 <DIR> d-------- c:\program files\Java
2009-02-13 14:36 . 2009-02-13 14:36 410,984 --a------ c:\windows\System32\deploytk.dll
2009-02-13 14:22 . 2009-02-13 14:22 0 --ah----- c:\users\Default.LOG2
2009-02-13 14:22 . 2009-02-13 14:22 0 --ah----- c:\users\Default.LOG1
2009-02-13 14:22 . 2009-02-13 14:22 0 --ah----- C:\ProgramData.LOG2
2009-02-13 14:22 . 2009-02-13 14:22 0 --ah----- C:\ProgramData.LOG1
2009-02-13 14:09 . 2009-02-13 14:09 170 --a------ C:\install.dat
2009-02-13 12:44 . 2009-02-13 12:44 <DIR> d-------- c:\program files\Alwil Software
2009-02-12 00:02 . 2009-01-15 05:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-12 00:02 . 2009-01-15 08:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-11 21:00 . 2009-02-11 21:00 <DIR> d-------- c:\users\Desktop
2009-02-10 14:10 . 2009-02-10 14:10 <DIR> d-------- c:\program files\Skype
2009-02-10 14:10 . 2009-02-10 14:10 <DIR> d-------- c:\program files\Common Files\Skype
2009-02-09 19:41 . 2009-02-09 19:41 <DIR> d-------- c:\windows\Google Earth Pro 4.2
2009-02-09 19:41 . 2009-02-09 19:43 <DIR> d-------- c:\program files\Google Earth Pro 4.2
2009-02-09 16:55 . 2009-02-09 16:55 <DIR> d-------- c:\users\Public\Dictionary
2009-02-08 10:01 . 2009-02-08 21:55 <DIR> d-------- c:\users\VASIL\New Folder
2009-02-02 12:11 . 2009-02-02 12:14 <DIR> d-------- c:\users\VASIL\AppData\Roaming\cr3
2009-01-30 13:22 . 2009-01-30 13:22 <DIR> d-------- c:\users\All Users\Blizzard
2009-01-30 13:22 . 2009-01-30 13:22 <DIR> d-------- c:\programdata\Blizzard
2009-01-30 13:13 . 2009-01-30 13:13 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2009-01-27 16:24 . 2006-07-03 10:31 94,208 --a------ c:\windows\amcap.exe
2009-01-27 16:24 . 2005-11-23 13:55 53,248 --a------ c:\windows\System32\csnp325.dll
2009-01-27 16:24 . 2007-07-11 16:09 20,480 --a------ c:\windows\FixCamera.exe
2009-01-25 11:14 . 2009-01-25 11:14 <DIR> d-------- c:\program files\First Strike Gamepad
2009-01-25 11:14 . 2002-12-26 15:57 86,016 --a------ c:\windows\System32\FCVAP.dll
2009-01-25 11:14 . 2002-12-26 15:57 65,536 --a------ c:\windows\System32\EZFRD.dll
2009-01-20 15:12 . 2009-01-20 15:12 <DIR> d-------- c:\program files\AVG
2009-01-14 18:44 . 2009-02-14 03:51 98,397 --a------ c:\users\All Users\nvModes.dat
2009-01-14 18:44 . 2009-02-14 03:51 98,397 --a------ c:\programdata\nvModes.dat
2009-01-14 08:15 . 2008-12-16 04:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-14 02:57 . 2007-09-04 18:56 164,352 --a------ c:\windows\System32\unrar.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-13 22:00 --------- d-----w c:\users\VASIL\AppData\Roaming\skypePM
2009-02-13 22:00 --------- d-----w c:\users\VASIL\AppData\Roaming\Skype
2009-02-13 15:09 --------- d-----w c:\programdata\Kaspersky Lab
2009-02-13 13:22 --------- d-----w c:\users\VASIL\AppData\Roaming\uTorrent
2009-02-13 06:20 --------- d-----w c:\program files\Google
2009-02-12 01:00 --------- d-----w c:\program files\Windows Mail
2009-02-11 18:59 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-11 18:59 --------- d-----w c:\program files\CyberLink
2009-02-10 12:10 --------- d-----w c:\programdata\Skype
2009-02-04 16:19 --------- d-----w c:\users\VASIL\AppData\Roaming\CyberLink
2009-01-17 08:54 --------- d-----w c:\programdata\NVIDIA
2009-01-14 08:40 82,133 ----a-w c:\users\VASIL\AppData\Roaming\nvModes.dat
2009-01-14 00:57 --------- d-----w c:\program files\K-Lite Codec Pack
2009-01-14 00:49 --------- d-----w c:\program files\AviSynth 2.5
2009-01-14 00:47 --------- d-----w c:\program files\Gabest
2009-01-13 12:13 --------- d-----w c:\program files\Xvid
2009-01-11 19:29 --------- d-----w c:\programdata\ESET
2009-01-08 21:22 --------- d-----w c:\programdata\WindowsSearch
2008-12-27 21:15 --------- d-----w c:\program files\AVIConverter
2008-12-27 08:50 --------- d-----w c:\users\VASIL\AppData\Roaming\Teleca
2008-12-27 08:45 --------- d-----w c:\users\VASIL\AppData\Roaming\Sony Ericsson
2008-12-27 08:45 --------- d-----w c:\programdata\Teleca
2008-12-27 08:45 --------- d-----w c:\programdata\Sony Ericsson
2008-12-27 08:45 --------- d-----w c:\program files\Sony Ericsson
2008-12-27 08:45 --------- d-----w c:\program files\Common Files\Teleca Shared
2008-12-27 08:45 --------- d-----w c:\program files\Common Files\Sony Ericsson Shared
2008-12-26 07:27 --------- d-----w c:\users\VASIL\AppData\Roaming\DAEMON Tools
2008-12-22 22:44 --------- d-----w c:\users\VASIL\AppData\Roaming\Thinstall
2008-12-21 12:08 --------- d-----w c:\programdata\Oberon Games
2008-12-19 17:21 --------- d-----w c:\users\VASIL\AppData\Roaming\vlc
2008-12-19 17:20 --------- d-----w c:\program files\VideoLAN
2008-12-18 15:42 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-15 13:56 --------- d-----w c:\programdata\CyberLink
2008-12-01 22:28 174 --sha-w c:\program files\desktop.ini
2008-11-29 15:16 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-11-29 15:16 56 ---ha-w c:\programdata\ezsidmv.dat
2008-11-29 10:40 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-14 482760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-13 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-13 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{C58A6455-4DA2-4FB0-A6EB-E66D1BAD9501}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype
"UDP Query User{353D721D-D109-4186-A7AB-1225DC3A3EC0}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype
"TCP Query User{970C7416-913F-42FA-B33D-F5508DE07F35}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype
"TCP Query User{CAC76BA2-27BF-4A1D-A6AC-3EA13173A433}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{DE2AAB45-9A49-4189-98BC-844EFB3ACBF6}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{5BCCA899-3083-4E9C-9AC5-AAFAF0D373BB}d:\\games\\cs\\hl.exe"= UDP:d:\games\cs\hl.exe:Half-Life Launcher
"UDP Query User{C64F2FD6-0107-4CF1-8120-F6364DE86770}d:\\games\\cs\\hl.exe"= TCP:d:\games\cs\hl.exe:Half-Life Launcher
"TCP Query User{A14BC2C5-C0E4-4DC2-A8C5-26A059387E26}d:\\games\\csinstalated\\hl.exe"= UDP:d:\games\csinstalated\hl.exe:Half-Life Launcher
"UDP Query User{D9638914-B46C-439B-9CB0-539F626AE72A}d:\\games\\csinstalated\\hl.exe"= TCP:d:\games\csinstalated\hl.exe:Half-Life Launcher
"TCP Query User{5C7D11F3-3851-425E-9FA0-65A4D361D191}d:\\games\\csinstalated\\hl.exe"= UDP:d:\games\csinstalated\hl.exe:Half-Life Launcher
"UDP Query User{979A2EFA-3E77-4D85-A95E-0F93BBC71C3A}d:\\games\\csinstalated\\hl.exe"= TCP:d:\games\csinstalated\hl.exe:Half-Life Launcher
"{9893AF56-31B2-43DD-B423-C4A52A17F44F}"= UDP:c:\program files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{52707CAE-8386-450E-AFAC-3D7F27E65E8D}"= TCP:c:\program files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"TCP Query User{CC76C0B8-4EB6-4251-A2C8-890D4E46EAFF}d:\\games\\quake iii arena\\quake3.exe"= UDP:d:\games\quake iii arena\quake3.exe:quake3
"UDP Query User{5B4107CF-4C7C-4712-906C-F32667A220A5}d:\\games\\quake iii arena\\quake3.exe"= TCP:d:\games\quake iii arena\quake3.exe:quake3
"TCP Query User{83D2192A-E9B0-4831-A9E0-CBC136F02406}c:\\users\\vasil\\appdata\\local\\temp\\blizzard launcher temporary - 9080dbe0\\launcher.exe"= UDP:c:\users\vasil\appdata\local\temp\blizzard launcher temporary - 9080dbe0\launcher.exe:launcher.exe
"UDP Query User{7046112C-BEBA-4BF4-9E46-2A3AAE6C5887}c:\\users\\vasil\\appdata\\local\\temp\\blizzard launcher temporary - 9080dbe0\\launcher.exe"= TCP:c:\users\vasil\appdata\local\temp\blizzard launcher temporary - 9080dbe0\launcher.exe:launcher.exe
"TCP Query User{BD735BB4-942F-43F6-B2D5-32B2AEF90BFC}c:\\users\\vasil\\appdata\\local\\temp\\blizzard launcher temporary - ffbd6718\\launcher.exe"= UDP:c:\users\vasil\appdata\local\temp\blizzard launcher temporary - ffbd6718\launcher.exe:launcher.exe
"UDP Query User{BCB150A5-8E30-4B7B-BAE0-4F5DDD571305}c:\\users\\vasil\\appdata\\local\\temp\\blizzard launcher temporary - ffbd6718\\launcher.exe"= TCP:c:\users\vasil\appdata\local\temp\blizzard launcher temporary - ffbd6718\launcher.exe:launcher.exe
"{7C862E97-084B-4A55-9471-BC42296C064F}"= c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{F20A544F-72E5-4602-83ED-4EC2B3CBA67C}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{C944EA12-FD7E-427D-8EF6-3EEDD96BBA5E}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{FD59EEFA-97CD-48DF-8C3B-680C1E253D6F}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [2009-02-13 12552]
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [2009-02-13 23832]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-02-13 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-02-13 107272]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-13 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-13 298264]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [2009-02-13 1339600]
R3 OA004Ufd;Creative Camera OA004 Upper Filter Driver;c:\windows\System32\drivers\OA004Ufd.sys [2008-06-03 144672]
R3 OA004Vid;Creative Camera OA004 Function Driver;c:\windows\System32\drivers\OA004Vid.sys [2008-07-17 269760]
S2 gupdate1c98afb3a1af780;Google Update Service (gupdate1c98afb3a1af780);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 133104]
S3 ADM8511;REPOTEC USB100 To Fast Ethernet Adapter;c:\windows\System32\drivers\ADM8511.SYS [2008-11-29 24427]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [2009-02-13 38496]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\System32\drivers\s125bus.sys [2008-12-27 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;c:\windows\System32\drivers\s125mdfl.sys [2008-12-27 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;c:\windows\System32\drivers\s125mdm.sys [2008-12-27 108680]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s125mgmt.sys [2008-12-27 100488]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;c:\windows\System32\drivers\s125obex.sys [2008-12-27 98696]
--- Other Services/Drivers In Memory ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0374278d-c1f9-11dd-9bb9-001b24ec7aa8}]
\shell\AutoRun\command - qquq.bat
\shell\explore\Command - qquq.bat
\shell\open\Command - qquq.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03742790-c1f9-11dd-9bb9-001b24ec7aa8}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5942c3c3-c154-11dd-8853-001b24ec7aa8}]
\shell\AutoRun\command - F:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7fda1069-c793-11dd-be3c-001b24ec7aa8}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7fda107e-c793-11dd-be3c-001b24ec7aa8}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-09 23:11]
2009-02-14 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 23:13]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Internet Security Service - c:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\dark.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {28876572-FB22-44D8-89EE-D4A3640F1EA0} = 192.168.2.1
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\users\VASIL\AppData\Roaming\Mozilla\Firefox\Profiles\1mnxw8rf.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 09:31:20
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\wlanext.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\System32\drivers\XAudio.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-02-14 9:36:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-14 07:35:55
Pre-Run: 4 281 237 504 bytes free
Post-Run: 4,499,898,368 bytes free
277 --- E O F --- 2009-02-13 15:31:19