PDA

View Full Version : My PC is very slow



Adam[HUN]
2010-08-04, 22:48
My PC is very slow, and I think it is because of some infections. I would be pleased if you could help me.

My D.D.S. log:

DDS (Ver_10-03-17.01) - NTFSx86
Run by Kovács Ádám at 22:43:37.82 on 2010-08-04
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.923 [GMT 2:00]

AV: ESET NOD32 Antivirus System 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Kovács Ádám\Asztal\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.hu/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IeCatch5 Class: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\progra~1\flashget\jccatch.dll
BHO: {4ef92575-934d-4149-9513-156fbb80f1ab} - c:\windows\system32\msgsvc32.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live bejelentkezési segítség: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: gFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\progra~1\flashget\getflash.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [A High Definition Audio tulajdonságlap parancsikonja] HDAudPropShortcut.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\kovcsd~1\startm~1\programs\indtpu~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\flashget\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\flashget\jc_all.htm
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\imon.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225630135937
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://vexcast.com/download/vexcast.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\kovcsd~1\applic~1\mozilla\firefox\profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - component: c:\documents and settings\kovács ádám\application data\mozilla\firefox\profiles\ue9yjztf.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\kovács ádám\application data\mozilla\firefox\profiles\ue9yjztf.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\thrixxx\weblaunch\binaries\npWebLaunch.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("editor.use_css", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-12-3 15424]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2008-12-3 552064]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-18 136176]

=============== Created Last 30 ================

2010-07-25 15:54:23 0 d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54:11 0 d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18:07 0 d-----w- c:\program files\AVConverter
2010-07-23 08:31:00 0 d-----w- c:\documents and settings\kovács ádám\dwhelper
2010-07-16 07:46:40 54156 ---ha-w- c:\windows\QTFont.qfn
2010-07-16 07:46:40 1409 ----a-w- c:\windows\QTFont.for
2010-07-15 18:57:21 0 d-----w- C:\Fraps
2010-07-15 06:09:40 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47:24 0 d-----w- c:\program files\directx
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BB.tmp

==================== Find3M ====================

2010-06-23 12:07:42 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-06-23 12:07:42 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-06-15 02:16:24 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-11 12:16:00 411368 ----a-w- c:\windows\system32\deployJava1.dll

============= FINISH: 22:44:19.26 ===============

[B]My "attach".txt log:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2006-11-24 20:58:22
System Uptime: 2010-08-04 22:08:10 (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5GDC Pro
Processor: Intel(R) Celeron(R) CPU 2.80GHz | Socket 775 | 2810/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 54.172 GiB free.
D: is CDROM ()
E: is CDROM ()
G: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Microsoft UAA busz-illesztőprogram - High Definition Audio
Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Manufacturer: Microsoft
Name: Microsoft UAA busz-illesztőprogram - High Definition Audio
PNP Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Service: HDAudBus

Class GUID: {4D36E980-E325-11CE-BFC1-08002BE10318}
Description: Hajlékonylemezes meghajtó
Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Manufacturer: (Normál hajlékonylemezes meghajtó)
Name: Hajlékonylemezes meghajtó
PNP Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Service: flpydisk

==== System Restore Points ===================

RP491: 2010-08-04 15:54:23 - Configured Ubisoft Game Launcher

==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
Adobe® Photoshop® Album Starter Edition 3.0
AGEIA GAME System Software
Amnézia 1.2
Apple Software Update
ArGeNT Serial Number Pack
Assassin's Creed II
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATMA V 5.05
Audacity 1.2.6
AVConverter 1.0
Bridge Base Online
Bridge Building Game
C-Media High Definition Audio Driver
Camtasia Studio 4
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Spanish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Polish
CCC Help Portuguese
CCC Help Spanish
Counter-Strike: Source
Cs Non Steam
CS16 Full v32.1 Non-Steam
Diablo 2 Calculator
DNA
DriverGuide Toolkit
EA SPORTS online 2008
EAX(tm) Unified (SHELL)
EAX4 Unified Redist
ERUNT 1.1j
Fallout2
FIFA 10
FlashFXP
FlashFXP v3
FlashGet(JetCar)
Fraps (remove only)
Free Audio CD Burner version 1.2
Free YouTube to MP3 Converter version 3.2
Frogger2
Google Earth
Google Föld
Google Update Helper
Grand Theft Auto
Guitar Hero III
Hamachi 1.0.3.0
Heroes of Might and Magic® III Complete
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HoboSoccer v2.0 Demo
Home Kit 08_09
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
hp deskjet 3500
hp deskjet 3500 series
Java Auto Updater
Java(TM) 6 Update 20
Java(TM) 6 Update 7
JVolleyball 2.2
K-Lite Mega Codec Pack 4.2.5
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Language Pack - hun
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Game Studios Common Redistributables Pack 1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional és FrontPage
Microsoft Office XP Web Components
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual J# 2.0 Redistributable Package
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.6.8)
MP3 Player Utilities 4.00
MP3 Player Utilities 4.04
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
Nero 7 Premium
NOD32 antivirus system
NOD32 FiX
NVIDIA PhysX
Nyelvi csomag a Microsoft .NET-keretrendszer 3.5-ös verziójához*– HUN
OpenAL
PC Wizard 2008.1.80
Prince of Persia T2T
Prince of Persia Warrior Within (Demo)
PunkBuster Services
QuickTime
RadLight 4.0 FINAL
Rockstar Games Social Club
RTP 1.32 Add-On for RM2k
RunAlyzer
Security Update for CAPICOM (KB931906)
Segoe UI
Skins
SnagIt Studio
SopCast 3.2.4
Spider-Man(R) - Web of Shadows(TM) 1.1 Patch
Spybot - Search & Destroy
SpywareBlaster 4.1
Steam
Stellarium 0.10.4
System Requirements Lab
TeamSpeak 2 RC2
TeamSpeak 2 Server RC2
TES Construction Set
Time Adjuster STANDARD 3.1
Total Commander (Remove or Repair)
Ubisoft Game Launcher
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Vampire - The Masquerade Bloodlines
Veetle TV 0.9.15
Ventrilo Client
Ventrilo Server
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Internet Explorer 8 biztonsági frissítés - KB969897
Windows Internet Explorer 8 biztonsági frissítés - KB971961
Windows Internet Explorer 8 biztonsági frissítés - KB972260
Windows Internet Explorer 8 biztonsági frissítés - KB978207
Windows Internet Explorer 8 biztonsági frissítés - KB981332
Windows Internet Explorer 8 biztonsági frissítés - KB982381
Windows Internet Explorer 8 frissítés - KB968220
Windows Internet Explorer 8 frissítés - KB976662
Windows Internet Explorer 8 frissítés - KB980182
Windows Live bejelentkezési segéd
Windows Live Communications Platform
Windows Live Essentials
Windows Live feltöltőeszköz
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player Biztonsági frissítés (KB952069)
Windows Media Player Biztonsági frissítés (KB954155)
Windows Media Player Biztonsági frissítés (KB968816)
Windows Media Player Biztonsági frissítés (KB973540)
Windows Media Player Biztonsági frissítés (KB978695)
Windows Media Player Biztonsági frissítés (KB979402)
Windows Presentation Foundation
Windows XP biztonsági frissítés - KB2229593
Windows XP biztonsági frissítés - KB2286198
Windows XP biztonsági frissítés - KB923561
Windows XP biztonsági frissítés - KB938464
Windows XP biztonsági frissítés - KB938464-v2
Windows XP biztonsági frissítés - KB946648
Windows XP biztonsági frissítés - KB950762
Windows XP biztonsági frissítés - KB950974
Windows XP biztonsági frissítés - KB951066
Windows XP biztonsági frissítés - KB951376-v2
Windows XP biztonsági frissítés - KB951698
Windows XP biztonsági frissítés - KB951748
Windows XP biztonsági frissítés - KB952004
Windows XP biztonsági frissítés - KB952954
Windows XP biztonsági frissítés - KB954211
Windows XP biztonsági frissítés - KB954459
Windows XP biztonsági frissítés - KB954600
Windows XP biztonsági frissítés - KB955069
Windows XP biztonsági frissítés - KB956390
Windows XP biztonsági frissítés - KB956391
Windows XP biztonsági frissítés - KB956572
Windows XP biztonsági frissítés - KB956744
Windows XP biztonsági frissítés - KB956802
Windows XP biztonsági frissítés - KB956803
Windows XP biztonsági frissítés - KB956841
Windows XP biztonsági frissítés - KB956844
Windows XP biztonsági frissítés - KB957095
Windows XP biztonsági frissítés - KB957097
Windows XP biztonsági frissítés - KB958215
Windows XP biztonsági frissítés - KB958644
Windows XP biztonsági frissítés - KB958687
Windows XP biztonsági frissítés - KB958690
Windows XP biztonsági frissítés - KB958869
Windows XP biztonsági frissítés - KB959426
Windows XP biztonsági frissítés - KB960225
Windows XP biztonsági frissítés - KB960714
Windows XP biztonsági frissítés - KB960715
Windows XP biztonsági frissítés - KB960803
Windows XP biztonsági frissítés - KB960859
Windows XP biztonsági frissítés - KB961371
Windows XP biztonsági frissítés - KB961373
Windows XP biztonsági frissítés - KB961501
Windows XP biztonsági frissítés - KB968537
Windows XP biztonsági frissítés - KB969059
Windows XP biztonsági frissítés - KB969898
Windows XP biztonsági frissítés - KB969947
Windows XP biztonsági frissítés - KB970238
Windows XP biztonsági frissítés - KB970430
Windows XP biztonsági frissítés - KB971468
Windows XP biztonsági frissítés - KB971486
Windows XP biztonsági frissítés - KB971557
Windows XP biztonsági frissítés - KB971633
Windows XP biztonsági frissítés - KB971657
Windows XP biztonsági frissítés - KB972270
Windows XP biztonsági frissítés - KB973346
Windows XP biztonsági frissítés - KB973354
Windows XP biztonsági frissítés - KB973507
Windows XP biztonsági frissítés - KB973525
Windows XP biztonsági frissítés - KB973869
Windows XP biztonsági frissítés - KB973904
Windows XP biztonsági frissítés - KB974112
Windows XP biztonsági frissítés - KB974318
Windows XP biztonsági frissítés - KB974392
Windows XP biztonsági frissítés - KB974571
Windows XP biztonsági frissítés - KB975025
Windows XP biztonsági frissítés - KB975467
Windows XP biztonsági frissítés - KB975560
Windows XP biztonsági frissítés - KB975561
Windows XP biztonsági frissítés - KB975562
Windows XP biztonsági frissítés - KB975713
Windows XP biztonsági frissítés - KB977165
Windows XP biztonsági frissítés - KB977816
Windows XP biztonsági frissítés - KB977914
Windows XP biztonsági frissítés - KB978037
Windows XP biztonsági frissítés - KB978251
Windows XP biztonsági frissítés - KB978262
Windows XP biztonsági frissítés - KB978338
Windows XP biztonsági frissítés - KB978542
Windows XP biztonsági frissítés - KB978601
Windows XP biztonsági frissítés - KB978706
Windows XP biztonsági frissítés - KB979309
Windows XP biztonsági frissítés - KB979482
Windows XP biztonsági frissítés - KB979559
Windows XP biztonsági frissítés - KB979683
Windows XP biztonsági frissítés - KB980195
Windows XP biztonsági frissítés - KB980218
Windows XP biztonsági frissítés - KB980232
Windows XP Biztonsági frissítés (KB941569)
Windows XP frissítés - KB951072-v2
Windows XP frissítés - KB951978
Windows XP frissítés - KB955759
Windows XP frissítés - KB955839
Windows XP frissítés - KB961503
Windows XP frissítés - KB967715
Windows XP frissítés - KB968389
Windows XP frissítés - KB971737
Windows XP frissítés - KB973687
Windows XP frissítés - KB973815
Windows XP gyorsjavítás - KB952287
Windows XP gyorsjavítás - KB961118
Windows XP gyorsjavítás - KB970653-v3
Windows XP gyorsjavítás - KB976098-v2
Windows XP gyorsjavítás - KB979306
Windows XP gyorsjavítás - KB981793
Windows XP Service Pack 3
WinRAR archiváló
Wise Registry Cleaner 4 Free 4.66
Wolfenstein - Enemy Territory
Xbox 360 Controller for Windows
Xfire (remove only)
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
XnView 1.96.1
YouTube Downloader 2.5.6

==== End Of File ===========================

Blade81
2010-08-11, 06:32
Hi,

If still needing help post a fresh dds.txt log, please.

Adam[HUN]
2010-08-11, 13:49
DDS log:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Kovács Ádám at 13:47:25.50 on 2010-08-11
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.939 [GMT 2:00]

AV: ESET NOD32 Antivirus System 2.70 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kovács Ádám\Asztal\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.hu/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IeCatch5 Class: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\progra~1\flashget\jccatch.dll
BHO: {4ef92575-934d-4149-9513-156fbb80f1ab} - c:\windows\system32\msgsvc32.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live bejelentkezési segítség: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: gFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\progra~1\flashget\getflash.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p
mRun: [A High Definition Audio tulajdonságlap parancsikonja] HDAudPropShortcut.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\kovcsd~1\startm~1\programs\indtpu~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\flashget\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\flashget\jc_all.htm
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\imon.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225630135937
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://vexcast.com/download/vexcast.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\kovcsd~1\applic~1\mozilla\firefox\profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\thrixxx\weblaunch\binaries\npWebLaunch.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("editor.use_css", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-12-3 15424]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2008-12-3 552064]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-18 136176]

=============== Created Last 30 ================

2010-08-08 08:55:06 0 d-----w- c:\program files\NEXON
2010-07-25 15:54:23 0 d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54:11 0 d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18:07 0 d-----w- c:\program files\AVConverter
2010-07-23 08:31:00 0 d-----w- c:\documents and settings\kovács ádám\dwhelper
2010-07-16 07:46:40 54156 ---ha-w- c:\windows\QTFont.qfn
2010-07-16 07:46:40 1409 ----a-w- c:\windows\QTFont.for
2010-07-15 18:57:21 0 d-----w- C:\Fraps
2010-07-15 06:09:40 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47:24 0 d-----w- c:\program files\directx
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BB.tmp

==================== Find3M ====================

2010-06-23 12:07:42 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-06-23 12:07:42 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-06-15 02:16:24 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-11 12:16:00 411368 ----a-w- c:\windows\system32\deployJava1.dll

============= FINISH: 13:48:22.44 ===============

[B]Attach.txt:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2006-11-24 20:58:22
System Uptime: 2010-08-11 13:01:36 (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5GDC Pro
Processor: Intel(R) Celeron(R) CPU 2.80GHz | Socket 775 | 2810/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 60.536 GiB free.
D: is CDROM ()
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Microsoft UAA busz-illesztőprogram - High Definition Audio
Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Manufacturer: Microsoft
Name: Microsoft UAA busz-illesztőprogram - High Definition Audio
PNP Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Service: HDAudBus

Class GUID: {4D36E980-E325-11CE-BFC1-08002BE10318}
Description: Hajlékonylemezes meghajtó
Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Manufacturer: (Normál hajlékonylemezes meghajtó)
Name: Hajlékonylemezes meghajtó
PNP Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Service: flpydisk

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
Adobe® Photoshop® Album Starter Edition 3.0
AGEIA GAME System Software
Amnézia 1.2
Apple Software Update
ArGeNT Serial Number Pack
Assassin's Creed II
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATMA V 5.05
Audacity 1.2.6
AVConverter 1.0
Bridge Base Online
Bridge Building Game
C-Media High Definition Audio Driver
Camtasia Studio 4
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Spanish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Polish
CCC Help Portuguese
CCC Help Spanish
Counter-Strike: Source
Cs Non Steam
CS16 Full v32.1 Non-Steam
Diablo 2 Calculator
DNA
DriverGuide Toolkit
EA SPORTS online 2008
EAX(tm) Unified (SHELL)
EAX4 Unified Redist
ERUNT 1.1j
Fallout2
FIFA 10
FlashFXP
FlashFXP v3
FlashGet(JetCar)
Fraps (remove only)
Free Audio CD Burner version 1.2
Free YouTube to MP3 Converter version 3.2
Frogger2
Google Earth
Google Föld
Google Update Helper
Grand Theft Auto
Guitar Hero III
Hamachi 1.0.3.0
Heroes of Might and Magic® III Complete
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HoboSoccer v2.0 Demo
Home Kit 08_09
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
hp deskjet 3500
hp deskjet 3500 series
Java Auto Updater
Java(TM) 6 Update 20
Java(TM) 6 Update 7
JVolleyball 2.2
K-Lite Mega Codec Pack 4.2.5
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Language Pack - hun
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Game Studios Common Redistributables Pack 1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional és FrontPage
Microsoft Office XP Web Components
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual J# 2.0 Redistributable Package
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.6.8)
MP3 Player Utilities 4.00
MP3 Player Utilities 4.04
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
Nero 7 Premium
NOD32 antivirus system
NOD32 FiX
NVIDIA PhysX
Nyelvi csomag a Microsoft .NET-keretrendszer 3.5-ös verziójához*– HUN
OpenAL
PC Wizard 2008.1.80
Prince of Persia T2T
Prince of Persia Warrior Within (Demo)
PunkBuster Services
QuickTime
RadLight 4.0 FINAL
Rockstar Games Social Club
RTP 1.32 Add-On for RM2k
RunAlyzer
Security Update for CAPICOM (KB931906)
Segoe UI
Skins
SnagIt Studio
SopCast 3.2.4
Spider-Man(R) - Web of Shadows(TM) 1.1 Patch
Spybot - Search & Destroy
SpywareBlaster 4.1
Steam
Stellarium 0.10.4
System Requirements Lab
TeamSpeak 2 RC2
TeamSpeak 2 Server RC2
TES Construction Set
Time Adjuster STANDARD 3.1
Total Commander (Remove or Repair)
Ubisoft Game Launcher
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Vampire - The Masquerade Bloodlines
Veetle TV 0.9.15
Ventrilo Client
Ventrilo Server
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Internet Explorer 8 biztonsági frissítés - KB969897
Windows Internet Explorer 8 biztonsági frissítés - KB971961
Windows Internet Explorer 8 biztonsági frissítés - KB972260
Windows Internet Explorer 8 biztonsági frissítés - KB978207
Windows Internet Explorer 8 biztonsági frissítés - KB981332
Windows Internet Explorer 8 biztonsági frissítés - KB982381
Windows Internet Explorer 8 frissítés - KB968220
Windows Internet Explorer 8 frissítés - KB976662
Windows Internet Explorer 8 frissítés - KB980182
Windows Live bejelentkezési segéd
Windows Live Communications Platform
Windows Live Essentials
Windows Live feltöltőeszköz
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player Biztonsági frissítés (KB952069)
Windows Media Player Biztonsági frissítés (KB954155)
Windows Media Player Biztonsági frissítés (KB968816)
Windows Media Player Biztonsági frissítés (KB973540)
Windows Media Player Biztonsági frissítés (KB978695)
Windows Media Player Biztonsági frissítés (KB979402)
Windows Presentation Foundation
Windows XP biztonsági frissítés - KB2229593
Windows XP biztonsági frissítés - KB2286198
Windows XP biztonsági frissítés - KB923561
Windows XP biztonsági frissítés - KB938464
Windows XP biztonsági frissítés - KB938464-v2
Windows XP biztonsági frissítés - KB946648
Windows XP biztonsági frissítés - KB950762
Windows XP biztonsági frissítés - KB950974
Windows XP biztonsági frissítés - KB951066
Windows XP biztonsági frissítés - KB951376-v2
Windows XP biztonsági frissítés - KB951698
Windows XP biztonsági frissítés - KB951748
Windows XP biztonsági frissítés - KB952004
Windows XP biztonsági frissítés - KB952954
Windows XP biztonsági frissítés - KB954211
Windows XP biztonsági frissítés - KB954459
Windows XP biztonsági frissítés - KB954600
Windows XP biztonsági frissítés - KB955069
Windows XP biztonsági frissítés - KB956390
Windows XP biztonsági frissítés - KB956391
Windows XP biztonsági frissítés - KB956572
Windows XP biztonsági frissítés - KB956744
Windows XP biztonsági frissítés - KB956802
Windows XP biztonsági frissítés - KB956803
Windows XP biztonsági frissítés - KB956841
Windows XP biztonsági frissítés - KB956844
Windows XP biztonsági frissítés - KB957095
Windows XP biztonsági frissítés - KB957097
Windows XP biztonsági frissítés - KB958215
Windows XP biztonsági frissítés - KB958644
Windows XP biztonsági frissítés - KB958687
Windows XP biztonsági frissítés - KB958690
Windows XP biztonsági frissítés - KB958869
Windows XP biztonsági frissítés - KB959426
Windows XP biztonsági frissítés - KB960225
Windows XP biztonsági frissítés - KB960714
Windows XP biztonsági frissítés - KB960715
Windows XP biztonsági frissítés - KB960803
Windows XP biztonsági frissítés - KB960859
Windows XP biztonsági frissítés - KB961371
Windows XP biztonsági frissítés - KB961373
Windows XP biztonsági frissítés - KB961501
Windows XP biztonsági frissítés - KB968537
Windows XP biztonsági frissítés - KB969059
Windows XP biztonsági frissítés - KB969898
Windows XP biztonsági frissítés - KB969947
Windows XP biztonsági frissítés - KB970238
Windows XP biztonsági frissítés - KB970430
Windows XP biztonsági frissítés - KB971468
Windows XP biztonsági frissítés - KB971486
Windows XP biztonsági frissítés - KB971557
Windows XP biztonsági frissítés - KB971633
Windows XP biztonsági frissítés - KB971657
Windows XP biztonsági frissítés - KB972270
Windows XP biztonsági frissítés - KB973346
Windows XP biztonsági frissítés - KB973354
Windows XP biztonsági frissítés - KB973507
Windows XP biztonsági frissítés - KB973525
Windows XP biztonsági frissítés - KB973869
Windows XP biztonsági frissítés - KB973904
Windows XP biztonsági frissítés - KB974112
Windows XP biztonsági frissítés - KB974318
Windows XP biztonsági frissítés - KB974392
Windows XP biztonsági frissítés - KB974571
Windows XP biztonsági frissítés - KB975025
Windows XP biztonsági frissítés - KB975467
Windows XP biztonsági frissítés - KB975560
Windows XP biztonsági frissítés - KB975561
Windows XP biztonsági frissítés - KB975562
Windows XP biztonsági frissítés - KB975713
Windows XP biztonsági frissítés - KB977165
Windows XP biztonsági frissítés - KB977816
Windows XP biztonsági frissítés - KB977914
Windows XP biztonsági frissítés - KB978037
Windows XP biztonsági frissítés - KB978251
Windows XP biztonsági frissítés - KB978262
Windows XP biztonsági frissítés - KB978338
Windows XP biztonsági frissítés - KB978542
Windows XP biztonsági frissítés - KB978601
Windows XP biztonsági frissítés - KB978706
Windows XP biztonsági frissítés - KB979309
Windows XP biztonsági frissítés - KB979482
Windows XP biztonsági frissítés - KB979559
Windows XP biztonsági frissítés - KB979683
Windows XP biztonsági frissítés - KB980195
Windows XP biztonsági frissítés - KB980218
Windows XP biztonsági frissítés - KB980232
Windows XP Biztonsági frissítés (KB941569)
Windows XP frissítés - KB951072-v2
Windows XP frissítés - KB951978
Windows XP frissítés - KB955759
Windows XP frissítés - KB955839
Windows XP frissítés - KB961503
Windows XP frissítés - KB967715
Windows XP frissítés - KB968389
Windows XP frissítés - KB971737
Windows XP frissítés - KB973687
Windows XP frissítés - KB973815
Windows XP gyorsjavítás - KB952287
Windows XP gyorsjavítás - KB961118
Windows XP gyorsjavítás - KB970653-v3
Windows XP gyorsjavítás - KB976098-v2
Windows XP gyorsjavítás - KB979306
Windows XP gyorsjavítás - KB981793
Windows XP Service Pack 3
WinRAR archiváló
Wise Registry Cleaner 4 Free 4.66
Wolfenstein - Enemy Territory
Xbox 360 Controller for Windows
Xfire (remove only)
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
XnView 1.96.1
YouTube Downloader 2.5.6

==== End Of File ===========================

Blade81
2010-08-11, 19:59
Hi,

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

DNA


I'd like you to read this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).


Also, your ESET Nod is not legit one. This is the 2nd time I have to notify about it (previously had to do it in your topic a couple of years ago). If I still see it installed I have to ask you to seek help elsewhere. We don't support cracks and other illegal software here. So, if you want me to continue helping remove the illegal software.


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Adam[HUN]
2010-08-12, 09:18
I'm sorry, you're right. I've uninstalled Nod32.
However, I don't know what this "DNA" thing is. I'm sure I didn't install it, nevermind. At Control Panel > Add/Remove Programs I couldn't find it. So I searched it on :C. I found it in Application Data, without any exe, or any uninstall.exe, so I deleted it. I hope it is enough.

Combofix log:

ComboFix 10-08-11.04 - Kovács Ádám 2010-08-12 9:01.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.1061 [GMT 2:00]
Running from: c:\documents and settings\Kovács Ádám\Asztal\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Install.exe
c:\windows\system32\SHELLLNK.TLB

.
((((((((((((((((((((((((( Files Created from 2010-07-12 to 2010-08-12 )))))))))))))))))))))))))))))))
.

2010-08-11 13:37 . 2010-08-11 13:37 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-08 08:55 . 2010-08-08 08:55 -------- d-----w- c:\program files\NEXON
2010-08-06 15:34 . 2010-08-06 15:34 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Vuze_Remote
2010-08-06 11:41 . 2010-08-06 12:18 -------- d-----w- c:\program files\Ubisoft
2010-08-04 20:42 . 2010-08-04 20:42 -------- d-----w- c:\program files\ERUNT
2010-07-25 15:54 . 2010-07-25 15:54 -------- d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54 . 2010-07-23 14:54 -------- d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18 . 2010-07-23 12:18 -------- d-----w- c:\program files\AVConverter
2010-07-15 18:57 . 2010-07-15 18:58 -------- d-----w- C:\Fraps
2010-07-15 06:09 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47 . 2010-07-14 14:47 -------- d-----w- c:\program files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-12 06:48 . 2001-10-26 12:00 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-08-12 06:48 . 2001-10-26 12:00 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-08-08 06:45 . 2008-11-02 16:09 -------- d-----w- c:\program files\Vuze
2010-08-06 11:41 . 2006-11-25 08:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-04 06:43 . 2010-01-12 12:49 -------- d-----w- c:\program files\Steam
2010-07-22 16:01 . 2008-05-17 11:25 -------- d-----w- c:\program files\YouTube Downloader
2010-07-18 07:06 . 2007-03-15 15:16 -------- d-----w- c:\program files\Google
2010-07-17 10:35 . 2007-03-15 15:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BB.tmp
2010-06-30 12:33 . 2004-08-17 14:47 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:26 . 2004-08-17 14:47 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2004-08-17 14:30 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-03 21:14 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-19 09:51 . 2010-06-19 09:50 -------- d-----w- c:\program files\3DO
2010-06-19 09:50 . 2010-06-19 09:50 -------- d-----w- c:\program files\Common Files\3DO Shared
2010-06-17 14:03 . 2004-08-17 14:46 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 02:16 . 2010-06-15 02:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-14 14:31 . 2006-11-24 19:52 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:43 . 2004-08-17 14:47 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 12:16 . 2010-06-11 12:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-16 15:08 . 2006-11-25 08:23 1224 ----a-w- c:\windows\ImpTableL.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4EF92575-934D-4149-9513-156FBB80F1AB}]
2008-12-09 15:56 14848 ----a-w- c:\windows\system32\msgsvc32.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A High Definition Audio tulajdonságlap parancsikonja"="HDAudPropShortcut.exe" [2004-03-17 61952]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-16 286720]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Kov*cs µd*m\Start Menu\Programs\Indˇt˘pult\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Valve\\Half-Life 2\\hl2.exe"=
"c:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.EXE"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
"c:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Ádám\\Suxx\\Majesty - The Fantasy Kingdom Sim\\Majesty.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA 10\\FIFA10.exe"=
"c:\\Ádám\\Creed 2 Emulator\\server.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Ádám\\Sacred\\sacred.exe"=
"c:\\Ádám\\Sacred\\GameServer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\varen10\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5800:TCP"= 5800:TCP:Java(TM)
"5900:TCP"= 5900:TCP:Java(TM)

R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 136176]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2006-12-11 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2010-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 11:42]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hu/
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\FlashGet\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\FlashGet\jc_all.htm
FF - ProfilePath - c:\documents and settings\Kovács Ádám\Application Data\Mozilla\Firefox\Profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
AddRemove-ArGeNT Serial Number Pack - c:\argentsn\Uninstal.exe
AddRemove-Grand Theft Auto - c:\program files\Rockstar Games\Grand Theft Auto\Uninst.isu
AddRemove-Stellarium_is1 - c:\program files\Stellarium\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-12 09:08
Windows 5.1.2600 Szervizcsomag 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{41CA70AC-A46B-7C83-A128-C8EFE32D8223}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iafndpefdglibjcepp"=hex:6b,61,62,69,64,6b,6b,64,6d,66,66,67,6a,6c,70,6a,69,65,
6e,61,6a,6a,00,00
"hadnndcmhlfeclko"=hex:6b,61,62,69,64,6b,6b,64,6d,66,66,67,6a,6c,70,6a,69,65,
6e,61,6a,6a,00,00

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:78,01,77,5a,01,35,d7,04,24,cf,ef,3d,1d,ee,8e,1a,d2,84,6e,de,dc,b5,9c,
27,05,d2,72,07,ff,62,61,1a,9a,39,61,94,7f,db,49,ee,72,d2,7d,de,6d,87,ce,72,\
"??"=hex:e4,36,2f,e6,8c,2c,c8,f0,34,20,61,ff,b1,e7,8f,2d

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:57,40,e7,56,8e,d5,b3,6a,79,a3,f1,26,69,6c,17,55,5c,96,69,54,5c,
53,5c,f3,00,c4,13,26,63,a7,8b,43,89,27,73,f1,c3,06,16,65,89,8e,0f,fd,09,6b,\
"rkeysecu"=hex:fc,75,ae,4b,09,bb,d3,31,97,95,01,ba,05,6f,3b,ea
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-08-12 09:11:19
ComboFix-quarantined-files.txt 2010-08-12 07:11

Pre-Run: 64,751,243,264 bájt szabad
Post-Run: 66,262,663,168 bájt szabad

- - End Of File - - 87E6154229AC5C59CA6B1B4A5B1DA579

DDS log:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Kovács Ádám at 9:14:06.04 on 2010-08-12
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.999 [GMT 2:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Kovács Ádám\Asztal\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.hu/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IeCatch5 Class: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\progra~1\flashget\jccatch.dll
BHO: {4ef92575-934d-4149-9513-156fbb80f1ab} - c:\windows\system32\msgsvc32.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live bejelentkezési segítség: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: gFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\progra~1\flashget\getflash.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [A High Definition Audio tulajdonságlap parancsikonja] HDAudPropShortcut.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\kovcsd~1\startm~1\programs\indtpu~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\flashget\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\flashget\jc_all.htm
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225630135937
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://vexcast.com/download/vexcast.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\kovcsd~1\applic~1\mozilla\firefox\profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("editor.use_css", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-18 136176]

=============== Created Last 30 ================

2010-08-12 06:58:29 98816 ----a-w- c:\windows\sed.exe
2010-08-12 06:58:29 77312 ----a-w- c:\windows\MBR.exe
2010-08-12 06:58:29 256512 ----a-w- c:\windows\PEV.exe
2010-08-12 06:58:29 161792 ----a-w- c:\windows\SWREG.exe
2010-08-11 13:37:41 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-08 08:55:06 0 d-----w- c:\program files\NEXON
2010-07-25 15:54:23 0 d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54:11 0 d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18:07 0 d-----w- c:\program files\AVConverter
2010-07-23 08:31:00 0 d-----w- c:\documents and settings\kovács ádám\dwhelper
2010-07-16 07:46:40 54156 ---ha-w- c:\windows\QTFont.qfn
2010-07-16 07:46:40 1409 ----a-w- c:\windows\QTFont.for
2010-07-15 18:57:21 0 d-----w- C:\Fraps
2010-07-15 06:09:40 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47:24 0 d-----w- c:\program files\directx
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BB.tmp

==================== Find3M ====================

2010-08-12 06:48:08 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-08-12 06:48:08 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-06-30 12:33:05 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:26:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02:56 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27:11 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03:49 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 02:16:24 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-14 07:43:19 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 12:16:00 411368 ----a-w- c:\windows\system32\deployJava1.dll

============= FINISH: 9:14:26.93 ===============


[B]Attach.txt:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2006-11-24 20:58:22
System Uptime: 2010-08-12 08:57:24 (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5GDC Pro
Processor: Intel(R) Celeron(R) CPU 2.80GHz | Socket 775 | 2810/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 61.74 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Microsoft UAA busz-illesztőprogram - High Definition Audio
Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Manufacturer: Microsoft
Name: Microsoft UAA busz-illesztőprogram - High Definition Audio
PNP Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Service: HDAudBus

Class GUID: {4D36E980-E325-11CE-BFC1-08002BE10318}
Description: Hajlékonylemezes meghajtó
Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Manufacturer: (Normál hajlékonylemezes meghajtó)
Name: Hajlékonylemezes meghajtó
PNP Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Service: flpydisk

==== System Restore Points ===================

RP500: 2010-08-12 08:41:32 - Software Distribution Service 3.0

==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
Adobe® Photoshop® Album Starter Edition 3.0
AGEIA GAME System Software
Amnézia 1.2
Apple Software Update
Assassin's Creed II
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATMA V 5.05
Audacity 1.2.6
AVConverter 1.0
Bridge Base Online
Bridge Building Game
C-Media High Definition Audio Driver
Camtasia Studio 4
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Spanish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Polish
CCC Help Portuguese
CCC Help Spanish
Counter-Strike: Source
Cs Non Steam
CS16 Full v32.1 Non-Steam
Diablo 2 Calculator
DNA
DriverGuide Toolkit
EA SPORTS online 2008
EAX(tm) Unified (SHELL)
EAX4 Unified Redist
ERUNT 1.1j
Fallout2
FIFA 10
FlashFXP
FlashFXP v3
FlashGet(JetCar)
Fraps (remove only)
Free Audio CD Burner version 1.2
Free YouTube to MP3 Converter version 3.2
Frogger2
Google Earth
Google Föld
Google Update Helper
Guitar Hero III
Hamachi 1.0.3.0
Heroes of Might and Magic® III Complete
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HoboSoccer v2.0 Demo
Home Kit 08_09
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
hp deskjet 3500
hp deskjet 3500 series
Java Auto Updater
Java(TM) 6 Update 20
Java(TM) 6 Update 7
JVolleyball 2.2
K-Lite Mega Codec Pack 4.2.5
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Language Pack - hun
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Game Studios Common Redistributables Pack 1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional és FrontPage
Microsoft Office XP Web Components
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual J# 2.0 Redistributable Package
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.6.8)
MP3 Player Utilities 4.00
MP3 Player Utilities 4.04
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
Nero 7 Premium
NVIDIA PhysX
Nyelvi csomag a Microsoft .NET-keretrendszer 3.5-ös verziójához*– HUN
OpenAL
PC Wizard 2008.1.80
Prince of Persia T2T
Prince of Persia Warrior Within (Demo)
PunkBuster Services
QuickTime
RadLight 4.0 FINAL
Rockstar Games Social Club
RTP 1.32 Add-On for RM2k
RunAlyzer
Security Update for CAPICOM (KB931906)
Segoe UI
Skins
SnagIt Studio
SopCast 3.2.4
Spider-Man(R) - Web of Shadows(TM) 1.1 Patch
Spybot - Search & Destroy
SpywareBlaster 4.1
Steam
System Requirements Lab
TeamSpeak 2 RC2
TeamSpeak 2 Server RC2
TES Construction Set
Time Adjuster STANDARD 3.1
Total Commander (Remove or Repair)
Ubisoft Game Launcher
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Vampire - The Masquerade Bloodlines
Veetle TV 0.9.15
Ventrilo Client
Ventrilo Server
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Internet Explorer 8 biztonsági frissítés - KB2183461
Windows Internet Explorer 8 biztonsági frissítés - KB969897
Windows Internet Explorer 8 biztonsági frissítés - KB971961
Windows Internet Explorer 8 biztonsági frissítés - KB972260
Windows Internet Explorer 8 biztonsági frissítés - KB978207
Windows Internet Explorer 8 biztonsági frissítés - KB981332
Windows Internet Explorer 8 biztonsági frissítés - KB982381
Windows Internet Explorer 8 frissítés - KB968220
Windows Internet Explorer 8 frissítés - KB976662
Windows Internet Explorer 8 frissítés - KB980182
Windows Live bejelentkezési segéd
Windows Live Communications Platform
Windows Live Essentials
Windows Live feltöltőeszköz
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player Biztonsági frissítés (KB952069)
Windows Media Player Biztonsági frissítés (KB954155)
Windows Media Player Biztonsági frissítés (KB968816)
Windows Media Player Biztonsági frissítés (KB973540)
Windows Media Player Biztonsági frissítés (KB978695)
Windows Media Player Biztonsági frissítés (KB979402)
Windows Presentation Foundation
Windows XP biztonsági frissítés - KB2079403
Windows XP biztonsági frissítés - KB2115168
Windows XP biztonsági frissítés - KB2160329
Windows XP biztonsági frissítés - KB2229593
Windows XP biztonsági frissítés - KB2286198
Windows XP biztonsági frissítés - KB923561
Windows XP biztonsági frissítés - KB938464
Windows XP biztonsági frissítés - KB938464-v2
Windows XP biztonsági frissítés - KB946648
Windows XP biztonsági frissítés - KB950762
Windows XP biztonsági frissítés - KB950974
Windows XP biztonsági frissítés - KB951066
Windows XP biztonsági frissítés - KB951376-v2
Windows XP biztonsági frissítés - KB951698
Windows XP biztonsági frissítés - KB951748
Windows XP biztonsági frissítés - KB952004
Windows XP biztonsági frissítés - KB952954
Windows XP biztonsági frissítés - KB954211
Windows XP biztonsági frissítés - KB954459
Windows XP biztonsági frissítés - KB954600
Windows XP biztonsági frissítés - KB955069
Windows XP biztonsági frissítés - KB956390
Windows XP biztonsági frissítés - KB956391
Windows XP biztonsági frissítés - KB956572
Windows XP biztonsági frissítés - KB956744
Windows XP biztonsági frissítés - KB956802
Windows XP biztonsági frissítés - KB956803
Windows XP biztonsági frissítés - KB956841
Windows XP biztonsági frissítés - KB956844
Windows XP biztonsági frissítés - KB957095
Windows XP biztonsági frissítés - KB957097
Windows XP biztonsági frissítés - KB958215
Windows XP biztonsági frissítés - KB958644
Windows XP biztonsági frissítés - KB958687
Windows XP biztonsági frissítés - KB958690
Windows XP biztonsági frissítés - KB958869
Windows XP biztonsági frissítés - KB959426
Windows XP biztonsági frissítés - KB960225
Windows XP biztonsági frissítés - KB960714
Windows XP biztonsági frissítés - KB960715
Windows XP biztonsági frissítés - KB960803
Windows XP biztonsági frissítés - KB960859
Windows XP biztonsági frissítés - KB961371
Windows XP biztonsági frissítés - KB961373
Windows XP biztonsági frissítés - KB961501
Windows XP biztonsági frissítés - KB968537
Windows XP biztonsági frissítés - KB969059
Windows XP biztonsági frissítés - KB969898
Windows XP biztonsági frissítés - KB969947
Windows XP biztonsági frissítés - KB970238
Windows XP biztonsági frissítés - KB970430
Windows XP biztonsági frissítés - KB971468
Windows XP biztonsági frissítés - KB971486
Windows XP biztonsági frissítés - KB971557
Windows XP biztonsági frissítés - KB971633
Windows XP biztonsági frissítés - KB971657
Windows XP biztonsági frissítés - KB972270
Windows XP biztonsági frissítés - KB973346
Windows XP biztonsági frissítés - KB973354
Windows XP biztonsági frissítés - KB973507
Windows XP biztonsági frissítés - KB973525
Windows XP biztonsági frissítés - KB973869
Windows XP biztonsági frissítés - KB973904
Windows XP biztonsági frissítés - KB974112
Windows XP biztonsági frissítés - KB974318
Windows XP biztonsági frissítés - KB974392
Windows XP biztonsági frissítés - KB974571
Windows XP biztonsági frissítés - KB975025
Windows XP biztonsági frissítés - KB975467
Windows XP biztonsági frissítés - KB975560
Windows XP biztonsági frissítés - KB975561
Windows XP biztonsági frissítés - KB975562
Windows XP biztonsági frissítés - KB975713
Windows XP biztonsági frissítés - KB977165
Windows XP biztonsági frissítés - KB977816
Windows XP biztonsági frissítés - KB977914
Windows XP biztonsági frissítés - KB978037
Windows XP biztonsági frissítés - KB978251
Windows XP biztonsági frissítés - KB978262
Windows XP biztonsági frissítés - KB978338
Windows XP biztonsági frissítés - KB978542
Windows XP biztonsági frissítés - KB978601
Windows XP biztonsági frissítés - KB978706
Windows XP biztonsági frissítés - KB979309
Windows XP biztonsági frissítés - KB979482
Windows XP biztonsági frissítés - KB979559
Windows XP biztonsági frissítés - KB979683
Windows XP biztonsági frissítés - KB980195
Windows XP biztonsági frissítés - KB980218
Windows XP biztonsági frissítés - KB980232
Windows XP biztonsági frissítés - KB980436
Windows XP biztonsági frissítés - KB981852
Windows XP biztonsági frissítés - KB981997
Windows XP biztonsági frissítés - KB982214
Windows XP biztonsági frissítés - KB982665
Windows XP Biztonsági frissítés (KB941569)
Windows XP frissítés - KB951072-v2
Windows XP frissítés - KB951978
Windows XP frissítés - KB955759
Windows XP frissítés - KB955839
Windows XP frissítés - KB961503
Windows XP frissítés - KB967715
Windows XP frissítés - KB968389
Windows XP frissítés - KB971737
Windows XP frissítés - KB973687
Windows XP frissítés - KB973815
Windows XP gyorsjavítás - KB952287
Windows XP gyorsjavítás - KB961118
Windows XP gyorsjavítás - KB970653-v3
Windows XP gyorsjavítás - KB976098-v2
Windows XP gyorsjavítás - KB979306
Windows XP gyorsjavítás - KB981793
Windows XP Service Pack 3
WinRAR archiváló
Wise Registry Cleaner 4 Free 4.66
Wolfenstein - Enemy Territory
Xbox 360 Controller for Windows
Xfire (remove only)
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
XnView 1.96.1
YouTube Downloader 2.5.6

==== End Of File ===========================

Blade81
2010-08-12, 10:09
Hi,

Upload c:\qoobox\quarantine\c\windows\system32\SHELLLNK.TLB.vir and c:\windows\system32\msgsvc32.dll files to http://www.virustotal.com and post back the results/links to the results.

Adam[HUN]
2010-08-12, 11:06
Okay, here is the result.

SHELLLNK.TLB.vir: http://www.virustotal.com/file-scan/reanalysis.html?id=47960e5838c4a76d0bf10b635e3750cdfd7c03caf109feca8ab4551266d6b93d-1281603687

msgsvc32.dll: http://www.virustotal.com/file-scan/reanalysis.html?id=adde06f11ae36bdc879a08088f1cc8b41aef29972897948d1f89cc8cf3224efa-1281603898

Blade81
2010-08-12, 11:09
Sorry, forgot to say to reanalyse if asked. Post links to fresh results when ready.

Adam[HUN]
2010-08-12, 11:34
Okay, I reanalysed them.

SHELLLNK.TLB.vir: http://www.virustotal.com/file-scan/report.html?id=47960e5838c4a76d0bf10b635e3750cdfd7c03caf109feca8ab4551266d6b93d-1281605360

msgsvc32.dll: http://www.virustotal.com/file-scan/report.html?id=adde06f11ae36bdc879a08088f1cc8b41aef29972897948d1f89cc8cf3224efa-1281605543

Blade81
2010-08-12, 11:46
Hi,

Open notepad and copy/paste the text in the codebox below into it:



@echo off
for %%g in (
c:\qoobox\quarantine\c\windows\system32\SHELLLNK.TLB.vir
) do zip Files_for_submission %%g
del %0


Save this as grab.bat
Choose to Save type as - All Files
Save it on your desktop.
Double click on grab.bat & allow it to run

A file, Files_for_submission.zip will be created on your desktop. Upload it to this website: http://www.bleepingcomputer.com/submit-malware.php?channel=4

Kindly include a link to this topic in the message.


---------



Open notepad and copy/paste the text in the quotebox below into it:



http://forums.spybot.info/showthread.php?p=380572#post380572
Collect::
c:\windows\system32\msgsvc32.dll
Folder::
c:\documents and settings\NetworkService\Local Settings\Application Data\Vuze_Remote
c:\program files\Vuze
Regnull::
[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{41CA70AC-A46B-7C83-A128-C8EFE32D8223}*]



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Uninstall Java(TM) 6 Update 7.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

Adam[HUN]
2010-08-12, 20:24
Here are the requested logs:

Combofix:
ComboFix 10-08-11.05 - Kovács Ádám 2010-08-12 12:08:09.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.1024 [GMT 2:00]
Running from: c:\documents and settings\Kovács Ádám\Asztal\Malware\ComboFix.exe
Command switches used :: c:\documents and settings\Kovács Ádám\Asztal\Malware\CFScript.txt

file zipped: c:\windows\system32\msgsvc32.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Local Settings\Application Data\Vuze_Remote
c:\program files\Vuze
c:\program files\Vuze\plugins\azemp\azemp_2.0.30.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.30.zip
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.zip
c:\program files\Vuze\plugins\azemp\azemp_2.0.34.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.34.zip
c:\program files\Vuze\plugins\azemp\azemp_2.1.02.jar
c:\program files\Vuze\plugins\azemp\azemp_2.1.02.zip
c:\program files\Vuze\plugins\azemp\azemp_2.1.06.jar
c:\program files\Vuze\plugins\azemp\azemp_2.1.06.zip
c:\program files\Vuze\plugins\azemp\azemp_2.2.2.jar
c:\program files\Vuze\plugins\azemp\azemp_2.2.2.zip
c:\program files\Vuze\plugins\azemp\azemp_3.1.6.jar
c:\program files\Vuze\plugins\azemp\azemp_3.1.6.zip
c:\program files\Vuze\plugins\azemp\azmplay.exe.bak
c:\program files\Vuze\plugins\azemp\cp1250-a.raw.bak
c:\program files\Vuze\plugins\azemp\cp1250-b.raw.bak
c:\program files\Vuze\plugins\azemp\font.desc.bak
c:\program files\Vuze\plugins\azemp\libmprCanvas_1.2.jar
c:\program files\Vuze\plugins\azemp\mplayer\config
c:\program files\Vuze\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Vuze\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.30
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.32
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.34
c:\program files\Vuze\plugins\azemp\plugin.properties_2.1.02
c:\program files\Vuze\plugins\azemp\plugin.properties_2.1.06
c:\program files\Vuze\plugins\azemp\plugin.properties_2.2.2
c:\program files\Vuze\plugins\azemp\plugin.properties_3.1.6
c:\program files\Vuze\plugins\azemp\vuzeplayer.exe
c:\program files\Vuze\plugins\azupdater\azupdater_1.8.10.zip
c:\program files\Vuze\plugins\azupdater\azupdaterpatcher_1.8.10.jar
c:\program files\Vuze\plugins\azupdater\Azureus2_4.2.0.8_P4.pax
c:\program files\Vuze\plugins\azupdater\plugin.properties_1.8.10
c:\program files\Vuze\plugins\azupdater\Updater.jar.bak
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.17.jar
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.17.zip
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.21.jar
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.21.zip
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.5.jar
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.5.zip
c:\program files\Vuze\plugins\azupnpav\plugin.properties_0.2.17
c:\program files\Vuze\plugins\azupnpav\plugin.properties_0.2.21
c:\program files\Vuze\plugins\azupnpav\plugin.properties_0.2.5
c:\windows\SW_Win9423X24.DLL
c:\windows\system32\msgsvc32.dll

.
((((((((((((((((((((((((( Files Created from 2010-07-12 to 2010-08-12 )))))))))))))))))))))))))))))))
.

2010-08-12 09:38 . 2010-08-12 09:38 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-08-12 09:14 . 2010-08-12 09:14 -------- d-----w- c:\program files\Softinterface, Inc
2010-08-12 09:03 . 2010-08-12 09:03 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Net
2010-08-11 13:37 . 2010-08-11 13:37 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-08 08:55 . 2010-08-08 08:55 -------- d-----w- c:\program files\NEXON
2010-08-06 11:41 . 2010-08-06 12:18 -------- d-----w- c:\program files\Ubisoft
2010-08-04 20:42 . 2010-08-04 20:42 -------- d-----w- c:\program files\ERUNT
2010-07-25 15:54 . 2010-07-25 15:54 -------- d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54 . 2010-07-23 14:54 -------- d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18 . 2010-07-23 12:18 -------- d-----w- c:\program files\AVConverter
2010-07-15 18:57 . 2010-07-15 18:58 -------- d-----w- C:\Fraps
2010-07-15 06:09 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47 . 2010-07-14 14:47 -------- d-----w- c:\program files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-12 09:38 . 2006-12-11 14:59 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-08-12 06:48 . 2001-10-26 12:00 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-08-12 06:48 . 2001-10-26 12:00 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-08-06 11:41 . 2006-11-25 08:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-04 06:43 . 2010-01-12 12:49 -------- d-----w- c:\program files\Steam
2010-07-22 16:01 . 2008-05-17 11:25 -------- d-----w- c:\program files\YouTube Downloader
2010-07-18 07:06 . 2007-03-15 15:16 -------- d-----w- c:\program files\Google
2010-07-17 10:35 . 2007-03-15 15:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BB.tmp
2010-06-30 12:33 . 2004-08-17 14:47 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:26 . 2004-08-17 14:47 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2004-08-17 14:30 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-03 21:14 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-19 09:51 . 2010-06-19 09:50 -------- d-----w- c:\program files\3DO
2010-06-19 09:50 . 2010-06-19 09:50 -------- d-----w- c:\program files\Common Files\3DO Shared
2010-06-17 14:03 . 2004-08-17 14:46 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 02:16 . 2010-06-15 02:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-14 14:31 . 2006-11-24 19:52 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:43 . 2004-08-17 14:47 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 12:16 . 2010-06-11 12:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-16 15:08 . 2006-11-25 08:23 1224 ----a-w- c:\windows\ImpTableL.bin
.

((((((((((((((((((((((((((((( SnapShot@2010-08-12_07.08.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-12 10:03 . 2010-08-12 10:03 16384 c:\windows\temp\Perflib_Perfdata_5fc.dat
+ 2009-04-23 05:46 . 2003-07-08 13:50 344064 c:\windows\system32\MSVCR70.DLL
- 2009-04-23 05:46 . 2002-01-05 13:37 344064 c:\windows\system32\msvcr70.dll
+ 2001-09-05 19:00 . 2001-08-23 15:00 1700352 c:\windows\system32\GdiPlus.dll
- 2001-09-05 19:00 . 2001-09-05 19:00 1700352 c:\windows\system32\gdiplus.dll
+ 2010-08-12 10:11 . 2010-08-12 10:11 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8061a0f5c1c2ee0549e19224352f67fa\System.Runtime.Serialization.ni.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A High Definition Audio tulajdonságlap parancsikonja"="HDAudPropShortcut.exe" [2004-03-17 61952]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-16 286720]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Kov*cs µd*m\Start Menu\Programs\Indˇt˘pult\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Valve\\Half-Life 2\\hl2.exe"=
"c:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.EXE"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
"c:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Ádám\\Suxx\\Majesty - The Fantasy Kingdom Sim\\Majesty.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA 10\\FIFA10.exe"=
"c:\\Ádám\\Creed 2 Emulator\\server.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Ádám\\Sacred\\sacred.exe"=
"c:\\Ádám\\Sacred\\GameServer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\varen10\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5800:TCP"= 5800:TCP:Java(TM)
"5900:TCP"= 5900:TCP:Java(TM)

R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 136176]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2006-12-11 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2010-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 11:42]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hu/
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\FlashGet\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\FlashGet\jc_all.htm
FF - ProfilePath - c:\documents and settings\Kovács Ádám\Application Data\Mozilla\Firefox\Profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-12 12:14
Windows 5.1.2600 Szervizcsomag 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:78,01,77,5a,01,35,d7,04,24,cf,ef,3d,1d,ee,8e,1a,d2,84,6e,de,dc,b5,9c,
27,05,d2,72,07,ff,62,61,1a,9a,39,61,94,7f,db,49,ee,72,d2,7d,de,6d,87,ce,72,\
"??"=hex:e4,36,2f,e6,8c,2c,c8,f0,34,20,61,ff,b1,e7,8f,2d

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:57,40,e7,56,8e,d5,b3,6a,79,a3,f1,26,69,6c,17,55,5c,96,69,54,5c,
53,5c,f3,00,c4,13,26,63,a7,8b,43,89,27,73,f1,c3,06,16,65,89,8e,0f,fd,09,6b,\
"rkeysecu"=hex:fc,75,ae,4b,09,bb,d3,31,97,95,01,ba,05,6f,3b,ea
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-08-12 12:17:24
ComboFix-quarantined-files.txt 2010-08-12 10:17
ComboFix2.txt 2010-08-12 07:11

Pre-Run: 66,275,962,880 bájt szabad
Post-Run: 66,239,856,640 bájt szabad

- - End Of File - - 89B6A532D42D5432CA06F22B12251013
Upload was successful

Kaspersky log:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, August 12, 2010
Operating system: Microsoft Windows XP Professional Szervizcsomag 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, August 12, 2010 09:04:41
Records in database: 4128472
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 154882
Threats found: 5
Infected objects found: 5
Suspicious objects found: 0
Scan duration: 04:18:54


File name / Threat / Threats count
C:\Program Files\Valve\Half-Life 2\Steam.dll.off Infected: Trojan-PSW.Win32.Staem.ha 1
C:\Program Files\Wolfenstein - Enemy Territory\pb\pbags.dll Infected: Backdoor.Win32.Psychward.dz 1
C:\Util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\HostFileEditor.exe Infected: Trojan-Dropper.Win32.Delf.eiw 1
C:\Util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\ProcessWatch.exe Infected: Trojan-Dropper.Win32.Delf.eix 1
C:\Util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\update-cracked.exe Infected: Trojan-Dropper.Win32.Delf.epx 1

Selected area has been scanned.

Fresh DDS log:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Kovács Ádám at 20:08:43.60 on 2010-08-12
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.801 [GMT 2:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Kovács Ádám\Local Settings\temp\jkos-Kovács Ádám\binaries\ScanningProcess.exe
C:\Documents and Settings\Kovács Ádám\Asztal\Malware\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.hu/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IeCatch5 Class: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\progra~1\flashget\jccatch.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live bejelentkezési segítség: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: gFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\progra~1\flashget\getflash.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [A High Definition Audio tulajdonságlap parancsikonja] HDAudPropShortcut.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\kovcsd~1\startm~1\programs\indtpu~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\flashget\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\flashget\jc_all.htm
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1225630135937
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://vexcast.com/download/vexcast.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\kovcsd~1\applic~1\mozilla\firefox\profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("editor.use_css", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-18 136176]

=============== Created Last 30 ================

2010-08-12 09:14:26 224016 ----a-w- c:\windows\system32\tabctl32.ocx
2010-08-12 09:14:25 0 d-----w- c:\program files\Softinterface, Inc
2010-08-12 09:12:47 0 d-----w- c:\docume~1\kovcsd~1\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-08-12 09:03:03 0 d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Net
2010-08-12 09:02:51 0 d-----w- c:\docume~1\kovcsd~1\applic~1\DAEMON Tools Net
2010-08-12 06:58:29 98816 ----a-w- c:\windows\sed.exe
2010-08-12 06:58:29 77312 ----a-w- c:\windows\MBR.exe
2010-08-12 06:58:29 256512 ----a-w- c:\windows\PEV.exe
2010-08-12 06:58:29 161792 ----a-w- c:\windows\SWREG.exe
2010-08-11 13:37:41 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-08 08:55:06 0 d-----w- c:\program files\NEXON
2010-07-25 15:54:23 0 d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54:11 0 d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18:07 0 d-----w- c:\program files\AVConverter
2010-07-23 08:31:00 0 d-----w- c:\documents and settings\kovács ádám\dwhelper
2010-07-16 07:46:40 54156 ---ha-w- c:\windows\QTFont.qfn
2010-07-16 07:46:40 1409 ----a-w- c:\windows\QTFont.for
2010-07-15 18:57:21 0 d-----w- C:\Fraps
2010-07-15 06:09:40 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47:24 0 d-----w- c:\program files\directx
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47:24 0 ----a-w- c:\windows\DXT61BB.tmp

==================== Find3M ====================

2010-08-12 09:38:53 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-08-12 06:48:08 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-08-12 06:48:08 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-06-30 12:33:05 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:26:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02:56 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27:11 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03:49 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 02:16:24 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-14 07:43:19 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 12:16:00 411368 ----a-w- c:\windows\system32\deployJava1.dll

============= FINISH: 20:09:47.76 ===============


[B]Attach.txt:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2006-11-24 20:58:22
System Uptime: 2010-08-12 14:01:50 (6 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5GDC Pro
Processor: Intel(R) Celeron(R) CPU 2.80GHz | Socket 775 | 2810/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 61.711 GiB free.
D: is CDROM (CDFS)

==== Disabled Device Manager Items =============

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Microsoft UAA busz-illesztőprogram - High Definition Audio
Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Manufacturer: Microsoft
Name: Microsoft UAA busz-illesztőprogram - High Definition Audio
PNP Device ID: PCI\VEN_1002&DEV_AA38&SUBSYS_AA38174B&REV_00\4&178951BB&0&0108
Service: HDAudBus

Class GUID: {4D36E980-E325-11CE-BFC1-08002BE10318}
Description: Hajlékonylemezes meghajtó
Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Manufacturer: (Normál hajlékonylemezes meghajtó)
Name: Hajlékonylemezes meghajtó
PNP Device ID: FDC\GENERIC_FLOPPY_DRIVE\5&559926A&0&0
Service: flpydisk

==== System Restore Points ===================

RP502: 2010-08-12 14:09:43 - Removed Java(TM) 6 Update 7

==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
Adobe® Photoshop® Album Starter Edition 3.0
AGEIA GAME System Software
Amnézia 1.2
Apple Software Update
Assassin's Creed II
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATMA V 5.05
Audacity 1.2.6
AVConverter 1.0
Bridge Base Online
Bridge Building Game
C-Media High Definition Audio Driver
Camtasia Studio 4
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Spanish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Polish
CCC Help Portuguese
CCC Help Spanish
Counter-Strike: Source
Cs Non Steam
CS16 Full v32.1 Non-Steam
Diablo 2 Calculator
DNA
DriverGuide Toolkit
EA SPORTS online 2008
EAX(tm) Unified (SHELL)
EAX4 Unified Redist
ERUNT 1.1j
Fallout2
FIFA 10
FlashFXP
FlashFXP v3
FlashGet(JetCar)
Fraps (remove only)
Free Audio CD Burner version 1.2
Free YouTube to MP3 Converter version 3.2
Frogger2
Google Earth
Google Föld
Google Update Helper
Guitar Hero III
Hamachi 1.0.3.0
Heroes of Might and Magic® III Complete
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HoboSoccer v2.0 Demo
Home Kit 08_09
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
hp deskjet 3500
hp deskjet 3500 series
Java Auto Updater
Java(TM) 6 Update 20
JVolleyball 2.2
K-Lite Mega Codec Pack 4.2.5
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - HUN
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Language Pack - hun
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Game Studios Common Redistributables Pack 1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional és FrontPage
Microsoft Office XP Web Components
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual J# 2.0 Redistributable Package
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.6.8)
MP3 Player Utilities 4.00
MP3 Player Utilities 4.04
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
Nero 7 Premium
NVIDIA PhysX
Nyelvi csomag a Microsoft .NET-keretrendszer 3.5-ös verziójához*– HUN
OpenAL
PC Wizard 2008.1.80
Prince of Persia T2T
Prince of Persia Warrior Within (Demo)
PunkBuster Services
QuickTime
RadLight 4.0 FINAL
Rockstar Games Social Club
RTP 1.32 Add-On for RM2k
RunAlyzer
Security Update for CAPICOM (KB931906)
Segoe UI
Skins
SnagIt Studio
SopCast 3.2.4
Spider-Man(R) - Web of Shadows(TM) 1.1 Patch
Spybot - Search & Destroy
SpywareBlaster 4.1
Steam
System Requirements Lab
TeamSpeak 2 RC2
TeamSpeak 2 Server RC2
TES Construction Set
Time Adjuster STANDARD 3.1
Total Commander (Remove or Repair)
Ubisoft Game Launcher
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Vampire - The Masquerade Bloodlines
Veetle TV 0.9.15
Ventrilo Client
Ventrilo Server
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Internet Explorer 8 biztonsági frissítés - KB2183461
Windows Internet Explorer 8 biztonsági frissítés - KB969897
Windows Internet Explorer 8 biztonsági frissítés - KB971961
Windows Internet Explorer 8 biztonsági frissítés - KB972260
Windows Internet Explorer 8 biztonsági frissítés - KB978207
Windows Internet Explorer 8 biztonsági frissítés - KB981332
Windows Internet Explorer 8 biztonsági frissítés - KB982381
Windows Internet Explorer 8 frissítés - KB968220
Windows Internet Explorer 8 frissítés - KB976662
Windows Internet Explorer 8 frissítés - KB980182
Windows Live bejelentkezési segéd
Windows Live Communications Platform
Windows Live Essentials
Windows Live feltöltőeszköz
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player Biztonsági frissítés (KB952069)
Windows Media Player Biztonsági frissítés (KB954155)
Windows Media Player Biztonsági frissítés (KB968816)
Windows Media Player Biztonsági frissítés (KB973540)
Windows Media Player Biztonsági frissítés (KB978695)
Windows Media Player Biztonsági frissítés (KB979402)
Windows Presentation Foundation
Windows XP biztonsági frissítés - KB2079403
Windows XP biztonsági frissítés - KB2115168
Windows XP biztonsági frissítés - KB2160329
Windows XP biztonsági frissítés - KB2229593
Windows XP biztonsági frissítés - KB2286198
Windows XP biztonsági frissítés - KB923561
Windows XP biztonsági frissítés - KB938464
Windows XP biztonsági frissítés - KB938464-v2
Windows XP biztonsági frissítés - KB946648
Windows XP biztonsági frissítés - KB950762
Windows XP biztonsági frissítés - KB950974
Windows XP biztonsági frissítés - KB951066
Windows XP biztonsági frissítés - KB951376-v2
Windows XP biztonsági frissítés - KB951698
Windows XP biztonsági frissítés - KB951748
Windows XP biztonsági frissítés - KB952004
Windows XP biztonsági frissítés - KB952954
Windows XP biztonsági frissítés - KB954211
Windows XP biztonsági frissítés - KB954459
Windows XP biztonsági frissítés - KB954600
Windows XP biztonsági frissítés - KB955069
Windows XP biztonsági frissítés - KB956390
Windows XP biztonsági frissítés - KB956391
Windows XP biztonsági frissítés - KB956572
Windows XP biztonsági frissítés - KB956744
Windows XP biztonsági frissítés - KB956802
Windows XP biztonsági frissítés - KB956803
Windows XP biztonsági frissítés - KB956841
Windows XP biztonsági frissítés - KB956844
Windows XP biztonsági frissítés - KB957095
Windows XP biztonsági frissítés - KB957097
Windows XP biztonsági frissítés - KB958215
Windows XP biztonsági frissítés - KB958644
Windows XP biztonsági frissítés - KB958687
Windows XP biztonsági frissítés - KB958690
Windows XP biztonsági frissítés - KB958869
Windows XP biztonsági frissítés - KB959426
Windows XP biztonsági frissítés - KB960225
Windows XP biztonsági frissítés - KB960714
Windows XP biztonsági frissítés - KB960715
Windows XP biztonsági frissítés - KB960803
Windows XP biztonsági frissítés - KB960859
Windows XP biztonsági frissítés - KB961371
Windows XP biztonsági frissítés - KB961373
Windows XP biztonsági frissítés - KB961501
Windows XP biztonsági frissítés - KB968537
Windows XP biztonsági frissítés - KB969059
Windows XP biztonsági frissítés - KB969898
Windows XP biztonsági frissítés - KB969947
Windows XP biztonsági frissítés - KB970238
Windows XP biztonsági frissítés - KB970430
Windows XP biztonsági frissítés - KB971468
Windows XP biztonsági frissítés - KB971486
Windows XP biztonsági frissítés - KB971557
Windows XP biztonsági frissítés - KB971633
Windows XP biztonsági frissítés - KB971657
Windows XP biztonsági frissítés - KB972270
Windows XP biztonsági frissítés - KB973346
Windows XP biztonsági frissítés - KB973354
Windows XP biztonsági frissítés - KB973507
Windows XP biztonsági frissítés - KB973525
Windows XP biztonsági frissítés - KB973869
Windows XP biztonsági frissítés - KB973904
Windows XP biztonsági frissítés - KB974112
Windows XP biztonsági frissítés - KB974318
Windows XP biztonsági frissítés - KB974392
Windows XP biztonsági frissítés - KB974571
Windows XP biztonsági frissítés - KB975025
Windows XP biztonsági frissítés - KB975467
Windows XP biztonsági frissítés - KB975560
Windows XP biztonsági frissítés - KB975561
Windows XP biztonsági frissítés - KB975562
Windows XP biztonsági frissítés - KB975713
Windows XP biztonsági frissítés - KB977165
Windows XP biztonsági frissítés - KB977816
Windows XP biztonsági frissítés - KB977914
Windows XP biztonsági frissítés - KB978037
Windows XP biztonsági frissítés - KB978251
Windows XP biztonsági frissítés - KB978262
Windows XP biztonsági frissítés - KB978338
Windows XP biztonsági frissítés - KB978542
Windows XP biztonsági frissítés - KB978601
Windows XP biztonsági frissítés - KB978706
Windows XP biztonsági frissítés - KB979309
Windows XP biztonsági frissítés - KB979482
Windows XP biztonsági frissítés - KB979559
Windows XP biztonsági frissítés - KB979683
Windows XP biztonsági frissítés - KB980195
Windows XP biztonsági frissítés - KB980218
Windows XP biztonsági frissítés - KB980232
Windows XP biztonsági frissítés - KB980436
Windows XP biztonsági frissítés - KB981852
Windows XP biztonsági frissítés - KB981997
Windows XP biztonsági frissítés - KB982214
Windows XP biztonsági frissítés - KB982665
Windows XP Biztonsági frissítés (KB941569)
Windows XP frissítés - KB951072-v2
Windows XP frissítés - KB951978
Windows XP frissítés - KB955759
Windows XP frissítés - KB955839
Windows XP frissítés - KB961503
Windows XP frissítés - KB967715
Windows XP frissítés - KB968389
Windows XP frissítés - KB971737
Windows XP frissítés - KB973687
Windows XP frissítés - KB973815
Windows XP gyorsjavítás - KB952287
Windows XP gyorsjavítás - KB961118
Windows XP gyorsjavítás - KB970653-v3
Windows XP gyorsjavítás - KB976098-v2
Windows XP gyorsjavítás - KB979306
Windows XP gyorsjavítás - KB981793
Windows XP Service Pack 3
WinRAR archiváló
Wise Registry Cleaner 4 Free 4.66
Wolfenstein - Enemy Territory
Xbox 360 Controller for Windows
Xfire (remove only)
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
XnView 1.96.1
YouTube Downloader 2.5.6

==== End Of File ===========================

Blade81
2010-08-12, 22:19
Hi,

Open notepad and copy/paste the text in the quotebox below into it:



DeQuarantine::
c:\qoobox\quarantine\c\windows\system32\SHELLLNK.TLB.vir
Ignore::
c:\windows\system32\SHELLLNK.TLB
File::
C:\Program Files\Valve\Half-Life 2\Steam.dll.off
C:\Program Files\Wolfenstein - Enemy Territory\pb\pbags.dll
Folder::
C:\Util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log. Any symptoms left?

Adam[HUN]
2010-08-13, 09:26
ComboFix log:

2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BB.tmp
2010-06-30 12:33 . 2004-08-17 14:47 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:26 . 2004-08-17 14:47 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2004-08-17 14:30 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-03 21:14 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-19 09:51 . 2010-06-19 09:50 -------- d-----w- c:\program files\3DO
2010-06-19 09:50 . 2010-06-19 09:50 -------- d-----w- c:\program files\Common Files\3DO Shared
2010-06-17 14:03 . 2004-08-17 14:46 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 02:16 . 2010-06-15 02:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-14 14:31 . 2006-11-24 19:52 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:43 . 2004-08-17 14:47 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 12:16 . 2010-06-11 12:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-16 15:08 . 2006-11-25 08:23 1224 ----a-w- c:\windows\ImpTableL.bin
.

((((((((((((((((((((((((((((( SnapShot@2010-08-12_07.08.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-13 07:01 . 2010-08-13 07:01 16384 c:\windows\temp\Perflib_Perfdata_568.dat
+ 2010-08-12 10:26 . 2010-08-12 10:26 23552 c:\windows\assembly\NativeImages_v2.0.50727_32\VjsWfcBrowserStubLib\2f56e62b34cdfedf038ff59d22a2ddc4\VjsWfcBrowserStubLib.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 49664 c:\windows\assembly\NativeImages_v2.0.50727_32\vjsvwaux\01b7c7339d3ad8476bda9f744c600397\vjsvwaux.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\vjslibcw\7d9513899e315289cbeb4b4ed61e2683\vjslibcw.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 32768 c:\windows\assembly\NativeImages_v2.0.50727_32\vjsjbc\e9830a024bf34b0654283145339e395c\vjsjbc.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 31232 c:\windows\assembly\NativeImages_v2.0.50727_32\vjscor\a10f8751cbfc8c2cca8b76d5ab38e258\vjscor.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\46ef15b88ef577de4882c519329fc5d2\System.Windows.Presentation.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\aada360296a42e0413579a19c771ec2d\System.Web.DynamicData.Design.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\2b5ff2c6358c483eb1439b99badb54fd\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\6125ff5a4fcd93d70a246cbff3005d42\System.AddIn.Contract.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\5e5176efbfeb803b7f217525beec6844\Microsoft.Vsa.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e1d4e0b1f112000ab33bbaf88bd9ed99\Microsoft.Build.Framework.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\50b7fc7f36c76313cbb434b10923e4e9\dfsvc.ni.exe
+ 2009-04-23 05:46 . 2003-07-08 13:50 344064 c:\windows\system32\MSVCR70.DLL
- 2009-04-23 05:46 . 2002-01-05 13:37 344064 c:\windows\system32\msvcr70.dll
+ 2010-08-13 07:02 . 2010-08-13 07:02 380928 c:\windows\ERDNT\AutoBackup\2010-08-13\Users\00000002\UsrClass.dat
+ 2010-08-13 07:02 . 2005-10-20 10:02 163328 c:\windows\ERDNT\AutoBackup\2010-08-13\ERDNT.EXE
+ 2010-08-12 10:17 . 2010-08-12 10:17 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\a16b8bcca59515281688ec856c034698\WsatConfig.ni.exe
+ 2010-08-12 10:26 . 2010-08-12 10:26 452608 c:\windows\assembly\NativeImages_v2.0.50727_32\vjswfccw\62868fa34b1569a35ea2d8d07b87e80a\vjswfccw.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 112128 c:\windows\assembly\NativeImages_v2.0.50727_32\VJSharpCodeProvider\6368ecd0a79586afc0d81306fb307541\VJSharpCodeProvider.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ff53d5b5249a2841ee196294429f51cf\System.Xml.Linq.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\5e16c279496a553c988c6199f0cee8aa\System.Web.Routing.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\720b28d81e987b889180b291ea19b821\System.Web.Extensions.Design.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\da36fd678161cd3444ef547c894e3f35\System.Web.Entity.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\49ae7c73fac8827123d5db1714c22599\System.Web.Entity.Design.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ce3aa27d3c4c052845ac5abb1374defa\System.Web.DynamicData.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\95fab896ef2af14876e3e1524379773b\System.Web.Abstractions.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\2a080994f308f347b0497bb8804861cf\System.Net.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\97bd2a5d946aa3a824e4cfe5b6ef95aa\System.Messaging.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\bc1cf48ba7dc00f45d0e949c49ab677a\System.Management.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\904fda53006680a67f917ab638be0305\System.Management.Instrumentation.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\849e98c9f428a12cb581320a23f69dbd\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ad95820d2e29e8d55c0d8a838214c6e5\System.Data.Services.Design.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\617acb0d900bdde947ec79f7b5ccc183\System.Data.Services.Client.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\488c4017d45e861644a34fae557aa80f\System.Data.Entity.Design.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\41345e34f26854fc1878eae3e4d5d4a5\System.Data.DataSetExtensions.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\93a0958d5557e2b380647af0171ad354\System.AddIn.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\a055d54c458b7557d957c714551873c3\sysglobl.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\d0758f84e927e3f0a15a6cde1b96d835\SMSvcHost.ni.exe
+ 2010-08-12 10:17 . 2010-08-12 10:17 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8043a108e3bb2d3dcc84b547b8085e99\SMDiagnostics.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5aeb40ff7128df2881fb03c01d070b20\ServiceModelReg.ni.exe
+ 2010-08-12 10:17 . 2010-08-12 10:17 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5db9c32d9f352162e6da220ca463db0d\MSBuild.ni.exe
+ 2010-08-12 10:17 . 2010-08-12 10:17 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fcf975f74bd134d8e0fa8f37c5bc6a8c\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 102912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Vis#\358785eda3789bf140507e0c0f96ff3a\Microsoft.Build.VisualJSharp.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\585cc7218599e7806521d0e737ba5ffb\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\3057ec53731286e69e389d103c32fa41\Microsoft.Build.Engine.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\914e338ac6e92714f3e32ae5d89bf03b\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\12ae6f3635448471fc9f7d8bfe39c67d\CustomMarshalers.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\daca3c9ad6d867d3fec70d14b4f20cf3\ComSvcConfig.ni.exe
- 2001-09-05 19:00 . 2001-09-05 19:00 1700352 c:\windows\system32\gdiplus.dll
+ 2001-09-05 19:00 . 2001-08-23 15:00 1700352 c:\windows\system32\GdiPlus.dll
+ 2010-08-12 10:26 . 2010-08-12 10:26 3262976 c:\windows\assembly\NativeImages_v2.0.50727_32\vjswfchtml\4008068ebf776ae55e348636faea8a04\vjswfchtml.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:26 7011328 c:\windows\assembly\NativeImages_v2.0.50727_32\vjswfc\5a801547e187d088895bb51f2d248a84\vjswfc.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 2559488 c:\windows\assembly\NativeImages_v2.0.50727_32\VJSSupUILib\e3f1beec36ca51ec28d26c3758623e96\VJSSupUILib.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 7982592 c:\windows\assembly\NativeImages_v2.0.50727_32\vjslib\3fb554faafe300ad7a5d030211b81123\vjslib.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\60b3c9a63b2065a6952d16256545c25d\System.WorkflowServices.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\5cc2a23ce8ac371c7a97b5e542ee27ed\System.Workflow.Runtime.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c0aabf67e7ef98dc10c3e174c136731b\System.Workflow.ComponentModel.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\66682c8a064608ba4ffd0463cf09aef9\System.Workflow.Activities.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\9b455702c9b7b02c5708406f87986751\System.Web.Mobile.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\49c7a1c78ed9502ba97c11e6bd993f63\System.Web.Extensions.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\5eb08849d17b272ed2a393420cb0305b\System.Speech.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\f5790a1b7b41e7b8d05f01b549c80f39\System.ServiceModel.Web.ni.dll
+ 2010-08-12 10:11 . 2010-08-12 10:11 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8061a0f5c1c2ee0549e19224352f67fa\System.Runtime.Serialization.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\23cf0498f2ebe4c8ffa5cc79efca2dc5\System.Data.Services.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6ce886492d9b6a34555be3f328682ec2\System.Data.Entity.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\9732a7c993055f82040642966db07ccf\Microsoft.VisualBasic.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\773d7bf69a9a0c0556aa41f53e75ab05\Microsoft.Transactions.Bridge.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\16ff33f07efdb9da2a18e27585c604be\Microsoft.JScript.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d0fb91b296616a1a844bf265947018ee\Microsoft.Build.Tasks.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\892e993c8df1c75081113131dc429c15\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\d0beebd2c9045158cdcd4bd5987b717b\Microsoft.Build.Engine.ni.dll
+ 2010-08-13 07:02 . 2010-08-13 07:02 19202048 c:\windows\ERDNT\AutoBackup\2010-08-13\Users\00000001\NTUSER.DAT
+ 2010-08-12 10:16 . 2010-08-12 10:16 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\f523a69e7c93ee4f245c996eac4b3a57\System.ServiceModel.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A High Definition Audio tulajdonságlap parancsikonja"="HDAudPropShortcut.exe" [2004-03-17 61952]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-16 286720]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Kov*cs µd*m\Start Menu\Programs\Indˇt˘pult\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Valve\\Half-Life 2\\hl2.exe"=
"c:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.EXE"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
"c:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Ádám\\Suxx\\Majesty - The Fantasy Kingdom Sim\\Majesty.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA 10\\FIFA10.exe"=
"c:\\Ádám\\Creed 2 Emulator\\server.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Ádám\\Sacred\\sacred.exe"=
"c:\\Ádám\\Sacred\\GameServer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\varen10\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5800:TCP"= 5800:TCP:Java(TM)
"5900:TCP"= 5900:TCP:Java(TM)

R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 136176]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2006-12-11 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2010-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 11:42]

2010-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hu/
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\FlashGet\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\FlashGet\jc_all.htm
FF - ProfilePath - c:\documents and settings\Kovács Ádám\Application Data\Mozilla\Firefox\Profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-13 09:21
Windows 5.1.2600 Szervizcsomag 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:78,01,77,5a,01,35,d7,04,24,cf,ef,3d,1d,ee,8e,1a,d2,84,6e,de,dc,b5,9c,
27,05,d2,72,07,ff,62,61,1a,9a,39,61,94,7f,db,49,ee,72,d2,7d,de,6d,87,ce,72,\
"??"=hex:e4,36,2f,e6,8c,2c,c8,f0,34,20,61,ff,b1,e7,8f,2d

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:57,40,e7,56,8e,d5,b3,6a,79,a3,f1,26,69,6c,17,55,5c,96,69,54,5c,
53,5c,f3,00,c4,13,26,63,a7,8b,43,89,27,73,f1,c3,06,16,65,89,8e,0f,fd,09,6b,\
"rkeysecu"=hex:fc,75,ae,4b,09,bb,d3,31,97,95,01,ba,05,6f,3b,ea
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-08-13 09:24:23
ComboFix-quarantined-files.txt 2010-08-13 07:24
ComboFix2.txt 2010-08-12 10:18
ComboFix3.txt 2010-08-12 07:11
C:\DeQuarantine.txt

Pre-Run: 66,164,633,600 bájt szabad
Post-Run: 66,263,289,856 bájt szabad

- - End Of File - - 50AD304D0D48FC145E9FD38EAE75C764


DeQuarantine.txt:


c:\qoobox\quarantine\c\windows\system32\SHELLLNK.TLB.vir -> c:\windows\system32\SHELLLNK.TLB ( 6114 bytes )

Blade81
2010-08-13, 09:41
Hi,

Seems that part of ComboFix log wasn't posted. Post the complete log, please.

Adam[HUN]
2010-08-13, 10:12
oh-oh. That's not good, because I didn't save the Combofix log :sad: What should I do? Do the Combofix stuff again?

Blade81
2010-08-13, 11:04
Hi,

c:\ComboFix.txt file should exist there. It has the report of previous run.

Adam[HUN]
2010-08-13, 12:44
Oh ok, I got it.

Combofix log:

ComboFix 10-08-12.02 - Kovács Ádám 2010-08-13 9:15.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.1535.1116 [GMT 2:00]
Running from: c:\documents and settings\Kovács Ádám\Asztal\Malware\ComboFix.exe
Command switches used :: c:\documents and settings\Kovács Ádám\Asztal\Malware\CFScript.txt

FILE ::
"c:\program files\Valve\Half-Life 2\Steam.dll.off"
"c:\program files\Wolfenstein - Enemy Territory\pb\pbags.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Valve\Half-Life 2\Steam.dll.off
c:\program files\Wolfenstein - Enemy Territory\pb\pbags.dll
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\Ad-Aware2007.exe
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\Ad-Watch2007.exe
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\Help\Ad-Aware2007manual.chm
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\HostFileEditor.exe
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\LSUpdateManager.exe
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\ProcessWatch.exe
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\Skin\Ad-Aware 2007 Pro Default.LGFF
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\Skin\Sedona.LGFF
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\crack\update-cracked.exe
c:\util\spam\Lavasoft Ad-Aware 2007 Professional Edition 7.0.1.3\setup\aaw2007.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-13 to 2010-08-13 )))))))))))))))))))))))))))))))
.

2010-08-12 09:14 . 2010-08-12 09:14 -------- d-----w- c:\program files\Softinterface, Inc
2010-08-12 09:03 . 2010-08-12 09:03 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Net
2010-08-11 13:37 . 2010-08-11 13:37 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-08 08:55 . 2010-08-08 08:55 -------- d-----w- c:\program files\NEXON
2010-08-06 11:41 . 2010-08-06 12:18 -------- d-----w- c:\program files\Ubisoft
2010-08-04 20:42 . 2010-08-04 20:42 -------- d-----w- c:\program files\ERUNT
2010-07-25 15:54 . 2010-07-25 15:54 -------- d-----w- c:\program files\TimeAdjuster
2010-07-23 14:54 . 2010-07-23 14:54 -------- d-----w- c:\program files\MP3 Player Utilities 4.04
2010-07-23 12:18 . 2010-07-23 12:18 -------- d-----w- c:\program files\AVConverter
2010-07-15 18:57 . 2010-07-15 18:58 -------- d-----w- C:\Fraps
2010-07-15 06:09 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-14 14:47 . 2010-07-14 14:47 -------- d-----w- c:\program files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-12 12:09 . 2008-10-28 11:27 -------- d-----w- c:\program files\Common Files\Java
2010-08-12 12:09 . 2007-05-07 04:26 -------- d-----w- c:\program files\Java
2010-08-12 09:38 . 2006-12-11 14:59 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-08-12 06:48 . 2001-10-26 12:00 447236 ----a-w- c:\windows\system32\perfh00E.dat
2010-08-12 06:48 . 2001-10-26 12:00 100144 ----a-w- c:\windows\system32\perfc00E.dat
2010-08-06 11:41 . 2006-11-25 08:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-04 06:43 . 2010-01-12 12:49 -------- d-----w- c:\program files\Steam
2010-07-22 16:01 . 2008-05-17 11:25 -------- d-----w- c:\program files\YouTube Downloader
2010-07-18 07:06 . 2007-03-15 15:16 -------- d-----w- c:\program files\Google
2010-07-17 10:35 . 2007-03-15 15:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61C0.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BF.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BE.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BD.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BC.tmp
2010-07-14 14:47 . 2010-07-14 14:47 0 ----a-w- c:\windows\DXT61BB.tmp
2010-06-30 12:33 . 2004-08-17 14:47 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:26 . 2004-08-17 14:47 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2004-08-17 14:30 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-03 21:14 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-19 09:51 . 2010-06-19 09:50 -------- d-----w- c:\program files\3DO
2010-06-19 09:50 . 2010-06-19 09:50 -------- d-----w- c:\program files\Common Files\3DO Shared
2010-06-17 14:03 . 2004-08-17 14:46 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 02:16 . 2010-06-15 02:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-14 14:31 . 2006-11-24 19:52 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:43 . 2004-08-17 14:47 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 12:16 . 2010-06-11 12:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-16 15:08 . 2006-11-25 08:23 1224 ----a-w- c:\windows\ImpTableL.bin
.

((((((((((((((((((((((((((((( SnapShot@2010-08-12_07.08.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-13 07:01 . 2010-08-13 07:01 16384 c:\windows\temp\Perflib_Perfdata_568.dat
+ 2010-08-12 10:26 . 2010-08-12 10:26 23552 c:\windows\assembly\NativeImages_v2.0.50727_32\VjsWfcBrowserStubLib\2f56e62b34cdfedf038ff59d22a2ddc4\VjsWfcBrowserStubLib.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 49664 c:\windows\assembly\NativeImages_v2.0.50727_32\vjsvwaux\01b7c7339d3ad8476bda9f744c600397\vjsvwaux.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\vjslibcw\7d9513899e315289cbeb4b4ed61e2683\vjslibcw.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 32768 c:\windows\assembly\NativeImages_v2.0.50727_32\vjsjbc\e9830a024bf34b0654283145339e395c\vjsjbc.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 31232 c:\windows\assembly\NativeImages_v2.0.50727_32\vjscor\a10f8751cbfc8c2cca8b76d5ab38e258\vjscor.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\46ef15b88ef577de4882c519329fc5d2\System.Windows.Presentation.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\aada360296a42e0413579a19c771ec2d\System.Web.DynamicData.Design.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\2b5ff2c6358c483eb1439b99badb54fd\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\6125ff5a4fcd93d70a246cbff3005d42\System.AddIn.Contract.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\5e5176efbfeb803b7f217525beec6844\Microsoft.Vsa.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e1d4e0b1f112000ab33bbaf88bd9ed99\Microsoft.Build.Framework.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\50b7fc7f36c76313cbb434b10923e4e9\dfsvc.ni.exe
+ 2009-04-23 05:46 . 2003-07-08 13:50 344064 c:\windows\system32\MSVCR70.DLL
- 2009-04-23 05:46 . 2002-01-05 13:37 344064 c:\windows\system32\msvcr70.dll
+ 2010-08-13 07:02 . 2010-08-13 07:02 380928 c:\windows\ERDNT\AutoBackup\2010-08-13\Users\00000002\UsrClass.dat
+ 2010-08-13 07:02 . 2005-10-20 10:02 163328 c:\windows\ERDNT\AutoBackup\2010-08-13\ERDNT.EXE
+ 2010-08-12 10:17 . 2010-08-12 10:17 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\a16b8bcca59515281688ec856c034698\WsatConfig.ni.exe
+ 2010-08-12 10:26 . 2010-08-12 10:26 452608 c:\windows\assembly\NativeImages_v2.0.50727_32\vjswfccw\62868fa34b1569a35ea2d8d07b87e80a\vjswfccw.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 112128 c:\windows\assembly\NativeImages_v2.0.50727_32\VJSharpCodeProvider\6368ecd0a79586afc0d81306fb307541\VJSharpCodeProvider.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ff53d5b5249a2841ee196294429f51cf\System.Xml.Linq.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\5e16c279496a553c988c6199f0cee8aa\System.Web.Routing.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\720b28d81e987b889180b291ea19b821\System.Web.Extensions.Design.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\da36fd678161cd3444ef547c894e3f35\System.Web.Entity.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\49ae7c73fac8827123d5db1714c22599\System.Web.Entity.Design.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ce3aa27d3c4c052845ac5abb1374defa\System.Web.DynamicData.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\95fab896ef2af14876e3e1524379773b\System.Web.Abstractions.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\2a080994f308f347b0497bb8804861cf\System.Net.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\97bd2a5d946aa3a824e4cfe5b6ef95aa\System.Messaging.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\bc1cf48ba7dc00f45d0e949c49ab677a\System.Management.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\904fda53006680a67f917ab638be0305\System.Management.Instrumentation.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\849e98c9f428a12cb581320a23f69dbd\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ad95820d2e29e8d55c0d8a838214c6e5\System.Data.Services.Design.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\617acb0d900bdde947ec79f7b5ccc183\System.Data.Services.Client.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\488c4017d45e861644a34fae557aa80f\System.Data.Entity.Design.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\41345e34f26854fc1878eae3e4d5d4a5\System.Data.DataSetExtensions.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\93a0958d5557e2b380647af0171ad354\System.AddIn.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\a055d54c458b7557d957c714551873c3\sysglobl.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\d0758f84e927e3f0a15a6cde1b96d835\SMSvcHost.ni.exe
+ 2010-08-12 10:17 . 2010-08-12 10:17 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8043a108e3bb2d3dcc84b547b8085e99\SMDiagnostics.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5aeb40ff7128df2881fb03c01d070b20\ServiceModelReg.ni.exe
+ 2010-08-12 10:17 . 2010-08-12 10:17 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5db9c32d9f352162e6da220ca463db0d\MSBuild.ni.exe
+ 2010-08-12 10:17 . 2010-08-12 10:17 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fcf975f74bd134d8e0fa8f37c5bc6a8c\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 102912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Vis#\358785eda3789bf140507e0c0f96ff3a\Microsoft.Build.VisualJSharp.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\585cc7218599e7806521d0e737ba5ffb\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\3057ec53731286e69e389d103c32fa41\Microsoft.Build.Engine.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\914e338ac6e92714f3e32ae5d89bf03b\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\12ae6f3635448471fc9f7d8bfe39c67d\CustomMarshalers.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\daca3c9ad6d867d3fec70d14b4f20cf3\ComSvcConfig.ni.exe
- 2001-09-05 19:00 . 2001-09-05 19:00 1700352 c:\windows\system32\gdiplus.dll
+ 2001-09-05 19:00 . 2001-08-23 15:00 1700352 c:\windows\system32\GdiPlus.dll
+ 2010-08-12 10:26 . 2010-08-12 10:26 3262976 c:\windows\assembly\NativeImages_v2.0.50727_32\vjswfchtml\4008068ebf776ae55e348636faea8a04\vjswfchtml.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:26 7011328 c:\windows\assembly\NativeImages_v2.0.50727_32\vjswfc\5a801547e187d088895bb51f2d248a84\vjswfc.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 2559488 c:\windows\assembly\NativeImages_v2.0.50727_32\VJSSupUILib\e3f1beec36ca51ec28d26c3758623e96\VJSSupUILib.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 7982592 c:\windows\assembly\NativeImages_v2.0.50727_32\vjslib\3fb554faafe300ad7a5d030211b81123\vjslib.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\60b3c9a63b2065a6952d16256545c25d\System.WorkflowServices.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\5cc2a23ce8ac371c7a97b5e542ee27ed\System.Workflow.Runtime.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c0aabf67e7ef98dc10c3e174c136731b\System.Workflow.ComponentModel.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\66682c8a064608ba4ffd0463cf09aef9\System.Workflow.Activities.ni.dll
+ 2010-08-12 10:25 . 2010-08-12 10:25 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\9b455702c9b7b02c5708406f87986751\System.Web.Mobile.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\49c7a1c78ed9502ba97c11e6bd993f63\System.Web.Extensions.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\5eb08849d17b272ed2a393420cb0305b\System.Speech.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\f5790a1b7b41e7b8d05f01b549c80f39\System.ServiceModel.Web.ni.dll
+ 2010-08-12 10:11 . 2010-08-12 10:11 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8061a0f5c1c2ee0549e19224352f67fa\System.Runtime.Serialization.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\23cf0498f2ebe4c8ffa5cc79efca2dc5\System.Data.Services.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6ce886492d9b6a34555be3f328682ec2\System.Data.Entity.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\9732a7c993055f82040642966db07ccf\Microsoft.VisualBasic.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\773d7bf69a9a0c0556aa41f53e75ab05\Microsoft.Transactions.Bridge.ni.dll
+ 2010-08-12 10:24 . 2010-08-12 10:24 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\16ff33f07efdb9da2a18e27585c604be\Microsoft.JScript.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d0fb91b296616a1a844bf265947018ee\Microsoft.Build.Tasks.ni.dll
+ 2010-08-12 10:23 . 2010-08-12 10:23 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\892e993c8df1c75081113131dc429c15\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-08-12 10:17 . 2010-08-12 10:17 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\d0beebd2c9045158cdcd4bd5987b717b\Microsoft.Build.Engine.ni.dll
+ 2010-08-13 07:02 . 2010-08-13 07:02 19202048 c:\windows\ERDNT\AutoBackup\2010-08-13\Users\00000001\NTUSER.DAT
+ 2010-08-12 10:16 . 2010-08-12 10:16 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\f523a69e7c93ee4f245c996eac4b3a57\System.ServiceModel.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A High Definition Audio tulajdonságlap parancsikonja"="HDAudPropShortcut.exe" [2004-03-17 61952]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-16 286720]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Kov*cs µd*m\Start Menu\Programs\Indˇt˘pult\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Valve\\Half-Life 2\\hl2.exe"=
"c:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.EXE"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
"c:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Ádám\\Suxx\\Majesty - The Fantasy Kingdom Sim\\Majesty.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA 10\\FIFA10.exe"=
"c:\\Ádám\\Creed 2 Emulator\\server.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Ádám\\Sacred\\sacred.exe"=
"c:\\Ádám\\Sacred\\GameServer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\varen10\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5800:TCP"= 5800:TCP:Java(TM)
"5900:TCP"= 5900:TCP:Java(TM)

R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2006-11-25 1275584]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 136176]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2006-12-11 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2010-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 11:42]

2010-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 06:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hu/
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Letöltés a FlashGet-tel - c:\program files\FlashGet\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\program files\FlashGet\jc_all.htm
FF - ProfilePath - c:\documents and settings\Kovács Ádám\Application Data\Mozilla\Firefox\Profiles\ue9yjztf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.hu
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-13 09:21
Windows 5.1.2600 Szervizcsomag 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:78,01,77,5a,01,35,d7,04,24,cf,ef,3d,1d,ee,8e,1a,d2,84,6e,de,dc,b5,9c,
27,05,d2,72,07,ff,62,61,1a,9a,39,61,94,7f,db,49,ee,72,d2,7d,de,6d,87,ce,72,\
"??"=hex:e4,36,2f,e6,8c,2c,c8,f0,34,20,61,ff,b1,e7,8f,2d

[HKEY_USERS\S-1-5-21-746137067-1715567821-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:57,40,e7,56,8e,d5,b3,6a,79,a3,f1,26,69,6c,17,55,5c,96,69,54,5c,
53,5c,f3,00,c4,13,26,63,a7,8b,43,89,27,73,f1,c3,06,16,65,89,8e,0f,fd,09,6b,\
"rkeysecu"=hex:fc,75,ae,4b,09,bb,d3,31,97,95,01,ba,05,6f,3b,ea
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-08-13 09:24:23
ComboFix-quarantined-files.txt 2010-08-13 07:24
ComboFix2.txt 2010-08-12 10:18
ComboFix3.txt 2010-08-12 07:11
C:\DeQuarantine.txt

Pre-Run: 66,164,633,600 bájt szabad
Post-Run: 66,263,289,856 bájt szabad

- - End Of File - - 50AD304D0D48FC145E9FD38EAE75C764


DeQuarantine.txt:


c:\qoobox\quarantine\c\windows\system32\SHELLLNK.TLB.vir -> c:\windows\system32\SHELLLNK.TLB ( 6114 bytes )

Blade81
2010-08-13, 23:08
Looks ok. How's it running now?

Adam[HUN]
2010-08-14, 13:43
It's defenitely more fluent, and better

Blade81
2010-08-14, 15:29
Good. To have better chances keeping the system in better shape I recommend to not get involved with P2P and cracks again.

It's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis



Now lets uninstall ComboFix:

Click START then RUN
Now copy-paste Combofix /uninstall in the runbox and click OK



Please download OTC (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the
Begin cleanup Process?
prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok
Download and run Secunia Personal Software Inspector (PSI) (http://secunia.com/vulnerability_scanning/personal/) and fix its findings.
Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. Good free antivirus programs are:
Antivir (http://free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html)
Avast! (http://www.avast.com/eng/download-avast-home.html)
Good commercial ones are from:
Kaspersky (http://www.kaspersky.com/homeuser) and
ESET (http://www.eset.com/products/index.php)
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free (http://www.tallemu.com/free-firewall-protection-software.html) or Comodo Firewall Pro (http://www.personalfirewall.comodo.com/download_firewall.html#fw3.0) (If you choose Comodo: Uncheck during installation Install Comodo HopSurf.., Make Comodo my default search provider and Make Comodo Search my homepage and install firewall ONLY!). Both providers have support forums that help with configuration related questions.



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

Adam[HUN]
2010-08-15, 08:20
I did what you asked. I also ran spybot, and avira: I fixed it's findings.

My pc is good, but I have some minor problems:

1) I use firefox. My problem is that it can't remember my passwords for any sites (like Spybot, like my e-mail address etc.) so I have to type them every time.

2) Another thing is, when I go to Shut Down my PC, it sometimes restarts. I don't know why, it doesn't do it always, but often. When it happens, I push the shut down button on my PC, and that doest the trick.

Blade81
2010-08-15, 09:42
Hi,

1. This (http://support.mozilla.com/en-US/kb/username+and+password+not+remembered) may help. Also, you might consider getting separate free KeePass password manager (http://keepass.info/).
2. Disable automatic restart on error instructions (http://pcsupport.about.com/od/tipstricks/ht/disautorestart.htm) and there should be blue screen with error message instead of automatic restart in error situation. That message may give some idea what is causing restart happen.

Adam[HUN]
2010-08-15, 11:00
Okay number 1 is solved.

I disabled the restart function, so I got a blue screen. I searched for the error message, and this is it:

STOP Error 0x0000007E: SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
STOP error 0x7E means that a system thread generated an exception that the error handler did not catch. STOP code 0x0000007E may also display "SYSTEM_THREAD_EXCEPTION_NOT_HANDLED" on the same STOP message.

The complete error is this:

STOP: 0x0000007E (0xC0000005, 0xF7878AB9, 0xF78BE90C, 0xF78BE608)

Blade81
2010-08-15, 21:51
Hi,

When did this error occur first time? Do you recall what was done prior it?

Adam[HUN]
2010-08-15, 21:58
No, I don't. It started to happen from I don't know maybe a year, but I didn't care about it, because it didn't bother me. Now it does.

Blade81
2010-08-15, 22:18
Hi,

This is likely related to some program or driver issue. I believe you'll get better assistance on some forum that has area for general issues too. One such forum would be Tech Support Guy (http://www.techguy.org/).

Adam[HUN]
2010-08-15, 22:30
Okay, thanks for everything. You are really helpful. Don't want to make it sticky, but I can't thank it enough. It is the second time you helped me.

I hope you enjoy what you do, and it is not just a "must". And I also hope you know how much everybody is thankful to you and the whole team. :bigthumb:

Blade81
2010-08-15, 22:39
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.