Hi.
Sorry for not responding. I hope it is not a bid deal.
I couldn't find SaveNow, so I couldn't uninstall it.
Old Java and Adobe Versions were deleted, new ones were installed.
ATF cleaner was ran, but after 2-3 hours of computer using, website visiting it can clean files, space again. Is it normal?
Eset Online scanner log: (found 2 threats)
# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3570 (20081030)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=36a84ffe29d09d49be5eec91c01d2334
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-10-30 07:19:49
# local_time=2008-10-30 08:19:49 (+0100, Közép-európai téli id# country="Hungary"
# osver=5.1.2600 NT Szervizcsomag 2
# scanned=372163
# found=2
# scan_time=6403
# nod_component=NOD32MOD_WINNT_ENGLISH_BASE Build:0x11080308 (NOD32 For Windows NT/2000/XP/2003/x64 - Base)
# nod_component=NOD32MOD_WINNT_ENGLISH_INET Build:0x11080308 (NOD32 For Windows NT/2000/XP/2003/x64 - Internet support)
# nod_component=NOD32MOD_WINNT_ENGLISH_STANDARD Build:0x11080308 (NOD32 for Windows NT/2000/XP/2003/x64 - Standard component)
C:\Program Files\Warcraft III\GatewayEditor.exe probably a variant of Win32/Spy.Agent trojan 3599087322470C8EDA86A2983106D77F
C:\Ádám\Programok\tc6Uni_crk.exe probably a variant of Win32/Agent trojan 201DE25454F5AE0FB6E12B77EFFFFD25
It run 1:46:43 long, is it normal?
Combofix ran with CFScript, here is the log:
ComboFix 08-10-27.04 - Kovács Ádám 2008-10-28 12:04:28.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.233 [GMT 1:00]
Running from: C:\Documents and Settings\Kovács Ádám\Asztal\malware\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kovács Ádám\Asztal\malware\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\windows\system32\sznhost.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Kovács Ádám\Application Data\DNA
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\dht.dat
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\dht.dat.old
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\dna.lng
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\resume.dat
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\resume.dat.old
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\rss.dat
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\settings.dat
C:\Documents and Settings\Kovács Ádám\Application Data\DNA\settings.dat.old
C:\Program Files\BitTorrent_DNA
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\BitTorrent_DNA\npbtdna.dll
C:\Program Files\DNA
C:\Program Files\DNA\btdna.exe
C:\Program Files\DNA\DNAcpl.cpl
C:\Program Files\DNA\plugins\npbtdna.dll
C:\Program Files\SaveNow
C:\Program Files\SaveNow\SaveNow.exe
C:\windows\system32\sznhost.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDRMKAUN
-------\Service_cdrmkaun
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.
2008-10-28 07:31 . 2008-10-28 07:31 120,320 --a------ C:\WINDOWS\system32\drivers\SSHDRV65.sys
2008-10-28 07:07 . 2008-10-28 07:13 <DIR> d-------- C:\Program Files\Ascaron Entertainment
2008-10-27 09:27 . 2008-10-27 09:27 <DIR> d-------- C:\rsit
2008-10-26 11:23 . 2008-10-26 11:23 <DIR> d-------- C:\Program Files\Safer Networking
2008-10-26 10:48 . 2008-10-26 10:48 153,152 --a------ C:\WINDOWS\zip32.dll
2008-10-26 10:48 . 2008-10-26 10:48 104,088 --a------ C:\WINDOWS\vnchooks.dll
2008-10-26 10:48 . 2008-10-26 10:48 104,000 --a------ C:\WINDOWS\unzip32.dll
2008-10-26 10:48 . 2008-10-26 10:48 12,288 --a------ C:\WINDOWS\logmessages.dll
2008-10-26 10:48 . 2008-10-26 10:48 730 --a------ C:\WINDOWS\ultravnc.ini
2008-10-26 10:34 . 2008-10-26 10:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-22 12:15 . 2008-10-22 12:15 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-10-22 12:15 . 2008-10-22 12:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-10-21 18:42 . 2008-10-22 14:08 22,328 --a------ C:\Documents and Settings\Kovács Ádám\Application Data\PnkBstrK.sys
2008-10-21 18:30 . 2008-10-22 14:07 319 --a------ C:\WINDOWS\game.ini
2008-10-11 16:00 . 2008-10-11 16:00 8,282 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
2008-10-11 15:38 . 2008-03-05 14:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-10-06 17:15 . 2008-10-06 17:15 <DIR> d-------- C:\Documents and Settings\Kovács Ádám\Application Data\ValuSoft
2008-10-05 17:07 . 2008-10-10 05:29 <DIR> d-------- C:\Program Files\Prison Tycoon 4
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 11:13 32,856,096 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-28 11:12 --------- d-----w C:\Program Files\Steam
2008-10-28 11:11 4,639,826 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-10-28 11:10 385,988 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-27 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-27 08:45 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-10-27 08:45 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-10-26 12:04 --------- d-----w C:\Documents and Settings\Kovács Ádám\Application Data\Azureus
2008-10-26 09:56 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-10-26 06:55 370,176 ----a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2008-10-22 10:51 --------- d-----w C:\Program Files\Activision
2008-10-22 08:49 2,665,472 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2008-10-21 17:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-21 15:57 --------- d-----w C:\Documents and Settings\Kovács Ádám\Application Data\My Battle for Middle-earth(tm) II Files
2008-10-15 14:17 --------- d-----w C:\Documents and Settings\Kovács Ádám\Application Data\Hamachi
2008-10-15 11:58 --------- d-----w C:\Program Files\Common Files\LogiShrd
2008-10-15 04:06 --------- d-----w C:\Program Files\Logitech
2008-10-11 15:00 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-10-11 14:38 --------- d-----w C:\Program Files\EA SPORTS
2008-10-11 14:04 --------- d-----w C:\Program Files\Portal
2008-10-08 10:36 142,848 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-10-08 10:36 1,746,432 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-10-06 13:19 2,869,760 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-10-03 14:59 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-03 14:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-27 11:37 --------- d-----w C:\Program Files\3D Driving-School
2008-09-23 14:31 2,724,352 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-09-20 05:48 --------- d-----w C:\Program Files\Bridge Building Game
2008-09-18 09:52 3,093,504 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-09-18 09:52 1,701,376 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-08-30 11:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-29 14:49 --------- d-----w C:\Documents and Settings\Kovács Ádám\Application Data\InstallShield
2008-08-19 08:48 64,419 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-08-19 08:48 6,120 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-08-19 08:48 219,136 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-08-17 15:52 2,050,560 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-08-17 15:52 1,613,824 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-06-29 15:45 26,720 ----a-w C:\Documents and Settings\Kovács Ádám\Application Data\GDIPFONTCACHEV1.DAT
2007-05-28 11:48 1 ----a-w C:\Documents and Settings\Kovács Ádám\SI.bin
2007-05-28 11:48 1 ----a-w C:\Documents and Settings\Kovács Ádám\SI.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-17 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-10-08 1410296]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15360]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-02-15 917504]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-16 286720]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 37376]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 919016]
"A High Definition Audio tulajdonságlap parancsikonja"="HDAudPropShortcut.exe" [2004-03-17 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15360]
C:\Documents and Settings\Kov cs µd m\Start Menu\Programs\Indˇt˘pult\
FIFA 09 Regisztr ci˘.lnk - C:\Program Files\EA SPORTS\FIFA 09\Support\EAregister.exe [2008-08-13 4369408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"C:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"C:\\Program Files\\Valve\\Half-Life 2\\hl2.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.EXE"=
"C:\\Program Files\\Valve\\hl.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Splinter Cell Chaos Theory\\System\\SPLINTERCELL3.EXE"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Splinter Cell Chaos Theory\\Versus\\System\\SCCT_Versus_DedicatedServer.exe"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Splinter Cell Chaos Theory\\Versus\\System\\SCCT_Versus.ex"=
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
"C:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\varen10\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Steam\\steamapps\\varen10\\half-life 2 deathmatch\\hl2.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\WINDOWS\\system32\\javaw.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
"5800:TCP"= 5800:TCP:Java(TM)
"5900:TCP"= 5900:TCP:Java(TM)
R1 SSHDRV65;SSHDRV65;C:\windows\system32\drivers\SSHDRV65.sys [2008-10-28 120320]
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2006-11-25 162432]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2006-11-25 12032]
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2004-10-21 1275584]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e79f8f9b-06ad-11dc-acd0-0015f2cc1002}]
\Shell\AutoRun\command - F:\autorun.exe
.
Contents of the 'Scheduled Tasks' folder
2008-10-24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-28 12:11:42
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2008-10-28 12:17:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-28 11:17:26
ComboFix2.txt 2008-10-28 07:10:18
ComboFix3.txt 2008-10-27 11:40:17
Pre-Run: 34 345 156 608 bájt szabad
Post-Run: 34,392,309,760 bájt szabad
211
Combofix can't update itself: I hope it is not a big deal.
Finally the fresh HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:46:47, on 2008.10.30.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\windows\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Steam\Steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.hu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [A High Definition Audio tulajdonságlap parancsikonja] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'HELYI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'HÁLÓZATI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: FIFA 09 Regisztráció.lnk = C:\Program Files\EA SPORTS\FIFA 09\Support\EAregister.exe
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7541 bytes
I hope nothing is missing.
Tomorrow morning I'll try Kapersky Online Scanner again, maybe it will work.