offline
- Pridružio: 05 Avg 2008
- Poruke: 33
|
ComboFix 09-01-08.01 - Dragan 2009-01-08 23:28:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1605 [GMT 1:00]
Running from: c:\documents and settings\Dragan\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dragan\My Documents\My Music\My Music.url
c:\documents and settings\Dragan\My Documents\My Pictures\My Pictures.url
c:\documents and settings\Dragan\My Documents\My Videos\My Video.url
c:\windows\system32\drivers\npf.sys
c:\windows\system32\NTVBSvcW.tlb
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\wanpacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.
2009-01-08 19:54 . 2009-01-08 19:54 <DIR> d-------- c:\program files\Lavasoft
2009-01-08 19:54 . 2009-01-08 19:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-06 14:55 . 2009-01-06 14:55 <DIR> d-------- c:\program files\7-Zip
2009-01-06 13:59 . 2009-01-07 12:03 <DIR> d-------- c:\program files\Tomb Raider - Legend
2009-01-06 13:16 . 2009-01-06 17:58 <DIR> d-------- c:\program files\GameShadow
2009-01-06 11:40 . 2009-01-06 11:40 <DIR> d-------- c:\program files\Actual Rar Repair
2009-01-06 11:27 . 2009-01-06 11:27 <DIR> d-------- c:\program files\ExtractNow
2009-01-04 10:15 . 2009-01-04 10:15 <DIR> d-------- c:\documents and settings\Dragan\Application Data\Lost Marble
2009-01-04 10:14 . 2009-01-04 10:14 <DIR> d-------- c:\program files\Smith Micro
2009-01-04 04:02 . 2009-01-04 04:02 <DIR> d-------- c:\program files\XoftSpySE
2009-01-02 15:19 . 2009-01-02 15:34 <DIR> d-------- c:\documents and settings\Dragan\Application Data\Hide IP NG
2009-01-01 21:42 . 2009-01-01 21:42 <DIR> d-------- c:\documents and settings\Dragan\Application Data\ForgottenRiddles2
2009-01-01 21:40 . 2009-01-01 21:40 <DIR> d-------- c:\program files\Forgotten Riddles - The Moonlight Sonatas
2009-01-01 21:40 . 2009-01-02 18:07 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-01 21:25 . 2009-01-01 21:25 <DIR> d-------- c:\program files\bfgclient
2009-01-01 21:24 . 2009-01-01 21:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-01-01 20:49 . 2009-01-01 20:49 <DIR> d-------- c:\program files\RegCure
2009-01-01 20:45 . 2009-01-01 20:45 <DIR> d-------- c:\program files\Game_Maker7
2009-01-01 20:45 . 2009-01-01 20:45 0 --ah----- c:\windows\SwSys2.bmp
2009-01-01 20:45 . 2009-01-01 20:45 0 --ah----- c:\windows\SwSys1.bmp
2009-01-01 20:32 . 2009-01-01 20:32 <DIR> d-------- c:\program files\WME DevKit
2009-01-01 12:20 . 2009-01-01 12:20 <DIR> d-------- c:\program files\iTunes
2009-01-01 12:20 . 2009-01-01 12:20 <DIR> d-------- c:\program files\iPod
2009-01-01 12:20 . 2009-01-01 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-01 12:20 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2009-01-01 12:20 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2009-01-01 12:17 . 2009-01-01 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-01 12:15 . 2009-01-01 12:20 <DIR> d-------- c:\program files\Common Files\Apple
2009-01-01 12:15 . 2009-01-01 12:16 <DIR> d-------- c:\program files\Apple Software Update
2009-01-01 12:15 . 2009-01-01 12:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-12-29 12:46 . 2008-12-29 12:46 69,632 --a------ c:\windows\promo_freesoft.dll
2008-12-19 15:01 . 2008-12-30 19:02 286 --a------ c:\windows\Christmas Adventure 2.ini
2008-12-19 15:00 . 2008-11-26 10:27 4,662,859 --a------ c:\windows\Christmas Adventure 2.scr
2008-12-19 15:00 . 2008-12-19 15:00 682,266 --a------ c:\windows\unins000.exe
2008-12-19 15:00 . 2008-12-19 15:00 3,323 --a------ c:\windows\unins000.dat
2008-12-19 15:00 . 2004-11-02 19:35 2,238 --a------ c:\windows\Christmas Adventure 2.ico
2008-12-15 16:05 . 2008-12-15 16:05 7,680 --ahs---- c:\windows\Thumbs.db
2008-12-15 16:05 . 2008-12-15 16:05 5,120 --ahs---- c:\windows\system32\Thumbs.db
2008-12-14 17:50 . 2003-11-04 15:11 159,744 --a------ c:\windows\system32\lfpng13n.dll
2008-12-13 21:54 . 2008-12-13 21:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Bluetooth
2008-12-13 21:52 . 2008-12-13 21:52 <DIR> d-------- c:\program files\IVT Corporation
2008-12-13 21:52 . 2008-12-13 21:53 32 --a------ c:\windows\0
2008-12-13 21:52 . 2008-12-13 21:52 0 --a------ c:\windows\system32\0
2008-12-13 21:43 . 2004-08-03 23:10 38,016 --a------ c:\windows\system32\drivers\bthmodem.sys
2008-12-13 21:43 . 2004-08-03 23:10 38,016 --a--c--- c:\windows\system32\dllcache\bthmodem.sys
2008-12-13 21:37 . 2004-08-03 22:58 100,992 --a------ c:\windows\system32\drivers\bthpan.sys
2008-12-13 21:37 . 2004-08-03 22:58 100,992 --a--c--- c:\windows\system32\dllcache\bthpan.sys
2008-12-13 21:36 . 2004-08-04 00:56 152,576 --a------ c:\windows\system32\irftp.exe
2008-12-13 21:36 . 2004-08-04 00:56 152,576 --a--c--- c:\windows\system32\dllcache\irftp.exe
2008-12-13 21:36 . 2004-08-03 23:10 59,648 --a------ c:\windows\system32\drivers\rfcomm.sys
2008-12-13 21:36 . 2004-08-03 23:10 59,648 --a--c--- c:\windows\system32\dllcache\rfcomm.sys
2008-12-13 21:36 . 2004-08-04 00:56 27,136 --a------ c:\windows\system32\irmon.dll
2008-12-13 21:36 . 2004-08-04 00:56 27,136 --a--c--- c:\windows\system32\dllcache\irmon.dll
2008-12-13 21:36 . 2004-08-03 23:10 18,944 --a------ c:\windows\system32\drivers\BTHUSB.SYS
2008-12-13 21:36 . 2004-08-03 23:10 18,944 --a--c--- c:\windows\system32\dllcache\bthusb.sys
2008-12-13 21:36 . 2004-08-03 23:10 17,024 --a------ c:\windows\system32\drivers\BthEnum.sys
2008-12-13 21:36 . 2004-08-03 23:10 17,024 --a--c--- c:\windows\system32\dllcache\bthenum.sys
2008-12-13 21:36 . 2004-08-04 00:56 8,192 --a------ c:\windows\system32\wshirda.dll
2008-12-13 21:36 . 2004-08-04 00:56 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2008-12-09 18:52 . 2008-12-09 18:53 <DIR> d-------- c:\windows\system32\Adobe
2008-12-08 21:35 . 2008-12-08 21:35 <DIR> d-------- c:\program files\Ubisoft
2008-12-08 18:28 . 2004-01-05 23:42 118,784 --a------ c:\windows\system32\SkyDll.dll
2008-12-08 18:28 . 2004-01-05 23:42 118,784 --a------ c:\windows\system32\Sky2PCUI.dll
2008-12-08 18:28 . 2004-01-05 19:50 102,400 --a------ c:\windows\system32\libbz2.dll
2008-12-08 17:48 . 2008-12-08 17:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-08 17:00 . 2008-12-08 17:00 <DIR> d-------- c:\documents and settings\Dragan\Application Data\TuneUp Software
2008-12-08 17:00 . 2008-12-08 17:00 355,584 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-12-08 17:00 . 2008-05-29 09:28 28,416 --a------ c:\windows\system32\uxtuneup.dll
2008-12-08 16:59 . 2008-12-08 17:00 <DIR> d-------- c:\program files\TuneUp Utilities 2008
2008-12-08 16:59 . 2008-12-08 16:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-12-08 15:54 . 2008-12-08 16:28 592 --a------ c:\windows\chgkey.vbs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 22:31 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-01-08 22:29 925,728 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-08 22:29 7,770,144 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-08 22:29 63,880 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-08 22:29 6,340 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-08 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2009-01-08 18:53 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-08 00:51 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-01 20:09 --------- d-----w c:\program files\Bonjour
2009-01-01 12:01 --------- d-----w c:\program files\Common Files\Adobe
2009-01-01 11:21 --------- d-----w c:\documents and settings\Dragan\Application Data\Apple Computer
2009-01-01 11:17 --------- d-----w c:\program files\QuickTime
2008-12-24 20:31 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-23 15:21 --------- d-----w c:\documents and settings\Dragan\Application Data\gtk-2.0
2008-12-19 20:19 --------- d-----w c:\program files\Google
2008-12-10 16:49 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-08 17:28 --------- d-----w c:\program files\TechniSat DVB
2008-12-08 15:30 --------- d-----w c:\documents and settings\Dragan\Application Data\zweitgeist
2008-12-08 11:05 --------- d-----w c:\program files\Di recnik
2008-12-07 13:58 --------- d-----w c:\program files\GameSpy Arcade
2008-12-07 13:55 --------- d-----w c:\program files\Firefly Studios
2008-12-06 15:07 --------- d-----w c:\program files\CCleaner
2008-12-04 21:43 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-12-04 15:45 --------- d-----w c:\program files\WinPcap
2008-12-04 15:30 74,240 ----a-w c:\windows\ST6UNST.EXE
2008-12-04 15:30 253,952 ------w c:\windows\Setup1.exe
2008-11-30 15:19 --------- d-----w c:\program files\D-Tools
2008-11-29 20:49 --------- d-----w c:\program files\Flash Wallpaper Maker
2008-11-29 19:30 --------- d-----w c:\program files\weblin
2008-11-29 06:50 --------- d-----w c:\program files\Launchy
2008-11-29 06:50 --------- d-----w c:\documents and settings\Dragan\Application Data\Launchy
2008-11-21 11:24 --------- d-----w c:\documents and settings\Dragan\Application Data\Canon
2008-11-21 11:14 98,304 ----a-w c:\windows\DUMPc3bd.tmp
2008-11-21 06:48 98,304 ----a-w c:\windows\DUMPc0fe.tmp
2008-11-21 06:45 98,304 ----a-w c:\windows\DUMPbfc5.tmp
2008-11-21 06:37 98,304 ----a-w c:\windows\DUMPc505.tmp
2008-11-20 16:46 --------- d-----w c:\program files\ElcomSoft
2008-11-18 16:16 --------- d-----w c:\documents and settings\All Users\Application Data\CanonIJPLM
2008-11-18 08:48 --------- d-----w c:\documents and settings\Dragan\Application Data\Media Player Classic
2008-11-08 21:18 --------- d-----w c:\program files\Gimp-2.0
2008-10-28 12:50 22,328 ----a-w c:\documents and settings\Dragan\Application Data\PnkBstrK.sys
2008-10-14 13:16 155,995 ----a-w c:\windows\java\Packages\8CWQ7DBR.ZIP
2008-10-14 12:54 315,392 ----a-w c:\windows\HideWin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-15 39408]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-05-17 661369]
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2008-12-08 430080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Launchy.lnk
backup=c:\windows\pss\Launchy.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
--a------ 2007-04-03 17:50 1603152 c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
--a------ 2007-05-14 17:01 644696 c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\filehippo.com]
--a------ 2008-10-22 13:51 147968 c:\program files\filehippo.com\UpdateChecker.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GAINWARD]
--a------ 2008-07-03 15:50 2177576 c:\program files\EXPERTool\TBPANEL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-09-17 23:55 13574144 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-09-17 23:55 86016 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
--a------ 2007-02-04 11:02 79400 c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
--a------ 2006-10-25 08:03 210472 c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-11-15 11:39 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMonitorVMUVC]
--a------ 2007-04-13 17:08 114688 c:\program files\Vimicro\Vimicro UVC USB2.0 PC Camera\x86\VMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zweitgeist Assistant]
--a------ 2008-11-29 20:30 192512 c:\program files\weblin\weblinAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-09-17 23:55 1657376 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2008-02-13 07:31 16857600 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\TechniSat DVB\\bin\\Server4PC.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"e:\\STARI KOMPJUTER\\Disk C\\Program Filles\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 SKYNET;B2C2 Broadband Receiver PCI Adapter;c:\windows\system32\drivers\SkyNET.sys [2008-10-14 446884]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [2008-10-15 248448]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [2008-10-15 476032]
R4 PNRCPP;PNRCPP;c:\program files\Phone Recorder Plus\PNRCPP.exe [2005-08-08 397312]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S4 gupdate1c94710f0192b80;Google Update Service (gupdate1c94710f0192b80);c:\program files\Google\Update\GoogleUpdate.exe [2008-11-15 133104]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-01-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:09]
2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-01-08 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-11-15 12:09]
2009-01-08 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 19:55]
2009-01-08 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 19:55]
2009-01-08 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-23 18:08]
2009-01-04 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-23 18:08]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-BDAgent - c:\program files\Softwin\BitDefender10\bdagent.exe
MSConfigStartUp-BDMCon - c:\program files\Softwin\BitDefender10\bdmcon.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.rs/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
uInternet Settings,ProxyServer = socks=
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\system32\NetSeTAPI.dll - c:\windows\system32\PexCryptoAPI.dll
O16 -: {62CF4D10-EBA7-45DA-ACA0-4B002E8B3A85}
hxxps://ebank.agrobanka.rs/Retail/Pages/Download/CABS/DigitrustApiNetSetPlugIn.cab
c:\windows\Downloaded Program Files\DigitrustApiNetSetPlugin.inf
FF - ProfilePath - c:\documents and settings\Dragan\Application Data\Mozilla\Firefox\Profiles\j2zpbja0.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.133.33\npGoogleOneClick7.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\jaman.js - pref("network.protocol-handler.warn-external.jaman", false);
.
.
------- File Associations -------
.
inifile\shell\mv2player\command="c:\program files\Mv2Player\Mv2PlayerPlus.exe" "%1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-08 23:31:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\rundll32.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-08 23:32:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-08 22:32:50
Pre-Run: 30,274,301,952 bytes free
Post-Run: 30,219,710,464 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
334 --- E O F --- 2008-12-07 20:58:13
|