Application popup

1

Application popup

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Logfile of HijackThis v1.99.1
Scan saved at 6:00:37 PM, on 8/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lock My PC 4\LmpcServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\Program Files\Advanced Registry Doctor\RegManServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Nettalk6\Nettalk.exe
C:\Documents and Settings\Dejan\Desktop\Opera_9.23_Classic_Setup.exe
C:\Program Files\Opera 9\Opera.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Dejan\Desktop\New Folder (2)\bla.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {47B83D78-F986-4E96-9769-2C55EF14DA0B} - C:\WINDOWS\system32\__c004A35E.dat
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0DCE0F0-10E9-4651-AF14-5D9026F052B0}: NameServer = 77.105.0.18 77.105.0.19
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0021F10.dat
O20 - Winlogon Notify: fsp_lmwl - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lock My PC Service (LmpcService) - Unknown owner - C:\Program Files\Lock My PC 4\LmpcServ.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Advanced Registry Doctor\RegManServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe



E ovako stoje stvari
Imam problema sa firefoxom ( ver 2.0.0.6 ), nakon par minuta koriscenja dobijem poruku:
Application popup: firefox.exe - Application Error : The instruction at "0x100021d5" referenced memory at "0x00000011". The memory could not be "written".

probao sam clean install 3 razlicite verzije ali nije pomoglo... molim za pomoc Very Happy

( ceo sistem je skeniran sa KAV 6 i ad aware 07, sve je cisto )

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Iskoristi sledecu formu za upload:
http://www.mycity.rs/ambulanta-upload.php

Tu uploaduj sledeci fajl:
C:\WINDOWS\system32\__c004A35E.dat

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Vas fajl je uspesno uploadovan. Smile

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Fajl je maliciozan. Necemo ga brisati dok ne saznamo da li ima jos necega.

Preuzmi program Deckard's System Scanner.
Preporučuje se čuvanje programa direktno na Desktop radi lakšeg i bržeg pokretanja.

Program se startuje prosto - dvoklikom na ikonu. Skeniranje i provera sistema se odvija kroz par koraka i traje maksimalno par minuta.

Rezultat je log main.txt koji Deckard's System Scanner kreira i otvara automatski po završtetku skeniranja. Kompletan sadržaj tog loga je potrebno kopirati i postovati na forum u sledećem postu radi analize.

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

ne mogu da zavrsim skeniranje...
negde pred kraj neprekidno dobijam gresku:
Application popup: sed.exe - Application Error : The instruction at "0x00991d11" referenced memory at "0x33508965". The memory could not be "read".

a na pocetku je bilo
Application popup: md5deep.exe - Application Error : The instruction at "0x00d81d11" referenced memory at "0x33508965". The memory could not be "read".

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Jesi li siguran da ti je RAM ispravan i da ti je napajajne OK?

Ajde alterativno da probamo sledece:

Preuzmi fajl gmer.zip sa ovog linka i sačuvaj na Desktop-u.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskopiraj nam ovde sadrzaj ta dva fajla koja smo malopre snimili

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Evo loga konacno
Deckard's System Scanner v20070826.66
Run by Dejan on 2007-08-31 19:16:27
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2007-08-31 17:17:13 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 504 MiB (512 MiB recommended).


-- HijackThis (run as Dejan.exe) -----------------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------

Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-08-31 19:20:57
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.5730.11)

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lock My PC 4\LmpcServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\Program Files\Advanced Registry Doctor\RegManServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Nettalk6\Nettalk.exe
C:\Documents and Settings\Dejan\Desktop\Opera_9.23_Classic_Setup.exe
C:\Program Files\Opera 9\Opera.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Dejan\Desktop\New Folder (2)\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {47B83D78-F986-4E96-9769-2C55EF14DA0B} - C:\WINDOWS\system32\__c004A35E.dat
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKEY_LOCAL_MACHINE\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
O4 - HKEY_LOCAL_MACHINE\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKEY_LOCAL_MACHINE\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKEY_LOCAL_MACHINE\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKEY_LOCAL_MACHINE\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKEY_LOCAL_MACHINE\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKEY_LOCAL_MACHINE\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\Program Files\Flash Saver\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\Program Files\Flash Saver\save.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (file missing)
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {44627E97-789B-40d4-B5C2-58BD171129A1} - (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{F0DCE0F0-10E9-4651-AF14-5D9026F052B0}: NameServer = 77.105.0.18 77.105.0.19
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0021F10.dat
O20 - Winlogon Notify: fsp_lmwl - C:\WINDOWS\system32\
O23 - Service: Adobe LM Service - Adobe Systems - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /service
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Advanced Registry Doctor\RegManServ.exe
O23 - Service: ServiceLayer - Nokia. - "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"
O23 - Service: Visual Studio Analyzer RPC bridge - Unknown owner - C:\Program Files\Microsoft Visual Studio .NET\Common7\Tools\Analyzer\varpc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe %SystemRoot%\System32\bcmwltry.exe



-- File Associations -----------------------------------------------------------

.js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2
.js - JSFile - shell\open\command - NOTEPAD.EXE %1
.vbs - VBSFile - shell\open\command - NOTEPAD.EXE %1


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R1 VFILT (Outpost Firewall Kernel Driver) - c:\program files\agnitum\outpost firewall\kernel\filtnt.sys <Not Verified; Agnitum Ltd.; Virtual Firewall>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)>
R3 ADBLOCK.DLL (Outpost Firewall PlugIn (ADBLOCK.DLL)) - c:\program files\agnitum\outpost firewall\kernel\adblock.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 ARP.DLL (Outpost Firewall PlugIn (ARP.DLL)) - c:\program files\agnitum\outpost firewall\kernel\arp.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 CnxEtP (Conexant AccessRunner USB ADSL WAN Adapter Filter Driver) - c:\windows\system32\drivers\cnxetp.sys <Not Verified; Conexant; Conexant USB ADSL Modem>
R3 CnxEtU (Conexant AccessRunner USB ADSL Interface Device Driver) - c:\windows\system32\drivers\cnxetu.sys <Not Verified; Conexant; Conexant USB ADSL Modem>
R3 CnxTgN (Conexant AccessRunner USB ADSL WAN Adapter Driver) - c:\windows\system32\drivers\cnxtgn.sys <Not Verified; Conexant Systems Inc.; Conexant AccessRunner ADSL>
R3 CONTENT.DLL (Outpost Firewall PlugIn (CONTENT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\content.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 DNSCACHE.DLL (Outpost Firewall PlugIn (DNSCACHE.DLL)) - c:\program files\agnitum\outpost firewall\kernel\dnscache.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 FTPFILT.DLL (Outpost Firewall PlugIn (FTPFILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\ftpfilt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 HTMLFILT.DLL (Outpost Firewall PlugIn (HTMLFILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\htmlfilt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 HTTPFILT.DLL (Outpost Firewall PlugIn (HTTPFILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\httpfilt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 IMAPFILT.DLL (Outpost Firewall PlugIn (IMAPFILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\imapfilt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 MAILFILT.DLL (Outpost Firewall PlugIn (MAILFILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\mailfilt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 NNTPFILT.DLL (Outpost Firewall PlugIn (NNTPFILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\nntpfilt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 POP3FILT.DLL (Outpost Firewall PlugIn (POP3FILT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\pop3filt.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 PROTECT.DLL (Outpost Firewall PlugIn (PROTECT.DLL)) - c:\program files\agnitum\outpost firewall\kernel\protect.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>
R3 SECRET.DLL (Outpost Firewall PlugIn (SECRET.DLL)) - c:\program files\agnitum\outpost firewall\kernel\secret.dll <Not Verified; Agnitum Ltd.; Outpost Firewall>

S3 Ad-Watch Connect Filter (Ad-Watch Connect Kernel Filter) - c:\windows\system32\drivers\nsdriver.sys (file missing)
S3 Ad-Watch Real-Time Scanner (AW Real-Time Scanner) - c:\windows\system32\drivers\awrtpd.sys (file missing)
S3 EverestDriver (Lavalys EVEREST Kernel Driver) - c:\program files\lavalys\everest ultimate edition\kerneld.wnt
S3 UIUSys (Conexant Setup API) - c:\windows\system32\drivers\uiusys.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 OutpostFirewall (Outpost Firewall Service) - c:\program files\agnitum\outpost firewall\outpost.exe /service <Not Verified; Agnitum Ltd.; Outpost Firewall>
R2 RegManServ (Registry Management Service) - c:\program files\advanced registry doctor\regmanserv.exe

S3 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution>
S3 UPHClean (User Profile Hive Cleanup) - c:\program files\uphclean\uphclean.exe <Not Verified; Microsoft Corporation; User Profile Hive Cleanup Service>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID:
Description: Modem Device on High Definition Audio Bus
Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_14F100C3&REV_0900\4&1D1AAA2D&0&0102
Manufacturer:
Name: Modem Device on High Definition Audio Bus
PNP Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_14F100C3&REV_0900\4&1D1AAA2D&0&0102
Service:

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Broadcom 440x 10/100 Integrated Controller
Device ID: PCI\VEN_14E4&DEV_170C&SUBSYS_01C91028&REV_02\4&2FA23535&0&00F0
Manufacturer: Broadcom
Name: Broadcom 440x 10/100 Integrated Controller
PNP Device ID: PCI\VEN_14E4&DEV_170C&SUBSYS_01C91028&REV_02\4&2FA23535&0&00F0
Service: bcm4sbxp

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Dell Wireless 1370 WLAN Mini-PCI Card
Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_00051028&REV_02\4&2FA23535&0&18F0
Manufacturer: Broadcom
Name: Dell Wireless 1370 WLAN Mini-PCI Card
PNP Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_00051028&REV_02\4&2FA23535&0&18F0
Service: BCM43XX

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6670
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd


-- Scheduled Tasks -------------------------------------------------------------

2006-07-03 18:18:24 106 --a------ C:\WINDOWS\Tasks\Low Battery Alarm Program.job


-- Files created between 2007-07-31 and 2007-08-31 -----------------------------

2007-08-31 18:49:58 0 d-------- C:\Documents and Settings\Dejan\Application Data\ICQLite
2007-08-31 13:39:21 0 d-------- C:\Documents and Settings\Dejan\Application Data\Opera
2007-08-31 13:39:06 0 d-------- C:\Program Files\Opera 9
2007-08-31 13:02:37 23584 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-08-31 13:02:37 1478432 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-31 12:57:29 82258 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-08-31 12:57:29 82258 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-08-31 12:52:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2007-08-30 12:36:44 0 d-------- C:\Documents and Settings\Dejan\.SunDownloadManager
2007-08-30 10:51:37 335 --a------ C:\WINDOWS\mozregistry.dat
2007-08-29 21:40:17 0 d-------- C:\Lyrics
2007-08-29 21:40:16 0 d-------- C:\Documents and Settings\Dejan\Application Data\MiniLyrics
2007-08-29 21:39:47 0 d-------- C:\Program Files\Minilyrics
2007-08-29 15:08:41 0 d-------- C:\Documents and Settings\Dejan\Application Data\Talkback
2007-08-29 14:21:14 0 d-------- C:\Program Files\Lavasoft
2007-08-29 14:21:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-08-28 20:58:33 2522 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-28 20:57:40 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2007-08-28 20:57:40 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2007-08-28 20:57:40 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-28 20:28:45 0 dr-h----- C:\Documents and Settings\Dejan\Recent
2007-08-28 18:46:50 65436 --a------ C:\WINDOWS\system32\__c004A35E.dat
2007-08-28 18:46:46 84538 --a------ C:\WINDOWS\system32\__c0021F10.dat
2007-08-27 08:27:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-08-27 08:27:07 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-08-24 23:02:06 0 d-------- C:\skin
2007-08-22 13:25:31 0 d-------- C:\Program Files\RadioXpi
2007-08-21 11:07:18 106496 --a------ C:\WINDOWS\system32\DrvTrNTl.dll <Not Verified; High Criteria inc.; Total Recorder (Professional Edition)>
2007-08-21 11:07:18 0 d-------- C:\Program Files\HighCriteria
2007-08-21 11:07:17 54272 --a------ C:\WINDOWS\system32\DrvTrNTm.dll <Not Verified; High Criteria inc.; Total Recorder (Professional Edition)>
2007-08-19 10:00:31 0 d-------- C:\Program Files\Mp3 My Mp3 2.0
2007-08-17 12:31:33 0 d-------- C:\Documents and Settings\Dejan\Application Data\Sun
2007-08-15 10:40:57 0 d-------- C:\Program Files\Windows Media Connect 2
2007-08-15 10:32:38 0 d-------- C:\WINDOWS\system32\LogFiles
2007-08-15 10:32:38 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-08-14 17:46:50 0 d-------- C:\Program Files\Lock My PC 4
2007-08-02 22:50:30 0 d-------- C:\Program Files\TrackMania Nations ESWC
2007-08-02 19:53:28 278695200 --a------ C:\Program Files\TmNationsESWC_Setup.exe <Not Verified; Nadeo; >


-- Find3M Report ---------------------------------------------------------------

2007-08-31 13:07:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-31 12:56:18 0 d-------- C:\Program Files\Kaspersky Lab
2007-08-30 12:12:59 3749 --a------ C:\WINDOWS\mozver.dat
2007-08-30 12:07:31 0 d-------- C:\Program Files\Java
2007-08-30 11:28:59 0 d-------- C:\Documents and Settings\Dejan\Application Data\uTorrent
2007-08-29 21:55:43 0 d-------- C:\Program Files\Winamp
2007-08-29 09:34:09 0 d-------- C:\Documents and Settings\Dejan\Application Data\LimeWire
2007-08-29 09:32:51 0 d-------- C:\Program Files\LimeWire
2007-08-28 20:17:45 0 d-------- C:\Program Files\Intel
2007-08-28 19:51:45 0 d-------- C:\Program Files\eMule
2007-08-28 17:08:34 0 d-------- C:\Program Files\Trillian
2007-08-27 18:06:47 0 d-------- C:\Program Files\Cuvari Prirode
2007-08-27 17:44:25 0 d-------- C:\Documents and Settings\Dejan\Application Data\Adobe
2007-08-27 09:42:44 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-08-27 08:30:57 0 d-------- C:\Program Files\Common Files\Adobe
2007-08-27 08:27:07 0 d-------- C:\Program Files\Common Files
2007-08-26 22:48:04 0 d-------- C:\Program Files\Paint.NET
2007-08-23 20:58:38 20364 --a------ C:\Program Files\emot134.gif
2007-08-22 18:05:37 0 d-------- C:\Program Files\New Folder (3)
2007-08-19 11:27:27 2926 --a------ C:\Documents and Settings\Dejan\Application Data\NMM-MetaData.db
2007-08-19 11:24:21 0 d-------- C:\Documents and Settings\Dejan\Application Data\Nokia
2007-08-16 19:57:53 0 d-------- C:\Documents and Settings\Dejan\Application Data\Real
2007-08-13 08:20:03 0 d-------- C:\Program Files\Opera
2007-08-04 13:35:10 0 d-------- C:\Program Files\KONAMI
2007-08-04 13:29:55 0 d-------- C:\Program Files\EA GAMES
2007-07-22 08:16:48 0 d-------- C:\Program Files\EA SPORTS
2007-07-22 06:51:05 0 d-------- C:\Program Files\Common Files\EasyInfo
2007-07-19 17:51:49 0 d-------- C:\Program Files\NudgeMania
2007-07-19 12:31:11 0 d-------- C:\Program Files\Lonely Cat Games
2007-07-19 10:55:50 99 --a------ C:\Program Files\New Text Document (2).txt
2007-07-17 09:31:23 0 d-------- C:\Documents and Settings\Dejan\Application Data\Lavasoft
2007-07-16 21:50:48 0 d-------- C:\Program Files\Advanced Registry Doctor
2007-07-16 19:26:33 0 --a------ C:\WINDOWS\system32\OXN
2007-07-15 23:44:21 262144 --a------ C:\WINDOWS\system32\default_user_class.dat
2007-07-15 17:17:15 0 d-------- C:\Program Files\UPHClean
2007-07-15 15:46:28 0 d-------- C:\Program Files\Uniblue
2007-07-15 15:33:56 0 d-------- C:\Documents and Settings\Dejan\Application Data\Uniblue
2007-07-15 14:15:24 0 d-------- C:\Program Files\Yamicsoft
2007-07-15 13:09:16 0 d-------- C:\Program Files\my doc
2007-07-14 18:38:37 0 d-------- C:\Documents and Settings\Dejan\Application Data\BitTorrent
2007-07-14 18:38:00 0 d-------- C:\Program Files\BitTorrent
2007-07-11 16:01:51 0 d-------- C:\Documents and Settings\Dejan\Application Data\AdobeUM
2007-07-10 08:46:14 0 d-------- C:\Documents and Settings\Dejan\Application Data\Macromedia
2007-07-05 13:54:40 0 d-------- C:\Program Files\Jazz Jackrabbit 2
2007-06-30 23:56:28 0 d-------- C:\Documents and Settings\Dejan\Application Data\CyberLink
2007-06-25 16:58:28 141577 --a------ C:\Program Files\Nettalk - (6-25-2007 45819 PM).mht
2007-06-25 16:57:43 141577 --a------ C:\Program Files\Nettalk - (6-25-2007 45656 PM).mht
2007-06-24 22:33:57 37234029 --a------ C:\Program Files\System_Mechanic_6_Pro_6.0u.rar
2007-06-24 21:13:47 42182925 --a------ C:\Program Files\System_Mechanic1.rar
2007-06-24 18:51:45 15055322 --a------ C:\Program Files\Tradewinds_Legends_Unlikely_Heroes.rar
2007-06-23 18:26:52 194 --a------ C:\Program Files\Pass.txt
2007-06-23 08:48:03 1938004 --a------ C:\Program Files\PictureResizeGeniusEn.exe <Not Verified; Lonking Software,LLC; >
2007-06-21 21:28:03 5853108 --a------ C:\Program Files\Banners_Patch.rar
2007-06-21 19:17:38 118069 --a------ C:\Program Files\DreamGirl.MCO
2007-06-21 19:11:11 25 --a------ C:\Program Files\winkscount.ini
2007-06-21 19:01:49 645745 --a------ C:\Program Files\MSNWinks.exe
2007-06-21 19:00:15 181296 --a------ C:\Program Files\TheFinger[msnpro.com].mco
2007-06-21 11:10:53 895131 --a------ C:\Program Files\MOTO.GP.2.V1.0.ENG.DARKNEZZ.NOCD.ZIP
2007-06-20 23:09:02 14337529 --a------ C:\Program Files\homer1
2007-06-20 20:17:25 84503 --a------ C:\Program Files\bluesky-gps_v1_1__1_.14-n6600_136.zip
2007-06-19 21:08:13 650672 --a------ C:\Program Files\plumberpete_s60.zip
2007-06-18 21:30:21 806947 --a------ C:\Program Files\MidpRuntimeDLL.zip
2007-06-18 21:28:36 62532 --a------ C:\Program Files\Midp2Exe.zip
2007-06-18 11:07:59 119050 --a------ C:\Program Files\callcheater_1.02_full_dotsis_102.rar
2007-06-17 17:37:59 15521329 --a------ C:\Program Files\Internet_Explorer_7.FINAL.rar
2007-06-17 17:01:47 3903999 --a------ C:\Program Files\ProxySwitcher373647.rar
2007-06-17 16:23:21 668610 --a------ C:\Program Files\The.Privacy.Guard.v1.5.(zabranjeno)ed.ARN.zix
2007-06-17 16:16:10 793086 --a------ C:\Program Files\The.Privacy.Guard.v1.5.rar_crk.rar
2007-06-16 21:19:37 6676282 --a------ C:\Program Files\SetupISB.exe <Not Verified; Macrovision Corporation; InstallShield (R)>
2007-06-16 21:09:54 266788 --a------ C:\Program Files\Softmate.IPSwitcher.Router.v2.00.02-Lz0.ZIP
2007-06-16 21:06:30 436674 --a------ C:\Program Files\The.Privacy.Guard.v1.3.(zabranjeno)ed-EXPLOSiON.rar
2007-06-16 19:29:47 930321 --a------ C:\Program Files\The.Privacy.Guard.v1.5.rar
2007-06-16 19:00:58 670878 --a------ C:\Program Files\theprivacyguardv1.5(zabranjeno)aggression.zip
2007-06-16 18:40:21 756046 --a------ C:\Program Files\PrivacyGuardSetup.exe <Not Verified; ; The Privacy Guard Install Program>
2007-06-13 20:41:05 623809 --a------ C:\Program Files\milioner symbian7.zip
2007-06-12 18:32:13 540904 --a------ C:\Program Files\Hes_Drunk-My_Humps_BLK_EYE_PEEAS.mp3
2007-06-12 17:55:39 38534 --a------ C:\Program Files\Melody of farm 2.mp3
2007-06-12 17:55:23 72479 --a------ C:\Program Files\Cow singer.mp3
2007-06-12 17:54:53 35614 --a------ C:\Program Files\Talkative chickens.mp3
2007-06-12 17:53:38 41975 --a------ C:\Program Files\Rooster.mp3
2007-06-12 17:52:59 56444 --a------ C:\Program Files\pork.mp3
2007-06-12 17:52:52 144448 --a------ C:\Program Files\rap-chicken.mp3
2007-06-11 22:13:09 3551635 --a------ C:\Program Files\Anti_Mosquito_1.0_Full.rar
2007-06-09 09:02:29 324 --a------ C:\Program Files\listen.pls
2007-06-08 22:43:19 34997203 --a------ C:\Program Files\sfzero2_www.ciklet-bb.tr.cx.rar
2007-06-08 21:13:59 6893372 --a------ C:\Program Files\mame0115b.exe
2007-06-07 22:31:39 109640 --a------ C:\Program Files\Omaitek.OmaiProtect.v1.00.S60.SymbianOS7.Incl.Keygen.Patch-BiNPDA.zip
2007-06-07 22:25:50 239479 --a------ C:\Program Files\blackballer10reg_175.zip
2007-06-07 09:59:09 4871409 --a------ C:\Program Files\sangy+angfeatsangyhajdesad.mp3
2007-06-04 08:41:08 84232 --a------ C:\Program Files\EA.Mobile.Tiger.Woods.07.v1.3.28.S60v1.J2ME.Retail-BiNPDA.zip
2007-06-04 08:39:26 595734 --a------ C:\Program Files\Worms 2007.rar
2007-06-04 08:33:12 1472790 --a------ C:\Program Files\new_Counter_Strike(2).rar
2007-06-03 20:21:31 62992468 --a------ C:\Program Files\WOLF_bramjnet.com_Metal_Slug_5.rar
2007-06-03 19:30:45 42917736 --a------ C:\Program Files\System_Mechanic_Professional_7.1.7(2).rar
2007-06-03 19:22:57 900097 --a------ C:\Program Files\Glu.Mobile.Project.Gotham.Racing.v1.0.4.S60.J2ME.Retail-daddyfatsax.zip
2007-06-03 19:18:33 302883 --a------ C:\Program Files\EA.Mobile.Fight.Night.Round.3.240x320.v7.3.18.S60v3.J2ME.Retail-BiNPDA.zip
2007-06-03 19:17:20 295855 --a------ C:\Program Files\EA.Mobile.Fight.Night.Round.3.v7.2.41.S60v2.J2ME.Retail-BiNPDA.zip
2007-06-03 19:15:46 294566 --a------ C:\Program Files\EA.Mobile.Fight.Night.Round.3.176x208.v7.2.91.S60v3.J2ME.Retail-BiNPDA.zip
2007-06-03 19:09:33 185357 --a------ C:\Program Files\I-Play_Metal.Slug.M3_176x208_english.rar
2007-06-03 18:50:33 41424600 --a------ C:\Program Files\System_Mechanic_Professional_7.1.7.rar.part
2007-06-03 18:18:22 338911 --a------ C:\Program Files\System_M7_actv.rar
2007-06-03 13:49:08 10313099 --a------ C:\Program Files\Realplayer_Gold.rar
2007-06-03 13:10:47 1718823 --a------ C:\Program Files\onpla_home.zip
2007-06-02 22:40:45 41422694 --a------ C:\Program Files\System.Mechanic.Professional.7.1.8.4.By.DeViL.rar
2007-05-31 21:28:44 2359695 --a------ C:\Program Files\UEFA.CHAMPIONS.LEAGUE.2006.07.ENG.RAZOR1911.NOCD.ZIP
2007-05-31 21:18:09 23198 --a------ C:\Program Files\mIRGGI_2nd.zip
2007-05-31 21:16:42 33550 --a------ C:\Program Files\mIRGGI.zip
2007-05-31 19:25:41 183028 --a------ C:\Program Files\3MSN.zip
2007-05-31 19:17:31 208404 --a------ C:\Program Files\MMIM.Windows.Live.Messenger.v1.00.S60.SymbianOS7.zip
2007-05-31 19:16:23 267485 --a------ C:\Program Files\messenger_s60_3_0_v_2_0_0_signed.zip
2007-05-31 19:11:44 779 --a------ C:\Program Files\binkw32.zip
2007-05-31 19:11:31 324791 --a------ C:\Program Files\WildPalm.ZipMan.2.5.SymbianOS.S60.(zabranjeno)ed-Bryan.zip


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47B83D78-F986-4E96-9769-2C55EF14DA0B}]
08/28/2007 06:46 PM 65436 --a------ C:\WINDOWS\system32\__c004A35E.dat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Outpost Firewall"="C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" [10/20/2006 03:49 PM]
"OutpostFeedBack"="C:\Program Files\Agnitum\Outpost Firewall\feedback.exe" [10/30/2006 05:07 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/03/2007 01:51 PM]
"TotalRecorderScheduler"="C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe" [12/05/2006 08:49 PM]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" []
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" []
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [06/28/2007 12:51 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 06:24 PM]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:54 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"ICQ Lite"=C:\Program Files\ICQLite\ICQLite.exe -trayboot

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\Dejan\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 7:16:50 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\__c0021F10.dat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Uniblue RegistryBooster 2"=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\setup.exe




-- End of Deckard's System Scanner: finished at 2007-08-31 19:38:29 ------------



A sto se RAMa tice sve je ok, testirao sam ga juce...

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Daj mi na upload i sledeci fajl:
C:\WINDOWS\system32\__c0021F10.dat

Skeniraj HJT-om i stikliraj polja ispred sledecih linija:
O2 - BHO: (no name) - {47B83D78-F986-4E96-9769-2C55EF14DA0B} - C:\WINDOWS\system32\__c004A35E.dat
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0021F10.dat

Klikni na Fix checked

Restartuj u Safe mode i probaj da obrises fajlove:
C:\WINDOWS\system32\__c004A35E.dat
C:\WINDOWS\system32\__c0021F10.dat

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

uploadovano...

Dopuna: 31 Avg 2007 20:09

nisam uspeo da obrisem
C:\WINDOWS\system32\__c0021F10.dat

da probam sa Unlockerom?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Ne verujem da tu Unlocker moze da pomogne. Probaj, ali tesko. Pre ce Pocket KillBox da ga obrise.
Javi mi u toku veceri da li si uspeo sa Unlockerom, ukoliko ne, onda da ti napisem uputstvo za Avenger, on ce sigurno da ga ubije.

Ko je trenutno na forumu
 

Ukupno su 552 korisnika na forumu :: 11 registrovanih, 1 sakriven i 540 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: darkojbn, djo97, dragoljub11987, Kenanjoz, kybonacci, mikki jons, MilosKop, Mixelotti, opt1, saputnik plavetnila, Shilok