exej...imam isti problem...smrc
ComboFix 08-10-09.06 - branko 2008-10-10 15:53:30.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1033.18.1020 [GMT 2:00]
Running from: C:\Users\branko\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\x64
C:\Windows\system32\x64\csnp2uvc.dll
C:\Windows\system32\x64\rsnpvc64.dll
C:\Windows\system32\x64\sncduvc.sys
C:\Windows\system32\x64\snp2uvc.sys
C:\Windows\system32\x64\vsnpvc64.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.
2008-10-10 12:37 . 2008-10-10 12:37 <DIR> d-------- C:\Users\branko\AppData\Roaming\Malwarebytes
2008-10-10 12:37 . 2008-10-10 12:37 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-10-10 12:37 . 2008-10-10 12:37 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-09-19 19:53 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-19 19:53 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
2008-09-10 10:57 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-10 10:57 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
2008-09-10 10:57 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
2008-09-10 10:57 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-10 10:57 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-09-10 10:57 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll
2008-09-10 10:57 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-10 13:57 --------- d-----w C:\Users\branko\AppData\Roaming\Skype
2008-10-10 13:26 48,438 ----a-w C:\Users\branko\AppData\Roaming\nvModes.dat
2008-10-02 09:37 --------- d-----w C:\Program Files\Google
2008-09-25 20:39 --------- d-----w C:\Program Files\SpeedFan
2008-09-17 21:32 --------- d-----w C:\Users\branko\AppData\Roaming\mIRC
2008-09-11 20:13 --------- d-----w C:\Users\branko\AppData\Roaming\LimeWire
2008-09-10 09:10 --------- d-----w C:\ProgramData\Microsoft Help
2008-09-10 09:07 --------- d-----w C:\Program Files\Microsoft Works
2008-09-07 09:30 --------- d-----w C:\Program Files\Winamp
2008-09-03 01:55 --------- d-----w C:\Users\branko\AppData\Roaming\Winamp
2008-09-01 17:51 --------- d-----w C:\Program Files\Java
2008-09-01 17:44 --------- d-----w C:\Program Files\Common Files\Java
2008-09-01 17:40 --------- d-----w C:\Program Files\LimeWire
2008-08-24 14:53 --------- d-----w C:\Program Files\Great Secrets Da Vinci
2008-08-23 15:39 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-23 15:39 --------- d-----w C:\Program Files\Common Files\Real
2008-08-19 13:09 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 09:33 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 21:07 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-31 14:35 174 --sha-w C:\Program Files\desktop.ini
2008-02-19 18:17 0 ----a-w C:\Users\branko\AppData\Roaming\wklnhst.dat
2007-11-26 17:38 32 ----a-w C:\Users\All Users\ezsid.dat
2007-11-26 17:38 32 ----a-w C:\ProgramData\ezsid.dat
2008-05-06 22:38 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-05-06 22:38 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-26 457216]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-06-11 1286144]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-08-15 772616]
"MSPService"="C:\Program Files\Acer Arcade Deluxe\SportsCap\Kernel\MagicSports\MSPMirage.exe" [2007-02-14 102400]
"TVEService"="C:\Program Files\Acer Arcade Deluxe\TV Joy\TVEService.exe" [2007-06-02 151552]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-24 206952]
"PLFSetL"="C:\Windows\PLFSetL.exe" [2007-07-05 94208]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-06-06 159744]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-05-23 151552]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-23 949376]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-25 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-25 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-25 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-23 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-07-25 535336]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-12-26 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2606352464-3568935387-3783892624-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{93095D21-614D-4009-B519-EFD2A48F45DF}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{32945355-CDBE-48E8-AA99-E3234C3E3E07}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D5107B99-FAD3-484B-B1FD-0F99B02215B0}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{F2979B51-C7D7-4432-AC71-A5771C73BB2D}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{9C8B4F34-9FE3-4EEC-9D40-CAEA3189C548}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{A287267E-E282-4EE2-89E6-DBF838D4E07D}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{A25E77DD-5854-4064-B13B-3EFC20045A1C}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{F6286C0B-548D-4FF8-A8C5-D0CD7098A58A}"= C:\Program Files\Acer Arcade Deluxe\SportsCap\SportsCap.exe:SportsCap
"{212BD598-B73A-46CF-A1E2-AFC451A13C1D}"= C:\Program Files\Acer Arcade Deluxe\TV Joy\TV Joy.exe:TV Joy
"{AD50A072-E21B-4281-85D9-F329811DB42C}"= C:\Program Files\Acer Arcade Deluxe\TV Joy\TVEService.exe:TV Joy Resident Program
"{C0D524FC-D5BB-4E9E-A57A-555568F45575}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{3D87BAAD-7219-4C6D-9CFA-938A9DB987E8}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{4DF3DC89-57CA-46C3-94C7-579C45BD74C9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{183DC3BA-B733-454B-9D52-30B1BFA30BC4}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{28FA2CE7-CA99-4B3E-BA10-C4B1D45EB2E6}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{13A1130F-391B-4BEA-B5BE-B6CA95A911A2}C:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= UDP:C:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"UDP Query User{F107D3C5-43B1-4B38-8435-60671D9663C4}C:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= TCP:C:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"{C065C261-7E16-402C-9D4A-AE471AD87F9B}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{5E9F1BF5-D622-4FAB-A6C2-3245023ED7C9}C:\\program files\\dap\\dap.exe"= UDP:C:\program files\dap\dap.exe:Download Accelerator Plus
"UDP Query User{27AB6FDC-BDB1-4EBD-9DD3-03C041036D5B}C:\\program files\\dap\\dap.exe"= TCP:C:\program files\dap\dap.exe:Download Accelerator Plus
"{D0427FDD-799C-4843-ADC4-251D385C93D5}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{C8F849F7-E421-4691-9A8C-D173F534DC0C}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{38A998F3-CB80-4EF4-9EED-3C4F77BB90F3}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{88E43180-94A1-40D5-A966-319AF0652A65}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A1580DB6-45AF-4896-861B-2938D51A6F28}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{559A4BD4-4D11-4E70-8C0C-002220566DD7}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{F593D2D4-A45E-456A-9CEC-8F9D7E0D13C4}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{F1ECEDEE-A20A-4BF5-A8B6-3299D2B3F8DC}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{A1660D43-5121-40D5-9E07-84D36072954D}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{FE1BB9B6-7D5B-481A-AB54-2CEEE7DA7E14}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{6C0C7E68-ACF9-4384-A4AC-5A2D6261079F}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{6FECC61F-43D1-465D-A651-8B58E26897CA}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{9360BF8D-AFEB-4019-A045-C9226373D25E}C:\\program files\\spontania video collaboration\\dialcomwcs.exe"= UDP:C:\program files\spontania video collaboration\dialcomwcs.exe:dialcomwcs
"UDP Query User{70AD7CB9-E7C1-46D8-84AD-4059A49ED48B}C:\\program files\\spontania video collaboration\\dialcomwcs.exe"= TCP:C:\program files\spontania video collaboration\dialcomwcs.exe:dialcomwcs
"TCP Query User{69FC1129-CAA1-43EA-86C1-3EEBC0D316C2}C:\\program files\\valve\\hl.exe"= UDP:C:\program files\valve\hl.exe:Half-Life Launcher
"UDP Query User{5DD4CE0A-55A2-4885-885B-4A03552CBC16}C:\\program files\\valve\\hl.exe"= TCP:C:\program files\valve\hl.exe:Half-Life Launcher
"TCP Query User{09419CC9-9990-4FF2-B744-16570D4FDCBF}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{EF1D80BE-B27A-404D-81DA-538982B552E6}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{B664E91B-881C-42B0-8D74-0217D2382887}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{ED5578D5-E9B8-414D-AC30-F34CFA127662}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{4242BF99-213B-458E-B752-C7C17205873C}C:\\program files\\valve\\hlds.exe"= UDP:C:\program files\valve\hlds.exe:HLDS Launcher
"UDP Query User{0EDDA47F-D8E2-4E53-B7F9-B61F4132D096}C:\\program files\\valve\\hlds.exe"= TCP:C:\program files\valve\hlds.exe:HLDS Launcher
"{38131963-1F90-48DE-BB43-DC34AFF320CD}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{D520795B-C7D5-43E3-A80A-6CBCA9E5899C}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{391E42B7-3093-49F5-B7B6-F2A56A785E59}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{2A769639-0C71-4E12-B36A-AD9D28139247}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FC83DF06-6B42-455C-8468-7B272DDAFC05}C:\\program files\\empire xp 5\\empire xp.exe"= UDP:C:\program files\empire xp 5\empire xp.exe:Empire XP 5.2
"UDP Query User{554811A9-5265-4A45-8FBA-9B5DD7A14114}C:\\program files\\empire xp 5\\empire xp.exe"= TCP:C:\program files\empire xp 5\empire xp.exe:Empire XP 5.2
"{917FF743-327A-47E5-B0B3-C5BC0F36EA8C}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8ED00B15-3DA3-46FC-AA48-4835E3F0C694}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A9D7EBD7-3CE7-4009-B2A4-0B2349422547}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05B0F2F7-DA4E-4D6C-8E27-91DD355CA815}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C7FE2817-A816-45AF-AC35-DEC59F43B25A}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{0A1AEDFA-A98A-4A69-A87F-D580B91B2919}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{1F8CB8E2-1EA7-464A-9044-3F2B33AF26D4}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"TCP Query User{BA54C92C-20A2-46C3-AF9F-D75A0F04EDB1}C:\\program files\\icall\\icall.exe"= UDP:C:\program files\icall\icall.exe:iCall Internet Phone
"UDP Query User{048F8C80-1885-4992-A59A-9AF3BF985715}C:\\program files\\icall\\icall.exe"= TCP:C:\program files\icall\icall.exe:iCall Internet Phone
"{94FF60D5-0391-4F84-9956-0D7232FE4D91}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{99010A96-6FA4-4F86-8CE8-724202A6A60D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{3AC95D85-8E95-42F4-BEA9-6DA9F5485F90}C:\\programdata\\chat republic games\\chatrepublicplayer.exe"= UDP:C:\programdata\chat republic games\chatrepublicplayer.exe:Executable Install, Update, Uninstall
"UDP Query User{405A114B-100D-47DC-97C2-0CC5EDB048D5}C:\\programdata\\chat republic games\\chatrepublicplayer.exe"= TCP:C:\programdata\chat republic games\chatrepublicplayer.exe:Executable Install, Update, Uninstall
"TCP Query User{B2C7E9C2-F795-4488-B475-C9D3B5B3038E}C:\\program files\\winamp\\winamp.exe"= UDP:C:\program files\winamp\winamp.exe:Winamp
"UDP Query User{2FE0AECF-8D39-496C-A638-79B535552DC5}C:\\program files\\winamp\\winamp.exe"= TCP:C:\program files\winamp\winamp.exe:Winamp
"TCP Query User{C4A14C80-51ED-402B-A612-49A0ABC3C4B1}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{74549E06-E39E-414F-B54B-00E2C9996E33}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\\Program Files\\iCall\\iCall.exe"= C:\Program Files\iCall\iCall.exe:*:Enabled:iCall
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-03 01:51 13560]
R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 45848]
R2 LogWatch;Event Log Watch;C:\Windows\LogWatNT.exe [2000-06-08 50176]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);C:\Program Files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVECapSvc.exe [2007-06-02 286820]
R2 TVESched;TVEnhance Task Scheduler (TTS));C:\Program Files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVESched.exe [2007-06-02 110682]
R3 A310;AVerMedia A310 DVB-T;C:\Windows\system32\DRIVERS\AVerA310USB.sys [2007-08-19 26496]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;C:\Windows\system32\drivers\AVerA310Cap.sys [2007-08-19 42496]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
S2 gupdate1c905f7c70fb470;Google Update Service (gupdate1c905f7c70fb470);C:\Program Files\Google\Update\GoogleUpdate.exe [2008-08-30 133104]
S3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-05-17 79664]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-05-17 81200]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-05-17 16432]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2007-02-22 2808664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{485acae7-3606-11dd-9d3d-001b3857b22d}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-09-14 C:\Windows\Tasks\ErrorSmart Scheduled Scan.job
- C:\Program Files\ErrorSmart\ErrorSmart.exe []
2008-09-14 C:\Windows\Tasks\ErrorSmart Scheduled Scan.job
- C:\Program Files\ErrorSmart []
2008-10-10 C:\Windows\Tasks\GoogleUpdateTaskMachine.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2008-08-30 11:52]
2008-10-10 C:\Windows\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-03-10 19:57]
2008-07-24 C:\Windows\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-03-10 19:57]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Acer Tour Reminder - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\branko\AppData\Roaming\Mozilla\Firefox\Profiles\pyfreqeq.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.daemon-search.com/startpage
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-10-10 15:57:47
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-10 16:00:11
ComboFix-quarantined-files.txt 2008-10-10 13:59:50
Pre-Run: 20.665.204.736 bytes free
Post-Run: 20,598,775,808 bytes free
253 --- E O F --- 2008-10-07 21:02:34
i to vec duzi vremenski period...
sta mi preporucujete da odradim...
|