offline
- greekgoddess

- Novi MyCity građanin
- Pridružio: 28 Maj 2009
- Poruke: 17
|
Napisano: 29 Maj 2009 21:18
ComboFix 09-05-28.09 - Barbika 29.05.2009 21:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1708 [GMT 2:00]
Running from: c:\documents and settings\Barbika\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\20080128135518500_Samsung_PC_Studio_321_HA4.exe
c:\documents and settings\Download programs\GameHouse-Installer_am-escaperosecliffislandtm_gamehouse.exe
c:\windows\system32\drivers\UACmeyxwhkdpkmrqqf.sys
c:\windows\system32\UACdpxenteruhpaxrd.db
c:\windows\system32\UACeevlidkyvbucbtq.log
c:\windows\system32\UACfbdedbnuigsnjnv.dll
c:\windows\system32\UACflnstcomufxjexg.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiudfwiljxgbrlkt.dll
c:\windows\system32\UACkgyjkqbrshlpdnt.log
c:\windows\system32\UAClvmpomtrskoqvrh.dll
c:\windows\system32\UAClwopavohjjhfosb.dll
c:\windows\system32\UACmpktsjnrcxpsihx.dll
c:\windows\system32\UACoewswvbvxwuiwah.dll
c:\windows\system32\UACthtfuwdvaespnii.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-29 )))))))))))))))))))))))))))))))
.
2009-05-28 11:22 . 2009-05-28 11:22 -------- d-----w c:\documents and settings\Dragana\Application Data\Malwarebytes
2009-05-28 00:20 . 2009-05-28 00:20 -------- d-----w c:\documents and settings\Barbika\Application Data\Malwarebytes
2009-05-27 23:49 . 2009-05-27 23:49 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-27 23:49 . 2009-05-29 18:51 -------- d-----w c:\program files\12345
2009-05-27 23:24 . 2009-03-30 08:33 96104 ----a-w c:\windows\system32\drivers\avipbb.sys
2009-05-27 23:24 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-27 23:24 . 2009-02-13 10:29 22360 ----a-w c:\windows\system32\drivers\avgntmgr.sys
2009-05-27 23:24 . 2009-02-13 10:17 45416 ----a-w c:\windows\system32\drivers\avgntdd.sys
2009-05-27 23:24 . 2009-05-27 23:24 -------- d-----w c:\program files\Avira
2009-05-27 23:24 . 2009-05-27 23:24 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-27 14:32 . 2009-05-27 18:19 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-27 14:32 . 2009-05-27 17:04 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-26 18:09 . 2004-08-05 13:58 65536 ----a-w c:\windows\system32\NeroCo.dll
2009-05-26 18:09 . 2004-08-04 12:19 2031616 ------w c:\windows\UNNeroBurnRights.exe
2009-05-22 21:41 . 2009-05-22 21:41 -------- d-----w c:\documents and settings\All Users\Application Data\DivoGames
2009-05-22 21:40 . 2009-05-22 21:40 -------- d-----w c:\program files\Be Rich
2009-05-22 21:30 . 2009-05-22 21:30 -------- d-----w c:\windows\Be Rich
2009-05-22 21:18 . 2009-05-22 21:21 -------- d-----w c:\documents and settings\Download programs\Big Fish Games - Be Rich + Adnan_Boy 2008 + Pre(zabranjeno)ed
2009-05-22 21:18 . 2009-05-22 21:18 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-05-22 20:40 . 2000-06-26 08:45 106496 ----a-w c:\windows\system32\TwnLib20.dll
2009-05-22 20:40 . 2004-07-20 14:24 471040 ------w c:\windows\system32\ImagXRA7.dll
2009-05-22 20:40 . 2004-07-09 06:43 364544 ------w c:\windows\system32\TwnLib4.dll
2009-05-22 20:40 . 2004-07-20 14:24 476320 ------w c:\windows\system32\ImagXpr7.dll
2009-05-22 20:40 . 2004-07-20 14:24 262144 ------w c:\windows\system32\ImagXR7.dll
2009-05-22 20:40 . 2004-07-20 14:24 1568768 ------w c:\windows\system32\ImagX7.dll
2009-05-22 20:40 . 2001-06-26 05:15 38912 ------w c:\windows\system32\picn20.dll
2009-05-22 20:40 . 2009-05-22 20:40 -------- d-----w c:\program files\Common Files\Ahead
2009-05-22 20:40 . 2001-07-09 08:50 155648 ----a-w c:\windows\system32\NeroCheck.exe
2009-05-22 20:40 . 2009-05-26 18:09 -------- d-----w c:\program files\Ahead
2009-05-20 15:48 . 2009-05-20 15:48 -------- d-----w c:\documents and settings\Barbika\Local Settings\Application Data\Microsoft Help
2009-05-20 14:18 . 2006-04-27 23:51 29968 ----a-w c:\windows\system32\mdimon.dll
2009-05-20 14:15 . 2009-05-20 14:15 -------- d-----w c:\documents and settings\Dragana\Local Settings\Application Data\Microsoft Help
2009-05-20 14:15 . 2009-05-22 20:37 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-20 00:12 . 2009-05-20 00:12 -------- d-----w c:\program files\Dream Chronicles - The Chosen Child
2009-05-18 20:11 . 2009-05-18 20:11 0 ----a-w c:\windows\nsreg.dat
2009-05-18 20:11 . 2009-05-18 20:11 -------- d-----w c:\documents and settings\Barbika\Local Settings\Application Data\Mozilla
2009-05-18 19:06 . 2009-05-18 19:06 -------- d-----w c:\documents and settings\Dragana\Application Data\Yahoo!
2009-05-18 19:06 . 2009-05-18 19:06 -------- d-----w c:\documents and settings\Dragana\Local Settings\Application Data\Winamp Toolbar
2009-05-15 23:19 . 2009-05-15 23:27 -------- d-----w c:\documents and settings\All Users\Application Data\VirtualFarm
2009-05-14 22:25 . 2009-05-14 23:16 144124179 ----a-w c:\documents and settings\Download programs\Fairy Godmother Tycoon.zip
2009-05-14 22:21 . 2009-05-14 22:21 -------- d-----w c:\documents and settings\Barbika\Application Data\ShinyTales
2009-05-14 22:17 . 2009-05-14 22:17 -------- d-----w c:\program files\Wonderburg
2009-05-14 22:17 . 2009-05-14 22:17 -------- d-----w c:\windows\Wonderburg
2009-05-14 21:08 . 2009-05-14 21:08 -------- d-----w c:\documents and settings\Barbika\Local Settings\Application Data\DivoGames
2009-05-14 21:05 . 2009-05-14 21:11 -------- d-----w c:\documents and settings\Download programs\Big Fish Games - Wonderburg + Adnan_Boy 2008 + Pre(zabranjeno)ed
2009-05-13 13:57 . 2009-05-13 13:57 -------- d-----w c:\documents and settings\Download programs\Angels & Demons 2009 TeleSync.DivX.Eng.no subs
2009-05-13 13:45 . 2009-05-13 13:45 -------- d-----w c:\documents and settings\Download programs\Angels & Demons 2009 [DVDrip] [Xvid] [CLEAR RELEASE]-BeastieClock
2009-05-12 14:55 . 2009-05-12 14:55 -------- d-----w c:\documents and settings\Barbika\Application Data\Enchanted Katya
2009-05-12 02:11 . 2009-05-12 14:55 -------- d-----w c:\program files\Enchanted Katya and the Mystery of the Lost Wizard
2009-05-10 13:15 . 2009-05-10 13:15 -------- d-----w c:\windows\Wandering Willows
2009-05-10 13:15 . 2009-05-10 13:15 -------- d-----w c:\program files\Wandering Willows
2009-05-10 13:00 . 2009-05-10 13:00 -------- d-----w c:\documents and settings\Download programs\Reflexive Games - Wandering Willows + Adnan_Boy 2008
2009-05-10 00:54 . 2009-05-10 00:54 -------- d-----w c:\program files\Romopolis
2009-05-10 00:22 . 2009-05-10 00:22 -------- d-----w c:\program files\The Legend of Crystal Valley
2009-05-10 00:14 . 2009-05-10 00:14 -------- d-----w c:\documents and settings\Barbika\Application Data\Boomzap
2009-05-10 00:00 . 2009-05-10 00:01 -------- d-----w c:\program files\Frogs in Love
2009-05-09 23:57 . 2009-05-09 23:57 -------- d-----w c:\documents and settings\Barbika\Application Data\TikGames
2009-05-09 23:57 . 2009-05-09 23:57 -------- d-----w c:\documents and settings\All Users\Application Data\TikGames
2009-05-09 23:54 . 2009-05-09 23:54 -------- d-----w c:\program files\Wild Tribe
2009-05-09 23:40 . 2009-05-09 23:40 -------- d-----w c:\documents and settings\Barbika\Application Data\Playrix Entertainment
2009-05-09 22:46 . 2009-05-09 22:47 -------- d-----w c:\program files\Fishdom H2O - Hidden Odyssey
2009-05-09 21:18 . 2009-05-09 21:18 -------- d-----w c:\documents and settings\Barbika\Local Settings\Application Data\Astar Games
2009-05-09 20:24 . 2009-05-09 20:25 -------- d-----w c:\program files\Laura Jones and the Secret Legacy of Nikola Tesla
2009-05-09 20:16 . 2009-05-09 20:16 -------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2009-05-09 20:06 . 2009-05-10 12:49 -------- d-----w c:\documents and settings\Download programs\Reflexive - Flower Paradise - New Match 3 - Wendy99
2009-05-09 20:05 . 2009-05-09 20:08 -------- d-----w c:\program files\Adventure Chronicles - The Search for Lost Treasure
2009-05-08 19:48 . 2009-05-08 19:48 -------- d-----w c:\documents and settings\Download programs\BigFish Games - Flux Family Secrets The Ripple Effect with Strategy Guide - New HOG Puzzle - Wendy99
2009-05-07 19:33 . 2009-05-07 19:33 -------- d-----w c:\windows\Flux Family Secrets - The Ripple Effect
2009-05-07 17:13 . 2009-05-07 17:14 -------- d-----w c:\program files\Pocahontas - Princess of Powhatan
2009-05-07 17:13 . 2009-05-07 17:13 -------- d-----w c:\windows\Pocahontas - Princess of Powhatan
2009-05-07 16:51 . 2009-05-07 16:56 -------- d-----w c:\documents and settings\Download programs\Big Fish Games - Pocahontas - Princess of Powhatan + Adnan_Boy 2008
2009-05-07 00:00 . 2009-05-07 00:00 -------- d-----w c:\documents and settings\Barbika\Application Data\Skunk Studios
2009-05-06 23:59 . 2009-05-08 19:45 -------- d-----w c:\program files\Flux Family Secrets - The Ripple Effect
2009-05-06 22:34 . 2009-05-06 22:34 -------- d-----w c:\documents and settings\Barbika\Application Data\Twintale Entertainment
2009-05-06 22:11 . 2009-05-06 22:34 -------- d-----w c:\program files\Pocahontas - Princess of the Powhatan
2009-05-05 01:56 . 2009-05-05 01:57 -------- d-----w c:\documents and settings\Barbika\Application Data\HiT-MM
2009-05-05 01:02 . 2009-05-11 23:11 0 ----a-w c:\windows\system32\drivers\472a45fa.sys
2009-05-03 21:06 . 2009-05-03 21:06 -------- d-----w c:\documents and settings\Download programs\Betoven-_J_
2009-05-03 15:57 . 2009-05-03 15:57 -------- d-----w c:\documents and settings\Dragana\WINDOWS
2009-05-03 15:49 . 2009-05-03 16:03 21840 ----atw c:\windows\system32\SIntfNT.dll
2009-05-03 15:49 . 2009-05-03 16:03 17212 ----atw c:\windows\system32\SIntf32.dll
2009-05-03 15:49 . 2009-05-03 16:03 12067 ----atw c:\windows\system32\SIntf16.dll
2009-05-03 15:45 . 2009-05-03 15:45 -------- d-----w c:\program files\Sierra On-Line
2009-05-03 15:08 . 2009-05-10 12:55 -------- d-----w c:\program files\Games
2009-05-03 14:57 . 2009-05-03 14:59 -------- d-----w c:\documents and settings\Download programs\Cradle of Rome - Match 3 (Requested) [h33t][Wendy99]
2009-05-03 14:11 . 1998-01-23 10:22 304128 ----a-w c:\windows\IsUninst.exe
2009-05-03 13:35 . 2009-05-03 13:35 -------- d-----w c:\documents and settings\Barbika\WINDOWS
2009-05-03 12:43 . 2009-05-03 13:34 -------- d-----w c:\documents and settings\Download programs\Zeus - Master of Olympus
2009-04-30 21:08 . 2009-04-30 21:08 -------- d-----w c:\program files\WildGames
2009-04-30 20:27 . 2009-04-30 20:48 -------- d-----w c:\documents and settings\Download programs\WildGames - National Geographic - Herod's Lost Tomb - RaBBiT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-29 18:52 . 2008-11-19 20:07 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-28 00:08 . 2009-03-26 15:40 -------- d-----w c:\program files\Mystery of Shark Island
2009-05-27 16:36 . 2009-03-26 15:29 -------- d-----w c:\program files\Hide And Secret
2009-05-27 15:01 . 2008-10-20 20:02 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-26 16:14 . 2008-10-08 11:18 69840 ----a-w c:\documents and settings\Dragana\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-25 14:57 . 2009-04-22 14:55 261 --s-a-w c:\windows\system32\2698396479.dat
2009-05-22 21:28 . 2008-12-02 22:39 -------- d-----w c:\documents and settings\Barbika\Application Data\uTorrent
2009-05-22 21:12 . 2008-10-26 21:43 -------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-05-22 20:51 . 2008-10-11 20:05 69840 ----a-w c:\documents and settings\Barbika\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-20 00:13 . 2008-10-22 18:58 -------- d-----w c:\documents and settings\Barbika\Application Data\PlayFirst
2009-05-13 11:50 . 2009-02-06 10:43 -------- d-----w c:\documents and settings\Dragana\Application Data\uTorrent
2009-05-10 00:52 . 2009-03-26 15:47 -------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2009-05-05 00:55 . 2008-10-23 23:51 -------- d-----w c:\documents and settings\All Users\Application Data\MumboJumbo
2009-05-01 02:03 . 2008-12-02 22:39 -------- d-----w c:\program files\uTorrent
2009-04-23 14:56 . 2008-10-28 21:37 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-18 19:00 . 2009-04-01 19:53 -------- d-----w c:\program files\Cradle Of Persia
2009-04-18 19:00 . 2009-01-09 20:41 -------- d-----w c:\program files\Audacity 1.3 Beta (Unicode)
2009-04-17 10:54 . 2009-04-17 10:53 -------- d-----w c:\program files\All Mortal Combat PC Games Collection
2009-04-14 17:17 . 2009-04-14 17:17 -------- d-----w c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2009-04-10 17:10 . 2008-10-07 21:14 -------- d-----w c:\program files\Opera
2009-04-09 22:23 . 2009-04-09 22:23 -------- d-----w c:\program files\Opera 10 Preview
2009-04-04 20:01 . 2009-04-04 20:01 -------- d-----w c:\documents and settings\Dragana\Application Data\PC Suite
2009-04-04 14:13 . 2008-10-21 18:53 -------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2009-04-04 14:04 . 2009-02-23 17:15 -------- d-----w c:\program files\GameHouse
2009-04-04 14:04 . 2008-11-19 20:07 -------- d-----w c:\program files\Google
2009-04-04 14:03 . 2009-04-04 14:03 -------- d-----w c:\program files\Big City Adventure SF
2009-04-04 14:02 . 2009-04-04 14:02 -------- d-----w c:\documents and settings\Barbika\Application Data\funkitron
2009-04-04 14:01 . 2009-04-04 14:01 -------- d-----w c:\documents and settings\Barbika\Application Data\EA
2009-04-04 14:01 . 2009-04-04 14:01 -------- d-----w c:\documents and settings\All Users\Application Data\EA
2009-04-04 13:54 . 2009-04-04 13:54 -------- d-----w c:\documents and settings\Barbika\Application Data\Incredible Ink
2009-04-04 13:52 . 2009-04-04 13:52 -------- d-----w c:\documents and settings\Barbika\Application Data\pixelStorm
2009-04-04 13:47 . 2009-04-04 13:47 -------- d-----w c:\documents and settings\Barbika\Application Data\GameBlend
2009-04-04 13:47 . 2009-04-04 13:47 -------- d-----w c:\documents and settings\All Users\Application Data\GameBlend
2009-04-01 20:02 . 2009-04-01 20:02 -------- d-----w c:\documents and settings\All Users\Application Data\Awem
2009-03-31 02:03 . 2009-03-26 15:41 -------- d-----w c:\program files\Mystery Case Files Huntsville
2009-03-31 00:59 . 2009-03-26 15:37 -------- d-----w c:\program files\Paradise Pet Salon
2009-03-30 19:45 . 2009-01-09 20:41 -------- d-----w c:\documents and settings\Barbika\Application Data\Audacity
2009-03-30 01:56 . 2008-12-01 17:29 30 ----a-w c:\windows\popcinfo.dat
2009-03-26 15:37 . 2009-03-26 15:37 409600 ----a-w c:\windows\system32\wrap_oal.dll
2009-03-26 15:37 . 2009-03-26 15:37 114688 ----a-w c:\windows\system32\OpenAL32.dll
2009-03-08 14:11 . 2009-03-08 14:07 23510720 ----a-w c:\documents and settings\Barbika\Application Data\Sony Setup\09063B41-0916-4360-A80D-0C2A2B89D300\dotnetfx.exe
2009-03-08 14:03 . 2009-03-08 14:03 249856 ------w c:\windows\Setup1.exe
2009-03-08 14:03 . 2009-03-08 14:03 73216 ----a-w c:\windows\ST6UNST.EXE
2009-03-06 14:44 . 2002-08-29 03:41 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-05 23:19 . 2009-03-05 23:07 39892192 ----a-w c:\documents and settings\All Users\Application Data\BigFishGamesCache\GameManager\GameDB\F2863T1L1\setup_gF2863T1L1_d457044967_l1_s1.exe
2009-03-05 20:17 . 2009-03-05 20:17 8192 ----a-w c:\documents and settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Installer\CommonCustomActions\UninstCCD.exe
2009-03-05 20:17 . 2009-03-05 20:17 61440 ----a-w c:\documents and settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-03-05 20:17 . 2009-03-05 20:17 10240 ----a-w c:\documents and settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Installer\CommonCustomActions\UninstPCS.exe
2009-03-05 20:16 . 2009-03-05 20:17 33642704 ----a-w c:\documents and settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Nokia_PC_Suite_7_1_18_0_eng_web.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2008-03-11 13520896]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2008-03-11 86016]
"WireLessMouse"="c:\program files\Multimedia Mouse Driver\StartAutorun.exe" [2005-11-30 94208]
"WireLessKeyboard"="c:\program files\Office Keyboard Driver\StartAutorun.exe" [2005-11-30 94208]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2005-11-07 73728]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-11-10 406016]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"LogonStudio"="c:\program files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"PMCS"="c:\program files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" [2005-11-08 65536]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-09-27 16844800]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-08-03 1826816]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-03-11 1626112]
c:\documents and settings\Dragana\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-10-11 3450608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-9-19 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [28.5.2009 1:24 108289]
R3 3xHybrid;Pinnacle PCTV 110i service;c:\windows\system32\drivers\3xHybrid.sys [11.10.2008 18:12 827008]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [7.10.2008 22:08 36864]
S1 472a45fa;472a45fa;c:\windows\system32\drivers\472a45fa.sys [5.5.2009 3:02 0]
S2 srserviceRDSessMgr;System Restore Service srserviceRDSessMgr;c:\windows\system32\1037l.exe srv --> c:\windows\system32\1037l.exe srv [?]
.
Contents of the 'Scheduled Tasks' folder
2009-05-28 c:\windows\Tasks\PMCS_Wakeup633791306738593750.job
- c:\program files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe [2008-10-11 07:41]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Microsoft WinUpdate - c:\windows\system32\msupdte.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
mStart Page = [Link mogu videti samo ulogovani korisnici]
uInternet Connection Wizard,ShellNext = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
IE: &Google Search - c:\program files\Google\googletoolbar.dll/cmsearch.html
IE: Backward &Links - c:\program files\Google\googletoolbar.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\googletoolbar.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Si&milar Pages - c:\program files\Google\googletoolbar.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\googletoolbar.dll/cmtrans.html
DPF: DirectAnimation Java Classes - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Barbika\Application Data\Mozilla\Firefox\Profiles\ytx9lkcj.default\
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-05-29 21:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,35,3a,f2,60,68,
c9,8b,a7,2e,e8,e1,00,eb,16,2b,de,35,9b,5e,9c,25,5f,43,76,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,25,f9,41,df,9d,
f3,7c,8b,46,47,15,b0,92,4b,c7,ef,fe,2b,5a,9a,cd,b0,bc,f9,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,db,75,b0,c5,6f,
b5,b6,d3,7a,45,05,fd,91,e8,6f,31,b7,91,03,e2,9d,e6,80,b8,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,87,3f,8b,c6,36,
10,91,19,6b,65,49,6a,7e,99,74,f7,85,9e,57,b9,db,e9,36,54,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,9c,d5,35,d3,52,
bb,f9,06,e9,02,6c,fa,fb,1d,47,57,f2,c0,11,1b,e3,5e,82,0e,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,ea,7e,27,19,89,
80,c7,56,50,93,e5,ab,ec,6a,4e,ab,ef,5e,3e,0b,e5,e2,01,44,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,bd,d3,a9,07,7d,
5f,55,79,97,20,4e,9a,c7,f1,35,ee,31,ec,5e,90,86,fc,78,ad,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:aa,52,c6,00,84,3c,26,64,55,b3,1f,68,bd,
cf,9e,fb,aa,52,c6,00,84,3c,26,64,37,fe,b8,22,4f,ae,74,22,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,37,2d,61,7d,96,
8f,3c,24,b2,46,9a,e2,1b,fe,1b,94,18,15,cd,2b,b6,1b,47,1f,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,3d,59,90,ed,26,
72,7f,f2,37,a4,aa,c3,a6,15,56,0a,d4,90,b4,14,a8,a1,36,4b,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,56,16,18,5f,77,
a4,92,4d,f8,31,0f,a9,5f,a0,ec,fb,df,3c,a9,ef,8c,14,6b,51,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,4d,bf,43,76,98,
c5,44,a1,05,73,21,dd,54,d8,4a,c5,c3,2a,8d,b9,36,e0,96,1f,6c,43,2d,1e,aa,22,\
.
Completion time: 2009-05-29 21:13
ComboFix-quarantined-files.txt 2009-05-29 19:13
Pre-Run: 131.149.725.696 bytes free
Post-Run: 135.187.722.240 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
331 --- E O F --- 2009-04-16 01:01
Dopuna: 29 Maj 2009 21:21
Ovo je izvestaj, potpun je, sada cu da pokrenem anivirus da vidim sta smo uradili.
Dopuna: 29 Maj 2009 21:38
Malwarebytes' Anti-Malware 1.37
Database version: 2193
Windows 5.1.2600 Service Pack 2
29.5.2009 21:30:14
mbam-log-2009-05-29 (21-30-14).txt
Scan type: Quick Scan
Objects scanned: 90562
Time elapsed: 10 minute(s), 2 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
ovo je izvestaj, lepo kaze nema nista, ljudi pa vi ste kraljevi, nemam pojma kako da vam se zahvalim.......
Hvalaaaaaaaaaaaaaaa
|