offline
- daisyca
- Novi MyCity građanin
- Pridružio: 05 Feb 2009
- Poruke: 15
|
ComboFix 09-02-04.04 - Admin 2009-02-05 14:25:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.895.624 [GMT 1:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated)
FW: ESET Personal firewall *enabled*
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\recycler\S-7-1-13-100000747-100016712-100022569-1314.com
c:\windows\system32\drivers\gaopdxethelwfe.sys
c:\windows\system32\drivers\gaopdxhpyyqxtp.sys
c:\windows\system32\drivers\gaopdxmlemovdb.sys
c:\windows\system32\drivers\gaopdxoofjwbpq.sys
c:\windows\system32\drivers\gaopdxpagxanfo.sys
c:\windows\system32\drivers\gaopdxppfejbxn.sys
c:\windows\system32\drivers\gaopdxvrrppjnq.sys
c:\windows\system32\drivers\gaopdxygkfkveo.sys
c:\windows\system32\gaopdxsmbitaxt.dll
c:\windows\system32\MSREPL35.DLL
D:\Autorun.inf
d:\recycler\S-0-7-24-100027430-100025366-100022757-6355.com
d:\recycler\S-1-7-79-100019978-100032028-100023808-8009.com
d:\recycler\S-2-1-85-100022079-100030316-100032082-2253.com
d:\recycler\S-3-2-39-100021188-100009380-100019529-3109.com
d:\recycler\S-3-5-47-100000641-100023497-100023349-9805.com
d:\recycler\S-6-0-13-100014523-100006379-100031857-2139.com
d:\recycler\S-6-7-32-100012726-100025815-100030603-9724.com
d:\recycler\S-7-1-13-100000747-100016712-100022569-1314.com
d:\recycler\S-7-6-61-100027988-100030269-100004107-7975.com
d:\recycler\S-8-6-55-100005931-100014105-100019939-2596.com
d:\recycler\S-8-9-22-100030984-100022399-100000157-9079.com
d:\recycler\S-9-1-63-100002742-100024252-100030415-7871.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-02-04 16:43 . 2009-02-04 16:44 <DIR> d-------- c:\windows\system32\NtmsData
2009-02-04 11:51 . 2009-02-04 11:51 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-02-04 11:51 . 2009-02-04 11:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\Macrovision
2009-02-04 11:51 . 2009-02-04 11:51 <DIR> d-------- c:\documents and settings\Admin\Application Data\Ldoce
2009-02-04 11:51 . 2009-02-04 11:51 54,784 --a------ c:\windows\system32\drivers\CDAC11BA.EXE
2009-02-04 11:51 . 2009-02-04 11:51 12,464 --a------ c:\windows\system32\drivers\CdaC15BA.SYS
2009-02-04 11:51 . 2009-02-04 11:51 335 --a------ c:\windows\ldoce.dat
2009-02-04 11:46 . 2009-02-04 11:46 <DIR> d-------- c:\program files\Longman
2009-02-04 10:30 . 2009-02-04 10:30 <DIR> d-------- c:\program files\URUSoft
2009-02-03 17:52 . 2009-02-03 17:52 <DIR> d-------- c:\program files\PDFCreator
2009-02-03 17:52 . 1998-06-24 01:00 137,000 --a------ c:\windows\system32\MSMAPI32.OCX
2009-02-03 17:52 . 2001-10-28 17:42 116,224 --a------ c:\windows\system32\pdfcmnnt.dll
2009-02-03 17:52 . 1998-07-06 01:00 23,552 --a------ c:\windows\system32\MSMPIDE.DLL
2009-01-28 17:16 . 2009-01-28 17:16 <DIR> d-------- c:\documents and settings\Admin\Application Data\Move Networks
2009-01-28 16:48 . 2009-01-28 16:48 <DIR> d-------- c:\windows\HDTVPlayer
2009-01-28 16:48 . 2009-01-28 16:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\BlazeVideo
2009-01-28 16:48 . 2009-02-05 12:53 4 --a------ c:\windows\system32\gaopdxcounter
2009-01-27 14:54 . 2009-02-04 09:52 <DIR> d-------- c:\program files\FrostWire
2009-01-27 14:54 . 2009-02-05 14:19 <DIR> d-------- c:\documents and settings\Admin\Application Data\FrostWire
2009-01-27 14:37 . 2009-01-27 14:53 <DIR> d-------- c:\program files\Common Files\Real
2009-01-25 12:44 . 2009-02-01 21:24 <DIR> d-------- C:\temp
2009-01-23 17:16 . 2004-05-14 16:53 462,848 --a------ c:\windows\system32\ltkrn13n.dll
2009-01-23 17:16 . 2004-05-14 16:53 450,560 --a------ c:\windows\system32\ltimg13n.dll
2009-01-23 17:16 . 2004-05-14 16:53 401,408 --a------ c:\windows\system32\lfcmp13n.dll
2009-01-23 17:16 . 2004-05-14 16:53 299,008 --a------ c:\windows\system32\ltdis13n.dll
2009-01-23 17:16 . 2004-01-12 02:09 206,336 --a------ c:\windows\system32\ltefx13n.dll
2009-01-23 17:16 . 2004-05-14 16:53 163,840 --a------ c:\windows\system32\ltfil13n.dll
2009-01-23 17:16 . 2003-11-04 15:11 159,744 --a------ c:\windows\system32\lfpng13n.dll
2009-01-23 17:16 . 2003-11-04 15:10 69,632 --a------ c:\windows\system32\lfgif13n.dll
2009-01-23 17:16 . 2004-05-14 16:53 57,344 --a------ c:\windows\system32\lfbmp13n.dll
2009-01-22 11:57 . 2009-01-22 11:57 38 --a------ c:\windows\avisplitter.INI
2009-01-21 23:19 . 2005-03-25 23:42 363,520 --a------ c:\windows\system32\psisdecd.dll
2009-01-21 23:19 . 2005-03-25 23:42 363,520 --a--c--- c:\windows\system32\dllcache\psisdecd.dll
2009-01-21 23:19 . 2004-08-04 00:56 56,832 --a------ c:\windows\system32\msdvbnp.ax
2009-01-21 23:19 . 2004-08-04 00:56 56,832 --a--c--- c:\windows\system32\dllcache\msdvbnp.ax
2009-01-21 23:19 . 2004-08-04 00:56 33,280 --a------ c:\windows\system32\psisrndr.ax
2009-01-21 23:19 . 2004-08-04 00:56 33,280 --a--c--- c:\windows\system32\dllcache\psisrndr.ax
2009-01-20 13:11 . 2009-01-20 13:11 <DIR> d-------- c:\program files\BearShare
2009-01-20 13:11 . 2009-02-03 19:38 <DIR> d-------- C:\My Downloads
2009-01-17 17:51 . 2009-01-17 17:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-01-17 17:46 . 2009-01-17 17:46 <DIR> d-------- c:\program files\FaxTools
2009-01-17 17:46 . 2009-01-17 17:46 <DIR> d-------- c:\program files\ABBYY FineReader 6.0
2009-01-17 17:46 . 2009-01-17 17:46 <DIR> d-------- c:\program files\ABBYY FineReader 5.0 Sprint
2009-01-17 17:46 . 2009-01-17 17:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\BVRP Software
2009-01-17 17:44 . 2009-01-17 17:45 <DIR> d-------- c:\program files\Lexmark 1200 Series
2009-01-17 17:44 . 2006-01-12 05:32 983,107 --a------ c:\windows\system32\LXCZGF.DLL
2009-01-17 17:44 . 2006-07-13 06:22 458,752 --a------ c:\windows\system32\LXCZJSWR.DLL
2009-01-17 17:44 . 2006-07-13 06:17 356,352 --a------ c:\windows\system32\LXCZUTIL.DLL
2009-01-17 17:44 . 2006-07-13 06:45 69,632 --a------ c:\windows\system32\lxczscin.dll
2009-01-17 17:44 . 2006-07-13 06:45 57,344 --a------ c:\windows\system32\lxczcinf.dll
2009-01-17 17:44 . 2006-07-13 06:45 49,152 --a------ c:\windows\system32\lxczcoin.dll
2009-01-17 17:44 . 2006-01-30 13:42 270 --a------ c:\windows\system32\lxczcoin.ini
2009-01-17 17:36 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-01-17 17:36 . 2004-08-03 23:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2009-01-16 16:02 . 2009-02-02 20:42 <DIR> d-------- C:\DVDVideoSoft
2009-01-15 17:01 . 2009-01-25 12:57 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-15 17:01 . 2009-01-15 17:01 1,409 --a------ c:\windows\QTFont.for
2009-01-14 16:41 . 2009-01-14 16:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\CyberLink
2009-01-14 16:41 . 2009-01-14 16:41 <DIR> d-------- c:\documents and settings\Admin\Application Data\CyberLink
2009-01-14 16:16 . 2009-01-14 16:16 <DIR> d-------- c:\program files\DVDVideoSoft
2009-01-14 16:16 . 2009-01-14 16:17 <DIR> d-------- c:\program files\Common Files\DVDVideoSoft
2009-01-14 15:20 . 2009-01-27 14:53 59 --a------ c:\windows\cdplayer.ini
2009-01-14 14:37 . 2009-01-14 14:41 <DIR> d-------- c:\program files\Winamp
2009-01-14 14:37 . 2009-01-14 14:44 <DIR> d-------- c:\documents and settings\Admin\Application Data\Winamp
2009-01-13 22:05 . 2009-01-13 22:06 <DIR> d-------- c:\program files\Internet Jamb Klub
2009-01-13 22:05 . 2009-01-13 22:05 720,896 --a------ c:\windows\iun6002.exe
2009-01-13 21:58 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2009-01-13 21:58 . 2001-08-17 14:02 9,600 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-01-13 21:40 . 2001-03-06 18:05 4,358,144 -ra------ c:\windows\uncsetup.exe
2009-01-13 21:27 . 2008-10-27 14:38 2,362 --a------ C:\ma477.bin
2009-01-13 20:34 . 2009-01-13 20:34 <DIR> d-------- c:\documents and settings\Admin\Application Data\ACD Systems
2009-01-13 20:30 . 2009-02-02 20:52 <DIR> d-------- c:\documents and settings\Admin\Application Data\Wildfire
2009-01-13 20:30 . 2009-01-13 20:30 4,096 --a------ c:\windows\d3dx.dat
2009-01-13 19:39 . 2008-01-07 14:29 352 --ah----- c:\windows\nod32fixtemdono.reg
2009-01-13 19:38 . 2009-01-13 19:38 <DIR> d-------- c:\documents and settings\Admin\Application Data\ESET
2009-01-13 19:37 . 2009-01-13 19:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2009-01-13 19:36 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2009-01-13 19:24 . 2009-01-13 19:24 <DIR> d-------- c:\documents and settings\Admin\Application Data\Media Player Classic
2009-01-13 19:24 . 2009-01-29 17:38 69 --a------ c:\windows\NeroDigital.ini
2009-01-13 19:19 . 2009-01-13 19:19 <DIR> d-------- c:\windows\system32\RTCOM
2009-01-13 19:19 . 2006-07-12 16:50 146,048 --a------ c:\windows\system32\drivers\portcls.sys
2009-01-13 19:19 . 2004-08-04 01:56 130,048 --a------ c:\windows\system32\ksproxy.ax
2009-01-13 19:19 . 2004-08-04 00:08 60,288 --a------ c:\windows\system32\drivers\drmk.sys
2009-01-13 19:19 . 2004-08-03 23:59 57,472 --a------ c:\windows\system32\drivers\redbook.sys
2009-01-13 19:19 . 2004-08-04 01:56 4,096 --a------ c:\windows\system32\ksuser.dll
2009-01-13 19:18 . 2009-01-13 19:18 <DIR> d-------- c:\windows\Motorola
2009-01-13 19:18 . 2004-08-04 01:56 74,240 --a------ c:\windows\system32\usbui.dll
2009-01-13 19:18 . 2009-01-13 19:18 0 --a------ c:\windows\ativpsrm.bin
2009-01-13 19:13 . 2009-01-13 18:25 <DIR> dr------- c:\documents and settings\All Users\Documents
2009-01-13 19:12 . 2002-12-31 13:00 2,012,670 --a--c--- c:\windows\system32\dllcache\NT5.CAT
2009-01-13 19:11 . 2009-02-05 14:25 <DIR> d-------- c:\windows\system32\CatRoot2
2009-01-13 19:11 . 2009-01-13 19:11 <DIR> d-------- c:\windows\system32\CatRoot
2009-01-13 19:11 . 2002-12-31 13:00 1,086,058 -ra------ c:\windows\SET4.tmp
2009-01-13 19:11 . 2002-12-31 13:00 1,042,903 -ra------ c:\windows\SET3.tmp
2009-01-13 19:11 . 2002-12-31 13:00 13,753 -ra------ c:\windows\SET8.tmp
2009-01-13 19:10 . 2005-01-11 13:25 923,826 --a------ c:\windows\system32\drivers\smserial.sys
2009-01-13 19:10 . 2004-12-29 12:01 544,768 --a------ c:\windows\sm56hlpr.exe
2009-01-13 19:10 . 2004-12-29 12:01 73,728 --a------ c:\windows\system32\sm56co.dll
2009-01-13 19:10 . 2004-11-02 16:12 65,536 --a------ c:\windows\sm56spn.dll
2009-01-13 19:10 . 2004-11-02 16:12 65,536 --a------ c:\windows\sm56itl.dll
2009-01-13 19:10 . 2004-11-02 16:12 65,536 --a------ c:\windows\sm56ger.dll
2009-01-13 19:10 . 2004-11-02 16:12 65,536 --a------ c:\windows\sm56fra.dll
2009-01-13 19:10 . 2004-11-10 10:42 65,536 --a------ c:\windows\sm56eng.dll
2009-01-13 19:10 . 2004-11-02 16:12 65,536 --a------ c:\windows\sm56brz.dll
2009-01-13 19:10 . 2004-11-10 10:42 49,152 --a------ c:\windows\sm56jpn.dll
2009-01-13 19:10 . 2004-11-10 10:42 45,056 --a------ c:\windows\sm56cht.dll
2009-01-13 19:10 . 2004-11-11 07:16 45,056 --a------ c:\windows\sm56chs.dll
2009-01-13 19:07 . 2008-01-29 21:47 16,859,648 --a------ c:\windows\RTHDCPL.EXE
2009-01-13 19:07 . 2007-03-24 01:19 9,715,200 --a------ c:\windows\RTLCPL.EXE
2009-01-13 19:07 . 2008-01-30 17:28 4,725,760 --a------ c:\windows\system32\drivers\RtkHDAud.sys
2009-01-13 19:07 . 2006-05-04 22:26 2,808,832 --a------ c:\windows\ALCWZRD.EXE
2009-01-13 19:07 . 2007-06-28 22:44 2,165,760 --a------ c:\windows\MicCal.exe
2009-01-13 19:07 . 2007-11-21 00:15 1,826,816 --a------ c:\windows\SkyTel.exe
2009-01-13 19:07 . 2007-11-07 23:31 1,191,936 --a------ c:\windows\RtlUpd.exe
2009-01-13 19:07 . 2005-09-21 16:25 299,008 --a------ c:\windows\system32\ALSNDMGR.CPL
2009-01-13 19:07 . 2006-08-18 12:58 282,624 --a------ c:\windows\system32\RTSndMgr.CPL
2009-01-13 19:07 . 2006-07-21 22:14 86,016 --a------ c:\windows\SOUNDMAN.EXE
2009-01-13 19:07 . 2005-05-04 00:43 69,632 --a------ c:\windows\ALCMTR.EXE
2009-01-13 19:06 . 2007-07-12 16:49 96,384 --a------ c:\windows\system32\drivers\Rtnicxp.sys
2009-01-13 19:03 . 2008-01-22 21:14 3,107,788 --a------ c:\windows\system32\ativvaxx.dat
2009-01-13 19:03 . 2008-01-22 21:14 3,107,788 --a------ c:\windows\system32\ativva5x.dat
2009-01-13 19:03 . 2008-01-22 21:14 887,724 --a------ c:\windows\system32\ativva6x.dat
2009-01-13 19:03 . 2008-01-22 21:34 512,000 --a------ c:\windows\system32\ati2evxx.exe
2009-01-13 19:03 . 2008-01-07 15:43 165,782 --a------ c:\windows\system32\atiicdxx.dat
2009-01-13 19:03 . 2006-06-19 04:37 36,864 --a------ c:\windows\system32\drivers\AmdK8.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-01 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-27 13:49 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-01-21 15:49 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-17 16:46 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-13 19:35 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-13 19:30 --------- d-----w c:\program files\Tumblebugs
2009-01-13 18:37 --------- d-----w c:\program files\Eset
2009-01-13 17:55 --------- d-----w c:\program files\PerformanceTest
2009-01-13 17:55 --------- d-----w c:\program files\Common Files\Ahead
2009-01-13 17:55 --------- d-----w c:\program files\Ahead
2009-01-13 17:54 --------- d-----w c:\program files\Microsoft Works
2009-01-13 17:54 --------- d-----w c:\program files\CyberLink
2009-01-13 17:50 --------- d-----w c:\program files\Common Files\ACD Systems
2009-01-13 17:50 --------- d-----w c:\program files\ACD Systems
2009-01-13 17:50 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-01-13 17:49 --------- d-----w c:\program files\MrDicty 2000
2009-01-13 17:46 --------- d-----w c:\program files\SM
2009-01-13 17:46 --------- d-----w c:\program files\Jooleem
2009-01-13 17:46 --------- d-----w c:\program files\EverestUltimatePortable
2009-01-13 17:46 --------- d-----w c:\program files\Audiograbber
2009-01-13 17:43 --------- d-----w c:\program files\microsoft frontpage
2009-01-13 17:42 --------- d-----w c:\program files\Real Alternative
2009-01-13 17:42 --------- d-----w c:\program files\QuickTime Alternative
2009-01-13 17:42 --------- d-----w c:\program files\K-Lite Codec Pack
2009-01-13 17:42 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-13 17:41 --------- d-----w c:\program files\Webteh
2009-01-13 17:41 --------- d-----w c:\program files\Utilities
2009-01-13 17:41 --------- d-----w c:\program files\Java
2009-01-13 17:41 --------- d-----w c:\program files\Common Files\Java
2009-01-13 17:40 --------- d-----w c:\program files\Lavasoft
2009-01-13 17:40 --------- d-----w c:\program files\Common Files\Adobe
2009-01-13 17:29 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-13 17:23 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-13 17:23 --------- d-----w c:\program files\NeoSmart Technologies
2009-01-13 17:23 --------- d-----w c:\program files\DVD Shrink
2009-01-13 17:23 --------- d-----w c:\program files\DVD Decrypter
.
------- Sigcheck -------
2002-12-31 13:00 360832 ce3ec03c9f65302e44af5c452d20a86f c:\windows\system32\drivers\tcpip.sys
2002-12-31 13:00 502272 6225f14b8ce08ccba8b25ad27843c674 c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"BearShare"="c:\program files\BearShare\BearShare.exe" [2005-11-17 3223552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2002-12-31 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [2002-12-31 119808]
R2 ekrn;Eset Service;c:\program files\Eset\ESET Smart Security\ekrn.exe [2007-12-21 468224]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASPI32
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BlazeServoTool - c:\program files\HDTVPlayer\BlazeDTV 3.5\MediaDetector.exe
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchMigratedDefaultURL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-05 14:26:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(964)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-05 14:27:16
ComboFix-quarantined-files.txt 2009-02-05 13:27:14
Pre-Run: 45,600,722,944 bytes free
Post-Run: 45,654,876,160 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
285
|