offline
- gucijan
- Novi MyCity građanin
- Pridružio: 27 Sep 2008
- Poruke: 5
|
evo, nisam ni znao da je isključivanje "zaštite" teže no uključivanje
ComboFix 09-05-04.A0 - Administrator 06.05.2009 17:38.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.1023.504 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\1doc2pdf.dll
c:\windows\n.tmp
c:\windows\system32\msconfig.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-06 to 2009-05-06 )))))))))))))))))))))))))))))))
.
2009-05-05 15:50 . 2009-05-05 15:50 -------- d-----w c:\program files\Common Files\ABBYY
2009-05-05 15:38 . 2008-05-16 03:51 -------- d-----w C:\FR90PE_VOL
2009-05-05 15:18 . 2008-06-30 21:04 -------- d-----w c:\temp\afr_www.(zabranjeno)rocker.net
2009-05-05 13:02 . 2009-05-05 13:02 32256 ----a-w c:\windows\system32\goe.exe
2009-05-05 13:02 . 2009-05-05 13:02 32256 ---h--w c:\documents and settings\Administrator\smw.exe
2009-05-05 11:00 . 2009-05-05 11:00 -------- d-----w c:\documents and settings\Administrator\Application Data\ABBYY
2009-05-05 10:51 . 2009-05-05 15:44 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\ABBYY
2009-05-05 10:51 . 2009-05-05 10:51 -------- d-----w c:\documents and settings\All Users\Application Data\ABBYY
2009-05-05 10:51 . 2009-05-05 17:46 -------- d-----w c:\program files\ABBYY FineReader 9.0
2009-05-04 17:35 . 2009-05-04 17:35 -------- d-----w c:\temp\KTS
2009-04-29 17:07 . 2009-04-29 17:07 -------- d-----w c:\program files\Western Digital Technologies
2009-04-29 15:59 . 2009-04-29 15:59 -------- d-sh--w c:\documents and settings\Default User\IETldCache
2009-04-29 08:25 . 2009-04-29 08:25 -------- d-----w c:\documents and settings\All Users\Application Data\CanonCP
2009-04-28 16:59 . 2009-04-28 16:59 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-26 21:29 . 2009-04-26 21:29 -------- d-----w c:\temp\CrashDumps
2009-04-26 21:27 . 2009-04-26 21:27 -------- d-----w c:\windows\ClearView plug-in activation
2009-04-26 21:25 . 2009-04-26 21:25 -------- d-----w c:\windows\Echo Wave II
2009-04-26 21:25 . 2009-04-26 21:25 -------- d-----w C:\Echo Images
2009-04-22 17:33 . 2009-04-22 17:33 -------- d-----w C:\crtani dvd 90
2009-04-22 08:41 . 2009-04-22 08:41 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-04-21 15:01 . 2009-04-21 15:01 -------- d-sh--w c:\documents and settings\Administrator\IECompatCache
2009-04-14 20:23 . 2009-04-14 21:13 -------- d-----w c:\windows\SxsCaPendDel
2009-04-14 20:13 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-14 20:13 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-14 20:13 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 20:13 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-14 20:13 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 20:13 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 20:13 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 20:13 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 20:13 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 20:13 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 19:52 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-14 19:52 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-13 21:46 . 2009-04-13 21:47 -------- d-----w c:\windows\system32\ECGIII
2009-04-13 21:24 . 2009-04-13 21:28 -------- d-----w c:\temp\uz srca barcelona
2009-04-13 21:15 . 2009-04-13 21:15 -------- d-----w c:\temp\0491 Thrombosis
2009-04-13 21:14 . 2009-04-13 21:14 -------- d-----w c:\temp\0304 GryAna39
2009-04-11 21:23 . 2009-04-11 21:23 -------- d-sh--w c:\documents and settings\Administrator\PrivacIE
2009-04-11 21:13 . 2009-04-11 21:13 -------- d-----w c:\documents and settings\Administrator\Application Data\ESET
2009-04-11 20:56 . 2009-04-11 20:56 -------- d-sh--w c:\documents and settings\Administrator\IETldCache
2009-04-11 20:50 . 2009-04-11 20:50 -------- d-----w c:\windows\ie8updates
2009-04-11 20:47 . 2009-04-11 20:48 -------- dc-h--w c:\windows\ie8
2009-04-11 20:44 . 2009-02-28 04:55 105984 ------w c:\windows\system32\dllcache\iecompat.dll
2009-04-11 20:00 . 2009-04-11 20:00 -------- d-----w c:\program files\Windows Defender
2009-04-06 20:43 . 2001-10-28 23:42 116224 ----a-w c:\windows\system32\pdfmonnt.dll
2009-04-06 20:43 . 2009-04-06 20:43 -------- d-----w c:\program files\8848Soft
2009-04-06 20:43 . 2009-04-06 20:43 -------- d-----w c:\windows\system32\psconv
2009-04-06 20:43 . 2009-04-06 20:43 -------- d-----w c:\program files\psconvert
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-06 15:42 . 2008-07-20 22:10 -------- d-----w c:\program files\FlashGet
2009-05-05 22:13 . 2009-01-03 22:46 -------- d-----w c:\program files\Common Files\Adobe
2009-05-05 14:22 . 2008-09-27 18:17 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-29 08:51 . 2009-01-02 17:54 8456 --sha-w c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-04-26 22:00 . 2009-04-26 22:00 0 ----a-w C:\sys1335.tmp
2009-04-14 21:32 . 2009-03-28 09:11 566784 ----a-w c:\windows\~de74bc.tmp
2009-04-14 21:16 . 2008-07-21 13:40 107776 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-09 21:19 . 2008-09-27 13:42 -------- d-----w c:\program files\Java
2009-04-01 14:45 . 2009-04-01 14:45 -------- d-----w c:\program files\eRightSoft
2009-04-01 10:57 . 2009-04-01 10:57 -------- d-----w c:\program files\mkvtoavis
2009-03-29 10:15 . 2009-03-29 10:15 -------- d-----w c:\program files\Common Files\Autodata Limited Shared
2009-03-28 10:31 . 2009-03-28 10:31 565248 ----a-w c:\windows\uninstal.exe
2009-03-28 08:47 . 2009-01-28 22:07 249856 ------w c:\windows\Setup1.exe
2009-03-28 08:47 . 2009-01-28 22:07 73216 ----a-w c:\windows\ST6UNST.EXE
2009-03-27 09:16 . 2008-12-04 22:22 -------- d-----w c:\program files\Nokia
2009-03-27 07:41 . 2008-12-04 22:23 -------- d-----w c:\program files\Common Files\Nokia
2009-03-26 10:52 . 2008-09-21 21:49 35328 ----a-w c:\windows\system32\cygz.dll
2009-03-26 10:52 . 2008-09-21 21:49 35328 ----a-w c:\windows\cygz.dll
2009-03-26 10:52 . 2008-09-21 21:49 1126281 ----a-w c:\windows\system32\cygwin1.dll
2009-03-26 10:52 . 2008-09-21 21:49 1126281 ----a-w c:\windows\cygwin1.dll
2009-03-25 22:24 . 2009-03-25 22:24 -------- d-----w c:\program files\Common Files\PCSuite
2009-03-25 22:23 . 2009-03-25 22:23 -------- d-----w c:\program files\PC Connectivity Solution
2009-03-19 15:02 . 2009-03-19 15:02 -------- d-----w c:\program files\PowerISO
2009-03-17 09:43 . 2008-07-17 08:28 630784 ----a-w c:\windows\system32\Usgfw2.dll
2009-03-09 03:19 . 2009-02-20 22:25 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 02:34 . 2008-05-06 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2008-05-06 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2008-05-06 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2008-05-06 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2008-05-06 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2008-05-06 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2008-05-06 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2008-05-06 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2008-05-06 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2008-05-06 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2008-05-06 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-27 09:13 . 2008-07-17 08:28 380928 ----a-w c:\windows\system32\Usgfw.dll
2009-02-09 12:10 . 2008-05-06 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2008-05-06 12:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2008-05-06 12:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2008-05-06 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2008-05-06 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 06:37 . 2009-03-27 07:44 7808 ----a-w c:\windows\system32\usbser_lowerfltj.sys
2009-02-09 06:37 . 2009-03-27 07:44 659968 ----a-w c:\windows\system32\nmwcdcocls.dll
2009-02-09 06:37 . 2009-03-27 07:44 7808 ----a-w c:\windows\system32\usbser_lowerflt.sys
2009-02-09 06:37 . 2008-12-04 22:22 91136 ----a-w c:\windows\system32\nmwcdcls.dll
2009-02-09 06:37 . 2009-03-27 07:44 22016 ----a-w c:\windows\system32\drivers\ccdcmbo.sys
2009-02-09 06:37 . 2009-03-27 07:44 17664 ----a-w c:\windows\system32\drivers\ccdcmb.sys
2009-02-09 06:32 . 2009-03-27 07:44 1112288 ----a-w c:\windows\system32\wdfcoinstaller01007.dll
2009-02-07 17:02 . 2008-04-13 23:01 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 12:24 . 2009-02-06 12:24 56280 ----a-w c:\windows\system32\drivers\epfwtdi.sys
2009-02-06 12:24 . 2009-02-06 12:24 33096 ----a-w c:\windows\system32\drivers\epfwndis.sys
2009-02-06 12:24 . 2009-02-06 12:24 130952 ----a-w c:\windows\system32\drivers\epfw.sys
2009-02-06 12:23 . 2009-02-06 12:23 106208 ----a-w c:\windows\system32\drivers\ehdrv.sys
2009-02-06 12:19 . 2009-02-06 12:19 113448 ----a-w c:\windows\system32\drivers\eamon.sys
2009-02-06 11:11 . 2008-05-06 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2008-05-06 12:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2008-05-06 12:00 35328 ----a-w c:\windows\system32\sc.exe
2008-05-05 20:14 . 2008-07-20 19:44 34048 ----a-w c:\program files\opera\program\plugins\upd62i9x.dll
2008-05-05 20:14 . 2008-07-20 19:44 45056 ----a-w c:\program files\opera\program\plugins\upd62int.dll
.
------- Sigcheck -------
[-] 2008-02-29 14:28 57856 7435B108B935E42EA92CA94F59C8E717 c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"PWSActivePrint_5"="c:\program files\Pocket Watch LLC\ActivePrint System\ActivePrintSystem.exe" [2007-11-23 312832]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-11-23 1247232]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-18 4804608]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2007-05-22 405504]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-06-29 1990704]
"VX1000"="c:\windows\vVX1000.exe" [2008-08-04 721936]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2008-08-18 16712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-02-25 77824]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 167936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-11-18 323584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-7-22 1205840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"StartMenuFavorites"= 0 (0x0)
"Start_ShowMyComputer"= 1 (0x1)
"Start_ShowMyDocs"= 1 (0x1)
"Start_ShowMyMusic"= 0 (0x0)
"Start_ShowRun"= 1 (0x1)
"Start_ShowSearch"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Pocket Watch LLC\\ActivePrint System\\ActivePrintSystem.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\goe.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 14:23 106208]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 14:23 727720]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [22.7.2008 11:51 104344]
R3 EMCR;EMCR;c:\windows\system32\drivers\EMCR7SK.sys [15.8.2003 16:10 68480]
R3 ParadigmVScanner;USB Scanner Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [10.8.2008 15:49 15104]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [10.8.2008 17:50 9446]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [22.7.2008 11:51 69656]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [6.5.2008 14:00 3584]
S3 AVHybrid;AVHybrid service;c:\windows\system32\drivers\AVHybrid.sys [25.3.2009 15:41 1013760]
S3 CrystalSysInfo;CrystalSysInfo;\??\c:\program files\MediaCoder\SysInfo.sys --> c:\program files\MediaCoder\SysInfo.sys [?]
S3 XRNBO;XRNBO;c:\windows\system32\drivers\XRNBO.sys [4.12.2008 23:19 177152]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder
2009-05-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2009-05-06 c:\windows\Tasks\User_Feed_Synchronization-{FFBE3C03-DF8C-4774-A1E5-455995A21427}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AnalogClock - c:\program files\ENT\Analog Clock\AnalogClock.exe
HKCU-Run-TopDesk - c:\program files\ENT\TopDesk\topdesk.exe
HKCU-Run-TrueTransparency - c:\program files\ENT\TrueTransparency\TrueTransparency.exe
HKCU-Run-UberIcon - c:\program files\ENT\UberIcon\UberIcon Manager.exe
HKCU-Run-Visual Task Tips - c:\program files\ENT\VisualTaskTips\VisualTaskTips.exe
HKCU-Run-RocketDock - c:\program files\RocketDock\RocketDock.exe
HKLM-Run-KRun - c:\program files\ENT\RunMe\RunMe.exe
HKLM-Run-Remote - c:\program files\TVR\Remote.exe
HKLM-Run-RecSche - c:\program files\TVR\RecSche.exe
HKLM-Run-WinampAgent - c:\program files\WinampPortable\App\Winamp\winampa.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
IE: &Preuzmi sa FlashGet-om - c:\program files\FlashGet\jc_link.htm
IE: &Preuzmi sve sa FlashGet-om - c:\program files\FlashGet\jc_all.htm
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - [Link mogu videti samo ulogovani korisnici]
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\7avlwnf1.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-05-06 17:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Remote = c:\program files\TVR\Remote.exe??????????????????????????????????????????????????????????????????????????????????????
???????????????????????????????????????????????????????????????????????????????????????????????????
???????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1202660629-1788223648-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,01,06,38,22,10,ec,41,97,16,a8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,01,06,38,22,10,ec,41,97,16,a8,\
.
Completion time: 2009-05-06 17:45
ComboFix-quarantined-files.txt 2009-05-06 15:45
Pre-Run: 18.360.311.808 bytes free
Post-Run: 18.830.381.056 bytes free
290 --- E O F --- 2009-05-05 00:12
|