racunar odjednom veoma uspori pregrejava se i stalno pojaviljvanje prozora not responding...

racunar odjednom veoma uspori pregrejava se i stalno pojaviljvanje prozora not responding...

offline
  • sojic1 
  • Novi MyCity građanin
  • Pridružio: 27 Jul 2011
  • Poruke: 25

racunar mi je bio veoma usporen sve zivo je seckalo cak i strelica misa nasao sam neke savete na vasem sajtu i neke progarme koje sam koristio i sad je malo bolje ponekad radi normalno ali ponekad samo odjednom prestane da radi kako treba sve zivo secka kad pokrenem bilo koju igricu pojavljuje se prozor not responding igricu najvise mogu da igram do sat vremena jer se veoma brzo ugreje i ugasi se cak sam iznova podigao windovs i formatirao ceo racunar ali dzaba....
problem se poceo ispoljavati od pre 3 sedmice celo vreme
sam pokusavao da nadjem nesto na netu sto ce mi pomoci ali sve sto sam pokusao nije vredelo...
pokusao sam da resim problem sa combofix-om skenirao sam sve sa ccleanerom defragmentavao koristio sam i hijackthis i skenirao sa spybotom i sa ad -awareom i sa advanced care i izbrisao skoro instalirane programe izbrisao temp fajlove itd...
imam adsl 4mbg...
okacicu i report to sam dobio skeniranjem neki programom sa vaseg sajta
hvala unapred
DDS file>>>>>

.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Korisnik at 14:09:46 on 2011-08-22
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3063.1974 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_94cb740f1febe83e\STacSV.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_94cb740f1febe83e\aestsrv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Korisnik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Korisnik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Korisnik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Korisnik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Korisnik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Korisnik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mif5ba~1\office14\URLREDIR.DLL
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\mif5ba~1\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{00F00BD5-4A8D-40E1-8AEC-42E54A3CEC07} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{00F00BD5-4A8D-40E1-8AEC-42E54A3CEC07}\144667562747160234F6D60757475627023586F607 : DhcpNameServer = 89.216.1.40 89.216.1.50
TCP: Interfaces\{E046E886-C11F-47D9-8BFF-F4AEC2D1EA15} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKslffdcd29c;MpKslffdcd29c;c:\programdata\microsoft\microsoft antimalware\definition updates\{6f291e02-2f60-439a-b0fa-4c3df56939a2}\MpKslffdcd29c.sys [2011-8-22 28752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_94cb740f1febe83e\AEstSrv.exe [2011-7-27 81920]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-3-9 172032]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-3-10 5341696]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-3-9 152064]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2011-7-27 227896]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-6-23 275048]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 540D4421;540D4421;c:\windows\system32\540d4421.exe --> c:\windows\system32\540D4421.exe [?]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
.
=============== Created Last 30 ================
.
2011-08-22 08:06:28 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6f291e02-2f60-439a-b0fa-4c3df56939a2}\MpKslffdcd29c.sys
2011-08-22 08:06:18 7152464 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6f291e02-2f60-439a-b0fa-4c3df56939a2}\mpengine.dll
2011-08-17 09:22:52 439632 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-08-17 09:22:50 439632 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6b9861fd-eb0e-4213-9e7f-aed4f653d42a}\gapaengine.dll
2011-07-29 14:16:12 -------- d-----w- c:\users\korisnik\appdata\local\GHISLER
2011-07-28 22:41:57 -------- d-----w- c:\programdata\KONAMI
2011-07-28 21:48:56 -------- d-----w- c:\program files\BitTorrent
2011-07-28 21:48:24 -------- d-----w- c:\users\korisnik\appdata\roaming\BitTorrent
2011-07-28 19:18:50 -------- d-----w- c:\program files\Franzis
2011-07-28 08:01:23 7152464 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-07-27 19:47:31 -------- d-sh--w- C:\$RECYCLE.BIN
2011-07-27 18:41:07 98816 ----a-w- c:\windows\sed.exe
2011-07-27 18:41:07 518144 ----a-w- c:\windows\SWREG.exe
2011-07-27 18:41:07 256000 ----a-w- c:\windows\PEV.exe
2011-07-27 18:41:07 208896 ----a-w- c:\windows\MBR.exe
2011-07-27 18:09:39 -------- d-----w- c:\users\korisnik\appdata\local\Adobe
2011-07-27 18:03:05 -------- d-----w- c:\users\korisnik\appdata\local\ElevatedDiagnostics
2011-07-27 16:21:18 -------- d-----w- c:\windows\Panther
2011-07-27 08:53:37 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-07-27 08:53:24 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-07-27 08:53:14 -------- d-----w- c:\users\korisnik\appdata\roaming\DAEMON Tools Lite
2011-07-27 08:53:14 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-07-27 08:52:07 -------- d-----w- c:\program files\CCleaner
2011-07-27 08:51:40 545 ----a-w- c:\windows\UC.PIF
2011-07-27 08:51:40 545 ----a-w- c:\windows\RAR.PIF
2011-07-27 08:51:40 545 ----a-w- c:\windows\PKZIP.PIF
2011-07-27 08:51:40 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-07-27 08:51:40 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-07-27 08:51:40 545 ----a-w- c:\windows\LHA.PIF
2011-07-27 08:51:40 545 ----a-w- c:\windows\ARJ.PIF
2011-07-27 08:51:39 -------- d-----w- c:\users\korisnik\appdata\roaming\GHISLER
2011-07-27 08:51:39 -------- d-----w- C:\totalcmd
2011-07-27 08:50:03 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2011-07-27 08:50:03 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2011-07-27 08:50:03 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2011-07-27 08:50:03 258048 ----a-w- c:\windows\system32\imagXR7.dll
2011-07-27 08:50:02 1757184 ----a-w- c:\windows\system32\imagX7.dll
2011-07-27 08:50:02 -------- d-----w- c:\programdata\Nero
2011-07-27 08:50:02 -------- d-----w- c:\program files\Nero
2011-07-27 08:48:48 -------- d-----w- c:\program files\GRETECH
2011-07-27 08:48:02 -------- d-----w- c:\program files\VideoLAN
2011-07-27 08:47:46 175616 ----a-w- c:\windows\system32\unrar.dll
2011-07-27 08:47:42 232448 ----a-w- c:\windows\system32\mp3fhg.acm
2011-07-27 08:47:42 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-07-27 08:47:41 631808 ----a-w- c:\windows\system32\xvidcore.dll
2011-07-27 08:47:41 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2011-07-27 08:47:41 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2011-07-27 08:47:40 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-07-27 08:47:36 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-07-27 08:47:04 -------- d-----w- c:\users\korisnik\appdata\roaming\foobar2000
2011-07-27 08:46:57 -------- d-----w- c:\program files\foobar2000
2011-07-27 08:45:49 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-07-27 08:45:48 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2011-07-27 08:45:25 -------- d-----w- c:\program files\common files\PX Storage Engine
2011-07-27 08:07:29 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-07-27 08:07:01 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-27 08:06:02 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-07-27 08:05:25 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-07-27 08:05:09 -------- d-----w- c:\users\korisnik\appdata\local\Microsoft Help
2011-07-27 08:03:51 -------- d-----w- c:\users\korisnik\appdata\roaming\ACD Systems
2011-07-27 08:03:51 -------- d-----w- c:\users\korisnik\appdata\local\ACD Systems
2011-07-27 08:00:08 -------- d-----w- c:\programdata\ACD Systems
2011-07-27 07:59:56 -------- d-----w- c:\program files\common files\ACD Systems
2011-07-27 07:59:56 -------- d-----w- c:\program files\ACD Systems
2011-07-27 07:59:30 -------- d-----w- c:\users\korisnik\appdata\local\Downloaded Installations
2011-07-27 07:48:28 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-27 07:45:30 -------- d-----w- c:\users\korisnik\appdata\local\Google
2011-07-27 07:42:13 -------- d-----r- c:\program files\Skype
2011-07-27 07:41:44 -------- d-----w- c:\users\korisnik\Tracing
2011-07-27 07:39:37 6260088 ----a-w- c:\program files\common files\windows live\.cache\555748f91cc4c300d\Silverlight.4.0.exe
2011-07-27 07:39:13 -------- d-----w- c:\users\korisnik\appdata\local\Windows Live
2011-07-27 07:39:12 -------- d-----w- c:\program files\common files\Windows Live
2011-07-27 07:35:57 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-27 07:34:36 -------- d-----w- c:\users\korisnik\appdata\local\ATI
2011-07-27 07:32:48 -------- d-----w- c:\program files\ATI Technologies
2011-07-27 07:32:47 -------- d-----w- c:\program files\ATI
2011-07-27 07:26:44 -------- d-----w- c:\users\korisnik\appdata\roaming\hpqLog
2011-07-27 07:26:18 15872 ----a-w- c:\windows\system32\drivers\HpqKbFiltr.sys
2011-07-27 07:26:18 1419232 ----a-w- c:\windows\system32\drivers\wdfcoinstaller01005.dll
2011-07-27 07:26:17 1885488 ----a-w- c:\windows\system32\BttnCmns.dll
2011-07-27 07:26:17 1863680 ----a-w- c:\windows\system32\BttnCmn.dll
2011-07-27 07:20:58 -------- d-----w- C:\swsetup
2011-07-27 07:17:58 -------- d-----w- c:\program files\HP
2011-07-27 07:17:41 -------- d-----w- c:\windows\Downloaded Installations
2011-07-27 07:06:11 60416 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-27 07:06:11 393728 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-27 06:55:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-27 06:55:07 141104 ----a-w- c:\program files\internet explorer\sqmapi.dll
2011-07-27 06:55:06 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-27 06:53:30 -------- d-----w- c:\program files\Microsoft IntelliPoint
2011-07-27 06:53:25 -------- d-----w- c:\windows\PCHEALTH
2011-07-27 06:53:23 -------- d-sh--w- c:\windows\Installer
2011-07-27 06:43:44 6881616 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{91ff468b-1599-4c17-9db1-9b33ccfdddbd}\mpengine.dll
2011-07-27 06:43:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-27 06:43:03 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-07-27 06:43:03 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-07-27 06:43:03 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-27 06:43:03 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-27 06:43:02 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-07-27 06:43:02 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-07-27 06:43:01 271872 ----a-w- c:\windows\system32\conhost.exe
2011-07-27 06:43:01 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-27 06:43:00 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-07-27 06:38:13 0 ----a-w- c:\windows\ativpsrm.bin
.
==================== Find3M ====================
.
2011-06-11 02:29:25 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-06-03 05:59:23 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-06-03 03:48:32 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 14:10:10.98 ===============

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Pozdrav!






ComboFix nije dijagnosticki alat kao ovi iz uputstva. To je jako mocan alat, koji nepravilnim rukovanjem, moze unistiti operativni sistem ili pak obrisati sve padatke sa hard diska. Pokrece se iskljucivo uz predlog, nadleznost i detaljno uputstvo helpera koji je expert u toj oblasti i zna sta radi.

Za ubuduce, ne pokreci ComboFix na svoju ruku!!!






Arrow


Postavi mi ComboFix izvestaj da pogledam.
Izvestaj se nalazi na sledecoj lokaciji: C:\ComboFix.txt









goran9888 (AMF Tim)

offline
  • sojic1 
  • Novi MyCity građanin
  • Pridružio: 27 Jul 2011
  • Poruke: 25

evo

ComboFix 11-07-27.02 - Korisnik 07/27/2011 21:43:30.2.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3063.2234 [GMT 2:00]
Running from: c:\users\Korisnik\Desktop\ComboFix.exe
Command switches used :: c:\users\Korisnik\Desktop\CFScript.txt.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-27 to 2011-07-27 )))))))))))))))))))))))))))))))
.
.
2011-07-27 19:46 . 2011-07-27 19:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-27 19:09 . 2011-07-12 18:39 6881616 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7FEDDF0D-9756-48B5-A7DD-77E8140EBAC7}\mpengine.dll
2011-07-27 16:21 . 2011-07-27 06:29 -------- d-----w- c:\windows\Panther
2011-07-27 08:53 . 2011-07-27 08:53 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-07-27 08:53 . 2011-07-27 08:53 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-07-27 08:53 . 2011-07-27 08:53 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-07-27 08:52 . 2011-07-27 08:52 -------- d-----w- c:\program files\CCleaner
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\UC.PIF
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\RAR.PIF
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\PKZIP.PIF
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\LHA.PIF
2011-07-27 08:51 . 2006-10-31 05:00 545 ----a-w- c:\windows\ARJ.PIF
2011-07-27 08:51 . 2011-07-27 08:51 -------- d-----w- C:\totalcmd
2011-07-27 08:51 . 2011-07-27 08:51 -------- d-----w- c:\program files\7-Zip
2011-07-27 08:50 . 2006-03-17 13:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2011-07-27 08:50 . 2006-03-17 10:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2011-07-27 08:50 . 2006-03-17 10:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2011-07-27 08:50 . 2006-03-17 10:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2011-07-27 08:50 . 2011-07-27 08:50 -------- d-----w- c:\program files\Nero
2011-07-27 08:50 . 2011-07-27 08:50 -------- d-----w- c:\programdata\Nero
2011-07-27 08:50 . 2006-03-17 10:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2011-07-27 08:50 . 2011-07-27 08:50 -------- d-----w- c:\program files\Common Files\Nero
2011-07-27 08:48 . 2011-07-27 08:48 -------- d-----w- c:\program files\GRETECH
2011-07-27 08:48 . 2011-07-27 08:48 -------- d-----w- c:\program files\VideoLAN
2011-07-27 08:47 . 2011-03-02 10:43 175616 ----a-w- c:\windows\system32\unrar.dll
2011-07-27 08:47 . 2011-03-19 19:00 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-07-27 08:47 . 2006-10-18 18:05 232448 ----a-w- c:\windows\system32\mp3fhg.acm
2011-07-27 08:47 . 2011-03-24 19:35 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2011-07-27 08:47 . 2011-03-24 19:28 631808 ----a-w- c:\windows\system32\xvidcore.dll
2011-07-27 08:47 . 2010-11-03 18:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2011-07-27 08:47 . 2011-03-29 08:00 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-07-27 08:47 . 2011-07-27 08:47 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-07-27 08:46 . 2011-07-27 08:47 -------- d-----w- c:\program files\foobar2000
2011-07-27 08:45 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-07-27 08:45 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2011-07-27 08:45 . 2011-07-27 08:45 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2011-07-27 08:45 . 2011-07-27 08:46 -------- d-----w- c:\program files\Winamp
2011-07-27 08:07 . 2011-07-27 08:07 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-07-27 08:07 . 2011-07-27 08:07 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-07-27 08:07 . 2011-07-27 08:07 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-27 08:06 . 2011-07-27 08:06 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-07-27 08:05 . 2011-07-27 08:05 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-07-27 08:05 . 2011-07-27 08:10 -------- d-----w- c:\programdata\Microsoft Help
2011-07-27 08:04 . 2011-07-27 08:04 -------- d-----r- C:\MSOCache
2011-07-27 08:00 . 2011-07-27 08:00 -------- d-----w- c:\programdata\ACD Systems
2011-07-27 07:59 . 2011-07-27 08:00 -------- d-----w- c:\program files\Common Files\ACD Systems
2011-07-27 07:59 . 2011-07-27 07:59 -------- d-----w- c:\program files\ACD Systems
2011-07-27 07:53 . 2011-07-27 07:53 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-27 07:48 . 2011-07-27 07:50 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-27 07:48 . 2011-07-27 07:48 -------- d-----w- c:\windows\system32\Macromed
2011-07-27 07:42 . 2011-07-27 07:42 -------- d-----r- c:\program files\Skype
2011-07-27 07:42 . 2011-07-27 07:42 -------- d-----w- c:\programdata\Skype
2011-07-27 07:40 . 2011-07-27 07:41 -------- d-----w- c:\program files\Windows Live
2011-07-27 07:39 . 2011-07-27 07:39 -------- d-----w- c:\program files\Microsoft Silverlight
2011-07-27 07:39 . 2011-07-27 07:39 -------- d-----w- c:\program files\Common Files\Windows Live
2011-07-27 07:37 . 2011-07-27 07:37 439632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BD758D72-E3CF-4F8D-BB51-C9BAC9F86750}\gapaengine.dll
2011-07-27 07:35 . 2011-07-27 07:36 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-27 07:34 . 2011-07-27 07:34 -------- d-----w- c:\programdata\ATI
2011-07-27 07:32 . 2011-07-27 07:34 -------- d-----w- c:\program files\ATI Technologies
2011-07-27 07:32 . 2011-07-27 07:32 -------- d-----w- c:\program files\ATI
2011-07-27 07:26 . 2010-02-25 13:18 15872 ----a-w- c:\windows\system32\drivers\HpqKbFiltr.sys
2011-07-27 07:26 . 2010-02-25 13:18 1419232 ----a-w- c:\windows\system32\drivers\wdfcoinstaller01005.dll
2011-07-27 07:26 . 2011-07-27 07:26 -------- d-----w- c:\program files\Hewlett-Packard
2011-07-27 07:26 . 2010-02-25 15:51 1863680 ----a-w- c:\windows\system32\BttnCmn.dll
2011-07-27 07:26 . 2010-02-25 13:20 1885488 ----a-w- c:\windows\system32\BttnCmns.dll
2011-07-27 07:20 . 2011-07-27 07:32 -------- d-----w- C:\swsetup
2011-07-27 07:17 . 2011-07-27 07:17 -------- d-----w- c:\program files\HP
2011-07-27 07:17 . 2011-07-27 07:17 -------- d-----w- c:\windows\Downloaded Installations
2011-07-27 07:01 . 2011-07-27 08:07 -------- d-----w- c:\program files\Microsoft.NET
2011-07-27 06:55 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-07-27 06:55 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-27 06:55 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-27 06:53 . 2011-07-27 06:53 -------- d-----w- c:\program files\Microsoft IntelliPoint
2011-07-27 06:53 . 2011-07-27 06:53 -------- d-----w- c:\windows\PCHEALTH
2011-07-27 06:53 . 2011-07-27 08:50 -------- d-sh--w- c:\windows\Installer
2011-07-27 06:43 . 2011-07-20 07:44 6881616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{91FF468B-1599-4C17-9DB1-9B33CCFDDDBD}\mpengine.dll
2011-07-27 06:43 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-27 06:43 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-07-27 06:43 . 2011-04-27 02:17 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-27 06:43 . 2011-04-27 02:17 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-07-27 06:43 . 2011-04-27 02:17 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-27 06:43 . 2011-05-03 04:30 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-07-27 06:43 . 2011-02-25 05:34 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-07-27 06:43 . 2011-06-03 06:01 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-27 06:43 . 2011-06-03 05:56 271872 ----a-w- c:\windows\system32\conhost.exe
2011-07-27 06:43 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-07-27 06:38 . 2011-07-27 06:38 0 ----a-w- c:\windows\ativpsrm.bin
2011-07-27 06:29 . 2011-07-27 07:41 -------- d-----w- c:\users\Korisnik
2011-07-27 06:29 . 2011-07-27 06:29 -------- d-----w- C:\Recovery
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-27 07:40 . 2010-06-24 09:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-05-12 22:45 . 2011-05-12 22:45 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-05-12 22:45 . 2011-05-12 22:45 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-05-12 22:45 . 2011-05-12 22:45 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-05-12 22:45 . 2011-05-12 22:45 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-05-12 22:45 . 2011-05-12 22:45 1699328 ----a-w- c:\windows\system32\esent.dll
2011-05-12 22:45 . 2011-05-12 22:45 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-05-12 22:45 . 2011-05-12 22:45 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-05-12 22:45 . 2011-05-12 22:45 1211264 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-05-12 22:45 . 2011-05-12 22:45 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-05-12 22:44 . 2011-05-12 22:44 75776 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 22:44 . 2011-05-12 22:44 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 22:44 . 2011-05-12 22:44 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 22:44 . 2011-05-12 22:44 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 22:44 . 2011-05-12 22:44 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 22:44 . 2011-05-12 22:44 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 22:44 . 2011-05-12 22:44 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-12 22:44 . 2011-05-12 22:44 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2011-05-12 22:44 . 2011-05-12 22:44 2616320 ----a-w- c:\windows\explorer.exe
2011-05-12 22:44 . 2011-05-12 22:44 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-05-12 22:44 . 2011-05-12 22:44 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-05-12 22:44 . 2011-05-12 22:44 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-05-12 22:44 . 2011-05-12 22:44 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-05-12 22:43 . 2011-05-12 22:43 70656 ----a-w- c:\windows\system32\fontsub.dll
2011-05-12 22:43 . 2011-05-12 22:43 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-05-12 22:43 . 2011-05-12 22:43 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-05-12 22:43 . 2011-05-12 22:43 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-05-12 22:43 . 2011-05-12 22:43 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-05-12 22:43 . 2011-05-12 22:43 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-05-12 22:43 . 2011-05-12 22:43 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-05-12 22:43 . 2011-05-12 22:43 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-05-12 22:43 . 2011-05-12 22:43 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-05-12 22:43 . 2011-05-12 22:43 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-05-12 22:42 . 2011-05-12 22:42 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-05-12 22:42 . 2011-05-12 22:42 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-12 22:42 . 2011-05-12 22:42 850944 ----a-w- c:\windows\system32\sbe.dll
2011-05-12 22:42 . 2011-05-12 22:42 642048 ----a-w- c:\windows\system32\CPFilters.dll
2011-05-12 22:42 . 2011-05-12 22:42 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-05-12 22:42 . 2011-05-12 22:42 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2011-05-12 22:42 . 2011-05-12 22:42 542208 ----a-w- c:\windows\system32\kerberos.dll
2011-05-12 22:41 . 2011-05-12 22:41 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-12 22:41 . 2011-05-12 22:41 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-12 22:41 . 2011-05-12 22:41 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-12 22:41 . 2011-05-12 22:41 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-12 22:41 . 2011-05-12 22:41 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-12 22:41 . 2011-05-12 22:41 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-12 22:41 . 2011-05-12 22:41 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-12 22:41 . 2011-05-12 22:41 367104 ----a-w- c:\windows\system32\html.iec
2011-05-12 22:41 . 2011-05-12 22:41 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-12 22:41 . 2011-05-12 22:41 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-12 22:41 . 2011-05-12 22:41 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-12 22:41 . 2011-05-12 22:41 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-12 22:41 . 2011-05-12 22:41 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-12 22:41 . 2011-05-12 22:41 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-12 22:41 . 2011-05-12 22:41 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-12 22:41 . 2011-05-12 22:41 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-12 22:41 . 2011-05-12 22:41 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-12 22:41 . 2011-05-12 22:41 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-12 22:41 . 2011-05-12 22:41 101888 ----a-w- c:\windows\system32\admparse.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\CUPRIJA\Local Settings\Application Data\WMTools Downloaded Files ----
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-10-20 495708]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-09 98304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_94cb740f1febe83e\aestsrv.exe [2009-03-03 81920]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-09 172032]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-09 5341696]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-09 152064]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
.
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.032"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.abr"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ani"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.apd"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.arw"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bay"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bmp"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bw"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cr2"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.crw"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cs1"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cur"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dcr"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dcx"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dib"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.djv"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.djvu"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dng"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.emf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.eps"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.erf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.fff"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.fpx"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.gif"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.hdr"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.icl"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.icn"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (S-1-5-21-256050692-2632604472-3796655907-1000)
@Denied: (2) (LocalSystem)
"Progid"="Winamp.File.iff"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ilbm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.int"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.inta"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.iw4"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.j2c"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.j2k"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jbr"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jfif"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jif"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jp2"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpc"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpe"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpeg"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpg"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpk"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpx"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.kdc"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.lbm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mef"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mos"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mrw"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.nef"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.nrw"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.orf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pbm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pbr"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pcd"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pct"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pcx"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pef"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pgm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pic"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pict"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pix"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.png"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ppm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.psd"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.psp"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pspbrush"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pspimage"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.raf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ras"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (S-1-5-21-256050692-2632604472-3796655907-1000)
@Denied: (2) (LocalSystem)
"Progid"="Winamp.File.raw"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rgb"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rgba"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rle"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rsb"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rw2"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rwl"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.sgi"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.sr2"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.srf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tga"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.thm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tif"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tiff"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ttc"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ttf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30po"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30pp"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30ppf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wbm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wbmp"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wmf"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xbm"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xif"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xmp"
.
[HKEY_USERS\S-1-5-21-256050692-2632604472-3796655907-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xpm"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-27 21:48:35
ComboFix-quarantined-files.txt 2011-07-27 19:48
ComboFix2.txt 2011-07-27 19:03
.
Pre-Run: 91,111,022,592 bytes free
Post-Run: 91,064,139,776 bytes free
.
- - End Of File - - 8AA215B9C48FEEC3B4D1AF24CE51026E

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Sa kojom li si ti skriptom poretao CF i zasto li si to uopste radio?! GUZ - Glavom U Zid


Da li se mozes setiti koju si skriptu prevukao preko CF ikonice?






Zapakuj u (zip, rar) arhivu sledeci folder:

C:\Qoobox\Quarantine

... i upload-uj ga preko link-a:

http://www.mycity.rs/ambulanta-upload.php








goran9888 (AMF Tim)

offline
  • sojic1 
  • Novi MyCity građanin
  • Pridružio: 27 Jul 2011
  • Poruke: 25

jbg Sad(( stvarno ne mogu da nadjem nemam to u istoriji a i trazio sam po sajtu i nista Sad......sad sam se setio da su mi se prije pojavili folderi koje nisam mogao izbrisati svi se zvali ZZZZZZZ...... uploadovao sam quarantine

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

sojic1 ::jbg Sad(( stvarno ne mogu da nadjem nemam to u istoriji a i trazio sam po sajtu i nista Sad......sad sam se setio da su mi se prije pojavili folderi koje nisam mogao izbrisati svi se zvali ZZZZZZZ...... uploadovao sam quarantine


Sledeci put kada budes imao problema sa malware-om, javi se ovde pre nego sto bilo sta pokusas. ComboFix smo se dogovorili da vise ne koristis "na svoju ruku" (mozes izazvati vece probleme nego sto ih imas).




Pregledah sve izvestaje i mogu ti reci da nemas aktivnu infekciju na sistemu. U svakom slucaju i opis problema ne deluje kao da je problem do malware-a.



Otvori temu u odgovarajucem potforumu i opisi problem. Npr ovde: http://www.mycity.rs/Windows/




Arrow


Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.






Arrow


Preuzmi TFC (Temp File Cleaner) i sacuvaj ga na Desktop.
Dvoklikom pokreni program i klikni na dugme Start da bi dozvolio programu da otpocne skeniranje.
Kada program zavrsi skeniranje,mozda ce zatraziti da restartujes racunar. Dozvoli mu.

Napomena: Kada zavrsis sa ciscenjem temp fajlova,program mozes obrisati ili ga sacuvati za kasniju upotrebu.








offline
  • sojic1 
  • Novi MyCity građanin
  • Pridružio: 27 Jul 2011
  • Poruke: 25

uradio sam ovo sto si rekao za uninstalaciju combofix-a ali nece nesto kad prekopiram u start sreach nista mi ne pronalazi ustvari kao da mi ne radi sreach sta god da ukucam sto imam na kompu ne pronalazi Sad

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Skini na Desktop i pokreni sledeci alat: http://download.bleepingcomputer.com/sUBs/CF_UNINST.EXE




Ovaj alat bi trebalo da ukloni CF sa sistema.








goran9888 (AMF Tim)

Ko je trenutno na forumu
 

Ukupno su 465 korisnika na forumu :: 31 registrovanih, 7 sakrivenih i 427 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Pegaz_, A.R.Chafee.Jr., babaroga, bato, cenejac111, Cufo, danilopu, darkangel, DH, Djokislav, goxin, ILGromovnik, indja, ivan979, Krusarac, madza, mercedesamg, MIg, Milos ZA, Mirage 2000N, mnn2, moldway, mrvica78, radoznao, Rakenica, Sirius, x9, Yellow Pinky, zlaya011, zuxbg, Čivi