sanjalica1234 - izdvojeno iz druge teme

sanjalica1234 - izdvojeno iz druge teme

offline
  • Pridružio: 12 Jul 2009
  • Poruke: 1

ComboFix 09-07-09.08 - slobo 11.07.2009 23:44.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1349 [GMT 2:00]
Running from: c:\documents and settings\slobo\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
c:\documents and settings\All Users\Application Data\SeekmoSA
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA_hpk.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA_kyf.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAau.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht
c:\documents and settings\All Users\Start Menu\Programs\Seekmo
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Reset Cursor.lnk
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Seekmo Customer Support Center.lnk
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Seekmo Uninstall Instructions.lnk
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Weather.lnk
c:\documents and settings\slobo\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusRemover2008.lnk
c:\documents and settings\slobo\Application Data\Seekmo
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1019490.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1384984.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1399409.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1836247.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\3404705.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\3709044.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\992161.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\141880
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\191116
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\198406
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\21060
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\252531
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\26656
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\268125
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29115
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29547
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\3338
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\35047
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\39245
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\423530
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\43120
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\449624
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\45364
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\579123
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\58841
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\64495
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\6558
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\65770
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67464
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\705052
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\72123
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\752499
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753250
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753299
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\79246
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\82511
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\8443
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\85062
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93899
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\3862.dat
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_2000.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_3000.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bar.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bbar1.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_logos.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_other.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_weather.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hotbarcom.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\icons2.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\layout.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\linkpathlegal.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\progress.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\s_icons_buttons.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\sales_buttons.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo_ie_menu.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\t2_bg.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\theweb.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\top7.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Top7_theweb.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\tsd_bg.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_weather.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\icons2.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\progress.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip
c:\documents and settings\slobo\Application Data\ShoppingReport
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
c:\documents and settings\slobo\Application Data\WeatherDPA
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\SearchWeather.xml
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\Weather_XML\Default
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\Weather_XML\Genera1
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\Weather_XML\General
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Links
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Display
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Loading
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen1
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen2
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen3
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\soaperror
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Version
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\WeatherPreferences
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherStartup.xml
c:\program files\seekmo
c:\program files\seekmo\bin\10.3.85.0\arrow.ico
c:\program files\seekmo\bin\10.3.85.0\CntntCntr.dll
c:\program files\seekmo\bin\10.3.85.0\copyright.txt
c:\program files\seekmo\bin\10.3.85.0\CoreSrv.dll
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\chrome.manifest
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\components\npclntax.xpt
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\install.rdf
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\plugins\npclntax_SeekmoSA.dll
c:\program files\seekmo\bin\10.3.85.0\HostIE.dll
c:\program files\seekmo\bin\10.3.85.0\HostOE.dll
c:\program files\seekmo\bin\10.3.85.0\HostOL.dll
c:\program files\seekmo\bin\10.3.85.0\link.ico
c:\program files\seekmo\bin\10.3.85.0\OEAddOn.exe
c:\program files\seekmo\bin\10.3.85.0\SeekmoSA.exe
c:\program files\seekmo\bin\10.3.85.0\SeekmoSAAX.dll
c:\program files\seekmo\bin\10.3.85.0\SeekmoSADF.exe
c:\program files\seekmo\bin\10.3.85.0\SeekmoSAHook.dll
c:\program files\seekmo\bin\10.3.85.0\SeekmoUninstaller.exe
c:\program files\seekmo\bin\10.3.85.0\Srv.exe
c:\program files\seekmo\bin\10.3.85.0\Toolbar.dll
c:\program files\seekmo\bin\10.3.85.0\Wallpaper.dll
c:\program files\seekmo\bin\10.3.85.0\Weather.exe
c:\program files\seekmo\bin\10.3.85.0\WeSkin.dll
c:\program files\ShoppingReport
c:\program files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
c:\program files\ShoppingReport\Uninst.exe
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
C:\sivrpld.exe
c:\windows\dialerexe.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\ljqxau_navfx.dat
c:\windows\system32\msvcrt2.dll
c:\windows\system32\nvs2.inf
c:\windows\system32\qmasukw_navfx.dat
c:\windows\system32\weiiu.dat
c:\windows\system32\weiiu_nav.dat
c:\windows\system32\weiiu_navps.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_FCI
-------\Legacy_ICF
-------\Legacy_TCPSR


((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.

2009-07-09 20:57 . 2009-07-09 20:58 -------- d-----w- c:\documents and settings\slobo\Local Settings\Application Data\Temp
2009-07-09 20:57 . 2009-07-09 20:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-09 20:37 . 2009-07-09 20:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-09 20:37 . 2009-07-09 20:58 -------- d-----w- c:\documents and settings\slobo\Local Settings\Application Data\Google
2009-07-09 20:36 . 2009-07-09 20:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-09 20:36 . 2009-07-09 20:38 -------- d-----w- c:\program files\Google
2009-07-05 15:27 . 2009-07-05 15:27 -------- d-----w- c:\documents and settings\slobo\Application Data\BSplayer PRO
2009-06-12 12:06 . 2009-06-12 12:06 -------- d-----w- c:\documents and settings\slobo\Local Settings\Application Data\Ares

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 20:57 . 2009-05-31 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-08 16:00 . 2009-04-01 08:50 -------- d-----w- c:\program files\Norton Security Scan
2009-07-08 12:05 . 2009-06-03 18:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-07-01 12:52 . 2009-05-31 16:26 770080 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-01 12:52 . 2009-05-31 16:26 4760 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-01 12:52 . 2009-05-31 16:26 4035616 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-01 12:52 . 2009-05-31 16:26 33656 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-01 12:32 . 2009-05-31 16:26 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-01 12:29 . 2009-05-31 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-17 16:05 . 2009-04-01 08:50 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-11 20:54 . 2009-06-11 20:54 1915520 ----a-w- c:\documents and settings\slobo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-06 21:46 . 2009-04-23 20:03 -------- d-----w- c:\program files\Hrvatsko - Engleski Rjeènik
2009-06-06 21:40 . 2009-06-06 21:40 -------- d-----w- c:\program files\ReflexiveArcade
2009-06-06 21:35 . 2009-06-06 21:35 -------- d-----w- c:\documents and settings\slobo\Application Data\EleFun Games
2009-06-06 21:35 . 2009-02-07 21:14 -------- d-----w- c:\program files\MyPlayCity
2009-06-06 21:35 . 2009-06-06 21:35 -------- d-----w- c:\program files\MyPlayCity.com
2009-06-04 08:20 . 2009-06-03 18:18 -------- d-----w- c:\program files\Enigma Software Group
2009-06-03 19:36 . 2009-06-03 19:36 2560 ----a-w- c:\windows\system32\drivers\mchInjDrv.sys
2009-06-03 18:43 . 2009-06-03 18:43 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-06-03 18:43 . 2009-06-03 18:43 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-06-03 18:43 . 2009-06-03 18:43 -------- d-----w- c:\program files\Prevx
2009-05-31 16:43 . 2001-08-23 12:00 14336 ----a-w- c:\windows\system32\svchost.exe
2009-05-31 16:38 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-05-31 16:38 . 2009-05-31 16:27 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-31 16:38 . 2009-05-31 16:27 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-31 16:38 . 2009-05-31 16:38 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-05-31 16:38 . 2009-05-31 16:38 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-05-31 16:38 . 2009-05-31 16:38 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-05-31 16:23 . 2009-02-13 11:46 -------- d-----w- c:\program files\Spyware Doctor
2009-05-31 16:23 . 2009-02-01 01:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-30 23:26 . 2007-11-18 18:21 -------- d-----w- c:\program files\Winamp
2009-05-13 05:15 . 2001-08-23 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:44 . 2001-08-23 12:00 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 09:58 . 2001-08-23 12:00 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2001-08-23 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2007-05-15 19:34 . 2007-11-18 18:42 66672 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-05-15 19:34 . 2007-11-18 18:42 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-05-15 19:34 . 2007-11-18 18:42 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-05-15 19:34 . 2007-11-18 18:42 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-05-15 19:34 . 2007-11-18 18:42 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
2009-06-28 00:22 2094616 ----a-w- c:\program files\MyPlayCity\tbMyP1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-09 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-05-31 206088]

c:\documents and settings\slobo\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2006-10-27 338216]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1ekxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [18.11.2007 19:40 10112]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29.1.2008 17:29 33808]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [3.6.2009 20:43 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [3.6.2009 20:43 27656]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [3.6.2009 20:43 4368952]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [18.11.2007 19:41 4300]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [23.8.2001 14:00 14336]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [19.9.2007 8:47 29184]
S0 ati1ekxx;ati1ekxx;c:\windows\system32\drivers\ati1ekxx.sys [10.1.2009 16:02 32768]
S4 BsUDF;B.H.A UDF Filesystem;c:\windows\system32\drivers\BsUDF.sys [18.11.2007 19:40 165376]
S4 SNM WLAN Service;SNM WLAN Service;c:\program files\Samsung\Samsung Network Manager\SNMWLANService.exe [28.5.2005 9:35 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-09 20:36]

2009-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-09 20:37]

2009-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-09 20:37]

2009-07-08 c:\windows\Tasks\Norton Security Scan for slobo.job
- c:\program files\Norton Security Scan\Nss.exe [2009-03-13 15:20]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ares - c:\program files\Ares\Ares.exe
HKU-Default-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
Notify-dnqcvbnm - dnqcvbnm32.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com
uInternet Connection Wizard,ShellNext = iexplore
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B3} - {A16AD1E9-F69A-45af-9462-B1C286708842} -
FF - ProfilePath - c:\documents and settings\slobo\Application Data\Mozilla\Firefox\Profiles\l1rxeqxz.default\
FF - prefs.js: browser.search.selectedEngine - Crawler Search
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-07-11 23:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(676)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3744)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-07-11 23:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 21:54

Pre-Run: 14.814.048.256 bytes free
Post-Run: 16.890.179.584 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

392 --- E O F --- 2009-06-12 01:03

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Hteo si nešto?

Ko je trenutno na forumu
 

Ukupno su 908 korisnika na forumu :: 49 registrovanih, 3 sakrivenih i 856 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Apok, ArchaBasha, Areal84, Bobrock1, cenejac111, comi_pfc, crnitrn, djordje92sm, DonRumataEstorski, flash12, FOX, goxin, Griffon vulture, havoc995, hooraay, Karla, Krvava Devetka, Kubovac, ljuba, mercedesamg, milenko crazy north, minmatar34957, Misirac, Mixelotti, mkukoleca, nebkv, ostoja, ozzy, pacika, panzerwaffe, pein, Raso75, raykan, royst33, shone34, Singidunumac, Sirius, Srle993, Tores, vasa.93, Vatreni Zmaj, virked, Vlad000, vlajkox, Vlajman1957, voja64, wolverined4, zeo