offline
- rewritable
- Ugledni građanin
- Pridružio: 20 Mar 2009
- Poruke: 300
- Gde živiš: Republic Of Srpska Banjaluka
|
evo ga
ComboFix 08-09-16.05 - PST 2008-09-20 12:44:00.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.658 [GMT 2:00]
Running from: C:\Documents and Settings\PST\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\PST\Desktop\CFScript
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.
2008-09-19 06:22 . 2008-09-19 06:22 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-19 06:13 . 2008-09-19 06:13 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-18 21:19 . 2008-09-18 21:19 <DIR> d-------- C:\Documents and Settings\PST\Application Data\Grisoft
2008-09-18 21:18 . 2008-09-18 21:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-09-18 21:18 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-09-18 20:55 . 2008-09-19 15:52 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-18 20:55 . 2008-09-18 20:55 <DIR> d-------- C:\Program Files\AVG
2008-09-18 20:55 . 2008-09-19 06:22 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-18 20:55 . 2008-09-19 06:22 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-18 20:00 . 2008-09-18 20:12 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-18 20:00 . 2008-09-18 20:12 <DIR> d-------- C:\Documents and Settings\PST\Application Data\SUPERAntiSpyware.com
2008-09-18 20:00 . 2008-09-18 20:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-18 19:38 . 2008-09-18 19:38 5,364 --a------ C:\Documents and Settings\cc_20080918_1938.reg
2008-09-18 09:52 . 2008-09-18 20:08 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-18 09:39 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-09-18 09:39 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-09-18 09:39 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-09-18 09:39 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-09-18 09:39 . 2007-09-28 14:26 25,088 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-09-18 07:29 . 2008-09-18 20:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-09-18 07:26 . 2008-09-18 20:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-09-18 06:46 . 2008-09-18 06:46 14,932 --a------ C:\Documents and Settings\cc_20080918_0646.reg
2008-09-18 06:04 . 2008-09-18 09:43 1,140 --a------ C:\WINDOWS\system32\tmp.reg
2008-09-09 22:41 . 2008-09-09 22:41 21,910 --a------ C:\Documents and Settings\cc_20080909_2240.reg
2008-08-31 20:24 . 2008-08-31 20:25 6,180 --a------ C:\Documents and Settings\cc_20080831_2024.reg
2008-08-29 17:40 . 2008-09-18 20:55 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-28 22:08 . 2008-08-28 22:08 0 --a------ C:\WINDOWS\mngui.INI
2008-08-27 20:50 . 2008-08-27 20:50 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-08-27 20:49 . 2008-08-27 20:49 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-08-27 20:49 . 2008-08-27 20:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Teleca
2008-08-25 18:47 . 2008-08-25 18:47 <DIR> d-------- C:\Documents and Settings\PST\Application Data\Teleca
2008-08-25 18:47 . 2006-09-18 14:59 90,800 -ra------ C:\WINDOWS\system32\drivers\se27unic.sys
2008-08-25 18:47 . 2006-09-18 14:59 18,704 -ra------ C:\WINDOWS\system32\drivers\se27nd5.sys
2008-08-25 18:47 . 2006-09-18 14:58 4,128 -ra------ C:\WINDOWS\system32\drivers\se27cr.sys
2008-08-25 18:46 . 2006-09-18 14:58 97,184 -ra------ C:\WINDOWS\system32\drivers\SE27mdm.sys
2008-08-25 18:46 . 2006-09-18 14:58 88,688 -ra------ C:\WINDOWS\system32\drivers\SE27mgmt.sys
2008-08-25 18:46 . 2006-09-18 14:59 86,560 -ra------ C:\WINDOWS\system32\drivers\SE27obex.sys
2008-08-25 18:46 . 2006-09-18 14:58 61,600 -ra------ C:\WINDOWS\system32\drivers\SE27bus.sys
2008-08-25 18:46 . 2006-09-18 14:58 9,360 -ra------ C:\WINDOWS\system32\drivers\SE27mdfl.sys
2008-08-25 18:46 . 2006-09-18 14:58 6,240 -ra------ C:\WINDOWS\system32\drivers\SE27cmnt.sys
2008-08-25 18:46 . 2006-09-18 14:58 6,240 -ra------ C:\WINDOWS\system32\drivers\SE27cm.sys
2008-08-25 18:46 . 2006-09-18 14:59 5,872 -ra------ C:\WINDOWS\system32\drivers\SE27whnt.sys
2008-08-25 18:46 . 2006-09-18 14:59 5,872 -ra------ C:\WINDOWS\system32\drivers\SE27wh.sys
2008-08-25 18:41 . 2008-08-25 18:41 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-08-25 18:31 . 2008-08-25 18:31 <DIR> d-------- C:\Documents and Settings\PST\Application Data\Sony Ericsson
2008-08-25 18:27 . 2008-08-27 20:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-25 18:27 . 2008-08-27 20:50 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 19:02 --------- d-----w C:\Documents and Settings\PST\Application Data\uTorrent
2008-09-18 19:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 19:14 --------- d-----w C:\Program Files\SpywareBlaster
2008-09-18 17:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 07:54 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-09-13 05:11 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-12 04:40 10,022 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-09-09 22:24 --------- d-----w C:\Documents and Settings\PST\Application Data\Skype
2008-09-09 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-09 20:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-28 17:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-27 18:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-08-18 22:01 --------- d-----w C:\Documents and Settings\PST\Application Data\skypePM
2008-08-18 19:37 --------- d-----w C:\Documents and Settings\PST\Application Data\CyberLink
2008-08-18 19:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-18 19:36 --------- d-----w C:\Program Files\CyberLink
2008-08-12 21:32 --------- d-----w C:\Program Files\uTorrent
2008-08-06 22:20 299,392 ----a-w C:\WINDOWS\system32\imon.dll
2008-08-05 20:50 --------- d-----w C:\Program Files\DX-Ball
2008-07-30 20:26 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-21 22:55 --------- d-----w C:\Program Files\Lavasoft
2008-07-02 04:07 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-01-08 13:39 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="C:\Program Files\ClocX\ClocX.exe" [2005-01-26 270336]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-19 1235736]
C:\Documents and Settings\PST\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-01-18 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Native Instruments\\Traktor DJ Studio 2\\TraktorDJStudio2.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Documents and Settings\\PST\\Desktop\\Skype.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-09-05 77056]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-19 97928]
R2 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-05-12 8768]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-19 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-19 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-19 76040]
R2 MarxDev1;MarxDev1;C:\WINDOWS\system32\drivers\MarxDev1.sys [2001-05-28 8864]
R2 MarxDev2;MarxDev2;C:\WINDOWS\system32\drivers\MarxDev2.sys [2001-05-28 8864]
R2 MarxDev3;MarxDev3;C:\WINDOWS\system32\drivers\MarxDev3.sys [2001-05-28 8864]
R2 Tdlpt;Tdlpt;C:\WINDOWS\system32\drivers\Tdlpt.sys [2001-10-16 8012]
S3 usb2vcom;USB Data Cable;C:\WINDOWS\system32\DRIVERS\usb2vcom.sys [2005-12-21 29152]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1190db55-d7af-11db-82e1-00112fb41aa6}]
\Shell\AutoRun\command - H:\autorun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-09-20 12:46:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-20 12:48:51
ComboFix-quarantined-files.txt 2008-09-20 10:48:23
ComboFix2.txt 2008-09-19 14:17:49
Pre-Run: 6,931,791,872 bytes free
Post-Run: 6,917,500,928 bytes free
145
Dopuna: 20 Sep 2008 12:57
ajoj majko moja zaboravio sam ugasiti avg onu opciju prije skeniranja
sta sad?
mogu iskljuciti pa ponoviti skeniranje???????e jesam levat pravi
Dopuna: 20 Sep 2008 13:07
ma odradio sam ja njega bez avg-a pa sta bude evo
ComboFix 08-09-16.05 - PST 2008-09-20 12:56:40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.634 [GMT 2:00]
Running from: C:\Documents and Settings\PST\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\PST\Desktop\CFScript
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.
2008-09-19 06:22 . 2008-09-19 06:22 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-19 06:13 . 2008-09-19 06:13 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-18 21:19 . 2008-09-18 21:19 <DIR> d-------- C:\Documents and Settings\PST\Application Data\Grisoft
2008-09-18 21:18 . 2008-09-18 21:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-09-18 21:18 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-09-18 20:55 . 2008-09-19 15:52 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-18 20:55 . 2008-09-18 20:55 <DIR> d-------- C:\Program Files\AVG
2008-09-18 20:55 . 2008-09-19 06:22 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-18 20:55 . 2008-09-19 06:22 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-18 20:00 . 2008-09-18 20:12 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-18 20:00 . 2008-09-18 20:12 <DIR> d-------- C:\Documents and Settings\PST\Application Data\SUPERAntiSpyware.com
2008-09-18 20:00 . 2008-09-18 20:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-18 19:38 . 2008-09-18 19:38 5,364 --a------ C:\Documents and Settings\cc_20080918_1938.reg
2008-09-18 09:52 . 2008-09-18 20:08 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-18 09:39 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-09-18 09:39 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-09-18 09:39 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-09-18 09:39 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-09-18 09:39 . 2007-09-28 14:26 25,088 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-09-18 07:29 . 2008-09-18 20:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-09-18 07:26 . 2008-09-18 20:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-09-18 06:46 . 2008-09-18 06:46 14,932 --a------ C:\Documents and Settings\cc_20080918_0646.reg
2008-09-18 06:04 . 2008-09-18 09:43 1,140 --a------ C:\WINDOWS\system32\tmp.reg
2008-09-09 22:41 . 2008-09-09 22:41 21,910 --a------ C:\Documents and Settings\cc_20080909_2240.reg
2008-08-31 20:24 . 2008-08-31 20:25 6,180 --a------ C:\Documents and Settings\cc_20080831_2024.reg
2008-08-29 17:40 . 2008-09-18 20:55 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-28 22:08 . 2008-08-28 22:08 0 --a------ C:\WINDOWS\mngui.INI
2008-08-27 20:50 . 2008-08-27 20:50 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-08-27 20:49 . 2008-08-27 20:49 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-08-27 20:49 . 2008-08-27 20:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Teleca
2008-08-25 18:47 . 2008-08-25 18:47 <DIR> d-------- C:\Documents and Settings\PST\Application Data\Teleca
2008-08-25 18:47 . 2006-09-18 14:59 90,800 -ra------ C:\WINDOWS\system32\drivers\se27unic.sys
2008-08-25 18:47 . 2006-09-18 14:59 18,704 -ra------ C:\WINDOWS\system32\drivers\se27nd5.sys
2008-08-25 18:47 . 2006-09-18 14:58 4,128 -ra------ C:\WINDOWS\system32\drivers\se27cr.sys
2008-08-25 18:46 . 2006-09-18 14:58 97,184 -ra------ C:\WINDOWS\system32\drivers\SE27mdm.sys
2008-08-25 18:46 . 2006-09-18 14:58 88,688 -ra------ C:\WINDOWS\system32\drivers\SE27mgmt.sys
2008-08-25 18:46 . 2006-09-18 14:59 86,560 -ra------ C:\WINDOWS\system32\drivers\SE27obex.sys
2008-08-25 18:46 . 2006-09-18 14:58 61,600 -ra------ C:\WINDOWS\system32\drivers\SE27bus.sys
2008-08-25 18:46 . 2006-09-18 14:58 9,360 -ra------ C:\WINDOWS\system32\drivers\SE27mdfl.sys
2008-08-25 18:46 . 2006-09-18 14:58 6,240 -ra------ C:\WINDOWS\system32\drivers\SE27cmnt.sys
2008-08-25 18:46 . 2006-09-18 14:58 6,240 -ra------ C:\WINDOWS\system32\drivers\SE27cm.sys
2008-08-25 18:46 . 2006-09-18 14:59 5,872 -ra------ C:\WINDOWS\system32\drivers\SE27whnt.sys
2008-08-25 18:46 . 2006-09-18 14:59 5,872 -ra------ C:\WINDOWS\system32\drivers\SE27wh.sys
2008-08-25 18:41 . 2008-08-25 18:41 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-08-25 18:31 . 2008-08-25 18:31 <DIR> d-------- C:\Documents and Settings\PST\Application Data\Sony Ericsson
2008-08-25 18:27 . 2008-08-27 20:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-25 18:27 . 2008-08-27 20:50 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 19:02 --------- d-----w C:\Documents and Settings\PST\Application Data\uTorrent
2008-09-18 19:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 19:14 --------- d-----w C:\Program Files\SpywareBlaster
2008-09-18 17:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 07:54 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-09-13 05:11 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-12 04:40 10,022 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-09-09 22:24 --------- d-----w C:\Documents and Settings\PST\Application Data\Skype
2008-09-09 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-09 20:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-28 17:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-27 18:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-08-18 22:01 --------- d-----w C:\Documents and Settings\PST\Application Data\skypePM
2008-08-18 19:37 --------- d-----w C:\Documents and Settings\PST\Application Data\CyberLink
2008-08-18 19:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-18 19:36 --------- d-----w C:\Program Files\CyberLink
2008-08-12 21:32 --------- d-----w C:\Program Files\uTorrent
2008-08-06 22:20 299,392 ----a-w C:\WINDOWS\system32\imon.dll
2008-08-05 20:50 --------- d-----w C:\Program Files\DX-Ball
2008-07-30 20:26 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-21 22:55 --------- d-----w C:\Program Files\Lavasoft
2008-07-02 04:07 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-01-08 13:39 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="C:\Program Files\ClocX\ClocX.exe" [2005-01-26 270336]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-19 1235736]
C:\Documents and Settings\PST\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-01-18 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Native Instruments\\Traktor DJ Studio 2\\TraktorDJStudio2.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Documents and Settings\\PST\\Desktop\\Skype.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-09-05 77056]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-19 97928]
R2 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-05-12 8768]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-19 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-19 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-19 76040]
R2 MarxDev1;MarxDev1;C:\WINDOWS\system32\drivers\MarxDev1.sys [2001-05-28 8864]
R2 MarxDev2;MarxDev2;C:\WINDOWS\system32\drivers\MarxDev2.sys [2001-05-28 8864]
R2 MarxDev3;MarxDev3;C:\WINDOWS\system32\drivers\MarxDev3.sys [2001-05-28 8864]
R2 Tdlpt;Tdlpt;C:\WINDOWS\system32\drivers\Tdlpt.sys [2001-10-16 8012]
S3 usb2vcom;USB Data Cable;C:\WINDOWS\system32\DRIVERS\usb2vcom.sys [2005-12-21 29152]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1190db55-d7af-11db-82e1-00112fb41aa6}]
\Shell\AutoRun\command - H:\autorun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-09-20 12:58:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-20 13:00:34
ComboFix-quarantined-files.txt 2008-09-20 11:00:00
ComboFix2.txt 2008-09-20 10:48:53
ComboFix3.txt 2008-09-19 14:17:49
Pre-Run: 6,896,087,040 bytes free
Post-Run: 6,882,361,344 bytes free
146
|