offline
- Frosina19
- Novi MyCity građanin
- Pridružio: 22 Sep 2009
- Poruke: 12
|
DDS (Ver_09-07-30.01) - NTFSx86
Run by Frose at 1:57:56.25 on Tue 09/22/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.764 [GMT 2:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AutorunRemover\AutorunRemover.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Frose\Desktop\dds.scr
============== Pseudo HJT Report ===============
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AutorunRemover.exe] c:\program files\autorunremover\AutorunRemover.exe -Hide
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
TCP: {72324D6D-F090-4C72-8948-35AC29E1652D} = 62.162.32.6 62.162.32.5
TCP: {BAC78D70-F11D-4D2A-98CC-381F15880214} = 62.162.32.5,62.162.32.6
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\frose\applic~1\mozilla\firefox\profiles\akogi327.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=15161&l=dis
FF - prefs.js: keyword.URL -
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-4-8 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-4-8 161392]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-9-16 179856]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-4-17 1706176]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-9-19 603904]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-9-16 15504]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20050412.023\naveng.sys [2009-9-21 73728]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20050412.023\navex15.sys [2009-9-21 631040]
S?4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-9-16 38496]
S2 gstdygz;Boot Monitor;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-4-8 83568]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-4-17 124608]
=============== Created Last 30 ================
2009-09-21 16:42 123,200 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-21 16:42 91,856 a------- c:\windows\system32\S32EVNT1.DLL
2009-09-21 16:17 <DIR> --d----- c:\program files\Trend Micro
2009-09-20 17:30 25 a------- c:\windows\cdplayer.ini
2009-09-20 17:26 <DIR> --d----- c:\program files\common files\xing shared
2009-09-20 17:24 <DIR> --d----- c:\program files\common files\Real
2009-09-20 17:17 476,696 a------- C:\RealPlayer11GOLD.exe
2009-09-19 23:21 603,904 a------- c:\windows\system32\TUProgSt.exe
2009-09-19 23:21 27,904 a------- c:\windows\system32\uxtuneup.dll
2009-09-19 23:21 360,192 a------- c:\windows\system32\TuneUpDefragService.exe
2009-09-19 23:21 <DIR> --d----- c:\docume~1\frose\applic~1\TuneUp Software
2009-09-19 23:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TuneUp Software
2009-09-19 23:20 <DIR> --d----- c:\program files\TuneUp Utilities 2009
2009-09-19 13:03 1,240 a------- c:\windows\system32\nyovgbmmlh.pdf
2009-09-18 18:32 <DIR> --d----- c:\program files\uTorrent
2009-09-18 18:32 <DIR> --d----- c:\docume~1\frose\applic~1\uTorrent
2009-09-18 00:43 0 a------- c:\windows\system32\a
2009-09-16 18:34 42,496 a------- c:\windows\system32\drivers\fetnd5bv.sys
2009-09-16 18:34 61,440 a------- c:\windows\system32\vuins32.dll
2009-09-16 18:34 <DIR> --d----- c:\windows\vnDrvBas
2009-09-16 18:01 <DIR> --d----- c:\windows\pss
2009-09-16 17:52 0 a------- c:\windows\vpc32.INI
2009-09-16 17:29 <DIR> --d----- c:\docume~1\frose\applic~1\Malwarebytes
2009-09-16 17:29 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-09-16 17:29 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-16 17:29 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-16 17:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-16 17:25 <DIR> --d----- c:\program files\Symantec
2009-09-16 17:25 <DIR> --d----- c:\program files\Symantec AntiVirus
2009-09-16 17:25 <DIR> --d----- c:\program files\common files\Symantec Shared
2009-09-16 17:25 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec
2009-09-16 16:54 <DIR> --d----- c:\windows\system32\appmgmt
2009-09-16 01:00 1,067 a------- c:\windows\system32\aajkzhshkk.pdf
2009-09-12 17:32 <DIR> --d----- c:\program files\AutorunRemover
2009-08-29 14:50 <DIR> --d----- c:\docume~1\frose\applic~1\BSplayer PRO
2009-08-29 13:51 <DIR> --d----- c:\docume~1\frose\applic~1\Samsung
2009-08-29 13:49 174,592 a------- c:\windows\system32\framedyn.dll
2009-08-29 13:49 137,884 a------- c:\windows\system32\drivers\sscdmdm.sys
2009-08-29 13:49 80,272 a------- c:\windows\system32\drivers\sscdbus.sys
2009-08-29 13:49 11,877 a------- c:\windows\system32\drivers\sscdcmnt.sys
2009-08-29 13:49 11,877 a------- c:\windows\system32\drivers\sscdcm.sys
2009-08-29 13:49 11,188 a------- c:\windows\system32\drivers\sscdwhnt.sys
2009-08-29 13:49 11,188 a------- c:\windows\system32\drivers\sscdwh.sys
2009-08-29 13:49 10,864 a------- c:\windows\system32\drivers\sscdmdfl.sys
2009-08-29 13:48 <DIR> --d----- c:\windows\system32\Samsung_USB_Drivers
2009-08-29 13:47 766 a------- c:\windows\system32\Uninstall.ico
2009-08-29 13:47 5,632 a------- c:\windows\system32\drivers\StarOpen.sys
2009-08-29 13:46 <DIR> --d----- c:\program files\Samsung
2009-08-28 15:39 20 a------- c:\windows\mafosav.INI
2009-08-25 19:19 1,067 a------- c:\windows\system32\tfayjyylkp.pdf
2009-08-25 19:18 1,067 a------- c:\windows\system32\aklkrbzqyb.pdf
2009-08-25 19:18 1,067 a------- c:\windows\system32\dfcjheilla.pdf
2009-08-25 19:18 1,067 a------- c:\windows\system32\qyjftbmvvo.pdf
2009-08-25 18:22 1,067 a------- c:\windows\system32\jzapopmyrl.pdf
==================== Find3M ====================
2009-09-17 10:27 186,496 a---h--- c:\windows\system32\mlfcache.dat
2009-09-12 17:20 100 a------- c:\docume~1\alluse~1\applic~1\{0xffcc220x45aaff}.dat
2009-07-22 17:00 407,129 a------- c:\windows\MarioForever_Toolbar_Uninstaller_3468.exe
2009-07-20 00:59 4,096 a------- c:\windows\d3dx.dat
2009-06-17 12:34 56 ---shr-- c:\windows\system32\61A5AFCF43.sys
2009-06-17 12:34 1,890 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-04-14 06:41 164,746 a--shr-- c:\windows\system32\ntayhw.dll
2009-05-13 16:41 16,384 a--sh--- c:\windows\system32\config\systemprofile\cookies\index.dat
2009-05-13 16:41 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2009-05-13 16:41 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009051320090514\index.dat
2009-05-13 16:41 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 1:58:33.10 ===============
mycity.rs/must-login.png
|