offline
- Pridružio: 07 Sep 2008
- Poruke: 49
|
Pozz, hvala ti sto si odgovorio. Evo ga izvestaj.
ComboFix 09-08-29.01 - Administrator 08/30/2009 16:14.3.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3327.2087 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\TestBrowser.html
c:\documents and settings\All Users\Application Data\Seekapp
c:\documents and settings\All Users\Application Data\Seekapp\seekapp132.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886
c:\windows\system32\lsprst7.dll
c:\windows\system32\ssprs.dll
.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.
2009-08-26 10:07 . 2009-08-26 10:07 118829 --sh--r- c:\windows\traymanager.exe
2009-08-26 10:07 . 2009-08-26 10:08 217133 ----a-w- c:\windows\msauo.exe
2009-08-25 19:40 . 2009-08-25 19:45 -------- d-----w- c:\program files\CamStudio
2009-08-25 19:34 . 2009-08-25 19:34 -------- d-----w- c:\program files\Kursevi
2009-08-25 19:23 . 2009-08-26 13:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\Any Video Converter
2009-08-25 19:23 . 2009-08-25 19:23 -------- d-----w- c:\program files\Any Video Converter
2009-08-23 00:11 . 2009-08-23 00:11 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2009-08-19 20:58 . 2009-08-19 21:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\Move Networks
2009-08-19 20:57 . 2009-03-09 09:34 971776 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pxdgk9ry.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
2009-08-17 16:59 . 2001-08-17 20:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-08-17 16:59 . 2008-04-14 03:42 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-08-16 22:06 . 2009-08-16 22:06 -------- d-----w- C:\Downloads
2009-08-16 21:32 . 2009-08-16 21:32 -------- d-----w- c:\program files\Xilisoft
2009-08-16 18:21 . 2009-08-16 18:22 -------- d-----w- c:\program files\Plato DVD Ripper Professional
2009-08-16 18:13 . 2009-08-16 18:39 -------- d-----w- C:\platodvdripper
2009-08-12 19:09 . 2009-08-12 20:05 -------- d-----w- c:\program files\NewBlue
2009-08-11 22:19 . 2009-08-11 22:20 -------- d-----w- c:\program files\The KMPlayer
2009-08-11 14:26 . 2009-08-11 14:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Publish Providers
2009-08-07 22:09 . 2009-08-26 13:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2009-08-03 18:54 . 2009-08-03 18:54 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-03 18:53 . 2009-08-03 18:53 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-08-03 18:10 . 2009-08-03 18:10 -------- d-----w- c:\windows\Sun
2009-08-03 13:42 . 2009-08-03 13:42 38208 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-03 13:39 . 2009-08-03 13:39 -------- d-----w- c:\program files\Adobe Media Player
2009-08-02 19:52 . 2009-08-02 19:52 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-01 15:59 . 2009-08-01 16:13 1772288 ----a-w- c:\documents and settings\Administrator\Application Data\Integrator.exe
2009-08-01 15:52 . 2009-08-01 15:54 -------- d-----w- c:\program files\Download Direct
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-30 12:47 . 2009-03-06 23:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2009-08-26 13:21 . 2009-07-23 10:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2009-08-13 01:31 . 2009-03-17 20:26 45056 ----a-w- c:\windows\system32\WNASPI32.DLL
2009-08-13 01:31 . 2009-03-17 20:26 16512 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
2009-08-12 00:02 . 2009-03-06 21:13 -------- d-----w- c:\program files\Sony
2009-08-11 23:19 . 2009-03-06 21:10 -------- d-----w- c:\program files\Sony Setup
2009-08-11 22:06 . 2009-03-07 14:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-04 14:36 . 2009-03-06 21:08 -------- d-----w- c:\program files\FormatFactory
2009-08-03 18:53 . 2009-03-06 04:30 -------- d-----w- c:\program files\Java
2009-08-03 13:42 . 2009-07-09 02:10 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-08-03 13:42 . 2009-03-12 23:17 38208 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-03 11:16 . 2009-03-06 20:24 -------- d-----w- c:\program files\Winamp
2009-08-02 20:33 . 2009-03-06 04:48 96584 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-02 16:41 . 2009-04-01 08:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\gtk-2.0
2009-07-31 06:33 . 2009-03-08 19:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-31 06:33 . 2009-03-08 19:07 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-31 06:33 . 2009-03-08 19:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-31 04:41 . 2009-07-31 04:41 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-07-23 10:32 . 2009-07-23 10:32 -------- d-----w- c:\program files\VideoLAN
2009-07-21 02:39 . 2009-03-07 14:22 1078560 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-19 22:00 . 2009-07-19 22:00 -------- d-----w- c:\program files\TechSmith
2009-07-17 14:33 . 2009-07-17 14:32 -------- d-----w- c:\program files\DVD Decrypter
2009-07-16 21:43 . 2009-03-12 14:42 -------- d-----w- c:\program files\iTunes
2009-07-16 21:43 . 2009-07-16 21:43 -------- d-----w- c:\program files\iPod
2009-07-16 21:42 . 2009-03-12 14:40 -------- d-----w- c:\program files\Common Files\Apple
2009-07-16 21:41 . 2009-03-06 04:31 -------- d-----w- c:\program files\QuickTime Alternative
2009-07-16 21:37 . 2009-07-16 21:37 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-09 22:19 . 2009-07-09 22:18 -------- d-----w- c:\program files\Common Files\Real
2009-07-09 22:19 . 2009-07-09 22:19 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-09 22:19 . 2009-07-09 22:19 -------- d-----w- c:\program files\Real
2009-07-09 22:19 . 2009-03-06 04:31 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-09 22:19 . 2003-03-19 02:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-08 13:11 . 2009-07-08 13:11 -------- d-----w- c:\program files\MP3 Player Utilities 3.75
2009-06-23 23:46 . 2009-06-23 23:46 65074 --sh--r- c:\windows\usbmngr.exe
2009-03-11 19:18 . 2009-03-11 19:18 56 --sh--r- c:\windows\system32\56CD60389B.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-13 2007832]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2008-12-22 240656]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-09 198160]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-03 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-11-17 17676288]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
"Windows Data Serivce"="usbmngr.exe" - c:\windows\usbmngr.exe [2009-06-23 65074]
"traymanager"="traymanager.exe" - c:\windows\traymanager.exe [2009-08-26 118829]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 13:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2009-05-09 11:48 210168 ----a-w- c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-31 06:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/8/2009 9:07 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/8/2009 9:07 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/8/2009 9:07 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/10/2009 12:19 AM 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [4/30/2009 8:53 AM 1370488]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [3/8/2009 9:03 PM 29208]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [3/6/2009 6:54 AM 38400]
R3 RTCore32;RTCore32;c:\program files\EVGA Precision\RTCore32.sys [5/25/2005 9:39 PM 4608]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 6:46 AM 288112]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [3/17/2009 10:26 PM 16512]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [3/8/2009 9:03 PM 29208]
--- Other Services/Drivers In Memory ---
*Deregistered* - aujasnkj
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-08-30 c:\windows\Tasks\User_Feed_Synchronization-{6EDAEBEF-8F93-49CE-965C-6D6180D1119F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Real Desktop - c:\program files\Real Desktop\Real Desktop.exe
HKCU-Run-Microsoft Drive Guard - c:\documents and settings\Administrator\DrvGuard.exe
HKCU-Run-DLD.EXE - c:\program files\Download Direct\DLD.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-LClock - c:\program files\LClock\LClock.exe
HKLM-Run-Launch LGDCore - c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe
HKLM-Run-Launch LCDMon - c:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pxdgk9ry.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-08-30 16:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-606747145-920026266-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,42,39,ba,6d,0f,43,3d,49,a5,60,a4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,42,39,ba,6d,0f,43,3d,49,a5,60,a4,\
[HKEY_USERS\S-1-5-21-606747145-920026266-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_USERS\S-1-5-21-606747145-920026266-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*4]
@Class="Shell"
[HKEY_USERS\S-1-5-21-606747145-920026266-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*4\OpenWithList]
@Class="Shell"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:5f,0a,e3,33,96,f2,e4,27,18,a7,5c,3e,0f,e7,47,ac,ec,0b,46,98,74,
7f,5a,ed,eb,98,2d,66,2f,09,c0,16,ce,3e,50,26,eb,79,dc,e8,41,80,ef,c3,94,00,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:5f,0a,e3,33,96,f2,e4,27,18,a7,5c,3e,0f,e7,47,ac,ec,0b,46,98,74,
7f,5a,ed,eb,98,2d,66,2f,09,c0,16,ce,3e,50,26,eb,79,dc,e8,41,80,ef,c3,94,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1032)
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
.
Completion time: 2009-08-30 16:23
ComboFix-quarantined-files.txt 2009-08-30 14:23
ComboFix2.txt 2009-03-09 22:02
Pre-Run: 70,667,714,560 bytes free
Post-Run: 73,327,968,256 bytes free
248
|