offline
- Balkanac82
- Legendarni građanin
- Pridružio: 20 Dec 2004
- Poruke: 2887
- Gde živiš: Na Balkanu
|
ComboFix 09-03-06.02 - Miljan 2009-03-09 8:28:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1334 [GMT -5:00]
Running from: c:\documents and settings\Miljan\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\MabryObj.dll
c:\windows\system32\nett12.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-09 to 2009-03-09 )))))))))))))))))))))))))))))))
.
2009-03-08 22:18 . 2009-03-08 22:19 <DIR> d-------- c:\program files\Transcender
2009-03-08 22:18 . 2007-11-15 19:11 2,155,096 --a------ c:\windows\system32\QDMEAXRT.ocx
2009-03-07 09:21 . 2009-03-07 09:21 <DIR> d-------- c:\program files\Common Files\Macromedia
2009-03-07 09:20 . 2009-03-07 09:20 <DIR> d-------- c:\program files\Macromedia
2009-03-04 21:38 . 2009-03-04 21:38 <DIR> d-------- c:\program files\TechSmith
2009-03-04 21:38 . 2009-03-04 21:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\TechSmith
2009-03-04 21:37 . 2009-03-04 21:37 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-04 21:09 . 2009-03-04 21:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\LightScribe
2009-03-01 21:50 . 2009-03-01 21:50 <DIR> d-------- c:\program files\Microsoft Visual Studio .NET
2009-03-01 21:49 . 2009-03-01 21:50 <DIR> d-------- C:\oraclexe
2009-03-01 01:29 . 2009-03-07 09:25 182 --a------ c:\windows\wcx_ftp.ini
2009-03-01 01:27 . 2009-03-01 01:28 <DIR> d-------- C:\totalcmd
2009-03-01 01:27 . 2009-03-07 09:25 1,594 --a------ c:\windows\wincmd.ini
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\UC.PIF
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\RAR.PIF
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\PKZIP.PIF
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\PKUNZIP.PIF
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\NOCLOSE.PIF
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\LHA.PIF
2009-03-01 01:27 . 2008-08-08 08:04 545 --a------ c:\windows\ARJ.PIF
2009-02-28 21:41 . 2009-02-28 21:41 <DIR> dr------- c:\documents and settings\Miljan\Application Data\Brother
2009-02-28 21:41 . 2009-03-05 15:29 426 --a------ c:\windows\BRWMARK.INI
2009-02-28 21:41 . 2009-02-28 21:41 34 --a------ c:\windows\system32\BD5250DN.DAT
2009-02-27 23:19 . 2009-02-27 23:49 <DIR> d-------- c:\documents and settings\Miljan\dwhelper
2009-02-27 21:07 . 2009-02-27 21:07 <DIR> d-------- c:\windows\Sun
2009-02-24 13:03 . 2009-02-24 13:03 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-02-24 07:36 . 2008-10-16 15:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-24 07:36 . 2008-10-16 15:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-24 07:36 . 2008-10-16 15:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-23 15:45 . 2009-03-08 18:49 488 --a------ C:\hpfr5550.xml
2009-02-23 15:44 . 2009-02-23 15:44 <DIR> d-------- c:\documents and settings\Miljan\Application Data\Hewlett-Packard
2009-02-23 15:41 . 2008-04-13 13:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-02-23 15:41 . 2008-04-13 13:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2009-02-23 15:40 . 2009-02-23 15:40 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-02-23 15:40 . 2008-04-13 13:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-23 15:40 . 2008-04-13 13:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-02-23 15:39 . 2009-02-23 15:39 <DIR> d-------- c:\program files\Hewlett-Packard
2009-02-23 15:38 . 2009-02-23 15:38 <DIR> d-------- c:\temp\HP All-in-One Series Web Release
2009-02-23 15:38 . 2009-02-23 15:38 <DIR> d-------- C:\temp
2009-02-23 15:38 . 2009-02-23 15:42 19,558 --a------ c:\windows\hpoins01.dat
2009-02-23 15:38 . 2003-04-22 11:24 16,606 --------- c:\windows\hpomdl01.dat
2009-02-23 14:50 . 2009-02-23 14:50 <DIR> d-------- c:\documents and settings\Miljan\Application Data\OpenOffice.org
2009-02-23 14:14 . 2009-02-23 14:14 <DIR> d-------- c:\program files\iTunes
2009-02-23 14:14 . 2009-02-23 14:14 <DIR> d-------- c:\program files\iPod
2009-02-23 14:14 . 2009-02-23 14:14 <DIR> d-------- c:\program files\Bonjour
2009-02-23 14:14 . 2009-02-23 14:41 <DIR> d-------- c:\documents and settings\Miljan\Application Data\Apple Computer
2009-02-23 14:14 . 2009-02-23 14:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-23 14:13 . 2009-02-23 14:13 <DIR> d-------- c:\program files\QuickTime
2009-02-23 14:13 . 2009-02-23 14:14 <DIR> d-------- c:\program files\Common Files\Apple
2009-02-23 14:13 . 2009-02-23 14:13 <DIR> d-------- c:\program files\Apple Software Update
2009-02-23 14:13 . 2009-02-23 14:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-23 14:13 . 2009-02-23 14:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2009-02-23 13:33 . 2009-02-23 13:33 <DIR> d-------- c:\program files\FLV Player
2009-02-23 13:28 . 2009-02-23 13:28 <DIR> d-------- c:\documents and settings\Miljan\Application Data\DivX
2009-02-23 13:27 . 2009-02-23 13:28 <DIR> d-------- c:\program files\DivX
2009-02-23 12:42 . 2009-03-08 19:59 2,984,152 --a------ C:\bar.emf
2009-02-23 12:02 . 2009-02-23 12:02 162 --a------ c:\windows\ODBC.INI
2009-02-23 11:34 . 2009-02-23 12:04 <DIR> d-------- c:\documents and settings\Miljan\Application Data\GetRightToGo
2009-02-23 11:31 . 2009-02-23 11:31 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-02-22 14:06 . 2009-03-08 23:02 69 --a------ c:\windows\NeroDigital.ini
2009-02-22 14:05 . 2009-03-07 11:45 <DIR> d-------- c:\documents and settings\Miljan\Application Data\U3
2009-02-21 21:16 . 2009-02-21 21:16 <DIR> d-------- c:\program files\FileZilla FTP Client
2009-02-21 21:16 . 2009-02-27 16:31 <DIR> d-------- c:\documents and settings\Miljan\Application Data\FileZilla
2009-02-21 21:13 . 2009-02-21 21:04 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-21 21:10 . 2009-02-21 21:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-21 21:10 . 2009-02-21 21:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-21 21:05 . 2009-02-21 21:04 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-21 21:03 . 2009-02-21 21:03 <DIR> d-------- c:\program files\Lavasoft
2009-02-21 21:03 . 2009-02-21 21:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-21 21:03 . 2009-02-21 21:03 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-21 21:00 . 2009-02-21 21:00 <DIR> d-------- c:\program files\Trend Micro
2009-02-21 20:56 . 2009-02-21 20:56 <DIR> d-------- c:\documents and settings\Miljan\.tuxguitar-1.0
2009-02-21 20:55 . 2009-02-21 20:56 <DIR> d-------- c:\program files\tuxguitar-1.0
2009-02-21 20:47 . 2009-02-21 20:47 <DIR> d-------- c:\program files\Common Files\LightScribe
2009-02-21 20:46 . 2009-03-04 21:09 <DIR> d-------- c:\documents and settings\Miljan\Application Data\Ahead
2009-02-21 20:46 . 2009-02-21 20:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ahead
2009-02-21 20:42 . 2009-02-21 20:42 <DIR> d-------- c:\program files\Nero
2009-02-21 20:42 . 2009-02-21 20:46 <DIR> d-------- c:\program files\Common Files\Ahead
2009-02-21 20:42 . 2009-02-21 20:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2009-02-21 20:25 . 2009-02-21 20:25 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-21 15:05 . 2009-02-21 15:05 <DIR> d-------- c:\program files\NewTech Infosystems
2009-02-21 15:05 . 2007-12-06 09:06 24,147,994 --a------ C:\Shadow for PC.exe
2009-02-21 15:05 . 2000-08-02 21:50 1,056,768 --a------ c:\windows\system32\roboex32.dll
2009-02-21 14:52 . 2009-02-21 14:52 <DIR> d-------- c:\program files\OpenOffice.org 3
2009-02-21 14:52 . 2009-02-21 14:52 <DIR> d-------- c:\program files\JRE
2009-02-21 08:42 . 2009-02-21 08:44 <DIR> d-------- c:\documents and settings\Miljan\Application Data\Dev-Cpp
2009-02-21 08:42 . 2009-02-21 08:42 <DIR> d-------- C:\Dev-Cpp
2009-02-21 08:19 . 2008-04-13 19:11 21,504 --a------ c:\windows\system32\hidserv.dll
2009-02-21 08:19 . 2008-04-13 19:11 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
2009-02-21 08:18 . 2008-04-13 13:39 14,592 --a------ c:\windows\system32\drivers\kbdhid.sys
2009-02-21 08:18 . 2008-04-13 13:39 14,592 --a--c--- c:\windows\system32\dllcache\kbdhid.sys
2009-02-21 08:18 . 2001-08-17 14:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-02-21 08:18 . 2001-08-17 14:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-02-21 08:18 . 2008-04-13 13:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-21 08:18 . 2008-04-13 13:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-02-21 01:22 . 2009-02-21 01:22 <DIR> d-------- c:\program files\Notepad++
2009-02-21 01:22 . 2009-02-21 01:22 <DIR> d-------- c:\documents and settings\Miljan\Application Data\Notepad++
2009-02-21 01:19 . 2009-02-21 01:19 <DIR> d-------- c:\program files\ESET
2009-02-21 01:19 . 2009-02-21 01:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2009-02-21 01:12 . 2009-02-21 01:12 16 --a------ c:\windows\system32\coh.cache
2009-02-21 01:04 . 2008-06-13 06:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-02-21 01:02 . 2008-08-14 05:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-21 01:02 . 2008-08-14 05:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-21 01:02 . 2008-08-14 04:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-21 01:02 . 2008-08-14 04:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-21 01:02 . 2008-09-15 07:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2009-02-21 01:01 . 2009-02-21 01:01 0 --a------ c:\windows\nsreg.dat
2009-02-21 00:59 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-21 00:59 . 2008-05-08 09:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2009-02-21 00:58 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2009-02-21 00:58 . 2008-12-11 05:57 333,952 -----c--- c:\windows\system32\dllcache\srv.sys
2009-02-21 00:58 . 2008-05-01 09:33 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2009-02-21 00:57 . 2008-12-20 18:15 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-02-21 00:57 . 2007-04-17 04:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-02-21 00:57 . 2007-03-08 00:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-21 00:57 . 2008-12-20 18:15 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-02-21 00:57 . 2008-12-20 18:15 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-02-21 00:57 . 2008-12-20 18:15 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-02-21 00:57 . 2008-12-20 18:15 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-02-21 00:57 . 2008-12-20 18:15 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-21 00:57 . 2008-12-19 04:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-02-21 00:56 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-02-21 00:56 . 2008-10-15 11:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2009-02-21 00:56 . 2008-10-03 05:02 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2009-02-21 00:53 . 2009-02-21 00:53 4,212 --ah----- c:\windows\system32\zllictbl.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-07 14:20 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-02 02:50 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-02 02:48 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-22 01:52 --------- d-----w c:\program files\Google
2009-02-21 19:52 --------- d-----w c:\program files\Java
2009-02-21 06:15 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-21 06:15 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-02-21 05:42 --------- d-----w c:\program files\TOSHIBA
2009-02-21 05:35 21,361 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-02-21 05:35 21,361 ----a-w c:\windows\AegisP.sys
2009-02-21 05:35 --------- d-----w c:\program files\Intel
2009-02-21 05:29 315,392 ----a-w c:\windows\HideWin.exe
2009-02-21 05:29 --------- d-----w c:\program files\Realtek
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-03-07 03:25 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2008-03-04 360448]
"DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2007-04-13 311296]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2007-04-09 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-05 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-05 137752]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1024000]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-24 1451264]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-21 509784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"TFncKy"="TFncKy.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2008-01-29 c:\windows\RTHDCPL.exe]
"TPSMain"="TPSMain.exe" [2007-10-08 c:\windows\system32\TPSMain.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-09 28672]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-21 64160]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-10-24 34824]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-10-24 468224]
R2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE --> c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE [?]
R2 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE [2006-02-02 204800]
R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2007-03-26 105856]
R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [2007-02-19 134016]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-03-06 5888]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE --> c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-02-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-21 21:04]
2009-02-23 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1235421750.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 18:56]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Miljan\Application Data\Mozilla\Firefox\Profiles\vmpwepcz.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 08:29:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\netprovcredman.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2009-03-09 8:30:22
ComboFix-quarantined-files.txt 2009-03-09 13:30:20
Pre-Run: 120,034,508,800 bytes free
Post-Run: 120,123,183,104 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
270 --- E O F --- 2009-02-25 18:32:54
|