offline
- snoop
- Genghis Khan
- Pridružio: 18 Apr 2003
- Poruke: 8134
- Gde živiš: U kesici gumenih bombona...
|
IP adresa mu nije poznata...
Evo ComboFix loga:
ComboFix 08-06-15.4 - dr.mrvica 2008-06-17 14:34:49.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.1.1033.18.1244 [GMT 2:00]
Running from: C:\Users\dr.mrvica\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-17 to 2008-06-17 )))))))))))))))))))))))))))))))
.
2008-06-14 23:12 . 2008-06-15 13:02 <DIR> d-------- C:\Users\dr.mrvica\{b5e230ac-077b-401d-9c1d-8386d09b432c}
2008-06-14 23:12 . 2008-06-15 13:02 <DIR> d-------- C:\Program Files\MT882
2008-06-14 23:12 . 2006-03-22 11:59 19,220 --a------ C:\Windows\wwdslcfg.ini
2008-06-14 22:25 . 2008-06-14 22:25 691 --a------ C:\Users\dr.mrvica\AppData\Roaming\GetValue.vbs
2008-06-14 22:25 . 2008-06-14 22:25 35 --a------ C:\Users\dr.mrvica\AppData\Roaming\SetValue.bat
2008-06-14 20:24 . 2008-06-14 22:25 1,490 --a------ C:\Windows\System32\tmp.reg
2008-06-14 16:00 . 2008-06-15 13:02 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-06-14 16:00 . 2008-06-15 13:02 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-06-14 16:00 . 2008-06-14 16:00 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-14 13:19 . 2008-06-15 18:42 218 --a------ C:\Windows\EurekaLog.ini
2008-06-14 12:33 . 2008-06-14 12:33 <DIR> d-------- C:\Program Files\Marvell
2008-06-11 13:48 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-11 13:48 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-11 13:48 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-11 13:48 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-03 11:56 . 2008-06-03 11:56 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-06-03 11:50 . 2008-06-03 11:50 <DIR> d-------- C:\Program Files\Nero
2008-06-03 11:50 . 2008-06-03 11:52 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-06-01 17:43 . 2008-06-04 13:34 <DIR> d-------- C:\Kurir 2008
2008-05-29 10:36 . 2008-05-29 10:36 <DIR> d-------- C:\Program Files\CCleaner
2008-05-28 16:52 . 2008-03-08 04:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-28 16:52 . 2008-03-08 06:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-22 16:47 . 2008-05-28 15:50 <DIR> d-------- C:\Users\dr.mrvica\Adobe Premiere Elements Auto-Save
2008-05-22 16:25 . 2008-05-28 15:31 <DIR> d-------- C:\Users\dr.mrvica\Media Cache Files
2008-05-22 16:25 . 2008-05-28 15:52 <DIR> d-------- C:\Users\dr.mrvica\Encoded Files
2008-05-22 16:25 . 2008-05-28 15:30 <DIR> d-------- C:\Users\dr.mrvica\Adobe Premiere Elements Preview Files
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-17 12:36 722,004,000 --sha-w C:\Windows\system32\drivers\fidbox.dat
2008-06-17 12:30 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-06-17 12:21 --------- d-----w C:\Program Files\AskTBar
2008-06-17 12:20 9,671,456 --sha-w C:\Windows\system32\drivers\fidbox.idx
2008-06-16 11:29 --------- d---a-w C:\ProgramData\TEMP
2008-06-16 07:47 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 5
2008-06-15 11:02 --------- d-----w C:\ProgramData\FLEXnet
2008-06-14 17:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-14 07:01 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\IDM
2008-06-14 07:01 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\DMCache
2008-06-13 11:42 --------- d-----w C:\Program Files\Winamp
2008-06-13 11:41 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\Winamp
2008-06-12 18:52 --------- d-----w C:\Program Files\Winamp Remote
2008-06-11 12:06 --------- d-----w C:\Program Files\Windows Mail
2008-06-03 10:50 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\Ahead
2008-06-03 09:50 --------- d-----w C:\ProgramData\Nero
2008-06-03 08:43 --------- d-----w C:\Program Files\FlashGet
2008-06-03 08:20 --------- d-----w C:\ProgramData\BlazeVideo
2008-06-03 08:09 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-03 08:08 --------- d-----w C:\ProgramData\ACD Systems
2008-06-03 08:08 --------- d-----w C:\Program Files\ACD Systems
2008-05-29 18:30 88,774 ----a-w C:\Windows\system32\drivers\klick.dat
2008-05-28 16:35 96,966 ----a-w C:\Windows\system32\drivers\klin.dat
2008-05-28 13:43 112,144 ----a-w C:\Windows\system32\drivers\kl1.sys
2008-05-21 10:33 --------- d-----w C:\Program Files\Easy Video Downloader
2008-05-20 10:47 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-15 13:04 --------- d-----w C:\Program Files\Common Files\LogiShrd
2008-05-15 13:03 --------- d-----w C:\ProgramData\LogiShrd
2008-05-15 13:03 --------- d-----w C:\Program Files\Logitech
2008-05-14 15:16 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-05-14 15:15 354,560 ----a-w C:\Windows\System32\TuneUpDefragService.exe
2008-05-14 15:11 --------- d-----w C:\ProgramData\TuneUp Software
2008-05-14 15:10 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-14 15:07 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\TuneUp Software
2008-05-14 15:07 --------- d-----w C:\Program Files\TuneUp Utilities 2008 (made by Fares)
2008-05-14 14:03 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-13 16:16 --------- d-----w C:\Program Files\BlazeVideo
2008-05-11 08:17 --------- d-----w C:\ProgramData\Kaspersky Lab Setup Files
2008-05-10 01:33 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-05-09 07:03 --------- d-----w C:\Program Files\Pinnacle
2008-05-08 21:17 --------- d-----w C:\ProgramData\Pinnacle Studio
2008-05-08 21:17 --------- d-----w C:\ProgramData\Pinnacle
2008-05-08 13:10 52,809 ----a-w C:\Windows\UN_CODA.EXE
2008-05-06 06:58 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\Skype
2008-05-06 06:57 --------- d-----w C:\Users\dr.mrvica\AppData\Roaming\skypePM
2008-05-01 20:16 --------- d-----w C:\Program Files\EA SPORTS
2008-04-30 18:42 --------- d-----w C:\Program Files\HP
2008-04-30 12:14 56 ---ha-w C:\Users\All Users\ezsidmv.dat
2008-04-30 12:14 56 ---ha-w C:\ProgramData\ezsidmv.dat
2008-04-30 12:11 --------- d-----w C:\ProgramData\Skype
2008-04-30 12:11 --------- d-----w C:\Program Files\Skype
2008-04-30 12:10 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-29 09:56 --------- d-----w C:\ProgramData\InterAction studios
2008-04-29 09:53 --------- d-----w C:\Program Files\ReflexiveArcade
2008-04-29 09:53 --------- d-----w C:\Program Files\Chicken Invaders 3
2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-04-29 01:42 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2008-04-29 01:42 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 15:46 --------- d-----w C:\ProgramData\DVD Shrink
2008-04-25 10:30 130,208 ------r C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-04-24 11:54 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-04-24 11:50 --------- d-----w C:\Program Files\Realtek
2008-04-23 21:22 --------- d-----w C:\ProgramData\Test Drive Unlimited
2008-04-17 19:09 --------- d-----w C:\Program Files\Atari
2008-04-17 14:31 2,098,904 ----a-w C:\Windows\system32\drivers\RTKVHDA.sys
2008-04-17 09:50 6,111,232 ----a-w C:\Windows\RtHDVCpl.exe
2008-04-16 12:28 2,172,416 ----a-w C:\Windows\System32\RtkAPO.dll
2008-04-16 11:22 1,929,216 ----a-w C:\Windows\System32\MaxxAudioEQ.dll
2008-04-16 10:16 1,773,568 ----a-w C:\Windows\System32\WavesLib.dll
2008-04-15 09:45 140,288 ----a-w C:\Windows\System32\FMAPO.dll
2008-04-12 11:56 127,034 ------r C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-04-11 15:23 38,400 ----a-w C:\Windows\System32\SoundSchemes.exe
2008-04-09 09:15 694,272 ----a-w C:\Windows\System32\RtkPgExt.dll
2008-04-06 16:06 155,648 ----a-w C:\Windows\System32\MaxxAudioAPO20.dll
2008-04-04 12:51 28,416 ----a-w C:\Windows\System32\uxtuneup.dll
2008-04-04 12:51 16,640 ----a-w C:\Windows\System32\authuitu.dll
2008-04-03 14:51 31,232 ----a-w C:\Windows\System32\RtkCoInst.dll
2008-04-03 06:16 174 --sha-w C:\Program Files\desktop.ini
2008-04-03 05:48 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-03 05:48 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-02 07:27 1,196,032 ----a-w C:\Windows\RtlUpd.exe
2008-03-28 08:59 285,216 ----a-w C:\Windows\System32\RtkApoApi.dll
2007-11-30 23:45 22,328 ----a-w C:\Users\dr.mrvica\AppData\Roaming\PnkBstrK.sys
2006-01-23 09:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 13:40 132,848 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
2007-10-24 19:51 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-10-24 19:51 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-10-24 19:51 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-06-17_14.16.56,66 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-17 11:21:49 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-06-17 12:21:56 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-06-17 11:24:50 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-06-17 12:25:04 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-06-17 11:24:45 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-17 12:24:17 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-17 12:24:17 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-06-17 11:23:25 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-17 12:23:31 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-17 11:23:25 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-17 12:23:31 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-17 11:23:25 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-17 12:23:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-17 11:46:57 105,586 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-06-17 12:27:58 105,586 ----a-w C:\Windows\System32\perfc009.dat
- 2008-06-17 11:46:57 598,212 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-06-17 12:27:58 598,212 ----a-w C:\Windows\System32\perfh009.dat
- 2008-06-17 11:24:59 10,996 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1966442060-1778625922-3816698468-1000_UserData.bin
+ 2008-06-17 12:25:05 10,996 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1966442060-1778625922-3816698468-1000_UserData.bin
- 2008-06-17 11:24:59 112,978 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-17 12:25:05 113,118 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-06-17 11:24:58 68,788 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-06-17 12:25:04 68,796 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2008-01-19 09:33 227840]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-17 11:50 6111232 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=acaptuser32.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GammaTray.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk
backup=C:\Windows\pss\GammaTray.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\Windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Media Key.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Media Key.lnk
backup=C:\Windows\pss\Media Key.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=C:\Windows\pss\NaturalColorLoad.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Server4PC.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Server4PC.lnk
backup=C:\Windows\pss\Server4PC.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\Windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^dr.mrvica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Users\dr.mrvica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\Windows\pss\Adobe Gamma.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^dr.mrvica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Ubisoft register.lnk]
path=C:\Users\dr.mrvica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ubisoft register.lnk
backup=C:\Windows\pss\Ubisoft register.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^dr.mrvica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^UDPixel.lnk]
path=C:\Users\dr.mrvica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UDPixel.lnk
backup=C:\Windows\pss\UDPixel.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^dr.mrvica^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Users\dr.mrvica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\Windows\pss\Webshots.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2008-01-11 20:54 623992 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
--a------ 2007-05-11 02:59 46200 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ai Quicker Help]
--a------ 2006-11-09 21:29 3165696 C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2007-07-02 12:29 220544 C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSGamerOSD]
--a------ 2007-02-14 09:42 380928 C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
--a------ 2007-11-16 20:20 91432 C:\Program Files\Cyberlink\Shared Files\brs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
--a------ 2007-12-01 11:03 282624 C:\Program Files\BlazeVideo\BlazeDTV 3.5\MediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
C:\Program Files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVBV Service Ctrl]
C:\Program Files\DVBViewerTE\DVBVCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-05-30 09:28 1986608 C:\Program Files\FlashGet\FlashGet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GameFace Messenger]
C:\Program Files\GameFace Messenger\GameFace.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 08:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2007-11-27 21:20 2553264 C:\Program Files\IDM\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--------- 2007-10-11 13:06 62760 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
--a------ 2006-07-24 15:32 3712512 C:\Program Files\ASUS\AI Booster\OverClk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2007-10-25 16:33 563984 C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-10-25 16:37 2178832 C:\Program Files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicTuneEngine]
--a------ 2007-06-14 11:00 69632 C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-02-18 16:29 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-09-12 05:28 8497696 C:\Windows\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-09-12 05:28 81920 C:\Windows\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-09-12 05:28 86016 C:\Windows\system32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 2008-01-07 22:02 495616 C:\Program Files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-07-06 21:30 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-10-28 10:35 72736 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-04-23 17:45 22058792 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
--a------ 2007-11-20 18:15 1826816 C:\Windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-10-22 14:44 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse]
--a------ 2007-02-10 16:07 241664 C:\Program Files\A4Tech\Mouse\Amoumain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-04-01 20:49 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 09:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{5BF2980C-A1DD-4C0F-8CB1-686656FC8497}C:\\windows.old\\program files\\atari\\test drive unlimited\\testdriveunlimited.exe"= UDP:C:\windows.old\program files\atari\test drive unlimited\testdriveunlimited.exe:Test Drive Unlimited
"UDP Query User{41FA0A23-17AB-44F8-8EDD-BC3CAAB242B9}C:\\windows.old\\program files\\atari\\test drive unlimited\\testdriveunlimited.exe"= TCP:C:\windows.old\program files\atari\test drive unlimited\testdriveunlimited.exe:Test Drive Unlimited
"{62E27DD4-1A07-4512-A90A-3ED366227BA9}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{BB0AAAE1-0855-42F2-A80E-AB2B0CA1312C}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{41AE3B70-4BAB-40F6-943D-65C3F5D5A0D0}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{2211E951-BCD3-40F8-AA11-BF518A89CAB6}"= UDP:C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\Win32\RpcDataSrv.exe:SiSoftware Database Agent Service
"{6CA1E0F6-5DCD-4849-B9B4-ACFCE6DAC831}"= TCP:C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\Win32\RpcDataSrv.exe:SiSoftware Database Agent Service
"{63A736C4-68DC-477A-A931-371EFEF620AC}"= UDP:C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\RpcSandraSrv.exe:SiSoftware Sandra Agent Service
"{EA857E69-9007-40AC-AE73-10460F1C99D2}"= TCP:C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\RpcSandraSrv.exe:SiSoftware Sandra Agent Service
"{2F664432-B8DF-4F38-8315-AE584A23F695}"= UDP:C:\Program Files\Cyanide\GameCenter\GameCenter.exe:GameCenter
"{C6CBD623-2F57-4AE5-90D1-C90CFC596118}"= TCP:C:\Program Files\Cyanide\GameCenter\GameCenter.exe:GameCenter
"{2A2B36E9-93A8-402C-9067-3BA89521AD82}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{782DE86A-E891-48B0-9D62-D8476C736CA3}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{3BE807BB-852A-459B-9779-AADCBC56E0B8}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{E8380277-9065-4A24-9A60-E1BC829AA9FB}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{F01ACC42-CE26-440E-A7C8-F936F13D3B69}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{BB6ADFF9-B294-433E-B919-AA282402564E}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{F1181EC6-FEBD-468F-944D-7E6C3C88A07C}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent
"{00009BF6-ABBD-40A1-B2C5-50A2C23973D0}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{A6F49E45-15CF-4E4C-84BB-3026D0D847D4}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{D2C43C6E-FCDE-42C1-8C67-D856CFB07EBF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{0F4139F4-74F6-413A-A267-CCEE3EAE86B9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{64F21FB5-DE19-4317-99B3-AFF2CE6B7112}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{95272E3C-C528-413D-8948-3975E454FEF9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{AD7267E0-2533-4E9D-A165-272D6D16FDF8}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{13A39E82-E3A6-4395-8A0B-8B187B477C8E}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{1F013F81-5FEC-45BE-B7D3-6D8F41444E64}"= C:\Program Files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{D89C3202-6C7E-41BF-A528-206C7BC44226}"= UDP:E:\Games instal\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{D1A52822-0E7A-4DC0-994E-07A2A2D450C4}"= TCP:E:\Games instal\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{10C3840F-9E89-4B5C-BF6E-4B506CE110A4}"= UDP:E:\Games instal\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{583068CF-EF3D-4BB6-A988-6F7EFF953EFC}"= TCP:E:\Games instal\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{32B2437C-5C24-4EC5-99AC-D5EF4E3246C5}"= UDP:E:\Games instal\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{71A5278C-D80C-410D-8735-F24944A7DAAB}"= TCP:E:\Games instal\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{66FB0024-0E23-41CE-A010-F3E6DC4B046C}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{7C58299B-880C-4D53-B631-12001547C14B}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{99B2B226-B21E-4E3E-B611-21B75FAC5B09}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{4469966D-53BF-445C-9F6A-A614C9EB5A1A}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{3DF14977-8C58-4442-8E30-1187C2C01ECA}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{D0371663-B913-4E04-8440-EC836A5A209E}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{E6C57F03-51BB-4C74-93BD-A27EF564CEC0}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{CF9B3887-BF47-4947-B12B-65C011077AF8}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{B53270E6-F0F5-49AA-9030-8DBB28A51FD2}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{1B4B9EF8-B4DF-43F5-8A28-A4EB75D93BD2}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{3A42CE08-58AF-42B9-92E7-BF9DD0E9DED9}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{57BFEC72-6D3F-4586-8979-E145DA44DAAA}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{4D040D81-1D35-4408-8545-3873E293DC8E}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{3025BC81-B41C-47CB-9EA9-1BCD5C499B91}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
"{5DAAFE36-A73E-448A-BC31-2EC1D6940353}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\xchat\\xchat.exe"= C:\Program Files\xchat\xchat.exe:*:Enabled:XChat IRC Client
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\Windows\system32\drivers\sfsync03.sys [2006-07-11 09:30]
R1 atkdisplf;ATK Kernel Mode Enhanced Driver;C:\Windows\system32\Drivers\atkdisplowfilter.sys [2007-04-02 18:03]
R1 kbfilter;Keyboard Filter Drive;C:\Windows\system32\drivers\kbfilter.sys [2002-07-11 13:00]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2007-10-16 12:05]
R1 UsbFltr;WayTechUSBFilterDrive;C:\Windows\system32\drivers\UsbFltr.sys [2003-12-29 19:27]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 01:12]
R2 ASDR;ASDR;C:\Windows\System32\ASDR.exe [2007-03-20 18:16]
R2 cvintdrv;cvintdrv;C:\Windows\system32\drivers\cvintdrv.sys [2006-07-27 11:00]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2008-01-19 09:33]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187.sys [2007-11-19 07:59]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\Windows\system32\DRIVERS\SkyNET.SYS [2007-03-06 14:39]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 10:51]
S2 ATKFUSService;ATK Fast User Switch Service;C:\Windows\system32\ATKFUSService.exe [2007-04-02 18:08]
S2 DVBVRecorder;DVBViewer Recording service;C:\Program Files\DVBViewerTE\DVBVservice.exe []
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;C:\Windows\system32\DRIVERS\Amps2prt.sys [2007-02-09 20:04]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 13:54]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-05-14 17:15]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;"C:\Program Files\MSN Messenger\usnsvc.exe" [2007-01-19 12:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
GPSvcGroup REG_MULTI_SZ GPSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{321be1ce-612e-11dc-8a1e-00d0d70f7fc6}]
\shell\Auto\command - L:\Cn911.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL L:\Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ec7909-7243-11dc-bc48-806e6f6e6963}]
\shell\AutoRun\command - K:\setup.exe
\shell\configure\command - K:\setup.exe
\shell\install\command - K:\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
"2008-06-13 17:09:12 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-06-13 19:32:00 C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 14:39:13
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-17 14:40:54
ComboFix-quarantined-files.txt 2008-06-17 12:40:50
ComboFix2.txt 2008-06-17 12:18:10
Pre-Run: 10,180,591,616 bytes free
Post-Run: 10,125,606,912 bytes free
402 --- E O F --- 2008-06-11 12:04:19
|