offline
- anjes
- Novi MyCity građanin
- Pridružio: 15 Mar 2009
- Poruke: 6
|
Imam Symantec u Program files - Live update, Symantec u Program data, kao i Symantec shared u Program files/Common files.
Izgleda da je Vista puna Symanteca.
ComboFix 09-03-14.01 - RR 2009-03-15 15:31:37.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.381.1033.18.1917.1072 [GMT 1:00]
Running from: c:\users\RR\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
/wow section - STAGE 41
The system cannot find the path specified.
The system cannot find the path specified.
The system cannot find the path specified.
The system cannot find the path specified.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\A360
c:\program files\A360\av360.exe.tmp
c:\program files\FBrowserAdvisor
c:\program files\FBrowsingAdvisor
c:\program files\FBrowsingAdvisor\IXPCOMEvents.xpt
c:\program files\FBrowsingAdvisor\Logo.png
c:\program files\FBrowsingAdvisor\main.db
c:\program files\FBrowsingAdvisor\unins000.dat
c:\program files\FBrowsingAdvisor\unins000.exe
c:\windows\system32\lsprst7.dll
c:\windows\system32\nsprs.dll
c:\windows\system32\serauth1.dll
c:\windows\system32\serauth2.dll
c:\windows\system32\ssprs.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.
2009-03-14 20:15 . 2009-03-14 20:15 2,048 --a------ c:\windows\System32\sysprs7.tgz
2009-03-14 20:15 . 2009-03-14 20:15 2,048 --a------ c:\windows\System32\sysprs7.dll
2009-03-14 20:15 . 2009-03-14 20:34 219 --a------ c:\windows\System32\lsprst7.tgz
2009-03-14 20:15 . 2009-03-14 20:34 16 ---h----- c:\windows\System32\servdat.slm
2009-03-14 20:15 . 2009-03-14 20:15 14 --a------ c:\windows\System32\tmpPrst.tgz
2009-03-14 20:15 . 2009-03-14 20:34 14 --a------ c:\windows\System32\ssprs.tgz
2009-03-14 00:00 . 2009-03-14 00:00 <DIR> d-------- c:\users\All Users\SpeedBit
2009-03-14 00:00 . 2009-03-14 00:00 <DIR> d-------- c:\programdata\SpeedBit
2009-03-13 22:44 . 2009-03-15 15:26 <DIR> d-------- c:\program files\Everything
2009-03-13 21:37 . 2009-03-14 20:34 <DIR> d-------- c:\program files\SPSSEval
2009-03-13 21:07 . 2009-03-13 23:16 <DIR> dr------- c:\users\RR\Downloads
2009-03-10 18:39 . 2009-02-09 04:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-10 18:39 . 2008-11-27 05:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 18:36 . 2009-03-10 18:36 1,024 --a------ c:\windows\System32\clauth2.dll
2009-03-10 18:36 . 2009-03-10 18:36 1,024 --a------ c:\windows\System32\clauth1.dll
2009-03-10 18:36 . 2009-03-10 18:36 0 --a------ c:\windows\System32\nsprs.tgz
2009-03-08 16:33 . 2009-03-08 16:33 49 --a------ c:\windows\NeroDigital.ini
2009-03-08 16:24 . 2009-03-01 13:25 25 ---h----- c:\windows\sysdws.dat
2009-03-07 20:44 . 2009-03-14 20:55 <DIR> d-------- c:\users\RR\AppData\Roaming\Software Informer
2009-03-07 18:46 . 2009-03-07 18:46 <DIR> d-------- c:\users\RR\AppData\Roaming\TuneUp Software
2009-03-07 18:46 . 2009-03-07 18:46 <DIR> d-------- c:\users\All Users\TuneUp Software
2009-03-07 18:46 . 2009-03-07 18:46 <DIR> d-------- c:\programdata\TuneUp Software
2009-03-07 18:46 . 2009-03-07 19:50 603,904 --a------ c:\windows\System32\TUProgSt.exe
2009-03-07 18:45 . 2009-03-07 20:22 <DIR> d--hs---- c:\users\All Users\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-07 18:45 . 2009-03-07 20:22 <DIR> d--hs---- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-07 18:05 . 1998-10-01 16:52 565,760 --a------ c:\windows\System32\msvcp50.dll
2009-03-07 17:47 . 2008-12-16 04:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-07 17:47 . 2008-12-16 06:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-07 17:47 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-07 17:47 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-01 19:18 . 2009-03-14 01:30 <DIR> d-------- c:\users\RR\Tracing
2009-03-01 19:04 . 2009-03-01 19:04 <DIR> d-------- c:\program files\Microsoft Office Outlook Connector
2009-03-01 19:03 . 2009-03-01 19:03 <DIR> d-------- c:\program files\Microsoft Sync Framework
2009-03-01 19:02 . 2009-03-07 17:48 <DIR> d-------- c:\program files\Microsoft
2009-03-01 19:01 . 2009-03-01 19:01 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-03-01 18:36 . 2009-03-01 18:36 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-02-28 17:11 . 2009-02-28 17:11 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-02-28 17:08 . 2009-02-28 17:08 <DIR> d-------- c:\program files\Common Files\Adobe
2009-02-25 18:24 . 2009-02-27 15:52 <DIR> d-------- c:\users\RR\AppData\Roaming\IObit
2009-02-20 22:42 . 2009-02-20 22:42 <DIR> d-------- c:\program files\Common Files\xing shared
2009-02-20 22:42 . 2009-02-20 22:42 <DIR> d-------- c:\program files\Common Files\Real
2009-02-20 21:58 . 2009-02-20 21:58 <DIR> d-------- C:\Fix
2009-02-20 21:58 . 2008-03-03 18:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2009-02-20 21:56 . 2009-02-20 21:56 <DIR> d-------- c:\program files\ESET
2009-02-20 20:24 . 2008-03-03 14:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2009-02-20 20:21 . 2009-02-20 20:21 <DIR> d-------- c:\users\All Users\ESET
2009-02-20 20:21 . 2009-02-20 20:21 <DIR> d-------- c:\programdata\ESET
2009-02-19 23:03 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-19 23:03 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-19 23:03 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-19 23:03 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-19 23:03 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-19 23:03 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-19 23:02 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-19 23:02 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-19 22:53 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-19 22:53 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-19 22:53 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-19 22:53 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-19 22:53 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-19 22:38 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-19 22:38 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-19 22:38 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-19 22:38 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-19 22:38 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-19 20:52 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-19 20:52 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 13:55 --------- d---a-w c:\programdata\TEMP
2009-03-14 22:47 --------- d-----w c:\users\RR\AppData\Roaming\uTorrent
2009-03-14 20:51 --------- d-----w c:\users\RR\AppData\Roaming\Skype
2009-03-13 23:02 --------- d-----w c:\program files\DAP
2009-03-13 22:50 --------- d-----w c:\users\RR\AppData\Roaming\FrostWire
2009-03-13 17:23 --------- d-----w c:\users\RR\AppData\Roaming\skypePM
2009-03-10 18:06 --------- d-----w c:\program files\Windows Mail
2009-03-10 17:49 --------- d-----w c:\programdata\Microsoft Help
2009-03-08 20:24 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-08 15:33 --------- d-----w c:\program files\URUSoft
2009-03-08 15:30 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-08 15:30 --------- d-----w c:\programdata\Ulead Systems
2009-03-08 15:30 --------- d-----w c:\program files\Ulead Systems
2009-03-07 19:40 --------- d-----w c:\program files\IObit
2009-03-01 18:04 --------- d-----w c:\program files\Windows Live
2009-02-27 17:22 --------- d-----w c:\program files\Total Video Player
2009-02-26 18:31 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-24 00:03 --------- d-----w c:\users\RR\AppData\Roaming\Ahead
2009-02-20 21:41 --------- d-----w c:\program files\Real
2009-02-08 16:31 --------- d-----w c:\programdata\Ahead
2009-02-08 16:30 --------- d-----w c:\program files\Common Files\Ahead
2009-02-08 16:27 --------- d-----w c:\programdata\Nero
2009-02-08 16:27 --------- d-----w c:\program files\Nero
2009-02-08 14:55 --------- d-----w c:\program files\SweetIM
2009-02-08 14:23 --------- d-----w c:\users\RR\AppData\Roaming\Crystal Player
2009-02-06 17:52 49,504 ----a-w c:\windows\System32\sirenacm.dll
2009-01-25 01:07 --------- d-----w c:\program files\FrostWire
2009-01-20 05:49 142,848 ----a-w c:\windows\system32\drivers\Rtlh86.sys
2009-01-16 08:59 73,728 ----a-w c:\windows\System32\RtNicProp32.dll
2009-01-01 20:56 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-05-10 20:22 256 ----a-w c:\users\RR\AppData\Roaming\wklnhst.dat
2008-04-01 18:54 174 --sha-w c:\program files\desktop.ini
2009-03-13 23:00 251,392 ----a-w c:\program files\opera\program\plugins\dapop.dll
2008-05-18 20:34 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-05-18 20:34 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-18 20:34 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}"= "c:\program files\Foxit\tbFox0.dll" [2007-11-25 1498136]
[HKEY_CLASSES_ROOT\clsid\{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}]
2007-11-25 16:48 1498136 --a------ c:\program files\Foxit\tbFox0.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
2009-03-13 23:59 140880 --a------ c:\progra~1\DAP\dapieloader.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}"= "c:\program files\Foxit\tbFox0.dll" [2007-11-25 1498136]
[HKEY_CLASSES_ROOT\clsid\{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{73C7D5B0-7B03-444A-84C7-CE1BA03B5573}"= "c:\program files\Foxit\tbFox0.dll" [2007-11-25 1498136]
[HKEY_CLASSES_ROOT\clsid\{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2008-05-15 95536]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-03-13 2807296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-15 102400]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-04-03 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2008-05-15 54576]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-09 c:\windows\RtHDVCpl.exe]
c:\users\RR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSSMSGS"=rundll32.exe winxpl32.rom,CgORun
"SunJavaUpdateSched"=c:\program files\Java\jre1.6.0_07\bin\jusched.exe
"Google Update"="c:\users\RR\AppData\Local\Google\Update\GoogleUpdate.exe" /c
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2758273403-3538249848-2898790983-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D7E7D535-ADAE-48AE-9E29-AC895A80C3C3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5A9C4C42-BC7A-4A6F-A4B0-9BCFF89FF2D5}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D56C7EE5-4B31-4941-82DC-E03F0DEDCCAE}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{DE5290EC-AE7F-422A-A065-81CC16386759}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{740D567B-D36C-477D-8E8D-EE7F3E3878BB}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{39FA71B9-02EC-41D9-9F09-A0484D2851F2}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{FD5B7291-F716-4D76-BE84-4C243589251D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F31371F7-9A0F-46A6-8366-468FB7A6F2C1}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CEC75FB7-97DB-4761-801E-E20F345AD7F9}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{69078A51-CEC9-463E-8F91-82E1FD6819A0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{7A351773-CD78-40E1-9E6C-FEDAEC15C169}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{F37BC8AD-C84B-41F7-8420-78755FD7D30A}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{ED613865-691E-432F-A0CA-D7844F81EEE8}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{A4794E00-07A5-44AE-A97C-E9F79EF31151}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D3837E68-180E-4F47-96C9-D74619D99490}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{2AFB06C3-6FC9-485B-B2AB-5932CFE0B645}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{D8674900-201D-4390-8DB0-3EAB4FAFDBF9}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{57AB8486-DD3B-4CAD-875B-34BF3603B707}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{9B674189-C018-46DC-B74C-44D4CF6FB451}"= Disabled:UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CAB8A796-2CCD-464D-A7F5-685FB4B95B68}"= Disabled:TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{B7B3615F-CB98-4E14-B212-D83DDEB94DCD}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{3A6C5CB8-1180-4ED5-836D-3A4514A824FD}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2008-02-20 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [2007-09-13 7168]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187B.sys [2009-01-13 346112]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\System32\regedt32.exe [2006-11-02 9216]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e60c7e0-5343-11dd-ac68-00a0d19684aa}]
\shell\AutoRun\command - D:\
\shell\open\Command - rundll32.exe .\\comlepl.dll,InstallM
.
Contents of the 'Scheduled Tasks' folder
2009-03-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe []
2009-03-15 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2008-12-12 12:17]
2009-03-15 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\ [2009-03-14 20:52]
2009-03-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2758273403-3538249848-2898790983-1000.job
- c:\users\RR\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-26 23:45]
2009-03-01 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-13 18:15]
2009-03-01 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\ [2009-02-27 14:41]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
BHO-{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com?o=1607
mStart Page = hxxp://home.sweetim.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - amazon.co.uk/exec/obidos/redirect-home?.....&site=home
FF - ProfilePath - c:\users\RR\AppData\Roaming\Mozilla\Firefox\Profiles\iwz5xh8g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Torrent Finder
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\users\RR\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-15 15:34:49
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-15 15:38:01
ComboFix-quarantined-files.txt 2009-03-15 14:37:59
Pre-Run: 41,153,003,520 bytes free
Post-Run: 41,121,189,888 bytes free
310 --- E O F --- 2009-03-11 09:04:17
Dopuna: 15 Mar 2009 16:21
Zaboravila sam da napisem da na inernet idem najnormalnije preko LAN kabla,tj. kompjuter se povezuje na takvu mrezu, ali na wireless nikako.
|