offline
- drmoler
- Novi MyCity građanin
- Pridružio: 02 Mar 2008
- Poruke: 9
|
mycity.rs/must-login.png
ovo sam danas uradio i recite mi je li ima nekih problema hvala
ComboFix 09-02-21.01 - Vlatko i Kiko 2009-02-22 19:36:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.1.1033.18.1023.566 [GMT 1:00]
Running from: d:\programi 2\C-F.exe
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated)
FW: Kaspersky Internet Security *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-01-22 to 2009-02-22 )))))))))))))))))))))))))))))))
.
2009-02-21 21:32 . 2009-02-21 21:32 <DIR> dr-h----- c:\documents and settings\Vlatko i Kiko\Application Data\SecuROM
2009-02-21 21:32 . 2009-02-21 21:32 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-02-21 20:59 . 2009-02-21 20:59 <DIR> d-------- c:\program files\Dream Chronicles
2009-02-21 20:59 . 2009-02-21 20:59 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\PlayFirst
2009-02-21 20:59 . 2009-02-21 20:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\PlayFirst
2009-02-21 20:57 . 2009-02-21 20:57 <DIR> d-------- c:\program files\LeeGTs Games
2009-02-21 14:14 . 2009-02-21 14:49 <DIR> d-------- c:\program files\Common Files\Sandlot Shared
2009-02-21 14:05 . 2009-02-21 14:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\55-64-11-0p-s7-36
2009-02-21 13:41 . 2009-02-21 13:41 <DIR> d--hs---- c:\windows\ftpcache
2009-02-21 13:41 . 2009-02-21 13:41 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Sandlot Games
2009-02-21 13:41 . 2009-02-21 14:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sandlot Games
2009-02-21 13:39 . 2009-02-21 13:39 <DIR> d-------- c:\program files\MSN Games
2009-02-20 22:04 . 2009-02-20 22:04 876 --a------ c:\windows\$_hpcst$.hpc
2009-02-20 16:34 . 2009-02-20 16:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Oberon Media
2009-02-20 13:53 . 2009-02-20 13:53 <DIR> d-------- c:\program files\DVD X Studios
2009-02-20 13:53 . 2009-02-20 13:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\DVD X Studios
2009-02-20 13:53 . 2009-02-20 13:53 14 --a------ c:\windows\system32\SystemInfo32.sys
2009-02-18 13:51 . 2009-02-18 13:51 640 --a------ c:\documents and settings\Vlatko i Kiko\scores.dat
2009-02-18 13:51 . 2009-02-18 13:51 80 --a------ c:\documents and settings\Vlatko i Kiko\config.dat
2009-02-18 11:45 . 2009-02-18 11:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2009-02-18 11:42 . 2009-02-18 11:51 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\GameHouse
2009-02-17 21:46 . 2009-02-18 20:10 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\funkitron
2009-02-16 18:28 . 2009-02-16 18:28 0 --a------ c:\windows\Pool.INI
2009-02-16 17:52 . 2009-02-16 18:02 <DIR> d-------- c:\program files\Intelore
2009-02-14 22:42 . 2009-02-14 22:42 <DIR> d-------- c:\program files\Notepad++
2009-02-14 22:42 . 2009-02-14 22:42 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Notepad++
2009-02-14 22:33 . 2008-09-24 19:41 839,680 --a------ c:\windows\system32\lameACM.acm
2009-02-14 22:33 . 2008-09-16 20:23 168,448 --a------ c:\windows\system32\unrar.dll
2009-02-14 22:33 . 2007-09-21 01:52 118,784 --a------ c:\windows\system32\ac3acm.acm
2009-02-14 22:33 . 2008-10-03 13:30 414 --a------ c:\windows\system32\lame_acm.xml
2009-02-14 22:32 . 2009-02-14 22:33 <DIR> d-------- c:\program files\K-Lite Codec Pack
2009-02-14 22:32 . 2008-11-06 17:37 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2009-02-14 22:32 . 2008-12-07 19:08 795,648 --a------ c:\windows\system32\xvidcore.dll
2009-02-14 22:32 . 2008-11-06 17:33 684,032 --a------ c:\windows\system32\divx.dll
2009-02-14 22:32 . 2004-01-25 17:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2009-02-14 22:32 . 2008-12-07 19:08 130,048 --a------ c:\windows\system32\xvidvfw.dll
2009-02-14 22:32 . 2008-12-11 01:33 86,016 --a------ c:\windows\system32\dpl100.dll
2009-02-14 22:32 . 2009-02-09 19:56 67,584 --a------ c:\windows\system32\ff_vfw.dll
2009-02-14 22:32 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2009-02-13 15:00 . 2009-02-13 15:00 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\EA
2009-02-13 15:00 . 2009-02-13 15:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\EA
2009-02-12 21:52 . 2009-02-12 21:52 <DIR> d-------- c:\program files\GameSpy Arcade
2009-02-11 23:40 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys
2009-02-11 23:40 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys
2009-02-11 23:40 . 2008-10-23 17:42 290,816 --a------ c:\windows\vncutil.exe
2009-02-11 23:40 . 2008-06-24 14:46 104,992 --a------ c:\windows\RtkAudioService.exe
2009-02-11 23:40 . 2009-02-03 16:35 35,840 --a------ c:\windows\system32\RtkCoInstXP.dll
2009-02-10 15:33 . 2009-02-10 15:33 <DIR> d-------- c:\program files\AnalogX
2009-02-10 15:16 . 2009-02-12 20:10 <DIR> d-------- c:\program files\Startup Faster
2009-02-10 15:16 . 2009-02-10 15:16 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\URSoft
2009-02-10 14:16 . 2009-02-10 14:16 <DIR> d-------- c:\program files\Microsoft Bootvis
2009-02-09 17:44 . 2009-02-09 17:44 406 --a------ c:\windows\system32\ioloBootDefrag.cfg
2009-02-09 17:28 . 2009-02-09 17:28 <DIR> d-------- c:\documents and settings\LocalService\Application Data\iolo
2009-02-09 17:22 . 2009-02-09 17:56 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\iolo
2009-02-09 17:22 . 2009-02-09 18:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\iolo
2009-02-08 14:22 . 2009-02-08 14:35 <DIR> d-------- c:\program files\ICQ6.5
2009-02-07 14:06 . 2009-02-07 14:17 <DIR> d--hs---- C:\RECYCLER(2)
2009-02-07 13:18 . 2009-02-07 13:18 360,192 --a------ c:\windows\system32\TuneUpDefragService(2).exe
2009-02-06 23:52 . 2009-02-07 00:03 <DIR> d-------- C:\TuneUpPortable
2009-02-06 23:52 . 2009-02-06 23:52 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\TuneUp Software
2009-02-06 23:52 . 2009-02-06 23:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-02-06 23:10 . 2009-02-12 14:08 <DIR> d-------- c:\program files\Bonjour
2009-02-06 23:09 . 2009-02-06 23:15 <DIR> d-------- c:\program files\Common Files\Apple
2009-02-06 12:03 . 2009-02-16 13:00 <DIR> d-------- c:\program files\Liong - The Lost Amulets
2009-02-06 11:46 . 2009-02-06 11:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\DivoGames
2009-02-06 00:15 . 2009-02-06 00:15 <DIR> d-------- c:\program files\StoneLoops of Jurassica Setup
2009-02-06 00:15 . 2009-02-06 00:15 <DIR> d-------- c:\program files\Games
2009-02-06 00:15 . 2009-02-06 00:19 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\StoneLoopsIW
2009-02-05 23:26 . 2009-02-05 23:26 <DIR> d-------- c:\windows\SHELLNEW
2009-02-05 23:26 . 2009-02-05 23:26 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-05 23:26 . 2009-02-05 23:26 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-02-05 13:11 . 2009-02-05 13:23 <DIR> d-------- c:\program files\Snow for Windows
2009-02-04 20:01 . 2009-02-04 20:01 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Thinstall
2009-02-04 14:41 . 2009-02-04 14:41 <DIR> d-------- c:\program files\PC Optimizer Pro
2009-02-04 14:41 . 2004-03-09 00:00 440,352 --a------ c:\windows\system32\mshflxgd.ocx
2009-02-04 14:41 . 2004-03-09 00:00 224,016 --a------ c:\windows\system32\tabctl32.ocx
2009-02-04 14:41 . 2004-03-09 00:00 212,240 --a------ c:\windows\system32\richtx32.ocx
2009-02-04 14:41 . 2004-03-09 00:00 152,848 --a------ c:\windows\system32\comdlg32.ocx
2009-02-04 14:41 . 2007-03-19 13:25 18,728 --a------ c:\windows\system32\ishf_Ex.TLB
2009-02-04 14:41 . 2007-03-19 13:25 7,752 --a------ c:\windows\system32\shelllink.TLB
2009-02-03 22:20 . 2009-02-03 22:20 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\PowerChallenge
2009-02-03 17:53 . 2009-02-03 17:53 <DIR> d-------- c:\windows\MyFreeWeather
2009-02-03 17:53 . 2009-02-03 17:55 <DIR> d-------- c:\program files\MyFreeWeather
2009-02-03 17:45 . 2009-02-06 23:15 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-02-03 16:34 . 2009-02-03 16:34 <DIR> d-------- c:\program files\IrfanView
2009-02-03 14:30 . 2009-02-03 14:30 <DIR> d-------- c:\program files\OsvetaBesnogPileta
2009-02-03 14:30 . 2009-02-03 14:30 151,996 --a------ c:\windows\Osveta Besnog Pileta Uninstaller.exe
2009-02-02 20:24 . 2009-02-21 23:24 116 --a------ c:\windows\NeroDigital.ini
2009-02-02 19:19 . 2009-02-02 19:19 40 --a------ c:\windows\RSoftInfo.dat
2009-02-02 18:55 . 2009-02-02 18:57 34 --a------ c:\documents and settings\Vlatko i Kiko\jagex_runescape_preferences.dat
2009-02-02 18:54 . 2009-02-02 18:54 <DIR> d-------- c:\windows\Sun
2009-02-02 18:54 . 2009-02-02 18:54 <DIR> d-------- c:\windows\.jagex_cache_32
2009-02-02 13:47 . 2009-02-02 13:47 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-02-02 13:44 . 2009-02-02 14:08 <DIR> d-------- c:\program files\NOS
2009-02-02 13:44 . 2009-02-02 14:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-02-02 13:41 . 2009-02-02 13:41 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\AdobeUM
2009-02-02 11:49 . 2009-02-12 21:57 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Apple Computer
2009-02-02 11:40 . 2009-02-02 11:40 <DIR> d-------- c:\program files\Apple Software Update
2009-02-02 11:40 . 2009-02-02 11:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2009-02-02 11:35 . 2009-02-12 21:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-02 11:02 . 2009-02-06 21:54 <DIR> d-------- C:\fixwareout
2009-02-01 23:26 . 2009-02-01 23:33 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Wildfire
2009-02-01 23:26 . 2009-02-01 23:26 4,096 --a------ c:\windows\d3dx.dat
2009-02-01 18:34 . 2009-02-01 18:34 <DIR> d-------- c:\windows\system32\xircom
2009-02-01 18:34 . 2009-02-01 18:34 <DIR> d-------- c:\program files\microsoft frontpage
2009-02-01 18:19 . 2009-02-15 16:32 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Ahead
2009-02-01 18:18 . 2009-02-01 18:18 <DIR> d-------- c:\program files\Nero
2009-02-01 18:18 . 2009-02-01 18:19 <DIR> d-------- c:\program files\Common Files\Ahead
2009-02-01 18:14 . 2009-02-01 18:14 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\ACD Systems
2009-02-01 18:13 . 2009-02-01 18:13 <DIR> d-------- c:\program files\Common Files\ACD Systems
2009-02-01 18:13 . 2009-02-01 18:13 <DIR> d-------- c:\program files\ACD Systems
2009-02-01 18:13 . 2009-02-01 18:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\ACD Systems
2009-02-01 18:13 . 2009-02-01 18:13 10,368 --a------ c:\windows\system32\drivers\pfc.sys
2009-02-01 18:11 . 2009-02-01 18:11 <DIR> d-------- c:\windows\AdAware SE Pro 1.06
2009-02-01 18:11 . 2009-02-01 18:11 <DIR> d-------- c:\program files\AdAware SE Pro 1.06
2009-02-01 17:32 . 2008-02-28 14:26 1,414,440 --a------ c:\windows\system32\ShellManager310E2D762.dll
2009-02-01 17:10 . 2009-02-01 17:10 0 --a------ c:\windows\Irremote.ini
2009-02-01 13:50 . 2009-02-01 13:50 <DIR> d-------- c:\program files\Windows Sidebar
2009-02-01 12:20 . 2009-02-01 18:08 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Nero
2009-02-01 11:58 . 2009-02-01 18:07 <DIR> d-------- c:\program files\Common Files\Nero
2009-02-01 11:58 . 2009-02-19 16:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2009-02-01 00:04 . 2009-02-01 00:04 <DIR> d-------- c:\documents and settings\Vlatko i Kiko\Application Data\Ashampoo
2009-02-01 00:04 . 2009-02-06 22:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\ashampoo
2009-02-01 00:03 . 2009-02-06 22:36 <DIR> d-------- c:\program files\Ashampoo
2009-01-31 23:52 . 2009-02-22 17:01 13,030 --a------ C:\PDOXUSRS.NET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 12:38 --------- d-----w c:\documents and settings\Vlatko i Kiko\Application Data\BSplayer PRO
2009-02-20 12:26 --------- d-----w c:\documents and settings\Vlatko i Kiko\Application Data\Winamp
2009-02-12 22:15 --------- d-----w c:\documents and settings\Vlatko i Kiko\Application Data\Media Player Classic
2009-02-12 20:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-04 14:45 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-03 16:32 18,085,888 ----a-w c:\windows\RTHDCPL.EXE
2009-02-03 16:22 5,030,912 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2009-02-02 19:27 --------- d-----w c:\program files\Webteh
2009-02-02 12:47 --------- d-----w c:\program files\Common Files\Adobe
2009-01-31 17:26 --------- d-----w c:\program files\Atomic Alarm Clock
2009-01-30 10:55 --------- d-----w c:\program files\Alcohol Soft
2009-01-30 10:53 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-01-30 10:38 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-30 10:38 --------- d-----w c:\documents and settings\Vlatko i Kiko\Application Data\Malwarebytes
2009-01-30 10:37 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-30 10:23 --------- d-----w c:\program files\Winamp
2009-01-30 10:06 --------- d-----w c:\program files\PowerISO
2009-01-30 09:56 --------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-01-30 09:49 --------- d-----w c:\documents and settings\Vlatko i Kiko\Application Data\InstallShield
2009-01-30 09:48 --------- d-----w c:\program files\Realtek
2009-01-30 09:48 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-30 09:46 --------- d-----w c:\program files\Intel
2009-01-30 09:33 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-21 14:54 1,206,816 ----a-w c:\windows\RtlUpd.exe
2009-01-08 20:12 361,600 ----a-w c:\windows\system32\drivers\tcpip.sys
2009-01-08 20:12 218,624 ----a-w c:\windows\system32\uxtheme.dll
2009-01-08 20:12 140,288 ----a-w c:\windows\system32\sfc_os.dll
2009-01-08 20:10 603,648 ----a-w c:\windows\system32\wmspdmod.dll
2009-01-08 20:10 4,096 ----a-w c:\windows\system32\wmvdmoe2.dll
2009-01-08 20:10 4,096 ----a-w c:\windows\system32\wmvdmod.dll
2009-01-08 20:10 1,329,152 ----a-w c:\windows\system32\wmspdmoe.dll
2009-01-08 20:09 99,840 ----a-w c:\windows\system32\wmpshell.dll
2009-01-08 20:09 938,496 ----a-w c:\windows\system32\wmnetmgr.dll
2009-01-08 20:09 8,231,936 ----a-w c:\windows\system32\wmploc.dll
2009-01-08 20:09 4,096 ----a-w c:\windows\system32\wmsdmoe2.dll
2009-01-08 20:09 4,096 ----a-w c:\windows\system32\wmsdmod.dll
2009-01-08 20:09 314,880 ----a-w c:\windows\system32\wmpdxm.dll
2009-01-08 20:09 242,688 ----a-w c:\windows\system32\wmpasf.dll
2009-01-08 20:09 227,328 ----a-w c:\windows\system32\wmerror.dll
2009-01-08 20:09 157,184 ----a-w c:\windows\system32\wmidx.dll
2009-01-08 19:41 80,128 ----a-w c:\windows\system32\drivers\parport.sys
2009-01-08 19:38 86,073 ----a-w c:\windows\system32\usrfaxa.dll
2009-01-08 19:23 990,208 ----a-w c:\windows\system32\syssetup.dll
2009-01-08 19:23 26,112 ----a-w c:\windows\system32\idndl.dll
2009-01-08 19:23 24,576 ----a-w c:\windows\system32\nlsdl.dll
2009-01-08 19:23 23,552 ----a-w c:\windows\system32\normaliz.dll
2009-01-08 19:22 48,128 ----a-w c:\windows\system32\mshtmler.dll
2009-01-08 19:22 45,568 ----a-w c:\windows\system32\mshta.exe
2009-01-08 19:22 156,160 ----a-w c:\windows\system32\msls31.dll
2009-01-08 19:21 55,296 ----a-w c:\windows\system32\iesetup.dll
2009-01-08 19:21 40,960 ----a-w c:\windows\system32\licmgr10.dll
2009-01-08 19:21 36,352 ----a-w c:\windows\system32\imgutil.dll
2009-01-08 19:20 78,336 ----a-w c:\windows\system32\ieencode.dll
2009-01-08 19:20 71,680 ----a-w c:\windows\system32\admparse.dll
2009-01-08 19:20 17,408 ----a-w c:\windows\system32\corpol.dll
2009-01-08 19:15 96,792 ----a-w c:\windows\system32\basecsp.dll
2009-01-08 19:15 633,344 ----a-w c:\windows\system32\gpprefcl.dll
2009-01-08 19:15 6,144 ----a-w c:\windows\system32\FontReg.exe
2009-01-08 19:15 465,920 ----a-w c:\windows\system32\imapi2fs.dll
2009-01-08 19:15 383,488 ----a-w c:\windows\system32\wzcdlg.dll
2009-01-08 19:15 323,696 ----a-w c:\windows\system32\msdrm.dll
2009-01-08 19:15 317,952 ----a-w c:\windows\system32\imapi2.dll
2009-01-08 19:15 25,600 ----a-w c:\windows\system32\bcsprsrc.dll
2009-01-08 19:15 202,776 ----a-w c:\windows\system32\wuweb.dll
2009-01-08 19:15 151,552 ----a-w c:\windows\system32\ifxcardm.dll
2009-01-08 19:15 133,120 ----a-w c:\windows\system32\axaltocm.dll
2009-01-08 19:13 713,216 ----a-w c:\windows\system32\sxs.dll
2009-01-08 19:13 712,704 ----a-w c:\windows\system32\windowscodecs.dll
2009-01-08 19:13 52,736 ----a-w c:\windows\system32\w32tm.exe
2009-01-08 19:13 430,080 ----a-w c:\windows\system32\vbscript.dll
2009-01-08 19:13 347,648 ----a-w c:\windows\system32\windowscodecsext.dll
2009-01-08 19:13 249,856 ----a-w c:\windows\system32\tapisrv.dll
2009-01-08 19:13 225,856 ----a-w c:\windows\system32\drivers\tcpip6.sys
2009-01-08 19:13 175,616 ----a-w c:\windows\system32\w32time.dll
2009-01-08 19:13 123,392 ----a-w c:\windows\system32\umpnpmgr.dll
2009-01-08 19:12 66,048 ----a-w c:\windows\system32\shimeng.dll
2009-01-08 19:12 446,464 ----a-w c:\windows\system32\sqlsrv32.dll
2009-01-08 19:12 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2009-01-08 19:12 247,326 ----a-w c:\windows\system32\strmdll.dll
2009-01-08 19:11 985,088 ----a-w c:\windows\system32\setupapi.dll
2009-01-08 19:11 97,280 ----a-w c:\windows\system32\psbase.dll
2009-01-08 19:11 203,136 ----a-w c:\windows\system32\drivers\RMCast.sys
2009-01-08 19:11 180,224 ----a-w c:\windows\system32\scrobj.dll
2009-01-08 19:11 174,848 ----a-w c:\windows\system32\drivers\rdbss.sys
2009-01-08 19:11 172,032 ----a-w c:\windows\system32\scrrun.dll
2009-01-08 19:11 144,896 ----a-w c:\windows\system32\schannel.dll
2009-01-08 19:11 139,656 ----a-w c:\windows\system32\drivers\rdpwd.sys
2009-01-08 19:11 1,288,192 ----a-w c:\windows\system32\quartz.dll
2009-01-08 19:10 270,336 ----a-w c:\windows\system32\oakley.dll
2009-01-08 19:10 249,856 ----a-w c:\windows\system32\odbc32.dll
2009-01-08 19:10 24,576 ----a-w c:\windows\system32\odbcbcp.dll
2009-01-08 19:10 215,552 ----a-w c:\windows\system32\osk.exe
2009-01-08 19:10 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-01-08 19:10 1,288,192 ----a-w c:\windows\system32\ole32.dll
2009-01-08 19:08 74,240 ----a-w c:\windows\system32\mscms.dll
2009-01-08 19:08 304,152 ----a-w c:\windows\system32\msexcl40.dll
2009-01-08 19:08 299,520 ----a-w c:\windows\system32\MSCTF.dll
2009-01-08 19:07 728,064 ----a-w c:\windows\system32\lsasrv.dll
2009-01-08 19:07 691,712 ----a-w c:\windows\system32\inetcomm.dll
2009-01-08 19:07 455,936 ----a-w c:\windows\system32\drivers\mrxsmb.sys
.
------- Sigcheck -------
2009-01-08 21:12 361600 5ae1c2695f6523ad98b948f2887d8c5e c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-01-31 57344]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-05-20 1737216]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-01-29 23975720]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2009-02-18 171448]
"Myweather"="c:\program files\MyFreeWeather\MyWeather.exe" [2009-01-22 1585152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-04 206088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2009-01-30 12:18 4608 c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\myweather]
--a------ 2009-01-22 21:51 1585152 c:\program files\MyFreeWeather\MyWeather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-11-02 09:38 167936 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-09-12 17:45 36352 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2009-02-03 17:32 18085888 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-30 170640]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-01-30 15504]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-02-11 1684736]
.
Contents of the 'Scheduled Tasks' folder
2009-02-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-ISTray - c:\program files\Spyware Doctor\pctsTray.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
IE: Dodaj u zastitu od reklama - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Vlatko i Kiko\Application Data\Mozilla\Firefox\Profiles\esq1b0dq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-22 19:38:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-73586283-329068152-1417001333-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:87,c8,19,86,9d,ce,89,20,96,c3,f6,43,53,38,bf,b3,9e,fa,02,e9,1f,a4,ef,
56,00,7f,5b,8f,1a,94,55,f8,67,87,d8,10,89,dc,91,ad,aa,47,29,e7,ae,e5,cb,06,\
"??"=hex:27,df,7b,4e,0e,94,5f,d6,1c,bc,30,c8,56,1b,31,ab
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="C9A8C35A0020D1EF8907F179654A4E
c:\windows\system32\msi.dll
c:\program files\Atomic Alarm Clock\Clock.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-02-22 19:39:36
ComboFix-quarantined-files.txt 2009-02-22 18:39:23
ComboFix2.txt 2009-02-22 11:37:47
ComboFix3.txt 2009-02-20 21:43:41
ComboFix4.txt 2009-02-16 14:46:09
ComboFix5.txt 2009-02-22 18:36:12
Pre-Run: 48.427.450.368 bytes free
Post-Run: 48,413,941,760 bytes free
369
|