offline
- Rocky I
- Građanin
- Pridružio: 26 Dec 2007
- Poruke: 132
|
Evo. Samo sto nisam ovo uradio:
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
Ja preskocio. Jel moram opet da uradim?
ComboFix 09-11-24.04 - DeCkY 25.11.2009 13:41.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.381.1033.18.1023.623 [GMT 1:00]
Running from: d:\downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\.#
.
((((((((((((((((((((((((( Files Created from 2009-10-25 to 2009-11-25 )))))))))))))))))))))))))))))))
.
2009-11-19 11:00 . 2009-09-29 14:14 3101560 ----a-w- c:\documents and settings\Administrator\Application Data\Simply Super Software\Trojan Remover\rur2AE.exe
2009-11-18 23:33 . 2009-11-18 23:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-11-18 23:33 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-18 23:33 . 2009-11-18 23:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-18 23:33 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-18 23:33 . 2009-11-18 23:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-14 18:54 . 2009-11-14 18:54 2735104 ----a-w- c:\windows\system32\libvlc.dll
2009-11-09 22:40 . 2009-10-30 14:08 29512 ----a-w- c:\windows\system32\TURegOpt.exe
2009-11-09 22:39 . 2009-11-09 22:40 -------- d-----w- c:\program files\TuneUp Utilities 2010
2009-11-09 22:39 . 2009-11-09 22:39 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-09 19:55 . 2009-11-12 01:42 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\S2
2009-11-04 01:52 . 2009-11-04 01:52 -------- d-----w- c:\program files\Rosetta Stone
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-25 12:36 . 2009-02-02 18:17 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-11-25 12:36 . 2009-02-02 18:16 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2009-11-25 11:55 . 2008-05-18 15:58 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-11-25 11:53 . 2008-04-30 21:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-11-25 11:47 . 2009-06-17 20:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2009-11-25 03:12 . 2009-11-25 11:46 7629312 ----a-w- c:\windows\Internet Logs\xDB166.tmp
2009-11-24 02:41 . 2009-11-24 10:22 246784 ----a-w- c:\windows\Internet Logs\xDB165.tmp
2009-11-23 02:31 . 2009-11-23 09:34 217088 ----a-w- c:\windows\Internet Logs\xDB163.tmp
2009-11-23 02:31 . 2009-11-23 09:34 7620608 ----a-w- c:\windows\Internet Logs\xDB164.tmp
2009-11-22 21:47 . 2008-05-06 11:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\LimeWire
2009-11-22 02:43 . 2009-11-22 10:54 7609344 ----a-w- c:\windows\Internet Logs\xDB162.tmp
2009-11-22 02:43 . 2009-11-22 10:54 719360 ----a-w- c:\windows\Internet Logs\xDB161.tmp
2009-11-21 01:41 . 2009-11-21 10:52 7608832 ----a-w- c:\windows\Internet Logs\xDB160.tmp
2009-11-21 01:41 . 2009-11-21 10:52 1278464 ----a-w- c:\windows\Internet Logs\xDB15F.tmp
2009-11-19 00:35 . 2009-06-11 15:27 -------- d-----w- c:\program files\Trojan Remover
2009-11-18 19:46 . 2009-03-21 02:06 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-18 11:56 . 2009-01-24 11:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-18 11:52 . 2009-01-24 11:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-18 01:47 . 2009-11-18 10:38 230400 ----a-w- c:\windows\Internet Logs\xDB15D.tmp
2009-11-18 01:47 . 2009-11-18 10:38 7577088 ----a-w- c:\windows\Internet Logs\xDB15E.tmp
2009-11-17 01:49 . 2009-11-17 09:49 7576576 ----a-w- c:\windows\Internet Logs\xDB15C.tmp
2009-11-17 01:49 . 2009-11-17 09:49 375808 ----a-w- c:\windows\Internet Logs\xDB15B.tmp
2009-11-16 02:33 . 2009-11-16 11:02 127488 ----a-w- c:\windows\Internet Logs\xDB159.tmp
2009-11-16 02:33 . 2009-11-16 11:02 7576064 ----a-w- c:\windows\Internet Logs\xDB15A.tmp
2009-11-15 14:20 . 2009-11-15 21:19 138240 ----a-w- c:\windows\Internet Logs\xDB158.tmp
2009-11-14 21:37 . 2009-11-15 01:16 7559168 ----a-w- c:\windows\Internet Logs\xDB157.tmp
2009-11-14 21:37 . 2009-11-15 01:16 54784 ----a-w- c:\windows\Internet Logs\xDB156.tmp
2009-11-14 19:13 . 2009-11-14 20:47 7558656 ----a-w- c:\windows\Internet Logs\xDB155.tmp
2009-11-14 19:13 . 2009-11-14 20:47 151040 ----a-w- c:\windows\Internet Logs\xDB154.tmp
2009-11-14 02:50 . 2009-11-14 11:32 689152 ----a-w- c:\windows\Internet Logs\xDB153.tmp
2009-11-12 01:50 . 2009-11-12 09:26 360960 ----a-w- c:\windows\Internet Logs\xDB152.tmp
2009-11-11 01:55 . 2009-11-11 11:09 7556608 ----a-w- c:\windows\Internet Logs\xDB151.tmp
2009-11-11 01:55 . 2009-11-11 11:09 296448 ----a-w- c:\windows\Internet Logs\xDB150.tmp
2009-11-10 01:49 . 2009-11-10 07:41 503808 ----a-w- c:\windows\Internet Logs\xDB14F.tmp
2009-11-09 22:39 . 2008-05-13 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-11-09 01:01 . 2009-11-09 10:43 562176 ----a-w- c:\windows\Internet Logs\xDB14E.tmp
2009-11-08 04:24 . 2009-11-08 04:27 7508480 ----a-w- c:\windows\Internet Logs\xDB14D.tmp
2009-11-06 20:29 . 2009-11-07 02:25 7502848 ----a-w- c:\windows\Internet Logs\xDB14C.tmp
2009-11-06 20:29 . 2009-11-07 02:25 159744 ----a-w- c:\windows\Internet Logs\xDB14B.tmp
2009-11-06 03:24 . 2009-11-06 12:01 167936 ----a-w- c:\windows\Internet Logs\xDB14A.tmp
2009-11-05 22:21 . 2009-11-05 22:22 7488512 ----a-w- c:\windows\Internet Logs\xDB149.tmp
2009-11-05 22:21 . 2009-11-05 22:22 85504 ----a-w- c:\windows\Internet Logs\xDB148.tmp
2009-11-05 16:43 . 2009-11-05 18:01 7479296 ----a-w- c:\windows\Internet Logs\xDB147.tmp
2009-11-05 16:43 . 2009-11-05 18:01 108032 ----a-w- c:\windows\Internet Logs\xDB146.tmp
2009-11-05 03:27 . 2009-11-05 12:04 1179648 ----a-w- c:\windows\Internet Logs\xDB145.tmp
2009-11-05 02:46 . 2009-06-17 20:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Babylon
2009-11-04 18:15 . 2009-11-04 18:16 7467520 ----a-w- c:\windows\Internet Logs\xDB144.tmp
2009-11-04 18:15 . 2009-11-04 18:16 94208 ----a-w- c:\windows\Internet Logs\xDB143.tmp
2009-11-04 02:45 . 2009-11-04 11:37 7467008 ----a-w- c:\windows\Internet Logs\xDB142.tmp
2009-11-04 02:45 . 2009-11-04 11:37 589824 ----a-w- c:\windows\Internet Logs\xDB141.tmp
2009-11-04 02:15 . 2009-02-23 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Rosetta Stone
2009-11-04 01:52 . 2009-02-24 19:19 -------- d-----w- c:\documents and settings\All Users\Application Data\RosettaStoneLtdBackup
2009-11-04 01:52 . 2009-02-23 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-11-03 02:37 . 2009-11-03 10:25 7455744 ----a-w- c:\windows\Internet Logs\xDB140.tmp
2009-11-03 02:37 . 2009-11-03 10:25 359936 ----a-w- c:\windows\Internet Logs\xDB13F.tmp
2009-11-02 02:50 . 2009-11-02 11:02 7455232 ----a-w- c:\windows\Internet Logs\xDB13E.tmp
2009-11-02 02:50 . 2009-11-02 11:02 403968 ----a-w- c:\windows\Internet Logs\xDB13D.tmp
2009-11-01 12:45 . 2009-11-01 12:46 61440 ----a-w- c:\windows\Internet Logs\xDB13C.tmp
2009-11-01 02:39 . 2009-11-01 11:54 194048 ----a-w- c:\windows\Internet Logs\xDB13A.tmp
2009-11-01 02:38 . 2009-11-01 11:54 7443968 ----a-w- c:\windows\Internet Logs\xDB13B.tmp
2009-10-31 14:52 . 2009-09-01 14:22 -------- d-----w- c:\program files\Opera
2009-10-30 20:59 . 2009-10-31 11:38 7440384 ----a-w- c:\windows\Internet Logs\xDB139.tmp
2009-10-30 20:59 . 2009-10-31 11:38 225792 ----a-w- c:\windows\Internet Logs\xDB138.tmp
2009-10-30 03:08 . 2009-10-30 08:21 7439872 ----a-w- c:\windows\Internet Logs\xDB137.tmp
2009-10-30 03:08 . 2009-10-30 08:21 158720 ----a-w- c:\windows\Internet Logs\xDB136.tmp
2009-10-29 02:27 . 2009-10-29 10:53 7434240 ----a-w- c:\windows\Internet Logs\xDB135.tmp
2009-10-29 02:27 . 2009-10-29 10:53 138752 ----a-w- c:\windows\Internet Logs\xDB134.tmp
2009-10-28 02:37 . 2009-10-28 10:56 49152 ----a-w- c:\windows\Internet Logs\xDB133.tmp
2009-10-28 02:17 . 2009-10-28 02:18 7433216 ----a-w- c:\windows\Internet Logs\xDB132.tmp
2009-10-28 02:17 . 2009-10-28 02:18 177664 ----a-w- c:\windows\Internet Logs\xDB131.tmp
2009-10-27 02:08 . 2009-10-27 10:00 359424 ----a-w- c:\windows\Internet Logs\xDB12F.tmp
2009-10-27 02:08 . 2009-10-27 10:00 7432704 ----a-w- c:\windows\Internet Logs\xDB130.tmp
2009-10-26 02:30 . 2009-10-26 08:47 82432 ----a-w- c:\windows\Internet Logs\xDB12D.tmp
2009-10-26 02:30 . 2009-10-26 08:47 7432192 ----a-w- c:\windows\Internet Logs\xDB12E.tmp
2009-10-25 18:48 . 2009-10-26 00:04 7431680 ----a-w- c:\windows\Internet Logs\xDB12C.tmp
2009-10-25 18:48 . 2009-10-26 00:04 115712 ----a-w- c:\windows\Internet Logs\xDB12B.tmp
2009-10-25 02:04 . 2009-10-25 10:39 7431168 ----a-w- c:\windows\Internet Logs\xDB12A.tmp
2009-10-25 02:04 . 2009-10-25 10:39 211968 ----a-w- c:\windows\Internet Logs\xDB129.tmp
2009-10-24 23:59 . 2009-10-25 00:00 7430656 ----a-w- c:\windows\Internet Logs\xDB128.tmp
2009-10-24 01:25 . 2009-10-24 09:34 511488 ----a-w- c:\windows\Internet Logs\xDB126.tmp
2009-10-24 01:25 . 2009-10-24 09:34 7428608 ----a-w- c:\windows\Internet Logs\xDB127.tmp
2009-10-23 01:39 . 2009-10-23 10:24 1275904 ----a-w- c:\windows\Internet Logs\xDB125.tmp
2009-10-22 01:04 . 2009-10-22 09:26 373760 ----a-w- c:\windows\Internet Logs\xDB124.tmp
2009-10-20 00:58 . 2009-10-20 09:07 113152 ----a-w- c:\windows\Internet Logs\xDB123.tmp
2009-10-19 19:51 . 2009-10-19 19:52 1476096 ----a-w- c:\windows\Internet Logs\xDB122.tmp
2009-10-19 19:02 . 2009-10-19 19:03 7418368 ----a-w- c:\windows\Internet Logs\xDB121.tmp
2009-10-19 13:16 . 2009-08-30 21:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2009-10-19 01:55 . 2009-10-19 09:31 159232 ----a-w- c:\windows\Internet Logs\xDB11F.tmp
2009-10-19 01:55 . 2009-10-19 09:31 7416320 ----a-w- c:\windows\Internet Logs\xDB120.tmp
2009-10-19 00:56 . 2009-10-19 00:56 -------- d-----w- c:\program files\Microsoft
2009-10-19 00:56 . 2009-10-19 00:56 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-18 01:54 . 2009-10-18 10:49 7410176 ----a-w- c:\windows\Internet Logs\xDB11E.tmp
2009-10-18 01:54 . 2009-10-18 10:49 595456 ----a-w- c:\windows\Internet Logs\xDB11D.tmp
2009-10-17 02:08 . 2009-10-17 10:44 161280 ----a-w- c:\windows\Internet Logs\xDB11C.tmp
2009-10-16 01:51 . 2009-10-16 10:20 534016 ----a-w- c:\windows\Internet Logs\xDB11B.tmp
2009-10-15 01:28 . 2009-10-15 10:19 1611264 ----a-w- c:\windows\Internet Logs\xDB119.tmp
2009-10-15 01:28 . 2009-10-15 10:19 7379456 ----a-w- c:\windows\Internet Logs\xDB11A.tmp
2009-10-14 01:58 . 2009-10-14 09:31 7374336 ----a-w- c:\windows\Internet Logs\xDB118.tmp
2009-10-14 01:58 . 2009-10-14 09:31 1601024 ----a-w- c:\windows\Internet Logs\xDB117.tmp
2009-10-12 01:22 . 2009-10-12 11:28 663040 ----a-w- c:\windows\Internet Logs\xDB116.tmp
2009-08-30 21:59 . 2009-09-01 20:54 2735104 ----a-w- c:\program files\opera\program\plugins\libvlc.dll
.
------- Sigcheck -------
[-] 2009-02-18 . C86970F63DAFFB97D8221A0136DF3224 . 360960 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-02-18 . C86970F63DAFFB97D8221A0136DF3224 . 360960 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-04-07 . 43A336FC1C015417D981B2D32B27B8FF . 643072 . . [5.82] . . c:\windows\LastGood.Tmp\system32\comctl32.dll
[-] 2008-04-07 . 43A336FC1C015417D981B2D32B27B8FF . 643072 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2008-04-07 . EF5C722E9F1BAEFC7675023FC26786B8 . 3731968 . . [6.00.2900.3268] . . c:\windows\system32\mshtml.dll
[-] 2008-04-07 . 7A540726CA75E1E988D56AB69925BA79 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
[-] 2008-04-07 . 4DF249A77F56F6B759340101FDB94654 . 776192 . . [6.00.2900.3268] . . c:\windows\LastGood.Tmp\system32\wininet.dll
[-] 2008-04-07 . 4DF249A77F56F6B759340101FDB94654 . 776192 . . [6.00.2900.3268] . . c:\windows\system32\wininet.dll
[-] 2008-04-07 . 16A2E225871FE74735F51AFE2C9164A9 . 1588736 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2008-04-07 . E00DFA816FA5521EB44C5D63109DE2A9 . 40448 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe
c:\windows\System32\regsvc.dll ... is missing !!
c:\windows\System32\ssdpsrv.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyB0.dll" [2008-11-23 1784856]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2008-11-23 22:03 1784856 ----a-w- c:\program files\myBabylon_English\tbmyB0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyB0.dll" [2008-11-23 1784856]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\lclock.exe" [2004-09-19 65536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2009-06-17 3959696]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - c:\program files\ASUS USB ADSL Modem\ASUS USB ADSL Modem\DSLMON.exe [2008-4-30 929889]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyDocs"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"MaxRecentDocs"= 15 (0xf)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyDocs"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"StartMenuLogoff"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders schannel.dll, digest.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RecSche"="c:\program files\LifeView TVR\RecSche.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TrojanScanner"=c:\program files\Trojan Remover\Trjscan.exe /boot
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
R0 pe3ajbeb;L Ile Noyee Environment Driver (pe3ajbeb);c:\windows\system32\drivers\pe3ajbeb.sys [22.8.2007 17:31 64632]
R0 ps7ajbeb;L Ile Noyee Synchronization Driver (ps7ajbeb);c:\windows\system32\drivers\ps7ajbeb.sys [22.8.2007 17:30 68736]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21.12.2007 7:21 94360]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [23.4.2007 12:03 82200]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.11.2009 0:33 269648]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [30.10.2009 15:05 1021256]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [10.2.2009 23:19 598856]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.11.2009 0:33 19160]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [30.4.2008 23:01 721904]
S2 pr2ajbeb;L Ile Noyee Drivers Auto Removal (pr2ajbeb);c:\windows\system32\pr2ajbeb.exe svc --> c:\windows\system32\pr2ajbeb.exe svc [?]
S3 FGUARD32;FGUARD32;c:\program files\Folder Guard Pro\FGUARD32.SYS [11.7.2009 22:06 54008]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - TUNEUPUTILITIESDRV
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-11-25 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-10-30 14:12]
2009-11-25 c:\windows\Tasks\Malwarebytes' Scheduled Update for DeCkY.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-18 13:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.babylon.com/home
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
IE: YamicsoftDisabled
IE: YamicsoftDisabled\&Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: YamicsoftDisabled\&Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: YamicsoftDisabled\Add to Google Photos Screensa&ver
IE: YamicsoftDisabled\E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: YamicsoftDisabled\Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: YamicsoftDisabled\Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: YamicsoftDisabled\Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\k63621ll.default\
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\npvlc.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-CASINO.RS - d:\games\CASINO.RS\_SetupCasino_936.exe
AddRemove-HijackThis - C:\Small Programs
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
AddRemove-POKERDUKAT.RS - d:\games\POKERDUKAT.RS\_SetupPoker_2530.exe
AddRemove-Tweak UI 2.10 - c:\windows\system32\mshta.exe res://c:\windows\system32\TweakUI.exe/uninstall.hta
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-11-25 14:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-299502267-1214440339-682003330-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b1,dd,6b,49,dc,37,e8,3b,38,98,0c,03,44,47,f3,96,ec,01,6e,83,6c,be,27,
0a,3e,a5,1e,0d,74,92,8e,3f,ef,c1,db,52,a0,4e,65,fd,ef,04,ff,8e,e6,2f,9f,de,\
"??"=hex:1d,2b,e5,bb,1c,7e,37,22,0d,79,19,40,aa,fe,b9,19
[HKEY_USERS\S-1-5-21-299502267-1214440339-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:a7,21,5d,f0,31,f9,8e,af,5f,d7,60,8d,b1,42,57,5d,fe,f0,b2,99,a7,
f0,23,be,7b,e1,9a,e9,4d,b8,7e,d2,2c,e6,81,83,9f,f8,45,76,0d,66,9a,96,0b,56,\
"rkeysecu"=hex:a2,76,94,96,eb,8d,b4,4b,cf,1c,9c,15,2c,13,cd,80
.
Completion time: 2009-11-25 14:08
ComboFix-quarantined-files.txt 2009-11-25 13:08
Pre-Run: 28.940.824.576 bytes free
Post-Run: 29.216.702.464 bytes free
- - End Of File - - D43D22918FD8E3D11DFE2E73F1209C8A
|