offline
- Clark
- Novi MyCity građanin
- Pridružio: 26 Jun 2008
- Poruke: 7
|
ComboFix 08-06-20.4 - M3 2008-06-27 22:36:03.3 - NTFSx86
Running from: C:\Documents and Settings\M3\Desktop\New Folder\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\M3\Application Data\inst.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
2008-06-27 19:07 . 2008-06-27 19:07 359,808 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-06-27 14:27 . 2008-06-27 22:41 380,960 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-27 14:27 . 2008-06-27 22:09 4,556 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-27 14:26 . 2008-06-27 14:26 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-06-27 14:24 . 2008-06-27 14:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-26 20:03 . 2008-06-26 20:03 <DIR> d-------- C:\Documents and Settings\M3\Application Data\iolo
2008-06-26 20:03 . 2008-06-26 20:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2008-06-26 19:31 . 2008-03-13 23:11 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-06-26 19:25 . 2008-06-26 19:25 <DIR> d-------- C:\Program Files\Zone Labs
2008-06-25 20:26 . 2008-06-25 20:26 63,925 --a------ C:\WINDOWS\system32\{cb06620c-9c34-83db-e6f7-98b8e0e54e43}.dll-uninst.exe
2008-06-25 17:07 . 2008-06-25 17:08 <DIR> d-------- C:\Documents and Settings\Lalica\Application Data\LimeWire
2008-06-25 15:37 . 2008-06-25 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-25 15:36 . 2008-06-25 15:36 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-06-25 01:07 . 2008-06-25 15:38 <DIR> d-------- C:\Program Files\LimeWire
2008-06-25 01:07 . 2008-06-27 21:44 <DIR> d-------- C:\Documents and Settings\M3\Application Data\LimeWire
2008-06-22 23:38 . 2008-06-26 19:46 <DIR> d-------- C:\Program Files\Avira
2008-06-22 23:38 . 2008-06-27 22:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-22 20:41 . 2008-06-22 20:41 <DIR> d-------- C:\Program Files\Opera
2008-06-22 18:10 . 2008-06-22 18:10 <DIR> d-------- C:\Program Files\uTorrent
2008-06-22 18:10 . 2008-06-27 22:09 <DIR> d-------- C:\Documents and Settings\M3\Application Data\uTorrent
2008-06-22 11:04 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-06-22 11:04 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-06-22 03:42 . 2008-06-27 22:08 <DIR> d-------- C:\Program Files\Alwil Software
2008-06-16 17:25 . 2008-06-27 22:22 <DIR> d-------- C:\Program Files\2 Find MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 19:56 2,745,856 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-06-27 19:56 1,363,968 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-06-27 17:07 359,808 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-06-27 00:46 51,071 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2008_06_27_02_03_15_small.dmp.zip
2008-06-26 20:45 537,600 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-06-26 20:45 1,294,848 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-06-25 17:49 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-23 01:21 --------- d-----w C:\Program Files\eMule
2008-06-22 20:33 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-22 19:24 --------- d-----w C:\Program Files\Lavasoft
2008-06-22 19:24 --------- d-----w C:\Documents and Settings\M3\Application Data\Lavasoft
2008-05-17 21:32 --------- d-----w C:\Program Files\Master Converter
2008-05-08 23:58 --------- d-----w C:\Program Files\Winamp
2008-05-03 21:33 --------- d-----w C:\Program Files\Free Hide Folder
2008-05-01 16:12 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-05-01 15:42 --------- d-----w C:\Program Files\PowerArchiver
2008-04-29 13:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-29 13:58 --------- d-----w C:\Program Files\DVD-RAM
2008-04-28 18:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Barbie Fashion Show
2008-04-28 17:56 --------- d-----w C:\Program Files\Common Files\Vivendi Universal Games
2008-04-27 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-06-20 11:35 47,360 ----a-w C:\Documents and Settings\M3\Application Data\pcouffin.sys
.
------- Sigcheck -------
2005-03-02 20:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 17:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 00:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 20:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 17:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 17:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll
2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2008-06-27 19:07 359808 8d8949936913b041c6a0e184fbf1030b C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-06-27 19:07 359808 8d8949936913b041c6a0e184fbf1030b C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-26 20:46:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-27 20:10:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-12 16:44:11 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-12 16:32:02 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-12 16:33:19 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-12 16:38:45 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-12 16:38:25 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-12 16:34:42 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-12 16:36:18 77,904 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-12 16:33:38 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2007-07-19 13:10:28 127,768 ----a-w C:\WINDOWS\system32\drivers\klif.sys
- 2008-04-02 19:07:40 83,432 ------w C:\WINDOWS\system32\vsdata.dll
+ 2008-03-13 21:10:52 83,432 ----a-w C:\WINDOWS\system32\vsdata.dll
- 2008-04-02 19:08:00 394,952 ------w C:\WINDOWS\system32\vsdatant.sys
+ 2008-03-13 21:11:18 394,952 ----a-w C:\WINDOWS\system32\vsdatant.sys
- 2007-03-08 23:01:26 71,408 ----a-w C:\WINDOWS\system32\vsregexp.dll
+ 2008-03-13 21:10:54 71,144 ----a-w C:\WINDOWS\system32\vsregexp.dll
- 2007-03-08 23:01:30 46,832 ----a-w C:\WINDOWS\system32\vswmi.dll
+ 2008-03-13 21:10:56 46,568 ----a-w C:\WINDOWS\system32\vswmi.dll
- 2008-06-26 17:33:50 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-06-27 12:26:18 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
- 2007-03-08 23:01:10 362,280 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2008-03-13 21:10:44 370,208 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-05-30 22:03:30 65,248 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
- 2006-06-30 13:47:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2006-06-30 12:47:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-30 22:03:30 1,628 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\pdmkl.dat
- 2006-12-19 17:13:50 61,565 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-30 22:03:16 77,824 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
- 2006-12-19 17:13:50 114,813 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-30 22:03:16 110,592 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
- 2006-12-19 17:13:50 307,323 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-30 22:03:16 331,776 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
- 2006-11-29 21:02:26 36,923 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2007-05-30 22:03:16 38,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
- 2006-09-19 22:12:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
+ 2006-09-19 21:12:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
- 2007-01-11 16:31:04 274,514 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2007-12-03 12:53:58 282,624 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
- 2006-12-19 17:13:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2006-12-19 16:13:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-30 22:03:20 548,864 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-30 22:03:20 626,688 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
- 2006-11-29 21:02:26 184,445 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-30 22:03:18 184,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-30 22:03:22 90,112 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
- 2006-12-19 17:13:52 94,313 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2007-12-03 12:53:58 139,264 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
- 2006-12-19 17:13:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
+ 2006-12-19 16:13:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
- 2007-03-08 23:01:10 100,080 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2008-03-13 21:10:44 99,816 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
- 2004-01-30 11:35:08 813,568 ----a-w C:\WINDOWS\system32\ZoneLabs\dbghelp.dll
+ 2004-01-30 10:35:08 813,568 ----a-w C:\WINDOWS\system32\ZoneLabs\dbghelp.dll
- 2007-03-08 23:01:14 128,744 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2008-03-13 21:10:46 128,480 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
- 2007-03-08 23:01:14 38,640 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2008-03-13 21:10:46 38,376 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
- 2007-03-08 23:01:14 321,280 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2008-03-13 21:10:46 321,016 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
- 2007-03-08 23:02:12 288,408 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2008-03-13 21:11:20 288,144 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
- 2007-03-08 23:02:12 153,240 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
+ 2008-06-27 12:56:15 152,976 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
- 2007-03-08 23:02:14 26,264 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2008-03-13 21:11:20 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
- 2007-03-08 23:02:14 1,361,560 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2008-03-13 21:11:22 1,361,296 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
- 2007-03-08 23:02:14 71,320 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2008-03-13 21:11:22 71,056 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
- 2007-03-08 23:04:42 30,448 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2008-03-13 21:12:38 30,184 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
- 2007-03-08 23:04:44 30,480 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2008-03-13 21:12:38 30,216 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
- 2007-01-18 04:39:16 714,472 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2008-02-27 01:10:26 714,208 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
- 2007-01-18 04:39:16 677,608 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2008-02-27 01:10:28 792,032 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
- 2007-01-11 10:12:08 2,432,259 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-01-21 06:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
- 2007-01-18 04:39:18 1,369,832 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2008-02-27 01:10:32 1,504,736 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
- 2007-01-18 04:39:20 50,416 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
+ 2008-02-27 01:10:44 51,176 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
- 2007-03-08 23:04:44 210,696 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2008-03-13 21:12:38 214,528 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
- 2007-03-08 23:04:46 3,229,440 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2008-03-13 21:12:40 3,266,040 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
- 2006-09-04 19:59:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
+ 2006-09-04 18:59:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
- 2006-10-28 02:03:16 833,520 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2007-10-11 14:50:32 832,984 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
- 2007-03-08 23:01:58 141,104 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2008-03-13 21:11:08 144,936 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
- 2007-01-11 16:31:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
+ 2007-01-11 15:31:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
- 2007-03-08 23:01:58 75,568 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2008-03-13 21:11:08 75,304 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
- 2007-03-08 23:01:28 243,440 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2008-03-13 21:10:54 239,080 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
- 2007-01-11 10:12:08 2,432,259 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
+ 2008-01-21 06:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
- 2007-03-08 23:01:32 79,608 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2008-03-13 21:10:58 79,344 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
- 2007-03-08 23:01:34 378,608 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2008-03-13 21:10:58 382,440 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
- 2007-03-08 23:01:34 120,560 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
+ 2008-03-13 21:10:58 120,296 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
- 2007-03-08 23:01:42 1,087,216 ----a-w C:\WINDOWS\system32\zpeng24.dll
+ 2008-03-13 21:11:02 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
+ 2008-06-27 20:11:25 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_764.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-12-10 19:12 5419008]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-07 21:45 98304]
"nwiz"="nwiz.exe" [2004-12-10 19:12 1490944 C:\WINDOWS\system32\nwiz.exe]
"NVRotateSysTray"="C:\WINDOWS\system32\nvsysrot.dll" [2004-12-10 19:12 49152]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 23:37 88363 C:\WINDOWS\agrsmmsg.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
"BluetoothAuthenticationAgent"="bthprops.cpl,,BluetoothAuthenticationAgent" []
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-09-09 15:07 49152]
"TAudEffect"="C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe" [2004-10-06 18:48 331840]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"00THotkey"="C:\WINDOWS\system32\00THotkey.exe" [2004-08-11 10:36 253952]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-12 18:39 79224]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2008-04-29 15:58:41 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.3ivx"= 3ivxVfWCodec.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
backup=C:\WINDOWS\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Monitor.lnk]
backup=C:\WINDOWS\pss\Bluetooth Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK]
--a------ 2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
--a------ 2004-08-11 10:36 253952 C:\WINDOWS\system32\00THotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--------- 2004-07-26 19:14 1867776 C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2004-12-10 19:12 5419008 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-12-10 19:12 1490944 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-05-07 21:45 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2004-08-06 08:27 860160 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 09:11 1388544 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosHKCW.exe]
--a------ 2002-09-09 15:07 49152 C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"CiSvc"=3 (0x3)
"mnmsrvc"=3 (0x3)
"SysmonLog"=3 (0x3)
"Schedule"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-12 18:36]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-12 18:38]
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2007-11-20 19:46]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2004-05-13 12:58]
R3 TEchoCan;Toshiba Audio Effect;C:\WINDOWS\system32\DRIVERS\TEchoCan.sys [2004-09-27 11:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cec7017-07c8-11dd-a9bd-b77ca24eb84f}]
\Shell\Auto\command - Long.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Long.exe
*Newly Created Service* - ASWUPDSV
*Newly Created Service* - AVAST!_ANTIVIRUS
*Newly Created Service* - AVAST!_MAIL_SCANNER
*Newly Created Service* - AVAST!_WEB_SCANNER
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-01-20 11:24:08 C:\WINDOWS\Tasks\Critical Battery Alarm Program.job"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-06-27 22:40:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-27 22:45:51
ComboFix-quarantined-files.txt 2008-06-27 20:45:44
ComboFix2.txt 2008-06-27 01:14:24
ComboFix3.txt 2008-06-26 20:58:32
Pre-Run: 4,728,246,272 bytes free
Post-Run: 4,708,184,064 bytes free
310 --- E O F --- 2007-08-03 02:21:24
Izvini, ali nisam mogao ranije. Antivirusni program mi je nesto bagovao, pa sam presao na avast.
Od p2p koristim utorrent i limeware. Istina je da tu nikada ne zna covek sta skida, ali uvek skeniram pre nego sto bilo sta otvorim. Znam da to nije dovoljno ali...
|