offline
- bedazzled

- Građanin
- Pridružio: 04 Jun 2007
- Poruke: 157
|
ComboFix 08-08-12.01 - Bad 2008-08-13 15:40:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1501 [GMT 2:00]
Running from: C:\Documents and Settings\Bad\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-13 to 2008-08-13 )))))))))))))))))))))))))))))))
.
2008-08-07 14:21 . 2008-08-07 14:21 <DIR> d-------- C:\Program Files\TGTSoft
2008-08-07 03:41 . 2008-08-07 03:41 <DIR> d--h----- C:\WINDOWS\Icons
2008-08-06 22:01 . 2008-08-06 22:01 38 --a------ C:\WINDOWS\avisplitter.INI
2008-08-05 14:27 . 2008-08-05 14:27 <DIR> d-------- C:\Program Files\K-Lite Codec Pack2
2008-08-05 14:27 . 2008-08-05 14:28 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\bsplayer
2008-08-05 14:22 . 2008-08-05 14:22 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\Media Player Classic
2008-08-05 14:19 . 2008-08-05 14:19 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-08-04 14:46 . 2008-08-04 14:46 <DIR> d-------- C:\Program Files\SweetIM
2008-08-04 14:46 . 2008-08-04 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM
2008-08-04 13:49 . 2008-08-04 13:49 <DIR> d-------- C:\Program Files\The Rosetta Stone
2008-08-02 17:55 . 2008-08-02 17:55 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\ACD Systems
2008-08-01 11:43 . 2008-08-01 11:43 <DIR> d-------- C:\WINDOWS\Sun
2008-08-01 04:43 . 2008-08-01 04:43 268 --ah----- C:\sqmdata08.sqm
2008-08-01 04:43 . 2008-08-01 04:43 244 --ah----- C:\sqmnoopt08.sqm
2008-08-01 04:09 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-08-01 04:06 . 2008-08-01 04:06 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-01 04:04 . 2008-08-01 04:04 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-08-01 04:02 . 2008-08-01 04:02 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-08-01 04:01 . 2008-08-01 04:05 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-08-01 04:01 . 2008-08-01 04:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-01 04:00 . 2008-08-01 04:00 <DIR> dr-h----- C:\MSOCache
2008-08-01 03:54 . 2008-08-01 03:54 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-08-01 03:54 . 2008-08-01 03:54 <DIR> d-------- C:\Program Files\ACD Systems
2008-08-01 03:54 . 2008-08-01 03:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-08-01 03:50 . 2008-08-01 03:50 268 --ah----- C:\sqmdata07.sqm
2008-08-01 03:50 . 2008-08-01 03:50 244 --ah----- C:\sqmnoopt07.sqm
2008-08-01 03:37 . 2008-08-01 03:37 <DIR> d-------- C:\Program Files\MSN Messenger
2008-08-01 01:11 . 2008-08-01 01:11 <DIR> d-------- C:\Program Files\Avanquest update
2008-08-01 01:11 . 2008-08-01 01:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-08-01 01:10 . 2008-08-01 01:10 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-08-01 01:10 . 2008-08-01 01:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-08-01 01:02 . 2008-08-01 01:02 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\NetMedia Providers
2008-08-01 00:39 . 2008-08-01 00:39 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\InstallShield
2008-07-31 19:25 . 2008-07-31 19:25 <DIR> d-------- C:\Program Files\PowerISO
2008-07-31 18:18 . 2008-07-31 18:21 <DIR> d-------- C:\Program Files\Ant Movie Catalog
2008-07-30 22:43 . 2008-07-30 22:43 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-07-30 19:47 . 2008-07-30 19:47 <DIR> d-------- C:\Program Files\Total Video Converter
2008-07-29 20:43 . 2008-07-29 20:43 268 --ah----- C:\sqmdata06.sqm
2008-07-29 20:43 . 2008-07-29 20:43 244 --ah----- C:\sqmnoopt06.sqm
2008-07-29 01:29 . 2008-07-29 01:29 <DIR> d-------- C:\Program Files\AllMyMovies
2008-07-28 13:19 . 2008-07-28 13:19 268 --ah----- C:\sqmdata05.sqm
2008-07-28 13:19 . 2008-07-28 13:19 244 --ah----- C:\sqmnoopt05.sqm
2008-07-28 13:00 . 2008-07-28 13:00 268 --ah----- C:\sqmdata04.sqm
2008-07-28 13:00 . 2008-07-28 13:00 244 --ah----- C:\sqmnoopt04.sqm
2008-07-28 12:30 . 2008-07-28 12:30 268 --ah----- C:\sqmdata03.sqm
2008-07-28 12:30 . 2008-07-28 12:30 244 --ah----- C:\sqmnoopt03.sqm
2008-07-27 23:10 . 2008-07-30 20:56 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-27 22:36 . 2008-07-27 22:36 268 --ah----- C:\sqmdata02.sqm
2008-07-27 22:36 . 2008-07-27 22:36 244 --ah----- C:\sqmnoopt02.sqm
2008-07-27 22:29 . 2008-07-27 22:29 268 --ah----- C:\sqmdata01.sqm
2008-07-27 22:29 . 2008-07-27 22:29 244 --ah----- C:\sqmnoopt01.sqm
2008-07-27 21:05 . 2008-08-11 18:44 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-07-27 20:56 . 2008-04-14 09:42 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-07-27 20:56 . 2008-04-14 09:42 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-07-27 20:56 . 2008-04-14 04:16 15,232 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-07-27 20:56 . 2008-04-14 04:16 15,232 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-07-27 20:56 . 2008-04-14 04:16 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-07-27 20:56 . 2008-04-14 04:16 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-07-27 20:56 . 2008-04-14 04:09 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-07-27 20:56 . 2008-04-14 04:09 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-07-27 20:50 . 2008-08-01 04:05 <DIR> d-------- C:\Program Files\MSBuild
2008-07-27 20:48 . 2008-07-27 20:48 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-07-27 20:47 . 2008-07-27 20:47 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-07-27 20:47 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-07-27 20:01 . 2008-07-27 20:01 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\Sony Setup
2008-07-27 18:20 . 2008-07-27 20:49 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\OpenOffice.org2
2008-07-27 18:17 . 2008-04-14 04:15 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-26 21:23 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-07-26 21:22 . 2008-07-26 21:23 <DIR> d-------- C:\Program Files\Parallel Port Joystick
2008-07-26 21:21 . 2008-07-27 19:28 <DIR> d-------- C:\Documents and Settings\Bad\Incomplete
2008-07-26 21:21 . 2008-07-27 19:29 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\LimeWire
2008-07-26 21:21 . 2007-07-12 02:22 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-26 21:20 . 2008-07-26 21:21 <DIR> d-------- C:\Program Files\Java
2008-07-26 21:20 . 2008-07-26 21:20 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-26 21:03 . 2008-07-26 21:21 <DIR> d-------- C:\Program Files\LimeWire
2008-07-26 20:51 . 2008-08-05 20:45 <DIR> d-------- C:\Documents and Settings\Bad\Contacts
2008-07-26 20:50 . 2008-07-26 20:50 268 --ah----- C:\sqmdata00.sqm
2008-07-26 20:50 . 2008-07-26 20:50 244 --ah----- C:\sqmnoopt00.sqm
2008-07-26 20:49 . 2008-08-01 03:37 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-26 20:45 . 2008-07-26 20:45 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-07-26 20:45 . 2008-07-27 20:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sony
2008-07-26 20:45 . 1998-10-29 15:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-07-26 20:45 . 2002-12-17 16:23 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2008-07-26 20:45 . 2002-10-20 14:05 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2008-07-26 19:43 . 2001-09-17 13:20 19,968 --a------ C:\WINDOWS\system32\cpuinf32.dll
2008-07-26 15:42 . 2008-07-26 15:42 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\Nero
2008-07-26 15:38 . 2008-07-26 15:38 <DIR> d-------- C:\Program Files\Nero
2008-07-26 15:38 . 2008-07-26 15:39 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-07-26 15:38 . 2008-07-26 15:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-26 15:32 . 2008-07-26 15:32 <DIR> d-------- C:\Program Files\ASIO4ALL v2
2008-07-26 15:32 . 2008-07-26 15:32 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\Publish Providers
2008-07-26 15:31 . 2008-08-01 01:10 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\Sony
2008-07-26 15:28 . 2008-07-26 15:28 <DIR> d-------- C:\Program Files\Vstplugins
2008-07-26 15:27 . 2008-07-27 20:51 <DIR> d-------- C:\Program Files\Sony
2008-07-26 15:26 . 2008-07-26 20:42 <DIR> d-------- C:\Program Files\Sony Setup
2008-07-26 15:23 . 2008-07-26 15:23 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-26 15:21 . 2008-08-01 03:57 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-26 13:04 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-07-26 13:04 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-07-26 13:04 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-07-26 13:04 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-07-26 13:03 . 2008-07-26 13:03 <DIR> d-------- C:\Program Files\Sygate
2008-07-26 13:03 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-07-26 13:03 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-07-26 13:03 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-07-26 12:57 . 2008-07-26 13:04 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\GetRightToGo
2008-07-26 12:42 . 2008-08-11 14:59 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-07-26 12:42 . 2008-08-13 15:32 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\Spyware Terminator
2008-07-26 12:42 . 2008-08-11 14:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-07-26 12:42 . 2008-07-26 12:42 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-07-26 12:24 . 2008-07-26 12:24 <DIR> d-------- C:\Program Files\Avira
2008-07-26 03:59 . 2008-08-13 14:34 <DIR> d-------- C:\Program Files\FlashGet
2008-07-26 03:54 . 2008-07-26 03:55 <DIR> d-------- C:\Program Files\BitComet
2008-07-26 03:54 . 2008-08-07 20:11 <DIR> d-------- C:\Downloads
2008-07-26 03:54 . 2008-07-26 03:54 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-07-26 03:50 . 2008-07-26 03:51 <DIR> d-------- C:\Program Files\Desktop Tray Clock
2008-07-26 03:50 . 2008-07-26 03:50 58,880 --a------ C:\WINDOWS\system32\byxndeed.dll.ren
2008-07-26 03:31 . 2008-07-26 03:31 <DIR> d-------- C:\Program Files\TuneUp Utilities 2007
2008-07-26 03:31 . 2008-07-26 03:31 <DIR> d-------- C:\Documents and Settings\Bad\Application Data\TuneUp Software
2008-07-26 03:31 . 2007-03-28 19:42 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-07-26 03:30 . 2008-07-26 13:03 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 03:30 . 2008-07-26 03:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-07-26 03:24 . 2008-07-26 03:24 <DIR> d-------- C:\Program Files\CyberLink
2008-07-26 03:24 . 2008-07-26 03:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-26 03:24 . 2003-04-23 18:29 221,215 --------- C:\WINDOWS\system32\Divxdec.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-01 01:07 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-31 23:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-26 10:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-07-25 23:34 21,275 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-07-25 23:34 --------- d-----w C:\Program Files\TP-LINK
2008-07-25 23:29 --------- d-----w C:\Documents and Settings\Bad\Application Data\ATI
2008-07-25 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
2008-07-25 23:23 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-25 23:23 --------- d-----w C:\Program Files\ATI Technologies
2008-07-12 19:24 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-07-12 19:20 1,614,848 ----a-w C:\WINDOWS\system32\sfcfiles.dll
2008-07-12 19:18 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-07-12 19:10 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-12 19:10 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-07-12 19:10 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-07-12 19:10 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-07-12 19:10 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-07-12 19:10 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-07-12 19:10 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-07-12 19:10 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2008-07-12 19:10 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2008-07-12 19:10 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2008-07-12 19:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-07-07 07:40 56,108 ----a-w C:\WINDOWS\system32\drivers\scdemu.sys
2008-07-04 06:33 3,230,720 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-07-04 03:48 9,490,432 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 53,248 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-07-04 02:28 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:22 565,248 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-07-03 16:35 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-05-30 12:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 12:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 12:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 12:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 12:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 12:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 12:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-07-06 12:44 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-07-06 12:44 1164600 --a------ C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 12:44 1164600]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 12:44 1164600]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="C:\Program Files\Desktop Tray Clock\DTClock.exe" [2008-07-26 03:51 1694720]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 10:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 09:47 61440]
"TWCU"="C:\Program Files\TP-LINK\TWCU\TWCU.exe" [2006-03-29 13:42 364544]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43 57344]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-07-26 12:42 1783808]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-07-07 09:34 167936]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"SweetIM"="C:\Program Files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 12:32 111928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FlashGet\\FlashGet.exe"=
"D:\\Games INST\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"D:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\MSLPLTS.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11535:TCP"= 11535:TCP:BitComet 11535 TCP
"11535:UDP"= 11535:UDP:BitComet 11535 UDP
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-07-26 12:42]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 10:00]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;C:\WINDOWS\system32\drivers\PPJoyBus.sys [2004-10-24 08:11]
R3 PPortJoystick;Parallel Port Joystick device driver;C:\WINDOWS\system32\drivers\PPortJoy.sys [2004-10-24 08:11]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-08-08 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]
.
- - - - ORPHANS REMOVED - - - -
Notify-byXNdeed - byXNdeed.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Bad\Application Data\Mozilla\Firefox\Profiles\62xoep3i.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - [Link mogu videti samo ulogovani korisnici]
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-08-13 15:43:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-08-13 15:44:49
ComboFix-quarantined-files.txt 2008-08-13 13:44:24
Pre-Run: 9,184,845,824 bytes free
Post-Run: 9,210,388,480 bytes free
307
|