sanjalica1234 - izdvojeno iz druge teme

sanjalica1234 - izdvojeno iz druge teme

offline
  • Pridružio: 12 Jul 2009
  • Poruke: 1

ComboFix 09-07-09.08 - slobo 11.07.2009 23:44.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1349 [GMT 2:00]
Running from: c:\documents and settings\slobo\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
c:\documents and settings\All Users\Application Data\SeekmoSA
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA_hpk.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA_kyf.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAau.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht
c:\documents and settings\All Users\Start Menu\Programs\Seekmo
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Reset Cursor.lnk
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Seekmo Customer Support Center.lnk
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Seekmo Uninstall Instructions.lnk
c:\documents and settings\All Users\Start Menu\Programs\Seekmo\Weather.lnk
c:\documents and settings\slobo\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusRemover2008.lnk
c:\documents and settings\slobo\Application Data\Seekmo
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1019490.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1384984.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1399409.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\1836247.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\3404705.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\3709044.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\992161.sdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\141880
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\191116
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\198406
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\21060
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\252531
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\26656
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\268125
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29115
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29547
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\3338
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\35047
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\39245
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\423530
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\43120
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\449624
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\45364
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\579123
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\58841
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\64495
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\6558
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\65770
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67464
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\705052
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\72123
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\752499
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753250
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753299
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\79246
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\82511
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\8443
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\85062
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93899
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\3862.dat
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_2000.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_3000.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bar.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bbar1.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_logos.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_other.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_weather.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hotbarcom.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\icons2.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\layout.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\linkpathlegal.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\progress.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\s_icons_buttons.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\sales_buttons.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo_ie_menu.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\t2_bg.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\theweb.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\top7.cdf
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\Top7_theweb.mnu
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\1\tsd_bg.res
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_weather.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\icons2.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\progress.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip
c:\documents and settings\slobo\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip
c:\documents and settings\slobo\Application Data\ShoppingReport
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\slobo\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
c:\documents and settings\slobo\Application Data\WeatherDPA
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\SearchWeather.xml
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\Weather_XML\Default
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\Weather_XML\Genera1
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\Weather_XML\General
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Links
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Display
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Loading
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen1
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen2
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\screen3
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\soaperror
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\Weather_XML\Version
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherDPA\WeatherPreferences
c:\documents and settings\slobo\Application Data\WeatherDPA\Weather\WeatherStartup.xml
c:\program files\seekmo
c:\program files\seekmo\bin\10.3.85.0\arrow.ico
c:\program files\seekmo\bin\10.3.85.0\CntntCntr.dll
c:\program files\seekmo\bin\10.3.85.0\copyright.txt
c:\program files\seekmo\bin\10.3.85.0\CoreSrv.dll
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\chrome.manifest
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\components\npclntax.xpt
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\install.rdf
c:\program files\seekmo\bin\10.3.85.0\firefox\extensions\plugins\npclntax_SeekmoSA.dll
c:\program files\seekmo\bin\10.3.85.0\HostIE.dll
c:\program files\seekmo\bin\10.3.85.0\HostOE.dll
c:\program files\seekmo\bin\10.3.85.0\HostOL.dll
c:\program files\seekmo\bin\10.3.85.0\link.ico
c:\program files\seekmo\bin\10.3.85.0\OEAddOn.exe
c:\program files\seekmo\bin\10.3.85.0\SeekmoSA.exe
c:\program files\seekmo\bin\10.3.85.0\SeekmoSAAX.dll
c:\program files\seekmo\bin\10.3.85.0\SeekmoSADF.exe
c:\program files\seekmo\bin\10.3.85.0\SeekmoSAHook.dll
c:\program files\seekmo\bin\10.3.85.0\SeekmoUninstaller.exe
c:\program files\seekmo\bin\10.3.85.0\Srv.exe
c:\program files\seekmo\bin\10.3.85.0\Toolbar.dll
c:\program files\seekmo\bin\10.3.85.0\Wallpaper.dll
c:\program files\seekmo\bin\10.3.85.0\Weather.exe
c:\program files\seekmo\bin\10.3.85.0\WeSkin.dll
c:\program files\ShoppingReport
c:\program files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
c:\program files\ShoppingReport\Uninst.exe
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
C:\sivrpld.exe
c:\windows\dialerexe.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\ljqxau_navfx.dat
c:\windows\system32\msvcrt2.dll
c:\windows\system32\nvs2.inf
c:\windows\system32\qmasukw_navfx.dat
c:\windows\system32\weiiu.dat
c:\windows\system32\weiiu_nav.dat
c:\windows\system32\weiiu_navps.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_FCI
-------\Legacy_ICF
-------\Legacy_TCPSR


((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.

2009-07-09 20:57 . 2009-07-09 20:58 -------- d-----w- c:\documents and settings\slobo\Local Settings\Application Data\Temp
2009-07-09 20:57 . 2009-07-09 20:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-09 20:37 . 2009-07-09 20:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-09 20:37 . 2009-07-09 20:58 -------- d-----w- c:\documents and settings\slobo\Local Settings\Application Data\Google
2009-07-09 20:36 . 2009-07-09 20:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-09 20:36 . 2009-07-09 20:38 -------- d-----w- c:\program files\Google
2009-07-05 15:27 . 2009-07-05 15:27 -------- d-----w- c:\documents and settings\slobo\Application Data\BSplayer PRO
2009-06-12 12:06 . 2009-06-12 12:06 -------- d-----w- c:\documents and settings\slobo\Local Settings\Application Data\Ares

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 20:57 . 2009-05-31 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-08 16:00 . 2009-04-01 08:50 -------- d-----w- c:\program files\Norton Security Scan
2009-07-08 12:05 . 2009-06-03 18:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-07-01 12:52 . 2009-05-31 16:26 770080 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-01 12:52 . 2009-05-31 16:26 4760 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-01 12:52 . 2009-05-31 16:26 4035616 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-01 12:52 . 2009-05-31 16:26 33656 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-01 12:32 . 2009-05-31 16:26 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-01 12:29 . 2009-05-31 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-17 16:05 . 2009-04-01 08:50 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-11 20:54 . 2009-06-11 20:54 1915520 ----a-w- c:\documents and settings\slobo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-06 21:46 . 2009-04-23 20:03 -------- d-----w- c:\program files\Hrvatsko - Engleski Rjeènik
2009-06-06 21:40 . 2009-06-06 21:40 -------- d-----w- c:\program files\ReflexiveArcade
2009-06-06 21:35 . 2009-06-06 21:35 -------- d-----w- c:\documents and settings\slobo\Application Data\EleFun Games
2009-06-06 21:35 . 2009-02-07 21:14 -------- d-----w- c:\program files\MyPlayCity
2009-06-06 21:35 . 2009-06-06 21:35 -------- d-----w- c:\program files\MyPlayCity.com
2009-06-04 08:20 . 2009-06-03 18:18 -------- d-----w- c:\program files\Enigma Software Group
2009-06-03 19:36 . 2009-06-03 19:36 2560 ----a-w- c:\windows\system32\drivers\mchInjDrv.sys
2009-06-03 18:43 . 2009-06-03 18:43 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-06-03 18:43 . 2009-06-03 18:43 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-06-03 18:43 . 2009-06-03 18:43 -------- d-----w- c:\program files\Prevx
2009-05-31 16:43 . 2001-08-23 12:00 14336 ----a-w- c:\windows\system32\svchost.exe
2009-05-31 16:38 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-05-31 16:38 . 2009-05-31 16:27 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-31 16:38 . 2009-05-31 16:27 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-31 16:38 . 2009-05-31 16:38 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-05-31 16:38 . 2009-05-31 16:38 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-05-31 16:38 . 2009-05-31 16:38 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-05-31 16:23 . 2009-02-13 11:46 -------- d-----w- c:\program files\Spyware Doctor
2009-05-31 16:23 . 2009-02-01 01:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-30 23:26 . 2007-11-18 18:21 -------- d-----w- c:\program files\Winamp
2009-05-13 05:15 . 2001-08-23 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:44 . 2001-08-23 12:00 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 09:58 . 2001-08-23 12:00 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2001-08-23 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2007-05-15 19:34 . 2007-11-18 18:42 66672 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-05-15 19:34 . 2007-11-18 18:42 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-05-15 19:34 . 2007-11-18 18:42 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-05-15 19:34 . 2007-11-18 18:42 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-05-15 19:34 . 2007-11-18 18:42 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
2009-06-28 00:22 2094616 ----a-w- c:\program files\MyPlayCity\tbMyP1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-09 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-05-31 206088]

c:\documents and settings\slobo\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2006-10-27 338216]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1ekxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [18.11.2007 19:40 10112]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29.1.2008 17:29 33808]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [3.6.2009 20:43 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [3.6.2009 20:43 27656]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [3.6.2009 20:43 4368952]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [18.11.2007 19:41 4300]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [23.8.2001 14:00 14336]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [19.9.2007 8:47 29184]
S0 ati1ekxx;ati1ekxx;c:\windows\system32\drivers\ati1ekxx.sys [10.1.2009 16:02 32768]
S4 BsUDF;B.H.A UDF Filesystem;c:\windows\system32\drivers\BsUDF.sys [18.11.2007 19:40 165376]
S4 SNM WLAN Service;SNM WLAN Service;c:\program files\Samsung\Samsung Network Manager\SNMWLANService.exe [28.5.2005 9:35 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-09 20:36]

2009-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-09 20:37]

2009-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-09 20:37]

2009-07-08 c:\windows\Tasks\Norton Security Scan for slobo.job
- c:\program files\Norton Security Scan\Nss.exe [2009-03-13 15:20]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ares - c:\program files\Ares\Ares.exe
HKU-Default-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
Notify-dnqcvbnm - dnqcvbnm32.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com
uInternet Connection Wizard,ShellNext = iexplore
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B3} - {A16AD1E9-F69A-45af-9462-B1C286708842} -
FF - ProfilePath - c:\documents and settings\slobo\Application Data\Mozilla\Firefox\Profiles\l1rxeqxz.default\
FF - prefs.js: browser.search.selectedEngine - Crawler Search
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-07-11 23:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(676)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3744)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-07-11 23:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 21:54

Pre-Run: 14.814.048.256 bytes free
Post-Run: 16.890.179.584 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

392 --- E O F --- 2009-06-12 01:03

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Hteo si nešto?

Ko je trenutno na forumu
 

Ukupno su 936 korisnika na forumu :: 39 registrovanih, 5 sakrivenih i 892 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, A.R.Chafee.Jr., aleksmajstor, amaterSRB, anta, Bluper, bojank, bokisha253, BraneS, ceman, djboj, Djokkinen, Georgius, goxin, HrcAk47, jukeboxer, kokodakalo, Kubovac, laki_bb, ljuba, loon123, MiGac, milenko crazy north, Milometer, nemkea71, Parker, RED4G-304, repac, Ripanjac, ruma, sabros, Sirius, srbijaiznadsvega, Srki94, Trpe Grozni, Vlad000, Vlada78, Zandar, Čivi