offline
- zeka_94
- Novi MyCity građanin
- Pridružio: 22 Sep 2009
- Poruke: 10
- Gde živiš: Cuprija
|
Evo ga i ComboFix,imao sam jedan problem,posle skeniranja combofix-a kompjuter mi se dizao oko 5 minuta,ali posle je bilo sve u redu.....
ComboFix 09-09-25.01 - CUPRIJA 09/27/2009 19:51.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.511.216 [GMT 2:00]
Running from: c:\documents and settings\CUPRIJA\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - system32: deleted 1047061 bytes in 2 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\CUPRIJA\Application Data\Gmail
c:\program files\XPCode\Games.lnk
c:\windows\system32\28463
c:\windows\system32\28463\akv.cfg
c:\windows\system32\28463\NUSR.001
c:\windows\system32\28463\NUSR.002
c:\windows\system32\28463\NUSR.005
c:\windows\system32\28463\NUSR.009
c:\windows\Sysvxd.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-27 to 2009-09-27 )))))))))))))))))))))))))))))))
.
2009-09-23 15:10 . 2009-09-23 15:12 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\Temp
2009-09-19 22:10 . 2009-09-19 22:10 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-09-19 21:56 . 2009-09-19 21:56 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\Real
2009-09-19 21:55 . 2009-09-19 21:55 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-19 21:52 . 2009-09-19 21:52 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-09-16 13:15 . 2009-09-16 13:15 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\WMTools Downloaded Files
2009-09-13 20:28 . 2009-09-14 16:27 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\uTorrent
2009-09-13 14:14 . 2004-03-18 16:36 401484 ----a-w- c:\windows\system32\msvcrtd.dll
2009-09-13 13:25 . 2008-04-13 22:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2009-09-13 13:25 . 2008-04-13 22:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-09-13 13:25 . 2008-04-13 22:16 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2009-09-13 13:25 . 2008-04-13 22:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2009-09-13 13:25 . 2008-04-13 22:16 15232 -c--a-w- c:\windows\system32\dllcache\streamip.sys
2009-09-13 13:25 . 2008-04-13 22:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2009-09-13 13:25 . 2008-04-13 22:16 11136 -c--a-w- c:\windows\system32\dllcache\slip.sys
2009-09-13 13:25 . 2008-04-13 22:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2009-09-13 13:25 . 2008-04-14 03:42 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-09-13 13:25 . 2008-04-14 03:42 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-09-13 13:25 . 2008-04-13 22:16 19200 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys
2009-09-13 13:25 . 2008-04-13 22:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-09-13 13:24 . 2008-04-13 22:16 85248 -c--a-w- c:\windows\system32\dllcache\nabtsfec.sys
2009-09-13 13:24 . 2008-04-13 22:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2009-09-13 13:24 . 2008-04-13 22:16 17024 -c--a-w- c:\windows\system32\dllcache\ccdecode.sys
2009-09-13 13:24 . 2008-04-13 22:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2009-09-13 13:24 . 2006-11-01 16:45 219264 ----a-w- c:\windows\system32\drivers\BTCamDrv.sys
2009-09-13 13:13 . 2007-09-20 11:04 114688 ----a-w- c:\windows\system32\BTCamVideoSource.dll
2009-09-13 12:38 . 2009-09-13 12:38 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\WinZip
2009-09-13 12:37 . 2009-09-13 12:40 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-09-13 12:12 . 2003-03-19 07:12 1047552 ----a-w- c:\windows\system32\MFC71u.dll
2009-09-13 10:56 . 2009-09-13 10:56 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-09-13 10:55 . 2009-09-24 16:42 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\skypePM
2009-09-13 10:52 . 2009-09-24 21:20 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Skype
2009-09-13 10:51 . 2009-09-13 10:51 -------- d-----w- c:\program files\Common Files\Skype
2009-09-10 18:07 . 2009-09-10 18:11 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\mIRC
2009-09-08 20:11 . 2009-09-08 20:11 -------- d-----w- c:\program files\AnswerWorks 4.0
2009-09-08 20:09 . 2009-09-08 20:18 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Autodesk
2009-09-08 20:09 . 2009-09-08 20:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2009-09-08 20:09 . 2009-09-08 20:09 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\Autodesk
2009-09-08 20:05 . 2009-09-08 20:13 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2009-09-08 20:05 . 2009-09-08 20:05 -------- d-----w- c:\program files\Autodesk
2009-09-06 10:49 . 2009-09-06 10:49 278768 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-06 10:47 . 2009-09-06 10:47 -------- d-----w- c:\program files\MSBuild
2009-09-06 10:47 . 2009-09-06 10:47 -------- d-----w- c:\windows\system32\XPSViewer
2009-09-06 10:47 . 2009-09-06 10:47 -------- d-----w- c:\program files\Reference Assemblies
2009-09-06 10:46 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-09-04 14:12 . 2009-09-04 14:12 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\Deployment
2009-09-03 18:40 . 2009-09-03 18:40 -------- d-----w- c:\program files\Gaxian
2009-08-31 00:08 . 2009-08-31 00:08 -------- d-----w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142020}
2009-08-30 19:39 . 2009-08-30 19:39 -------- d-----w- c:\documents and settings\CUPRIJA\.idlerc
2009-08-29 11:19 . 2009-08-29 11:19 86016 ----a-w- c:\windows\system32\frapsvid.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 18:07 . 2009-06-22 14:30 -------- d-----w- c:\program files\XPCode
2009-09-26 21:06 . 2009-06-05 17:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-22 19:58 . 2009-08-21 17:36 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-19 21:55 . 2009-06-05 16:29 -------- d-----w- c:\program files\Common Files\Real
2009-09-19 21:54 . 2009-06-05 16:29 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-09-19 21:54 . 2009-06-05 16:29 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-19 21:54 . 2009-06-05 16:29 -------- d-----w- c:\program files\Real
2009-09-19 21:53 . 2009-07-21 17:20 -------- d-----w- c:\program files\Google
2009-09-14 16:27 . 2009-06-05 17:54 -------- d-----w- c:\program files\FlashGet
2009-09-13 10:50 . 2009-07-01 21:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-09-08 20:17 . 2009-06-05 14:08 168952 ----a-w- c:\documents and settings\CUPRIJA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-07 18:40 . 2009-06-05 15:09 -------- d-----w- c:\program files\ATI Technologies
2009-08-28 17:07 . 2009-08-28 17:07 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\ACD Systems
2009-08-27 18:16 . 2009-08-27 18:11 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Notepad++
2009-08-26 17:52 . 2009-08-26 17:52 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\teamspeak2
2009-08-24 13:15 . 2009-08-24 13:15 -------- d-----w- c:\program files\Lavasoft
2009-08-24 13:15 . 2009-08-22 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-24 13:14 . 2009-08-24 13:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-22 15:36 . 2009-08-22 00:20 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Uniblue
2009-08-22 15:36 . 2009-08-22 00:20 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-08-22 11:05 . 2009-06-05 14:19 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Lavasoft
2009-08-22 00:58 . 2009-08-22 00:58 -------- d-----w- c:\program files\MSXML 4.0
2009-08-21 22:13 . 2009-08-21 22:13 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-21 22:13 . 2009-08-21 22:13 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-08-21 22:13 . 2009-08-21 18:10 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-08-21 19:43 . 2009-08-21 19:43 -------- d-----w- c:\program files\aSkola
2009-08-21 18:11 . 2009-08-21 18:11 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\TuneUp Software
2009-08-21 18:10 . 2009-08-21 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-08-21 18:09 . 2009-08-21 18:09 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-08-21 08:42 . 2009-06-05 14:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-20 21:18 . 2009-08-17 12:46 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\MessengerDiscovery 2
2009-08-20 15:15 . 2009-08-20 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-20 15:15 . 2009-08-20 15:15 -------- d-----w- c:\program files\Microsoft WSE
2009-08-20 13:55 . 2009-08-20 13:16 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\TeamViewer
2009-08-20 11:22 . 2009-08-19 23:16 -------- d-----w- c:\program files\Common Files\Reallusion
2009-08-19 11:32 . 2009-08-19 11:32 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Media Player Classic
2009-08-17 15:03 . 2009-08-17 15:03 -------- d-----w- c:\program files\Ask.com
2009-08-15 22:35 . 2009-08-14 20:45 -------- d-----w- c:\documents and settings\CUPRIJA\Application Data\Hamachi
2009-08-14 22:35 . 2009-08-14 22:35 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-08-14 21:09 . 2009-08-14 20:43 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-08-11 20:33 . 2009-08-11 20:32 -------- d-----w- c:\program files\WinPcap
2009-08-10 21:05 . 2009-08-07 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-08-09 22:47 . 2009-08-09 22:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-08-08 22:13 . 2009-06-05 17:58 -------- d-----w- c:\program files\Mv2Player
2009-08-07 17:30 . 2009-08-07 17:30 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-05 22:45 . 2009-08-05 22:45 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-05 09:01 . 2008-04-14 03:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2008-04-14 03:42 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2008-04-14 03:41 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 16:26 . 2009-07-26 16:26 0 ----a-w- c:\windows\nsreg.dat
2009-07-26 10:59 . 2009-07-26 10:59 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-21 15:56 . 2009-07-21 15:56 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-17 19:01 . 2008-04-14 03:41 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 09:48 . 2009-08-21 22:13 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-13 16:46 . 2009-07-11 23:44 25 ----a-w- c:\windows\popcinfot.dat
2009-07-13 08:08 . 2008-04-14 03:42 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-07-02 2215960]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-07-02 08:18 2215960 ----a-w- c:\program files\ToggleEN\tbTogg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-05-06 16:11 1145736 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-07-02 2215960]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-05-06 1145736]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-07-02 2215960]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-05-06 1145736]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"H/PC Connection Agent"="d:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-06-05 949376]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-20 177472]
"ACU"="c:\program files\Atheros\ACU\Utility\ACU.exe" [2005-11-28 303104]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 344064]
"Java Updates"="d:\program files\Java\jre6\bin\java.exe" [2009-08-05 145184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-19 198160]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-08-05 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 99840]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-25 113664]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-5 10872]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-19 565309]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Valve\\hl.exe"=
"c:\\Documents and Settings\\CUPRIJA\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"d:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"d:\program files\Microsoft ActiveSync\rapimgr.exe"= d:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"d:\program files\Microsoft ActiveSync\wcescomm.exe"= d:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"d:\program files\Microsoft ActiveSync\WCESMgr.exe"= d:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\mIRC\\mirc.exe"=
"d:\\Program Files\\Mobiola Web Camera for Windows Mobile\\webcam.exe"=
"c:\\Documents and Settings\\CUPRIJA\\Desktop\\wlan hack\\air(zabranjeno)-ng-1.0-win\\bin\\buddy-ng.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\CUPRIJA\\Desktop\\webhack\\Hacking-WEP.Plugin\\WEPdecoder.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [6/5/2009 6:29 PM 15424]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [8/22/2009 12:13 AM 604488]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [8/22/2009 2:37 AM 7808]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [1/25/2008 11:12 AM 25088]
S2 gupdate1ca397378a8f1f0;Google Update Service (gupdate1ca397378a8f1f0);c:\program files\Google\Update\GoogleUpdate.exe [9/19/2009 11:52 PM 133104]
S3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\drivers\BTCamDrv.sys [9/13/2009 3:24 PM 219264]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;d:\program files\MAGIX\Common\Database\bin\fbserver.exe [7/21/2009 2:53 PM 1527900]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\NPF.sys --> c:\windows\system32\drivers\NPF.sys [?]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [7/26/2009 1:20 PM 558560]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - UWKIQFOG
*Deregistered* - uwkiqfog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4944C57-1102-8529-D13C-EE0924183803}]
c:\windows\system32:winlogon..exe
.
Contents of the 'Scheduled Tasks' folder
2009-09-27 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 08:54]
2009-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-19 21:52]
2009-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-19 21:52]
2009-09-27 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-05-06 16:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com/?SearchSource=10&ctid=CT2077543
uInternet Connection Wizard,ShellNext = login.live.com/ppsecure/sha1auth.srf?lc=1033
uInternet Settings,ProxyOverride = *.local
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Download with Xilisoft Download YouTube Video - d:\program files\Xilisoft\Download YouTube Video\upod_link.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\CUPRIJA\Application Data\Mozilla\Firefox\Profiles\113q3kwx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://sr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sr:official
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PCW&o=14734&locale=en_EU&q=
FF - component: c:\program files\Mozilla Firefox\extensions\browserhighlighter@ebay.com\components\Shim.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npjp2.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-09-27 20:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1275210071-1993962763-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{486F6224-DB96-F6FB-BE49-96F33E0142FD}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"ialnlbfbbekjbcbhff"=hex:6a,61,6f,65,65,65,61,66,6e,6c,66,6d,6f,6d,6b,6f,62,65,
69,61,00,00
"hafobbcimnijleme"=hex:6a,61,6f,65,65,65,61,66,6e,6c,66,6d,6f,6d,6b,6f,62,65,
69,61,00,00
[HKEY_USERS\S-1-5-21-1275210071-1993962763-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C9D733B8-CDB7-7F4A-39E9-A9661C08FE55}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iamafaoffhhjopklaa"=hex:6a,61,6a,62,6e,62,66,70,69,65,70,6e,6d,64,6f,63,63,6e,
66,6e,00,00
"haobljkmenpicddl"=hex:6a,61,6a,62,6e,62,66,70,69,65,70,6e,6d,64,6f,63,63,6e,
66,6e,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1300)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-09-27 20:14
ComboFix-quarantined-files.txt 2009-09-27 18:14
Pre-Run: 2,769,477,632 bytes free
Post-Run: 2,955,694,080 bytes free
315 --- E O F --- 2009-08-22 01:07
|