offline
- VULETICA
- Građanin
- Pridružio: 18 Nov 2008
- Poruke: 45
- Gde živiš: NEWCASTLE UPON TYNE
|
mycity.rs/must-login.png
EVO IZVESTAJA
HVALA NA JAVLJANJU I POMOCI
ALEKSA
ComboFix 08-10-25.01 - Owner 2008-11-19 19:42:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.661 [GMT 0:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Fonts\'
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\c.ico
C:\WINDOWS\system32\m.ico
C:\WINDOWS\system32\p.ico
C:\WINDOWS\system32\s.ico
.
((((((((((((((((((((((((( Files Created from 2008-10-19 to 2008-11-19 )))))))))))))))))))))))))))))))
.
2008-11-18 18:48 . 2008-11-18 18:48 125,952 --a------ C:\WINDOWS\system32\xplkax.dll
2008-11-18 18:48 . 2008-11-18 18:48 125,952 --a------ C:\WINDOWS\system32\vinhuhul.dll
2008-11-18 18:44 . 2008-11-18 18:45 1,453,990 ---hs---- C:\WINDOWS\system32\wslddxwx.ini
2008-11-18 18:43 . 2008-11-18 18:44 76,800 --a------ C:\WINDOWS\system32\xwxddlsw.dll
2008-11-18 18:41 . 2008-11-18 18:41 41,472 --a------ C:\WINDOWS\system32\cuycqaef.dll
2008-11-18 12:07 . 2008-11-18 12:07 1,459,790 ---hs---- C:\WINDOWS\system32\jaocrogr.ini
2008-11-18 12:06 . 2008-11-18 12:07 76,800 --------- C:\WINDOWS\system32\rgorcoaj.dll
2008-11-18 12:03 . 2008-11-18 12:03 125,952 --a------ C:\WINDOWS\system32\ucuxryya.dll
2008-11-18 12:03 . 2008-11-18 12:03 125,952 --a------ C:\WINDOWS\system32\byzlde.dll
2008-11-18 12:00 . 2008-11-18 12:00 41,472 --a------ C:\WINDOWS\system32\ttibivdw.dll
2008-11-18 11:59 . 2008-11-18 12:24 742,219 --ahs---- C:\WINDOWS\system32\gjkUBcdd.ini2
2008-11-18 11:59 . 2008-11-18 12:27 742,218 --ahs---- C:\WINDOWS\system32\gjkUBcdd.ini
2008-11-18 11:58 . 2008-11-18 11:58 322,560 --a------ C:\WINDOWS\system32\ddcBUkjg.dll
2008-11-17 18:30 . 2008-11-17 18:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-11-17 12:29 . 2008-11-17 12:29 1,538,487 ---hs---- C:\WINDOWS\system32\fluasdci.ini
2008-11-17 12:28 . 2008-11-17 12:29 76,288 --a------ C:\WINDOWS\system32\icdsaulf.dll
2008-11-16 20:22 . 2008-11-17 18:23 0 --a------ C:\log.tmp
2008-11-16 20:17 . 2008-11-16 20:17 <DIR> d-------- C:\Program Files\Ashampoo
2008-11-16 19:40 . 2008-11-16 19:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-11-16 12:18 . 2008-11-16 12:18 <DIR> d-------- C:\Documents and Settings\MIMI\Application Data\Ahead
2008-11-16 11:10 . 2008-11-16 11:10 <DIR> d-------- C:\Program Files\AVG
2008-11-16 10:46 . 2008-11-16 10:46 1,538,441 ---hs---- C:\WINDOWS\system32\hgcdwgqs.ini
2008-11-16 10:42 . 2008-11-16 10:43 125,952 --a------ C:\WINDOWS\system32\nuafeigt.dll
2008-11-16 10:40 . 2008-11-16 10:40 41,472 --a------ C:\WINDOWS\system32\kciwqptl.dll
2008-11-16 10:39 . 2008-11-16 10:39 322,560 --------- C:\WINDOWS\system32\xxyawxUO.dll
2008-11-16 10:39 . 2008-11-19 19:47 877 --ahs---- C:\WINDOWS\system32\OUxwayxx.ini2
2008-11-16 10:39 . 2008-11-19 19:47 877 --ahs---- C:\WINDOWS\system32\OUxwayxx.ini
2008-11-16 08:42 . 2008-11-16 08:42 <DIR> d-------- C:\Documents and Settings\MIMI\Application Data\PC Tools
2008-11-15 22:58 . 2008-11-15 22:58 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-11-15 22:51 . 2008-11-16 11:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-11-14 20:50 . 2008-11-15 12:40 1,562,260 ---hs---- C:\WINDOWS\system32\kcixpyqu.ini
2008-11-14 20:47 . 2008-11-14 20:46 125,952 --a------ C:\WINDOWS\system32\yvrvxi.dll
2008-11-14 20:46 . 2008-11-14 20:46 125,952 --a------ C:\WINDOWS\system32\vkluuknv.dll
2008-11-14 20:43 . 2008-11-14 20:43 41,472 --a------ C:\WINDOWS\system32\wvrlagoj.dll
2008-11-12 23:21 . 2008-11-13 00:02 1,556,330 ---hs---- C:\WINDOWS\system32\wcdpfmqv.ini
2008-11-12 23:21 . 2008-11-12 23:21 125,952 --a------ C:\WINDOWS\system32\kqfhas.dll
2008-11-12 23:20 . 2008-11-12 23:21 125,952 --a------ C:\WINDOWS\system32\jnenudaq.dll
2008-11-12 23:19 . 2008-11-12 23:20 85,504 --a------ C:\WINDOWS\system32\bjvaaqjm.dll
2008-11-12 22:34 . 2008-11-18 15:19 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-11-12 20:40 . 2008-11-12 20:39 125,952 --a------ C:\WINDOWS\system32\ojlfgm.dll
2008-11-12 20:39 . 2008-11-12 20:39 125,952 --a------ C:\WINDOWS\system32\hcwhrkkn.dll
2008-11-12 20:37 . 2008-11-12 20:37 85,504 --a------ C:\WINDOWS\system32\jefgoswj.dll
2008-11-12 19:31 . 2008-11-12 19:31 125,952 --a------ C:\WINDOWS\system32\xxmjsqxo.dll
2008-11-12 19:31 . 2008-11-12 19:31 125,952 --a------ C:\WINDOWS\system32\uzwdtm.dll
2008-11-12 19:28 . 2008-11-12 19:28 2,048 --a------ C:\WINDOWS\system32\mrbvdjhf.exe
2008-11-12 19:24 . 2008-11-12 19:25 1,557,387 ---hs---- C:\WINDOWS\system32\viexqpig.ini
2008-11-12 19:24 . 2008-11-12 19:24 76,800 --------- C:\WINDOWS\system32\gipqxeiv.dll
2008-11-11 09:06 . 2008-11-11 09:06 1,552,244 --ahs---- C:\WINDOWS\system32\idlebopr.ini
2008-11-11 09:00 . 2008-11-11 09:00 85,504 --a------ C:\WINDOWS\system32\avkrokwp.dll
2008-11-11 09:00 . 2008-11-15 21:54 345 --ahs---- C:\WINDOWS\system32\xayaGfhk.ini2
2008-11-11 09:00 . 2008-11-15 21:54 345 --ahs---- C:\WINDOWS\system32\xayaGfhk.ini
2008-11-10 20:59 . 2008-11-10 20:59 85,504 --a------ C:\WINDOWS\system32\rlweuijo.dll
2008-11-10 18:52 . 2008-11-10 18:52 <DIR> d-------- C:\Documents and Settings\Mama\Application Data\ScanSoft
2008-11-10 18:18 . 2008-11-10 18:18 <DIR> d-------- C:\Documents and Settings\Mama\Application Data\Sony
2008-11-08 21:03 . 2008-11-08 21:03 1,905,517 --ahs---- C:\WINDOWS\system32\wxdeuwli.ini
2008-11-08 20:54 . 2008-11-10 22:30 345 --ahs---- C:\WINDOWS\system32\kUuCefii.ini
2008-11-08 15:51 . 2008-11-08 15:52 1,905,517 --ahs---- C:\WINDOWS\system32\teucsacr.ini
2008-11-07 22:18 . 2008-11-07 22:18 <DIR> d-------- C:\Program Files\Common Files\Gibinsoft Shared
2008-11-07 21:39 . 2008-11-07 22:18 <DIR> d-------- C:\Program Files\GiPo@Utilities
2008-11-07 21:38 . 2008-11-07 21:38 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-11-07 21:38 . 2008-11-08 16:13 757,823 --ahs---- C:\WINDOWS\system32\EdNqqXyb.ini2
2008-11-07 10:19 . 2008-11-07 21:29 396 --ahs---- C:\WINDOWS\system32\jklmoUvw.ini2
2008-11-07 10:19 . 2008-11-07 21:28 396 --ahs---- C:\WINDOWS\system32\jklmoUvw.ini
2008-11-06 21:41 . 2008-11-06 20:29 61,440 --a------ C:\WINDOWS\system32\flcss.exe
2008-11-06 11:11 . 2008-11-06 11:11 1,882,530 --ahs---- C:\WINDOWS\system32\wnnvrnul.ini
2008-11-06 11:07 . 2008-11-06 11:07 132,096 --a------ C:\WINDOWS\system32\xtkkvt.dll
2008-11-06 11:07 . 2008-11-06 11:07 132,096 --a------ C:\WINDOWS\system32\pekusxha.dll
2008-11-06 11:05 . 2008-11-06 11:05 85,504 --a------ C:\WINDOWS\system32\tidcxytu.dll
2008-11-06 11:04 . 2008-11-06 22:04 345 --ahs---- C:\WINDOWS\system32\BIihkUtv.ini2
2008-11-06 11:04 . 2008-11-06 22:04 345 --ahs---- C:\WINDOWS\system32\BIihkUtv.ini
2008-11-05 17:41 . 2008-11-05 17:41 133,120 --a------ C:\WINDOWS\system32\ginjsakm.dll
2008-11-05 17:41 . 2008-11-05 17:41 133,120 --a------ C:\WINDOWS\system32\bqltjx.dll
2008-11-05 17:39 . 2008-11-05 17:39 1,890,737 --ahs---- C:\WINDOWS\system32\hfgoqufv.ini
2008-11-05 12:00 . 2008-11-11 08:48 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-11-05 11:59 . 2008-11-10 22:43 <DIR> d-------- C:\Program Files\Norton Security Scan
2008-11-05 11:17 . 2008-11-05 11:17 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\EAST Technologies
2008-11-05 10:58 . 2008-11-05 10:58 133,120 --a------ C:\WINDOWS\system32\gzxcrc.dll
2008-11-05 10:57 . 2008-11-05 10:58 133,120 --a------ C:\WINDOWS\system32\plrtnfbj.dll
2008-11-05 10:56 . 2008-11-05 10:56 1,880,564 --ahs---- C:\WINDOWS\system32\mimruxxe.ini
2008-11-05 02:17 . 2008-11-05 02:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\EAST Technologies
2008-11-05 02:03 . 2008-11-05 02:03 132,608 --a------ C:\WINDOWS\system32\nhlceiuu.dll
2008-11-05 02:03 . 2008-11-05 02:03 132,608 --a------ C:\WINDOWS\system32\gcggwv.dll
2008-11-05 02:01 . 2008-11-05 02:01 1,880,308 --ahs---- C:\WINDOWS\system32\jfllttwq.ini
2008-11-05 02:01 . 2008-11-05 02:01 75,392 --a------ C:\WINDOWS\system32\qwttllfj.dll
2008-11-05 01:37 . 2008-11-05 01:38 1,880,308 --ahs---- C:\WINDOWS\system32\inscqhoo.ini
2008-11-05 01:37 . 2008-11-05 01:37 132,608 --a------ C:\WINDOWS\system32\mrepynew.dll
2008-11-05 01:37 . 2008-11-05 01:37 132,608 --a------ C:\WINDOWS\system32\mogqad.dll
2008-11-04 19:43 . 2008-11-04 19:43 1,880,308 --ahs---- C:\WINDOWS\system32\hsdvujma.ini
2008-11-04 19:41 . 2008-11-04 19:41 132,608 --a------ C:\WINDOWS\system32\uzfpwc.dll
2008-11-04 19:40 . 2008-11-04 19:41 132,608 --a------ C:\WINDOWS\system32\ejxwsbkv.dll
2008-11-04 12:57 . 2008-11-04 12:57 1,871,805 --ahs---- C:\WINDOWS\system32\aclofpns.ini
2008-11-04 12:57 . 2008-11-04 12:57 132,608 --a------ C:\WINDOWS\system32\wbrdyfvm.dll
2008-11-04 12:57 . 2008-11-04 12:57 132,608 --a------ C:\WINDOWS\system32\srritk.dll
2008-11-04 12:26 . 2008-11-04 12:26 1,871,805 --ahs---- C:\WINDOWS\system32\kgauseek.ini
2008-11-04 12:26 . 2008-11-04 12:26 132,608 --a------ C:\WINDOWS\system32\dudsvith.dll
2008-11-04 12:26 . 2008-11-04 12:26 132,608 --a------ C:\WINDOWS\system32\dpgcuw.dll
2008-11-04 11:50 . 2008-11-05 18:39 345 --ahs---- C:\WINDOWS\system32\Gilllnmp.ini2
2008-11-04 11:50 . 2008-11-05 18:39 345 --ahs---- C:\WINDOWS\system32\Gilllnmp.ini
2008-11-04 11:45 . 2008-11-04 11:45 40,960 --a------ C:\WINDOWS\system32\iiffDWOg.dll
2008-11-04 11:36 . 2007-04-27 17:54 40,960 --a------ C:\WINDOWS\exitwx.exe
2008-11-03 21:08 . 2008-11-03 21:08 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Publish Providers
2008-11-03 20:50 . 2008-11-03 20:50 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Sony
2008-11-03 20:46 . 2008-11-03 20:46 <DIR> d-------- C:\Program Files\Vstplugins
2008-11-03 20:44 . 2008-11-03 20:44 <DIR> d-------- C:\Program Files\Sony Setup
2008-11-02 21:22 . 2008-11-02 21:22 <DIR> d-------- C:\Program Files\Jfuse
2008-11-02 12:59 . 2008-11-02 12:59 <DIR> d-------- C:\Documents and Settings\Mama\Application Data\Corel
2008-11-02 12:37 . 2008-11-02 12:37 <DIR> d-------- C:\Documents and Settings\Mama\Application Data\iolo
2008-11-02 12:18 . 1996-09-06 08:02 960,000 --a------ C:\WINDOWS\system32\evysh7.dll
2008-11-02 12:17 . 1996-12-10 12:21 39,095 --------- C:\WINDOWS\iccsigs.dat
2008-11-02 12:16 . 1998-04-15 09:07 218,112 --a------ C:\WINDOWS\system32\scint80.dll
2008-11-02 12:16 . 1996-09-06 08:02 90,112 --a------ C:\WINDOWS\system32\evysh7us.dll
2008-11-02 12:15 . 2008-11-02 12:15 <DIR> d-------- C:\WINDOWS\Profiles
2008-11-02 12:15 . 2008-11-02 12:15 <DIR> d-------- C:\WINDOWS\Favorites
2008-11-02 12:15 . 2008-11-02 12:15 <DIR> d-------- C:\Corel
2008-11-02 12:10 . 2008-11-02 12:10 <DIR> d-------- C:\Documents and Settings\Mama\Application Data\TuneUp Software
2008-10-31 17:37 . 2008-10-31 19:17 <DIR> d-------- C:\_$Temp
2008-10-30 21:33 . 2008-10-30 21:34 124,790,784 -r-h----- C:\WINDOWS\dcdisk0_0
2008-10-30 21:33 . 2008-10-30 21:33 4,204,544 -r-h----- C:\WINDOWS\dclog.bin
2008-10-30 21:33 . 2008-10-30 21:33 0 --a------ C:\WINDOWS\dclock.dc
2008-10-30 21:32 . 2008-11-04 11:37 <DIR> d-------- C:\Program Files\FarStone
2008-10-30 20:40 . 2008-10-30 20:41 <DIR> d-------- C:\Program Files\R-Drive Image
2008-10-30 20:29 . 2008-10-30 20:29 <DIR> d-------- C:\Program Files\Runtime Software
2008-10-29 20:48 . 2008-10-29 20:48 <DIR> d-------- C:\Program Files\Avanquest update
2008-10-29 20:48 . 2008-10-29 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-10-29 20:43 . 2008-06-04 06:34 122,024 --a------ C:\WINDOWS\system32\drivers\s1018mdm.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 19:44 7,322,144 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-11-19 19:44 58,284 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-11-19 19:44 4,972 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-11-19 19:44 1,138,720 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-11-19 19:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-11-18 15:19 --------- d-----w C:\Program Files\Pirate Poppers
2008-11-18 15:19 --------- d-----w C:\Documents and Settings\Owner\Application Data\PlayFirst
2008-11-17 21:37 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-11-12 22:45 --------- d-----w C:\Documents and Settings\Owner\Application Data\DNA
2008-11-12 21:44 --------- d-----w C:\Program Files\DNA
2008-11-07 20:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-05 20:34 --------- d-----w C:\Documents and Settings\MIMI\Application Data\ICQ
2008-11-05 20:33 --------- d-----w C:\Documents and Settings\Mama\Application Data\ICQ
2008-11-05 11:42 --------- d-----w C:\Documents and Settings\Owner\Application Data\EAST Technologies
2008-11-05 10:10 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-11-05 02:56 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-11-05 02:56 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-11-04 12:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-11-04 11:10 --------- d-----w C:\Program Files\NCH Software
2008-11-04 10:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2008-11-04 10:35 --------- d-----w C:\Program Files\SlySoft
2008-11-02 12:55 --------- d-----w C:\Documents and Settings\Mama\Application Data\Skype
2008-11-02 12:43 --------- d-----w C:\Documents and Settings\Mama\Application Data\skypePM
2008-11-01 10:50 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-11-01 10:32 --------- d-----w C:\Documents and Settings\Owner\Application Data\Skype
2008-11-01 10:27 --------- d-----w C:\Documents and Settings\Owner\Application Data\skypePM
2008-10-31 20:42 --------- d-----w C:\Program Files\ICQToolbar
2008-10-27 20:00 --------- d-----w C:\Documents and Settings\Owner\Application Data\XnView
2008-10-19 14:00 --------- d-----w C:\Program Files\Desktop Clock
2008-10-19 13:16 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-10-19 13:15 --------- d-----w C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
2008-10-17 21:21 --------- d-----w C:\Program Files\MagicISO
2008-10-17 14:27 --------- d-----w C:\Program Files\MAGIX
2008-10-17 13:42 352,050 ----a-w C:\Documents and Settings\Owner\griffith_backup.zip
2008-10-17 13:42 --------- d-----w C:\Documents and Settings\Owner\Application Data\gtk-2.0
2008-10-17 13:41 --------- d-----w C:\Documents and Settings\Owner\Application Data\griffith
2008-10-11 18:18 --------- d-----w C:\Documents and Settings\MIMI\Application Data\ICQ Toolbar
2008-10-07 22:06 --------- d-----w C:\Program Files\Realtek AC97
2008-10-07 21:35 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-10-07 21:35 --------- d-----w C:\Program Files\Common Files\NVIDIA Shared
2008-10-07 20:57 --------- d-----w C:\Program Files\Driver-Soft
2008-10-07 20:37 --------- d-----w C:\Program Files\Network Stumbler
2008-10-07 09:23 --------- d-----w C:\Program Files\iTunes
2008-10-07 09:23 --------- d-----w C:\Program Files\iPod
2008-10-07 09:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-06 18:33 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-06 18:32 --------- d-----w C:\Program Files\Common Files\Real
2008-10-05 09:42 --------- d-----w C:\Program Files\Skype
2008-10-04 14:48 --------- d-----w C:\Documents and Settings\MIMI\Application Data\iolo
2008-10-01 07:55 --------- d-----w C:\Documents and Settings\LocalService\Application Data\iolo
2008-09-30 18:08 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
2008-09-30 14:04 --------- d-----w C:\Documents and Settings\Owner\Application Data\iolo
2008-09-30 14:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2008-09-30 13:35 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2008-09-30 13:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
2008-09-30 13:34 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
2008-09-30 13:34 368,480 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
2008-09-30 13:34 132,224 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
2008-09-30 13:34 --------- d-----w C:\Program Files\Common Files\Acronis
2008-09-30 13:14 --------- d-----w C:\Program Files\CityMedia Player
2008-09-30 12:46 --------- d-----w C:\Documents and Settings\Owner\Application Data\Ahead
2008-09-29 16:11 --------- d-----w C:\Documents and Settings\MIMI\Application Data\PlayFirst
2008-09-26 17:49 --------- d-----w C:\Program Files\Text Express 2
2008-09-26 17:39 --------- d-----w C:\Documents and Settings\Owner\Application Data\SpinTop
2008-09-26 00:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-09-26 00:21 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-26 00:19 --------- d-----w C:\Program Files\Nero
2008-09-25 23:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-09-25 22:49 --------- d-----w C:\Program Files\Unlocker
2008-09-25 22:48 --------- d-----w C:\Documents and Settings\Owner\Application Data\Desktopicon
2008-09-25 19:45 --------- d-----w C:\Program Files\Zylom Games
2008-09-24 17:16 --------- d-----w C:\Documents and Settings\Owner\Application Data\Zylom
2008-09-23 20:54 --------- d-----w C:\Documents and Settings\Owner\Application Data\dvdcss
2008-09-23 20:06 --------- d-----w C:\Program Files\Software Informer
2008-09-23 12:59 --------- d-----w C:\Program Files\QuickTime
2008-09-23 12:58 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-23 12:42 --------- d-----w C:\Program Files\Apple Software Update
2008-09-22 20:48 --------- d-----w C:\Program Files\Paragon Software
2008-09-22 20:44 74,703 ----a-w C:\WINDOWS\system32\mfc45.dll
2008-09-22 20:26 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-09-22 15:34 --------- d-----w C:\Program Files\Tumblebugs 2
2008-09-21 22:37 --------- d-----w C:\Program Files\LimeWire
2008-09-21 16:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Eyeblaster
2008-08-21 02:19 425,984 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-08-21 02:18 314,880 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-08-21 02:08 184,320 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-08-21 02:08 143,360 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-08-21 02:07 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-08-21 02:07 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-08-21 02:07 143,360 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-08-21 02:05 573,440 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-08-21 02:04 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-08-21 02:01 10,084,352 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-08-21 01:55 4,094,560 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-08-21 01:50 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-08-21 01:38 2,377,856 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-08-21 01:23 48,640 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-08-21 01:19 380,928 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-08-21 01:18 37,376 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-08-21 01:18 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CAB59B4-55A3-4737-9FD5-B93C6430BF76}]
2008-11-12 23:20 85504 --a------ C:\WINDOWS\system32\bjvaaqjm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75b7b954-ec69-4c08-853c-ec9152a541a3}]
2008-11-18 18:48 125952 --a------ C:\WINDOWS\system32\xplkax.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96E74E0B-9143-4D55-B522-35112296956A}]
2008-11-04 11:45 40960 --a------ C:\WINDOWS\system32\iiffDWOg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7DB46DF-D5F2-4818-88DA-24EBD8A4DDA4}]
2008-11-16 10:39 322560 --------- C:\WINDOWS\system32\xxyawxUO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Gadwin PrintScreen"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Moo0 SystemMonitor 1.18.lnk - C:\Program Files\Moo0\SystemMonitor 1.18\SystemMonitor.exe [2008-10-19 1323008]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{96E74E0B-9143-4D55-B522-35112296956A}"= "C:\WINDOWS\system32\iiffDWOg.dll" [2008-11-04 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffDWOg]
2008-11-04 11:45 40960 C:\WINDOWS\system32\iiffDWOg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll,avgrsstx.dll xplkax.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap C:\WINDOWS\system32\xxyawxUO
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Corel MEDIA FOLDERS INDEXER 8.LNK]
backup=C:\WINDOWS\pss\Corel MEDIA FOLDERS INDEXER 8.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^UDPixel.lnk]
backup=C:\WINDOWS\pss\UDPixel.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\East-Tec Backup 2007
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Miro
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmcService
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\903c1117]
--------- 2008-11-12 19:24 76800 C:\WINDOWS\system32\gipqxeiv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2008-04-09 19:14 136472 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2008-01-11 21:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-11-04 10:36 2259904 C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
--a------ 2007-10-04 17:38 307200 C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-09-13 10:12 139264 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-11-12 20:51 342336 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
--------- 2007-03-12 13:51 663552 C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
--------- 2007-01-26 14:58 65536 C:\Program Files\Brother\ControlCenter3\BrCtrCen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
--a--c--- 2007-07-11 15:09 20480 C:\WINDOWS\FixCamera.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a--c--- 2007-01-29 20:10 46632 C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVMixerTray]
--a------ 2004-12-20 16:12 131072 C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2007-01-29 20:12 30248 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
--a------ 2005-11-16 15:14 344064 C:\WINDOWS\vsnp2std.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd3]
--a------ 2006-09-19 08:07 827392 C:\WINDOWS\vsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
--a------ 2008-07-02 16:16 393216 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
--a--c--- 2006-10-25 08:03 210472 C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2008-06-10 03:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-06 18:30 185872 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayServer]
--a------ 2008-02-07 11:00 90112 C:\Program Files\MAGIX\Movie_Edit_Pro_14_PLUS_Download_version\Trayserver.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
--a--c--- 2005-11-14 17:47 110592 C:\WINDOWS\tsnp2std.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
--a------ 2007-04-21 08:37 270336 C:\WINDOWS\tsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-10-18 19:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2004-08-04 12:00 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2005-05-03 18:38 64512 C:\WINDOWS\system32\P17.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TryAndDecideService"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
R0 hotcore3;hotcore3;C:\WINDOWS\system32\drivers\hotcore3.sys [2008-07-09 40368]
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R0 si3112r;si3112r;C:\WINDOWS\system32\drivers\si3112r.sys [2004-05-12 97408]
R0 SiWinAcc;SiWinAcc;C:\WINDOWS\system32\drivers\SiWinAcc.sys [2007-06-28 19240]
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-09-30 368480]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S2 ousbehci;OrangeWare USB Enhanced Host Controller Service;C:\WINDOWS\system32\Drivers\ousbehci.sys [2006-03-01 46080]
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2006-03-01 56960]
S3 R-ImageDisk;R-ImageDisk;C:\Program Files\R-Drive Image\R-ImageDisk.sys [2008-08-07 126551]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);C:\WINDOWS\system32\DRIVERS\s1018bus.sys [2008-06-04 90408]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s1018mdfl.sys [2008-06-04 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s1018mdm.sys [2008-06-04 122024]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s1018mgmt.sys [2008-06-04 115368]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);C:\WINDOWS\system32\DRIVERS\s1018nd5.sys [2008-06-04 25768]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s1018obex.sys [2008-06-04 111784]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);C:\WINDOWS\system32\DRIVERS\s1018unic.sys [2008-06-04 117544]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2005-11-18 10192896]
S4 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-10 521568]
.
Contents of the 'Scheduled Tasks' folder
2008-11-14 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-08-02 18:35]
2008-11-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
BHO-{26730C68-CF36-4353-A48B-EAA90D1C93E9} - (no file)
Toolbar-{7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
WebBrowser-{7C5C0F58-E061-457D-9033-77307F5ED00C} - (no file)
MSConfigStartUp-AVG8_TRAY - C:\PROGRA~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-Eraser RiskMonitor - C:\Program Files\East-Tec Eraser 2008\Launch.exe
MSConfigStartUp-TrueImageMonitor - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\e1ppiozp.default\
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-19 19:47:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\iiffDWOg.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\xxyawxUO.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\xxyawxUO.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-11-19 19:53:54 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-11-19 19:53:45
Pre-Run: 191,976,685,568 bytes free
Post-Run: 193,383,092,224 bytes free
453
|