offline
- dragannn
- Građanin
- Pridružio: 26 Dec 2007
- Poruke: 97
|
Napisano: 28 Dec 2009 2:18
ComboFix 09-12-26.05 - dragan 12/28/2009 1:49.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1527.911 [GMT 1:00]
Running from: c:\documents and settings\dragan\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091227-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\desktop.ini
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\recycler\S-1-5-21-1021014418-0590927759-270325044-3174
c:\recycler\S-1-5-21-3404941617-8258411286-255512666-4089
c:\recycler\S-1-5-21-4608540425-3293630619-475748746-9565
c:\recycler\S-1-5-21-6880283687-1465265892-459987151-5026
c:\recycler\S-1-5-21-7849976882-6472749022-611194407-1219
c:\recycler\S-1-5-21-8365874735-6851995393-907373698-2981
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-28 )))))))))))))))))))))))))))))))
.
2009-12-23 13:55 . 2009-12-23 13:55 -------- d-sh--w- c:\documents and settings\dragan\IECompatCache
2009-12-20 14:09 . 2009-12-20 14:09 -------- d-----w- c:\program files\EA SPORTS
2009-12-15 14:08 . 2009-12-15 14:08 -------- d-----w- c:\program files\Pocket Tanks Deluxe
2009-12-12 22:16 . 2009-12-12 22:16 -------- d-----r- C:\AHCache
2009-12-10 23:01 . 2009-12-10 23:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-12-08 15:34 . 2009-12-08 15:34 -------- d-----w- c:\documents and settings\dragan\Application Data\Real Desktop
2009-12-08 15:33 . 2009-12-08 15:33 -------- d-----w- c:\program files\Real Desktop
2009-12-08 15:29 . 2009-12-08 15:29 -------- d-----w- c:\documents and settings\dragan\Application Data\Locktime
2009-12-08 15:10 . 2009-12-08 15:10 -------- d-----w- c:\program files\Opera
2009-12-08 15:06 . 2009-12-08 15:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Locktime
2009-12-08 15:06 . 2009-12-08 15:06 -------- d-----w- c:\program files\NetLimiter 2 Monitor
2009-12-06 09:58 . 2009-12-06 09:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Systweak
2009-12-06 09:57 . 2009-12-06 09:57 -------- d-----w- c:\documents and settings\dragan\Application Data\Systweak
2009-12-06 09:56 . 2009-12-06 09:56 -------- d-----w- c:\documents and settings\All Users\Application Data\MyDefrag
2009-12-06 09:56 . 2009-08-19 15:49 17136 ----a-w- c:\windows\system32\sasnative32.exe
2009-12-06 09:56 . 2009-12-06 09:58 -------- d-----w- c:\program files\Advanced System Optimizer 3
2009-12-06 09:41 . 2009-12-06 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2009-12-06 09:41 . 2009-12-06 09:41 -------- d-----w- c:\program files\NCH Software
2009-12-06 01:12 . 2009-10-08 06:24 352256 ----a-w- c:\windows\vncutil.exe
2009-12-06 01:12 . 2009-10-23 10:53 41984 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2009-12-06 01:12 . 2009-03-17 06:07 122880 ----a-w- c:\windows\RtkAudioService.exe
2009-12-06 01:12 . 2006-01-04 07:41 1389056 ----a-w- c:\windows\system32\drivers\Monfilt.sys
2009-12-06 01:12 . 2008-08-05 12:10 1684736 ----a-w- c:\windows\system32\drivers\Ambfilt.sys
2009-12-06 01:12 . 2009-12-06 01:12 -------- d-----w- c:\program files\Realtek
2009-12-06 01:12 . 2009-11-02 05:48 831488 ----a-w- c:\windows\RtlExUpd.dll
2009-12-04 21:37 . 2009-12-04 21:37 -------- d-----w- c:\documents and settings\dragan\Local Settings\Application Data\ATI
2009-12-04 21:37 . 2009-12-04 21:37 -------- d-----w- c:\documents and settings\dragan\Application Data\ATI
2009-12-04 21:37 . 2009-12-04 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2009-12-04 21:36 . 2009-12-04 21:36 0 ----a-w- c:\windows\ativpsrm.bin
2009-12-04 21:31 . 2009-12-04 21:31 -------- d-----w- C:\ATI
2009-12-01 20:32 . 2009-12-01 20:32 -------- d-----w- c:\program files\Activision
2009-11-28 22:45 . 2009-12-04 21:27 -------- d-----w- c:\program files\THQ
2009-11-28 19:10 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-28 19:10 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-28 19:10 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-28 19:10 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-28 19:10 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-28 19:10 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-28 19:10 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-28 00:45 . 2009-11-26 23:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-25 18:22 . 2009-06-03 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-25 16:28 . 2009-08-30 22:12 -------- d-----w- c:\documents and settings\dragan\Application Data\AIMP
2009-12-25 16:24 . 2009-08-31 10:03 -------- d-----w- c:\program files\Opera 10 Beta
2009-12-15 16:44 . 2009-06-18 14:47 -------- d-----w- c:\documents and settings\dragan\Application Data\DAEMON Tools Lite
2009-12-15 16:42 . 2009-06-18 14:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-15 15:21 . 2009-06-18 14:47 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-12-15 15:21 . 2009-05-04 10:08 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-15 15:20 . 2009-06-18 14:47 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-12-08 15:14 . 2009-07-25 13:39 -------- d-----w- c:\documents and settings\dragan\Application Data\Winamp
2009-12-08 15:12 . 2009-07-25 13:39 -------- d-----w- c:\program files\Winamp
2009-12-06 16:58 . 2009-05-04 10:06 -------- d-----w- c:\program files\AIMP2
2009-12-06 10:00 . 2009-08-31 09:36 -------- d-----w- c:\documents and settings\dragan\Application Data\FreshDiagnose
2009-12-06 01:12 . 2009-05-04 01:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-04 21:35 . 2009-05-04 01:18 -------- d-----w- c:\program files\ATI Technologies
2009-12-02 22:26 . 2009-11-22 22:42 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-02 16:24 . 2009-05-09 15:27 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-28 19:58 . 2009-06-05 15:33 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-11-26 23:47 . 2009-05-04 01:14 -------- d-----w- c:\program files\QuickTime Alternative
2009-11-26 23:47 . 2009-11-26 23:47 -------- d-----w- c:\program files\Common Files\Apple
2009-11-26 23:47 . 2009-11-26 23:47 -------- d-----w- c:\program files\Apple Software Update
2009-11-26 23:47 . 2009-11-26 23:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-11-26 23:30 . 2009-11-26 23:28 -------- d-----w- c:\program files\DAP
2009-11-26 23:29 . 2009-11-26 23:29 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-11-26 23:29 . 2009-11-26 23:29 50688 ----a-w- c:\windows\system32\wbhelp2.dll
2009-11-24 23:54 . 2009-05-04 09:39 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-05-04 09:40 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-05-04 09:40 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-05-04 09:40 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-05-04 09:40 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-05-04 09:40 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-05-04 09:40 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-05-04 09:40 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-05-04 09:40 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-22 22:43 . 2009-11-22 22:43 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-22 16:53 . 2009-10-10 11:33 -------- d-----w- c:\documents and settings\dragan\Application Data\IObit
2009-11-21 09:22 . 2009-09-29 14:35 -------- d-----w- c:\program files\Google
2009-11-21 06:41 . 2009-11-21 06:41 -------- d-----w- c:\program files\Lavalys
2009-11-21 06:03 . 2009-11-21 06:01 -------- d-----w- c:\documents and settings\dragan\Application Data\WeatherPulse
2009-11-14 08:15 . 2009-08-30 22:23 -------- d-----w- c:\program files\Codebox
2009-11-14 07:22 . 2009-05-21 19:03 -------- d-----w- c:\program files\Ubisoft
2009-11-08 16:30 . 2009-05-09 15:27 -------- d-----w- c:\documents and settings\dragan\Application Data\InstallShield
2009-11-03 11:39 . 2009-05-04 01:23 5940736 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-11-02 10:53 . 2009-05-04 01:23 18782720 ----a-w- c:\windows\RTHDCPL.EXE
2009-10-30 11:10 . 2009-10-30 11:10 1183176 ----a-w- c:\documents and settings\dragan\Application Data\Mozilla\Firefox\Profiles\ba8vjz76.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
2009-10-24 12:56 . 2009-09-06 19:09 418480 -c--a-w- c:\windows\system32\wrap_oal.dll
2009-10-24 12:56 . 2009-09-06 19:09 115432 -c--a-w- c:\windows\system32\OpenAL32.dll
2009-10-06 17:40 . 2009-10-06 17:40 139152 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-06 17:40 . 2009-10-06 17:40 139152 -c--a-w- c:\documents and settings\dragan\Application Data\PnkBstrK.sys
2009-10-06 17:40 . 2009-10-06 17:40 139152 -c--a-w- c:\documents and settings\dragan\Application Data\PnkBstrK.sys
2009-10-06 17:39 . 2009-10-06 17:39 111928 -c--a-w- c:\windows\system32\PnkBstrB.exe
2009-10-06 17:39 . 2009-10-06 17:39 794408 -c--a-w- c:\windows\system32\pbsvc.exe
2009-10-06 17:39 . 2009-10-06 17:39 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-09-30 04:18 . 2009-05-04 01:57 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2009-09-30 02:20 . 2007-08-22 02:09 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-09-30 02:19 . 2009-05-04 01:56 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2009-09-30 02:10 . 2009-05-04 01:57 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2009-09-30 02:10 . 2009-05-04 01:57 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2009-09-30 02:10 . 2009-05-04 01:57 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2009-09-30 02:10 . 2009-05-04 01:56 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-09-30 02:10 . 2009-05-04 01:56 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2009-09-30 02:08 . 2009-05-04 01:57 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2009-09-30 02:08 . 2009-05-04 01:56 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2009-09-30 02:07 . 2009-05-04 01:56 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2009-09-30 02:07 . 2009-05-04 01:56 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2009-09-30 02:00 . 2009-05-04 01:56 3818272 ----a-w- c:\windows\system32\ati3duag.dll
2009-09-30 01:47 . 2009-05-04 01:57 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2009-09-30 01:46 . 2007-08-22 01:35 887724 ----a-w- c:\windows\system32\ativva6x.dat
2009-09-30 01:34 . 2009-09-30 01:34 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2009-09-30 01:30 . 2009-05-04 01:56 475136 ----a-w- c:\windows\system32\atikvmag.dll
2009-09-30 01:28 . 2009-09-30 01:28 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2009-09-30 01:28 . 2009-05-04 01:57 17408 ----a-w- c:\windows\system32\atitvo32.dll
2009-09-30 01:27 . 2009-05-04 01:56 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-09-30 01:27 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalrt.dll
2009-09-30 01:27 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalcl.dll
2009-09-30 01:26 . 2007-08-22 01:15 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2009-09-30 01:26 . 2009-09-30 01:26 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2009-09-30 01:22 . 2009-05-04 01:56 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2009-09-29 20:15 . 2009-05-11 11:01 593920 ------w- c:\windows\system32\ati2sgag.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-10-28 344064]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"RTHDCPL"="RTHDCPL.EXE" [2009-11-02 18782720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-13 44544]
c:\documents and settings\dragan\Start Menu\Programs\Startup\
Pravoslavac 2009.lnk - c:\program files\Pravoslavac\Pravoslavac.exe [2009-5-4 1547746]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Splinter Cell Double Agent\\SCDA-Offline\\System\\SplinterCell4.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Activision\\Modern Warfare 2\\iw4mp.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/4/2009 10:40 AM 114768]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [4/23/2007 5:08 PM 81688]
R2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\Advanced System Optimizer 3\ASO3DefragSrv.exe [12/6/2009 10:56 AM 201960]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/4/2009 10:40 AM 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [10/9/2009 11:07 PM 54752]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/4/2009 11:08 AM 691696]
S2 gupdate1ca6a72d33c7090;Google Update Service (gupdate1ca6a72d33c7090);c:\program files\Google\Update\GoogleUpdate.exe [11/21/2009 7:21 AM 133104]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe --> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe --> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [12/6/2009 2:12 AM 1684736]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
.
------- Supplementary Scan -------
.
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath - c:\documents and settings\dragan\Application Data\Mozilla\Firefox\Profiles\ba8vjz76.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-msnsc - c:\windows\system32\msnsc.exe
AddRemove-LifeGlobe Sharks, Terrors of the Deep_is1 - c:\program files\Prolific Publishing
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-12-28 01:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-448539723-796845957-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7e,d4,ce,4a,0b,01,a2,46,ee,69,8d,96,34,0b,65,6d,fb,29,52,36,f9,83,47,
4e,8a,74,01,68,02,d9,c8,77,32,f4,a7,bd,da,36,bf,02,ca,31,e0,45,ec,c1,39,97,\
"??"=hex:8a,e2,b0,b3,90,b9,b2,59,df,4c,b4,5f,ea,17,d5,b7
[HKEY_USERS\S-1-5-21-448539723-796845957-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:81,4a,29,81,cf,e5,aa,e0,14,9b,4b,1f,ff,9d,d7,37,4e,e6,15,40,5b,
55,13,57,28,82,68,c5,81,77,9e,f3,67,60,62,e7,cd,97,39,1d,5a,3c,89,ae,ef,e8,\
"rkeysecu"=hex:fb,05,da,b0,a2,1d,a6,52,e3,1e,94,ec,2a,54,19,2f
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768-)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-28 01:54:57
ComboFix-quarantined-files.txt 2009-12-28 00:54
Pre-Run: 38,906,216,448 bytes free
Post-Run: 38,869,495,808 bytes free
- - End Of File - - 38CD313E5DEF98CDA13B5CC8D942251D
Dopuna: 28 Dec 2009 16:09
pozz
sta dalje?
|