offline
- Pridružio: 07 Dec 2005
- Poruke: 4
|
ComboFix 08-08-29.02 - Dragan 2008-08-29 23:52:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.428 [GMT 2:00]
Running from: C:\Documents and Settings\Dragan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-29 )))))))))))))))))))))))))))))))
.
2008-08-29 15:38 . 2008-08-29 15:52 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-08-29 15:38 . 2008-08-29 15:52 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-08-29 15:36 . 2008-08-29 15:36 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-08-29 15:36 . 2008-08-29 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-29 15:36 . 2008-08-29 23:59 4,082,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-29 15:36 . 2008-08-29 23:59 434,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-29 15:36 . 2008-08-29 23:59 34,020 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-29 15:36 . 2008-08-29 23:59 3,612 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-29 14:55 . 2008-08-29 15:43 <DIR> d-------- C:\Documents and Settings\Dragan\DoctorWeb
2008-08-28 22:17 . 2008-08-28 22:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-28 22:16 . 2008-08-28 22:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sony Ericsson
2008-08-28 22:15 . 2008-08-28 22:15 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-28 15:14 . 2008-08-28 15:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-08-28 15:11 . 2008-08-28 15:11 <DIR> d-------- C:\Program Files\IVT Corporation
2008-08-28 15:07 . 2008-08-28 15:07 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-08-28 15:07 . 2008-08-28 15:07 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_btprot_01005.Wdf
2008-08-28 14:25 . 2008-02-27 02:41 <DIR> d-------- C:\Temp\USBThief
2008-08-21 18:57 . 2008-08-21 18:57 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2008-08-19 16:21 . 2003-06-19 00:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-08-19 16:19 . 2008-08-19 16:20 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-08-19 16:19 . 2008-08-19 16:19 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-08-19 16:16 . 2008-08-19 16:16 <DIR> dr-h----- C:\MSOCache
2008-08-19 12:44 . 2008-04-14 05:42 151,552 --a------ C:\WINDOWS\system32\irftp.exe
2008-08-19 12:44 . 2008-04-14 05:42 151,552 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2008-08-19 12:44 . 2008-04-14 05:41 28,160 --a------ C:\WINDOWS\system32\irmon.dll
2008-08-19 12:44 . 2008-04-14 05:41 28,160 --a--c--- C:\WINDOWS\system32\dllcache\irmon.dll
2008-08-19 12:44 . 2008-04-14 05:42 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-08-19 12:44 . 2008-04-14 05:42 8,192 --a--c--- C:\WINDOWS\system32\dllcache\wshirda.dll
2008-08-06 21:15 . 2008-04-14 05:41 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-08-06 21:15 . 2008-04-14 05:41 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-08-06 21:15 . 2008-04-14 00:09 14,592 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-08-06 21:15 . 2008-04-14 00:09 14,592 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-08-03 07:34 . 2008-08-03 07:34 <DIR> d-------- C:\Documents and Settings\Dragan\Application Data\zweitgeist
2008-08-02 10:22 . 2008-08-02 10:22 453,120 --a------ C:\WINDOWS\system32\drivers\btprot.sys
2008-07-30 21:27 . 2008-07-30 21:27 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-07-30 21:20 . 2008-06-13 13:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-30 21:19 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-07-30 21:19 . 2007-03-08 07:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-07-30 21:19 . 2008-04-23 06:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-07-30 21:19 . 2008-04-23 06:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-07-30 21:19 . 2008-04-23 06:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-07-30 21:19 . 2008-04-23 06:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-07-30 21:19 . 2008-04-23 06:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-07-30 21:19 . 2008-04-22 09:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-07-30 21:18 . 2008-04-23 06:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-07-30 21:05 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-07-30 09:04 . 2008-07-30 09:04 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-07-30 09:04 . 2008-07-30 09:04 23,808 --a------ C:\WINDOWS\system32\drivers\btiausb.sys
2008-07-30 09:04 . 2008-07-30 09:04 10,240 --a------ C:\WINDOWS\system32\btiaci.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 21:48 --------- d-----w C:\Documents and Settings\Dragan\Application Data\Skype
2008-08-29 14:29 --------- d-----w C:\Documents and Settings\Dragan\Application Data\skypePM
2008-08-28 13:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-28 12:52 --------- d-----w C:\Documents and Settings\Dragan\Application Data\Thinstall
2008-08-25 06:51 --------- d-----w C:\Documents and Settings\Dragan\Application Data\uTorrent
2008-08-19 13:47 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-16 15:23 --------- d-----w C:\Documents and Settings\Dragan\Application Data\Winamp
2008-07-25 23:56 --------- d-----w C:\Program Files\Bonjour
2008-07-25 23:54 --------- d-----w C:\Program Files\Process Master
2008-07-25 23:46 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-07-25 23:46 --------- d-----w C:\Documents and Settings\Dragan\Application Data\Malwarebytes
2008-07-25 23:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-25 16:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-07-23 22:21 --------- d-----w C:\Program Files\MP3Gain
2008-07-23 18:09 38,472 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-23 18:09 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-07-05 07:00 --------- d-----w C:\Program Files\Uniblue
2008-07-05 07:00 --------- d-----w C:\Documents and Settings\Dragan\Application Data\Uniblue
2008-07-04 16:56 --------- d-----w C:\Documents and Settings\Dragan\Application Data\Samsung
2008-07-04 16:52 --------- d-----w C:\Program Files\Samsung
2008-06-28 06:03 --------- d-----w C:\Documents and Settings\Dragan\Application Data\HateML
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-02-21 18:57 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-21 05:50 56 --sha-r C:\WINDOWS\system32\C2E67EEC1F.sys
2008-03-21 05:50 10,856 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-28_ 8.47.34.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-16 12:23:44 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
+ 2008-01-29 16:29:38 32,784 ----a-w C:\WINDOWS\system32\drivers\klbg.sys
+ 2008-03-13 17:02:46 26,640 ----a-w C:\WINDOWS\system32\drivers\klfltdev.sys
+ 2008-08-29 13:52:36 187,920 ----a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2008-03-25 18:07:10 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
+ 2008-04-25 16:21:06 26,964 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
+ 2006-11-02 05:22:54 492,000 ------w C:\WINDOWS\system32\drivers\wdf01000.sys
+ 2006-11-02 05:22:52 32,224 ------w C:\WINDOWS\system32\drivers\wdfldr.sys
+ 2008-04-25 16:22:24 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
- 2008-08-19 15:41:36 72,350 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-28 13:08:23 72,350 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-19 15:41:36 444,766 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-28 13:08:23 444,766 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2006-10-16 15:10:58 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-10-08 19:51:14 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ACU"="C:\Program Files\WLAN\ACU.exe" [2006-01-05 17:47 303104]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 08:44 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 08:43 688218]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 14:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - C:\WINDOWS\Installer\{C91DE044-D900-4F15-BBD1-44FD9D59B277}\Icon3E5562ED7.ico [2008-08-21 18:58:04 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dragan^Start Menu^Programs^Startup^Stickies.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HEXelon MAX
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
--------- 2007-12-14 11:36 50472 C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
--------- 2008-03-20 20:23 83240 C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
--a------ 2005-03-04 14:13 32768 C:\WINDOWS\system32\Keyhook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
--a------ 2004-06-10 14:48 286720 C:\WINDOWS\vsnpstd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
--a------ 2007-06-13 08:16 528384 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-10-08 08:43 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-10-08 08:44 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue Registry Booster2]
--a------ 2007-04-13 11:51 1848864 C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2008-04-14 14:00 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
-ra------ 2005-02-25 13:35 49152 C:\WINDOWS\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-02-23 12:13 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Install\\Windows_Live_Messenger_8.1.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"4445:TCP"= 4445:TCP:Network LookOut Administrator Configuration
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]
R2 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;C:\WINDOWS\ZDCNDIS5.sys [2006-04-14 16:35]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
S3 AR5523;WLAN USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys [2006-01-05 17:56]
S3 BTIAUSB;Generic Bluetooth Device;C:\WINDOWS\system32\DRIVERS\btiausb.sys [2008-07-30 09:04]
S3 BTPROT;Generic Bluetooth Filter;C:\WINDOWS\system32\DRIVERS\btprot.sys [2008-08-02 10:22]
S3 G120(ZyXEL);ZyXEL G-120 IEEE 802.11g Wireless CardBus Adapter(ZyXEL);C:\WINDOWS\system32\DRIVERS\G120.sys [2006-07-20 13:40]
S3 IACtrl;IA Analysing v2.0;C:\Program Files\Pointdev\IDEAL Administration\IACtrl.exe [2001-01-03 12:37]
S3 ncvhook;ncvhook;C:\WINDOWS\system32\DRIVERS\ncvhook.sys [2007-09-30 17:54]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 09:33]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s125mdfl.sys [2007-04-24 09:33]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s125mdm.sys [2007-04-24 09:33]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s125mgmt.sys [2007-04-24 09:33]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s125obex.sys [2007-04-24 09:33]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\system32\DRIVERS\sea1bus.sys [2007-02-08 12:55]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys [2007-02-08 12:55]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\sea1mdm.sys [2007-02-08 12:55]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys [2007-02-08 12:56]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);C:\WINDOWS\system32\DRIVERS\sea1nd5.sys [2007-02-08 12:56]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\sea1obex.sys [2007-02-08 12:56]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);C:\WINDOWS\system32\DRIVERS\sea1unic.sys [2007-02-08 12:56]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 11:11]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 11:11]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 11:11]
S3 TEUSBMU;Panasonic Analog PBX USB Main Unit driver;C:\WINDOWS\system32\Drivers\TEUSBMU.sys [2005-01-14 15:36]
S4 NetworkLookOutAgent;Network LookOut Agent;C:\Program Files\Network LookOut Administrator Pro\bin\NLAgentProSvc.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 -: {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O16 -: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} - hxxp://appservers.it.telekom.rs/forms/jinitiator/jinit13113.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-08-30 00:00:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\acs.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-08-30 0:06:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-29 22:05:57
ComboFix2.txt 2008-08-28 06:48:26
Pre-Run: 17,030,217,728 bytes free
Post-Run: 17,042,579,456 bytes free
254
Dopuna: 30 Avg 2008 0:22
Danas sam posle zadnjeg kontakta instalirao KIS 2009 i skenirao racunar(nasao je boga oca virusa,spywera itd.).Naravno pre toga sam sledio Dr. Borina uputstva.Uglavnom ishod svega je da mi Lap Top sada radi normalno.Dr.Boro stvano si doktor,uz neizmernu zahvanost saljem veliki pozdrav
|