offline
- Pridružio: 04 Avg 2008
- Poruke: 37
|
Evo i novog loga:
ComboFix 09-02-12.03 - Media 2009-02-15 2:22:06.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.97 [GMT 1:00]
Running from: c:\documents and settings\Media\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Media\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: COMODO Firewall *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-01-15 to 2009-02-15 )))))))))))))))))))))))))))))))
.
2009-02-15 01:15 . 2009-02-15 01:15 677,888 -r-hs---- c:\windows\system32\drivers\NirCmd.exe
2009-02-14 23:40 . 2009-02-14 23:40 <DIR> d-------- c:\program files\Prevx
2009-02-14 23:40 . 2009-02-14 23:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-02-14 23:40 . 2009-02-14 23:40 21,512 --a------ c:\windows\system32\drivers\pxscan.sys
2009-02-14 23:40 . 2009-02-14 23:40 64 --a------ c:\windows\wininit.ini
2009-02-03 23:01 . 2009-02-10 23:59 54,156 --ah----- c:\windows\QTFont.qfn
2009-02-03 23:01 . 2009-02-03 23:01 1,409 --a------ c:\windows\QTFont.for
2009-02-01 22:58 . 2009-02-01 22:59 <DIR> d-------- c:\program files\MP3 CD Converter
2009-01-29 22:55 . 2009-01-29 22:55 <DIR> d-------- c:\documents and settings\Media\Application Data\SpinTop Games
2009-01-29 22:54 . 2009-01-29 22:54 <DIR> d-------- c:\windows\Mystery P I The New York Fortune
2009-01-27 20:34 . 2009-01-27 20:34 <DIR> d-------- c:\windows\Luxor Quest for the Afterlife
2009-01-27 20:34 . 2009-01-27 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\MumboJumbo
2009-01-25 21:46 . 2006-06-01 10:11 42,648 -ra------ c:\windows\system32\usbport.sys
2009-01-25 21:46 . 2006-06-01 10:11 21,155 -ra------ c:\windows\system32\ser2up.vxd
2009-01-25 21:33 . 2009-01-25 21:33 <DIR> d-------- c:\program files\Common Files\PCSuite
2009-01-25 21:32 . 2009-01-25 21:32 <DIR> d-------- c:\program files\Common Files\Nokia
2009-01-25 21:32 . 2006-07-17 02:53 30,368 -ra------ c:\windows\system32\drivers\usb2vcom.sys
2009-01-25 21:32 . 2008-08-26 09:26 18,816 --a------ c:\windows\system32\drivers\pccsmcfd.sys
2009-01-25 21:28 . 2009-01-25 21:28 <DIR> d-------- c:\program files\PC Connectivity Solution
2009-01-25 21:26 . 2009-01-25 21:32 <DIR> d-------- c:\program files\Nokia
2009-01-25 17:19 . 2009-01-25 17:19 <DIR> d-------- c:\windows\Chocolate Shop Frenzy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-15 00:15 359,040 ------w c:\windows\system32\drivers\tcpip.sys
2009-02-14 23:08 --------- d-----w c:\documents and settings\Media\Application Data\uTorrent
2009-02-14 12:53 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-12 00:36 --------- d-----w c:\program files\AIMP2
2009-02-10 21:49 --------- d-----w c:\documents and settings\Media\Application Data\Skype
2009-02-10 07:10 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-29 07:04 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-29 07:04 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-29 07:04 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2009-01-29 07:04 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-01-26 00:38 --------- d-----w c:\documents and settings\Media\Application Data\Nokia
2009-01-25 21:11 --------- d-----w c:\documents and settings\Media\Application Data\PC Suite
2009-01-25 21:11 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-01-25 20:26 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-01-12 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\DivoGames
2009-01-12 18:50 --------- d-----w c:\documents and settings\Media\Application Data\Fabulous Finds
2009-01-04 21:06 2,829 ----a-w c:\windows\War3Unin.pif
2009-01-04 21:06 139,264 ----a-w c:\windows\War3Unin.exe
2009-01-03 21:12 --------- d-----w c:\documents and settings\All Users\Application Data\PlayPond
2009-01-01 12:34 --------- d-----w c:\documents and settings\Media\Application Data\World-LooM
2008-12-21 22:47 --------- d-----w c:\documents and settings\Media\Application Data\Samsung
2008-12-21 22:41 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-21 22:41 --------- d-----w c:\program files\Samsung
2008-12-20 16:49 147,192 ----a-w c:\windows\system32\guard32.dll
2008-12-20 16:49 101,776 ----a-w c:\windows\system32\drivers\cmdguard.sys
2008-12-15 19:55 --------- d-----w c:\program files\Free MSN Emoticons Pack 1
2008-11-21 01:26 112 ----a-w C:\tw0001.dat
2007-01-23 11:46 312 ----a-w c:\documents and settings\Media\Application Data\bbbconfig.dat
2007-02-25 15:48 3,350 --sha-w c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\Media\Local Settings\temp ----
2009-02-15 02:11 31404 --a------ c:\documents and settings\Media\Local Settings\temp\pcsuitecheck_new.xml
2009-02-15 02:11 174 --a------ c:\documents and settings\Media\Local Settings\temp\addonscheck.xml
2009-02-15 02:11 1427 --a------ c:\documents and settings\Media\Local Settings\temp\flashgot.edbk3j11.default\FlashGot.exe.test
2009-02-15 02:10 61 --a------ c:\documents and settings\Media\Local Settings\temp\libFNP_events.log
2009-02-15 02:10 160428 -ra------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf
2009-02-15 02:10 160428 --a------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\qt_temp.Hp1696
2009-02-15 02:10 157296 -ra------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\Nokia Sans Wide Italic v3.1.ttf
2009-02-15 02:10 157296 --a------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\qt_temp.Uh1696
2009-02-15 02:10 156520 -ra------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\Nokia Sans Wide BolIta v3.1.ttf
2009-02-15 02:10 156520 --a------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\qt_temp.gq1696
2009-02-15 02:10 13946 --a------ c:\documents and settings\Media\Local Settings\temp\NGLALog.txt
2009-01-25 21:34 143840 --a------ c:\documents and settings\Media\Local Settings\temp\NGLATempNokia\Nokia Sans Wide v3.1.ttf
------- Sigcheck -------
2004-08-03 22:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\dllcache\tcpip.sys
2009-02-15 01:15 359040 3bb4b08619c111c7be8bda07aa0de6a2 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-15_ 1.31.16.85 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-15 01:10:28 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_820.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-10-04 163840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-29 1601304]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2008-08-07 278264]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2008-12-02 1797880]
"Acrobat Assistant 8.0"="d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2008-11-25 295606]
Adobe Acrobat Synchronizer.lnk - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-10-20 49220]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-29 08:04 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Watch.lnk]
backup=c:\windows\pss\Watch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinNC - Launch WinNC - multiplelicense (external programming station).lnk]
backup=c:\windows\pss\WinNC - Launch WinNC - multiplelicense (external programming station).lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Media^Start Menu^Programs^Startup^3DO Registration.lnk]
backup=c:\windows\pss\3DO Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Media^Start Menu^Programs^Startup^H3 The Shadow of Death(TM).lnk]
backup=c:\windows\pss\H3 The Shadow of Death(TM).lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Media^Start Menu^Programs^Startup^MostFun.lnk]
backup=c:\windows\pss\MostFun.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-05-16 08:27 153136 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-09-29 21:58 49152 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-03-18 03:24 184320 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 22:57 30208 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
-ra------ 2003-09-23 10:06 88363 c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra------ 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 2006-05-18 07:27 16207872 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LIVESRV"=2 (0x2)
"VSSERV"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\AoEII\\age2_x1\\age2_x1.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Documents and Settings\\Media\\My Documents\\Duke3D.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"d:\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10317:TCP"= 10317:TCP:BitComet 10317 TCP
"10317:UDP"= 10317:UDP:BitComet 10317 UDP
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-02-14 21512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-11 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-07-11 107272]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2008-08-07 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-08-07 31504]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2007-03-18 120320]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-11 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-11 298264]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2009-02-14 4107832]
R2 NirSoft Service Controler;NirSoft Service Controler;c:\windows\system32\drivers\NirCmd.exe [2009-02-15 677888]
S3 usb2vcom;USB to Serial Bridge Controller;c:\windows\system32\drivers\usb2vcom.sys [2009-01-25 30368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Windows Video Drivers - c:\recycler\S-1-5-21-3289545935-9251731632-595881002-5076\winlogon.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comodo.com/search/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Media\Application Data\Mozilla\Firefox\Profiles\edbk3j11.default\
FF - prefs.js: browser.startup.homepage -
FF - component: c:\documents and settings\Media\Application Data\Mozilla\Firefox\Profiles\edbk3j11.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-15 02:24:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1123561945-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1DA74357-36D9-7A50-261E-C9DC78F35153}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jaiklmgegkkhfbkipdpe"=hex:6a,61,68,68,67,6e,61,6e,6a,69,6a,6d,64,67,61,6b,6f,
66,68,61,00,00
"iakkjndomnpbnnfhip"=hex:6a,61,68,68,67,6e,61,6e,6a,69,6a,6d,64,67,61,6b,6f,66,
68,61,00,1a
[HKEY_USERS\S-1-5-21-1123561945-2025429265-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,24,63,52,7e,0d,8f,49,9f,62,93,36,b8,39,68,76,ab,b2,c7,54,21,e6,ee,
f5,0b,87,a7,57,31,af,4b,95,02,0f,6e,0d,9c,40,a0,af,1d,c3,4b,f6,02,8c,10,41,\
"??"=hex:66,16,d0,f7,71,61,e5,12,51,6c,06,2e,c0,18,58,6b
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(848-)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-15 2:28:23
ComboFix-quarantined-files.txt 2009-02-15 01:27:26
ComboFix2.txt 2009-02-15 00:34:34
Pre-Run: 3,469,877,248 bytes free
Post-Run: 3,455,774,720 bytes free
267
|