offline
- Pridružio: 15 Sep 2008
- Poruke: 50
|
ok javljam se kad zavrsim
Dopuna: 29 Jan 2009 22:31
ComboFix 09-01-21.04 - Jowan 2009-01-29 22:23:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.662 [GMT 1:00]
Running from: c:\documents and settings\Jowan\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated)
FW: ESET Personal firewall *enabled*
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Jowan\Application Data\inst.exe
C:\install.exe
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\recycler\S-1-3-92-100004904-100010318-100014257-6142.com
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\gaopdxmnapyejb.sys
c:\windows\system32\drivers\gaopdxnuebnaih.sys
c:\windows\system32\drivers\gaopdxubrrnsfl.sys
c:\windows\system32\drivers\gaopdxwupxudps.sys
c:\windows\system32\gaopdxefyrcpyl.dll
D:\Autorun.inf
d:\recycler\S-0-9-39-100021274-100020488-100007008-5856.com
d:\recycler\S-1-3-79-100000028-100027346-100017886-5008.com
d:\recycler\S-1-3-92-100004904-100010318-100014257-6142.com
d:\recycler\S-2-7-58-100022114-100004512-100023163-1465.com
d:\recycler\S-2-9-48-100010156-100028169-100030650-5852.com
d:\recycler\S-3-1-41-100028528-100007648-100012312-3854.com
d:\recycler\S-6-1-61-100020731-100002673-100020422-5375.com
d:\recycler\S-7-2-35-100017940-100017384-100024957-3424.com
d:\recycler\S-8-9-80-100031605-100023347-100006992-3725.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-29 )))))))))))))))))))))))))))))))
.
2009-01-28 16:36 . 2009-01-29 21:49 4 --a------ c:\windows\system32\gaopdxcounter
2009-01-24 21:21 . 2009-01-24 21:21 244 --ah----- C:\sqmnoopt08.sqm
2009-01-24 21:21 . 2009-01-24 21:21 232 --ah----- C:\sqmdata08.sqm
2009-01-22 13:16 . 2009-01-22 13:16 <DIR> d-------- c:\windows\system32\F1_Screensaver_08 dir
2009-01-22 13:16 . 2009-01-22 13:16 532,480 --a------ c:\windows\system32\F1_Screensaver_08.scr
2009-01-19 20:42 . 2009-01-19 20:59 <DIR> d-------- C:\Casino
2009-01-17 18:57 . 2009-01-17 18:57 <DIR> d-------- c:\program files\TGTSoft
2009-01-16 23:07 . 2009-01-28 05:03 <DIR> d-------- c:\documents and settings\Jowan\Application Data\skypePM
2009-01-16 23:07 . 2009-01-16 23:07 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-01-16 23:06 . 2009-01-29 21:51 <DIR> d-------- c:\documents and settings\Jowan\Application Data\Skype
2009-01-16 23:05 . 2009-01-16 23:06 <DIR> d-------- c:\program files\Skype
2009-01-16 23:05 . 2009-01-16 23:05 <DIR> d-------- c:\program files\Common Files\Skype
2009-01-16 23:05 . 2009-01-16 23:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2009-01-14 14:58 . 2009-01-14 14:58 <DIR> d-------- c:\program files\Kiri Levente Software
2009-01-10 14:18 . 2009-01-10 14:18 126,976 --a------ c:\windows\system32\UAService7.exe
2009-01-10 13:12 . 2009-01-10 13:12 <DIR> d-------- c:\program files\JoWooD
2009-01-10 09:20 . 2009-01-10 09:20 268 --ah----- C:\sqmdata07.sqm
2009-01-10 09:20 . 2009-01-10 09:20 244 --ah----- C:\sqmnoopt07.sqm
2009-01-09 23:57 . 2009-01-09 23:57 268 --ah----- C:\sqmdata06.sqm
2009-01-09 23:57 . 2009-01-09 23:57 244 --ah----- C:\sqmnoopt06.sqm
2009-01-09 21:14 . 2009-01-28 16:46 <DIR> d-------- c:\program files\Banner Maker Pro 7
2009-01-08 16:05 . 2009-01-08 16:05 <DIR> d-------- c:\program files\Common Files\xing shared
2009-01-07 18:27 . 2009-01-07 18:27 <DIR> d-------- c:\windows\system32\Adobe
2009-01-07 18:27 . 2009-01-07 18:27 670 --a------ c:\windows\mozver.dat
2009-01-04 19:02 . 2009-01-04 19:04 <DIR> d-------- c:\windows\NV35083516.TMP
2009-01-04 18:58 . 2009-01-04 19:04 <DIR> d-------- c:\windows\NV10041440.TMP
2009-01-04 18:58 . 2009-01-04 18:58 664 --a------ c:\windows\system32\d3d9caps.dat
2009-01-04 13:35 . 2009-01-04 13:35 <DIR> d-------- c:\program files\id Software
2009-01-04 12:16 . 2009-01-04 12:16 <DIR> d--hs---- c:\windows\ftpcache
2009-01-03 11:47 . 2009-01-03 11:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Winter Sports 2009
2009-01-01 20:34 . 2009-01-01 20:35 9,351 --a------ c:\windows\system32\shutdown.rar
2009-01-01 20:34 . 2009-01-01 20:34 9,351 --a------ c:\windows\system32\hej.rar
2008-12-30 23:48 . 2008-12-30 23:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\vsosdk
2008-12-30 17:18 . 2006-05-20 16:16 1,184,984 --a------ c:\windows\system32\wvc1dmod.dll
2008-12-30 17:18 . 2006-05-11 19:21 626,688 --a------ c:\windows\system32\vp7vfw.dll
2008-12-30 17:18 . 2006-09-29 12:24 217,127 --a------ c:\windows\system32\drv43260.dll
2008-12-30 17:18 . 2006-09-29 12:25 208,935 --a------ c:\windows\system32\drv33260.dll
2008-12-30 17:18 . 2006-09-29 12:26 176,165 --a------ c:\windows\system32\drv23260.dll
2008-12-30 17:18 . 2002-12-10 02:20 102,439 --a------ c:\windows\system32\sipr3260.dll
2008-12-30 17:18 . 2007-03-18 20:37 65,602 --a------ c:\windows\system32\cook3260.dll
2008-12-30 13:04 . 2008-12-30 13:04 <DIR> d-------- c:\program files\SubMagic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 17:47 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-28 14:18 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-20 21:45 --------- d-----w c:\documents and settings\Jowan\Application Data\LimeWire
2009-01-08 15:05 --------- d-----w c:\program files\Common Files\Real
2009-01-07 17:27 --------- d-----w c:\program files\Wyzo
2009-01-02 13:00 183,112 ----a-w c:\windows\system32\PnkBstrB.exe
2009-01-02 13:00 138,184 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-01-01 16:09 --------- d-----w c:\documents and settings\Jowan\Application Data\Apple Computer
2008-12-31 10:11 --------- d-----w c:\documents and settings\Jowan\Application Data\Vso
2008-12-30 16:18 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-30 16:18 47,360 ----a-w c:\documents and settings\Jowan\Application Data\pcouffin.sys
2008-12-30 16:18 --------- d-----w c:\program files\vso
2008-12-30 15:45 --------- d-----w c:\program files\Avi2Dvd
2008-12-30 15:44 87,608 ----a-w c:\documents and settings\Jowan\Application Data\ezpinst.exe
2008-12-28 12:42 --------- d-----w c:\program files\LimeWire
2008-12-28 12:42 --------- d-----w c:\program files\FastStone Image Viewer
2008-12-28 12:42 --------- d-----w c:\program files\DAP
2008-12-28 12:42 --------- d-----w c:\program files\AGEIA Technologies
2008-12-25 11:59 --------- d-----w c:\program files\Ultra Video Joiner
2008-12-25 09:05 --------- d-----w c:\documents and settings\Jowan\Application Data\OpenOffice.org2
2008-12-24 19:37 --------- d-----w c:\program files\SUmIRC skripta
2008-12-24 19:23 --------- d-----w c:\documents and settings\Jowan\Application Data\mIRC
2008-12-24 19:21 --------- d-----w c:\program files\mIRC
2008-12-21 05:36 --------- d-----w c:\program files\Google
2008-12-19 08:31 --------- d-----w c:\program files\Azureus
2008-12-19 08:31 --------- d-----w c:\documents and settings\Jowan\Application Data\Azureus
2008-12-19 08:12 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-12-18 21:39 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2008-12-07 13:44 --------- d-----w c:\documents and settings\Jowan\Application Data\Nero
2008-12-05 16:38 --------- d-----w c:\program files\Java
2008-12-04 14:05 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-02 20:50 --------- d-----w c:\program files\MSDN
2008-12-02 09:13 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
2008-12-01 17:10 --------- d-----w c:\program files\Euro Truck Simulator
2008-11-28 10:49 --------- d-----w c:\program files\Common Files\Nero
2008-11-28 10:47 --------- d-----w c:\program files\Windows Sidebar
2008-11-28 10:38 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-11-28 09:42 --------- d-----w c:\program files\Nero
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-11-06 15:03 50,688 ----a-w c:\windows\system32\wbhelp2.dll
2008-10-30 12:01 8,192 ----a-w c:\windows\system32\k_KBD0.dll
2008-10-28 19:54 22,328 ----a-w c:\documents and settings\Jowan\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2008-10-07 57344]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 12:22 1172792 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-07-17 691656]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-07-17 691656]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-10-09 4555776]
"Google Update"="c:\documents and settings\Jowan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-16 133104]
"RGSC"="d:\igre\gta4\Rockstar Games Social Club\RGSCLauncher.exe" [2008-12-20 306088]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-20 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2007-08-23 241664]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2008-11-17 111928]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-08 185872]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-05-10 c:\windows\system32\nwiz.exe]
c:\documents and settings\Jowan\Start Menu\Programs\Startup\AutorunsDisabled
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-06-05 147456]
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2005-09-23 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"SENTINEL"= snti386.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Igre\\gta4\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Wyzo\\wyzo.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:UDP"= 139:UDP:*:Disabled:VPN_TCP_139
"5110:TCP"= 5110:TCP:*:Disabled:VPN_TCP_5110
"5110:UDP"= 5110:UDP:*:Disabled:VPN_TCP_5110
R4 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S4 gupdate1c9476cf56661dc;Google Update Service (gupdate1c9476cf56661dc);c:\program files\Google\Update\GoogleUpdate.exe [2008-11-15 133104]
.
Contents of the 'Scheduled Tasks' folder
2008-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-11-16 10:54]
2008-12-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-1645522239-725345543-1003.job
- c:\documents and settings\Jowan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-16 10:54]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKCU-Run-WinNTGuard - c:\windows\c:\adware.bat
HKCU-Run-msnmsgr - ~c:\program files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-DLD.EXE - c:\program files\Download Direct\DLD.exe
HKLM-Run-WinNTGuard - c:\windows\RSPremium.exe
HKLM-Run-(Default) - c:\windows\svchost.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.sweetim.com
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath - c:\documents and settings\Jowan\Application Data\Mozilla\Firefox\Profiles\oub5qak4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - SweetIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\documents and settings\Jowan\Application Data\Mozilla\Firefox\Profiles\oub5qak4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Jowan\Application Data\Mozilla\Firefox\Profiles\oub5qak4.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Jowan\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.133.33\npGoogleOneClick7.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-29 22:27:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
msnmsgr = ~"c:\program files\Windows Live\Messenger\msnmsgr.exe" /background?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1547161642-1645522239-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:f0,54,02,2c,de,a9,f4,68,11,f7,a8,52,14,9f,cb,6c,a1,ba,84,3c,7e,
71,cf,68,ab,67,db,c8,bd,d5,21,b5,92,02,88,9e,23,1f,28,6b,81,f9,4c,27,5b,46,\
"rkeysecu"=hex:5b,64,ae,14,c2,07,7e,bb,c9,39,4b,63,e6,ee,4f,2e
.
Completion time: 2009-01-29 22:28:36
ComboFix-quarantined-files.txt 2009-01-29 21:28:28
Pre-Run: 3,273,211,904 bytes free
Post-Run: 11,500,146,688 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
288 --- E O F --- 2008-10-09 12:33:15
Dopuna: 29 Jan 2009 22:48
evo sad sam proverio i mogu da udjem na c i d nepojavluje se onaj error zahvaljujem se jel mi mozete reci sta je to bilo kakva vrsta virusa i kako da se zastitim?
|