U pravu si, pukao mi je uninstall za AVG. Evo log-a
ComboFix 09-12-31.01 - Nikola 12/31/2009 19:35:45.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1566 [GMT 1:00]
Running from: c:\documents and settings\Nikola\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\EventSystem.log
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-31 )))))))))))))))))))))))))))))))
.
2009-12-31 14:40 . 2009-12-31 14:40 4 ----a-w- c:\windows\system32\aspdict-en.dat
2009-12-31 14:40 . 2009-12-31 14:40 16 ----a-w- c:\windows\system32\asdict.dat
2009-12-31 14:40 . 2009-12-31 14:40 0 ----a-w- C:\pcwords2.dat
2009-12-31 14:40 . 2009-12-31 14:40 0 ----a-w- C:\pcwords.dat
2009-12-31 14:39 . 2009-12-31 14:40 132 ----a-w- c:\windows\system32\rezumatenoi.dat
2009-12-31 14:30 . 2009-12-31 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2009-12-31 14:30 . 2009-12-31 14:30 -------- d-----w- c:\documents and settings\Nikola\Application Data\BitDefender
2009-12-31 14:30 . 2009-12-31 14:30 -------- d-----w- c:\program files\BitDefender
2009-12-31 14:29 . 2009-12-31 14:30 -------- d-----w- c:\program files\Common Files\BitDefender
2009-12-31 00:54 . 2009-12-31 00:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-12-30 23:58 . 2009-12-30 23:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-30 23:58 . 2009-12-30 23:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\Subversion
2009-12-29 22:21 . 2009-12-29 22:21 -------- d-----w- c:\documents and settings\Nikola\Application Data\Malwarebytes
2009-12-29 22:21 . 2009-12-31 14:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 22:21 . 2009-12-29 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-28 23:56 . 2009-12-28 23:56 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-12-28 20:09 . 2009-12-28 23:35 -------- d-----w- c:\program files\DrWeb
2009-12-27 02:51 . 2009-12-27 02:51 -------- d-----w- c:\program files\Enigma Software Group
2009-12-26 13:18 . 2009-12-27 00:26 52224 ----a-w- c:\documents and settings\Nikola\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-26 13:18 . 2009-12-27 00:26 117760 ----a-w- c:\documents and settings\Nikola\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-26 13:17 . 2009-12-26 13:17 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-26 13:17 . 2009-12-26 13:17 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-26 13:17 . 2009-12-26 13:17 -------- d-----w- c:\documents and settings\Nikola\Application Data\SUPERAntiSpyware.com
2009-12-23 21:27 . 2007-08-14 12:04 9216 ----a-w- c:\windows\system32\ffnd.exe
2009-12-23 21:22 . 2009-12-23 21:22 -------- d-----w- c:\documents and settings\Nikola\Local Settings\Application Data\FreeFixer
2009-12-23 21:22 . 2009-12-23 21:22 -------- d-----w- c:\documents and settings\Nikola\Application Data\FreeFixer
2009-12-23 20:57 . 2009-12-23 20:57 -------- d-----w- c:\documents and settings\Nikola\Local Settings\Application Data\VS Revo Group
2009-12-23 19:35 . 2009-12-23 19:35 -------- d-----w- c:\documents and settings\Nikola\Application Data\Uniblue
2009-12-23 19:10 . 2009-12-23 19:09 737280 ----a-w- c:\windows\iun6002.exe
2009-12-23 19:10 . 2009-12-23 19:12 -------- d-----w- c:\program files\Tweak-XP Pro 4
2009-12-22 08:21 . 2009-12-31 18:39 714752 ----a-w- c:\windows\system32\drivers\xjpgy.sys
2009-12-19 18:37 . 2009-12-19 18:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2009-12-15 17:36 . 2009-12-15 17:36 -------- d-----w- c:\documents and settings\Nikola\Application Data\teamspeak2
2009-12-15 17:31 . 2009-12-23 19:03 -------- d-----w- c:\program files\Teamspeak2_RC2
2009-12-07 17:49 . 2009-12-07 17:49 105736 ----a-w- c:\windows\system32\drivers\bdhv.sys
2009-12-07 17:46 . 2009-12-07 17:46 152456 ----a-w- c:\windows\system32\drivers\bdfm.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 14:09 . 2008-08-20 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-12-30 23:57 . 2009-12-30 23:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-12-30 17:39 . 2009-01-24 13:42 -------- d-----w- c:\program files\Astonsoft
2009-12-29 22:29 . 2009-05-20 19:13 -------- d-----w- c:\program files\Gigatron Konfygurator
2009-12-29 22:07 . 2008-08-28 21:18 -------- d-----w- c:\documents and settings\Nikola\Application Data\Skype
2009-12-29 22:06 . 2008-08-28 21:21 -------- d-----w- c:\documents and settings\Nikola\Application Data\skypePM
2009-12-26 23:44 . 2008-10-29 22:44 -------- d-----w- c:\documents and settings\Nikola\Application Data\MySQL
2009-12-26 13:17 . 2008-08-27 15:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-23 21:37 . 2009-07-04 15:13 -------- d-----w- c:\program files\MSECACHE
2009-12-23 20:54 . 2009-10-27 17:06 -------- d-----w- c:\documents and settings\Nikola\Application Data\VMware
2009-12-23 19:45 . 2008-08-20 14:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-22 23:07 . 2009-02-16 23:53 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
2009-12-22 23:07 . 2009-02-16 23:55 -------- d-----w- c:\documents and settings\NetworkService\Application Data\VMware
2009-12-19 20:24 . 2009-09-08 15:50 165984 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-19 18:38 . 2009-02-21 00:15 -------- d-----w- c:\documents and settings\Nikola\Application Data\EditPlus 3
2009-12-05 17:27 . 2008-08-22 17:12 -------- d-----w- c:\program files\phpDesigner 2008
2009-11-30 17:28 . 2008-08-21 13:13 -------- d-----w- c:\program files\Counter-Strike
2009-11-11 19:54 . 2009-11-08 14:55 -------- d-----w- c:\documents and settings\Nikola\Application Data\TortoiseSVN
2009-11-08 14:51 . 2009-11-08 14:51 -------- d-----w- c:\documents and settings\Nikola\Application Data\Subversion
2009-11-08 14:48 . 2009-11-08 14:48 -------- d-----w- c:\program files\TortoiseSVN
2009-11-08 14:48 . 2009-11-08 14:48 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2009-11-07 00:05 . 2009-11-04 19:19 1 ----a-w- c:\windows\system32\krx240.dat
2009-11-06 18:36 . 2009-02-17 12:53 -------- d-----w- c:\documents and settings\LocalService\Application Data\VMware
2009-11-06 18:34 . 2009-11-06 18:34 -------- d-----w- c:\program files\Common Files\VMware
2009-11-05 19:56 . 2009-11-05 19:56 -------- d-----w- c:\program files\ShowMyPCService
2009-11-04 19:19 . 2009-11-04 19:19 -------- d-----w- c:\program files\Web Button Maker Deluxe
2009-10-19 17:59 . 2009-12-31 14:33 47104 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-16 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2009-12-04 1118144]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nokia Ovi Suite.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Nokia Ovi Suite.lnk
backup=c:\windows\pss\Nokia Ovi Suite.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
backup=c:\windows\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Nikola^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-03 22:56 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-11 21:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 14:06 1840424 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-03 23:06 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 07:31 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-06-19 07:53 570664 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
2008-10-17 17:18 2323680 ----a-w- c:\program files\Nokia\Nokia Music\NokiaMusic.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia Home Server Manager]
2008-11-07 08:42 542208 ----a-w- c:\program files\Nokia\Nokia Home Media Server\NHSM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 14:09 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-08-20 07:38 16384512 ------r- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-08-11 15:46 21741864 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2006-11-23 23:06 487424 ----a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-11-03 21:16 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-11-24 14:51 185872 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2007-10-10 05:28 36352 ----a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ufad-ws60"=3 (0x3)
"TwonkyMedia"=3 (0x3)
"SQLWriter"=3 (0x3)
"SQLSERVERAGENT"=3 (0x3)
"MSSQLServerADHelper"=3 (0x3)
"MSSQLSERVER"=3 (0x3)
"ServiceLayer"=3 (0x3)
"SandraAgentSrv"=2 (0x2)
"NMIndexingService"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"ATI Smart"=2 (0x2)
"ASKUpgrade"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"EventSystem"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\wamp\\bin\\apache\\apache2.2.8\\bin\\httpd.exe"=
"c:\\Program Files\\phpDesigner 2008\\phpDesigner2008.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\edgios.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"e:\\PES.2009.Full.Rib\\pes2009.exe"=
"e:\\PES.2009.Full.Rib\\Crack\\pes2009.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymedia.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymediaserver.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 atitray;atitray;c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [8/24/2008 15:19 17952]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 16:26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 16:26 74480]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [12/7/2009 18:46 152456]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 16:27 7408]
S2 LogWatch;Event Log Watch;c:\ca_lic\LogWatNT.exe --> c:\ca_lic\LogWatNT.exe [?]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 16:06 183880]
S3 atidgllk;atidgllk;\??\c:\docume~1\Nikola\LOCALS~1\Temp\~Af27855\Upgrade\atidgllk.sys --> c:\docume~1\Nikola\LOCALS~1\Temp\~Af27855\Upgrade\atidgllk.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 07:01 2799808]
S4 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - xjpgy
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bsplayer-search.com/startpage
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
TCP: {BA7082B7-451A-4B86-AEF3-A14A14441AEC} = 212.200.191.166,212.200.190.166
FF - ProfilePath - c:\documents and settings\Nikola\Application Data\Mozilla\Firefox\Profiles\jt16ymu5.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
MSConfigStartUp-ISUSPM - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
MSConfigStartUp-SpyHunter Security Suite - c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe
MSConfigStartUp-sysgif32 - c:\windows\TEMP\~TM39.tmp
MSConfigStartUp-VMware hqtray - c:\program files\VMware\VMware Workstation\hqtray.exe
MSConfigStartUp-vmware-tray - c:\program files\VMware\VMware Workstation\vmware-tray.exe
AddRemove-2kv4.8.442 - c:\windows\Radeon Omega Drivers v4.8.442
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-31 19:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xjpgy]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(796)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-31 19:40:57
ComboFix-quarantined-files.txt 2009-12-31 18:40
Pre-Run: 18,455,998,464 bytes free
Post-Run: 18,531,250,176 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - 751F6D32CB8EB23B0807F00237CD4CEF