This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HJT log please check

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:30:44, on 21.3.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP1 (7.00.6000.20583)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\ApexDC++_Gusari_XY6\ApexDC.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.sbb.co.yu:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1004336348-1284227242-839522115-1001\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-1004336348-1284227242-839522115-1001\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User '?')
O4 - HKUS\S-1-5-21-1004336348-1284227242-839522115-1001\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203897398578
O18 - Protocol: schmap-help - (no CLSID) - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O24 - Desktop Component 0: (no name) - http://thumbs.fotopic.net/745017000727.jpg
O24 - Desktop Component 1: (no name) - http://www.turizam-krusevac.org.yu/assets/…/clearpixel.gif
O24 - Desktop Component 2: (no name) - file:///C:/DOCUME~1/kuca/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

–
End of file - 6761 bytes
Hello and welcome to Posted Image

Please do the following.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTListIt logfile created on: 30.4.2009 1:02:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\kuca\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.2180)
Locale: 0000081A | Country: Serbia and Montenegro | Language: SRL | Date Format: d.M.yyyy

503,23 Mb Total Physical Memory | 301,27 Mb Available Physical Memory | 59,87% Memory free
1,20 Gb Paging File | 0,99 Gb Available in Paging File | 82,53% Paging File free
Paging file location(s): c:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 2,56 Gb Free Space | 17,45% Space Free | Partition Type: NTFS
Drive D: | 61,68 Gb Total Space | 3,83 Gb Free Space | 6,21% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KUCA-ABEF35E449
Current User Name: kuca
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\UAService7.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\kuca\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (NNServ [Disabled | Stopped]) – File not found
SRV - (NWCWorkstation [Auto | Running]) – C:\WINDOWS\System32\nwwks.dll (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UPS [On_Demand | Stopped]) – File not found
SRV - (UserAccess7 [Auto | Running]) – C:\WINDOWS\system32\UAService7.exe ()
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (cdrbsdrv [System | Running]) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (d347bus [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\d347bus.sys ( )
DRV - (d347prt [Boot | Running]) – C:\WINDOWS\System32\Drivers\d347prt.sys ( )
DRV - (hwpsgt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\hwpsgt.sys ()
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (imagedrv [Disabled | Stopped]) – C:\WINDOWS\System32\Drivers\imagedrv.sys (Ahead Software AG)
DRV - (imagesrv [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\imagesrv.sys (Ahead Software AG)
DRV - (Intels51 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Intels51.sys (Intel Corporation)
DRV - (lemsgt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\lemsgt.sys ()
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (NwlnkIpx [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (NWRDR [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nwrdr.sys (Microsoft Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS ()
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys ()
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sscdbus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdbus.sys (MCCI Corporation)
DRV - (sscdmdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdmdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sscdmdm.sys (MCCI Corporation)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\System32\drivers\StarOpen.sys ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType;=tb50ffwinampie7&query;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.82.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20080609.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType;=tb50ffwinampab&query;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009.04.28 11:50:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009.04.28 11:50:00 | 00,000,000 | —D | M]

[2008.10.09 02:30:16 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\mozilla\Extensions
[2008.10.09 02:30:16 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.04.30 00:58:49 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\mozilla\Firefox\Profiles\jlhlynuj.default\extensions
[2008.06.22 23:25:23 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\mozilla\Firefox\Profiles\jlhlynuj.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2008.12.15 19:01:49 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\mozilla\Firefox\Profiles\jlhlynuj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008.06.22 23:25:43 | 00,001,196 | —- | M] () – C:\Documents and Settings\kuca\Application Data\Mozilla\FireFox\Profiles\jlhlynuj.default\searchplugins\winamp-search.xml
[2009.04.28 12:00:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009.04.28 11:50:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008.01.18 20:15:35 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{AF8637B0-18E3-44D3-86B7-55E09D9C4261}
[2007.06.10 13:43:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2006.12.16 20:01:07 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}
[2009.04.28 11:49:54 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009.04.28 11:49:54 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008.11.19 11:28:36 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008.11.19 11:28:36 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008.11.19 11:28:36 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008.11.19 11:28:36 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008.11.19 11:28:36 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008.11.19 11:28:36 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008.11.19 11:28:36 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (IeCatch2 Class) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\Jccatch.dll (Amaze Soft)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (FlashGet Bar) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll (Amaze Soft)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 (DAEMON'S HOME)
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart (Google)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ConfirmFileDelete = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: &Search; - Reg Error: Value error.
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (Amaze Soft)
O9 - Extra 'Tools' menuitem : &FlashGet; - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (Amaze Soft)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1203897398578 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 () - http://thumbs.fotopic.net/745017000727.jpg
O24 - Desktop Components:1 () - http://www.turizam-krusevac.org.yu/assets/…/clearpixel.gif
O24 - Desktop Components:2 () - file:///C:/DOCUME~1/kuca/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{85df9996-cda5-11dc-aac9-000272d1d9a6}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com – File not found
O33 - MountPoints2\{85df9996-cda5-11dc-aac9-000272d1d9a6}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com – File not found
O33 - MountPoints2\{91df1eba-0a87-11de-90ca-00138f26337b}\Shell\AutoRun\command - "" = wscript.exe .\.vbs
O33 - MountPoints2\{91df1eba-0a87-11de-90ca-00138f26337b}\Shell\open\command - "" = wscript.exe .\.vbs
O33 - MountPoints2\{9bc00446-d13a-11dd-ab7c-00138f26337b}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com
O33 - MountPoints2\{9bc00446-d13a-11dd-ab7c-00138f26337b}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\windowsupdate.com
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009.04.29 13:25:46 | 00,038,825 | —- | C] () – C:\Documents and Settings\kuca\Desktop\24772-must_love_dogs.zip
[2009.04.22 17:00:42 | 00,017,875 | —- | C] () – C:\Documents and Settings\kuca\Desktop\78074-desperate.housewives.519.hdtv.xvidxor.Cata.rar
[2009.04.22 12:41:36 | 00,172,544 | —- | C] () – C:\Documents and Settings\kuca\Desktop\Anketa za fizicka lica.doc
[2009.04.21 14:31:56 | 00,047,270 | —- | C] () – C:\Documents and Settings\kuca\Desktop\prison.break.417.hdtv-0tv.srt
[2009.04.19 23:34:51 | 00,030,753 | —- | C] () – C:\Documents and Settings\kuca\Desktop\VT.Prison.Break.S04E17.HDTV.XviD-0TV[valhallatorrent.org].torrent
[2009.04.19 19:45:28 | 00,000,000 | —D | C] – C:\Documents and Settings\kuca\Desktop\MUST HAVE PROGRAMI
[2009.04.19 19:32:39 | 73,555,5308 | —- | C] () – C:\Documents and Settings\kuca\Desktop\Made.Of.Honor[2008.avi
[2009.04.19 19:08:38 | 00,031,232 | —- | C] ( ) – C:\WINDOWS\System\vdremote.dll
[2009.04.19 19:08:38 | 00,025,088 | —- | C] ( ) – C:\WINDOWS\System\vdsvrlnk.dll
[2009.04.19 19:06:07 | 01,444,430 | —- | C] () – C:\Documents and Settings\kuca\Desktop\VirtualDub-1.9.1.zip
[2009.04.17 15:52:48 | 04,232,881 | —- | C] () – C:\Documents and Settings\kuca\Desktop\Danijela - Izdali Me.mp3
[2009.04.13 23:31:37 | 00,040,340 | —- | C] () – C:\Documents and Settings\kuca\Desktop\n1460927215_30038409_3957572.jpg
[2009.04.13 21:59:39 | 02,249,035 | —- | C] () – C:\Documents and Settings\kuca\Desktop\mapa.jpg
[2009.04.11 20:04:55 | 00,064,000 | —- | C] () – C:\Documents and Settings\kuca\Desktop\New Microsoft Word Docjnuhghument.doc
[2009.04.10 19:21:04 | 00,023,552 | —- | C] () – C:\Documents and Settings\kuca\Desktop\gradjansko pitanja.doc
[2009.04.10 19:17:22 | 00,010,752 | —- | C] () – C:\Documents and Settings\kuca\Desktop\New Microsoft Word Document.doc
[2009.04.10 10:45:10 | 28,868,320 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\kuca\Desktop\FileFormatConverters.exe
[2009.04.10 10:42:43 | 00,000,000 | —D | C] – C:\Program Files\MSECache
[2009.04.10 10:32:40 | 25,685,128 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\kuca\Desktop\wordview_en-us.exe
[2009.04.10 10:05:59 | 00,020,957 | —- | C] () – C:\Documents and Settings\kuca\Desktop\GraÄ'ansko pravo.docx
[2009.04.03 19:07:28 | 10,735,65696 | —- | C] () – C:\Documents and Settings\kuca\Desktop\VTS_01_1.VOB
[2009.04.03 19:06:57 | 15,937,3312 | —- | C] () – C:\Documents and Settings\kuca\Desktop\VTS_01_2.VOB
[2009.04.02 17:20:56 | 01,044,306 | —- | C] () – C:\Documents and Settings\kuca\Desktop\plazma_kuvar.pdf
[2009.03.31 20:45:29 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Documents and Settings\kuca\Desktop\OTListIt2.exe

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\*.tmp files]
[2009.04.30 00:55:24 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009.04.30 00:54:43 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009.04.29 18:41:57 | 00,000,552 | —- | M] () – C:\Documents and Settings\kuca\Ksenija\My Sharing Folders.lnk
[2009.04.29 13:25:49 | 00,038,825 | —- | M] () – C:\Documents and Settings\kuca\Desktop\24772-must_love_dogs.zip
[2009.04.29 13:23:41 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009.04.28 22:31:40 | 00,000,089 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2009.04.28 16:54:29 | 00,194,560 | —- | M] () – C:\Documents and Settings\kuca\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.04.28 10:31:07 | 00,136,464 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009.04.27 19:18:50 | 00,172,544 | —- | M] () – C:\Documents and Settings\kuca\Desktop\Anketa za fizicka lica.doc
[2009.04.22 17:00:48 | 00,017,875 | —- | M] () – C:\Documents and Settings\kuca\Desktop\78074-desperate.housewives.519.hdtv.xvidxor.Cata.rar
[2009.04.21 14:31:58 | 00,047,270 | —- | M] () – C:\Documents and Settings\kuca\Desktop\prison.break.417.hdtv-0tv.srt
[2009.04.19 23:34:53 | 00,030,753 | —- | M] () – C:\Documents and Settings\kuca\Desktop\VT.Prison.Break.S04E17.HDTV.XviD-0TV[valhallatorrent.org].torrent
[2009.04.19 19:34:53 | 73,555,5308 | —- | M] () – C:\Documents and Settings\kuca\Desktop\Made.Of.Honor[2008.avi
[2009.04.19 19:06:37 | 01,444,430 | —- | M] () – C:\Documents and Settings\kuca\Desktop\VirtualDub-1.9.1.zip
[2009.04.17 15:55:02 | 04,232,881 | —- | M] () – C:\Documents and Settings\kuca\Desktop\Danijela - Izdali Me.mp3
[2009.04.15 15:01:51 | 00,001,307 | —- | M] () – C:\Documents and Settings\kuca\Desktop\Nero StartSmart.lnk
[2009.04.14 23:11:33 | 00,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009.04.13 23:31:40 | 00,040,340 | —- | M] () – C:\Documents and Settings\kuca\Desktop\n1460927215_30038409_3957572.jpg
[2009.04.13 21:59:46 | 02,249,035 | —- | M] () – C:\Documents and Settings\kuca\Desktop\mapa.jpg
[2009.04.11 20:04:55 | 00,064,000 | —- | M] () – C:\Documents and Settings\kuca\Desktop\New Microsoft Word Docjnuhghument.doc
[2009.04.10 19:21:04 | 00,023,552 | —- | M] () – C:\Documents and Settings\kuca\Desktop\gradjansko pitanja.doc
[2009.04.10 19:17:23 | 00,010,752 | —- | M] () – C:\Documents and Settings\kuca\Desktop\New Microsoft Word Document.doc
[2009.04.10 10:53:40 | 28,868,320 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\kuca\Desktop\FileFormatConverters.exe
[2009.04.10 10:42:16 | 25,685,128 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\kuca\Desktop\wordview_en-us.exe
[2009.04.10 10:06:00 | 00,020,957 | —- | M] () – C:\Documents and Settings\kuca\Desktop\GraÄ'ansko pravo.docx
[2009.04.02 17:20:57 | 01,044,306 | —- | M] () – C:\Documents and Settings\kuca\Desktop\plazma_kuvar.pdf
[2009.03.31 20:45:34 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\kuca\Desktop\OTListIt2.exe

========== LOP Check ==========

[2009.02.07 14:47:39 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2005.11.07 10:47:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2005.11.07 10:40:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008.03.25 16:52:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg7
[2007.12.08 21:50:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2008.12.19 23:16:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2005.11.07 10:35:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008.08.25 18:53:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009.01.17 23:30:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009.04.30 00:50:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008.08.25 02:10:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin
[2006.03.21 13:31:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macrovision
[2008.10.08 22:38:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008.07.01 16:54:21 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006.12.02 20:54:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2007.07.08 16:56:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\My Games
[2007.05.26 14:05:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2007.04.08 00:54:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2007.12.13 21:02:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005.11.18 20:35:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2007.03.25 01:09:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Real
[2007.07.09 19:40:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2007.06.10 13:43:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2008.02.24 21:54:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008.06.09 18:33:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008.08.03 20:39:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006.08.21 18:03:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2006.09.27 00:42:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006.09.14 20:29:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2006.12.17 21:49:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2006.09.15 14:37:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009.04.09 12:10:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\kuca\Application Data
[2008.10.21 00:19:24 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\.purple
[2007.04.07 19:27:39 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\7Wonders
[2007.05.21 22:57:44 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\ACD Systems
[2009.01.10 18:18:40 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Adobe
[2005.11.10 02:08:23 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\AdobeUM
[2008.02.25 09:00:06 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\AVG7
[2006.02.13 15:06:34 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Corel
[2008.08.27 17:13:33 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\COWON
[2005.11.03 14:59:48 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\CyberLink
[2008.09.08 21:38:56 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\dvdcss
[2007.07.03 01:06:46 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Exodus
[2008.08.24 23:56:49 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Gaijin Ent
[2007.06.04 19:41:36 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\GameHouse
[2008.07.03 00:04:36 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Gamelab
[2009.01.05 15:31:00 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\GARMIN
[2007.07.08 16:57:18 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\gemsweeperextractedgfx
[2005.11.03 15:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\gen_ff v1.04
[2007.06.10 13:18:34 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Gizmoz
[2007.05.28 17:12:00 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Google
[2009.03.12 17:17:42 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\GRETECH
[2005.11.24 19:50:42 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Help
[2006.12.05 01:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\ICQ Toolbar
[2005.10.31 04:08:03 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Identities
[2008.08.27 17:12:10 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\InstallShield
[2008.08.25 02:09:46 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\iWin
[2009.03.20 17:25:15 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\JLC's Software
[2006.03.21 13:32:16 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Ldoce
[2007.06.25 11:56:38 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\ldoce4
[2007.01.24 17:07:16 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Macromedia
[2008.10.08 22:38:56 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Malwarebytes
[2007.03.25 01:10:47 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Media Player Classic
[2008.03.25 16:52:51 | 00,000,000 | –SD | M] – C:\Documents and Settings\kuca\Application Data\Microsoft
[2008.10.09 02:30:16 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Mozilla
[2006.02.20 11:39:46 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\NetMedia Providers
[2006.07.05 11:45:24 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\OLYMPUS
[2009.01.14 22:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Opera
[2007.12.13 21:02:18 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\PlayFirst
[2006.02.20 11:39:45 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Publish Providers
[2006.02.13 15:14:44 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\RadLight Company
[2007.04.10 00:08:26 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Real
[2007.07.08 11:23:57 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Reallusion
[2007.05.26 12:57:09 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Reasonable Software
[2008.09.15 16:51:49 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Samsung
[2007.07.09 19:40:01 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Sandlot Games
[2008.05.03 19:25:57 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Schmap
[2007.06.25 11:56:22 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\SecuROM
[2009.04.14 22:10:24 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Skype
[2006.09.13 19:36:40 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\SlySoft
[2006.02.13 15:19:14 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Sonic Foundry
[2006.09.18 11:18:49 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Sun
[2008.10.09 00:32:00 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\SUPERAntiSpyware.com
[2006.09.23 17:40:11 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Talkback
[2008.10.08 17:58:17 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\U3
[2009.04.28 07:59:01 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\uTorrent
[2007.01.25 03:05:49 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\vlc
[2008.01.18 23:54:48 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\VoipBusterPro
[2008.01.18 23:56:05 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\VoipStunt
[2008.08.25 19:34:24 | 00,000,000 | —D | M] – C:\Documents and Settings\kuca\Application Data\Wildfire

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1713795
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E3E060F
< End of report >

OTListIt Extras logfile created on: 30.4.2009 1:02:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\kuca\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.2180)
Locale: 0000081A | Country: Serbia and Montenegro | Language: SRL | Date Format: d.M.yyyy

503,23 Mb Total Physical Memory | 301,27 Mb Available Physical Memory | 59,87% Memory free
1,20 Gb Paging File | 0,99 Gb Available in Paging File | 82,53% Paging File free
Paging file location(s): c:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 2,56 Gb Free Space | 17,45% Space Free | Partition Type: NTFS
Drive D: | 61,68 Gb Total Space | 3,83 Gb Free Space | 6,21% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KUCA-ABEF35E449
Current User Name: kuca
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found
C:\Documents and Settings\kuca\Desktop\utorrent.exe:*:Enabled:µTorrent File not found
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil File not found
C:\Program Files\VoipBusterPro.com\VoipBusterPro\VoipBusterPro.exe:*:Enabled:VoipBusterPro File not found
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe:*:Enabled:VoipStunt File not found
C:\Documents and Settings\kuca\Ksenija\Internet\utorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
D:\Downloads\ApexDC++\ApexDC.exe:*:Enabled:ApexDC++ File not found
C:\Program Files\RealVNC\VNC4\winvnc4.exe:*:Enabled:VNC Server Free Edition for Win32 File not found
C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb File not found
C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray (Orb Networks)
C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client File not found
C:\Program Files\ApexDC++\ApexDC.exe:*:Enabled:ApexDC++ - Pinnacle of File Sharing File not found
C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk (Google)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B0098FF-1816-4F42-8203-FA29F5735596}" = Samsung PC Studio 3
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}" = Windows Live Sign-in Assistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{29622F4A-245C-4126-8764-897E21E888D1}" = Google Earth Pro
"{2A38B5AA-EA84-4F87-9937-2FB23982243A}" = Sonic Foundry ACID 4.0
"{2C0CD17D-0B06-4700-83FA-7344B868B0A2}" = Opera 9.63
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools
"{4A905F9B-97C5-4E7D-ADAC-3FC5048431D7}" = Vesala na srpski nacin
"{4EA96950-1A9C-4BAB-A6FD-73C0163D0B8A}" = Reasonable NoClone 4 Home
"{51312349-0B4D-450E-AFAA-03CC28A9531F}" = Microsoft Office 2003 programski dodatak za preslovljavanje
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{593AFFA4-D08E-4272-BABB-420949D32A10}" = QUICKfind
"{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}" = MP3 Player Utilities
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.2
"{62FC357F-022B-4F90-9376-7A0DF9FBE7A1}" = Sonic Foundry Sound Forge 6.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{73B1C023-4490-4A57-A7E1-F20268ECBE52}" = Windows Live Toolbar
"{7585478E9D9B42108671C12F8714CEFE}" = DivX Converter
"{7AC15160-A49B-4A89-B181-D4619C025FFF}" = Samsung Samples Installer
"{7DED5635-B47C-4B0F-9AD0-8765D15FD94F}" = Tabbed Browsing (Windows Live Toolbar)
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11109097}" = Luxor - Amun Rising
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{9E7E97D2-3F83-460D-9348-CE40A21E2CA6}" = Windows Live Toolbar MSN Extension (Windows Live Toolbar)
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2D41883-3BFC-4BA0-A2F6-5A2C9836C238}" = ACDSee 9 Photo Manager
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = COWON Media Center - jetAudio Basic
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1" = ACE Mega CoDecS Pack
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"ApexDC++ 1.1.0_is1" = ApexDC++ 1.1.0
"Auto Skola" = Auto Skola
"avast!" = avast! Antivirus
"BFGC" = Big Fish Games Client
"BSPlayer1" = BSPlayer
"Burger Island_is1" = Burger Island
"Ciao Bella" = Ciao Bella (remove only)
"Dynomite Deluxe 2.71" = Dynomite Deluxe 2.71
"Eggsucker_is1" = Eggsucker V2.0
"Fairy Godmother Tycoon_is1" = Fairy Godmother Tycoon
"FlashGet(JetCar)" = FlashGet(JetCar)
"Gemsweeper_is1" = Gemsweeper
"GOM Player" = GOM Player
"Google Updater" = Google Updater
"GTK 2.0" = GTK+ Runtime 2.12.8 rev a (remove only)
"Hammer Heads 1.0" = Hammer Heads 1.0
"HijackThis" = HijackThis 2.0.2
"JLC's Internet TV" = JLC's Internet TV
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.61
"Luxor_is1" = Luxor
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Merriam Websters Spell Jam_is1" = Merriam Websters Spell Jam
"Micro DVD Player" = Micro DVD Player
"MicroDVD" = MicroDVD
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"Muppet Babies Toyland Train" = Muppet Babies Toyland Train
"MV2Player" = MV2Player (remove only)
"Native Instruments Traktor v1.0" = Native Instruments Traktor v1.0
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"Peggle Deluxe_is1" = Peggle Deluxe
"Pidgin" = Pidgin
"QuickTime" = QuickTime
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SHOUTcastDSP" = SHOUTcast Source DSP 1.9.0 (remove only)
"SubtitleWorkshop" = Subtitle Workshop 2.51
"Total Commander" = Total Commander 6.53 PowerPack
"Tumblebugs" = Tumblebugs
"Tumblebugs 2" = Tumblebugs 2
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Winamp" = Winamp
"Windows Live Toolbar" = Windows Live Toolbar
"WinRAR archiver" = WinRAR archiver
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4.4.2009 9:56:54 | Computer Name = KUCA-ABEF35E449 | Source = Windows Live Messenger | ID = 1000
Description =

Error - 6.4.2009 4:52:24 | Computer Name = KUCA-ABEF35E449 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 28.4.2009 4:31:53 | Computer Name = KUCA-ABEF35E449 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 29.4.2009 18:50:02 | Computer Name = KUCA-ABEF35E449 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 29.4.2009 18:53:58 | Computer Name = KUCA-ABEF35E449 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80070005 from line 44 of d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 29.4.2009 18:55:14 | Computer Name = KUCA-ABEF35E449 | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

[ System Events ]
Error - 30.3.2009 5:44:46 | Computer Name = KUCA-ABEF35E449 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00138F26337B has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 30.3.2009 5:50:55 | Computer Name = KUCA-ABEF35E449 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 00138F26337B.

Error - 4.4.2009 9:57:39 | Computer Name = KUCA-ABEF35E449 | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 5.4.2009 11:52:32 | Computer Name = KUCA-ABEF35E449 | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort2, did not respond within the timeout
period.

Error - 5.4.2009 11:52:49 | Computer Name = KUCA-ABEF35E449 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom1, has a bad block.

Error - 6.4.2009 4:54:17 | Computer Name = KUCA-ABEF35E449 | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 7.4.2009 5:12:45 | Computer Name = KUCA-ABEF35E449 | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 13.4.2009 17:25:53 | Computer Name = KUCA-ABEF35E449 | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 28.4.2009 5:04:51 | Computer Name = KUCA-ABEF35E449 | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 29.4.2009 18:51:06 | Computer Name = KUCA-ABEF35E449 | Source = DCOM | ID = 10005
Description = DCOM got error "%1083" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}


< End of report >
Hi,

Sorry I missed your reply as you started a new topic instead of adding a reply to the original topic.

I have merged the threads now so please make sure when you reply to my next instructions that you choose the ADD REPLY button. Thanks.

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
ComboFix 09-05-22.05 - kuca 23.05.2009 1:22.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\inet20112
c:\windows\inet20112\gif\a.txt
c:\windows\inet20112\mm.pid
c:\windows\system32\msconfig.exe
c:\windows\Temp\scsF.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NNSERV
——-\Service_NNServ


((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.

2009-05-05 09:02 . 2009-05-05 09:02 ——– d—–w c:\documents and settings\kuca\Local Settings\Application Data\Microsoft Help
2009-05-05 09:02 . 2009-05-05 09:12 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 23:17 . 2006-12-21 22:58 ——– d—–w c:\documents and settings\kuca\Application Data\uTorrent
2009-05-22 23:17 . 2007-06-10 11:43 ——– d—–w c:\documents and settings\kuca\Application Data\Skype
2009-05-22 21:33 . 2008-08-18 14:07 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-22 21:33 . 2006-06-12 09:18 89 —-a-w c:\windows\popcinfo.dat
2009-05-19 15:40 . 2007-06-05 10:51 ——– d—–w c:\program files\Fairy Godmother Tycoon
2009-04-10 08:53 . 2009-04-10 08:42 ——– d—–w c:\program files\MSECache
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-06 68856]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
"DisableCAD"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInternetIcon"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 11:41 294912 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^kuca^Start Menu^Programs^Startup^Total Commander.lnk]
backup=c:\windows\pss\Total Commander.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\kuca\\Ksenija\\Internet\\utorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S1 aswSP;avast! Self Protection; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 5632]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2007-02-27 32256]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]


— Other Services/Drivers In Memory —

*NewlyCreated* - HELPSVC
*Deregistered* - Aavmker4
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - aswFsBlk
*Deregistered* - aswMon2
*Deregistered* - aswRdr
*Deregistered* - aswSP
*Deregistered* - aswTdi
*Deregistered* - aswUpdSv
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avast! Antivirus
*Deregistered* - avast! Mail Scanner
*Deregistered* - avast! Web Scanner
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - BthServ
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - d347bus
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gusvc
*Deregistered* - HTTP
*Deregistered* - hwpsgt
*Deregistered* - imagesrv
*Deregistered* - ImapiService
*Deregistered* - IntelIde
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - Kbdclass
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - lemsgt
*Deregistered* - LmHosts
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NWCWorkstation
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - NWRDR
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RDPWD
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - SASDIFSV
*Deregistered* - SASKUTIL
*Deregistered* - Secdrv
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - StarOpen
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TDTCP
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - UserAccess7
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - WZCSVC
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = proxy.sbb.co.yu:8080
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: Download All by FlashGet - c:\progra~1\FlashGet\jc_all.htm
IE: Download using FlashGet - c:\progra~1\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\kuca\Application Data\Mozilla\Firefox\Profiles\jlhlynuj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-23 01:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(620)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\UAService7.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-05-22 1:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-22 23:30

Pre-Run: 1.961.746.432 bytes free
Post-Run: 2.995.716.096 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

282 — E O F — 2008-02-25 02:12
topic reopened at request of Original poster. If you cannot reply to your topic within five days please advise. Please make sure you always use the "ADD REPLY" button rather than start a new topic. Thanks CB. I am now analyzing the current logs and will get back to you shortly with further instructions:
Hi,

Please do the following:


Go Start > Run and copy/paste the following single-line command into the Run box and click OK:



cmd /c del /f/a/s "C:\WINDOWS\popcinfo.dat"



NEXT


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Double-click GooredFix.exe to run it.
  • Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).Note: Do not run GooredFix option #2 yet



NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • GooredFix Log
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI