Yes i mean flopy drive, when all finish i see that all is better. Im allready happy. Now i cant hear sound of flopy drive.
Here are 2 log file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:36, on 9.11.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programi\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Programi\Nero 9\Nero 9\InCD\InCD.exe
D:\Programi\Nero 9\Nero 9\InCD\NBHGui.exe
D:\Programi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Programi\ObjectDock\ObjectDock.exe
D:\Programi\Avira\AntiVir PersonalEdition Classic\avguard.exe
D:\Programi\Nero 9\Nero 9\InCD\InCDSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\Programi\Nero 9\Nero 9\InCD\NBHRegInCDSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\Programi\Perfect Disk 2008\PD91Agent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Programi\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.hr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Programi\FlashGet 1.9\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Programi\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programi\Java\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\Programi\FlashGet 1.9\getflash.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] D:\Programi\Nero 9\Nero 9\InCD\InCD.exe
O4 - HKLM\..\Run: [NBHGui] D:\Programi\Nero 9\Nero 9\InCD\NBHGui.exe
O4 - HKLM\..\Run: [avgnt] "D:\Programi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ABIT uGuruIII] D:\Programi\Abit\uGuru\uGuru.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Stardock ObjectDock.lnk = D:\Programi\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Download All with FlashGet - D:\Programi\FlashGet 1.9\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - D:\Programi\FlashGet 1.9\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programi\Java\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programi\Java\bin\ssv.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programi\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Programi\FlashGet 1.9\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Programi\FlashGet 1.9\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: prio.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Programi\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Programi\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InCD Helper (InCDSrv) - Nero AG - D:\Programi\Nero 9\Nero 9\InCD\InCDSrv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - D:\Programi\Nero 9\Nero 9\InCD\NBHRegInCDSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - D:\Programi\Perfect Disk 2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - D:\Programi\Perfect Disk 2008\PD91Engine.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 5703 bytes
ComboFix 08-11-07.01 - Frane 2008-11-09 18:21:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1355 [GMT 1:00]
Running from: c:\documents and settings\Frane\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\resycled
c:\resycled\boot.com
c:\windows\system32\kdfau.exe
c:\windows\Temp\tmp3.tmp
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://www.8ballclub.com
.
((((((((((((((((((((((((( Files Created from 2008-10-09 to 2008-11-09 )))))))))))))))))))))))))))))))
.
2008-11-09 18:27 . 2008-11-09 18:27 <DIR> dr-hs---- C:\resycled
2008-11-09 16:35 . 2008-11-09 16:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-09 01:49 . 2008-11-09 01:49 <DIR> d-------- c:\documents and settings\Administrator
2008-11-09 00:37 . 2008-11-09 02:34 139 --a------ c:\windows\wininit.ini
2008-11-08 13:14 . 2008-11-08 13:14 <DIR> d-------- c:\documents and settings\Frane\Application Data\InstallShield Installation Information
2008-11-01 22:04 . 2008-11-01 22:04 <DIR> d-------- c:\documents and settings\Frane\Application Data\Capcom
2008-11-01 21:50 . 2008-11-01 21:50 <DIR> d-------- c:\documents and settings\Frane\Application Data\Activision
2008-11-01 21:50 . 2008-11-01 21:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Activision
2008-11-01 21:44 . 2008-11-01 21:44 <DIR> d-------- c:\windows\system32\xlive
2008-11-01 21:33 . 2008-11-01 21:33 <DIR> d--hs---- c:\windows\ftpcache
2008-11-01 20:34 . 2008-11-01 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-01 20:07 . 2008-11-01 20:07 <DIR> d-------- c:\program files\Adobe Media Player
2008-11-01 20:05 . 2008-11-01 20:05 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-01 20:01 . 2008-11-01 20:01 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-01 15:30 . 2008-11-01 15:30 <DIR> d-------- c:\documents and settings\Frane\Application Data\Red Alert 3
2008-10-27 17:38 . 2008-04-14 00:15 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-10-26 20:24 . 2008-11-08 22:47 <DIR> d-------- c:\documents and settings\Frane\Application Data\Hoyle Puzzle and Board Games
2008-10-26 20:24 . 2008-10-26 20:25 <DIR> d-------- c:\documents and settings\Frane\Application Data\Hoyle FaceCreator
2008-10-26 19:18 . 2008-11-01 16:05 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-10-26 16:12 . 2008-10-26 16:12 <DIR> d-------- c:\documents and settings\Frane\Application Data\Kaspersky_Key_Finder_(KKF
2008-10-23 17:44 . 2006-10-26 18:58 30,512 --a------ c:\windows\system32\mdimon.dll
2008-10-23 17:43 . 2008-10-23 17:43 <DIR> d-------- c:\program files\Microsoft Works
2008-10-23 17:42 . 2008-10-23 17:42 <DIR> d-------- c:\program files\Microsoft.NET
2008-10-23 17:40 . 2008-10-23 17:43 <DIR> d-------- c:\windows\SHELLNEW
2008-10-23 17:40 . 2008-10-23 17:40 <DIR> d-------- c:\program files\Microsoft Visual Studio 8
2008-10-23 17:39 . 2008-10-23 17:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-23 15:00 . 2008-10-23 15:00 <DIR> d-------- c:\documents and settings\Frane\Application Data\DAEMON Tools
2008-10-23 15:00 . 2008-10-23 15:00 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-10-21 21:39 . 2008-10-21 21:40 <DIR> d-------- c:\documents and settings\Frane\Application Data\mIRC
2008-10-20 20:37 . 2000-05-22 21:58 608,448 --a------ c:\windows\system32\comctl32.ocx
2008-10-20 19:40 . 2008-10-20 19:40 <DIR> d-------- c:\documents and settings\Frane\Application Data\TuneUp Software
2008-10-20 19:40 . 2008-10-20 19:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-10-20 19:40 . 2008-10-20 19:40 354,560 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-10-20 19:40 . 2008-04-04 13:51 28,416 --a------ c:\windows\system32\uxtuneup.dll
2008-10-20 19:39 . 2008-10-20 19:39 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-19 22:18 . 2008-10-19 22:18 <DIR> d-------- c:\windows\Logs
2008-10-19 22:18 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2008-10-19 22:18 . 2008-10-19 22:18 61,895 --a------ c:\windows\prio194uninstall.exe
2008-10-19 22:18 . 2008-10-19 22:18 135 --a------ c:\windows\system32\prio.ini
2008-10-19 22:14 . 2008-10-19 22:14 <DIR> d-------- c:\documents and settings\Frane\Application Data\InstallShield
2008-10-19 22:06 . 2008-10-19 22:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-19 21:44 . 2008-10-19 21:44 <DIR> d-------- c:\windows\Sun
2008-10-19 21:10 . 2008-10-19 21:10 <DIR> d-------- c:\documents and settings\Frane\Application Data\Apple Computer
2008-10-19 19:01 . 2008-10-19 19:01 <DIR> d-------- c:\program files\QuickTime
2008-10-19 19:01 . 2008-10-19 19:01 <DIR> d-------- c:\program files\Bonjour
2008-10-19 19:01 . 2008-10-19 19:01 <DIR> d-------- c:\program files\Apple Software Update
2008-10-19 19:01 . 2008-10-19 19:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-19 19:01 . 2008-10-19 19:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-10-19 18:56 . 2008-10-19 18:56 52,809 --a------ c:\windows\UN_CODA.EXE
2008-10-19 18:46 . 2007-09-15 14:11 27,136 --a------ c:\windows\system32\PCWizard.cpl
2008-10-19 18:40 . 2008-10-19 18:40 <DIR> d-------- c:\documents and settings\Frane\Application Data\DivX
2008-10-19 18:25 . 2008-10-19 18:25 <DIR> d-------- c:\program files\Common Files\xing shared
2008-10-19 18:25 . 2008-10-19 18:25 25 --a------ c:\windows\cdplayer.ini
2008-10-19 18:24 . 2008-10-19 18:25 <DIR> d-------- c:\program files\Common Files\Real
2008-10-19 18:22 . 2008-10-19 18:22 <DIR> d-------- c:\documents and settings\Frane\Application Data\URUSoft
2008-10-19 18:19 . 2008-10-19 18:19 <DIR> d-------- c:\documents and settings\Frane\Application Data\URUWorks
2008-10-19 18:09 . 2008-10-19 18:09 <DIR> d-------- c:\documents and settings\Frane\Application Data\CyberLink
2008-10-19 18:06 . 2008-10-19 18:06 <DIR> d-------- c:\program files\Cyberlink
2008-10-19 18:06 . 2008-10-19 18:06 <DIR> d-------- c:\program files\Common Files\CyberLink
2008-10-19 18:06 . 2008-10-19 18:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\CyberLink
2008-10-19 18:05 . 2008-10-19 18:04 29,480 --a------ c:\windows\system32\msxml3a.dll
2008-10-19 17:59 . 2008-10-19 17:59 20 --a------ c:\windows\system32\PDBootState
2008-10-19 17:54 . 2008-10-19 17:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Raxco
2008-10-19 17:54 . 2008-08-28 12:16 71,184 --a------ c:\windows\system32\drivers\DefragFS.sys
2008-10-19 17:16 . 2008-10-19 17:16 <DIR> d-------- c:\windows\system32\XPSViewer
2008-10-19 17:16 . 2008-10-19 17:16 <DIR> d-------- c:\program files\Reference Assemblies
2008-10-19 17:16 . 2008-10-23 17:43 <DIR> d-------- c:\program files\MSBuild
2008-10-19 17:15 . 2006-06-29 12:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-10-19 16:50 . 2008-10-19 16:51 <DIR> d-------- c:\windows\system32\URTTemp
2008-10-19 16:42 . 2008-10-23 13:52 22 --a------ c:\windows\popcinfot.dat
2008-10-19 16:42 . 2008-10-19 16:42 0 --a------ c:\windows\popcreg.dat
2008-10-19 16:33 . 2008-10-19 16:33 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-10-19 16:33 . 2008-04-14 13:00 221,184 --a------ c:\windows\system32\wmpns.dll
2008-10-19 16:31 . 2008-10-19 16:31 <DIR> d-------- c:\windows\system32\LogFiles
2008-10-19 16:31 . 2008-10-19 16:32 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-10-19 16:31 . 2006-09-25 16:58 23,856 --a------ c:\windows\system32\spupdsvc.exe
2008-10-19 16:30 . 2008-06-10 01:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-10-19 16:24 . 2008-10-19 16:24 <DIR> d-------- c:\program files\Common Files\Java
2008-10-19 16:21 . 2008-10-26 16:51 <DIR> d-------- c:\documents and settings\Frane\Application Data\TeamViewer
2008-10-19 16:20 . 2008-10-19 16:20 <DIR> d-------- c:\documents and settings\Frane\temp
2008-10-18 23:18 . 2008-10-18 23:18 <DIR> d-------- c:\program files\BFG
2008-10-18 23:18 . 2008-10-18 23:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Trymedia
2008-10-18 14:31 . 2008-10-18 14:31 <DIR> d-------- c:\documents and settings\Frane\Application Data\OtakuSoftware
2008-10-18 10:05 . 2008-10-18 10:05 <DIR> d-------- c:\documents and settings\Frane\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-10-18 09:59 . 2008-11-01 20:27 <DIR> d-------- c:\program files\Common Files\Adobe
2008-10-15 20:20 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\system32\d3dx9_32.dll
2008-10-15 20:19 . 2008-10-15 20:19 <DIR> d-------- c:\program files\Microsoft SQL Server Compact Edition
2008-10-15 20:18 . 2008-10-15 20:19 <DIR> d-------- c:\documents and settings\Frane\Contacts
2008-10-15 20:14 . 2008-10-15 20:20 <DIR> d-------- c:\program files\Windows Live
2008-10-15 20:14 . 2008-10-15 20:15 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-10-15 20:14 . 2008-10-15 20:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-15 20:14 . 2008-07-18 21:10 45,768 --a------ c:\windows\system32\wups2.dll
2008-10-15 20:14 . 2008-07-18 21:10 33,992 --a------ c:\windows\system32\wucltui.dll.mui
2008-10-15 20:14 . 2008-07-18 21:09 25,800 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-10-15 20:14 . 2008-07-18 21:09 25,800 --a------ c:\windows\system32\wuapi.dll.mui
2008-10-15 20:14 . 2008-07-18 21:08 20,680 --a------ c:\windows\system32\wuaueng.dll.mui
2008-10-15 20:01 . 2008-10-19 16:14 <DIR> d-------- c:\documents and settings\Frane\Application Data\skypePM
2008-10-15 20:01 . 2008-10-15 20:01 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-10-15 19:57 . 2008-10-15 19:57 <DIR> d-------- c:\program files\Common Files\Skype
2008-10-15 19:57 . 2008-10-19 22:19 <DIR> d-------- c:\documents and settings\Frane\Application Data\Skype
2008-10-15 19:56 . 2008-10-15 19:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2008-10-15 19:26 . 2008-10-30 17:26 <DIR> d-------- c:\documents and settings\Frane\Application Data\Nero
2008-10-15 19:16 . 2008-10-15 19:16 4,767 --a------ c:\windows\Irremote.ini
2008-10-15 19:05 . 2008-10-15 19:05 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-10-15 19:05 . 2008-09-19 15:53 129,560 --a------ c:\windows\system32\drivers\InCDFs.sys
2008-10-15 19:05 . 2008-09-19 15:53 41,752 --a------ c:\windows\system32\drivers\InCDRm.sys
2008-10-15 19:05 . 2008-09-19 15:53 40,216 --a------ c:\windows\system32\drivers\InCDPass.sys
2008-10-15 19:05 . 2008-09-19 15:53 19,352 --a------ c:\windows\system32\drivers\InCDRec.sys
2008-10-15 19:04 . 2008-10-15 19:25 <DIR> d-------- c:\program files\Common Files\Nero
2008-10-15 19:04 . 2008-10-15 19:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2008-10-14 18:22 . 2008-10-14 18:22 73,728 --a------ c:\windows\ALCFDRTM.EXE
2008-10-14 18:18 . 2008-10-14 18:21 <DIR> d-------- c:\windows\NV14081640.TMP
2008-10-14 15:43 . 2008-08-05 19:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys
2008-10-14 15:43 . 2006-01-04 14:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys
2008-10-14 15:43 . 2007-11-14 14:18 553 --a------ c:\windows\USetup.iss
2008-10-14 15:42 . 2008-10-14 15:42 319,488 --a------ c:\windows\HideWin.exe
2008-10-14 15:08 . 2008-10-14 15:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\NVIDIA
2008-10-14 13:06 . 2008-10-19 22:20 558 --a------ c:\windows\DFC.INI
2008-10-13 19:00 . 2008-10-14 13:04 <DIR> d-------- c:\windows\NV38201196.TMP
2008-10-13 18:51 . 2006-05-03 12:46 14,592 --a------ c:\windows\system32\drivers\uGuru.sys
2008-10-13 16:16 . 2008-11-02 15:46 <DIR> d-------- c:\documents and settings\Frane\Application Data\teamspeak2
2008-10-13 16:15 . 2008-10-13 16:15 34,064 --a------ c:\windows\system32\lhacm.acm
2008-10-12 22:12 . 2008-10-12 22:12 <DIR> d-------- c:\documents and settings\Frane\Application Data\URSoft
2008-10-12 22:11 . 2008-11-09 02:58 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-10-12 21:44 . 2008-10-12 21:44 <DIR> d-------- c:\program files\Common Files\Stardock
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 20:55 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-19 17:24 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-19 17:04 353,576 ----a-w c:\windows\system32\msvcr71.dll
2008-10-14 14:43 --------- d-----w c:\program files\Realtek
2008-10-12 15:23 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-12 15:22 --------- d-----w c:\program files\Intel
2008-10-12 15:12 --------- d-----w c:\program files\microsoft frontpage
2008-10-02 17:01 4,878,336 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2008-09-30 16:01 16,864,768 ----a-w c:\windows\RTHDCPL.EXE
2008-09-30 14:38 2,168,320 ----a-w c:\windows\MicCal.exe
2008-09-19 15:48 1,200,128 ----a-w c:\windows\RtlUpd.exe
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
2008-09-09 11:49 230,152 ----a-w c:\windows\system32\PDBoot.exe
2008-08-25 14:17 528,384 ----a-w c:\windows\RtlExUpd.dll
2008-08-19 11:26 77,824 ----a-w c:\windows\SOUNDMAN.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2008-09-19 15:53 98328 --a------ d:\programi\Nero 9\Nero 9\InCD\NBHshx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ABIT uGuruIII"="d:\programi\Abit\uGuru\uGuru.exe" [2006-07-24 417792]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"InCD"="d:\programi\Nero 9\Nero 9\InCD\InCD.exe" [2008-09-19 1111064]
"NBHGui"="d:\programi\Nero 9\Nero 9\InCD\NBHGui.exe" [2008-09-19 2079256]
"avgnt"="d:\programi\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
c:\documents and settings\Frane\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - d:\programi\ObjectDock\ObjectDock.exe [10/12/2008 9:44:27 PM 3581680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=prio.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DIVXA32.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Programi\\uTorrent\\uTorrent.exe"=
"d:\\Programi\\Skype\\Phone\\Skype.exe"=
"d:\\Programi\\FlashGet 1.9\\flashget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Programi\\Microsoft Office Professional Plus 2007\\Office12\\OUTLOOK.EXE"=
"d:\\Igre\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Igre\\Far Cry 2\\bin\\FC2Launcher.exe"=
"d:\\Igre\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Igre\\Activision\\Quantum of Solace(TM)\\JB_LiveEngine_s.exe"=
"d:\\Igre\\MotoGP 08\\Launcher.exe"=
"d:\\Igre\\8BallClub\\GameDirector.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 UGURU;UGURU;c:\windows\system32\drivers\uGuru.sys [2006-05-03 14592]
R1 prio;prio driver;c:\windows\system32\drivers\prio.sys [2006-10-28 29184]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};d:\programi\PowerDVD\PowerDVD8\
000.fcl [2008-05-15 11:07 61424]
R2 adfs;adfs;c:\windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 NeroRegInCDSrv;Nero Registry InCD Service;d:\programi\Nero 9\Nero 9\InCD\NBHRegInCDSrv.exe [2008-09-19 108568]
R2 PD91Agent;PD91Agent;d:\programi\Perfect Disk 2008\PD91Agent.exe [2008-09-09 693512]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe [2008-04-14 14336]
S3 PD91Engine;PD91Engine;d:\programi\Perfect Disk 2008\PD91Engine.exe [2008-09-09 906504]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-10-20 354560]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2008-11-09 c:\windows\Tasks\1-Click Maintenance.job
- d:\programi\TuneUp Utiliities 2008\OneClickStarter.exe [2008-04-16 08:59]
2008-11-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-c:\windows\system32\kdfau.exe - c:\windows\system32\kdfau.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Frane\Application Data\Mozilla\Firefox\Profiles\aforiqin.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.google.com
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
FF -: plugin - d:\programi\Adobe Reader 9\Reader\browser\nppdf32.dll
FF -: plugin - d:\programi\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - d:\programi\DivX\DivX Player\npDivxPlayerPlugin.dll
FF -: plugin - d:\programi\DivX\DivX Web Player\npdivx32.dll
FF -: plugin - d:\programi\Java\bin\npjava11.dll
FF -: plugin - d:\programi\Java\bin\npjava12.dll
FF -: plugin - d:\programi\Java\bin\npjava13.dll
FF -: plugin - d:\programi\Java\bin\npjava14.dll
FF -: plugin - d:\programi\Java\bin\npjava32.dll
FF -: plugin - d:\programi\Java\bin\npjpi160_07.dll
FF -: plugin - d:\programi\Java\bin\npoji610.dll
FF -: plugin - d:\programi\Mozilla Firefox\plugins\npnul32.dll
FF -: plugin - d:\programi\RealPlayer\Netscape6\nppl3260.dll
FF -: plugin - d:\programi\RealPlayer\Netscape6\nprjplug.dll
FF -: plugin - d:\programi\RealPlayer\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-09 18:30:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\d:\programi\PowerDVD\PowerDVD8\
000.fcl"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
d:\programi\Avira\AntiVir PersonalEdition Classic\sched.exe
d:\programi\Avira\AntiVir PersonalEdition Classic\avguard.exe
d:\programi\Nero 9\Nero 9\InCD\InCDSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-11-09 18:33:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-09 17:33:06
Pre-Run: 12.428.099.584 bytes free
Post-Run: 12,678,266,880 bytes free
303