evo i drugi.
DDS (Ver_09-07-30.01) - NTFSx86
Run by User at 16:24:08,87 on 14.09.2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1251.389.1033.18.1023.546 [GMT 2:00]
AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [NVMixerTray] "c:\program files\nvidia corporation\nvmixer\NVMixerTray.exe"
mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe"
mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Gainward] c:\program files\vdotool\TBPanel.exe /A
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Monitor] c:\windows\philips\spc220nc\Monitor.exe
mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\traymi~1.lnk - c:\program files\philips\philips spc220nc webcam\TrayMin220.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\SCIEPlgn.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {641D9245-E1B4-4362-8921-B8B83A23D64F} = 62.162.32.5 62.162.32.6
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: klogon - c:\windows\system32\klogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\nwpliolc.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2007-10-31 112144]
R1 klif;Klif;c:\windows\system32\drivers\klif.sys [2007-12-28 195344]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\cyberlink\powerdvd8\000.fcl [2008-2-1 41456]
R2 AVP;Kaspersky Anti-Virus 7.0;c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe [2008-2-8 227856]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592]
R3 SPC220NC;Philips SPC220NC Webcam;c:\windows\system32\drivers\SPC220NC.SYS [2009-8-17 507136]
=============== Created Last 30 ================
2009-09-13 05:53 <DIR> --d----- c:\docume~1\user\applic~1\Malwarebytes
2009-09-13 05:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-13 05:53 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 05:53 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-13 05:53 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-06 22:15 <DIR> --d----- c:\program files\mIRC
2009-08-30 04:24 <DIR> --d----- C:\OutputFolder
2009-08-26 23:11 <DIR> --d----- c:\docume~1\user\applic~1\mIRC
2009-08-24 21:24 64,376 a------- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-24 02:37 268,648 a------- c:\windows\system32\mucltui.dll
2009-08-24 02:37 208,744 a------- c:\windows\system32\muweb.dll
2009-08-24 02:37 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-08-24 00:04 <DIR> --d----- c:\program files\Webteh
2009-08-23 22:32 <DIR> --d----- c:\program files\Easy Video Downloader
2009-08-23 22:27 <DIR> --d----- c:\program files\Allok AVI to DVD SVCD VCD Converter
2009-08-23 22:04 <DIR> --d----- c:\program files\AliveMedia
2009-08-21 03:40 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
2009-08-21 03:40 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
2009-08-21 03:36 <DIR> -cdsh--- c:\program files\common files\WindowsLiveInstaller
2009-08-20 04:47 <DIR> --d----- c:\program files\MSXML 4.0
2009-08-19 06:08 56 a---h--- c:\windows\system32\ezsidmv.dat
2009-08-18 04:13 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-18 04:13 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-18 04:13 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-18 04:12 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-08-18 04:09 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-08-18 04:07 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-08-18 03:51 116 a------- c:\windows\NeroDigital.ini
2009-08-18 02:18 <DIR> --d----- c:\documents and settings\user\Contacts
2009-08-18 01:59 <DIR> --d----- c:\program files\common files\xing shared
2009-08-18 01:59 <DIR> --d----- c:\program files\common files\Real
2009-08-17 22:50 14,592 ac------ c:\windows\system32\dllcache\kbdhid.sys
2009-08-17 22:50 14,592 a------- c:\windows\system32\drivers\kbdhid.sys
2009-08-17 22:50 12,160 ac------ c:\windows\system32\dllcache\mouhid.sys
2009-08-17 22:50 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-08-17 22:49 10,368 ac------ c:\windows\system32\dllcache\hidusb.sys
2009-08-17 22:49 10,368 a------- c:\windows\system32\drivers\hidusb.sys
2009-08-17 20:47 <DIR> --d----- c:\program files\VVSN
2009-08-17 20:47 223,128 a------- c:\windows\system32\drivers\dtscsi.sys
2009-08-17 20:47 <DIR> --d----- c:\program files\DAEMON Tools
2009-08-17 20:44 664,064 a------- c:\windows\system32\drivers\sptd.sys
2009-08-17 20:44 96,384 a------- c:\windows\system32\drivers\sptd5165.sys
2009-08-17 20:30 61,952 ac------ c:\windows\system32\dllcache\kstvtune.ax
2009-08-17 20:30 61,952 a------- c:\windows\system32\kstvtune.ax
2009-08-17 20:29 507,136 a------- c:\windows\system32\drivers\SPC220NC.SYS
2009-08-17 20:29 6,656 a------- c:\windows\system32\CoInst.dll
2009-08-17 20:29 518 a------- c:\windows\system32\SPC220NC.INI
2009-08-17 20:29 119,808 a------- c:\windows\system32\SPC220NC.AX
2009-08-17 20:29 <DIR> --d----- c:\program files\Philips
2009-08-17 20:26 <DIR> --d----- c:\program files\IVT Corporation
2009-08-17 20:26 32 a------- c:\windows\0
2009-08-17 20:26 0 a------- c:\windows\system32\0
2009-08-17 20:24 940,794 a------- c:\windows\system32\LoopyMusic.wav
2009-08-17 20:24 146,650 a------- c:\windows\system32\BuzzingBee.wav
2009-08-17 20:23 <DIR> --d----- c:\windows\system32\Lang
2009-08-17 20:23 558 a------- c:\windows\DFC.INI
2009-08-17 20:21 127,254 a------- c:\windows\system32\nvapps.xml
2009-08-17 20:21 17,463 a------- c:\windows\system32\nvdisp.nvu
2009-08-17 20:21 356,352 a------- c:\windows\system32\nvudisp.exe
2009-08-17 20:20 356,352 a------- c:\windows\system32\NVUNINST.EXE
2009-08-17 03:19 12,256 a------- c:\windows\system32\drivers\TBPanel.sys
2009-08-17 03:19 <DIR> --d----- c:\program files\VDOTool
2009-08-17 03:18 83,200 a----r-- c:\windows\system32\drivers\Rtenicxp.sys
2009-08-17 03:18 <DIR> --d----- c:\windows\OPTIONS
2009-08-17 03:16 143,360 -----r-- c:\windows\system32\RtlCPAPI.dll
2009-08-17 03:16 49,152 -----r-- c:\windows\system32\ChCfg.exe
2009-08-17 03:15 <DIR> --d----- c:\windows\system32\RTCOM
2009-08-17 03:15 86,016 -----r-- c:\windows\SoundMan.exe
2009-08-17 03:15 2,879,488 -----r-- c:\windows\SkyTel.exe
2009-08-17 03:15 364,544 -----r-- c:\windows\RtlUpd.exe
2009-08-17 03:15 282,624 -----r-- c:\windows\system32\RTSndMgr.Cpl
2009-08-17 03:15 9,709,568 -----r-- c:\windows\RTLCPL.exe
2009-08-17 03:15 4,381,184 -----r-- c:\windows\system32\drivers\RtkHDAud.Sys
2009-08-17 03:15 16,264,192 -----r-- c:\windows\RTHDCPL.exe
2009-08-17 03:15 2,155,008 -----r-- c:\windows\MicCal.exe
2009-08-17 03:15 69,632 -----r-- c:\windows\Alcmtr.exe
2009-08-17 03:15 2,808,832 -----r-- c:\windows\alcwzrd.exe
2009-08-17 03:15 299,008 -----r-- c:\windows\system32\ALSndMgr.Cpl
2009-08-17 03:14 <DIR> --d----- c:\program files\Realtek
2009-08-17 03:14 499,712 -----r-- c:\windows\RtlExUpd.dll
2009-08-17 03:09 4,372 a------- c:\windows\Ascd_tmp.ini
2009-08-17 03:09 10,288 a------- c:\windows\system32\drivers\ASUSHWIO.SYS
2009-08-17 02:59 20,608 ac------ c:\windows\system32\dllcache\usbuhci.sys
2009-08-17 02:59 20,608 a------- c:\windows\system32\drivers\usbuhci.sys
==================== Find3M ====================
2009-09-14 16:24 78,880 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-09-14 16:24 286,752 a--sh--- c:\windows\system32\drivers\fidbox2.dat
2009-09-14 16:23 32 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-09-14 11:39 28,904 a--sh--- c:\windows\system32\drivers\fidbox2.idx
2009-09-11 02:24 107,547 a------- c:\windows\system32\drivers\klin.dat
2009-09-11 02:24 95,259 a------- c:\windows\system32\drivers\klick.dat
2009-08-23 22:14 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-18 01:59 499,712 a------- c:\windows\system32\msvcp71.dll
2009-08-18 00:15 112,144 a------- c:\windows\system32\drivers\kl1.sys
2009-08-05 11:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-29 06:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-17 21:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-06-29 18:12 827,392 a------- c:\windows\system32\wininet.dll
2009-06-29 18:12 78,336 a------- c:\windows\system32\ieencode.dll
2009-06-29 18:12 17,408 a------- c:\windows\system32\corpol.dll
2009-06-25 10:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 10:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 10:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-04-02 22:27 2,516 a--sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-04-02 22:27 88 ---shr-- c:\docume~1\alluse~1\applic~1\CB8BCAFAE3.sys
2009-04-02 22:39 56 ---shr-- c:\windows\system32\E3FACA8BCB.sys
2009-04-02 22:39 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-03-12 06:42 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009031120090312\index.dat
============= FINISH: 16:24:53,78 ===============