offline
- Coler master
- Zaslužni građanin
- Pridružio: 26 Dec 2007
- Poruke: 612
- Gde živiš: Beograd
|
evo izveštaja i od combo fixa
ComboFix 09-12-06.07 - Mandic 06/12/2009 23:19.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1457 [GMT 1:00]
Running from: c:\documents and settings\Mandic\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091206-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\documents and settings\Mandic\Application Data\Desktopicon
c:\documents and settings\Mandic\Application Data\Desktopicon\config.ini
c:\documents and settings\Mandic\Application Data\Desktopicon\eBayShortcuts.exe
c:\documents and settings\Mandic\Application Data\FunWebProducts
c:\documents and settings\Mandic\Application Data\FunWebProducts\Data\Mandic\avatar.dat
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\config.ini
c:\program files\Dealio Toolbar\DealioToolbarIE.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\separator.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\SearchSettingsKit.exe
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\00F6C547.urr
c:\program files\FunWebProducts\Shared\00FE6742.dat
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
c:\program files\Search Settings
c:\program files\Search Settings\kb128\SearchSettings.dll
c:\program files\Search Settings\kb128\SearchSettingsRes409.dll
c:\program files\Search Settings\SearchSettings.exe
c:\recycler\S-1-5-21-3819336069-7640369166-365150907-3337
c:\recycler\S-1-5-21-6884413928-1726280799-383457496-4751
c:\recycler\S-1-5-21-7363789880-3115145510-067250181-5173
c:\recycler\S-1-5-21-8485835088-0993659945-974422983-2933
c:\recycler\S-1-5-21-9999503957-0607780891-941765445-1004
c:\windows\n.tmp
c:\windows\system32\f3PSSavr.scr
Infected copy of c:\windows\system32\midimap.dll was found and disinfected
Restored copy from - c:\windows\VistaMizer\old\midimap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-02 16:16 . 2009-12-02 16:17 -------- d-----w- c:\program files\QuickTime
2009-12-02 16:16 . 2009-12-02 16:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-24 23:49 . 2009-11-27 00:22 -------- d-----w- c:\documents and settings\Mandic\Application Data\Tor
2009-11-24 23:49 . 2009-11-27 00:22 -------- d-----w- c:\documents and settings\Mandic\Application Data\Vidalia
2009-11-24 23:49 . 2009-11-24 23:49 -------- d-----w- c:\program files\Vidalia Bundle
2009-11-24 20:44 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-24 20:44 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-24 20:44 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-24 20:44 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-24 20:44 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-24 20:44 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-24 20:44 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-24 20:13 . 2009-11-24 20:13 -------- d-----w- c:\program files\Activision
2009-11-23 21:08 . 2009-11-23 21:08 -------- d-----w- c:\program files\Vstplugins
2009-11-23 21:08 . 2009-11-23 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony
2009-11-23 21:08 . 2009-11-23 21:08 -------- d-----w- c:\program files\Sony
2009-11-23 21:08 . 2009-11-23 21:08 -------- d-----w- c:\program files\Sony Setup
2009-11-22 11:04 . 2009-11-22 11:34 -------- d-----w- c:\program files\SopCast
2009-11-19 22:49 . 2009-11-19 22:59 -------- d-----w- c:\documents and settings\Mandic\Application Data\Publish Providers
2009-11-14 10:31 . 2009-11-14 10:31 -------- d-----w- c:\program files\Vimeo Uploader
2009-11-09 23:06 . 2009-11-22 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-11-09 14:56 . 2009-11-09 15:03 -------- d-----w- C:\vcs5core
2009-11-08 16:24 . 2009-11-08 16:24 -------- d-----w- c:\documents and settings\Mandic\Application Data\MPEG Streamclip
2009-11-08 15:51 . 2009-11-11 18:35 -------- d-----w- C:\vcs5BGEffects
2009-11-08 15:50 . 2009-11-21 20:08 -------- d-----w- c:\program files\AV Vcs 6.0 DIAMOND
2009-11-08 11:20 . 2009-11-23 21:12 -------- d-----w- c:\documents and settings\Mandic\Local Settings\Application Data\Sony
2009-11-08 11:20 . 2009-11-23 21:12 -------- d-----w- c:\documents and settings\Mandic\Application Data\Sony
2009-11-07 17:01 . 2009-12-06 11:45 -------- d-----w- c:\documents and settings\Mandic\Tracing
2009-11-07 16:58 . 2009-11-07 16:58 -------- d-----w- c:\program files\Microsoft Silverlight
2009-11-07 16:57 . 2009-11-07 16:57 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-11-07 16:57 . 2009-08-05 21:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-11-07 16:57 . 2009-11-07 16:57 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-07 16:56 . 2009-11-07 16:56 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-07 16:55 . 2009-11-07 16:58 -------- d-----w- c:\program files\Microsoft
2009-11-07 16:54 . 2009-11-07 16:54 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-07 16:40 . 2009-11-07 16:40 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 22:23 . 2009-03-12 19:59 117760 ----a-w- c:\documents and settings\Mandic\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-06 20:56 . 2008-10-10 21:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-05 19:45 . 2009-01-23 13:58 -------- d-----w- c:\documents and settings\Mandic\Application Data\uTorrent
2009-11-24 23:54 . 2008-10-10 18:18 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2008-10-10 18:18 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2008-10-10 18:18 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2008-10-10 18:22 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-10-10 18:22 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2008-10-10 18:18 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-10-10 18:18 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-10-10 18:18 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2008-10-10 18:18 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2009-11-22 22:51 . 2009-08-03 20:23 -------- d-----w- c:\program files\vSoft
2009-11-15 13:20 . 2009-10-28 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2009-11-14 10:31 . 2009-09-18 15:15 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-14 10:31 . 2009-09-18 15:15 38208 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-07 16:57 . 2008-10-11 16:04 -------- d-----w- c:\program files\Windows Live
2009-11-05 14:59 . 2009-10-21 18:23 -------- d-----w- c:\program files\iWisoft Flash SWF to Video Converter
2009-11-04 18:01 . 2008-10-03 07:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-04 18:00 . 2008-10-03 08:23 -------- d-----w- c:\program files\CyberLink
2009-11-04 18:00 . 2009-10-28 23:06 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
2009-11-04 18:00 . 2009-11-04 18:00 -------- d-----w- c:\program files\SmartSound Software
2009-11-04 17:58 . 2009-10-30 16:19 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2009-11-04 16:33 . 2009-11-04 16:33 -------- d-----w- c:\program files\Common Files\Apple
2009-11-04 16:33 . 2009-11-04 16:33 -------- d-----w- c:\program files\Apple Software Update
2009-11-04 16:33 . 2009-11-04 16:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-11-04 15:53 . 2009-04-20 20:21 -------- d-----w- c:\documents and settings\Mandic\Application Data\TeamViewer
2009-11-04 15:28 . 2008-10-11 08:12 -------- d-----w- c:\documents and settings\Mandic\Application Data\BSplayer PRO
2009-11-03 19:19 . 2009-04-20 20:21 -------- d-----w- c:\program files\TeamViewer
2009-11-01 17:17 . 2008-10-10 21:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-01 16:04 . 2009-11-01 16:04 -------- d-----w- c:\documents and settings\Mandic\Application Data\360desktop
2009-10-30 23:52 . 2009-10-30 23:52 -------- d-----w- c:\documents and settings\Mandic\Application Data\Apple Computer
2009-10-29 14:21 . 2009-10-29 14:21 -------- d-----w- c:\documents and settings\LocalService\Application Data\CyberLink
2009-10-28 23:15 . 2008-10-03 08:24 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-10-28 23:12 . 2008-12-07 13:03 -------- d-----w- c:\documents and settings\Mandic\Application Data\CyberLink
2009-10-28 23:10 . 2008-10-03 07:45 77208 ----a-w- c:\documents and settings\Mandic\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-25 17:30 . 2009-10-25 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-10-24 20:21 . 2009-10-24 20:21 -------- d-----w- c:\program files\Fun Web Products
2009-10-24 17:16 . 2009-10-24 17:16 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-10-24 17:16 . 2009-10-24 17:16 -------- d-----w- c:\program files\TechSmith
2009-10-23 12:00 . 2009-10-23 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-10-21 18:19 . 2009-10-21 18:09 -------- d-----w- c:\documents and settings\Mandic\Application Data\Eltima Software
2009-10-21 12:49 . 2009-10-21 12:49 -------- d-----w- c:\program files\Xilisoft
2009-10-21 12:35 . 2009-10-21 12:16 -------- d-----w- c:\program files\Real Alternative
2009-10-21 12:25 . 2008-10-11 08:37 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-21 07:52 . 2009-06-10 13:13 -------- d-----w- c:\program files\Garena
2009-10-13 18:00 . 2009-10-21 12:25 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-09-14 08:36 . 2009-10-21 12:25 758018 ----a-w- c:\windows\system32\xvidcore.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 25088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"BootSkin Startup Jobs"="c:\program files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 270336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
c:\documents and settings\Mandic\Start Menu\Programs\Startup\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-21 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"IncrediMail"=c:\program files\IncrediMail\bin\IncMail.exe /c
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"Magentic"=c:\progra~1\Magentic\bin\Magentic.exe /c
"RegistryMechanic"=c:\program files\Registry Mechanic\RegMech.exe /H
"Vidalia"="c:\program files\Vidalia Bundle\Vidalia\vidalia.exe"
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"MyWebSearch Email Plugin"=c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" -lang 1033
"Easy-PrintToolBox"=c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe"
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" -r
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"MyWebSearch Email Plugin"=c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Mandic\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\Capcom\\Bionic Commando\\bionic_commando.exe"=
"c:\\Program Files\\Capcom\\Bionic Commando\\Support\\CAP1-0101.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/10/2008 21:02 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [10/10/2008 19:22 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 10:01 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 10:01 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [10/10/2008 19:22 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [07/11/2009 17:57 54752]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 10:01 7408]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
S3 FStarForce;FStarForce;c:\windows\system32\drivers\FStarForce.sys [30/01/2009 21:07 8192]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Mandic\LOCALS~1\Temp\VDI34.tmp --> c:\docume~1\Mandic\LOCALS~1\Temp\VDI34.tmp [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mystart.incredimail.com/
mStart Page = hxxp://home.sweetim.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.avast.com/eng/avast_4_professional.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Mandic\Application Data\Mozilla\Firefox\Profiles\qqdhikh1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/intl/sr/
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJfox000&fl=0&ptb=S2PrLFhGmjrzwyi7dApY4g&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - plugin: c:\documents and settings\Mandic\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-Easy-PhotoPrint - c:\program files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
AddRemove-Easy-PrintToolBox - c:\program files\Canon\Easy-PrintToolBox\uninst.exe uninst.ini
AddRemove-MediaNavigation.CDLabelPrint - c:\program files\Canon\CD-LabelPrint\Uninstal.exe Canon.CDLabelPrint.Application
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-06 23:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys >>UNKNOWN [0x89DE41F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb80fcfc3
\Driver\ACPI -> ACPI.sys @ 0xb7e3fcb8
\Driver\atapi -> sfsync02.sys @ 0xb80c98b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8058236c
ParseProcedure -> ntkrnlpa.exe @ 0x8058146a
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8058236c
ParseProcedure -> ntkrnlpa.exe @ 0x8058146a
NDIS: Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xb7cdeba0
PacketIndicateHandler -> NDIS.sys @ 0xb7cebb21
SendHandler -> NDIS.sys @ 0xb7cc987b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Mandic\LOCALS~1\Temp\VDI34.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-839522115-1390067357-2147167427-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7D08336D-B457-EBC3-1FF4-A3BCB1C72D8F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"panppaicpjnmmoppjmdppdhendahgkdj"=hex:6a,61,6b,67,6f,61,66,66,6e,66,70,69,6a,
6c,63,66,6e,70,65,6c,00,7f
"oahancomoilngjcgkcapbndhoojpmk"=hex:6a,61,6b,67,6f,61,66,66,6e,66,70,69,6a,6c,
63,66,6e,70,65,6c,00,7f
[HKEY_USERS\S-1-5-21-839522115-1390067357-2147167427-1003\Software\SecuROM\License information*]
"datasecu"=hex:7d,30,6a,81,60,1e,24,04,2a,8e,85,ee,e1,13,2a,5d,77,95,cf,9c,37,
19,f9,54,72,98,d5,f8,07,d3,74,5f,b1,39,6a,e9,a6,4d,fe,5b,1b,8a,0f,94,c5,d8,\
"rkeysecu"=hex:15,29,29,60,41,81,cd,b4,c9,9e,93,41,c3,0e,69,92
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\sfc_os.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\Mandic\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\cscui.dll
c:\windows\system32\COMRes.dll
- - - - - - - > 'explorer.exe'(2888-)
c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.dll
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\TUProgSt.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Completion time: 2009-12-06 23:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-06 22:27
Pre-Run: 6,550,351,872 bytes free
Post-Run: 6,477,574,144 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - BC67D0EDBDC5C4B9D9C9BDAD7DDD4A30
|