offline
- x-Death-x
- Počasni građanin
- Pridružio: 12 Avg 2008
- Poruke: 708
- Gde živiš: Bogu iza tregera!
|
Napisano: 14 Jan 2012 1:09
ComboFix 12-01-13.05 - Administrator 01/14/2012 0:55.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.247.5 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Files Created from 2011-12-14 to 2012-01-14 )))))))))))))))))))))))))))))))
.
.
2012-01-13 13:58 . 2012-01-13 13:58 -------- d-----w- c:\program files\Speccy
2012-01-13 13:39 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-01-13 13:39 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-01-13 13:39 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-01-13 13:39 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-01-13 13:39 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-01-13 13:39 . 2011-11-28 17:52 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-01-13 13:39 . 2011-11-28 17:51 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-01-13 13:39 . 2011-11-28 17:48 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-01-13 13:37 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2012-01-13 13:37 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2012-01-13 13:36 . 2012-01-13 16:52 -------- d-----w- c:\program files\Avast
2012-01-13 13:36 . 2012-01-13 13:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-01-13 13:35 . 2012-01-13 13:35 -------- d-----w- c:\program files\SIW
2012-01-13 12:55 . 2012-01-13 12:55 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-13 12:55 . 2012-01-13 12:55 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-13 12:55 . 2012-01-13 12:55 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-13 12:55 . 2012-01-13 12:55 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-12 23:27 . 2012-01-12 23:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2012-01-12 23:11 . 2012-01-12 23:24 -------- d-----w- c:\program files\Common Files\Ahead
2012-01-12 23:11 . 2012-01-12 23:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2012-01-12 23:11 . 2012-01-12 23:11 -------- d-----w- c:\program files\Nero
2012-01-12 23:08 . 2004-08-11 00:45 47616 ----a-w- c:\program files\Windows Media Player\msoobci.dll
2012-01-12 23:08 . 2004-08-11 00:45 819200 ----a-w- c:\program files\Windows Media Player\wmsetsdk.exe
2012-01-12 20:23 . 2012-01-12 20:23 -------- d-----w- c:\program files\uTorrent
2012-01-12 20:22 . 2012-01-12 22:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2012-01-11 15:02 . 2012-01-11 15:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics
2012-01-11 13:18 . 2012-01-11 13:18 -------- d-----w- c:\program files\Common Files\Java
2012-01-11 13:17 . 2012-01-11 13:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-01-11 13:16 . 2012-01-11 13:16 -------- d-----w- c:\program files\Java
2012-01-11 13:07 . 2012-01-11 13:20 -------- d-----w- c:\program files\JDownloader
2012-01-11 13:07 . 2012-01-11 13:07 -------- d-----w- c:\program files\Common Files\i4j_jres
2011-12-26 18:40 . 2011-12-26 18:40 -------- d-----w- C:\SG Interactive
2011-12-26 17:53 . 2011-12-26 20:26 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\PMB Files
2011-12-26 17:53 . 2011-12-26 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2011-12-26 17:53 . 2011-12-26 17:53 -------- d-----w- c:\program files\Pando Networks
2011-12-25 18:59 . 2011-12-25 18:59 -------- d-----w- c:\documents and settings\Administrator\Application Data\CyberLink
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-11 13:16 . 2011-12-02 14:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-29 14:45 . 2011-11-29 14:45 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-19 06:01 . 2011-11-19 06:01 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-11-19 06:01 . 2011-11-19 06:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-01-13 12:55 . 2011-10-04 07:59 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-11-19 296056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"avast"="c:\program files\Avast\avastUI.exe" [2011-11-28 3744552]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57098:TCP"= 57098:TCP:Pando Media Booster
"57098:UDP"= 57098:UDP:Pando Media Booster
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [1/13/2012 2:39 PM 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/13/2012 2:39 PM 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/13/2012 2:39 PM 20568]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASWSNX
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-484763869-1417001333-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-09 22:31]
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-484763869-1417001333-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-09 22:31]
.
2012-01-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-484763869-1417001333-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-09 00:14]
.
2012-01-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-484763869-1417001333-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-09 00:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.drp.su/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 77.239.64.19 77.239.64.20
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\p2zhb4ag.default\
FF - prefs.js: browser.startup.homepage - www.google.com
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-RealPlayer 15.0 - c:\program files\real\realplayer\Update\r1puninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-14 01:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-484763869-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0e,ac,a0,8d,79,c6,04,41,83,aa,c2,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0e,ac,a0,8d,79,c6,04,41,83,aa,c2,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3200)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2012-01-14 01:09:09
ComboFix-quarantined-files.txt 2012-01-14 00:09
.
Pre-Run: 9,128,505,344 bytes free
Post-Run: 10,489,790,464 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - DB3A35249723B3E930DB3F2B6374F928
Dopuna: 14 Jan 2012 1:10
Izvini sto si cekao, ipak je nova(Pravoslavna).
Pa nek ti bude srecna i sa puno uspjeha!!!(oprosti ako je ne slavis)
I izvini za neke greske ako ima posto sam pripit...
|