offline
- Pridružio: 28 Jan 2009
- Poruke: 76
|
Uradjeno i to:
ComboFix 09-01-21.04 - Nikola 2009-01-28 17:31:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.575 [GMT 1:00]
Running from: C:\Documents and Settings\Nikola\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090127-0] *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090126215149683.log
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
C:\Documents and Settings\Nikola\Favorites\Download programs.url
C:\Documents and Settings\Nikola\Favorites\Games.url
C:\Documents and Settings\Nikola\Favorites\Online Security Test.url
C:\Documents and Settings\Nikola\Favorites\Translator.url
C:\Documents and Settings\Nikola\Favorites\Videos.url
C:\Documents and Settings\Nikola\Start Menu\Programs\Download programs.url
C:\Documents and Settings\Nikola\Start Menu\Programs\Games.url
C:\Documents and Settings\Nikola\Start Menu\Programs\Translator.url
C:\Documents and Settings\Nikola\Start Menu\Programs\Videos.url
C:\Program Files\Sotfone
C:\WINDOWS\jestertb.dll
C:\WINDOWS\system32\divx.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ISODRIVE
-------\Service_ISODrive
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-28 )))))))))))))))))))))))))))))))
.
2009-01-28 13:55 . 2009-01-28 13:55 45,106 -r-hs---- C:\WINDOWS\usbservice.exe
2009-01-28 13:55 . 2009-01-28 13:55 45,106 --a------ C:\WINDOWS\system32\mf.exe
2009-01-26 22:09 . 2009-01-26 22:09 244 --ah----- C:\sqmnoopt15.sqm
2009-01-26 22:09 . 2009-01-26 22:09 232 --ah----- C:\sqmdata15.sqm
2009-01-26 22:05 . 2009-01-26 22:05 244 --ah----- C:\sqmnoopt14.sqm
2009-01-26 22:05 . 2009-01-26 22:05 232 --ah----- C:\sqmdata14.sqm
2009-01-26 21:57 . 2009-01-26 21:57 1,507,328 --a------ C:\WINDOWS\system32\ru.exe
2009-01-26 21:51 . 2009-01-26 22:08 81,931 --a------ C:\nssetup.exe
2009-01-26 21:49 . 2009-01-26 21:49 1,507,328 --a------ C:\WINDOWS\system32\iw.exe
2009-01-26 21:48 . 2009-01-26 21:49 1,507,328 --a------ C:\WINDOWS\system32\gv.exe
2009-01-26 20:12 . 2009-01-26 20:12 268 --ah----- C:\sqmdata13.sqm
2009-01-26 20:12 . 2009-01-26 20:12 244 --ah----- C:\sqmnoopt13.sqm
2009-01-26 15:16 . 2009-01-26 15:16 268 --ah----- C:\sqmdata12.sqm
2009-01-26 15:16 . 2009-01-26 15:16 244 --ah----- C:\sqmnoopt12.sqm
2009-01-26 11:48 . 2009-01-26 11:48 268 --ah----- C:\sqmdata11.sqm
2009-01-26 11:48 . 2009-01-26 11:48 244 --ah----- C:\sqmnoopt11.sqm
2009-01-14 14:48 . 2009-01-14 14:48 <DIR> d-------- C:\Documents and Settings\Nikola\Application Data\ImTOO Software Studio
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- C:\Program Files\Moyea
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- C:\Documents and Settings\Nikola\Application Data\Moyea
2009-01-14 14:33 . 2008-08-28 18:56 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll
2009-01-14 14:24 . 2009-01-14 14:34 <DIR> d-------- C:\My FLVs
2009-01-14 14:23 . 2009-01-14 14:28 <DIR> d-------- C:\Program Files\YouTubeRobot
2009-01-14 14:23 . 2007-02-28 13:30 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2009-01-14 14:23 . 2007-02-28 13:30 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2009-01-14 14:23 . 2007-02-28 13:32 716,800 --a------ C:\WINDOWS\system32\lameACM.acm
2009-01-14 14:23 . 2007-02-28 13:30 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2009-01-14 14:23 . 2007-02-28 13:30 577,536 --a------ C:\WINDOWS\system32\divxdec.ax
2009-01-14 14:23 . 2007-02-28 13:33 389,120 --a------ C:\WINDOWS\system32\actskn43.ocx
2009-01-14 14:23 . 2007-02-28 13:30 294,912 --a------ C:\WINDOWS\system32\dpu11.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ C:\WINDOWS\system32\dtu100.dll
2009-01-14 14:23 . 2007-02-28 13:30 86,016 --a------ C:\WINDOWS\system32\dpl100.dll
2009-01-14 14:23 . 2007-02-28 13:30 57,344 --a------ C:\WINDOWS\system32\dpv11.dll
2009-01-14 14:23 . 2007-02-28 13:32 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- C:\Program Files\UltraISO
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- C:\Program Files\Common Files\EZB Systems
2009-01-08 12:25 . 2009-01-21 13:10 238 --a------ C:\WINDOWS\mafosav.INI
2009-01-08 12:22 . 2009-01-08 12:22 <DIR> d-------- C:\Buziol Games
2009-01-04 10:42 . 2009-01-04 10:43 35 --a------ C:\WINDOWS\mstutor.ini
2009-01-02 10:55 . 2009-01-02 10:55 <DIR> d-------- C:\Program Files\Xilisoft
2008-12-31 14:49 . 2008-12-31 14:49 <DIR> d-------- C:\svadba
2008-12-31 14:04 . 2008-12-31 14:04 <DIR> d-------- C:\Program Files\DVD Shrink
2008-12-31 14:04 . 2008-12-31 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-12-31 13:58 . 2008-12-31 13:58 <DIR> d-------- C:\Program Files\DVD Decrypter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 09:59 --------- d-----w C:\Documents and Settings\Nikola\Application Data\advantage
2009-01-27 17:10 --------- d-----w C:\Program Files\The KMPlayer
2009-01-14 13:48 --------- d-----w C:\Program Files\ImTOO
2009-01-14 13:42 --------- d-----w C:\Program Files\Total Video Converter
2009-01-08 18:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-01-08 12:18 --------- d-----w C:\Documents and Settings\Nikola\Application Data\LimeWire
2009-01-02 14:30 --------- d-----w C:\Documents and Settings\Nikola\Application Data\dvdcss
2008-12-31 16:48 --------- d-----w C:\Documents and Settings\Nikola\Application Data\Skype
2008-12-31 15:07 --------- d-----w C:\Documents and Settings\Nikola\Application Data\skypePM
2008-12-24 11:58 --------- d-----w C:\Program Files\YoutubeGet
2008-12-14 13:33 --------- d-----w C:\Program Files\Folder Lock
2008-12-12 09:46 --------- d-----w C:\Program Files\Realtek AC97
2008-12-04 20:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-12-04 12:15 --------- d-----w C:\Program Files\WMV9_VCM
2008-12-04 12:12 --------- d-----w C:\Program Files\1C
2008-12-04 11:54 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-12-04 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-12-04 11:53 --------- d-----w C:\Documents and Settings\Nikola\Application Data\DAEMON Tools Pro
2008-12-04 11:51 --------- d-----w C:\Program Files\advantage
2008-12-04 11:46 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-14 05:27 9,016 ----a-w C:\Program Files\tempdecal.wad
2004-07-22 09:51 3,432,656 ----a-w C:\Program Files\ManagedDX.CAB
2004-07-19 21:58 1,156,363 ----a-w C:\Program Files\BDANT.cab
2004-07-19 21:53 976,020 ----a-w C:\Program Files\BDAXP.cab
2004-07-16 13:30 3,858 ----a-w C:\Program Files\directx redist.txt
2004-07-09 13:17 13,265,040 ----a-w C:\Program Files\dxnt.cab
2004-07-09 08:13 703,080 ----a-w C:\Program Files\BDA.cab
2004-07-09 08:13 15,493,481 ----a-w C:\Program Files\DirectX.cab
2004-07-09 03:08 472,576 ----a-w C:\Program Files\dxsetup.exe
2004-07-09 03:08 2,242,560 ----a-w C:\Program Files\dsetup32.dll
2004-07-09 02:03 62,976 ----a-w C:\Program Files\DSETUP.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 15:21 1449984]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 11:54 5674352]
"AdVantage"="C:\Documents and Settings\Nikola\Application Data\advantage\AdVantage.exe" [2008-12-04 12:51 175024]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-05 15:15 273864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 17:00 98304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 11:36 229376]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35 90112]
"KMCONFIG"="C:\Program Files\Mouse Driver\StartAutorun.exe" [2007-03-06 14:51 212992]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 20:10 339968]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-24 15:27 180269]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 18:18 81000]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2002-01-01 01:48 98304]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 03:50 88363 C:\WINDOWS\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"C-Media Mixer"="Mixer.exe" [2003-03-20 15:21 1855488 C:\WINDOWS\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54 5674352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"vidc.X264"= x264vfw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"WinampAgent"=C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\zBoT Counter 1.6\\hl.exe"=
"C:\\Program Files\\ApexDC++\\ApexDC.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Opera\\opera.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\WINDOWS\\usbservice.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3478:UDP"= 3478:UDP:stun
"3479:UDP"= 3479:UDP:stun 2
"6112:UDP"= 6112:UDP:stun 3
"5730:UDP"= 5730:UDP:game
"5739:UDP"= 5739:UDP:game 1
"9001:TCP"= 9001:TCP:game 2
"11881:TCP"= 11881:TCP:game 3
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-12-14 14:06:24 111184]
R4 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [2008-12-14 14:06:24 20560]
R4 KMWDSERVICE;Keyboard And Mouse Communication Service;C:\Program Files\Mouse Driver\KMWDSrv.exe [2007-04-05 10:29:28 208896]
S4 Usb Service 2.0;Usb Service 2.0;C:\WINDOWS\usbservice.exe [2009-01-28 13:55:21 45106]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-16 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-MS AntiSpyware 2009 - C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/star
uInternet Settings,ProxyOverride = *.local
IE: Download all by YouTube Robot - C:\Program Files\YouTubeRobot\RobotExt.ocx/ALL.HTM
IE: Download by YouTube Robot - C:\Program Files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-28 17:37:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3E3786AA-5288-665B-DF40-0490A1A5049B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iajdmfhanbcdcgadpg"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01
"jajeakffndmddjklomho"=hex:62,61,66,63,00,00
"jajeakffndmddjklomdo"=hex:62,61,6b,63,00,00
"hahekfgcipbjfdbf"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01
[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A1A06CD3-E41F-1C1E-ECC2-DB2832F4F556}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaejogeiodcfbekjga"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
"japjoiodakalpbmgdpgo"=hex:62,61,6c,66,00,00
"jaljkkknoabjnadiohae"=hex:62,61,63,67,00,00
"hahdcjiipgkckfpf"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Mouse Driver\KMCONFIG.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Mouse Driver\KMProcess.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-01-28 17:40:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-28 16:40:24
Pre-Run: 5,171,150,848 bytes free
Post-Run: 5,219,622,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
270
|