offline
- zoox
- Novi MyCity građanin
- Pridružio: 19 Mar 2009
- Poruke: 7
|
log koji je napravio combofix
ComboFix 09-03-22.01 - Administrator 2009-03-23 9:37:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1014.518 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\cfxer.exe
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\windows\IE4 Error Log.txt
c:\windows\n.tmp
c:\windows\winsystem.exe
----- BITS: Possible infected sites -----
hxxp://kap-srv-ex1.kap.me
.
((((((((((((((((((((((((( Files Created from 2009-02-23 to 2009-03-23 )))))))))))))))))))))))))))))))
.
2009-03-23 09:02 . 2009-03-23 09:02 <DIR> d-------- c:\documents and settings\radomir.dasic\Tracing
2009-03-23 09:02 . 2009-03-23 09:02 <DIR> d-------- c:\documents and settings\radomir.dasic\Application Data\Internet Saving Optimizer
2009-03-23 09:02 . 2009-03-23 09:05 <DIR> d-------- c:\documents and settings\radomir.dasic\Application Data\AVGTOOLBAR
2009-03-23 09:02 . 2009-03-23 09:02 37,662 --a------ c:\documents and settings\radomir.dasic\iemultjx.exe
2009-03-23 09:02 . 2009-03-23 09:02 33,634 --a------ c:\documents and settings\radomir.dasic\cmgrs.exe
2009-03-23 09:02 . 2009-03-23 09:02 8,552 --a------ c:\documents and settings\radomir.dasic\bv2.exe
2009-03-23 09:01 . 2009-03-23 09:01 30,782 --a------ c:\documents and settings\radomir.dasic\mscupdate.exe
2009-03-23 09:01 . 2009-03-23 09:01 18,944 --a------ c:\documents and settings\radomir.dasic\tvs2.exe
2009-03-23 06:44 . 2009-03-23 09:19 37,662 --a------ c:\windows\system32\iemultjx.exe
2009-03-20 14:44 . 2009-03-23 09:18 33,634 --a------ c:\documents and settings\Administrator\cmgrs.exe
2009-03-20 14:44 . 2009-03-23 06:43 8,552 --a------ c:\documents and settings\Administrator\bv2.exe
2009-03-20 08:45 . 2009-03-20 11:14 <DIR> d-------- c:\program files\UseNeXT
2009-03-20 08:45 . 2009-03-20 14:18 <DIR> d-------- c:\documents and settings\Administrator\Application Data\UseNeXT
2009-03-20 08:33 . 2009-03-20 08:38 26,624 --a------ c:\temp\Project1.exe
2009-03-19 13:19 . 2009-03-23 09:18 18,944 --a------ c:\documents and settings\Administrator\tvs2.exe
2009-03-19 09:37 . 2009-03-19 09:38 <DIR> d-------- C:\rsit
2009-03-19 08:26 . 2009-03-19 08:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-19 08:26 . 2009-03-20 14:35 <DIR> d-------- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-03-18 12:29 . 2009-03-18 12:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\espionServerData
2009-03-16 09:28 . 2008-10-27 18:37 192,307 --a------ C:\wubildr
2009-03-16 09:28 . 2008-10-27 18:37 8,192 --a------ C:\wubildr.mbr
2009-03-16 09:23 . 2009-03-16 09:23 <DIR> d-------- C:\ubuntu
2009-03-13 11:36 . 2009-03-13 11:41 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Samsung
2009-03-13 11:34 . 2009-03-16 06:43 <DIR> d-------- c:\windows\system32\Samsung_USB_Drivers
2009-03-13 11:34 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2009-03-13 11:34 . 2006-07-24 16:05 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2009-03-13 11:34 . 2005-08-28 20:51 766 --a------ c:\windows\system32\Uninstall.ico
2009-03-13 11:04 . 2009-03-13 11:04 <DIR> d-------- c:\program files\Common Files\PCSuite
2009-03-13 11:04 . 2009-03-13 11:04 <DIR> d-------- c:\program files\Common Files\Nokia
2009-03-13 11:04 . 2008-09-15 07:29 1,112,288 --a------ c:\windows\system32\wdfcoinstaller01007.dll
2009-03-13 11:04 . 2008-09-15 07:56 659,968 --a------ c:\windows\system32\nmwcdcocls.dll
2009-03-13 11:04 . 2008-09-15 07:56 22,016 --a------ c:\windows\system32\drivers\ccdcmbo.sys
2009-03-13 11:04 . 2008-09-15 07:56 17,664 --a------ c:\windows\system32\drivers\ccdcmb.sys
2009-03-13 11:04 . 2008-09-15 07:56 8,064 --a------ c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-03-13 11:04 . 2008-09-15 07:56 8,064 --a------ c:\windows\system32\drivers\usbser_lowerflt.sys
2009-03-13 10:42 . 2009-03-13 10:42 <DIR> d-------- c:\program files\Oxygen Software
2009-03-11 14:31 . 2009-03-13 06:42 <DIR> d-------- c:\program files\Chess
2009-03-11 11:12 . 2009-03-11 11:12 <DIR> d-------- c:\program files\VS Revo Group
2009-03-11 09:58 . 2009-03-11 09:58 <DIR> d-------- c:\program files\directx
2009-03-11 09:57 . 2009-03-11 09:57 <DIR> d-------- c:\program files\Rockstar Games
2009-03-09 12:18 . 2009-03-09 12:20 <DIR> d-------- C:\BMW M3 Challenge
2009-03-06 10:32 . 2009-03-23 09:18 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-06 10:00 . 2009-03-06 10:00 325,640 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-06 10:00 . 2009-03-06 10:00 107,912 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-06 10:00 . 2009-03-06 10:00 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-06 09:59 . 2009-03-23 06:44 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-06 09:59 . 2009-03-06 09:59 <DIR> d-------- c:\program files\AVG
2009-03-06 09:59 . 2009-03-06 09:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-06 09:59 . 2009-03-06 10:04 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AVGTOOLBAR
2009-03-06 09:09 . 2008-09-25 14:27 905,216 --a------ c:\windows\system32\GearDrvs.msi
2009-03-06 08:51 . 2009-03-06 08:51 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Symantec
2009-03-06 08:40 . 2009-03-06 09:48 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-03-05 13:19 . 2008-04-14 01:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-03-05 13:19 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-03-05 13:19 . 2008-04-13 19:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-03-05 13:19 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-03-03 07:10 . 2009-03-03 07:10 <DIR> d-------- c:\documents and settings\Administrator\Application Data\IObit
2009-02-26 14:22 . 2009-02-26 14:22 <DIR> d-------- c:\documents and settings\Administrator\Application Data\ACD Systems
2009-02-26 14:21 . 2009-02-26 14:21 <DIR> d-------- c:\program files\ACD Systems
2009-02-26 14:21 . 2009-02-26 14:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\ACD Systems
2009-02-24 10:56 . 2009-03-11 11:14 <DIR> d-------- c:\program files\EA GAMES
2009-02-24 10:08 . 2009-02-24 10:08 0 --a------ C:\-1464429064
2009-02-24 08:44 . 2009-03-06 09:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec
2009-02-24 08:42 . 2009-02-24 08:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-02-24 08:37 . 2009-02-24 08:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-24 07:17 . 2009-02-24 10:56 <DIR> d-------- c:\program files\City Interactive
2009-02-23 14:28 . 2009-02-24 10:56 <DIR> d-------- c:\program files\NokiaFREE Unlock Codes Calculator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 07:15 --------- d-----w c:\program files\Windows Desktop Search
2009-03-18 11:11 --------- d-----w c:\program files\Common Files\Adobe
2009-03-18 11:07 9,464 ------w c:\windows\system32\drivers\cdralw2k.sys
2009-03-18 11:07 9,336 ------w c:\windows\system32\drivers\cdr4_xp.sys
2009-03-18 11:07 43,528 ------w c:\windows\system32\drivers\PxHelp20.sys
2009-03-13 10:34 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-13 10:17 --------- d-----w c:\documents and settings\Administrator\Application Data\Nokia
2009-03-13 10:04 --------- d-----w c:\program files\Nokia
2009-03-13 09:57 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-03-12 02:00 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-11 10:07 --------- d-----w c:\program files\Mobiola Web Camera 2 for S60 2nd Edition
2009-03-11 10:06 --------- d-----w c:\program files\Hair Pro 2008 Light
2009-03-11 10:05 --------- d-----w c:\program files\3D Home Architect
2009-03-06 08:48 --------- d-----w c:\program files\Di recnik
2009-03-03 06:10 --------- d-----w c:\program files\IObit
2009-02-27 09:28 --------- d-----w c:\program files\Pawn 2
2009-02-26 13:21 --------- d-----w c:\program files\Common Files\ACD Systems
2009-02-24 09:56 --------- d-----w c:\documents and settings\Administrator\Application Data\uTorrent
2009-02-20 06:57 --------- d-----w c:\program files\uTorrent
2009-02-20 06:30 --------- d-----w c:\program files\Nice Prosper
2009-02-20 06:30 --------- d-----w c:\documents and settings\Administrator\Application Data\Internet Saving Optimizer
2009-02-20 06:29 --------- d-----w c:\program files\System Search Dispatcher
2009-02-20 06:29 --------- d-----w c:\program files\Internet Saving Optimizer
2009-02-20 06:29 --------- d-----w c:\program files\DoubleD
2009-02-20 06:26 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-20 06:21 --------- d-----w c:\documents and settings\Administrator\Application Data\funkitron
2009-02-18 12:12 --------- d-----w c:\program files\Java
2009-02-18 08:44 --------- d-----w c:\program files\NeoTracePro
2009-02-16 12:20 --------- d-----w c:\program files\Windows Live
2009-02-16 12:19 --------- d-----w c:\program files\Microsoft Sync Framework
2009-02-16 12:17 --------- d-----w c:\program files\Windows Live SkyDrive
2009-02-16 12:17 --------- d-----w c:\program files\Microsoft
2009-02-16 11:55 --------- d-----w c:\program files\Common Files\Windows Live
2009-02-16 10:42 --------- d-----w c:\program files\FastStone Capture
2009-02-16 10:42 --------- d-----w c:\documents and settings\Administrator\Application Data\FastStone
2009-02-16 06:24 --------- d-----w c:\documents and settings\radomir.dasic\Application Data\Nokia
2009-02-12 13:09 --------- d-----w c:\documents and settings\All Users\Application Data\Nokia
2009-02-12 12:58 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-12 12:58 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-02-12 12:50 --------- d-----w c:\program files\PC Connectivity Solution
2009-02-12 12:44 --------- d-----w c:\documents and settings\Administrator\Application Data\PC Suite
2009-02-12 12:33 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2009-02-12 12:29 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-02-12 12:24 --------- d-----w c:\program files\Foxit Software
2009-02-11 07:24 --------- d-----w c:\program files\Common Files\Borland Shared
2009-02-11 07:22 --------- d-----w c:\program files\Borland
2009-02-10 07:09 --------- d-----w c:\program files\Jetpak
2009-02-10 07:07 --------- d-----w c:\program files\OpenOffice.org 3
2009-02-10 07:05 --------- d-----w c:\program files\Ulead Systems
2009-02-10 07:05 --------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2009-02-10 07:05 --------- d-----w c:\documents and settings\Administrator\Application Data\Ulead Systems
2009-02-10 06:56 --------- d-----w c:\program files\Microsoft Visual Studio 8
2009-02-10 06:56 --------- d-----w c:\program files\ImgBurn
2009-02-10 06:55 --------- d-----w c:\program files\Google
2009-02-10 06:55 --------- d-----w c:\program files\Common Files\Softwin
2009-02-10 06:55 --------- d-----w c:\program files\Common Files\BitDefender
2009-02-06 18:20 308,088 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 17:08 55,152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-01-30 08:47 --------- d-----w c:\program files\Simbin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-11 143360]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-11 172032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-11 143360]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-06 1932568]
"iemultjx"="c:\windows\system32\iemultjx.exe" [2009-03-23 37662]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-06 10:00 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.dvacm"= c:\progra~1\COMMON~1\Ulead Systems\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\COMMON~1\Ulead Systems\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\COMMON~1\Ulead Systems\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2008-10-14 21:38 623992 c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-09-11 00:43 67488 c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
--a------ 2008-11-26 16:11 2235920 c:\program files\IObit\Advanced SystemCare 3\AWC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Di dictionary]
--a------ 2007-03-16 20:45 518656 c:\program files\Di recnik\Di.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-26 23:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpbdfawep]
--a------ 2007-04-25 14:28 954368 c:\program files\HP\Dfawep\bin\hpbdfawep.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPUsageTracking]
--a------ 2007-05-04 13:14 36864 c:\program files\HP\HP UT\bin\hppusg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iemultjx]
--a------ 2009-03-23 09:19 37662 c:\windows\system32\iemultjx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-06-24 15:06 1840424 c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 01:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2009-02-06 18:50 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-06-08 08:31 2221352 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-06-19 08:53 570664 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-11-10 15:07 1253376 c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2008-12-03 12:47 1205760 c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-08-07 01:05 200704 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-02-18 13:12 148888 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-10-24 05:56 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-20 08:16 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
--a------ 2007-03-03 13:12 341488 c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherWatcher]
--a------ 2008-11-18 20:19 1081344 c:\program files\Weather Watcher\ww.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-03 17:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2007-04-12 16:33 16132608 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-06 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-06 107912]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-06 298264]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-02-16 55152]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2004-08-03 14336]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S3 fsssvc;Windows Live Porodična bezbednost;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 PortTalk;PortTalk;c:\windows\system32\drivers\PortTalk.sys [2009-02-16 3567]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\CDStart.Exe
\Shell\Install\Command - F:\Stub.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe /CD
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\CDStart.Exe
\Shell\Install\Command - H:\Stub.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-20 c:\windows\Tasks\HP WEP.job
- c:\program files\HP\Dfawep\bin\hpbdfawep.exe [2007-04-25 14:28]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Windows API Control Center - winsystem.exe
Notify-WgaLogon - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSConfigStartUp-Windows API Control Center - winsystem.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=10&ct=1234853227&rver=5.5.4177.0&wp=MBI&wreply=http:%2F%2Fhome.live.com%2Fdefault.aspx&lc=2074&id=251248
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &NeoTrace It! - c:\progra~1\NeoTracePro\NTXcontext.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-23 09:41:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-606747145-1482476501-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,df,92,f9,b5,0e,e2,50,41,bf,be,0c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,df,92,f9,b5,0e,e2,50,41,bf,be,0c,\
[HKEY_USERS\S-1-5-21-606747145-1482476501-839522115-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{918FA53A-2301-115E-ACBC-7C90ED481B25}*]
"habfaoeilfhpoicb"=hex:6a,61,6f,6f,6e,6b,6b,6a,66,6c,6d,69,66,63,64,6f,69,70,
62,62,00,00
"iadfokhghkpdifikmh"=hex:6a,61,6f,6f,6e,6b,6b,6a,66,6c,6d,69,66,63,64,6f,69,70,
62,62,00,00
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{918FA53A-2301-115E-ACBC-7C90ED481B25}\InProcServer32*]
"fanfnfeinpll"=hex:70,61,69,6f,69,6e,67,70,6a,64,69,6b,6b,6e,66,68,61,68,6e,68,
67,6c,66,6f,67,6a,6a,70,69,6b,62,6e,00,09
"nanfhdkckieeodggojgboinejpff"=hex:70,61,69,65,6d,6c,6a,6a,6f,66,64,63,64,6a,
6f,66,62,6d,68,66,67,6e,6d,62,6b,6e,64,61,67,65,64,62,00,09
[HKEY_LOCAL_MACHINE\software\MyWebSearch\SearchAssistant]
@DACL=(02 0000)
"pid"="ZRman000"
"fwp"="0"
"Dir"="c:\\Program Files\\MyWebSearch\\SrchAstt\\"
"sr"="11"
"pl"="26"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\spool\drivers\w32x86\3\HP1006MC.EXE
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2009-03-23 9:44:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-23 08:44:04
Pre-Run: 35.217.403.904 bytes free
Post-Run: 35,277,467,648 bytes free
349 --- E O F --- 2009-03-12 02:01:15
|