offline
- Pridružio: 25 Apr 2006
- Poruke: 46
|
ComboFix 09-01-21.04 - xp pro 2009-01-30 8:39:37.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1630 [GMT 1:00]
Running from: c:\documents and settings\xp pro\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated)
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-30 )))))))))))))))))))))))))))))))
.
2009-01-28 14:38 . 2009-01-28 16:42 <DIR> d-------- c:\program files\ESET
2009-01-22 11:10 . 2009-01-22 18:33 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-01-22 11:06 . 2009-01-22 11:06 <DIR> d-------- c:\program files\Lavasoft
2009-01-22 11:06 . 2009-01-22 11:06 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-22 11:06 . 2009-01-18 22:30 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-01-21 12:36 . 2009-01-21 12:38 <DIR> d-------- c:\program files\The KMPlayer
2009-01-17 11:03 . 2009-01-22 11:37 <DIR> d-------- c:\program files\K-Lite Codec Pack
2009-01-16 11:51 . 2009-01-16 11:51 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-14 19:58 . 2009-01-14 19:58 146 --a------ c:\windows\system32\test.aok
2009-01-14 19:49 . 2009-01-14 19:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-14 19:40 . 2009-01-14 19:42 3,652 --a------ c:\windows\desctemp.dat
2009-01-14 17:44 . 2009-01-14 17:44 <DIR> d-------- c:\program files\QuickTime
2009-01-14 17:29 . 2009-01-14 17:29 <DIR> d-------- c:\documents and settings\xp pro\.Nokia
2009-01-14 17:28 . 2009-01-14 17:29 <DIR> d--h----- c:\program files\Zero G Registry
2009-01-14 17:28 . 2009-01-14 17:28 <DIR> d--h----- c:\documents and settings\xp pro\InstallAnywhere
2009-01-14 02:26 . 2009-01-14 02:26 <DIR> d-------- c:\program files\Pure Networks
2009-01-10 21:44 . 2009-01-10 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Bluetooth
2009-01-10 21:41 . 2009-01-10 21:41 <DIR> d-------- c:\program files\IVT Corporation
2009-01-09 20:41 . 2009-01-22 11:12 <DIR> d-------- c:\windows\Luxor 4 - Quest for the Afterlife
2009-01-09 20:41 . 2009-01-09 20:43 <DIR> d-------- c:\program files\Luxor 4 - Quest for the Afterlife
2009-01-09 13:41 . 2004-01-11 23:00 348,160 --a------ c:\windows\system32\msvcr71.dll
2009-01-09 13:41 . 2007-09-04 17:56 164,352 --a------ c:\windows\system32\unrar.dll
2009-01-09 12:26 . 2009-01-30 08:35 <DIR> d-------- c:\program files\Mozilla Firefox 3.1 Beta 2
2009-01-09 11:48 . 2009-01-09 11:48 <DIR> d-------- c:\program files\Common Files\PCSuite
2009-01-09 11:48 . 2009-01-09 11:48 <DIR> d-------- c:\program files\Common Files\Nokia
2009-01-09 11:48 . 2009-01-09 11:48 <DIR> d-------- c:\program files\City Interactive
2009-01-09 11:48 . 2009-01-09 11:48 <DIR> d-------- c:\program files\aHisoft
2009-01-09 11:48 . 2009-01-30 08:38 <DIR> d-------- C:\My Videos
2009-01-09 11:48 . 2009-01-09 22:42 <DIR> d-------- C:\games
2009-01-09 11:48 . 2009-01-09 11:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\aHisoft
2009-01-09 11:18 . 2009-01-09 11:47 <DIR> d-------- c:\windows\DED53B0BB67C4244AE6AD6FD3C28D1EF(2).TMP
2009-01-08 15:42 . 2009-01-14 13:10 <DIR> d-------- c:\program files\SolSuite
2009-01-08 15:40 . 2009-01-09 11:22 <DIR> d-------- c:\program files\PC Connectivity Solution
2009-01-08 15:37 . 2009-01-08 15:37 <DIR> d-------- c:\program files\Escape From Paradise
2009-01-08 15:36 . 2009-01-08 15:36 <DIR> d-------- c:\program files\XP Repair Pro 2007
2009-01-08 15:36 . 2009-01-09 12:04 <DIR> d-------- c:\program files\Jardinains!
2009-01-08 15:36 . 2009-01-22 11:35 <DIR> d-------- c:\program files\GameHouse
2009-01-07 21:45 . 2009-01-07 21:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\InterAction studios
2009-01-05 13:21 . 2009-01-05 13:21 3,400 --a------ c:\windows\system32\PerfStringBackup.TMP
2009-01-04 21:20 . 2009-01-04 21:20 <DIR> d-------- c:\documents and settings\xp pro\Application Data\VMware
2008-12-30 14:21 . 2009-01-08 15:39 <DIR> d-------- c:\program files\X3mE Yamb
2008-12-30 14:09 . 2008-12-30 14:09 24 --a------ c:\windows\popcinfot.dat
2008-12-30 01:22 . 2009-01-08 15:39 <DIR> d-------- c:\program files\Weather Watcher Live
2008-12-30 01:22 . 2008-12-30 01:28 <DIR> d-------- c:\documents and settings\xp pro\Application Data\WeatherWatcherLive
2008-12-28 18:56 . 2008-12-28 18:56 <DIR> d-------- c:\windows\Logs
2008-12-28 18:39 . 2008-12-28 18:39 <DIR> d-------- c:\windows\system32\LogFiles
2008-12-24 20:51 . 2009-01-08 15:41 <DIR> d-------- c:\documents and settings\xp pro\Application Data\vlc
2008-12-24 20:50 . 2008-12-24 20:50 <DIR> d-------- c:\program files\VideoLAN
2008-12-24 20:35 . 2008-12-24 20:35 <DIR> d-------- c:\program files\Gabest
2008-12-24 18:20 . 2007-09-21 01:52 118,784 --a------ c:\windows\system32\ac3acm.acm
2008-12-24 17:20 . 2008-12-24 17:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\JollyBear
2008-12-24 15:01 . 2008-12-24 15:09 <DIR> d-------- c:\documents and settings\xp pro\Application Data\SolSuite
2008-12-24 15:01 . 2009-01-09 11:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\TreeCardGames
2008-12-10 22:14 . 2009-01-08 15:43 <DIR> d-------- c:\documents and settings\xp pro\Application Data\Hoyle Puzzle and Board Games
2008-12-10 22:14 . 2009-01-08 15:43 <DIR> d-------- c:\documents and settings\xp pro\Application Data\Hoyle FaceCreator
2008-12-05 16:54 . 2009-01-13 12:51 250 --a------ c:\windows\gmer.ini
2008-12-03 12:39 . 2008-01-07 14:29 352 --ah----- c:\windows\nod32fixtemdono.reg
2008-12-01 20:46 . 2008-12-01 20:46 <DIR> d-------- c:\documents and settings\xp pro\Application Data\Thinstall
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 07:33 --------- d-----w c:\documents and settings\xp pro\Application Data\uTorrent
2009-01-28 16:03 --------- d-----w c:\program files\Puzzle Express
2009-01-21 18:53 --------- d-----w c:\program files\Valve
2009-01-14 19:49 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-01-12 21:47 --------- d-----w c:\documents and settings\xp pro\Application Data\Vso
2009-01-12 21:46 81,920 ----a-w c:\documents and settings\xp pro\Application Data\ezpinst.exe
2009-01-12 21:46 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-01-12 21:46 47,360 ----a-w c:\documents and settings\xp pro\Application Data\pcouffin.sys
2009-01-12 12:14 --------- d-----w c:\program files\Video Convert Premier
2009-01-09 19:44 --------- d-----w c:\documents and settings\All Users\Application Data\MumboJumbo
2009-01-09 10:47 --------- d-----w c:\program files\Mozilla Firefox 3 Beta 5
2009-01-08 14:41 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-08 14:38 --------- d-----w c:\program files\ToGo Game
2009-01-08 14:37 --------- d-----w c:\program files\uTorrent
2008-12-29 12:18 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-12-09 09:38 --------- d-----w c:\program files\YouTubeRobot
2008-12-08 11:53 57,344 ----a-w c:\windows\system32\ff_vfw.dll
2008-12-07 18:08 795,648 ----a-w c:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w c:\windows\system32\xvidvfw.dll
2008-12-02 12:10 --------- d-----w c:\documents and settings\xp pro\Application Data\Gearbox Software
2008-12-01 19:49 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-30 11:46 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\Netsweeper
2008-11-26 19:25 16,376 ----a-w c:\windows\gdrv.sys
2008-10-27 12:39 26,555,220 ----a-w c:\windows\system32\ntx263769828.exe
2008-10-27 12:39 26,555,220 ----a-w c:\windows\system32\ntx263766796.exe
2007-07-26 19:00 23,800,756 ----a-w c:\program files\Burning Studio 7.1.0.exe
2002-07-01 14:13 224 --sha-w c:\documents and settings\xp pro\Application Data\maildriver32.dat
.
------- Sigcheck -------
2004-08-04 00:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\dllcache\tcpip.sys
2004-08-04 00:14 359040 27a5959c94ee173a063ca06bd14f021a c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-28 13516800]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-22 507224]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-04-23 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\xp pro\Start Menu\Programs\Startup\
æTorrent.lnk - c:\program files\uTorrent\uTorrent.exe [2008-07-10 220164]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Scheduler for OEM.lnk - c:\program files\honestech\honestech TVR\scheduleTV.exe [2008-07-07 307200]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-01-22 64160]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-04-23 33800]
R4 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [2008-02-01 16:24:04 41456]
R4 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2008-07-07 279552]
R4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-04-23 472320]
R4 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-09-30 51816]
R4 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2008-07-07 25984]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\Windows Live\Messenger\usnsvc.exe [2007-11-07 98840]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 942416]
.
Contents of the 'Scheduled Tasks' folder
2009-01-29 c:\windows\Tasks\Ad-Aware Update (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-22 18:33]
.
- - - - ORPHANS REMOVED - - - -
BHO-{E6D8F073-C95F-4CD3-91EB-AC9983C27C88} - (no file)
HKCU-Run-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
HKCU-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe
HKCU-Run-nodenable - c:\program files\eset\nodenable.exe
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {8AD8E4E2-6BD0-4E03-BE2A-4C46E9C6CA27} = 82.117.200.6
FF - ProfilePath - c:\documents and settings\xp pro\Application Data\Mozilla\Firefox\Profiles\ftjliinr.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-01-30 08:39:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1645522239-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{586A8F2C-7720-628A-1D0A-FFF4789DE6D3}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iabgbmbjhdkkafdalk"=hex:6a,61,69,61,65,6c,62,65,6d,6b,66,6d,6c,6f,61,6c,70,6d,
6e,6c,00,00
"halkdppjcapfhpfh"=hex:6a,61,69,61,65,6c,62,65,6d,6b,66,6d,6c,6f,61,6c,70,6d,
6e,6c,00,00
"eadhfclbnd"=hex:61,61,00,7c
"eajfbpbcmp"=hex:61,61,00,7c
[HKEY_USERS\S-1-5-21-1645522239-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A69BA63-A6A3-1087-816D-8AF284205586}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"nadfdmhlofdifbmcnjjpcgfhnpge"=hex:6a,61,67,61,66,6d,6b,6b,61,6a,64,69,70,6c,
6c,6f,6e,63,69,65,00,00
"majffmmmejphpbnmikpamopigk"=hex:6a,61,67,61,6a,6d,6f,6d,65,62,69,61,65,69,61,
61,64,6b,61,69,00,00
.
Completion time: 2009-01-30 8:41:23
ComboFix-quarantined-files.txt 2009-01-30 07:41:21
Pre-Run: 65,817,747,456 bytes free
Post-Run: 65,807,781,888 bytes free
210
Dopuna: 30 Jan 2009 8:46
To je nakon disable NOD32 i Ad-Aware
|