offline
- White_Shark
- Ugledni građanin
- Pridružio: 17 Sep 2006
- Poruke: 421
- Gde živiš: PALE, Republika Srpska
|
skenirao sam sa ComboFix-om i izbrisao mi je viruscinu, samo mi nije jasno kako je to Kasperskom promaklo. Glupi facemoods je bio zarazen (extenzija za mozilu). Probao sam media player i radi sasvim normalno kao i svi ostali programi. Hvala na pomoci, a evo ga LOG fajl od combofix-a.
ComboFix 10-08-18.05 - Aleksandar 20.08.2010 14:26:35.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.387.1033.18.3327.2624 [GMT 2:00]
Running from: c:\users\Aleksandar\Desktop\ComboFix.exe
* Created a new restore point
.
ADS - Windows: deleted 0 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.3.43.0\chrome.manifest
c:\program files\facemoods.com\facemoods\1.3.43.0\chrome\content\facemoods.png
c:\program files\facemoods.com\facemoods\1.3.43.0\chrome\content\ffxtlbr.xul
c:\program files\facemoods.com\facemoods\1.3.43.0\components\FFHst.dll
c:\program files\facemoods.com\facemoods\1.3.43.0\components\FFHst.xpt
c:\program files\facemoods.com\facemoods\1.3.43.0\escort.dll
c:\program files\facemoods.com\facemoods\1.3.43.0\escortApp.dll
c:\program files\facemoods.com\facemoods\1.3.43.0\escortEng.dll
c:\program files\facemoods.com\facemoods\1.3.43.0\escorTlbr.dll
c:\program files\facemoods.com\facemoods\1.3.43.0\install.rdf
c:\program files\facemoods.com\facemoods\1.3.43.0\uninstall.exe
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\chrome.manifest
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\blgc.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\facemoods.png
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\facemoods.xul
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\Loader.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\pref.jpg
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\preferences.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\preferences.xul
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\prefman.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\script-compiler.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\Thumbs.db
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\xmlhttprequester.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\defaults\preferences\facemoods.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\install.rdf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_osppsvc
((((((((((((((((((((((((( Files Created from 2010-07-20 to 2010-08-20 )))))))))))))))))))))))))))))))
.
2010-08-20 12:38 . 2010-08-20 12:41 -------- d-----w- c:\users\Aleksandar\AppData\Local\temp
2010-08-20 12:19 . 2010-08-20 12:19 -------- d-----w- C:\32788R22FWJFW
2010-08-19 21:41 . 2010-08-19 21:41 -------- d-----w- c:\users\Aleksandar\AppData\Roaming\Thinstall
2010-08-19 21:41 . 2010-08-19 21:41 -------- d-----w- c:\users\Aleksandar\AppData\Local\Thinstall
2010-08-16 12:45 . 2010-08-16 17:15 -------- d-----w- c:\users\Aleksandar\SiteGrinderData
2010-08-15 21:49 . 2010-08-15 21:49 -------- d-----w- c:\program files\SiteGrinder 3
2010-08-12 22:20 . 2010-08-12 22:20 -------- d-----w- c:\program files\Eidos
2010-08-10 14:16 . 2010-08-10 14:16 -------- d-----w- c:\users\Aleksandar\AppData\Local\2K Games
2010-08-10 09:37 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-08-10 09:37 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-08-10 09:37 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-08-10 09:37 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-08-10 09:37 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-08-10 09:37 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-08-09 17:54 . 2010-08-09 17:54 -------- d-----w- c:\programdata\Itoo Software
2010-08-09 17:54 . 2010-08-09 17:54 -------- d-----w- c:\program files\Itoo Software
2010-08-08 12:04 . 2010-08-08 12:04 -------- d-----w- c:\program files\Microsoft XNA
2010-08-08 12:03 . 2010-08-08 12:03 -------- d-----w- c:\program files\Privates
2010-08-05 22:45 . 2010-08-05 22:45 -------- d-----w- c:\users\Aleksandar\AppData\Local\CrashRpt
2010-07-24 15:11 . 2010-07-24 15:11 -------- d-----w- c:\users\Aleksandar\AppData\Local\TechSmith
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-20 12:41 . 2009-11-09 20:06 -------- d-----w- c:\programdata\Kaspersky Lab
2010-08-20 12:40 . 2009-10-28 23:56 -------- d-----w- c:\programdata\NVIDIA
2010-08-18 22:29 . 2009-10-28 22:01 -------- d-----w- c:\users\Aleksandar\AppData\Roaming\Skype
2010-08-18 22:08 . 2009-10-28 22:02 -------- d-----w- c:\users\Aleksandar\AppData\Roaming\skypePM
2010-08-18 16:28 . 2010-08-18 16:28 340456 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-18 16:28 . 2010-08-18 16:28 170512 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 16:28 . 2010-08-18 16:28 170584 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-18 16:28 . 2010-08-18 16:28 340520 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-17 12:33 . 2009-10-29 15:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-12 22:24 . 2009-12-20 22:59 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2010-08-12 22:24 . 2009-12-20 22:59 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2010-08-11 15:19 . 2009-11-17 14:50 -------- d-----w- c:\program files\Steam
2010-08-10 09:38 . 2009-10-28 23:57 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-09 17:16 . 2009-10-28 21:36 345800 ----a-w- c:\users\Aleksandar\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-06 12:19 . 2009-12-19 19:08 -------- d-----w- c:\users\Aleksandar\AppData\Roaming\SoftGrid Client
2010-08-04 19:29 . 2010-07-05 19:37 -------- d-----w- c:\program files\Minefield
2010-07-31 19:56 . 2009-10-29 00:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-29 16:40 . 2010-03-22 08:05 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 16:40 . 2010-03-22 08:05 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-07-16 16:10 . 2010-07-16 16:10 -------- d-----w- c:\users\Default\AppData\Roaming\Apple Computer
2010-07-16 13:01 . 2010-07-16 11:10 -------- d-----w- c:\users\Aleksandar\AppData\Roaming\Apple Computer
2010-07-16 13:00 . 2009-10-28 21:50 -------- d-----w- c:\programdata\Apple
2010-07-16 11:10 . 2010-07-16 11:09 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-16 11:10 . 2010-07-16 11:09 -------- d-----w- c:\program files\iTunes
2010-07-16 11:09 . 2010-07-16 11:09 -------- d-----w- c:\program files\iPod
2010-07-16 11:09 . 2010-02-13 15:53 -------- d-----w- c:\program files\Common Files\Apple
2010-07-16 11:09 . 2009-10-28 21:51 -------- d-----w- c:\programdata\Apple Computer
2010-07-16 11:08 . 2010-02-26 07:54 -------- d-----w- c:\program files\QuickTime
2010-07-16 11:06 . 2010-07-16 11:06 -------- d-----w- c:\program files\Apple Software Update
2010-07-16 11:06 . 2010-07-16 11:06 -------- d-----w- c:\program files\Bonjour
2010-07-09 10:56 . 2010-05-13 16:18 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-09 10:56 . 2010-05-13 16:13 -------- d-----w- c:\programdata\DivX
2010-07-09 10:56 . 2010-07-09 10:56 57715 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-07-09 10:56 . 2010-07-09 10:56 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-09 10:56 . 2009-11-10 11:04 -------- d-----w- c:\program files\DivX
2010-07-09 10:55 . 2010-07-09 10:55 84054 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-07-09 10:55 . 2010-07-09 10:55 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-07-09 10:53 . 2010-05-13 16:18 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-07-09 10:53 . 2010-05-13 16:18 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-07-04 20:52 . 2010-07-04 20:52 -------- d-----w- c:\users\Aleksandar\AppData\Roaming\Need for Speed World
2010-06-26 13:34 . 2010-04-15 20:26 148 ----a-w- c:\programdata\SafeNet Sentinel\Sentinel RMS Development Kit\System\prsgrc.dll
2010-06-24 20:06 . 2010-04-27 14:25 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2010-06-15 18:01 . 2010-06-15 18:01 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-15 11:47 . 2010-06-15 11:47 133720 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-06 07:20 . 2010-06-06 07:20 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-06-06 07:19 . 2010-06-06 07:19 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 57609 ----a-w- c:\programdata\DivX\MFComponents\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-06 07:18 . 2010-06-06 07:18 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"New Value #1"="“ctfmon”=”CTFMON.EXE”" [X]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-05-22 7514656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2010-08-18 340520]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0ENQBO]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-11-09 03:17 180224 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-14 07:30 1238352 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-11-29 135664]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-03-12 86016]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-10-29 721904]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-11-03 21520]
S2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [2008-05-19 57344]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2009-09-26 819600]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe [2007-10-16 81920]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2009-12-08 3616768]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2009-09-23 447832]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-03-16 240232]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe [2007-10-16 2711552]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
S3 sftfs;sftfs;c:\program files\Microsoft Application Virtualization Client\drivers\sftfslh.sys [2009-09-23 543064]
S3 sftplay;sftplay;c:\program files\Microsoft Application Virtualization Client\drivers\sftplaylh.sys [2009-09-23 190312]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-09-23 21848]
S3 sftvol;sftvol;c:\program files\Microsoft Application Virtualization Client\drivers\sftvollh.sys [2009-09-23 14680]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2009-09-23 203608]
.
Contents of the 'Scheduled Tasks' folder
2010-04-27 c:\windows\Tasks\AdobeAAMUpdater-1.0-Aleksandar-PC-Aleksandar.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-06-24 01:44]
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c96b488b012.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-29 17:18]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-29 17:18]
2010-05-18 c:\windows\Tasks\{12E46AB7-1004-443D-8000-3C44266F78DA}.job
- c:\program files\Skype\Phone\Skype.exe [2010-05-13 15:57]
2010-07-07 c:\windows\Tasks\{E21233D4-455A-4525-8B2B-7ED35D18460D}.job
- c:\program files\Skype\Phone\Skype.exe [2010-05-13 15:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.facemoods.com
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\6035u98f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1229009&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Hip Hop Internet Radio Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1229009&q=
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\6035u98f.default\extensions\{59ed24c5-0745-4256-9f4a-8c86df2891c3}\components\FFExternalAlert.dll
FF - component: c:\users\Aleksandar\AppData\Roaming\Mozilla\Firefox\Profiles\6035u98f.default\extensions\{59ed24c5-0745-4256-9f4a-8c86df2891c3}\components\RadioWMPCore.dll
FF - plugin: c:\progra~1\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\users\Aleksandar\AppData\Local\Yahoo!\BrowserPlus\2.5.1\Plugins\npybrowserplus_2.5.1.dll
FF - plugin: c:\users\Aleksandar\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files\facemoods.com\facemoods\1.3.43.0\escort.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files\facemoods.com\facemoods\1.3.43.0\escorTlbr.dll
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-RGSC - d:\program files (x86)\Rockstar Games Social Club\RGSCLauncher.exe
HKCU-Run-AdobeBridge - (no file)
MSConfigStartUp-msnmsgr - ~c:\program files\Windows Live\Messenger\msnmsgr.exe
AddRemove-Call of Duty Modern Warfare 2_is1 - c:\program files\Activision\Modern Warfare 2\unins000.exe
AddRemove-EyeCandy5Impact - c:\progra~1\Adobe\ADOBEP~2\Plug-ins\ALIENS~2\EYECAN~1\Unwise32.exe
AddRemove-EyeCandy5Nature - c:\progra~1\Adobe\ADOBEP~2\Plug-ins\ALIENS~2\EYECAN~2\Unwise32.exe
AddRemove-EyeCandy5Textures - c:\progra~1\Adobe\ADOBEP~2\Plug-ins\ALIENS~2\EYECAN~3\Unwise32.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.3.43.0\uninstall.exe
AddRemove-Snap Art - c:\progra~1\Adobe\ADOBEP~2\Plug-ins\ALIENS~2\SNAPAR~1\Unwise32.exe
AddRemove-Texas Hold'em Poker (Trial version)_is1 - d:\programi\Texas Hold'em Poker (Trial version)\unins000.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3638592946-3047454263-1808164732-1001\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Aleksandar\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"="c:\\Users\\Aleksandar\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
"ScreenshotsDir"="c:\\Users\\Aleksandar\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Aleksandar\\Documents\\Sports Interactive\\Football Manager 2010\\"
"LangDB"=""
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000000
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00000000
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:0000006f
"UniqueID"="C5-8380-E0EF"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
[HKEY_USERS\S-1-5-21-3638592946-3047454263-1808164732-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5A28347E-B85B-A509-C6AB-CDD30B17F865}*]
"hadblflepdnffnnf"=hex:6a,61,63,6f,70,6c,6c,6f,6a,6f,6a,6e,68,63,6c,69,63,67,
6d,6b,00,fc
"iabmbhoncemeoaanma"=hex:63,61,63,6f,6f,6c,00,00
"ianbfcpalofjggcfoh"=hex:6b,61,62,6f,62,6e,6e,68,70,70,69,6a,61,62,6c,70,70,6a,
6f,70,61,63,00,00
"dbloaanmhakcijofoecpoamgpbdofnohpbfnimkg"=hex:6a,62,6f,61,6e,64,6f,67,67,65,
67,63,70,67,64,64,6c,66,62,67,63,61,6e,6b,61,68,6d,6c,66,62,6e,6e,66,6f,62,\
"jbloaanmhakcijofoecpfokjcnmpobgiedfekmhfkplfjajonicd"=hex:67,63,6f,6c,62,63,
64,6c,6a,68,69,64,69,69,70,6b,62,6b,6c,62,67,65,6e,70,6c,69,70,66,70,64,65,\
[HKEY_USERS\S-1-5-21-3638592946-3047454263-1808164732-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:98,f6,5d,cd,9c,5e,46,04,05,fc,56,bf,84,8f,98,93,45,4d,c3,28,80,3d,7e,
1b,d2,52,a2,a7,ac,56,2d,f1,46,91,91,a5,82,7f,5e,b1,44,62,b6,d0,d2,f7,d2,d9,\
"??"=hex:bc,1c,4f,ad,e1,cf,1b,e4,ad,51,19,94,df,3d,14,af
[HKEY_USERS\S-1-5-21-3638592946-3047454263-1808164732-1001\Software\SecuROM\License information*]
"datasecu"=hex:38,e1,9a,be,7e,6b,50,be,e8,df,d7,1e,af,d4,25,a7,c5,4f,41,8d,38,
04,10,24,89,0c,b1,4d,c8,bd,21,5f,56,0e,8e,59,18,ba,4a,c2,49,fc,01,ff,57,a9,\
"rkeysecu"=hex:c9,97,0a,cb,26,6e,ff,bf,19,6e,b3,c8,ca,30,28,74
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\windows\system32\taskhost.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\Rundll32.exe
.
**************************************************************************
.
Completion time: 2010-08-20 14:54:03 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-20 12:53
Pre-Run: 9.040.314.368 bytes free
Post-Run: 11.890.118.656 bytes free
- - End Of File - - 3865C6DA11371EDCE15C503A582E260A
|