offline
- Pridružio: 25 Apr 2006
- Poruke: 46
|
Imam servis pack 2 ali ovaj sto je instaliran nije kod mene.
Log ComboFixa
ComboFix 09-05-14.07 - xp pro 15.05.2009 17:45.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1456 [GMT 2:00]
Running from: c:\documents and settings\xp pro\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\RKHit.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RKHIT
((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.
2009-05-14 13:29 . 2009-05-14 13:29 -------- d-----w C:\vcs5BGEffects
2009-05-14 13:24 . 2009-05-14 13:26 323584 ----a-w c:\windows\system32\AUDIOGENIE2.DLL
2009-05-14 13:23 . 2009-05-14 13:23 -------- d-----w c:\windows\Replay Media Catcher
2009-05-14 13:23 . 2009-05-14 14:58 -------- d-----w c:\program files\Replay Media Catcher
2009-05-13 21:37 . 2009-05-13 21:37 -------- d-----w c:\documents and settings\xp pro\Application Data\ESET
2009-05-04 16:52 . 2009-05-04 12:13 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-05-04 12:13 . 2009-05-04 12:12 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-05-04 12:10 . 2009-05-04 12:10 -------- dc-h--w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-05-04 12:09 . 2009-05-04 12:09 -------- d-----w c:\program files\Lavasoft
2009-04-29 11:26 . 2009-04-29 11:26 -------- d-----w c:\program files\Common Files\DirectX
2009-04-28 16:35 . 2009-05-12 17:48 -------- d-----w c:\program files\Ubisoft
2009-04-28 16:35 . 2009-04-28 16:35 -------- d-----w c:\documents and settings\All Users\Application Data\Ubisoft
2009-04-27 12:34 . 2009-04-27 12:34 -------- d-----w c:\documents and settings\xp pro\Application Data\Malwarebytes
2009-04-27 12:34 . 2009-04-27 12:34 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-27 12:31 . 2009-04-27 12:31 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-27 11:34 . 2009-05-04 12:09 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-27 08:07 . 2009-04-27 08:07 17408 ----a-w C:\psapi.dll
2009-04-27 07:49 . 2009-04-27 07:49 29170931 ----a-w c:\windows\system32\xa224354343.exe
2009-04-27 07:49 . 2009-04-27 07:49 29170931 ----a-w c:\windows\system32\xa224352843.exe
2009-04-24 13:19 . 2009-04-24 13:19 -------- d-----w c:\documents and settings\All Users\Application Data\Ashampoo
2009-04-19 22:28 . 2009-05-11 06:47 -------- d-----w c:\program files\Registry Clean Expert
2009-04-19 20:41 . 2009-05-14 15:00 -------- d-----w c:\program files\ESET
2009-04-19 20:41 . 2009-05-15 12:51 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-18 17:39 . 2009-04-18 17:39 -------- d-----w c:\program files\Gekko Mahjongg (Xmas edition)
2009-04-17 11:56 . 2009-04-17 11:56 -------- d-----w c:\program files\Xvid
2009-04-17 11:56 . 2009-04-17 11:56 -------- d-----w c:\program files\FDRLab
2009-04-17 11:55 . 2009-04-17 11:55 -------- d-----w c:\program files\YouTube Downloader
2009-04-16 21:38 . 2009-04-16 21:38 -------- d-----w c:\program files\YouTubeRobot
2009-04-16 14:23 . 2009-04-16 14:23 -------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2009-04-16 04:20 . 2009-04-16 04:20 -------- d-----w c:\documents and settings\xp pro\Application Data\Zylom
2009-04-16 04:20 . 2005-08-03 10:48 389120 ----a-w c:\windows\Adventure Inlay.scr
2009-04-16 04:20 . 2009-04-16 04:20 -------- d-----w c:\documents and settings\All Users\Application Data\Zylom
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 06:37 . 2009-01-09 11:26 -------- d-----w c:\program files\Mozilla Firefox 3.1 Beta 2
2009-05-13 15:35 . 2009-04-09 20:03 -------- d-----w c:\program files\Common Files\EZB Systems
2009-05-13 15:35 . 2008-10-05 11:13 -------- d-----w c:\program files\UltraISO
2009-05-12 18:46 . 2008-07-11 13:33 43 ----a-w c:\windows\popcinfo.dat
2009-05-10 16:22 . 2008-07-18 11:04 -------- d-----w c:\program files\Puzzle Express
2009-05-05 21:56 . 2009-02-08 19:40 -------- d-----w c:\program files\Perfect Uninstaller
2009-04-24 22:20 . 2009-01-09 19:41 -------- d-----w c:\program files\Luxor 4 - Quest for the Afterlife
2009-04-23 13:52 . 2009-01-21 11:36 -------- d-----w c:\program files\The KMPlayer
2009-04-19 22:38 . 2008-07-07 13:35 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-16 15:47 . 2008-08-01 20:19 -------- d-----w c:\program files\Empire Interactive
2009-04-09 20:30 . 2009-04-09 20:30 716272 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-06 13:32 . 2009-03-26 15:49 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-03-26 15:49 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-04 23:58 . 2009-02-02 22:15 -------- d-----w c:\program files\Alawar
2009-03-26 09:19 . 2008-11-05 09:17 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-25 21:30 . 2009-02-28 21:15 -------- d-----w c:\program files\BFDaily
2009-03-22 16:13 . 2008-07-10 20:25 -------- d-----w c:\program files\uTorrent
2009-03-21 01:24 . 2009-03-21 01:24 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-21 01:23 . 2008-07-11 13:30 -------- d-----w c:\program files\Mahjong Medley
2007-07-26 19:00 . 2008-07-07 13:51 23800756 ----a-w c:\program files\Burning Studio 7.1.0.exe
.
------- Sigcheck -------
[-] 2004-08-04 00:56 17408 B35F4F2B059F1A36FC393A55CA15FD86 c:\windows\system32\svchost.exe
[7] 2004-08-03 23:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\system32\dllcache\tcpip.sys
[-] 2004-08-03 23:14 359040 27A5959C94EE173A063CA06BD14F021A c:\windows\system32\drivers\tcpip.sys
[-] 2004-08-04 00:56 506368 9381C12D271113545126025F64106F17 c:\windows\system32\winlogon.exe
[-] 2004-08-04 00:56 1034752 EE5372FA8F010786D9B53A19C673CE63 c:\windows\explorer.exe
[-] 2004-08-04 00:56 110592 D1D1F99BB3C15807B0E578DF9A8B5260 c:\windows\system32\services.exe
[-] 2004-08-04 00:56 14848 FB0F915174118309E3BE189EBFA10AE9 c:\windows\system32\lsass.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-28 13516800]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Scheduler for OEM.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Scheduler for OEM.lnk
backup=c:\windows\pss\Scheduler for OEM.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4.5.2009 14:13 64160]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 15:24 93336]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [1.2.2008 17:24 41456]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [7.7.2008 15:45 279552]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [6.2.2009 14:23 727720]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18.1.2009 23:34 953168]
R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [30.9.2007 10:16 51816]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [7.7.2008 15:45 25984]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [26.3.2009 17:49 38496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d05b4181-8b88-11dd-bfbf-0018c034940f}]
\Shell\AutoRun\command - I:\uvsqfgwd.cmd
\Shell\open\Command - I:\uvsqfgwd.cmd
.
Contents of the 'Scheduled Tasks' folder
2009-05-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 12:12]
.
- - - - ORPHANS REMOVED - - - -
SSODL-lpegfdQJUUah-{24EFF327-8E45-598D-C495-C3FE5C0DFC65} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {8AD8E4E2-6BD0-4E03-BE2A-4C46E9C6CA27} = 89.216.45.193
DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} - [Link mogu videti samo ulogovani korisnici]
FF - ProfilePath - c:\documents and settings\xp pro\Application Data\Mozilla\Firefox\Profiles\ftjliinr.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 2\plugins\npzylomgamesplayer.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-05-15 17:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1645522239-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{586A8F2C-7720-628A-1D0A-FFF4789DE6D3}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iabgbmbjhdkkafdalk"=hex:6a,61,69,61,65,6c,62,65,6d,6b,66,6d,6c,6f,61,6c,70,6d,
6e,6c,00,00
"halkdppjcapfhpfh"=hex:6a,61,69,61,65,6c,62,65,6d,6b,66,6d,6c,6f,61,6c,70,6d,
6e,6c,00,00
"eadhfclbnd"=hex:61,61,00,7c
"eajfbpbcmp"=hex:61,61,00,7c
[HKEY_USERS\S-1-5-21-1645522239-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A69BA63-A6A3-1087-816D-8AF284205586}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"nadfdmhlofdifbmcnjjpcgfhnpge"=hex:6a,61,67,61,66,6d,6b,6b,61,6a,64,69,70,6c,
6c,6f,6e,63,69,65,00,00
"majffmmmejphpbnmikpamopigk"=hex:6a,61,67,61,6a,6d,6f,6d,65,62,69,61,65,69,61,
61,64,6b,61,69,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3496)
c:\windows\system32\msi.dll
c:\windows\system32\browselc.dll
c:\progra~1\SPYBOT~1\SDHelper.dll
c:\program files\Common Files\Nero\SMC\NeroDigitalExt.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\progra~1\MICROS~2\OFFICE11\MCPS.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclIrSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-05-15 17:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 15:50
ComboFix2.txt 2009-04-27 19:23
Pre-Run: 62.096.068.608 bytes free
Post-Run: 63.795.507.200 bytes free
228
Logovi Gmera
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
Inace mi ovaj Eset zadaje puno problema
|