offline
- Pridružio: 28 Maj 2010
- Poruke: 46
|
ComboFix 10-12-02.06 - Marijan 3.12.2010. 17:47:22.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.385.1033.18.1789.1058 [GMT 1:00]
Running from: c:\users\Marijan\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FLV Direct Player
c:\program files\FLV Direct Player\downloading.swf
c:\program files\FLV Direct Player\FLVPlayer.exe
c:\program files\FLV Direct Player\player.swf
c:\program files\FLV Direct Player\preload.swf
c:\program files\FLV Direct Player\Skin\DirectFLV\Button.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\Logo.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\skin.xml
c:\program files\FLV Direct Player\Skin\DirectFLV\SysCloseButton.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\SysMaxButton.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\SysMinButton.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\Window.bmp
c:\program files\FLV Direct Player\uninstall.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player
c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player\FLV Direct Player.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player\Uninstall FLV Direct Player.lnk
c:\users\Marijan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9635938.lnk
C:\Win
c:\win\1.exe
c:\win\desktop.exe
c:\win\lsass.exe
c:\win\names.txt
c:\windows\system32\-UfiR1Dkx.exe
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_usnjsvc
((((((((((((((((((((((((( Files Created from 2010-11-03 to 2010-12-03 )))))))))))))))))))))))))))))))
.
2010-12-03 16:55 . 2010-12-03 16:59 -------- d-----w- c:\users\Marijan\AppData\Local\temp
2010-12-03 16:55 . 2010-12-03 16:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-03 16:18 . 2010-12-03 16:18 -------- d-----w- c:\users\Marijan\AppData\Roaming\AVG10
2010-12-03 16:15 . 2010-12-03 16:15 -------- d--h--w- c:\programdata\Common Files
2010-12-03 16:14 . 2010-12-03 16:40 -------- d-----w- c:\programdata\AVG10
2010-12-03 16:04 . 2010-12-03 16:13 -------- d-----w- c:\programdata\MFAData
2010-12-03 13:48 . 2010-12-03 13:48 -------- d-----w- c:\users\Marijan\AppData\Local\Adobe
2010-12-03 08:41 . 2010-12-03 08:41 2 --shatr- c:\windows\winstart.bat
2010-12-03 08:40 . 2010-12-03 13:25 -------- d-----w- c:\program files\UnHackMe
2010-12-02 22:01 . 2010-12-03 08:28 -------- d-----w- c:\windows\system32\MpEngineStore
2010-12-02 21:11 . 2010-12-02 21:11 -------- d-----w- c:\users\Marijan\Pavark
2010-12-02 21:10 . 2010-12-02 21:10 -------- d-----w- c:\program files\IceSword
2010-12-02 21:09 . 2007-07-10 15:23 744960 ----a-w- c:\program files\Mozilla Firefox\IceSword122en\IceSword.exe
2010-12-02 21:05 . 2010-12-02 21:11 -------- d-----w- c:\program files\Sophos
2010-11-16 15:03 . 2010-11-16 15:03 -------- d-----w- c:\program files\HP Photosmart M417 FW Files
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-02 22:01 . 2009-07-13 23:23 35328 ----a-w- c:\windows\system32\drivers\blbdrive.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-05-17 5729136]
"Eraser"="c:\program files\Eraser\Eraser.exe" [2009-12-12 332800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-12-09 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Ultralingua 7 Hotkey"="c:\program files\Ultralingua\Ultralingua 7\ULHotkey.exe" [2009-11-04 1483264]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
c:\users\Marijan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
9635938.del [2010-5-7 949]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-12-10 106560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R3 <NtDriverName>;<NtDriverName>;c:\windows\System32\Drivers\<NtDriverName>.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 MGSGK;MGSGK;c:\users\Marijan\AppData\Local\Temp\MGSGK.exe [x]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [2010-07-02 375808]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
R3 XHAKL;XHAKL;c:\users\Marijan\AppData\Local\Temp\XHAKL.exe [x]
R3 XVUYQK;XVUYQK;c:\users\Marijan\AppData\Local\Temp\XVUYQK.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-09 691696]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [2007-11-02 566560]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-04 176128]
S2 Realtek87B;Realtek87B;c:\program files\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hr/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Marijan\AppData\Roaming\Mozilla\Firefox\Profiles\5dw6pwt9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.hr/
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\Mozilla Firefox\extensions\{ee1dd5b8-be23-521a-15e2-b13dbba8da81}\components\u_9yWWCq-GmriS.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Extension: LoudMo Contextual Ad Assistant: {ee1dd5b8-be23-521a-15e2-b13dbba8da81} - c:\program files\Mozilla Firefox\extensions\{ee1dd5b8-be23-521a-15e2-b13dbba8da81}
FF - Extension: Speed Dial: {64161300-e22b-11db-8314-0800200c9a66} - c:\users\Marijan\AppData\Roaming\Mozilla\Firefox\Profiles\5dw6pwt9.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
.
- - - - ORPHANS REMOVED - - - -
BHO-{9016c848-658e-e968-b881-a31dc53c4c60} - c:\windows\system32\vDh05J.dll
HKCU-Run-Canaveral - c:\windows\system32\sshnas21.dll
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
AddRemove--UfiR1Dkx - c:\windows\system32\-UfiR1Dkx.exe
AddRemove-Winamp Detect - c:\program files\Winamp Detect\UninstWaDetect.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1045542724-2555930307-1999853709-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:5e,8a,db,3f,ac,a8,97,18,10,91,cf,fd,13,84,ba,89,5e,4c,ad,f3,81,4b,1d,
9f,8d,af,31,8f,76,65,2e,92,2f,13,e4,f2,0b,bd,5a,af,44,91,ab,cd,05,f6,8e,5a,\
"??"=hex:e0,e2,4a,34,c0,2f,df,49,49,81,5d,ab,cf,2f,d7,f3
[HKEY_USERS\S-1-5-21-1045542724-2555930307-1999853709-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\sppsvc.exe
c:\program files\REALTEK\RTL8187 Wireless LAN Utility\RtWlan.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\UAService.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\taskhost.exe
.
**************************************************************************
.
Completion time: 2010-12-03 18:03:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-03 17:03
Pre-Run: 15.066.562.560 bytes free
Post-Run: 14.679.871.488 bytes free
- - End Of File - - 80B5F621E2FA2F07CB74A9C9000A897D
|