offline
- Wisdomseeker

- Super građanin
- Pridružio: 12 Feb 2007
- Poruke: 1239
|
Napisano: 19 Jan 2014 4:18
ComboFix log
ComboFix 14-01-16.03 - Irena 19.01.2014 4:10.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3564.3101 [GMT 1:00]
Running from: c:\documents and settings\Irena\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Irena\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DiscOuntExtensi
c:\documents and settings\All Users\Application Data\DiscOuntExtensi\n4zY1Ati.dat
c:\documents and settings\All Users\Application Data\DiscOuntExtensi\n4zY1Ati.tlb
c:\documents and settings\All Users\Application Data\fjmcodeedhdmlbbhnbncllflkchdkljp
c:\documents and settings\All Users\Application Data\fjmcodeedhdmlbbhnbncllflkchdkljp\background.html
c:\documents and settings\All Users\Application Data\fjmcodeedhdmlbbhnbncllflkchdkljp\content.js
c:\documents and settings\All Users\Application Data\fjmcodeedhdmlbbhnbncllflkchdkljp\lsdb.js
c:\documents and settings\All Users\Application Data\fjmcodeedhdmlbbhnbncllflkchdkljp\manifest.json
c:\documents and settings\All Users\Application Data\fjmcodeedhdmlbbhnbncllflkchdkljp\OcLRfL6Ooa.js
c:\documents and settings\All Users\Application Data\SavierExttenssioon
c:\documents and settings\All Users\Application Data\SavierExttenssioon\DpofPmgkIk.dat
c:\documents and settings\All Users\Application Data\SavierExttenssioon\DpofPmgkIk.tlb
.
.
((((((((((((((((((((((((( Files Created from 2013-12-19 to 2014-01-19 )))))))))))))))))))))))))))))))
.
.
2014-01-18 16:11 . 2014-01-18 16:12 -------- d-----w- C:\AdwCleaner
2014-01-18 13:43 . 2014-01-18 13:43 -------- d-----w- c:\program files\VS Revo Group
2014-01-18 12:58 . 2014-01-18 12:59 -------- d-----w- c:\windows\system32\MRT
2014-01-09 23:11 . 2014-01-09 23:11 -------- d-----w- c:\program files\MSXML 4.0
2014-01-09 05:02 . 2014-01-18 13:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-09 05:02 . 2014-01-18 13:48 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-01-09 04:38 . 2014-01-09 04:38 -------- d-----w- c:\documents and settings\Irena\Local Settings\Application Data\Mozilla
2014-01-09 04:37 . 2014-01-09 04:37 -------- d-----w- c:\program files\Mozilla Maintenance Service
2014-01-09 00:28 . 2014-01-18 13:39 -------- d-----w- c:\documents and settings\Irena\Application Data\uTorrent
2014-01-08 19:29 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2014-01-08 19:28 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2014-01-08 19:28 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2014-01-08 19:26 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2014-01-08 19:20 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2014-01-08 19:20 . 2013-07-03 02:12 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
2014-01-08 19:20 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2014-01-08 19:20 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2014-01-08 19:19 . 2013-11-27 20:21 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2014-01-08 19:19 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2014-01-08 19:19 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2014-01-08 19:19 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2014-01-08 19:19 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2014-01-08 19:19 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2014-01-08 19:19 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2014-01-08 19:19 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2014-01-08 19:19 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2014-01-08 19:15 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2014-01-08 19:14 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2014-01-08 19:14 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2014-01-08 19:14 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2014-01-08 19:13 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2014-01-08 19:12 . 2013-07-17 00:58 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
2014-01-08 19:12 . 2013-07-17 00:58 46848 -c----w- c:\windows\system32\dllcache\irbus.sys
2014-01-08 19:12 . 2013-07-17 00:58 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
2014-01-08 19:09 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2014-01-08 19:08 . 2013-08-09 00:55 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
2014-01-08 19:08 . 2013-08-09 00:55 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
2014-01-08 19:08 . 2013-08-09 00:55 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
2014-01-08 19:08 . 2009-03-18 11:02 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
2014-01-08 19:06 . 2014-01-09 00:29 -------- d-sh--w- c:\documents and settings\Irena\IECompatCache
2014-01-08 19:05 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2014-01-08 19:04 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2014-01-08 19:04 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2014-01-08 19:00 . 2010-12-09 15:15 718336 -c----w- c:\windows\system32\dllcache\ntdll.dll
2014-01-08 19:00 . 2013-07-04 03:03 2149888 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2014-01-08 19:00 . 2013-07-04 02:59 2193536 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2014-01-08 19:00 . 2013-07-04 02:08 2028544 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2014-01-08 19:00 . 2013-07-04 02:08 2070144 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2014-01-08 19:00 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2014-01-08 19:00 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2014-01-08 19:00 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2014-01-08 19:00 . 2010-01-13 14:01 86016 -c----w- c:\windows\system32\dllcache\cabview.dll
2014-01-08 18:49 . 2008-04-14 04:41 21504 ----a-w- c:\windows\system32\hidserv.dll
2014-01-08 18:49 . 2008-04-13 23:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2014-01-08 18:49 . 2008-04-13 23:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2014-01-08 18:49 . 2013-08-09 00:55 32384 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-07 17:35 . 2014-01-07 17:35 -------- d-----w- c:\documents and settings\Irena\Local Settings\Application Data\PCHealth
2014-01-04 17:08 . 2014-01-04 17:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Files To Phones
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-31 23:48 . 2013-10-18 21:24 410528 ----a-w- c:\windows\system32\drivers\aswsp.sys
2013-12-31 23:48 . 2013-10-18 21:24 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-31 23:48 . 2013-10-18 21:24 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-12-31 23:48 . 2013-10-18 21:24 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-31 23:48 . 2013-10-18 21:24 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-31 23:48 . 2013-10-18 21:24 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-31 23:48 . 2013-10-18 21:23 43152 ----a-w- c:\windows\avastSS.scr
2013-12-31 23:48 . 2013-07-06 12:28 270240 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-19 01:56 . 2013-12-19 01:56 4558848 ----a-w- c:\windows\system32\GPhotos.scr
2013-12-01 09:15 . 2013-12-01 09:15 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-11-28 22:45 . 2013-11-28 22:45 98304 ----a-w- c:\windows\system32CmdLineExt.dll
2013-11-27 20:21 . 2004-08-04 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2013-11-13 02:59 . 2004-08-04 12:00 150528 ----a-w- c:\windows\system32\imagehlp.dll
2013-11-07 05:38 . 2004-08-04 12:00 591360 ----a-w- c:\windows\system32\rpcrt4.dll
2013-11-06 01:03 . 2013-07-06 21:18 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-10-30 02:26 . 2004-08-04 12:00 1879040 ----a-w- c:\windows\system32\win32k.sys
2013-10-29 07:57 . 2004-08-04 12:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-29 07:57 . 2004-08-04 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2013-10-29 07:57 . 2004-08-04 12:00 18944 ----a-w- c:\windows\system32\corpol.dll
2013-10-29 07:57 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-10-29 00:45 . 2004-08-04 12:00 385024 ------w- c:\windows\system32\html.iec
2013-10-23 23:45 . 2004-08-04 12:00 172032 ----a-w- c:\windows\system32\scrrun.dll
2013-01-19 07:44 . 2013-01-19 07:44 2174976 ----a-w- c:\program files\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-31 23:48 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-31 3764024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CodecPackUpdateChecker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
backup=c:\windows\pss\CodecPackUpdateChecker.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Irena^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Irena\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Irena^Start Menu^Programs^Startup^MyPC Backup.lnk]
path=c:\documents and settings\Irena\Start Menu\Programs\Startup\MyPC Backup.lnk
backup=c:\windows\pss\MyPC Backup.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-09-05 14:03 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2012-05-15 09:40 15504192 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2012-05-15 09:40 108352 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2012-05-15 10:18 1634112 ----a-r- c:\program files\NVIDIA Corporation\nview\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2012-06-06 06:00 20065936 ----a-r- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Super-Charger]
2012-07-27 16:52 495616 ----a-w- c:\program files\MSI\Super-Charger\Super-Charger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2014-01-09 00:29 1340496 ----a-w- c:\documents and settings\Irena\Application Data\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Irena\\Application Data\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Red Alert 2 Yuri's Revenge\\game.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [18.10.2013 22:24 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [18.10.2013 22:24 180248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [18.10.2013 22:24 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [18.10.2013 22:24 410528]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [18.10.2013 22:24 67824]
R2 MSI_SuperCharger;MSI_SuperCharger;c:\program files\MSI\Super-Charger\ChargeService.exe [6.7.2013 12:17 136704]
R3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [6.7.2013 12:17 55104]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files\MSI\Super-Charger\NTIOLib.sys [6.7.2013 12:17 7680]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6.7.2013 12:21 1691480]
S3 MSICDSetup;MSICDSetup;\??\d:\cdriver.sys --> d:\CDriver.sys [?]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C;\??\d:\ntiolib.sys --> d:\NTIOLib.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - NTIOLIB_1_0_3
.
Contents of the 'Scheduled Tasks' folder
.
2014-01-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-09 13:48]
.
2014-01-19 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-18 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
mStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchAssistant = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Irena\Application Data\Mozilla\Firefox\Profiles\adfdl2s4.default\
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2014-01-19 04:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1715567821-1606980848-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:4b,ec,87,c3,5c,62,01,18,b3,cd,ce,3b,98,db,44,ad,68,df,74,31,75,12,9a,
da,13,de,d1,4d,1e,32,d3,02,b5,f5,01,b8,5b,07,80,60,89,8d,f9,46,8b,5e,74,0b,\
"??"=hex:be,8d,49,c6,af,88,31,c4,d4,fc,71,77,a5,0e,e5,5a
.
[HKEY_USERS\S-1-5-21-1715567821-1606980848-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:49,b3,4b,4a,13,2f,98,96,3a,b4,f0,f8,f7,62,ed,e7,9c,09,bb,50,88,
22,a2,4e,d2,26,f3,18,5d,ad,87,1a,0e,c8,2e,7b,33,d3,17,37,3d,85,ba,aa,e8,f1,\
"rkeysecu"=hex:da,ce,8f,a1,d7,a0,f4,20,96,f6,7e,1a,1b,4e,06,1a
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2014-01-19 04:13:38
ComboFix-quarantined-files.txt 2014-01-19 03:13
ComboFix2.txt 2014-01-18 20:07
.
Pre-Run: 120.339.701.760 bytes free
Post-Run: 120.328.491.008 bytes free
.
- - End Of File - - 42D11D9EA90EE02F867F6F185AB8C5BB
8F558EB6672622401DA993E1E865C861
Dopuna: 19 Jan 2014 4:26
Radi znatno bolje, stranice ovde na forumu iz Firefoxa se ucitavaju za neko normalno vreme (dosta brzo), ne koci vise prilikom ucitavanja stranica, OS se podigao iz prve kada sam ponovo ukljucio taj PC.
|