offline
- sense
- Novi MyCity građanin
- Pridružio: 28 Jun 2008
- Poruke: 13
|
evo loga
ComboFix 09-02-15.01 - Sasa 2009-02-16 16:56:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.139 [GMT 1:00]
Running from: c:\documents and settings\Sasa\Desktop\C-F.exe
Command switches used :: c:\documents and settings\Sasa\Desktop\CFScript.txt
AV: 3.0 *On-access scanning disabled* (Outdated)
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
* Created a new restore point
FILE ::
c:\windows\system32\frnscli32.dll
c:\windows\system32\stu2.exe
c:\windows\system32\txsocm32.dll
c:\windows\wciactrl.exe
.
/wow section - STAGE 41
The system cannot find the path specified.
The system cannot find the path specified.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system\wmisys.exe
c:\windows\system32\drivers\sysdrv32.sys
c:\windows\system32\frnscli32.dll
c:\windows\system32\stu2.exe
c:\windows\system32\txsocm32.dll
c:\windows\wciactrl.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NFAGENT
-------\Legacy_WMISYS
-------\Service_NFAgent
-------\Service_WMISYS
((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.
2009-02-16 16:55 . 2009-02-16 16:55 3 --a------ c:\windows\switch.inf
2009-02-16 13:50 . 2009-02-16 15:05 <DIR> d-------- c:\documents and settings\Administrator\Application Data\uTorrent
2009-02-16 13:41 . 2009-02-16 13:41 664 --a------ c:\windows\system32\d3d9caps.dat
2009-02-16 10:24 . 2009-02-16 10:24 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Ashampoo
2009-02-16 00:27 . 2009-02-16 00:27 <DIR> d-------- c:\documents and settings\Administrator\Application Data\URSoft
2009-02-15 22:16 . 2009-02-15 22:33 <DIR> d-------- c:\program files\Spyware Doctor
2009-02-15 22:16 . 2009-02-15 22:17 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-02-15 22:16 . 2009-02-15 22:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2009-02-15 22:16 . 2009-02-15 22:16 <DIR> d-------- c:\documents and settings\Administrator\Application Data\PC Tools
2009-02-15 22:16 . 2008-07-16 10:43 160,648 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-02-15 22:16 . 2008-06-10 21:22 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-02-15 22:16 . 2008-06-02 15:19 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-02-15 22:16 . 2008-06-02 15:19 42,376 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-02-15 22:16 . 2008-06-02 15:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-02-15 22:09 . 2009-02-15 22:09 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-15 20:32 . 2009-02-15 20:32 <DIR> d-------- c:\documents and settings\Sasa\Application Data\Avira
2009-02-15 20:16 . 2009-02-15 20:16 <DIR> d-------- c:\program files\Avira
2009-02-15 19:22 . 2009-02-15 20:01 1,551,904 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-02-15 19:22 . 2009-02-15 19:32 221,216 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-02-15 19:22 . 2009-02-15 20:01 14,252 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-02-15 19:22 . 2009-02-15 19:32 2,884 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-02-15 17:28 . 2009-02-15 17:28 4,036 --ah----- C:\aaw7boot.cmd
2009-02-15 15:58 . 2009-02-15 17:36 <DIR> d-------- c:\program files\Lavasoft
2009-02-15 15:18 . 2009-02-15 15:46 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-02-15 15:09 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2009-02-13 23:34 . 2009-02-16 00:48 <DIR> d-------- c:\program files\system
2009-02-13 22:39 . 2009-02-13 22:39 <DIR> d-------- c:\documents and settings\Nino\Application Data\Malwarebytes
2009-02-13 22:33 . 2009-02-13 22:33 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-13 21:25 . 2009-02-13 21:25 <DIR> d-------- c:\documents and settings\Sasa\Application Data\Sunbelt
2009-02-13 21:25 . 2009-02-13 21:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-13 21:22 . 2009-02-13 21:22 <DIR> d-------- c:\program files\Sunbelt Software
2009-02-13 17:57 . 2009-02-13 22:46 <DIR> d-------- c:\program files\Camfrog
2009-02-13 17:57 . 2009-02-13 17:57 <DIR> d-------- c:\documents and settings\Sasa\Application Data\Camfrog
2009-02-13 15:46 . 2009-02-13 15:49 <DIR> d-------- c:\program files\Valve
2009-02-12 23:05 . 2009-02-12 23:05 360,192 --a------ c:\windows\system32\TuneUpDefragService.exe
2009-02-12 23:05 . 2008-12-11 13:31 27,904 --a------ c:\windows\system32\uxtuneup.dll
2009-02-06 12:17 . 2009-02-06 18:46 687 --a------ c:\windows\SportballChallenge.ini
2009-02-06 10:31 . 2009-02-06 13:23 <DIR> d-------- c:\program files\Bud Redhead
2009-02-06 10:29 . 2009-02-06 10:29 827,392 --a------ c:\windows\system32\FLASH.OCX
2009-02-05 21:17 . 2009-02-05 21:17 <DIR> d-------- c:\program files\Alpha Ball
2009-02-05 17:52 . 2009-02-05 17:52 268 --ah----- C:\sqmdata01.sqm
2009-02-05 17:52 . 2009-02-05 17:52 244 --ah----- C:\sqmnoopt01.sqm
2009-01-31 12:04 . 2009-01-31 12:04 <DIR> d-------- c:\program files\Common Files\SWF Studio
2009-01-26 14:58 . 2009-01-26 14:58 <DIR> d-------- c:\program files\ReflexiveArcade
2009-01-26 14:58 . 2009-01-29 12:27 <DIR> d-------- c:\program files\Professor Fizzwizzle And The Molten Mystery
2009-01-25 23:46 . 2009-02-16 17:01 <DIR> d-------- c:\program files\AutoShutdown
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 16:03 --------- d-----w c:\documents and settings\Sasa\Application Data\uTorrent
2009-02-15 23:30 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-15 21:27 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-15 19:57 --------- d-----w c:\program files\sXe Injected
2009-02-15 19:49 --------- d-----w c:\program files\EarthView
2009-02-15 19:48 --------- d-----w c:\program files\DDORMap
2009-02-15 19:48 --------- d-----w c:\program files\DAEMON Tools
2009-02-15 19:31 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-15 16:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-15 16:32 --------- d-----w c:\program files\Mozilla Thunderbird
2009-02-15 15:15 --------- d-----w c:\documents and settings\Sasa\Application Data\mIRC
2009-02-15 15:14 --------- d-----w c:\program files\mIRC
2009-02-14 20:46 --------- d-----w c:\program files\Yahoo!
2009-02-14 14:04 --------- d-----w c:\program files\nLite
2009-02-14 09:34 --------- d-----w c:\program files\eMule
2009-02-13 21:40 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-12 22:05 603,904 ----a-w c:\windows\system32\TUProgSt.exe
2009-02-12 22:05 --------- d-----w c:\program files\TuneUp Utilities 2009
2009-02-12 16:59 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-02-12 15:20 --------- d-----w c:\program files\CCleaner
2009-02-12 15:18 --------- d-----w c:\program files\Ashampoo
2009-02-12 15:17 --------- d-----w c:\documents and settings\Sasa\Application Data\Ashampoo
2009-02-11 11:04 --------- d-----w c:\documents and settings\Sasa\Application Data\Skype
2009-02-11 09:59 --------- d-----w c:\program files\Google
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-04 10:12 --------- d-----w c:\program files\Warcraft III
2009-02-02 21:11 --------- d-----w c:\documents and settings\Sasa\Application Data\dvdcss
2009-01-30 17:27 --------- d-----w c:\documents and settings\All Users\Application Data\pdf995
2009-01-30 12:38 202,512 ----a-w c:\windows\system32\PnkBstrB.exe
2009-01-23 18:32 --------- d-----w c:\program files\Flickr Uploadr
2009-01-17 18:23 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-17 18:21 --------- d-----w c:\program files\Skolski Latinski Recnik
2009-01-11 21:10 --------- d-----w c:\documents and settings\Sasa\Application Data\Pump
2009-01-11 20:57 --------- d-----w c:\documents and settings\Sasa\Application Data\Podmailing
2009-01-11 20:50 --------- d-----w c:\program files\Podmailing
2009-01-09 22:35 --------- d-----w c:\documents and settings\Sasa\Application Data\Spotify
2009-01-09 18:12 --------- d-----w c:\documents and settings\Sasa\Application Data\Vso
2009-01-09 17:54 --------- d-----w c:\documents and settings\All Users\Application Data\vsosdk
2009-01-08 10:50 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-01-08 10:50 47,360 ----a-w c:\documents and settings\Sasa\Application Data\pcouffin.sys
2009-01-08 10:50 --------- d-----w c:\program files\VSO
2009-01-06 14:35 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-05 09:46 --------- d-----w c:\program files\CyberLeadingCorp
2009-01-03 16:08 --------- d-----w c:\documents and settings\Sasa\Application Data\Winamp
2009-01-03 16:00 --------- d-----w c:\documents and settings\Sasa\Application Data\ICQ
2009-01-02 19:16 --------- d-----w c:\program files\Garena
2009-01-02 15:11 --------- d-----w c:\program files\DX-Ball
2009-01-01 18:05 --------- d-----w c:\program files\Winamp
2009-01-01 17:12 --------- d-----w c:\documents and settings\Sasa\Application Data\AIMP
2008-12-31 09:35 --------- d-----w c:\program files\AIMP2
2008-12-30 15:32 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-30 06:04 52,224 ----a-w c:\windows\system32\Snow.Village.3D.Screensaver.v1.1.0.2-RES-patch.exe
2008-12-29 10:26 --------- d-----w c:\program files\Smoky City Design
2008-12-27 23:15 --------- d-----w c:\documents and settings\Sasa\Application Data\FileZilla
2008-12-27 17:28 --------- d-----w c:\documents and settings\Sasa\Application Data\M3
2008-12-25 21:32 --------- d-----w c:\program files\Java
2008-12-25 12:49 --------- d-----w c:\documents and settings\Sasa\Application Data\Desktopicon
2008-12-24 18:45 --------- d-----w c:\program files\FileZilla FTP Client
2008-12-24 12:24 --------- d-----w c:\documents and settings\Sasa\Application Data\JAlbum
2008-12-24 08:16 --------- d-----w c:\documents and settings\Sasa\Application Data\LimeWire
2008-12-24 07:32 --------- d-----w c:\program files\Jalbum8.1
2008-12-23 10:14 --------- d-----w c:\program files\Soulseek
2008-12-21 17:06 --------- d-----w c:\program files\TC PowerPack
2008-12-21 13:54 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-12-20 22:19 --------- d-----w c:\documents and settings\Sasa\Application Data\ArcSoft
2008-12-20 22:18 --------- d-----w c:\program files\ArcSoft
2008-12-20 20:32 --------- d-----w c:\program files\totalcmd
2008-12-20 16:12 --------- d-----w c:\program files\Common Files\Adobe
2008-12-20 15:57 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-12-20 13:50 --------- d-----w c:\program files\Adobe Media Player
2008-12-18 12:04 --------- d-----w c:\program files\Opera
2008-12-17 22:04 --------- d-----w c:\documents and settings\Sasa\Application Data\BSplayer PRO
2008-12-12 21:47 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-08 11:53 57,344 ----a-w c:\windows\system32\ff_vfw.dll
2008-12-07 18:08 795,648 ----a-w c:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w c:\windows\system32\xvidvfw.dll
2008-11-29 11:41 2,294,291 ----a-w c:\windows\system32\x264vfw.dll
2008-09-27 10:44 2,516 --sha-w c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2008-09-27 10:42 8 --sh--r c:\documents and settings\All Users\Application Data\E6FF164BA3.sys
2008-02-25 18:10 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-03-06 12:29 88 --sha-r c:\windows\system32\E6FF164BA3.sys
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2008-04-18 17:15 2,516 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-16_ 0.56.00.67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-16 16:01:54 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_5dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="c:\documents and settings\Sasa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-20 133104]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-02-10 270128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968]
"Quick TV Agent"="c:\program files\Terminator\Quick TV\Scheduled.exe" [2004-10-11 740352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"WinDVR SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2003-11-18 155648]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2004-07-27 c:\windows\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 c:\windows\system32\narrator.exe]
c:\documents and settings\Sasa\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-03-19 4742184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-11-09 151552]
TV Remote Control.lnk - c:\program files\Terminator\TV7131 Utilities\P3XRCtl.exe [2008-01-05 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"VIDC.ACDV"= ACDV.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck smrgdf c:\documents and settings\Sasa\Application Data\iolo\\0autocheck lsdelete\0autocheck lsdelete\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0OODBS
[HKLM\~\startupfolder\C:^Documents and Settings^Sasa^Start Menu^Programs^Startup^Babuki.lnk]
backup=c:\windows\pss\Babuki.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hard Disk Sentinel]
--a------ 2008-11-09 12:16 3407360 c:\program files\Hard Disk Sentinel\HDSentinel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Podmailing]
--a------ 2008-12-11 11:03 173568 c:\program files\Podmailing\podmailing.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
"RegistryMechanic"=c:\program files\Registry Mechanic\RegMech.exe /H
"Google Update"="c:\documents and settings\Sasa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Hard Disk Sentinel"="c:\program files\Hard Disk Sentinel\HDSentinel.exe" /AUTORUN
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Babylon Client"=c:\program files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"OODefragTray"=c:\windows\system32\oodtray.exe
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\ApexDC++\\ApexDC.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"d:\\Programi\\TeamViewerPortable_en\\TeamViewer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Documents and Settings\\Sasa\\Desktop\\CryptLoad_1.1.4\\RouterClient.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Documents and Settings\\Sasa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Sasa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Documents and Settings\\Sasa\\Desktop\\TeamViewerPortable_en\\TeamViewer.exe"=
"c:\\Documents and Settings\\Sasa\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Podmailing\\podmailing.exe"=
"c:\\Program Files\\JLC's Software\\Internet TV\\Internet TV.exe"=
"c:\\Program Files\\AutoShutdown\\AutoShutdown.exe"=
"d:\\DC++ downloads\\LDCPlusPlus.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
"c:\\Program Files\\Valve\\hlds.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"55380:TCP"= 55380:TCP:tshack
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-08-18 34312]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-02-15 160648]
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2009-02-15 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avwebgrd.exe [2009-02-15 258305]
R2 AutoShutdown;AutoShutdown Service;c:\progra~1\AUTOSH~1\AS_Service.exe [2009-01-25 244736]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2009-02-15 41217]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2008-11-22 603904]
R2 WinI2C-DDC;WinI2C-DDC Kernel Mode Driver;c:\windows\system32\drivers\ddcdrv.sys [2008-06-04 10240]
R3 Cap713x;Philips Cap713x Video Capture;c:\windows\system32\drivers\Cap713x.sys [2008-01-05 414592]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 ekrn;Eset Service;"c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe" --> c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [?]
S2 gupdate1c9427e290dcb1e;Google Update Service (gupdate1c9427e290dcb1e);c:\program files\Google\Update\GoogleUpdate.exe [2008-11-09 133104]
S3 k310bus;Sony Ericsson K310 Driver driver (WDM);c:\windows\system32\drivers\k310bus.sys [2008-10-13 60800]
S3 k310mdfl;Sony Ericsson K310 USB WMC Modem Filter;c:\windows\system32\drivers\k310mdfl.sys [2008-10-13 9264]
S3 k310mdm;Sony Ericsson K310 USB WMC Modem Driver;c:\windows\system32\drivers\k310mdm.sys [2008-10-13 96352]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-15 356920]
S3 sys32;System Driver;\??\c:\windows\system32\drivers\sys32.sys --> c:\windows\system32\drivers\sys32.sys [?]
S3 Z302Mic;Vimicro Z302 Mic Audio Filter Driver;c:\windows\system32\drivers\UsbMicfilt.sys [2008-03-21 22571]
S3 ZSMC302;PC CAM 300A;c:\windows\system32\drivers\usbVM302.sys [2008-03-21 93450]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93175b98-f8f7-11dd-9672-000feafaf521}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 21:36]
2009-02-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-02-16 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-20 10:44]
2009-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-839522115-682003330-1003.job
- c:\documents and settings\Sasa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-20 10:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=localhost:7070
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Link to &MidpX - c:\program files\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
LSP: avsda.dll
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Sasa\Application Data\Mozilla\Firefox\Profiles\rtzqt3sy.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\documents and settings\Sasa\Application Data\Mozilla\Firefox\Profiles\rtzqt3sy.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-16 17:02:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1715567821-839522115-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{205D0787-C690-164D-D6EF-F315C201A79A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hailoinofnmpinjp"=hex:6e,62,68,66,65,70,62,65,62,6d,61,70,66,68,68,61,68,69,
67,6e,67,68,66,6d,62,6d,68,69,66,62,6e,62,68,68,63,6a,69,61,61,6a,6d,6f,6f,\
"jailoinofnmpinjppnka"=hex:66,61,68,66,6f,69,65,6a,6f,62,70,70,00,06
"paalhieninokdmmocoeikpmkjbmdbmla"=hex:65,61,68,66,6c,69,67,69,66,67,00,70
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="41899AEFBF683B5DF043E9087FBC861FBB1D54657EBA69EDC03E5A31C142813F2C7709B488D01DC40652D957C61B7AB5D42FCAAE683153AA0E
75DBA872B7340A54CFCEB7E32CAF7A8A7A3C15F0BAD9F5B2A67C188EA88F601D60531544C699B56E167FD25AF8943B
E8A08506504EB0D6926657ED25A5B95EA283CE6E70E3F90AC291E647CA3E60FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127
BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A9C6AECB7A5D1407BA7FD869164D679432247FE309C9BF19E599875921A131CBE05D3F
C16D0B7733BD51F358D307ECA7B29214028C365BC4FBB87014D0C24496586483E7A016319294255B3D0F6622699F237E722E0BFDA03E276D85F8A41BFBBDE1326CDB18D542C2967EB3C1D73A3FA20259
F508F0A1082B46E43A7D6659D679311F24320DCBB03E1B0A6034309C348CDC1E969BFD82F9DAB1FB30BE78B7E20C39336975BD479EBF5770AE34B79B87324E21A93970A06EB7BE86F48B3A9844BFB68
BE625F60B14D6169D6D8B1882D90CC88CA946FBED74248FEFCEB356D41D416A46F1A6CDEE24ED498EC5E1AE62B21EA6A7892EF98DC97C9D717E53A0CB94D7E21DF9917B4FEB890E1DFD9FDCB32473
57FD519963D41894DAEAD8AE7BB65E936F85A1B47CB6B79EC5E798EA9EE
B6C878884797B5592456B303611332B9B283D30C6043B71002A2D17336A9BD8F1E9192876662F29A
BE26F988A1BE5C503177F7F2495F771926BBD4345B6306E4431F6C201AE48B22D3609F43123A0A1AA45F6BB
0EFBECE55DACC4378C2B48D1F758ADC298998358D6FC9EE49611D417F2548B6B39C2CD6599640DFDA3DBA382FB5F5156E2A14
5C787865E772C2BCBEF19AAA100F49D276CF0B4CE08D803334F07C09010C8AB853F24478DFE189E1DFCCCD634ACC520D77C8
063590AAABF3A0A459C30C6697D0C8003560591B4FCB911348ACEEAE0441319DA5B10FDCD935486D434879394C3
77D27370308C11386305E81814753567E24B86A8E7202BE5EBA0C86F80D4CF0C3880B1768F8EEEABB034F67BB84D5FCAA0207DFD6BF1600042B329581A2C564C1758746937F946
918DFC5F4E05B634157D28AC32B839BC11ECA3EF1FE90114D9AAAD6
27350F6C10AB7C317D458393BCDFB77F73D837EC5AC54D30C16947CAA71E2561760956FBD9BC2F188F1A2222FE2F5A7343F900E3246343061B2D60DF0B0012DA49E57934EAD156F102F69
7F012615552BF7B97AEF3A9EA5C51200E56E1D1A908DC3FBD5B90C6930FCB8C5A7D24DDB201CCEEE19A047F8250672737BE21D19E2C987"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(684)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
c:\windows\system32\avsda.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Premium\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Premium\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\PSIService.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-02-16 17:07:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-16 16:07:42
ComboFix2.txt 2009-02-15 23:58:29
ComboFix3.txt 2008-06-29 15:39:13
Pre-Run: 15,110,840,320 bytes free
Post-Run: 15,093,731,328 bytes free
407
|