Poslao: 05 Mar 2009 19:03
|
offline
- Z.Ziska
- Građanin
- Pridružio: 04 Mar 2009
- Poruke: 54
- Gde živiš: Vojvodina Serbia Selenca
|
ComboFix 09-03-04.01 - Ziska 2009-03-05 18:41:44.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.255.45 [GMT 1:00]
Running from: c:\documents and settings\Ziska\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ziska\Desktop\CFScript1.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\windows\system32\23.scr
c:\windows\system32\26.scr
c:\windows\system32\28.scr
c:\windows\system32\32.scr
c:\windows\system32\40.scr
c:\windows\system32\41.scr
c:\windows\system32\46.scr
c:\windows\system32\53.scr
c:\windows\system32\75.scr
c:\windows\system32\86.scr
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\23.scr
c:\windows\system32\26.scr
c:\windows\system32\28.scr
c:\windows\system32\32.scr
c:\windows\system32\40.scr
c:\windows\system32\41.scr
c:\windows\system32\46.scr
c:\windows\system32\53.scr
c:\windows\system32\75.scr
c:\windows\system32\86.scr
.
((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.
2009-03-05 18:19 . 2009-03-05 18:19 41,987 --a------ c:\windows\system32\82.scr
2009-03-05 18:17 . 2009-03-05 18:17 41,987 --a------ c:\windows\system32\68.scr
2009-03-05 18:12 . 2009-03-05 18:37 41,987 --a------ c:\windows\system32\38.scr
2009-03-05 18:12 . 2009-03-05 18:12 41,987 --a------ c:\windows\system32\20.scr
2009-03-05 18:09 . 2009-03-05 18:09 41,987 --a------ c:\windows\system32\03.scr
2009-03-05 18:09 . 2009-03-05 18:09 41,987 -r-hs---- c:\windows\system\msile.exe
2009-03-05 12:35 . 2009-03-05 12:35 63 --a------ c:\windows\wininit.ini
2009-03-04 21:52 . 2009-03-04 21:52 <DIR> d-------- c:\program files\Trend Micro
2009-03-04 19:34 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Stardock
2009-03-04 19:34 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Common Files\Stardock
2009-03-04 19:17 . 2009-03-04 19:17 2,560 --a------ c:\windows\_MSRSTRT.EXE
2009-03-03 20:47 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-03 20:47 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-03 20:47 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-01 14:22 . 2009-03-01 14:22 <DIR> d---s---- c:\documents and settings\Ziska\UserData
2009-03-01 13:23 . 2009-03-05 18:19 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-01 12:40 . 2009-03-05 12:29 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-01 12:40 . 2009-03-01 14:22 <DIR> d-------- c:\documents and settings\Ziska\Application Data\AVGTOOLBAR
2009-03-01 12:40 . 2009-03-01 12:40 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-01 12:40 . 2009-03-01 12:40 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-01 12:40 . 2009-03-01 12:40 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-01 12:39 . 2009-03-01 12:39 <DIR> d-------- c:\program files\AVG
2009-03-01 12:39 . 2009-03-01 12:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-01 02:24 . 2009-03-01 23:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-27 20:56 . 2009-03-01 01:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware(2)
2009-02-26 22:02 . 2009-02-26 22:02 <DIR> d-------- c:\documents and settings\Ziska\Application Data\Malwarebytes
2009-02-26 22:02 . 2009-02-26 22:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-14 18:46 . 2009-03-03 17:37 238 --a------ c:\windows\mafosav.INI
2009-02-14 15:55 . 2009-02-14 15:55 <DIR> d-------- c:\program files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 17:07 --------- d-----w c:\program files\FlashGet
2009-02-07 15:22 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-07 12:02 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-25 18:12 --------- d-----w c:\program files\Common Files\Real
2009-01-24 11:34 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-23 21:31 --------- d-----w c:\documents and settings\Ziska\Application Data\HLSW
2009-01-16 22:24 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-01-16 22:24 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-01-16 22:12 --------- d-----w c:\program files\Windows Live
2009-01-12 19:58 --------- d-----w c:\documents and settings\Ziska\Application Data\NetSupport
2009-01-12 19:53 --------- d-----w c:\program files\NetSupport
2009-01-12 19:53 --------- d-----w c:\documents and settings\All Users\Application Data\NetSupport
2009-01-11 21:19 --------- d-----w c:\program files\MessengerDiscovery
2008-12-28 12:05 218,624 ----a-w c:\windows\system32\uxtheme.dll
2008-12-28 12:05 111,110 ----a-w c:\windows\BricoPackUninst.cmd
.
------- Sigcheck -------
2008-04-14 04:42 699904 8a513e79e7980018daedca586b866bc3 c:\windows\system32\wininet.dll
2008-04-14 04:42 699904 8a513e79e7980018daedca586b866bc3 c:\windows\system32\dllcache\wininet.dll
2008-04-14 04:42 975872 561a50497324f378e30f55d09b4e1258 c:\windows\explorer.exe
2008-04-14 04:42 975872 088a0cd3d4cd3b584f3a4150d6cf941e c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 c:\windows\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2005-12-10 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Gigabyte Wireless Utility.lnk - c:\program files\GIGABYTE\Common\GNConfig.exe [12/26/2008 10:59:24 AM 753664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-01 12:40 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msile]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\client32.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\PCICTLUI.EXE"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\pcideply.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\PCISA.EXE"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\pciscrui.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\runscrip.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/1/2009 12:40:10 PM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/1/2009 12:40:18 PM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/1/2009 12:39:44 PM 298264]
S2 msile;microsoft install le;c:\windows\system\msile.exe [3/5/2009 6:09:41 PM 41987]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [12/26/2008 11:23:14 AM 670592]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MSILE
*Deregistered* - CSIScanner
*Deregistered* - pxscan
.
.
------- Supplementary Scan -------
.
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {BCE8778D-1AE7-46C0-98F0-93CB5E6CF7BC} = 195.252.122.154
FF - ProfilePath - c:\documents and settings\Ziska\Application Data\Mozilla\Firefox\Profiles\nhsg24iv.default\
FF - prefs.js: browser.startup.homepage - abakusbp.net
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-05 18:43:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Nf815c75f]
@Denied: (4) (Everyone)
@Denied: (4) (Administrators)
@Allowed: (A B C D Full GENERIC_EXECUTE GENERIC_WRITE Read 1 2 3 4 5 6) (LocalSystem)
"a"="M"
"InternetCode"="U52LDJMC37ONPGW35EG4SPJX45LFAJ6ESRKK7IY8"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'csrss.exe'(532)
c:\program files\NetSupport\NetSupport Manager\pcihooks.dll
.
Completion time: 2009-03-05 18:45:23
ComboFix-quarantined-files.txt 2009-03-05 17:45:20
ComboFix2.txt 2009-03-05 17:06:47
ComboFix3.txt 2009-03-04 22:25:51
Pre-Run: 5,746,061,312 bytes free
Post-Run: 5,736,361,984 bytes free
181
Dopuna: 05 Mar 2009 19:03
I ?????????
|
|
|
|
|
|
Poslao: 05 Mar 2009 19:55
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Treba mi log Autostart skeniranja. Do Autostart taba dolaziš klikom na >>>.
|
|
|
|
|
|
Poslao: 05 Mar 2009 21:22
|
offline
- Z.Ziska
- Građanin
- Pridružio: 04 Mar 2009
- Poruke: 54
- Gde živiš: Vojvodina Serbia Selenca
|
ComboFix 09-03-04.01 - Ziska 2009-03-05 21:10:40.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.255.51 [GMT 1:00]
Running from: c:\documents and settings\Ziska\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ziska\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\windows\system\msile.exe
c:\windows\system32\03.scr
c:\windows\system32\20.scr
c:\windows\system32\38.scr
c:\windows\system32\68.scr
c:\windows\system32\82.scr
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system\msile.exe
c:\windows\system32\03.scr
c:\windows\system32\20.scr
c:\windows\system32\38.scr
c:\windows\system32\68.scr
c:\windows\system32\82.scr
c:\windows\system32\drivers\sysdrv32.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSILE
-------\Legacy_SYSDRV32
-------\Service_msile
-------\Service_sysdrv32
((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.
2009-03-05 19:49 . 2009-03-05 19:49 41,987 --a------ c:\windows\system32\84.scr
2009-03-05 19:49 . 2009-03-05 19:49 41,987 --a------ c:\windows\system32\47.scr
2009-03-05 19:45 . 2009-03-05 19:45 41,987 --a------ c:\windows\system32\51.scr
2009-03-05 19:30 . 2009-03-05 19:30 41,987 --a------ c:\windows\system32\71.scr
2009-03-05 19:30 . 2009-03-05 19:54 250 --a------ c:\windows\gmer.ini
2009-03-05 19:28 . 2009-03-05 19:28 41,987 --a------ c:\windows\system32\00.scr
2009-03-05 19:27 . 2009-03-05 19:27 41,987 --a------ c:\windows\system32\85.scr
2009-03-05 19:27 . 2009-03-05 19:27 41,987 --a------ c:\windows\system32\10.scr
2009-03-05 19:25 . 2009-03-05 19:25 41,987 --a------ c:\windows\system32\40.scr
2009-03-05 19:24 . 2009-03-05 19:24 41,987 --a------ c:\windows\system32\21.scr
2009-03-05 19:08 . 2009-03-05 19:32 41,987 --a------ c:\windows\system32\44.scr
2009-03-05 19:06 . 2009-03-05 19:08 41,987 --a------ c:\windows\system32\81.scr
2009-03-05 19:05 . 2009-03-05 19:05 41,987 --a------ c:\windows\system32\24.scr
2009-03-05 19:03 . 2009-03-05 19:03 41,987 --a------ c:\windows\system32\86.scr
2009-03-05 18:51 . 2009-03-05 18:51 41,987 --a------ c:\windows\system32\54.scr
2009-03-05 18:49 . 2009-03-05 18:49 41,987 --a------ c:\windows\system32\53.scr
2009-03-05 18:49 . 2009-03-05 18:49 41,987 --a------ c:\windows\system32\34.scr
2009-03-05 12:35 . 2009-03-05 12:35 63 --a------ c:\windows\wininit.ini
2009-03-04 21:52 . 2009-03-04 21:52 <DIR> d-------- c:\program files\Trend Micro
2009-03-04 19:34 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Stardock
2009-03-04 19:34 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Common Files\Stardock
2009-03-04 19:17 . 2009-03-04 19:17 2,560 --a------ c:\windows\_MSRSTRT.EXE
2009-03-03 20:47 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-03 20:47 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-03 20:47 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-01 14:22 . 2009-03-01 14:22 <DIR> d---s---- c:\documents and settings\Ziska\UserData
2009-03-01 13:23 . 2009-03-05 18:19 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-01 12:40 . 2009-03-05 12:29 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-01 12:40 . 2009-03-01 14:22 <DIR> d-------- c:\documents and settings\Ziska\Application Data\AVGTOOLBAR
2009-03-01 12:40 . 2009-03-01 12:40 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-01 12:40 . 2009-03-01 12:40 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-01 12:40 . 2009-03-01 12:40 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-01 12:39 . 2009-03-01 12:39 <DIR> d-------- c:\program files\AVG
2009-03-01 12:39 . 2009-03-01 12:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-01 02:24 . 2009-03-01 23:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-27 20:56 . 2009-03-01 01:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware(2)
2009-02-26 22:02 . 2009-02-26 22:02 <DIR> d-------- c:\documents and settings\Ziska\Application Data\Malwarebytes
2009-02-26 22:02 . 2009-02-26 22:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-14 18:46 . 2009-03-03 17:37 238 --a------ c:\windows\mafosav.INI
2009-02-14 15:55 . 2009-02-14 15:55 <DIR> d-------- c:\program files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 19:22 --------- d-----w c:\program files\FlashGet
2009-02-07 15:22 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-07 12:02 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-25 18:12 --------- d-----w c:\program files\Common Files\Real
2009-01-24 11:34 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-23 21:31 --------- d-----w c:\documents and settings\Ziska\Application Data\HLSW
2009-01-16 22:24 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-01-16 22:24 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-01-16 22:12 --------- d-----w c:\program files\Windows Live
2009-01-12 19:58 --------- d-----w c:\documents and settings\Ziska\Application Data\NetSupport
2009-01-12 19:53 --------- d-----w c:\program files\NetSupport
2009-01-12 19:53 --------- d-----w c:\documents and settings\All Users\Application Data\NetSupport
2009-01-11 21:19 --------- d-----w c:\program files\MessengerDiscovery
2008-12-28 12:05 218,624 ----a-w c:\windows\system32\uxtheme.dll
2008-12-28 12:05 111,110 ----a-w c:\windows\BricoPackUninst.cmd
.
------- Sigcheck -------
2008-04-14 04:42 699904 8a513e79e7980018daedca586b866bc3 c:\windows\system32\wininet.dll
2008-04-14 04:42 699904 8a513e79e7980018daedca586b866bc3 c:\windows\system32\dllcache\wininet.dll
2008-04-14 04:42 975872 561a50497324f378e30f55d09b4e1258 c:\windows\explorer.exe
2008-04-14 04:42 975872 088a0cd3d4cd3b584f3a4150d6cf941e c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-04_23.24.58.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-05 18:30:17 884,736 ----a-w c:\windows\gmer.dll
+ 2008-04-17 20:13:02 811,008 ----a-w c:\windows\gmer.exe
+ 2009-03-05 18:30:17 85,969 ----a-w c:\windows\system32\drivers\gmer.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 c:\windows\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2005-12-10 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Gigabyte Wireless Utility.lnk - c:\program files\GIGABYTE\Common\GNConfig.exe [12/26/2008 10:59:24 AM 753664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-01 12:40 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\client32.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\PCICTLUI.EXE"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\pcideply.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\PCISA.EXE"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\pciscrui.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\runscrip.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/1/2009 12:40:10 PM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/1/2009 12:40:18 PM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/1/2009 12:39:44 PM 298264]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [12/26/2008 11:23:14 AM 670592]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
.
.
------- Supplementary Scan -------
.
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {BCE8778D-1AE7-46C0-98F0-93CB5E6CF7BC} = 195.252.122.154
FF - ProfilePath - c:\documents and settings\Ziska\Application Data\Mozilla\Firefox\Profiles\nhsg24iv.default\
FF - prefs.js: browser.startup.homepage - abakusbp.net
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-05 21:14:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Nf815c75f]
@Denied: (4) (Everyone)
@Denied: (4) (Administrators)
@Allowed: (A B C D Full GENERIC_EXECUTE GENERIC_WRITE Read 1 2 3 4 5 6) (LocalSystem)
"a"="M"
"InternetCode"="U52LDJMC37ONPGW35EG4SPJX45LFAJ6ESRKK7IY8"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'csrss.exe'(540)
c:\program files\NetSupport\NetSupport Manager\pcihooks.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\NetSupport\NetSupport Manager\client32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-05 21:16:40 - machine was rebooted [Ziska]
ComboFix-quarantined-files.txt 2009-03-05 20:16:35
ComboFix2.txt 2009-03-05 17:45:26
ComboFix3.txt 2009-03-05 17:06:47
ComboFix4.txt 2009-03-04 22:25:51
Pre-Run: 5,696,479,232 bytes free
Post-Run: 5,686,456,320 bytes free
201
|
|
|
|
|
Poslao: 05 Mar 2009 22:31
|
offline
- Z.Ziska
- Građanin
- Pridružio: 04 Mar 2009
- Poruke: 54
- Gde živiš: Vojvodina Serbia Selenca
|
ComboFix 09-03-04.01 - Ziska 2009-03-05 22:22:27.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.255.40 [GMT 1:00]
Running from: c:\documents and settings\Ziska\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ziska\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\windows\system32\00.scr
c:\windows\system32\10.scr
c:\windows\system32\21.scr
c:\windows\system32\24.scr
c:\windows\system32\34.scr
c:\windows\system32\40.scr
c:\windows\system32\44.scr
c:\windows\system32\47.scr
c:\windows\system32\51.scr
c:\windows\system32\53.scr
c:\windows\system32\54.scr
c:\windows\system32\71.scr
c:\windows\system32\81.scr
c:\windows\system32\84.scr
c:\windows\system32\85.scr
c:\windows\system32\86.scr
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\00.scr
c:\windows\system32\10.scr
c:\windows\system32\21.scr
c:\windows\system32\24.scr
c:\windows\system32\34.scr
c:\windows\system32\40.scr
c:\windows\system32\44.scr
c:\windows\system32\47.scr
c:\windows\system32\51.scr
c:\windows\system32\53.scr
c:\windows\system32\54.scr
c:\windows\system32\71.scr
c:\windows\system32\81.scr
c:\windows\system32\84.scr
c:\windows\system32\85.scr
c:\windows\system32\86.scr
.
((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.
2009-03-05 22:24 . 2009-03-05 22:24 41,987 --a------ c:\windows\system32\50.scr
2009-03-05 21:39 . 2009-03-05 21:39 41,987 --a------ c:\windows\system32\04.scr
2009-03-05 21:35 . 2009-03-05 21:35 41,987 -r-hs---- c:\windows\system\msile.exe
2009-03-05 19:30 . 2009-03-05 19:54 250 --a------ c:\windows\gmer.ini
2009-03-05 12:35 . 2009-03-05 12:35 63 --a------ c:\windows\wininit.ini
2009-03-04 21:52 . 2009-03-04 21:52 <DIR> d-------- c:\program files\Trend Micro
2009-03-04 19:34 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Stardock
2009-03-04 19:34 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Common Files\Stardock
2009-03-04 19:17 . 2009-03-04 19:17 2,560 --a------ c:\windows\_MSRSTRT.EXE
2009-03-03 20:47 . 2009-03-04 19:34 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-03 20:47 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-03 20:47 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-01 14:22 . 2009-03-01 14:22 <DIR> d---s---- c:\documents and settings\Ziska\UserData
2009-03-01 13:23 . 2009-03-05 18:19 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-01 12:40 . 2009-03-05 12:29 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-01 12:40 . 2009-03-01 14:22 <DIR> d-------- c:\documents and settings\Ziska\Application Data\AVGTOOLBAR
2009-03-01 12:40 . 2009-03-01 12:40 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-01 12:40 . 2009-03-01 12:40 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-01 12:40 . 2009-03-01 12:40 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-01 12:39 . 2009-03-01 12:39 <DIR> d-------- c:\program files\AVG
2009-03-01 12:39 . 2009-03-01 12:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-01 02:24 . 2009-03-01 23:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-27 20:56 . 2009-03-01 01:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware(2)
2009-02-26 22:02 . 2009-02-26 22:02 <DIR> d-------- c:\documents and settings\Ziska\Application Data\Malwarebytes
2009-02-26 22:02 . 2009-02-26 22:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-14 18:46 . 2009-03-03 17:37 238 --a------ c:\windows\mafosav.INI
2009-02-14 15:55 . 2009-02-14 15:55 <DIR> d-------- c:\program files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 20:16 --------- d-----w c:\program files\FlashGet
2009-02-07 15:22 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-07 12:02 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-25 18:12 --------- d-----w c:\program files\Common Files\Real
2009-01-24 11:34 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-23 21:31 --------- d-----w c:\documents and settings\Ziska\Application Data\HLSW
2009-01-16 22:24 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-01-16 22:24 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-01-16 22:12 --------- d-----w c:\program files\Windows Live
2009-01-12 19:58 --------- d-----w c:\documents and settings\Ziska\Application Data\NetSupport
2009-01-12 19:53 --------- d-----w c:\program files\NetSupport
2009-01-12 19:53 --------- d-----w c:\documents and settings\All Users\Application Data\NetSupport
2009-01-11 21:19 --------- d-----w c:\program files\MessengerDiscovery
2008-12-28 12:05 218,624 ----a-w c:\windows\system32\uxtheme.dll
2008-12-28 12:05 111,110 ----a-w c:\windows\BricoPackUninst.cmd
.
------- Sigcheck -------
2008-04-14 04:42 699904 8a513e79e7980018daedca586b866bc3 c:\windows\system32\wininet.dll
2008-04-14 04:42 699904 8a513e79e7980018daedca586b866bc3 c:\windows\system32\dllcache\wininet.dll
2008-04-14 04:42 975872 561a50497324f378e30f55d09b4e1258 c:\windows\explorer.exe
2008-04-14 04:42 975872 088a0cd3d4cd3b584f3a4150d6cf941e c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-04_23.24.58.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-05 18:30:17 884,736 ----a-w c:\windows\gmer.dll
+ 2008-04-17 20:13:02 811,008 ----a-w c:\windows\gmer.exe
+ 2009-03-05 18:30:17 85,969 ----a-w c:\windows\system32\drivers\gmer.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 c:\windows\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2005-12-10 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Gigabyte Wireless Utility.lnk - c:\program files\GIGABYTE\Common\GNConfig.exe [12/26/2008 10:59:24 AM 753664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-01 12:40 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msile]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\client32.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\PCICTLUI.EXE"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\pcideply.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\PCISA.EXE"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\pciscrui.exe"=
"c:\\Program Files\\NetSupport\\NetSupport Manager\\runscrip.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/1/2009 12:40:10 PM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/1/2009 12:40:18 PM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/1/2009 12:39:44 PM 298264]
S2 msile;microsoft install le;c:\windows\system\msile.exe [3/5/2009 9:35:24 PM 41987]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [12/26/2008 11:23:14 AM 670592]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MSILE
.
.
------- Supplementary Scan -------
.
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {BCE8778D-1AE7-46C0-98F0-93CB5E6CF7BC} = 195.252.122.154
FF - ProfilePath - c:\documents and settings\Ziska\Application Data\Mozilla\Firefox\Profiles\nhsg24iv.default\
FF - prefs.js: browser.startup.homepage - abakusbp.net
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-05 22:24:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Nf815c75f]
@Denied: (4) (Everyone)
@Denied: (4) (Administrators)
@Allowed: (A B C D Full GENERIC_EXECUTE GENERIC_WRITE Read 1 2 3 4 5 6) (LocalSystem)
"a"="M"
"InternetCode"="U52LDJMC37ONPGW35EG4SPJX45LFAJ6ESRKK7IY8"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'csrss.exe'(540)
c:\program files\NetSupport\NetSupport Manager\pcihooks.dll
.
Completion time: 2009-03-05 22:25:54
ComboFix-quarantined-files.txt 2009-03-05 21:25:51
ComboFix2.txt 2009-03-05 20:16:42
ComboFix3.txt 2009-03-05 17:45:26
ComboFix4.txt 2009-03-05 17:06:47
ComboFix5.txt 2009-03-05 21:21:34
Pre-Run: 5,681,504,256 bytes free
Post-Run: 5,671,395,328 bytes free
197
|
|
|
|
|