[ xman25 @ 11.11.2009. 17:18 ] @
Nedavno mi je pocela da iskace ova poruka ![]() ![]() Probao sam sa brisanjem Mozille i ponovnom instalacijom i nista i sa system restore na prethodni dan ali takodje ostaje nepromenjeno. Znaci sada ne mogu vise uopste da pokrenem Mozillu, uvek mi izbacuje one dve poruke. Uradio sam log preko ComboFix-a: Citat: ComboFix 09-11-11.01 - Administrator 11.11.2009 17:48.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.2047.1411 [GMT 1:00] Running from: c:\users\Administrator\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Dealio Toolbar c:\program files\Dealio Toolbar\config.ini c:\program files\Dealio Toolbar\DealioToolbarIE.dll c:\program files\Dealio Toolbar\Res\amazon.gif c:\program files\Dealio Toolbar\Res\apple.gif c:\program files\Dealio Toolbar\Res\barnes.gif c:\program files\Dealio Toolbar\Res\bestbuy.gif c:\program files\Dealio Toolbar\Res\dealio_logo.gif c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif c:\program files\Dealio Toolbar\Res\ebay.gif c:\program files\Dealio Toolbar\Res\icon_settings.gif c:\program files\Dealio Toolbar\Res\macys.gif c:\program files\Dealio Toolbar\Res\newegg.gif c:\program files\Dealio Toolbar\Res\overstock.gif c:\program files\Dealio Toolbar\Res\search-button-hover.gif c:\program files\Dealio Toolbar\Res\search-button.gif c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif c:\program files\Dealio Toolbar\Res\search-chevron.gif c:\program files\Dealio Toolbar\Res\search_amazon.gif c:\program files\Dealio Toolbar\Res\search_dealio.gif c:\program files\Dealio Toolbar\Res\search_ebay.gif c:\program files\Dealio Toolbar\Res\search_yahoo.gif c:\program files\Dealio Toolbar\Res\separator.gif c:\program files\Dealio Toolbar\Res\target.gif c:\program files\Dealio Toolbar\Res\walmart.gif c:\program files\Dealio Toolbar\Res\widgets.xml c:\program files\Dealio Toolbar\SeARchsettings.dll c:\program files\Dealio Toolbar\SearchSettings.exe c:\program files\Dealio Toolbar\SearchSettingsRes409.dll c:\program files\Dealio Toolbar\sscfg.ini c:\program files\Dealio Toolbar\WidgiHelper.exe c:\program files\Fast Browser Search c:\program files\Fast Browser Search\1.bat c:\program files\Fast Browser Search\about.html c:\program files\Fast Browser Search\affid.dat c:\program files\Fast Browser Search\basis.xml c:\program files\Fast Browser Search\basis_br.xml c:\program files\Fast Browser Search\basis_de.xml c:\program files\Fast Browser Search\basis_en.xml c:\program files\Fast Browser Search\basis_es.xml c:\program files\Fast Browser Search\basis_fr.xml c:\program files\Fast Browser Search\basis_it.xml c:\program files\Fast Browser Search\basis_nr.xml c:\program files\Fast Browser Search\basis_pt.xml c:\program files\Fast Browser Search\basis_ru.xml c:\program files\Fast Browser Search\basis_tr.xml c:\program files\Fast Browser Search\BHO.dll c:\program files\Fast Browser Search\ClearRecycleBin.exe c:\program files\Fast Browser Search\error.html c:\program files\Fast Browser Search\FBSPlugin.dll c:\program files\Fast Browser Search\fbsProtection.xml c:\program files\Fast Browser Search\FbsSearchProvider.xml c:\program files\Fast Browser Search\FbsSearchProviderIE8.exe c:\program files\Fast Browser Search\FBStoolbar.dll c:\program files\Fast Browser Search\fbstoolbar.jar c:\program files\Fast Browser Search\fbstoolbar.manifest c:\program files\Fast Browser Search\icons.bmp c:\program files\Fast Browser Search\IE\basis.xml c:\program files\Fast Browser Search\IE\fbsSearchProvider.xml c:\program files\Fast Browser Search\IE\FBStoolbar.exe c:\program files\Fast Browser Search\IE\search_de.bmp c:\program files\Fast Browser Search\IE\search_es.bmp c:\program files\Fast Browser Search\IE\search_fr.bmp c:\program files\Fast Browser Search\IE\search_it.bmp c:\program files\Fast Browser Search\IE\search_pt.bmp c:\program files\Fast Browser Search\IE\search_ru.bmp c:\program files\Fast Browser Search\IE\SearchGuardPlus.exe c:\program files\Fast Browser Search\IE\SearchGuardPlus.ico c:\program files\Fast Browser Search\IE\SGPU.ico c:\program files\Fast Browser Search\info.txt c:\program files\Fast Browser Search\local.xml c:\program files\Fast Browser Search\logobg.bmp c:\program files\Fast Browser Search\MTWBtoolbar.html c:\program files\Fast Browser Search\search.bmp c:\program files\Fast Browser Search\search_br.bmp c:\program files\Fast Browser Search\SGPUpdaterS.exe c:\program files\Fast Browser Search\tbhelper.dll c:\program files\Fast Browser Search\tbs_include_script_003175.js c:\program files\Fast Browser Search\tbs_include_script_005064.js c:\program files\Fast Browser Search\tbs_include_script_012817.js c:\program files\Fast Browser Search\Toolbar Help.htm c:\program files\Fast Browser Search\uninstall.exe c:\program files\Fast Browser Search\uninstalSGP.exe c:\program files\Fast Browser Search\uninstalSGPU.exe c:\program files\Fast Browser Search\update.exe c:\program files\Fast Browser Search\version.txt c:\program files\SGPSA c:\users\Administrator\My Documents\cc_20091103_005612.reg c:\windows\system32\d3d10core.dll c:\windows\system32\kernel32new.dll c:\windows\system32\msvcrtnew.dll c:\windows\version.txt c:\windows\system32\LogonUI.exe . . . is infected!! . ((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 ))))))))))))))))))))))))))))))) . 2009-11-11 15:37 . 2009-11-11 15:37 -------- d-----w- c:\windows\system32\wbem\Repository 2009-11-10 19:45 . 2009-11-10 19:45 -------- d-----w- c:\program files\eGames 2009-11-08 18:04 . 2009-11-08 18:04 10880192 ----a-w- c:\users\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe 2009-11-07 23:42 . 2009-11-07 23:42 -------- d-----w- c:\program files\BS player 2009-11-07 23:00 . 2009-11-07 23:02 -------- d-----w- c:\program files\Your Uninstaller 2009-11-07 22:54 . 2009-11-07 22:58 -------- d-----w- c:\program files\Your Uninstaller 2008 2009-11-07 20:31 . 2009-11-07 20:33 6147544 ----a-w- c:\users\Administrator\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe 2009-11-07 20:31 . 2007-03-22 10:46 126976 ----a-w- c:\users\Administrator\Application Data\GRETECH\GomPlayer\GrLauncher.exe 2009-11-05 00:04 . 2009-11-05 00:04 152576 ----a-w- c:\users\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-11-04 16:00 . 2009-11-04 18:26 -------- d-----w- c:\users\All Users\Application Data\FarmFrenzy3 2009-11-04 15:59 . 2009-11-04 15:59 -------- d-----w- c:\program files\LeeGTs Games 2009-11-03 16:51 . 2009-11-03 16:51 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2009-11-03 16:51 . 2009-11-03 16:51 93360 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys 2009-11-03 16:51 . 2009-11-03 16:51 554280 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll 2009-11-03 16:51 . 2009-11-03 16:51 212480 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll 2009-11-03 16:51 . 2009-11-03 16:51 283944 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll 2009-11-03 16:51 . 2009-11-03 16:51 1223976 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll 2009-11-03 16:51 . 2009-11-03 16:51 242984 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll 2009-10-29 02:03 . 2009-10-29 02:03 -------- d-----w- c:\users\Default User\Local Settings\Application Data\Microsoft Help 2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\users\All Users\Application Data\2BrightSparks 2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\program files\2BrightSparks 2009-10-19 18:33 . 2009-10-19 18:33 -------- d-----w- c:\users\All Users\Application Data\Freedom Scientific 2009-10-19 18:33 . 2009-10-19 18:33 -------- d-----w- c:\program files\ssce 2009-10-19 18:32 . 2009-10-19 18:32 -------- d-----w- c:\windows\system32\HJSMEM 2009-10-19 18:31 . 2009-10-19 18:33 -------- d-----w- c:\program files\Freedom Scientific 2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\4000008500003i\PDFToText.exe 2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\400000600002i\AcroRd32Info.exe 2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\1000000b00002i\verclsid.exe 2009-10-18 18:25 . 2003-12-18 16:53 6656 ----a-w- c:\windows\system32\haspvdd.dll 2009-10-18 18:25 . 2003-12-18 16:53 383 ----a-w- c:\windows\system32\haspdos.sys 2009-10-18 18:25 . 2003-12-18 16:53 304640 ----a-w- c:\windows\system32\hlvdd.dll 2009-10-18 18:25 . 2004-01-31 18:14 420000 ----a-w- c:\windows\system32\drivers\hardlock.sys 2009-10-18 18:25 . 2003-12-18 16:53 47616 ----a-w- c:\windows\system32\drivers\haspnt.sys 2009-10-18 18:22 . 2009-10-18 18:22 -------- d-----w- C:\HaspEmulPE.XP 2009-10-18 18:10 . 2009-10-18 18:10 -------- d-----w- c:\users\Administrator\Application Data\Freedom Scientific 2009-10-18 18:07 . 2009-10-18 18:08 -------- d-----w- c:\program files\anReader 2009-10-18 16:54 . 2009-10-19 18:32 -------- d--h--w- c:\program files\Freedom Scientific Installation Information 2009-10-18 15:57 . 2009-10-18 15:57 -------- d-----w- c:\program files\Rainbow Technologies 2009-10-18 15:57 . 2008-10-07 13:33 6058112 ----a-w- c:\windows\system32\dcmc0d0.dll 2009-10-17 19:31 . 2009-07-23 09:56 714752 ----a-w- c:\windows\system32\drivers\SandBox.sys 2009-10-17 19:30 . 2009-07-13 11:19 256792 ----a-w- c:\windows\system32\drivers\afwcore.sys 2009-10-17 19:29 . 2009-10-17 19:31 -------- d-----w- c:\windows\system32\Filt 2009-10-17 19:29 . 2009-02-18 15:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys 2009-10-17 19:28 . 2009-10-17 19:28 -------- d-----w- c:\program files\Agnitum 2009-10-17 19:28 . 2009-10-17 19:28 -------- d-----w- c:\users\All Users\Application Data\Agnitum 2009-10-17 17:52 . 2009-10-17 17:52 -------- d-sh--w- c:\users\LocalService\IETldCache 2009-10-17 15:50 . 2009-11-03 16:51 537576 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll 2009-10-17 15:46 . 2009-10-17 15:46 -------- dc-h--w- c:\users\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-10-17 15:46 . 2009-10-03 08:15 2924848 -c--a-w- c:\users\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe 2009-10-14 09:40 . 2009-07-17 16:22 1435648 ------w- c:\windows\system32\dllcache\query.dll 2009-10-14 09:37 . 2009-08-26 08:00 247326 ------w- c:\windows\system32\dllcache\strmdll.dll 2009-10-14 09:35 . 2009-09-04 21:03 58880 ------w- c:\windows\system32\dllcache\msasn1.dll 2009-10-13 22:35 . 2009-10-13 22:35 -------- d-----w- c:\program files\Search Guard PlusU 2009-10-13 22:35 . 2009-10-13 22:35 -------- d-----w- c:\program files\Search Guard Plus 2009-10-12 20:47 . 2008-03-05 14:03 329224 ----a-w- c:\windows\system32\DXErr.exe 2009-10-12 20:47 . 2008-03-09 05:25 236 ----a-w- c:\program files\Common Files\dx.reg 2009-10-12 20:47 . 2008-03-05 14:03 209416 ----a-w- c:\windows\system32\dxcpl.exe 2009-10-12 20:47 . 2006-11-02 10:46 167936 ----a-w- c:\windows\system32\dxgi.dll 2009-10-12 20:47 . 2006-11-02 10:46 39936 ----a-w- c:\windows\system32\dwmapi.dll 2009-10-12 20:47 . 2006-11-29 12:06 440080 ----a-w- c:\windows\system32\d3dx10.dll 2009-10-12 20:47 . 2006-11-02 10:47 1162656 ----a-w- c:\windows\system32\ntdllnew.dll 2009-10-12 20:47 . 2008-04-12 16:13 1029126 ----a-w- c:\windows\system32\d3d10.dll 2009-10-12 20:47 . 2009-10-12 20:45 716153 ----a-w- c:\windows\system32\unins000.exe 2009-10-12 20:46 . 2009-10-12 20:47 2733 ----a-w- c:\windows\system32\unins000.dat 2009-10-12 17:17 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2009-10-12 17:17 . 2009-09-04 15:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll 2009-10-12 17:17 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll 2009-10-12 17:17 . 2009-09-04 15:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll 2009-10-12 17:16 . 2009-09-04 15:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll 2009-10-12 17:16 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2009-10-12 17:16 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll 2009-10-12 17:16 . 2009-03-09 13:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll 2009-10-12 17:16 . 2009-03-09 13:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll 2009-10-12 17:16 . 2009-03-09 13:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll 2009-10-12 17:16 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2009-10-12 17:16 . 2009-03-16 12:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll 2009-10-12 17:16 . 2009-03-16 12:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll 2009-10-12 17:14 . 2009-03-16 12:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-11 16:58 . 2009-08-17 12:10 -------- d-----w- c:\users\All Users\Application Data\Babylon 2009-11-11 16:32 . 2009-08-11 16:22 -------- d-----w- c:\program files\Mozilla Thunderbird 2009-11-11 16:29 . 2009-08-01 14:11 -------- d-----w- c:\users\All Users\Application Data\Spyware Terminator 2009-11-11 16:29 . 2009-08-01 14:11 -------- d-----w- c:\program files\Spyware Terminator 2009-11-11 16:00 . 2009-08-01 14:11 -------- d-----w- c:\users\Administrator\Application Data\Spyware Terminator 2009-11-11 08:39 . 2009-08-01 15:34 -------- d---a-w- c:\users\All Users\Application Data\TEMP 2009-11-11 08:21 . 2009-08-01 13:34 -------- d-----w- c:\users\All Users\Application Data\Microsoft Help 2009-11-10 19:55 . 2009-08-01 21:33 -------- d-----w- c:\users\Administrator\Application Data\Skype 2009-11-10 18:38 . 2009-08-06 23:24 -------- d-----w- c:\users\Administrator\Application Data\Thinstall 2009-11-10 18:03 . 2009-08-01 21:35 -------- d-----w- c:\users\Administrator\Application Data\skypePM 2009-11-08 18:02 . 2009-08-16 02:03 2285056 ----a-w- c:\windows\system32\TUKernel.exe 2009-11-08 17:51 . 2009-07-31 18:02 -------- d-----w- c:\users\Administrator\Application Data\BSplayer PRO 2009-11-07 23:00 . 2009-08-01 15:34 -------- d-----w- c:\users\Administrator\Application Data\URSoft 2009-11-07 19:49 . 2009-08-01 19:16 -------- d-----w- c:\program files\Paint.NET 2009-11-05 00:05 . 2009-08-01 11:41 -------- d-----w- c:\program files\Java 2009-11-04 15:10 . 2009-08-30 21:27 -------- d-----w- c:\program files\Farm Frenzy Pizza Party 2009-11-03 16:51 . 2009-10-02 15:30 862040 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe 2009-11-03 16:51 . 2009-10-02 15:30 15880 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-11-03 16:51 . 2009-10-02 15:30 206944 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll 2009-11-03 16:51 . 2009-10-02 15:30 390288 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll 2009-11-03 16:51 . 2009-10-02 15:30 370744 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll 2009-11-03 16:51 . 2009-10-02 15:30 163728 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-11-03 16:51 . 2009-10-02 15:30 194104 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll 2009-11-03 16:51 . 2009-10-02 15:30 5908024 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll 2009-11-03 16:51 . 2009-10-02 15:30 87496 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-11-03 16:51 . 2009-10-02 15:30 327000 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-11-03 16:51 . 2009-10-02 15:30 933120 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll 2009-11-03 16:51 . 2009-10-02 15:30 640608 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe 2009-11-03 16:50 . 2009-10-02 15:30 815760 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2009-11-03 16:50 . 2009-10-02 15:29 822904 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2009-11-03 16:50 . 2009-10-02 15:29 1638104 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2009-11-03 16:50 . 2009-10-02 15:29 788368 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe 2009-11-03 16:50 . 2009-10-02 15:29 1179232 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe 2009-10-29 01:32 . 2009-08-01 11:28 -------- d-----w- c:\program files\Opera 2009-10-22 12:07 . 2009-08-17 12:10 -------- d-----w- c:\users\Administrator\Application Data\Babylon 2009-10-19 18:36 . 2006-11-20 12:27 2000000 ----atw- c:\windows\system32\HJSMEM.DAT 2009-10-19 18:28 . 2009-08-17 11:40 -------- d-----w- c:\users\All Users\Application Data\RFA_Backups 2009-10-18 18:54 . 2009-08-01 11:43 -------- d-----w- c:\program files\Common Files\Adobe 2009-10-17 18:24 . 2009-07-31 18:02 -------- d-----w- c:\users\Administrator\Application Data\Comodo 2009-10-17 18:24 . 2009-07-31 18:01 -------- d-----w- c:\program files\COMODO 2009-10-17 15:43 . 2009-08-01 14:49 -------- d-----w- c:\users\Administrator\Application Data\LimeWire 2009-10-11 03:17 . 2009-07-31 17:37 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-05 00:18 . 2009-10-05 00:18 -------- d-----w- c:\program files\inSoft 2009-10-03 04:44 . 2009-08-01 14:36 -------- d-----w- c:\program files\Unlocker 2009-10-02 16:04 . 2009-08-04 23:13 -------- d-----w- c:\program files\RegistryFix7 2009-10-02 15:30 . 2009-08-04 14:41 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-10-02 15:30 . 2009-10-02 15:30 17632 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\WSCUpdate.dll 2009-10-02 15:30 . 2009-10-02 15:30 68640 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys 2009-10-02 15:30 . 2009-10-02 15:30 525792 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\DIFxAPI.dll 2009-10-02 15:30 . 2009-10-02 15:30 303976 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe 2009-10-02 15:29 . 2009-10-02 15:29 640760 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe 2009-10-01 16:56 . 2009-10-01 16:56 -------- d-----w- c:\program files\Microsoft 2009-09-28 14:43 . 2009-09-03 18:24 177024 ----a-w- c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\zdwvxrnz.default\FlashGot.exe 2009-09-27 11:48 . 2009-09-06 12:57 -------- d-----w- c:\users\Administrator\Application Data\mp3rocket 2009-09-23 12:55 . 2009-08-01 15:05 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-09-19 09:44 . 2009-09-19 09:44 -------- d-----w- c:\users\Administrator\Application Data\Search Settings 2009-09-19 09:44 . 2009-09-19 09:44 -------- d-----w- c:\users\Administrator\Application Data\Dealio 2009-09-18 23:36 . 2009-09-18 23:26 -------- d-----w- c:\users\Administrator\Application Data\WeatherWatcherLive 2009-09-18 22:30 . 2009-09-18 22:30 -------- d-----w- c:\program files\Eggiz 2009-09-18 22:29 . 2009-08-01 14:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-18 22:27 . 2009-08-01 18:15 -------- d-----w- c:\program files\MyFreeWeather 2009-09-18 22:16 . 2009-08-04 20:47 4045528 ----a-w- c:\users\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-09-18 11:15 . 2009-08-04 23:53 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-09-18 01:02 . 2009-09-16 22:29 -------- d-----w- c:\program files\Cosmopolitan 2009-09-18 01:02 . 2009-08-29 11:10 -------- d-----w- c:\program files\Amazing Adventures The Lost Tomb 2009-09-15 10:57 . 2009-09-09 16:47 -------- d-----w- c:\program files\UlisesSoft 2009-09-15 00:05 . 2009-09-15 00:02 -------- d-----w- c:\program files\Digital Photo Software 2009-09-15 00:03 . 2009-09-15 00:03 8854 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut3_43405B1A6E07446F91523AC32617A818.exe 2009-09-15 00:03 . 2009-09-15 00:03 61440 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut2_25626A0D9AF7477DBD62B0C62B366983_1.exe 2009-09-15 00:03 . 2009-09-15 00:03 61440 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut1_25626A0D9AF7477DBD62B0C62B366983_1.exe 2009-09-15 00:03 . 2009-09-15 00:03 21630 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\ARPPRODUCTICON.exe 2009-09-11 14:13 . 2009-03-08 09:01 136704 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-11 07:08 . 2009-08-01 03:21 73264 ----a-w- c:\users\Default User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-10 12:54 . 2009-08-01 14:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 12:53 . 2009-08-01 14:06 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-06 10:53 . 2009-09-06 10:53 7680 ----a-w- c:\users\Administrator\Application Data\Thinstall\AMS Photo Effects 1.87\4000008000002i\Splash Screen.exe 2009-09-04 21:03 . 2008-04-14 03:42 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-08-29 08:08 . 2009-03-08 09:12 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:00 . 2009-03-08 09:12 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-23 14:53 . 2009-08-23 14:53 148736 ----a-w- c:\users\All Users\Application Data\hpe1E9A.dll 2009-08-23 14:53 . 2009-08-23 14:53 148736 ----a-w- c:\users\All Users\Application Data\hpe1E9A.dll 2009-08-21 22:16 . 2009-08-21 22:15 88 --sh--r- c:\users\All Users\Application Data\24993C8340.sys 2009-08-21 22:16 . 2009-08-21 22:15 88 --sh--r- c:\users\All Users\Application Data\24993C8340.sys 2009-08-21 22:16 . 2009-08-21 22:14 2516 --sha-w- c:\users\All Users\Application Data\KGyGaAvL.sys 2009-08-21 22:16 . 2009-08-21 22:14 2516 --sha-w- c:\users\All Users\Application Data\KGyGaAvL.sys 2009-08-20 19:15 . 2009-08-20 19:15 90112 ----a-w- c:\windows\Cuninst.exe 2009-08-15 20:36 . 2009-08-15 20:36 604416 ----a-w- c:\windows\system32\TUProgSt.exe 2009-08-15 20:36 . 2009-08-15 20:36 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe . ------- Sigcheck ------- [-] 2009-03-08 . FF267FF1D773BEA5522295E3A79701E9 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys [-] 2009-03-08 . 3D1ABDC3009D6B7CA7F9E66769C126CA . 568832 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe [-] 2009-03-08 . EA032FC150B9C6276C98EB3DED3B75C6 . 652800 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2009-03-08 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll [-] 2009-03-08 . E1F5F729264C8AF1D6A95ECD1C8086DD . 1723904 . . [6.00.2900.5634] . . c:\windows\explorer.exe [-] 2009-03-08 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RocketDock"="d:\ppapps\RocketDock\RocketDock.exe" [2007-09-02 495616] "Google Update"="c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-01 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640] "SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2009-08-01 2171904] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-05-26 4355512] "AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-05-26 960568] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-05-26 377248] "BigDog305"="c:\windows\VM305_STI.EXE" [2007-04-09 57344] "Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2009-08-17 3959696] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-07-24 1259336] "OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2009-07-24 436552] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-04-10 16861184] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-03-08 37376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "NewUser"="c:\windows\LastXP\NewUser.cmd" [2009-02-18 2375] "_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoSMConfigurePrograms"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSMConfigurePrograms"= 1 (0x1) [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="c:\users\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1.8.2009 16:05 64288] R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [1.8.2009 16:14 902592] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360] R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [17.10.2009 20:31 714752] R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [1.8.2009 15:11 142592] R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [17.10.2009 20:29 1312584] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840] R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [17.10.2009 20:29 31128] R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [17.10.2009 20:30 256792] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [23.8.2009 15:58 27632] R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\drivers\usbVM305.sys [24.8.2009 16:53 391688] S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [23.8.2009 15:52 90112] S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [15.8.2009 21:36 604416] S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [17.10.2009 20:31 33920] S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24.9.2009 12:17 1179232] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [23.8.2009 15:56 89256] --- Other Services/Drivers In Memory --- *NewlyCreated* - MBR *Deregistered* - mbr HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2009-11-11 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37] 2009-11-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:50] 2009-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-602162358-682003330-500Core.job - c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-01 11:12] 2009-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-602162358-682003330-500UA.job - c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-01 11:12] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.tattoodle.com?tid=0 uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm uInternet Settings,ProxyOverride = local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Crawler Search - tbr:iemenu IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: Translate this web page with Babylon IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm IE: Translate with Babylon Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll FF - ProfilePath - c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\zdwvxrnz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.tattoodle.com?tid={3392775D-2211-BE29-CDAA-662D033FFC9D} FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={3392775D-2211-BE29-CDAA-662D033FFC9D}&q= FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll FF - plugin: c:\users\Administrator\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . - - - - ORPHANS REMOVED - - - - BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-11 17:58 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@?????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-583907252-602162358-682003330-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ea,a0,9b,f9,2d,65,b0,4a,8f,64,f9,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ea,a0,9b,f9,2d,65,b0,4a,8f,64,f9,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1656) c:\windows\system32\SETUPAPI.dll c:\windows\system32\COMRes.dll c:\windows\system32\cscui.dll - - - - - - - > 'lsass.exe'(1736) c:\windows\system32\wdigest.dll c:\windows\system32\setupapi.dll - - - - - - - > 'explorer.exe'(2564) c:\windows\system32\SHDOCVW.dll c:\windows\system32\WININET.dll c:\windows\system32\msctfime.ime c:\windows\system32\COMRes.dll c:\windows\System32\cscui.dll c:\windows\system32\wpdshext.dll c:\windows\system32\portabledeviceapi.dll c:\windows\system32\SETUPAPI.dll c:\windows\system32\audiodev.dll c:\windows\system32\WMVCore.DLL c:\windows\system32\WMASF.DLL c:\program files\Babylon\Babylon-Pro\Captlib.dll c:\windows\system32\MSVCP60.dll c:\windows\System32\wiadefui.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\NETSHELL.dll c:\windows\system32\credui.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\program files\Spyware Terminator\sp_rsser.exe c:\windows\system32\RUNDLL32.EXE . ************************************************************************** . Completion time: 2009-11-11 18:05 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-11 17:05 Pre-Run: 7.418.703.872 bytes free Post-Run: 7.526.789.120 bytes free - - End Of File - - D808589F4A46F6AB8ED13B45495DCFCC Molim nekoga za pomoc! [Ovu poruku je menjao xman25 dana 11.11.2009. u 18:31 GMT+1] |