offline
- Pridružio: 25 Apr 2006
- Poruke: 46
|
E u tome je problem sto ga nema tu gde bi trebalo a niti ikone za unistall.Evo ovaj log _
ComboFix 09-04-25.A3 - xp pro 27.04.2009 16:51.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1531 [GMT 2:00]
Running from: c:\documents and settings\xp pro\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Outdated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\divx.dll
c:\windows\system32\drivers\RKHit.sys
----- BITS: Possible infected sites -----
hxxp://i5i.in
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RKHIT
((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-4-27 )))))))))))))))))))))))))))))))
.
2009-04-27 12:34 . 2009-04-27 12:34 -------- d-----w c:\documents and settings\xp pro\Application Data\Malwarebytes
2009-04-27 12:34 . 2009-04-27 12:34 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-27 12:31 . 2009-04-27 12:31 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-27 12:03 . 2009-04-27 12:03 33280 ---h--w c:\documents and settings\xp pro\pbcii.exe
2009-04-27 12:03 . 2009-04-27 12:03 33280 ----a-w c:\windows\system32\inmpsid.exe
2009-04-27 11:34 . 2009-04-27 11:34 -------- dc-h--w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-04-27 11:34 . 2009-04-27 11:34 -------- d-----w c:\program files\Lavasoft
2009-04-27 11:34 . 2009-04-27 11:34 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-27 08:09 . 2009-04-27 08:09 -------- d-----w c:\program files\GameHouse
2009-04-27 08:07 . 2009-04-27 08:07 17408 ----a-w C:\psapi.dll
2009-04-27 07:49 . 2009-04-27 07:49 29170931 ----a-w c:\windows\system32\xa224354343.exe
2009-04-27 07:49 . 2009-04-27 07:49 29170931 ----a-w c:\windows\system32\xa224352843.exe
2009-04-24 13:19 . 2009-04-24 13:19 -------- d-----w c:\documents and settings\All Users\Application Data\Ashampoo
2009-04-19 22:28 . 2009-04-24 16:42 -------- d-----w c:\program files\Registry Clean Expert
2009-04-19 20:41 . 2009-04-19 20:41 -------- d-----w c:\program files\ESET
2009-04-19 20:41 . 2009-04-19 20:41 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-19 11:58 . 2009-04-19 22:15 -------- d-----w c:\program files\Dc++ klient
2009-04-18 17:39 . 2009-04-18 17:39 -------- d-----w c:\program files\Gekko Mahjongg (Xmas edition)
2009-04-18 14:52 . 2009-04-18 14:52 77824 ----a-w c:\windows\system32\svcnost .exe
2009-04-17 11:56 . 2009-04-17 11:56 -------- d-----w c:\program files\Xvid
2009-04-17 11:56 . 2008-12-13 18:01 77824 ----a-w c:\windows\system32\xvid.ax
2009-04-17 11:56 . 2009-04-17 11:56 -------- d-----w c:\program files\FDRLab
2009-04-17 11:55 . 2009-04-17 11:55 -------- d-----w c:\program files\YouTube Downloader
2009-04-17 08:57 . 2009-04-17 09:44 307 ----a-w c:\windows\game.ini
2009-04-16 21:38 . 2007-02-28 11:33 389120 ----a-w c:\windows\system32\actskn43.ocx
2009-04-16 21:38 . 2009-04-16 21:38 -------- d-----w c:\program files\YouTubeRobot
2009-04-16 14:23 . 2009-04-16 14:23 -------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2009-04-16 04:20 . 2009-04-16 04:20 -------- d-----w c:\documents and settings\xp pro\Application Data\Zylom
2009-04-16 04:20 . 2005-08-03 10:48 389120 ----a-w c:\windows\Adventure Inlay.scr
2009-04-16 04:20 . 2009-04-16 04:20 -------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2009-04-09 21:26 . 2009-04-16 15:49 -------- d-----w c:\documents and settings\xp pro\Local Settings\Application Data\Conduit
2009-04-09 21:23 . 2009-04-16 15:49 -------- d-----w c:\program files\Conduit
2009-04-09 20:30 . 2009-04-09 20:30 716272 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-09 20:03 . 2009-04-09 20:03 -------- d-----w c:\program files\Common Files\EZB Systems
2009-04-02 12:59 . 2009-04-02 12:59 -------- d-----w c:\documents and settings\All Users\Application Data\Egoset
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 14:43 . 2009-01-09 11:26 -------- d-----w c:\program files\Mozilla Firefox 3.1 Beta 2
2009-04-27 14:38 . 2008-07-10 20:25 -------- d-----w c:\documents and settings\xp pro\Application Data\uTorrent
2009-04-24 22:20 . 2009-01-09 19:41 -------- d-----w c:\program files\Luxor 4 - Quest for the Afterlife
2009-04-24 17:30 . 2009-04-06 16:05 6017 ----a-w C:\aaw7boot.log
2009-04-23 13:52 . 2009-01-21 11:36 -------- d-----w c:\program files\The KMPlayer
2009-04-19 22:38 . 2008-07-07 13:35 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-19 19:23 . 2009-02-02 22:18 -------- d-----w c:\documents and settings\xp pro\Application Data\EnchantedCavern
2009-04-16 15:47 . 2008-08-01 20:19 -------- d-----w c:\program files\Empire Interactive
2009-04-11 23:00 . 2008-07-11 10:15 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-09 20:03 . 2008-10-05 11:13 -------- d-----w c:\program files\UltraISO
2009-04-06 13:32 . 2009-03-26 15:49 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-03-26 15:49 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-04 23:58 . 2009-02-02 22:15 -------- d-----w c:\program files\Alawar
2009-03-30 16:55 . 2008-07-18 11:04 -------- d-----w c:\program files\Puzzle Express
2009-03-26 17:08 . 2008-11-22 16:54 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-26 09:19 . 2008-11-05 09:17 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-25 21:30 . 2009-02-28 21:15 -------- d-----w c:\program files\BFDaily
2009-03-22 16:13 . 2008-07-10 20:25 -------- d-----w c:\program files\uTorrent
2009-03-21 01:24 . 2009-03-21 01:24 -------- d-----w c:\documents and settings\xp pro\Application Data\PipeMania
2009-03-21 01:24 . 2009-03-21 01:24 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-21 01:23 . 2008-07-11 13:30 -------- d-----w c:\program files\Mahjong Medley
2009-02-28 21:15 . 2009-02-09 22:44 -------- d-----w c:\documents and settings\All Users\Application Data\FireGlow
2009-02-28 13:51 . 2009-02-08 19:40 -------- d-----w c:\program files\Perfect Uninstaller
2009-02-27 23:52 . 2009-02-27 23:52 -------- d-----w c:\documents and settings\All Users\Application Data\AWEM
2009-02-27 23:27 . 2009-02-27 23:27 -------- d-----w c:\documents and settings\All Users\Application Data\AlawarWrapper
2009-01-15 20:43 . 2008-07-07 13:30 18632 ----a-w c:\documents and settings\xp pro\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-01-12 21:46 . 2008-10-14 21:01 81920 ----a-w c:\documents and settings\xp pro\Application Data\ezpinst.exe
2009-01-12 21:46 . 2008-10-14 21:01 47360 ----a-w c:\documents and settings\xp pro\Application Data\pcouffin.sys
2007-07-26 19:00 . 2008-07-07 13:51 23800756 ----a-w c:\program files\Burning Studio 7.1.0.exe
2002-07-01 14:13 . 2002-07-01 14:13 224 --sha-w c:\documents and settings\xp pro\Application Data\maildriver32.dat
.
------- Sigcheck -------
[-] 2004-08-04 00:56 17408 D41D8CD98F00B204E9800998ECF8427E c:\windows\system32\svchost.exe
[7] 2004-08-03 23:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\system32\dllcache\tcpip.sys
[-] 2004-08-03 23:14 359040 27A5959C94EE173A063CA06BD14F021A c:\windows\system32\drivers\tcpip.sys
[-] 2004-08-04 00:56 506368 D41D8CD98F00B204E9800998ECF8427E c:\windows\system32\winlogon.exe
[-] 2004-08-04 00:56 1034752 D41D8CD98F00B204E9800998ECF8427E c:\windows\explorer.exe
[-] 2004-08-04 00:56 110592 D41D8CD98F00B204E9800998ECF8427E c:\windows\system32\services.exe
[-] 2004-08-04 00:56 14848 D41D8CD98F00B204E9800998ECF8427E c:\windows\system32\lsass.exe
[-] 2004-08-04 00:56 58880 D41D8CD98F00B204E9800998ECF8427E c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"RegClean Expert Scheduler"="c:\program files\Registry Clean Expert\RCHelper.exe" [2009-04-19 602872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-28 13516800]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-27 23052]
"inmpsid"="c:\windows\system32\inmpsid.exe" [2009-04-27 33280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Scheduler for OEM.lnk - c:\program files\honestech\honestech TVR\scheduleTV.exe [2008-7-7 307200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"lpegfdQJUUah"= {24EFF327-8E45-598D-C495-C3FE5C0DFC65} - c:\windows\system32\iqvoqv.dll [2004-08-04 32768]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Documents and Settings\\xp pro\\pbcii.exe"=
"c:\\WINDOWS\\system32\\inmpsid.exe"=
R0 Lbd;Lbd; [x]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\Windows Live\Messenger\usnsvc.exe [2007-11-07 98840]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [2008-02-01 15:24 41456]
S2 713xTVCard;SAA7130 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2007-06-29 279552]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-27 953168]
S2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-09-30 51816]
S2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2007-06-29 25984]
.
Contents of the 'Scheduled Tasks' folder
2009-04-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 11:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.download3000.com/index.php?start=home
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {8AD8E4E2-6BD0-4E03-BE2A-4C46E9C6CA27} = 89.216.45.193
FF - ProfilePath - c:\documents and settings\xp pro\Application Data\Mozilla\Firefox\Profiles\ftjliinr.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 2\plugins\npzylomgamesplayer.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-04-27 16:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1645522239-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{586A8F2C-7720-628A-1D0A-FFF4789DE6D3}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iabgbmbjhdkkafdalk"=hex:6a,61,69,61,65,6c,62,65,6d,6b,66,6d,6c,6f,61,6c,70,6d,
6e,6c,00,00
"halkdppjcapfhpfh"=hex:6a,61,69,61,65,6c,62,65,6d,6b,66,6d,6c,6f,61,6c,70,6d,
6e,6c,00,00
"eadhfclbnd"=hex:61,61,00,7c
"eajfbpbcmp"=hex:61,61,00,7c
[HKEY_USERS\S-1-5-21-1645522239-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A69BA63-A6A3-1087-816D-8AF284205586}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"nadfdmhlofdifbmcnjjpcgfhnpge"=hex:6a,61,67,61,66,6d,6b,6b,61,6a,64,69,70,6c,
6c,6f,6e,63,69,65,00,00
"majffmmmejphpbnmikpamopigk"=hex:6a,61,67,61,6a,6d,6f,6d,65,62,69,61,65,69,61,
61,64,6b,61,69,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2500)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\ctfmon.exe3258177612c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclIrSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lavasoft\Ad-Aware\aawtray .exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-04-27 16:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-27 14:56
Pre-Run: 61.118.791.680 bytes free
Post-Run: 61.409.030.144 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
243
|