offline
- tuzor
- Legendarni građanin
- Pridružio: 03 Sep 2007
- Poruke: 4115
- Gde živiš: U Kraljevstvu duha
|
Izvoli! Ako je to ovo (ComboFix - Notepad):
ComboFix 09-01-16.03 - Tuzor 2009-01-17 14:29:58.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.138 [GMT 1:00]
Running from: c:\documents and settings\Tuzor\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-12-17 to 2009-01-17 )))))))))))))))))))))))))))))))
.
2009-01-15 12:57 . 2009-01-15 18:36 <DIR> d-------- c:\documents and settings\Tuzor\Application Data\Wildfire
2009-01-11 16:14 . 2009-01-11 16:13 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-23 17:50 . 2009-01-16 18:50 3,165,824 --a------ c:\program files\ccsetup215.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-11 15:13 --------- d-----w c:\program files\Java
2008-12-14 13:07 1,323,755 ----a-w c:\program files\WRC3Setup.exe
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-07 16:27 --------- d-----w c:\program files\Wise Disk Cleaner
2008-12-07 16:22 1,156,877 ----a-w c:\program files\WDC3Setup.exe
2008-07-29 21:00 774,144 ----a-w c:\program files\RngInterstitial.dll
2007-11-06 20:52 344,998,294 ----a-w c:\program files\Photoshop_CS2_tryout.zip
2007-11-03 13:42 1,399,575 ----a-w c:\program files\avg_asw_uma_en_75_8.pdf
.
------- Sigcheck -------
2007-06-13 11:23 1039872 d97fcfdaf10bfe662e627b4f2012149f c:\windows\explorer.exe
2007-06-13 12:26 1039872 dc0d433b5812bea909fcffb58dc1ba45 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 11:23 1039872 92473aa578fdb29857f6e1b5bdc63899 c:\windows\system32\dllcache\explorer.exe
2004-08-03 23:56 31232 cc641c1b59825b81dcbe86dce1161978 c:\windows\system32\userinit.exe
2004-08-03 23:56 31232 74a61160976f774f1d0e8cd90cd1084b c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2009-01-17_14.12.11,82 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-17 13:25:35 16,384 ----atw c:\windows\temp\Perflib_Perfdata_574.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1700864]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-12 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 163840]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 163840]
"CnxDslTaskBar"="c:\program files\ZyXEL\ADSL USB Modem\CnxDslTb.exe" [2003-07-31 458752]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-11-02 949376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-18 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-11 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
c:\documents and settings\Tuzor\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 120320]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SATARaid.lnk - c:\program files\Silicon Image\SiISATARaid\SATARaid.exe [2007-11-02 598069]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.vp31"= vp31vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnf.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [2007-11-02 85265]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-11-02 15424]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [2007-11-02 60288]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\drivers\CnxEtU.sys [2007-11-02 642944]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [2007-11-02 108675]
R3 nvsmbus;Service for NVIDIA nForce PCI System Management;c:\windows\system32\drivers\nvsmbus.sys [2007-11-02 10112]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm033YYRS
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
c:\windows\Downloaded Program Files\ghgamesplayer.dll - O16 -: {74E4A24D-5224-4F05-8A41-99445E0FC22B}
hxxp://www.gamehouse.com/realarcade-webgames/gamehouse/gamehouseplayer.cab
c:\windows\Downloaded Program Files\GHGamesPlayer.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-17 14:32:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(564)
c:\windows\system32\imon.dll
.
Completion time: 2009-01-17 14:35:32
ComboFix-quarantined-files.txt 2009-01-17 13:35:29
ComboFix2.txt 2009-01-17 13:13:15
Pre-Run: 1,099,546,624 bytes free
Post-Run: 1,082,654,720 bytes free
113 --- E O F --- 2009-01-14 17:06:21
Dopuna: 17 Jan 2009 15:49
2008-09-17 21:45:10 A------- 140 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST.vir
2008-09-17 21:45:10 A------- 305 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT.vir
2008-09-17 21:45:10 A------- 3,343 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG.vir
2008-09-17 21:45:10 A------- 5,446 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV.vir
2008-09-17 21:45:10 A------- 20,164 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG.vir
2008-09-17 21:45:10 A------- 20,480 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL.vir
2008-09-17 21:45:10 A------- 24,576 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir
2008-09-17 21:45:10 A------- 77,894 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir
2008-09-17 21:45:10 A------- 86,096 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir
2008-09-17 21:45:10 A------- 127,057 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir
2008-09-17 21:45:10 A------- 131,072 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir
2008-09-17 21:45:10 A------- 147,528 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir
2008-09-17 21:45:10 A------- 278,599 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir
2008-09-17 21:45:11 A------- 140 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST.vir
2008-09-17 21:45:11 A------- 32,768 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir
2008-09-17 21:45:29 A------- 89,655 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S.vir
2008-09-17 21:45:30 A------- 40,516 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON.F3S.vir
2008-09-17 21:45:30 A------- 71,675 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\DOG.F3S.vir
2008-09-17 21:45:30 A------- 106,998 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\FISH.F3S.vir
2008-09-17 21:45:30 A------- 301,118 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S.vir
2008-09-17 21:45:31 A------- 43,287 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S.vir
2008-09-17 21:45:31 A------- 122,747 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\MAID.F3S.vir
2008-09-17 21:45:31 A------- 129,559 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S.vir
2008-09-17 21:45:31 A------- 149,817 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S.vir
2008-09-17 21:45:31 A------- 155,471 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S.vir
2008-09-17 21:45:31 A------- 272,367 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S.vir
2008-09-17 21:45:32 A------- 7,406 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons\CM.ICO.vir
2008-09-17 21:45:32 A------- 7,406 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons\MFC.ICO.vir
2008-09-17 21:45:32 A------- 7,406 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons\SMILEY.ICO.vir
2008-09-17 21:45:32 A------- 7,406 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons\WB.ICO.vir
2008-09-17 21:45:32 A------- 10,134 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons\PSS.ICO.vir
2008-09-17 21:45:32 A------- 12,782 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO.vir
2008-09-17 21:45:32 A------- 56,438 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S.vir
2008-09-17 21:45:32 A------- 56,688 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Game\REVERSI.F3S.vir
2008-09-17 21:45:32 A------- 66,726 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Game\CHESS.F3S.vir
2008-09-17 21:45:32 A------- 113,081 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S.vir
2008-09-17 21:45:32 A------- 243,509 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S.vir
2008-09-17 21:45:33 A------- 24 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Settings\s_pid.dat.vir
2008-09-17 21:49:30 A------- 466 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\files.ini.vir
2008-09-17 21:49:39 A------- 68 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Settings\settings.dat.vir
2008-09-17 21:49:39 A------- 525 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Settings\setting2.htm.vir
2008-09-17 21:49:48 A------- 1,024 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\History\search3.vir
2008-09-17 21:49:48 A------- 81,301 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm.vir
2008-09-17 21:49:51 A------- 2,288 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A645B.bin.vir
2008-09-17 21:49:51 A------- 130,417 C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html.vir
2008-09-17 21:49:51 A------- 615,875 C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html.vir
2008-09-17 21:49:52 A------- 2,288 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A69DA.bin.vir
2008-09-17 21:49:54 A------- 1,724 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A6F29.bin.vir
2008-09-17 21:49:55 A------- 1,668 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A75A1.bin.vir
2008-09-17 21:49:56 A------- 1,284 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A7A83.bin.vir
2008-09-17 21:49:57 A------- 1,284 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A7DFE.bin.vir
2008-09-17 21:49:58 A------- 1,940 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\011A81E6.bin.vir
2008-09-18 18:48:47 A------- 1,922 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif.vir
2008-09-18 18:48:47 A------- 2,044 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\center.htm.vir
2008-09-18 18:48:47 A------- 2,353 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif.vir
2008-09-18 18:48:47 A------- 3,630 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm.vir
2008-09-18 18:48:47 A------- 7,794 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\index.htm.vir
2008-09-18 18:48:48 A------- 64 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif.vir
2008-09-18 18:48:48 A------- 145 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif.vir
2008-09-18 18:48:48 A------- 724 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif.vir
2008-09-18 18:48:48 A------- 1,517 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif.vir
2008-09-18 18:48:48 A------- 2,570 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm.vir
2008-09-18 18:48:48 A------- 3,036 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif.vir
2008-09-18 18:48:48 A------- 3,753 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif.vir
2008-09-18 18:48:48 A------- 4,345 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm.vir
2008-09-18 18:48:48 A------- 6,205 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm.vir
2008-09-18 21:33:09 A------- 324,902 C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html.vir
2008-09-28 23:51:03 A------- 107 C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\03975444.vir
2009-01-17 14:05:37 A------- 170 C:\Qoobox\Quarantine\catchme.log
2009-01-17 14:09:09 A------- 6,805 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-01-17 14:12:16 A------- 166 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-MyWebSearch Plugin.reg.dat
Evo i narednog:
ComboFix 09-01-16.03 - Zoran Tucakovic 2009-01-17 14:06:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.43 [GMT 1:00]
Running from: c:\documents and settings\Tuzor\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Tuzor\Application Data\FunWebProducts
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\011A645B.bin
c:\program files\MyWebSearch\bar\Cache\011A69DA.bin
c:\program files\MyWebSearch\bar\Cache\011A6F29.bin
c:\program files\MyWebSearch\bar\Cache\011A75A1.bin
c:\program files\MyWebSearch\bar\Cache\011A7A83.bin
c:\program files\MyWebSearch\bar\Cache\011A7DFE.bin
c:\program files\MyWebSearch\bar\Cache\011A81E6.bin
c:\program files\MyWebSearch\bar\Cache\03975444
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.htm
c:\program files\MyWebSearch\bar\Message\COMMON\center.htm
c:\program files\MyWebSearch\bar\Message\COMMON\index.htm
c:\program files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
c:\program files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\protect.htm
c:\program files\MyWebSearch\bar\Message\COMMON\shocked.gif
c:\program files\MyWebSearch\bar\Message\COMMON\stop.gif
c:\program files\MyWebSearch\bar\Message\COMMON\systray.htm
c:\program files\MyWebSearch\bar\Message\COMMON\systrayp.htm
c:\program files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
c:\program files\MyWebSearch\bar\Message\COMMON\warn.gif
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
.
((((((((((((((((((((((((( Files Created from 2008-12-17 to 2009-01-17 )))))))))))))))))))))))))))))))
.
2009-01-15 12:57 . 2009-01-15 18:36 <DIR> d-------- c:\documents and settings\Tuzor\Application Data\Wildfire
2009-01-11 16:14 . 2009-01-11 16:13 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-23 17:50 . 2009-01-16 18:50 3,165,824 --a------ c:\program files\ccsetup215.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-11 15:13 --------- d-----w c:\program files\Java
2008-12-14 13:07 1,323,755 ----a-w c:\program files\WRC3Setup.exe
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-07 16:27 --------- d-----w c:\program files\Wise Disk Cleaner
2008-12-07 16:22 1,156,877 ----a-w c:\program files\WDC3Setup.exe
2008-07-29 21:00 774,144 ----a-w c:\program files\RngInterstitial.dll
2007-11-06 20:52 344,998,294 ----a-w c:\program files\Photoshop_CS2_tryout.zip
2007-11-03 13:42 1,399,575 ----a-w c:\program files\avg_asw_uma_en_75_8.pdf
.
------- Sigcheck -------
2004-08-03 23:56 31232 cc641c1b59825b81dcbe86dce1161978 c:\windows\system32\userinit.exe
2004-08-03 23:56 31232 74a61160976f774f1d0e8cd90cd1084b c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1700864]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-12 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 163840]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 163840]
"CnxDslTaskBar"="c:\program files\ZyXEL\ADSL USB Modem\CnxDslTb.exe" [2003-07-31 458752]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-11-02 949376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-18 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-11 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
c:\documents and settings\Tuzor\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 120320]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SATARaid.lnk - c:\program files\Silicon Image\SiISATARaid\SATARaid.exe [2007-11-02 598069]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.vp31"= vp31vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnf.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [2007-11-02 85265]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-11-02 15424]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [2007-11-02 60288]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\drivers\CnxEtU.sys [2007-11-02 642944]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [2007-11-02 108675]
R3 nvsmbus;Service for NVIDIA nForce PCI System Management;c:\windows\system32\drivers\nvsmbus.sys [2007-11-02 10112]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm033YYRS
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
TCP: {32BCCC01-BE56-4036-A14B-6BFE750C77A6} = 212.200.164.5 212.200.164.10
c:\windows\Downloaded Program Files\ghgamesplayer.dll - O16 -: {74E4A24D-5224-4F05-8A41-99445E0FC22B}
hxxp://www.gamehouse.com/realarcade-webgames/gamehouse/gamehouseplayer.cab
c:\windows\Downloaded Program Files\GHGamesPlayer.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-17 14:09:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(504)
c:\windows\system32\imon.dll
- - - - - - - > 'lsass.exe'(560)
c:\windows\system32\imon.dll
.
Completion time: 2009-01-17 14:13:14
ComboFix-quarantined-files.txt 2009-01-17 13:13:12
Pre-Run: 1.170.321.408 bytes free
Post-Run: 1,156,714,496 bytes free
184 --- E O F --- 2009-01-14 17:06:21
|