

Probao sam sa brisanjem Mozille i ponovnom instalacijom i nista i sa system restore na prethodni dan ali takodje ostaje nepromenjeno. Znaci sada ne mogu vise uopste da pokrenem Mozillu, uvek mi izbacuje one dve poruke. Uradio sam log preko ComboFix-a:
Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.2047.1411 [GMT 1:00]
Running from: c:\users\Administrator\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\config.ini
c:\program files\Dealio Toolbar\DealioToolbarIE.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\separator.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\SeARchsettings.dll
c:\program files\Dealio Toolbar\SearchSettings.exe
c:\program files\Dealio Toolbar\SearchSettingsRes409.dll
c:\program files\Dealio Toolbar\sscfg.ini
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\Fast Browser Search
c:\program files\Fast Browser Search\1.bat
c:\program files\Fast Browser Search\about.html
c:\program files\Fast Browser Search\affid.dat
c:\program files\Fast Browser Search\basis.xml
c:\program files\Fast Browser Search\basis_br.xml
c:\program files\Fast Browser Search\basis_de.xml
c:\program files\Fast Browser Search\basis_en.xml
c:\program files\Fast Browser Search\basis_es.xml
c:\program files\Fast Browser Search\basis_fr.xml
c:\program files\Fast Browser Search\basis_it.xml
c:\program files\Fast Browser Search\basis_nr.xml
c:\program files\Fast Browser Search\basis_pt.xml
c:\program files\Fast Browser Search\basis_ru.xml
c:\program files\Fast Browser Search\basis_tr.xml
c:\program files\Fast Browser Search\BHO.dll
c:\program files\Fast Browser Search\ClearRecycleBin.exe
c:\program files\Fast Browser Search\error.html
c:\program files\Fast Browser Search\FBSPlugin.dll
c:\program files\Fast Browser Search\fbsProtection.xml
c:\program files\Fast Browser Search\FbsSearchProvider.xml
c:\program files\Fast Browser Search\FbsSearchProviderIE8.exe
c:\program files\Fast Browser Search\FBStoolbar.dll
c:\program files\Fast Browser Search\fbstoolbar.jar
c:\program files\Fast Browser Search\fbstoolbar.manifest
c:\program files\Fast Browser Search\icons.bmp
c:\program files\Fast Browser Search\IE\basis.xml
c:\program files\Fast Browser Search\IE\fbsSearchProvider.xml
c:\program files\Fast Browser Search\IE\FBStoolbar.exe
c:\program files\Fast Browser Search\IE\search_de.bmp
c:\program files\Fast Browser Search\IE\search_es.bmp
c:\program files\Fast Browser Search\IE\search_fr.bmp
c:\program files\Fast Browser Search\IE\search_it.bmp
c:\program files\Fast Browser Search\IE\search_pt.bmp
c:\program files\Fast Browser Search\IE\search_ru.bmp
c:\program files\Fast Browser Search\IE\SearchGuardPlus.exe
c:\program files\Fast Browser Search\IE\SearchGuardPlus.ico
c:\program files\Fast Browser Search\IE\SGPU.ico
c:\program files\Fast Browser Search\info.txt
c:\program files\Fast Browser Search\local.xml
c:\program files\Fast Browser Search\logobg.bmp
c:\program files\Fast Browser Search\MTWBtoolbar.html
c:\program files\Fast Browser Search\search.bmp
c:\program files\Fast Browser Search\search_br.bmp
c:\program files\Fast Browser Search\SGPUpdaterS.exe
c:\program files\Fast Browser Search\tbhelper.dll
c:\program files\Fast Browser Search\tbs_include_script_003175.js
c:\program files\Fast Browser Search\tbs_include_script_005064.js
c:\program files\Fast Browser Search\tbs_include_script_012817.js
c:\program files\Fast Browser Search\Toolbar Help.htm
c:\program files\Fast Browser Search\uninstall.exe
c:\program files\Fast Browser Search\uninstalSGP.exe
c:\program files\Fast Browser Search\uninstalSGPU.exe
c:\program files\Fast Browser Search\update.exe
c:\program files\Fast Browser Search\version.txt
c:\program files\SGPSA
c:\users\Administrator\My Documents\cc_20091103_005612.reg
c:\windows\system32\d3d10core.dll
c:\windows\system32\kernel32new.dll
c:\windows\system32\msvcrtnew.dll
c:\windows\version.txt
c:\windows\system32\LogonUI.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 )))))))))))))))))))))))))))))))
.
2009-11-11 15:37 . 2009-11-11 15:37 -------- d-----w- c:\windows\system32\wbem\Repository
2009-11-10 19:45 . 2009-11-10 19:45 -------- d-----w- c:\program files\eGames
2009-11-08 18:04 . 2009-11-08 18:04 10880192 ----a-w- c:\users\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe
2009-11-07 23:42 . 2009-11-07 23:42 -------- d-----w- c:\program files\BS player
2009-11-07 23:00 . 2009-11-07 23:02 -------- d-----w- c:\program files\Your Uninstaller
2009-11-07 22:54 . 2009-11-07 22:58 -------- d-----w- c:\program files\Your Uninstaller 2008
2009-11-07 20:31 . 2009-11-07 20:33 6147544 ----a-w- c:\users\Administrator\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-11-07 20:31 . 2007-03-22 10:46 126976 ----a-w- c:\users\Administrator\Application Data\GRETECH\GomPlayer\GrLauncher.exe
2009-11-05 00:04 . 2009-11-05 00:04 152576 ----a-w- c:\users\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-04 16:00 . 2009-11-04 18:26 -------- d-----w- c:\users\All Users\Application Data\FarmFrenzy3
2009-11-04 15:59 . 2009-11-04 15:59 -------- d-----w- c:\program files\LeeGTs Games
2009-11-03 16:51 . 2009-11-03 16:51 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-03 16:51 . 2009-11-03 16:51 93360 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-03 16:51 . 2009-11-03 16:51 554280 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-03 16:51 . 2009-11-03 16:51 212480 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-03 16:51 . 2009-11-03 16:51 283944 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-03 16:51 . 2009-11-03 16:51 1223976 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-03 16:51 . 2009-11-03 16:51 242984 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-10-29 02:03 . 2009-10-29 02:03 -------- d-----w- c:\users\Default User\Local Settings\Application Data\Microsoft Help
2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\users\All Users\Application Data\2BrightSparks
2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\program files\2BrightSparks
2009-10-19 18:33 . 2009-10-19 18:33 -------- d-----w- c:\users\All Users\Application Data\Freedom Scientific
2009-10-19 18:33 . 2009-10-19 18:33 -------- d-----w- c:\program files\ssce
2009-10-19 18:32 . 2009-10-19 18:32 -------- d-----w- c:\windows\system32\HJSMEM
2009-10-19 18:31 . 2009-10-19 18:33 -------- d-----w- c:\program files\Freedom Scientific
2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\4000008500003i\PDFToText.exe
2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\400000600002i\AcroRd32Info.exe
2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\1000000b00002i\verclsid.exe
2009-10-18 18:25 . 2003-12-18 16:53 6656 ----a-w- c:\windows\system32\haspvdd.dll
2009-10-18 18:25 . 2003-12-18 16:53 383 ----a-w- c:\windows\system32\haspdos.sys
2009-10-18 18:25 . 2003-12-18 16:53 304640 ----a-w- c:\windows\system32\hlvdd.dll
2009-10-18 18:25 . 2004-01-31 18:14 420000 ----a-w- c:\windows\system32\drivers\hardlock.sys
2009-10-18 18:25 . 2003-12-18 16:53 47616 ----a-w- c:\windows\system32\drivers\haspnt.sys
2009-10-18 18:22 . 2009-10-18 18:22 -------- d-----w- C:\HaspEmulPE.XP
2009-10-18 18:10 . 2009-10-18 18:10 -------- d-----w- c:\users\Administrator\Application Data\Freedom Scientific
2009-10-18 18:07 . 2009-10-18 18:08 -------- d-----w- c:\program files\anReader
2009-10-18 16:54 . 2009-10-19 18:32 -------- d--h--w- c:\program files\Freedom Scientific Installation Information
2009-10-18 15:57 . 2009-10-18 15:57 -------- d-----w- c:\program files\Rainbow Technologies
2009-10-18 15:57 . 2008-10-07 13:33 6058112 ----a-w- c:\windows\system32\dcmc0d0.dll
2009-10-17 19:31 . 2009-07-23 09:56 714752 ----a-w- c:\windows\system32\drivers\SandBox.sys
2009-10-17 19:30 . 2009-07-13 11:19 256792 ----a-w- c:\windows\system32\drivers\afwcore.sys
2009-10-17 19:29 . 2009-10-17 19:31 -------- d-----w- c:\windows\system32\Filt
2009-10-17 19:29 . 2009-02-18 15:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2009-10-17 19:28 . 2009-10-17 19:28 -------- d-----w- c:\program files\Agnitum
2009-10-17 19:28 . 2009-10-17 19:28 -------- d-----w- c:\users\All Users\Application Data\Agnitum
2009-10-17 17:52 . 2009-10-17 17:52 -------- d-sh--w- c:\users\LocalService\IETldCache
2009-10-17 15:50 . 2009-11-03 16:51 537576 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-10-17 15:46 . 2009-10-17 15:46 -------- dc-h--w- c:\users\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-17 15:46 . 2009-10-03 08:15 2924848 -c--a-w- c:\users\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-10-14 09:40 . 2009-07-17 16:22 1435648 ------w- c:\windows\system32\dllcache\query.dll
2009-10-14 09:37 . 2009-08-26 08:00 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-10-14 09:35 . 2009-09-04 21:03 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2009-10-13 22:35 . 2009-10-13 22:35 -------- d-----w- c:\program files\Search Guard PlusU
2009-10-13 22:35 . 2009-10-13 22:35 -------- d-----w- c:\program files\Search Guard Plus
2009-10-12 20:47 . 2008-03-05 14:03 329224 ----a-w- c:\windows\system32\DXErr.exe
2009-10-12 20:47 . 2008-03-09 05:25 236 ----a-w- c:\program files\Common Files\dx.reg
2009-10-12 20:47 . 2008-03-05 14:03 209416 ----a-w- c:\windows\system32\dxcpl.exe
2009-10-12 20:47 . 2006-11-02 10:46 167936 ----a-w- c:\windows\system32\dxgi.dll
2009-10-12 20:47 . 2006-11-02 10:46 39936 ----a-w- c:\windows\system32\dwmapi.dll
2009-10-12 20:47 . 2006-11-29 12:06 440080 ----a-w- c:\windows\system32\d3dx10.dll
2009-10-12 20:47 . 2006-11-02 10:47 1162656 ----a-w- c:\windows\system32\ntdllnew.dll
2009-10-12 20:47 . 2008-04-12 16:13 1029126 ----a-w- c:\windows\system32\d3d10.dll
2009-10-12 20:47 . 2009-10-12 20:45 716153 ----a-w- c:\windows\system32\unins000.exe
2009-10-12 20:46 . 2009-10-12 20:47 2733 ----a-w- c:\windows\system32\unins000.dat
2009-10-12 17:17 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-10-12 17:17 . 2009-09-04 15:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-10-12 17:17 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-10-12 17:17 . 2009-09-04 15:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-10-12 17:16 . 2009-09-04 15:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-10-12 17:16 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-10-12 17:16 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-10-12 17:16 . 2009-03-09 13:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-10-12 17:16 . 2009-03-09 13:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-10-12 17:16 . 2009-03-09 13:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-10-12 17:16 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-10-12 17:16 . 2009-03-16 12:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-10-12 17:16 . 2009-03-16 12:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-10-12 17:14 . 2009-03-16 12:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 16:58 . 2009-08-17 12:10 -------- d-----w- c:\users\All Users\Application Data\Babylon
2009-11-11 16:32 . 2009-08-11 16:22 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-11-11 16:29 . 2009-08-01 14:11 -------- d-----w- c:\users\All Users\Application Data\Spyware Terminator
2009-11-11 16:29 . 2009-08-01 14:11 -------- d-----w- c:\program files\Spyware Terminator
2009-11-11 16:00 . 2009-08-01 14:11 -------- d-----w- c:\users\Administrator\Application Data\Spyware Terminator
2009-11-11 08:39 . 2009-08-01 15:34 -------- d---a-w- c:\users\All Users\Application Data\TEMP
2009-11-11 08:21 . 2009-08-01 13:34 -------- d-----w- c:\users\All Users\Application Data\Microsoft Help
2009-11-10 19:55 . 2009-08-01 21:33 -------- d-----w- c:\users\Administrator\Application Data\Skype
2009-11-10 18:38 . 2009-08-06 23:24 -------- d-----w- c:\users\Administrator\Application Data\Thinstall
2009-11-10 18:03 . 2009-08-01 21:35 -------- d-----w- c:\users\Administrator\Application Data\skypePM
2009-11-08 18:02 . 2009-08-16 02:03 2285056 ----a-w- c:\windows\system32\TUKernel.exe
2009-11-08 17:51 . 2009-07-31 18:02 -------- d-----w- c:\users\Administrator\Application Data\BSplayer PRO
2009-11-07 23:00 . 2009-08-01 15:34 -------- d-----w- c:\users\Administrator\Application Data\URSoft
2009-11-07 19:49 . 2009-08-01 19:16 -------- d-----w- c:\program files\Paint.NET
2009-11-05 00:05 . 2009-08-01 11:41 -------- d-----w- c:\program files\Java
2009-11-04 15:10 . 2009-08-30 21:27 -------- d-----w- c:\program files\Farm Frenzy Pizza Party
2009-11-03 16:51 . 2009-10-02 15:30 862040 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-11-03 16:51 . 2009-10-02 15:30 15880 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-11-03 16:51 . 2009-10-02 15:30 206944 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-11-03 16:51 . 2009-10-02 15:30 390288 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-11-03 16:51 . 2009-10-02 15:30 370744 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-11-03 16:51 . 2009-10-02 15:30 163728 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-03 16:51 . 2009-10-02 15:30 194104 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-11-03 16:51 . 2009-10-02 15:30 5908024 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-11-03 16:51 . 2009-10-02 15:30 87496 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-03 16:51 . 2009-10-02 15:30 327000 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-03 16:51 . 2009-10-02 15:30 933120 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-03 16:51 . 2009-10-02 15:30 640608 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-03 16:50 . 2009-10-02 15:30 815760 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-03 16:50 . 2009-10-02 15:29 822904 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-03 16:50 . 2009-10-02 15:29 1638104 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-03 16:50 . 2009-10-02 15:29 788368 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-03 16:50 . 2009-10-02 15:29 1179232 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-10-29 01:32 . 2009-08-01 11:28 -------- d-----w- c:\program files\Opera
2009-10-22 12:07 . 2009-08-17 12:10 -------- d-----w- c:\users\Administrator\Application Data\Babylon
2009-10-19 18:36 . 2006-11-20 12:27 2000000 ----atw- c:\windows\system32\HJSMEM.DAT
2009-10-19 18:28 . 2009-08-17 11:40 -------- d-----w- c:\users\All Users\Application Data\RFA_Backups
2009-10-18 18:54 . 2009-08-01 11:43 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-17 18:24 . 2009-07-31 18:02 -------- d-----w- c:\users\Administrator\Application Data\Comodo
2009-10-17 18:24 . 2009-07-31 18:01 -------- d-----w- c:\program files\COMODO
2009-10-17 15:43 . 2009-08-01 14:49 -------- d-----w- c:\users\Administrator\Application Data\LimeWire
2009-10-11 03:17 . 2009-07-31 17:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-05 00:18 . 2009-10-05 00:18 -------- d-----w- c:\program files\inSoft
2009-10-03 04:44 . 2009-08-01 14:36 -------- d-----w- c:\program files\Unlocker
2009-10-02 16:04 . 2009-08-04 23:13 -------- d-----w- c:\program files\RegistryFix7
2009-10-02 15:30 . 2009-08-04 14:41 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-02 15:30 . 2009-10-02 15:30 17632 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2009-10-02 15:30 . 2009-10-02 15:30 68640 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
2009-10-02 15:30 . 2009-10-02 15:30 525792 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\DIFxAPI.dll
2009-10-02 15:30 . 2009-10-02 15:30 303976 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2009-10-02 15:29 . 2009-10-02 15:29 640760 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-10-01 16:56 . 2009-10-01 16:56 -------- d-----w- c:\program files\Microsoft
2009-09-28 14:43 . 2009-09-03 18:24 177024 ----a-w- c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\zdwvxrnz.default\FlashGot.exe
2009-09-27 11:48 . 2009-09-06 12:57 -------- d-----w- c:\users\Administrator\Application Data\mp3rocket
2009-09-23 12:55 . 2009-08-01 15:05 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-19 09:44 . 2009-09-19 09:44 -------- d-----w- c:\users\Administrator\Application Data\Search Settings
2009-09-19 09:44 . 2009-09-19 09:44 -------- d-----w- c:\users\Administrator\Application Data\Dealio
2009-09-18 23:36 . 2009-09-18 23:26 -------- d-----w- c:\users\Administrator\Application Data\WeatherWatcherLive
2009-09-18 22:30 . 2009-09-18 22:30 -------- d-----w- c:\program files\Eggiz
2009-09-18 22:29 . 2009-08-01 14:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-18 22:27 . 2009-08-01 18:15 -------- d-----w- c:\program files\MyFreeWeather
2009-09-18 22:16 . 2009-08-04 20:47 4045528 ----a-w- c:\users\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-18 11:15 . 2009-08-04 23:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-18 01:02 . 2009-09-16 22:29 -------- d-----w- c:\program files\Cosmopolitan
2009-09-18 01:02 . 2009-08-29 11:10 -------- d-----w- c:\program files\Amazing Adventures The Lost Tomb
2009-09-15 10:57 . 2009-09-09 16:47 -------- d-----w- c:\program files\UlisesSoft
2009-09-15 00:05 . 2009-09-15 00:02 -------- d-----w- c:\program files\Digital Photo Software
2009-09-15 00:03 . 2009-09-15 00:03 8854 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut3_43405B1A6E07446F91523AC32617A818.exe
2009-09-15 00:03 . 2009-09-15 00:03 61440 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut2_25626A0D9AF7477DBD62B0C62B366983_1.exe
2009-09-15 00:03 . 2009-09-15 00:03 61440 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut1_25626A0D9AF7477DBD62B0C62B366983_1.exe
2009-09-15 00:03 . 2009-09-15 00:03 21630 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\ARPPRODUCTICON.exe
2009-09-11 14:13 . 2009-03-08 09:01 136704 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 07:08 . 2009-08-01 03:21 73264 ----a-w- c:\users\Default User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-10 12:54 . 2009-08-01 14:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-08-01 14:06 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-06 10:53 . 2009-09-06 10:53 7680 ----a-w- c:\users\Administrator\Application Data\Thinstall\AMS Photo Effects 1.87\4000008000002i\Splash Screen.exe
2009-09-04 21:03 . 2008-04-14 03:42 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2009-03-08 09:12 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2009-03-08 09:12 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-23 14:53 . 2009-08-23 14:53 148736 ----a-w- c:\users\All Users\Application Data\hpe1E9A.dll
2009-08-23 14:53 . 2009-08-23 14:53 148736 ----a-w- c:\users\All Users\Application Data\hpe1E9A.dll
2009-08-21 22:16 . 2009-08-21 22:15 88 --sh--r- c:\users\All Users\Application Data\24993C8340.sys
2009-08-21 22:16 . 2009-08-21 22:15 88 --sh--r- c:\users\All Users\Application Data\24993C8340.sys
2009-08-21 22:16 . 2009-08-21 22:14 2516 --sha-w- c:\users\All Users\Application Data\KGyGaAvL.sys
2009-08-21 22:16 . 2009-08-21 22:14 2516 --sha-w- c:\users\All Users\Application Data\KGyGaAvL.sys
2009-08-20 19:15 . 2009-08-20 19:15 90112 ----a-w- c:\windows\Cuninst.exe
2009-08-15 20:36 . 2009-08-15 20:36 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-15 20:36 . 2009-08-15 20:36 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
.
------- Sigcheck -------
[-] 2009-03-08 . FF267FF1D773BEA5522295E3A79701E9 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-03-08 . 3D1ABDC3009D6B7CA7F9E66769C126CA . 568832 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2009-03-08 . EA032FC150B9C6276C98EB3DED3B75C6 . 652800 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2009-03-08 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2009-03-08 . E1F5F729264C8AF1D6A95ECD1C8086DD . 1723904 . . [6.00.2900.5634] . . c:\windows\explorer.exe
[-] 2009-03-08 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="d:\ppapps\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Google Update"="c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-01 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2009-08-01 2171904]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-05-26 4355512]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-05-26 960568]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-05-26 377248]
"BigDog305"="c:\windows\VM305_STI.EXE" [2007-04-09 57344]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2009-08-17 3959696]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-07-24 1259336]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2009-07-24 436552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-04-10 16861184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-03-08 37376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"NewUser"="c:\windows\LastXP\NewUser.cmd" [2009-02-18 2375]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\users\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1.8.2009 16:05 64288]
R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [1.8.2009 16:14 902592]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [17.10.2009 20:31 714752]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [1.8.2009 15:11 142592]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [17.10.2009 20:29 1312584]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [17.10.2009 20:29 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [17.10.2009 20:30 256792]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [23.8.2009 15:58 27632]
R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\drivers\usbVM305.sys [24.8.2009 16:53 391688]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [23.8.2009 15:52 90112]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [15.8.2009 21:36 604416]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [17.10.2009 20:31 33920]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24.9.2009 12:17 1179232]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [23.8.2009 15:56 89256]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-11-11 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]
2009-11-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:50]
2009-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-602162358-682003330-500Core.job
- c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-01 11:12]
2009-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-602162358-682003330-500UA.job
- c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-01 11:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tattoodle.com?tid=0
uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Translate this web page with Babylon
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
IE: Translate with Babylon
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\zdwvxrnz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.tattoodle.com?tid={3392775D-2211-BE29-CDAA-662D033FFC9D}
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={3392775D-2211-BE29-CDAA-662D033FFC9D}&q=
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: c:\users\Administrator\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORPHANS REMOVED - - - -
BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-11 17:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@??????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-583907252-602162358-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ea,a0,9b,f9,2d,65,b0,4a,8f,64,f9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ea,a0,9b,f9,2d,65,b0,4a,8f,64,f9,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1656)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(1736)
c:\windows\system32\wdigest.dll
c:\windows\system32\setupapi.dll
- - - - - - - > 'explorer.exe'(2564)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\msctfime.ime
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\WMVCore.DLL
c:\windows\system32\WMASF.DLL
c:\program files\Babylon\Babylon-Pro\Captlib.dll
c:\windows\system32\MSVCP60.dll
c:\windows\System32\wiadefui.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
Completion time: 2009-11-11 18:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-11 17:05
Pre-Run: 7.418.703.872 bytes free
Post-Run: 7.526.789.120 bytes free
- - End Of File - - D808589F4A46F6AB8ED13B45495DCFCC
Molim nekoga za pomoc!
[Ovu poruku je menjao xman25 dana 11.11.2009. u 18:31 GMT+1]