- ComboFix 10-03-19.08 - mladen 03/20/2010 14:59:07.1.1 - x86
- Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.96 [GMT 1:00]
- Running from: c:\documents and settings\mladen\My Documents\Programi\ComboFix.exe
- AV: avast! antivirus 4.8.1368 [VPS 100320-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
- WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\windows\system32\d3d10core.dll
- c:\windows\system32\kernel32new.dll
- c:\windows\system32\msvcrtnew.dll
- .
- ((((((((((((((((((((((((( Files Created from 2010-02-20 to 2010-03-20 )))))))))))))))))))))))))))))))
- .
- 2010-03-14 19:24 . 2010-03-14 19:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
- 2010-03-14 19:23 . 2010-03-14 19:23 -------- d-----w- c:\documents and settings\mladen\Application Data\DAEMON Tools Pro
- 2010-03-14 19:23 . 2010-03-14 19:23 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
- 2010-03-14 19:23 . 2010-03-14 19:23 -------- d-----w- c:\documents and settings\mladen\Application Data\DAEMON Tools
- 2010-03-14 13:19 . 2010-03-14 13:22 -------- d-----w- C:\FM
- 2010-03-14 13:09 . 2010-03-14 13:09 7886 ----a-r- c:\documents and settings\mladen\Application Data\Microsoft\Installer\{C6EB9182-27BD-425B-927B-29DE2A8737B8}\fm2005demo_EC0AB585B2794A778BB564C403E43EE7.exe
- 2010-03-14 13:09 . 2010-03-14 13:09 7886 ----a-r- c:\documents and settings\mladen\Application Data\Microsoft\Installer\{C6EB9182-27BD-425B-927B-29DE2A8737B8}\ARPPRODUCTICON.exe
- 2010-03-14 13:08 . 2010-03-14 13:08 -------- d-----w- c:\program files\Sports Interactive
- 2010-03-13 10:26 . 2010-03-13 10:27 -------- d-----w- c:\program files\8BallClub
- 2010-03-09 19:50 . 2010-03-09 19:50 -------- d-----w- c:\documents and settings\mladen\Local Settings\Application Data\Identities
- 2010-03-08 15:14 . 2010-03-08 15:15 -------- d-----w- c:\documents and settings\mladen\Application Data\Media Player Classic
- 2010-03-08 15:14 . 2010-03-08 15:14 -------- d-----w- c:\program files\MPC HomeCinema
- 2010-03-08 15:09 . 2010-03-08 15:10 -------- d-----w- c:\documents and settings\mladen\Application Data\BSplayer
- 2010-03-08 15:09 . 2010-03-08 15:09 -------- d-----w- c:\documents and settings\mladen\Application Data\BSplayer Pro
- 2010-03-08 15:09 . 2010-03-08 15:09 -------- d-----w- c:\program files\Webteh
- 2010-03-08 15:04 . 2010-03-08 15:04 -------- d-----w- c:\documents and settings\mladen\Application Data\GRETECH
- 2010-03-08 15:03 . 2010-03-08 15:03 -------- d-----w- c:\program files\GRETECH
- 2010-03-07 11:17 . 2010-03-07 11:17 -------- d-----w- c:\documents and settings\mladen\Application Data\AdobeUM
- 2010-03-07 11:16 . 2010-03-07 11:17 -------- d-----w- c:\documents and settings\mladen\Local Settings\Application Data\Adobe
- 2010-03-07 11:15 . 2010-03-07 11:16 -------- d-----w- c:\program files\Common Files\Adobe
- 2010-03-07 11:13 . 2010-03-07 11:16 -------- d-----w- c:\documents and settings\mladen\Local Settings\Application Data\NOS
- 2010-03-06 16:40 . 2010-03-06 16:40 -------- d-----w- c:\program files\Games
- 2010-03-05 22:53 . 2009-12-01 16:39 787 ----a-w- C:\ma477.bin
- 2010-03-05 10:42 . 2004-08-03 22:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
- 2010-03-04 21:57 . 2010-03-04 21:57 -------- d-----w- c:\documents and settings\mladen\Application Data\TypingMaster7
- 2010-03-04 21:56 . 2010-03-04 21:56 -------- d-----r- c:\program files\TypingMaster
- 2010-03-04 21:20 . 2010-03-08 18:34 -------- d-----w- c:\program files\PokerStars
- 2010-03-04 20:55 . 2010-03-04 20:55 -------- d-----w- c:\program files\YouTube Downloader
- 2010-03-04 18:55 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
- 2010-03-04 18:55 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
- 2010-03-02 18:48 . 2010-03-02 18:48 -------- d-----w- C:\Free Chess
- 2010-03-02 18:14 . 2010-03-02 18:14 0 ----a-w- c:\windows\nsreg.dat
- 2010-03-02 18:14 . 2010-03-02 18:14 -------- d-----w- c:\documents and settings\mladen\Local Settings\Application Data\Mozilla
- 2010-03-01 22:09 . 2010-03-01 22:09 -------- d-----w- c:\program files\NJ Soft
- 2010-03-01 17:24 . 2010-03-01 17:24 48 ---ha-w- c:\windows\system32\ezsidmv.dat
- 2010-03-01 17:24 . 2010-03-20 08:07 -------- d-----w- c:\documents and settings\mladen\Application Data\skypePM
- 2010-03-01 17:16 . 2010-03-20 13:35 -------- d-----w- c:\documents and settings\mladen\Application Data\Skype
- 2010-03-01 17:16 . 2010-03-01 17:16 -------- d-----w- c:\program files\Common Files\Skype
- 2010-03-01 17:16 . 2010-03-01 17:16 -------- d-----r- c:\program files\Skype
- 2010-03-01 17:16 . 2010-03-01 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-03-01 16:53 . 2010-03-01 15:50 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2010-03-01 16:33 . 2010-03-01 16:33 -------- d-----w- c:\program files\Alwil Software
- 2010-03-01 16:29 . 2010-03-01 16:29 -------- d-----w- c:\program files\VIA Technologies, Inc
- 2010-03-01 16:25 . 2010-03-01 16:25 2923 ----a-w- c:\windows\system32\unins000.dat
- 2010-03-01 16:25 . 2010-03-01 16:25 716153 ----a-w- c:\windows\system32\unins000.exe
- 2010-03-01 16:24 . 2010-03-01 16:21 -------- d-----w- c:\program files\Common Files\InstallShield
- 2010-03-01 16:22 . 2010-03-01 16:21 -------- d-----w- c:\program files\ATI Technologies
- 2010-03-01 16:22 . 2010-03-01 16:21 -------- d--h--w- c:\program files\InstallShield Installation Information
- 2010-03-01 16:14 . 2010-03-01 16:14 -------- d-----w- c:\program files\Opera
- 2010-03-01 15:59 . 2010-03-01 15:59 12328 ----a-w- c:\documents and settings\mladen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2010-03-01 15:52 . 2010-03-01 15:52 -------- d-----w- c:\program files\microsoft frontpage
- 2010-03-01 15:47 . 2010-03-01 15:47 21640 ----a-w- c:\windows\system32\emptyregdb.dat
- 2008-03-09 06:25 . 2010-03-01 16:25 236 ----a-w- c:\program files\Common Files\dx.reg
- 2004-08-03 22:56 . 2004-08-03 22:56 165025 --sha-r- c:\windows\system32\vkgqwr.dll
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-22 26101032]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-10-28 335872]
- "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
- c:\documents and settings\All Users\Start Menu\Programs\Startup\
- Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
- [HKEY_LOCAL_MACHINE\software\microsoft\security center]
- "AntiVirusOverride"=dword:00000001
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
- "EnableFirewall"= 0 (0x0)
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\Opera\\opera.exe"=
- "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
- "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
- "c:\\Program Files\\8BallClub\\GameDirector.exe"=
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
- "9163:TCP"= 9163:TCP:ybayz
- R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [3/4/2010 7:55 PM 114768]
- R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/4/2010 7:55 PM 20560]
- S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/14/2010 8:23 PM 717296]
- S2 smdqqzl;jnzezshb;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 11:56 PM 14336]
- S3 veillct;veillct;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
- smdqqzl
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.google.rs/
- FF - ProfilePath - c:\documents and settings\mladen\Application Data\Mozilla\Firefox\Profiles\xukmwvyp.default\
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs
- ---- FIREFOX POLICIES ----
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
- .
- **************************************************************************
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2010-03-20 15:03
- Windows 5.1.2600 Service Pack 2 NTFS
- scanning hidden processes ...
- scanning hidden autostart entries ...
- scanning hidden files ...
- scan completed successfully
- hidden files: 0
- **************************************************************************
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\veillct]
- "ImagePath"="\??\c:\windows\system32\01.tmp"
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\smdqqzl]
- "ServiceDll"="c:\windows\system32\vkgqwr.dll"
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\a67ae326-6297-6599-00a2-d678e65ee27]
- @Denied: (Full) (AuthenticatedUsers)
- @Denied: (Full) (Administrators)
- "1v0mvfsx3he2e"=hex:37,64,62,61,61,36,30,31,2d,33,32,36,33,2d,34,35,63,39,2d,
- 61,39,30,31,2d,66,30,37,33,33,64,64,65,39,36,65,37
- "1appx772ozi9x"=hex:65,00,00,00,f8,00,00,00,ff,1e,57,4b,6d,6c,61,64,65,6e,39,
- 35,73,74,75,62,69,63,61,00,01,a6,ba,7d,63,32,c9,45,a9,01,f0,73,3d,de,96,e7,\
- .
- Completion time: 2010-03-20 15:05:41
- ComboFix-quarantined-files.txt 2010-03-20 14:05
- Pre-Run: 8,984,768,512 bytes free
- Post-Run: 9,007,017,984 bytes free
- - - End Of File - - 20C55AB538452A9EB093E5E6FE541434
