joj, već me sram...
evo:
"Irena" - 2009-04-13 0:17:45 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Irena\"
Command switches used :: ""C:\Documents and Settings\Irena\Desktop\CFScript.txt""
((((((((((((((((((((((((((((((( Files Created from 2009-03-12 to 2009-04-12 ))))))))))))))))))))))))))))))))))
2009-04-12 21:01 49,152 --a------ C:\WINDOWS\nircmd.exe
2009-04-12 20:05 387,584 --a------ C:\WINDOWS\system32\CF15820.exe
2009-04-12 20:03 73,728 --a------ C:\pv.exe
2009-04-12 20:02 387,584 --a------ C:\WINDOWS\system32\CF15487.exe
2009-04-12 16:58 <DIR> d-------- C:\Program Files\Autorun Eater
2009-04-12 16:29 16,896 --a------ C:\WINDOWS\system32\WinCtrl32.dll
2009-04-12 15:25 7,168 --a------ C:\WINDOWS\system32\drivers\bltrust.sys
2009-04-12 15:25 <DIR> d-------- C:\WINDOWS\system32\TrustNoExe
2009-04-10 18:59 26,112 --a------ C:\WINDOWS\system32\drivers\MemStPCI.SYS
2009-03-14 22:40 410,984 --a------ C:\WINDOWS\system32\deploytk.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2009-04-12 10:18:34 31,616 ----a-w C:\WINDOWS\system32\drivers\Winjo60.sys
2009-03-09 11:37:13 -------- d-----w C:\Program Files\In Flames - Screensaver
2009-03-06 12:03:26 -------- d-----w C:\Program Files\Windows Live
2009-03-06 12:02:49 -------- d-----w C:\Program Files\Windows Live Toolbar
2009-03-06 12:02:21 -------- d-----w C:\Program Files\Microsoft Sync Framework
2009-03-06 12:01:13 -------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2009-03-06 11:57:52 -------- d-----w C:\Program Files\Windows Live SkyDrive
2009-03-06 11:46:24 -------- d-----w C:\Program Files\Common Files\Windows Live
2009-03-01 11:10:59 -------- d-----w C:\Program Files\OnLine Brojac v.7.0
2009-02-26 11:48:41 -------- d-----w C:\Program Files\Google
2009-02-25 19:10:50 -------- d-----w C:\DOCUME~1\Irena\APPLIC~1\Google
2009-02-25 19:00:03 -------- d-----w C:\Program Files\Windows Installer Clean Up
2009-02-25 18:59:54 -------- d-----w C:\Program Files\MSECACHE
2009-02-06 19:02:48 308,104 ----a-w C:\WINDOWS\WLXPGSS.SCR
2009-02-06 17:52:40 49,504 ----a-w C:\WINDOWS\system32\sirenacm.dll
2008-08-14 18:11:32 3,364,957 --sha-w C:\WINDOWS\system32\rsetup.exe
2008-02-08 20:45:21 2,026 --sha-r C:\WINDOWS\system32\udardn.dll
2008-02-08 20:45:17 84,968 --sha-r C:\WINDOWS\system32\hgmfjn.dll
2008-02-08 20:45:11 1,624 --sha-r C:\WINDOWS\system32\comqqcea.dll
2008-02-06 15:07:04 1,536 --sha-w C:\WINDOWS\page files\maxmeg.sys
2007-11-28 18:56:28 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-11-28 14:27:21 8 --sh--r C:\WINDOWS\system32\B83872C642.sys
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}=C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 19:04]
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}=C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 18:49]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 16:41]
{DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-14 22:39]
{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}=C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 19:17]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}=C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-14 22:39]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2009-03-03 15:50]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-03-14 22:39]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
"SystemExplorer"="C:\BUG\SystemExplorer 1.2.1\SystemExplorer.exe" [2007-12-23 20:39]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 19:52]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WinCtrl32]
WinCtrl32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\Winjo60.sys]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0767371f-87c7-11dc-9fa4-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0feda428-a7ec-11dc-9fdb-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0feda43d-a7ec-11dc-9fdb-00112faf3edf}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Open(&0)\command- Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{149d693a-ae4a-11dd-a209-00112faf3edf}]
auto\command- Knight.exe open
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
explore\command- Knight.exe open
find\command- Knight.exe open
install\command- Knight.exe open
open\command- Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{330b1590-1b61-11dd-a0e0-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36acb84c-27f0-11dd-a0f1-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38ae4188-7e43-11dc-9f95-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3940df15-f519-11dc-a097-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58e32767-7be5-11dc-9f91-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5921229d-1e99-11dd-a0e4-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5df69683-210b-11dd-a0e7-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c19380e-1658-11de-a2cd-00112faf3edf}]
auto\command- Knight.exe open
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
explore\command- Knight.exe open
find\command- Knight.exe open
install\command- Knight.exe open
open\command- Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e7c1658-25a7-11dd-a0ed-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bdc8b5a-e92c-11dc-a07e-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c4f0299-1139-11dd-a0ca-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d1c72cc-3234-11dd-a100-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e99cb84-53ed-11dd-a13d-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d3dcf94-0ae6-11dd-a0bc-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b17b9fde-00d4-11dd-a0ad-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b4e03bf6-70fb-11dc-9488-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c53ce9ec-dee7-11dc-a05d-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c96adf95-7735-11dc-9f88-00112faf3edf}]
AutoRun\command- G:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca877488-1201-11dd-a0cb-00112faf3edf}]
auto\command- Knight.exe open
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
explore\command- Knight.exe open
find\command- Knight.exe open
install\command- Knight.exe open
open\command- Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb09fc1c-69e2-11dd-a180-00112faf3edf}]
AutoRun\command- G:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3e43dc8-c5cf-11dc-a017-00112faf3edf}]
auto\command- Knight.exe open
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
explore\command- Knight.exe open
find\command- Knight.exe open
install\command- Knight.exe open
open\command- Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec4a0e08-af3d-11dd-a20b-00112faf3edf}]
auto\command- Knight.exe open
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
explore\command- Knight.exe open
find\command- Knight.exe open
install\command- Knight.exe open
open\command- Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef90ae6e-9b57-11dc-9fc0-00112faf3edf}]
auto\command- Knight.exe open
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
explore\command- Knight.exe open
find\command- Knight.exe open
install\command- Knight.exe open
open\command- Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6fb6ff9-0aea-11dd-a0bd-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6fb6ffa-0aea-11dd-a0bd-00112faf3edf}]
AutoRun\command- I:\
open\Command- rundll32.exe .\desktop.dll,InstallM
*Newly Created Service* - HTTPFILTER
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-13 00:24:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
disk error: C:\WINDOWS\
please note that you need administrator rights to perform deep scan
********************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\JavaQuickStarterService]
"ImagePath"="\"C:\Program Files\Java\jre6\bin\jqs.exe\" -service -config \"C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf\""
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\UACd.sys]
"imagepath"="\systemroot\system32\drivers\UACyqomuwyl.sys"
Completion time: 2009-04-13 0:28:45
C:\ComboFix-quarantined-files.txt ... 2009-04-13 00:28
C:\ComboFix2.txt ... 2009-04-12 21:01
--- E O F ---