ComboFix 09-12-19.03 - Korisnik 20.12.2009 18:47:00.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.513 [GMT 1:00]
Running from: c:\documents and settings\Korisnik\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091220-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Korisnik\Application Data\avdrn.dat
c:\documents and settings\Korisnik\Application Data\wiaserva.log
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm19.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm25.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm29.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm34.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm35.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm48E.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm4D.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tm75.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tmA2.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tmD.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\_tmDC.tmp
c:\documents and settings\Korisnik\Local Settings\Temporary Internet Files\stb06759.tmp
c:\documents and settings\Korisnik\Start Menu\Programs\Startup\siszyd32.exe
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\inf
c:\windows\system32\lsprst7.dll
c:\windows\system32\prsgrc.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-20 to 2009-12-20 )))))))))))))))))))))))))))))))
.
2009-12-20 14:59 . 2009-07-28 14:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-19 20:07 . 2009-12-20 17:50 734208 ----a-w- c:\windows\system32\drivers\unctzo.sys
2009-12-19 20:07 . 2009-12-19 20:07 148 ----a-w- c:\windows\system32\fjhdyfhsn.bat
2009-12-10 19:10 . 2009-12-17 21:03 -------- d-----w- c:\documents and settings\Korisnik\Local Settings\Application Data\Cooliris
2009-12-03 22:22 . 2009-12-03 22:23 -------- d-----w- c:\documents and settings\Korisnik\Application Data\SecondLife
2009-12-03 22:22 . 2009-12-03 22:44 -------- d-----w- c:\documents and settings\Korisnik\Local Settings\Application Data\SecondLife
2009-11-22 13:41 . 2009-11-22 13:41 117760 ----a-w- c:\documents and settings\Korisnik\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-22 13:40 . 2009-11-22 13:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-11-22 13:40 . 2009-12-07 16:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-11-22 13:40 . 2009-11-22 13:40 -------- d-----w- c:\documents and settings\Korisnik\Application Data\SUPERAntiSpyware.com
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-20 14:46 . 2009-11-04 16:12 186 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\prsgrc.dll
2009-12-20 13:31 . 2009-01-19 18:54 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-19 21:51 . 2008-01-19 01:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-19 20:17 . 2009-02-01 14:36 -------- d-----w- c:\documents and settings\Korisnik\Application Data\uTorrent
2009-12-19 20:06 . 2009-12-19 20:06 16 ----a-w- c:\documents and settings\LocalService\Application Data\fvgqad.dat
2009-12-19 14:17 . 2009-12-19 14:17 118784 ----a-w- c:\windows\Web\Wallpaper\Living Waterfalls Wallpaper #1.exe
2009-12-19 14:15 . 2008-11-17 15:25 -------- d-----w- c:\program files\MP3 Rocket
2009-12-19 14:15 . 2008-04-02 20:13 -------- d-----w- c:\documents and settings\Korisnik\Application Data\MP3Rocket
2009-12-14 20:32 . 2009-02-28 22:40 95744 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-02 13:18 . 2008-09-06 14:31 -------- d-----w- c:\program files\Google
2009-11-29 18:08 . 2008-04-08 17:56 -------- d-----w- c:\program files\Windows Live
2009-11-24 23:54 . 2009-02-09 21:09 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-02-09 21:09 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-02-09 21:09 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-02-09 21:09 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-02-09 21:09 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-02-09 21:09 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-02-09 21:09 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-02-09 21:09 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-02-09 21:09 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-22 13:40 . 2009-01-22 18:57 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-14 11:02 . 2009-01-12 20:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-04 17:14 . 2008-01-18 20:07 68984 -c--a-w- c:\documents and settings\Korisnik\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-04 16:08 . 2009-11-04 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\SPSS
2009-11-04 16:08 . 2009-11-04 16:08 -------- d-----w- c:\program files\Common Files\SPSS
2009-11-04 16:08 . 2009-11-04 16:08 -------- d-----w- c:\program files\SPSSInc
2009-11-04 16:08 . 2009-11-04 16:08 1025 ----a-w- c:\windows\system32\sysprs7.dll
2008-05-04 21:56 . 2008-05-04 21:55 2401296 ----a-w- c:\program files\WLinstaller.exe
2009-07-06 10:15 . 2009-02-09 20:55 251392 ----a-w- c:\program files\opera\program\plugins\dapop.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2006-12-22 10:28 271360 ----a-w- c:\windows\system32\mscoree.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-08-18 5137648]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-07-06 2749952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-09 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-10-28 344064]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"nwiz"="nwiz.exe" [2007-06-28 1626112]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-03 16841216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Korisnik^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Korisnik^Start Menu^Programs^Startup^Webshots.lnk]
path=c:\documents and settings\Korisnik\Start Menu\Programs\Startup\Webshots.lnk
backup=c:\windows\pss\Webshots.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 -c--a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-02-13 23:09 486856 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
2009-07-06 10:15 2749952 ----a-w- c:\program files\DAP\DAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-02 16:48 133104 -----tw- c:\documents and settings\Korisnik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP4 Player]
2008-11-06 17:23 772096 ----a-w- c:\program files\MP4 Player\Mp4Player.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nexus Radio]
2009-03-08 20:08 4685312 -c--a-w- c:\program files\Nexus Radio\Nexus Radio.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-10-19 18:16 286720 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24 32768 -c--a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2008-07-02 15:16 393216 ------w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-11-10 12:03 36975 -c--a-w- c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-09 21:25 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SENS"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"NVSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.com"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7.2.2009 0:49 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8.2.2009 23:03 28544]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9.2.2009 22:09 114768]
R2 AGCoreService;AG Core Services;c:\program files\AGI\core\3.1\AGCoreService.exe [20.9.2009 16:03 20480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.2.2009 22:09 20560]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16.2.2008 15:07 716272]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2.4.2009 12:38 13224]
--- Other Services/Drivers In Memory ---
*Deregistered* - unctzo
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.theprizeday.com/today.php
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.krstarica.com
uInternet Connection Wizard,ShellNext = iexplore
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Korisnik\Application Data\Mozilla\Firefox\Profiles\omeyncdj.default\
FF - prefs.js: browser.search.selectedEngine - GamingHarbor
FF - prefs.js: browser.startup.homepage - hxxp://home.gamingharbor.com
FF - prefs.js: keyword.URL - hxxp://www.gamingharbor.com/search.do?desktopsmiley&keyword=
FF - plugin: c:\documents and settings\Korisnik\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
pref(dom.disable_open_during_load, false);FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
Notify-WgaLogon - (no file)
MSConfigStartUp-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
MSConfigStartUp-SmileyApp - c:\program files\DoubleD\GamingHarbor Toolbar\4.1.4.20920\stbapp.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
AddRemove-{1FB52AB3-5987-45a2-85E0-F3EC30DDDC29}}_is1 - c:\program files\Internet Saving Optimizer\3.4.0.4340\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-20 18:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\_avast4_\unp235409863.tmp 1582 bytes
c:\windows\TEMP\_avast4_\unp5266459.tmp 1581 bytes
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\unctzo]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-20 18:52:50
ComboFix-quarantined-files.txt 2009-12-20 17:52
ComboFix2.txt 2009-02-09 20:21
Pre-Run: 29.007.126.528 bytes free
Post-Run: 29.018.800.128 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - A20FFA4CE9828AF7EDA85915CB4F7FB3