ComboFix 09-12-29.04 - pantovic.s 12/30/2009 9:37.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.149 [GMT 1:00]
Running from: c:\documents and settings\pantovic.s\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
-- Previous Run --
Infected copy of c:\windows\system32\msgsvc.dll was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\msgsvc.dll
--------
Infected copy of c:\windows\system32\msgsvc.dll was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\msgsvc.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.
2009-12-29 08:27 . 2009-12-23 12:49 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-12-29 08:27 . 2009-12-23 12:49 502040 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrsx.exe
2009-12-29 08:27 . 2009-12-23 12:49 12464 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrsstx.dll
2009-12-29 08:27 . 2009-12-23 12:49 28424 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2009-12-29 08:24 . 2009-12-23 12:49 877848 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-12-29 08:24 . 2009-12-23 12:49 1657112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-12-29 08:24 . 2009-12-23 12:49 798488 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2009-12-29 08:24 . 2009-12-23 12:49 610072 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-12-24 09:35 . 2009-12-24 09:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-24 09:35 . 2009-12-24 09:35 -------- d-----w- c:\program files\Java
2009-12-24 09:34 . 2009-12-24 09:34 152576 ----a-w- c:\documents and settings\pantovic.s\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-24 09:34 . 2009-12-24 09:34 79488 ----a-w- c:\documents and settings\pantovic.s\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-23 12:50 . 2009-12-23 13:11 -------- d-----w- C:\$AVG
2009-12-23 12:49 . 2009-12-29 08:26 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-23 12:49 . 2009-12-23 12:49 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-12-23 12:49 . 2009-12-29 08:26 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-23 12:49 . 2009-12-23 12:49 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-23 12:49 . 2009-12-29 08:26 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-23 12:49 . 2009-12-30 08:19 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-23 12:49 . 2009-12-23 12:49 -------- d-----w- c:\program files\AVG
2009-12-23 12:49 . 2009-12-30 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-23 12:43 . 2009-12-23 12:43 -------- d-----w- c:\documents and settings\pantovic.s\Contacts
2009-12-18 10:23 . 2009-12-18 11:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-18 10:23 . 2009-12-18 10:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-14 13:16 . 2009-12-14 13:16 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\U3
2009-12-09 13:11 . 2009-12-17 15:54 -------- d-----w- c:\program files\Telenor Internet
2009-12-04 13:44 . 2009-12-04 13:44 -------- d-----w- c:\program files\Trend Micro
2009-12-03 11:42 . 2009-12-03 11:42 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\Malwarebytes
2009-12-03 11:42 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 11:42 . 2009-12-03 11:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-03 11:42 . 2009-12-03 11:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-03 11:42 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-03 09:08 . 2009-12-15 08:56 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\vlc
2009-12-03 09:07 . 2009-12-03 09:07 -------- d-----w- c:\program files\VideoLAN
2009-12-03 08:56 . 2009-12-03 08:56 -------- d-----w- c:\program files\CCleaner
2009-12-03 08:27 . 2009-12-03 08:27 -------- d-----w- c:\documents and settings\suka.lj\Local Settings\Application Data\Mozilla
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 08:46 . 2009-11-10 13:01 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\Dropbox
2009-12-30 08:45 . 2009-08-25 12:47 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\OpenOffice.org2
2009-12-29 11:36 . 2009-08-28 09:44 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\Skype
2009-12-29 11:28 . 2009-08-28 09:53 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\skypePM
2009-12-23 12:42 . 2006-09-21 14:22 -------- d-----w- c:\program files\MSN Messenger
2009-12-04 13:46 . 2009-09-07 13:34 -------- d-----w- c:\program files\PokerStars
2009-12-03 12:49 . 2009-09-28 13:33 -------- d-----w- c:\program files\BitLord
2009-11-17 10:26 . 2009-09-08 12:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-13 09:59 . 2009-11-13 09:59 -------- d-----w- c:\program files\Ahead
2009-11-13 09:59 . 2009-11-13 09:59 -------- d-----w- c:\program files\Common Files\Ahead
2009-11-11 14:49 . 2009-10-14 07:57 -------- d-----w- c:\program files\Burn4Free
2009-11-10 13:02 . 2009-11-10 13:02 89962 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\Uninstall.exe
2009-11-09 12:33 . 2009-11-09 12:33 -------- d-----w- c:\documents and settings\pantovic.s\Application Data\Octoshape
2009-10-22 09:18 . 2009-10-22 09:18 15240 ----a-w- c:\documents and settings\pantovic.s\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
2009-10-13 11:47 . 2009-10-13 11:47 71208 ----a-w- c:\documents and settings\filipovic.n\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-09 01:18 . 2009-10-09 01:18 26805255 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\Dropbox.exe
2009-10-08 21:18 . 2009-10-08 21:18 499712 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\msvcp71.dll
2009-10-08 21:18 . 2009-10-08 21:18 348160 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\msvcr71.dll
2009-10-08 21:18 . 2009-10-08 21:18 77824 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\DropboxExt.3.dll
.
------- Sigcheck -------
[-] 2006-08-03 . 32272BF10467C8ACF1F83138C61D541E . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-10-29_09.00.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 19:54 . 2009-07-11 19:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-11 19:32 . 2009-07-11 19:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-12 00:07 . 2009-07-12 00:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 00:19 . 2009-07-12 00:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-11 18:41 . 2009-07-11 18:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2009-12-30 08:44 . 2009-12-30 08:44 16384 c:\windows\temp\Perflib_Perfdata_6c8.dat
+ 2009-10-23 10:50 . 2007-08-29 14:06 53248 c:\windows\system32\spool\drivers\w32x86\3\ZTAG.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 61440 c:\windows\system32\spool\drivers\w32x86\3\ZSDNT5UI.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 73728 c:\windows\system32\spool\drivers\w32x86\3\ZSDIMF.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 57344 c:\windows\system32\spool\drivers\w32x86\3\ZQDPRINT.DLL
+ 2007-04-04 14:46 . 2007-08-29 14:06 65536 c:\windows\system32\spool\drivers\w32x86\3\ZJBIG.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 57344 c:\windows\system32\spool\drivers\w32x86\3\ZIMFPRNT.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 61440 c:\windows\system32\spool\drivers\w32x86\3\ZIMF.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 98304 c:\windows\system32\spool\drivers\w32x86\3\ZGDI.DLL
+ 2007-01-19 11:53 . 2007-01-19 11:53 51056 c:\windows\system32\sirenacm.dll
+ 2002-12-31 13:00 . 2009-12-30 08:38 71370 c:\windows\system32\perfc009.dat
- 2002-12-31 13:00 . 2009-10-28 11:27 71370 c:\windows\system32\perfc009.dat
+ 2009-12-23 12:40 . 2009-12-23 12:40 29926 c:\windows\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2009-10-23 10:50 . 2008-02-11 13:26 7680 c:\windows\system32\spool\drivers\w32x86\3\HPAppUsg.dll
+ 2009-11-13 10:00 . 2005-09-01 10:03 5888 c:\windows\system32\drivers\imagedrv.sys
+ 2009-07-12 00:12 . 2009-07-12 00:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 00:09 . 2009-07-12 00:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 00:08 . 2009-07-12 00:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2006-06-05 13:14 . 2006-06-05 13:14 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
+ 2006-06-05 13:14 . 2006-06-05 13:14 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
+ 2006-06-05 13:14 . 2006-06-05 13:14 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2009-11-13 09:59 . 2004-07-09 07:43 364544 c:\windows\system32\TwnLib4.dll
+ 2009-11-13 09:59 . 2000-06-26 09:45 106496 c:\windows\system32\TwnLib20.dll
+ 2009-10-23 10:50 . 2007-08-29 14:06 286720 c:\windows\system32\spool\drivers\w32x86\3\ZSUXML.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 323584 c:\windows\system32\spool\drivers\w32x86\3\ZSR.DLL
+ 2007-04-04 14:46 . 2007-08-29 14:06 106496 c:\windows\system32\spool\drivers\w32x86\3\ZSPOOL.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 172032 c:\windows\system32\spool\drivers\w32x86\3\ZSDDMUI.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 122880 c:\windows\system32\spool\drivers\w32x86\3\ZSDDM.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 155648 c:\windows\system32\spool\drivers\w32x86\3\ZSD.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 110592 c:\windows\system32\spool\drivers\w32x86\3\ZIMFDRV.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 618496 c:\windows\system32\spool\drivers\w32x86\3\SUcp1215.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 454656 c:\windows\system32\spool\drivers\w32x86\3\SDcp1215.DLL
+ 2005-05-18 14:59 . 2005-05-18 14:59 262144 c:\windows\system32\PexCryptoAPI.dll
+ 2002-12-31 13:00 . 2009-12-30 08:38 439832 c:\windows\system32\perfh009.dat
- 2002-12-31 13:00 . 2009-10-28 11:27 439832 c:\windows\system32\perfh009.dat
+ 2005-05-18 15:00 . 2005-05-18 15:00 253952 c:\windows\system32\NetSeTAPI.dll
+ 2009-11-13 09:59 . 2006-01-12 14:40 155648 c:\windows\system32\NeroCheck.exe
+ 2009-12-24 09:35 . 2009-12-24 09:35 149280 c:\windows\system32\javaws.exe
+ 2009-12-24 09:35 . 2009-12-24 09:35 145184 c:\windows\system32\javaw.exe
+ 2009-12-24 09:35 . 2009-12-24 09:35 145184 c:\windows\system32\java.exe
+ 2009-11-13 09:59 . 2004-07-26 15:16 471040 c:\windows\system32\ImagXRA7.dll
+ 2009-11-13 09:59 . 2004-07-26 15:16 262144 c:\windows\system32\ImagXR7.dll
+ 2009-11-13 09:59 . 2004-07-26 15:16 476320 c:\windows\system32\ImagXpr7.dll
+ 2009-11-13 10:00 . 2005-09-01 10:03 127488 c:\windows\system32\drivers\imagesrv.sys
+ 2009-12-23 12:40 . 2009-12-23 12:40 697856 c:\windows\Installer\d42a6f.msi
+ 2009-12-23 12:49 . 2009-12-23 12:49 424448 c:\windows\Installer\648e9.msi
+ 2009-12-24 09:35 . 2009-12-24 09:35 537600 c:\windows\Installer\4d9930.msi
+ 2009-07-11 19:46 . 2009-07-11 19:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 19:46 . 2009-07-11 19:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2007-04-04 14:46 . 2007-08-29 14:06 1572864 c:\windows\system32\spool\drivers\w32x86\3\XERCES-C.DLL
+ 2009-10-23 10:50 . 2007-08-29 14:06 9916416 c:\windows\system32\spool\drivers\w32x86\3\cp1215PQ.dll
+ 2009-11-13 09:59 . 2004-07-26 15:16 1568768 c:\windows\system32\ImagX7.dll
+ 2009-12-23 12:40 . 2007-01-19 12:20 16633344 c:\windows\Installer\MSN Messenger 8.1.0178\MsnMsgs.Msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 ----a-w- c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\DropboxExt.3.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 761946]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 131072]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 454656]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88203]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2002-12-31 143360]
"GrooveMonitor"="c:\program files\Microsoft Outlook\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-29 2033432]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-24 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2002-12-31 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlhr"="c:\windows\System32\AdvPack.Dll" [2002-12-31 99840]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2002-12-31 44544]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]
c:\documents and settings\pantovic.s\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\Dropbox.exe [2009-10-9 26805255]
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-1-25 61440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"MaxGPOScriptWait"= 1800 (0x708)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-29 08:26 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7593:TCP"= 7593:TCP:ocbwn
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/23/2009 1:49 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/23/2009 1:49 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/23/2009 1:49 PM 360584]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/29/2009 9:26 AM 285392]
S2 hajwnjal;Time Microsoft;c:\windows\system32\svchost.exe -k netsvcs [12/31/2002 2:00 PM 14336]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys --> c:\windows\system32\DRIVERS\ewusbfake.sys [?]
S3 ids00026;ids00026;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys --> c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys [?]
S3 ids00118;ids00118;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00118.sys --> c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00118.sys [?]
S3 ids0014f;ids0014f;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0014f.sys --> c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0014f.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
hajwnjal
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {62CF4D10-EBA7-45DA-ACA0-4B002E8B3A85} - hxxps://secure.24x7.rs/MarfinBank/Corporate/Pages/Download/CABS/DigitrustApiNetSetPlugIn.cab
FF - ProfilePath - c:\documents and settings\pantovic.s\Application Data\Mozilla\Firefox\Profiles\tcj1louo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-30 09:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3808)
c:\documents and settings\pantovic.s\Application Data\Dropbox\bin\DropboxExt.3.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\msiexec.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\AGRSMMSG.exe
c:\progra~1\hpq\Shared\HPQTOA~1.EXE
c:\program files\OpenOffice.org 2.0\program\soffice.exe
c:\program files\OpenOffice.org 2.0\program\soffice.BIN
c:\program files\AVG\AVG9\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2009-12-30 09:50:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-30 08:50
ComboFix2.txt 2009-12-04 15:28
ComboFix3.txt 2009-10-29 09:26
ComboFix4.txt 2009-10-29 09:02
ComboFix5.txt 2009-12-29 09:08
Pre-Run: 7,625,969,664 bytes free
Post-Run: 7,605,567,488 bytes free
- - End Of File - - 552A2A5D46375A541AE74AB1E8A97DB0