offline
- zorantasevski
- Ugledni građanin
- Pridružio: 03 Avg 2003
- Poruke: 398
- Gde živiš: Deutschland
|
ComboFix 07-11-01.1** - PC 11/04/2007 23:09:43.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.2.1252.1.1033.18.253 [GMT 1:00]
Running from: C:\Documents and Settings\PC\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 )))))))))))))))))))))))))))))))
.
2007-11-04 23:09 51,200 --a------ C:\WINNT\NirCmd.exe
2007-11-04 23:09 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2c0.dat
2007-11-01 21:40 <DIR> d-------- C:\Program Files\2Bet
2007-10-30 10:16 8,224 --a------ C:\Documents and Settings\PC\Application Data\GDIPFONTCACHEV1.DAT
2007-10-27 16:14 <DIR> d-------- C:\Program Files\LG Electronics
2007-10-27 16:13 <DIR> d-------- C:\Program Files\LGGSM
2007-10-27 16:13 81,920 -ra------ C:\WINNT\system32\srctrl.dll
2007-10-13 10:35 <DIR> d-------- C:\Tanja
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 20:17 --------- d-----w C:\Program Files\Trillian
2007-10-27 15:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-27 15:13 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-02 19:51 --------- d-----w C:\Documents and Settings\PC\Application Data\ErrorSmart
2007-10-02 09:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-20 09:37 --------- d-----w C:\Program Files\Ahead
2007-09-20 09:35 --------- d-----w C:\Program Files\Common Files\Ahead
2007-09-16 18:50 --------- d-----w C:\Program Files\Mini recnik
2007-09-13 21:34 --------- d-----w C:\Program Files\FileZilla
2007-08-21 08:57 99,965 ----a-w C:\WINNT\UninstallFirefox.exe
2007-08-21 08:38 270,336 ----a-w C:\WINNT\system32\imon.dll
2007-08-20 21:11 9,488 ----a-w C:\WINNT\AppPatch\ProfilesRegQueryValueEx.dll
2007-08-20 21:11 9,488 ----a-w C:\WINNT\AppPatch\HandleStartKeyword.dll
2007-08-20 21:11 9,488 ----a-w C:\WINNT\AppPatch\HandleNullPrinterName.dll
2007-08-20 21:11 9,488 ----a-w C:\WINNT\AppPatch\ForceCDRomStop.dll
2007-08-20 21:11 9,488 ----a-w C:\WINNT\AppPatch\ForceAnsiGetDisplayNameOf.dll
2007-08-20 21:11 8,976 ----a-w C:\WINNT\AppPatch\ForceDxSetupSuccess.dll
2007-08-20 21:11 8,976 ----a-w C:\WINNT\AppPatch\DeleteSpecifiedFiles.dll
2007-08-20 21:11 8,976 ----a-w C:\WINNT\AppPatch\DelayShowGroup.dll
2007-08-20 21:11 8,464 ----a-w C:\WINNT\AppPatch\SyncSystemAndSystem32.dll
2007-08-20 21:11 8,464 ----a-w C:\WINNT\AppPatch\SearchPathInAppPaths.dll
2007-08-20 21:11 8,464 ----a-w C:\WINNT\AppPatch\RemoveSpacesAfterSlashFromFilenames.dll
2007-08-20 21:11 8,464 ----a-w C:\WINNT\AppPatch\DirectPlayEnumOrder.dll
2007-08-20 21:11 8,464 ----a-w C:\WINNT\AppPatch\DinosaurActivityCenter.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\SanitizeCreateProcessStartupInfo.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\RemoveReadOnlyAttrFromCDRomDirs.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\IgnoreLoadLibrary.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\ForceWorkingDirectoryToEXEPath.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\ForceDdrawWait.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\FillOnEraseBackground.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\DisableW2KOwnerDrawButtonStates.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\DeRandomizeExeName.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\CorrectDisableScreenSaver.dll
2007-08-20 21:11 7,952 ----a-w C:\WINNT\AppPatch\BattleZone.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\USNF97.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\UltimateSoccerManager.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\Ultima9.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\SyncMutexRelease.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\LoadComctl32Version5.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\LimitFindFile.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\IgnoreAltTab.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\HeapLookasideFree.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\FullPathCommandLine.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\ForceShellLinkResolveNoUI.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\ForceRedrawOnSetFocus.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\ForceKeepFocus.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\CorrectCreateProcess16Bit.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\Commandos.dll
2007-08-20 21:11 7,440 ----a-w C:\WINNT\AppPatch\3dJungleTrain.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\SwallowMessageBox.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\Riven.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\RecopyExeFromCD.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\ProfilesEnvStrings.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\IgnoreFreeLibrary.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\HoyleCasino4.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\HoyleBoardGames2000.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\HideDisplayModes.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\HandleRegExpandSzRegistryKeys.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\ForceOpenReadOnlyFiles.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\ForceApplicationFocus.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\EnableRestarts.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\DelayWinMMCallback.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\CorrectMapperDeviceId.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\CorrectActiveMoviePath.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\CheckTextColor.dll
2007-08-20 21:11 6,928 ----a-w C:\WINNT\AppPatch\AddWritePermissionsToDeviceFiles.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\WinFaxPro9.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\WinExecRaceConditionFix.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\Win95VersionLie.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\Win2000VersionLie.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\RemoveInvalidMessage.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\RedirectUserFoldersToCommon.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\PanzerCommander.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\NFLBlitz.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\MoveWinInitRenameToReg.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\IE5DOMSetup.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\HeapValidateFrees.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\HandleWvsprintfExceptions.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\HandleResourceInStatic.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\HandlePaintMessages.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\HandleGetFileAttributesExceptions.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\HandleBadSetWindowsHook.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\ForceTemporaryModeChange.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\ForceDefaultSystemPaletteEntries.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\ForceCoInitialize.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\ForceAVISameWindow.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\F18Carrier.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\DirtTrackRacing.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\DelayFree.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\CreateEventCorrectName.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\CorrectAcmStreamArgs.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\CheckJoyCaps.DLL
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\Battleship.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\BaanERP5.dll
2007-08-20 21:11 6,416 ----a-w C:\WINNT\AppPatch\2GbGetDiskFreeSpace.dll
2007-08-20 21:11 5,904 ----a-w C:\WINNT\AppPatch\Win9xCDROMSectors.dll
2007-08-20 21:11 5,904 ----a-w C:\WINNT\AppPatch\waveOutUsePreferredDevice.dll
2007-08-20 21:11 5,904 ----a-w C:\WINNT\AppPatch\VSAnalyzerServerSetup.dll
2007-08-20 21:11 5,904 ----a-w C:\WINNT\AppPatch\SyncSendMessage.dll
2007-08-20 21:11 5,904 ----a-w C:\WINNT\AppPatch\SucceedWhenFileNotFoundInRegQueries.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [05/08/01 01:00p C:\WINNT\system32\mobsync.exe]
"SoundMan"="soundman.exe" [05/19/00 04:56a C:\WINNT\system32\soundman.exe]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [03/10/06 06:45p]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [08/21/07 09:38a]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [07/09/01 10:50a]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [08/21/07 09:46a]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-08-21 12:27:21]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
R0 idebd;idebd;C:\WINNT\System32\DRIVERS\idebd.sys
R0 IntelATA;IntelATA;C:\WINNT\System32\DRIVERS\intelata.sys
R1 fwdrv;Kerio Personal Firewall Driver;C:\WINNT\System32\Drivers\fwdrv.sys
R3 ALCICH;Service for Avance AC'97 Driver (WDM);C:\WINNT\System32\drivers\ALCICH.SYS
R3 S3Inc;S3Inc;C:\WINNT\System32\DRIVERS\s3mini.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-02 19:51:49 C:\WINNT\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Program Files\ErrorSmart\ErrorSmart.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-04 23:10:44
Windows 5.0.2195 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/04/2007 23:11:09
.
--- E O F ---
|