offline
- Dejan123
- Počasni građanin
- Pridružio: 29 Avg 2005
- Poruke: 720
- Gde živiš: Beograd
|
ComboFix 07-12-19.2 - Dejan 2007-12-19 8:22:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.73 [GMT 1:00]
Running from: C:\Documents and Settings\Dejan\Desktop\New Folder (2)\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\sfsync02.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SFSYNC02
-------\sfsync02
((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 )))))))))))))))))))))))))))))))
.
2007-12-18 10:12 . 2007-12-18 10:20 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2007-12-18 09:50 . 2007-12-18 09:50 <DIR> d-------- C:\Your.Uninstaller_.2008.PRO
2007-12-18 09:47 . 2007-12-18 09:48 3,783,357 --a------ C:\Your.Uninstaller_.2008.PRO.rar
2007-12-16 18:07 . 2007-12-16 18:07 <DIR> d-------- C:\Program Files\General
2007-12-16 15:25 . 2007-12-16 15:25 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-12-16 09:12 . 2007-12-16 09:12 <DIR> d-------- C:\Program Files\Hotfix Manager
2007-12-16 08:46 . 2007-12-16 08:46 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-12-16 08:46 . 2007-12-16 08:46 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-12-16 08:15 . 2007-12-16 08:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-16 08:13 . 2007-12-16 08:13 <DIR> d-------- C:\Program Files\Malicious Software Removal Tool
2007-12-16 08:13 . 2007-03-07 18:45 6,054,400 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-16 08:13 . 2007-04-03 05:36 2,453,952 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-16 08:13 . 2007-01-31 07:47 991,232 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-16 08:13 . 2007-03-07 18:45 458,752 --a--c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-16 08:13 . 2007-04-03 15:46 383,488 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-16 08:13 . 2007-03-07 18:45 266,752 --a--c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-16 08:13 . 2007-03-07 18:45 51,712 --a--c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-16 08:13 . 2007-02-27 09:20 13,824 --a--c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-16 08:05 . 2007-12-16 08:05 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-16 07:45 . 2007-12-16 07:45 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-12-16 07:44 . 2007-12-16 07:44 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-12-16 07:44 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2007-12-16 07:39 . 2007-12-16 07:39 <DIR> d--h-c--- C:\WINDOWS\$SQLUninstallMSXML2SP6-KB887606-x86-ENU$
2007-12-16 07:39 . 2007-12-16 09:20 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-16 07:38 . 2007-12-16 07:38 <DIR> d-------- C:\Program Files\PowerMenu
2007-12-16 07:24 . 2007-03-12 16:16 10,752 --a------ C:\WINDOWS\system32\aamd532.dll
2007-12-16 07:18 . 2007-12-16 07:24 <DIR> d-------- C:\Program Files\AutoPatcher
2007-12-15 22:28 . 2007-12-16 01:07 319,507,151 --a------ C:\AutoPatcher_WinXP_May07_x86_ENU_Core.exe
2007-12-15 15:37 . 2007-12-15 15:37 <DIR> d-------- C:\Program Files\OrphansRemover
2007-12-15 15:37 . 2007-12-15 15:37 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\OrphansRemover
2007-12-15 14:17 . 2003-09-12 04:26 646,784 --a------ C:\WINDOWS\system32\drivers\CnxEtU.sys
2007-12-15 14:17 . 2003-10-29 08:07 163,840 --a------ C:\WINDOWS\system32\CnxHwIo.dll
2007-12-15 14:17 . 2002-08-06 08:59 118,784 --a------ C:\WINDOWS\system32\CnxMfdCo.dll
2007-12-15 14:17 . 2001-10-03 08:08 118,784 --a------ C:\WINDOWS\system32\CnxClsCo.dll
2007-12-15 14:17 . 2003-10-29 08:02 108,675 --a------ C:\WINDOWS\system32\drivers\CnxTgN.sys
2007-12-15 14:17 . 2003-09-12 04:26 60,288 --a------ C:\WINDOWS\system32\drivers\CnxEtP.sys
2007-12-15 13:46 . 2003-10-29 14:11 233,472 --a------ C:\WINDOWS\system32\CnxUnist.exe
2007-12-13 18:55 . 2005-04-30 23:41 200,704 --a------ C:\WINDOWS\system32\IfsDrives.dll
2007-12-13 18:55 . 2006-10-23 18:20 132,736 --a------ C:\WINDOWS\system32\drivers\ext2fs.sys
2007-12-13 18:55 . 2005-02-04 15:35 57,344 --a------ C:\WINDOWS\system32\IfsDrives.cpl
2007-12-13 18:55 . 2004-09-25 00:28 4,608 --a------ C:\WINDOWS\system32\drivers\IfsDrives.sys
2007-12-12 21:40 . 2007-12-12 21:41 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2007-12-12 21:37 . 2007-02-22 10:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-12-12 21:37 . 2007-02-22 10:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-12-12 21:37 . 2007-02-22 10:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-12-12 21:37 . 2007-02-22 10:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-12-11 17:58 . 2007-12-11 17:58 <DIR> d-------- C:\Program Files\Hirc
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\SystemRequirementsLab
2007-12-06 19:17 . 2007-12-13 20:13 90,980 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-06 19:17 . 2007-12-13 20:13 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-06 19:16 . 2007-12-19 08:33 19,995,168 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-06 19:16 . 2007-12-19 08:32 268,844 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-06 19:16 . 2007-12-19 08:33 205,600 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-06 19:16 . 2007-12-19 08:32 20,324 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-05 10:03 . 2007-12-11 12:34 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\gtk-2.0
2007-12-05 09:56 . 2007-12-05 09:56 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\Inkscape
2007-12-05 09:51 . 2007-12-05 09:55 <DIR> d-------- C:\Program Files\Inkscape
2007-11-25 19:26 . 2007-11-25 19:26 697 --a------ C:\WINDOWS\EReg515.dat
2007-11-25 18:00 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2007-11-25 18:00 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2007-11-25 18:00 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-11-25 18:00 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2007-11-25 18:00 . 2007-11-25 18:00 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-11-25 18:00 . 2007-11-25 18:00 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-11-25 17:56 . 2007-11-26 20:25 1,477 --a------ C:\WINDOWS\disney.ini
2007-11-21 09:34 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-19 06:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-18 19:06 --------- d-----w C:\Program Files\MSN Messenger
2007-12-18 19:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-18 10:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-18 09:36 --------- d-----w C:\Program Files\Paint.NET
2007-12-16 14:25 --------- d-----w C:\Program Files\Stardock
2007-12-16 06:55 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-16 06:50 --------- d-----w C:\Program Files\MSBuild
2007-12-15 17:15 --------- d-----w C:\Program Files\mIRC
2007-12-15 15:36 --------- d-----w C:\Documents and Settings\Dejan\Application Data\uTorrent
2007-12-15 14:24 --------- d-----w C:\Program Files\Blaze Media Pro
2007-12-15 13:04 --------- d-----w C:\Program Files\eMule
2007-12-15 12:54 --------- d-----w C:\Program Files\Gigatron
2007-12-15 12:51 --------- d-----w C:\Program Files\ConTEXT
2007-12-15 12:45 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-15 12:15 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{9EEC710E-58B9-4B76-93C5-36D01182487C}
2007-12-15 12:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 20:44 --------- d-----w C:\Program Files\Nokia
2007-12-12 20:44 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-12-12 20:44 --------- d-----w C:\Program Files\Common Files\Nokia
2007-12-12 20:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2007-12-06 18:16 --------- d-----w C:\Program Files\Kaspersky Lab
2007-11-30 12:21 --------- d-----w C:\Documents and Settings\Dejan\Application Data\Nokia
2007-11-22 19:14 --------- d-----w C:\Program Files\Trillian
2007-11-20 09:10 --------- d-----w C:\Documents and Settings\Dejan\Application Data\LimeWire
2007-11-14 20:56 --------- d-----w C:\Program Files\Common Files\SWF Studio
2007-11-13 05:37 11,264 --sha-w C:\Program Files\Thumbs.db
2007-11-13 05:37 --------- d-----w C:\Program Files\XviD
2007-11-13 05:37 --------- d-----w C:\Program Files\TrackMania Nations ESWC
2007-11-13 05:37 --------- d-----w C:\Program Files\mpegable
2007-11-12 18:35 --------- d-----w C:\Program Files\Nettalk6
2007-11-08 14:21 720,896 ----a-w C:\WINDOWS\iun6002.exe
2007-10-30 12:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Stardock
2007-10-23 10:31 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-10-23 10:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-23 10:25 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-21 06:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-20 14:47 --------- d-----w C:\Program Files\Opera 9
2007-06-25 14:58 141,577 ----a-w C:\Program Files\Nettalk - (6-25-2007 45819 PM).mht
2007-06-25 14:57 141,577 ----a-w C:\Program Files\Nettalk - (6-25-2007 45656 PM).mht
2007-05-08 21:05 80 --sha-r C:\WINDOWS\system32\AAF32A9973.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe" [2003-10-29 08:11]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35]
C:\Documents and Settings\Dejan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-12-16 15:25:54]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
PowerMenu.lnk - C:\Program Files\PowerMenu\PowerMenu.exe [2007-12-16 07:38:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-09-23 10:10 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Uniblue RegistryBooster 2"=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
R1 Ext2fs;Ext2fs;C:\WINDOWS\system32\DRIVERS\ext2fs.sys [2006-10-23 18:20]
R1 IfsDrives;IfsDrives;C:\WINDOWS\system32\DRIVERS\IfsDrives.sys [2004-09-25 00:28]
R2 LmpcService;Lock My PC Service;C:\Program Files\Lock My PC 4\LmpcServ.exe [2007-03-18 11:51]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2003-09-12 04:26]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2003-09-12 04:26]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2003-10-29 08:02]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
.
Contents of the 'Scheduled Tasks' folder
"2006-07-03 16:18:24 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-19 08:34:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
Completion time: 2007-12-19 8:37:35 - machine was rebooted
|