offline
- zakici
- Novi MyCity građanin
- Pridružio: 25 Jan 2008
- Poruke: 10
- Gde živiš: ZR
|
ComboFix 08-06-10.5 - XPPRESP3 2008-06-11 18:04:51.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.134 [GMT 2:00]
Running from: C:\Documents and Settings\XPPRESP3\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\XPPRESP3\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\vtUnKcaX.dll
C:\WINDOWS\system32\winccf32.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AdwareSpywareScannerDeleter
C:\Program Files\AdwareSpywareScannerDeleter\AdSpyDeleter.exe
C:\Program Files\AdwareSpywareScannerDeleter\homepage.url
C:\Program Files\AdwareSpywareScannerDeleter\LICENSE.TXT
C:\Program Files\AdwareSpywareScannerDeleter\unins000.dat
C:\Program Files\AdwareSpywareScannerDeleter\unins000.exe
C:\WINDOWS\system32\PsvwDMoq.ini
C:\WINDOWS\system32\PsvwDMoq.ini2
C:\WINDOWS\system32\qoMDwvsP.dll
C:\WINDOWS\system32\vtUnKcaX.dll
C:\WINDOWS\system32\winccf32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_WudfPf
((((((((((((((((((((((((( Files Created from 2008-05-11 to 2008-06-11 )))))))))))))))))))))))))))))))
.
2008-06-09 18:46 . 2008-06-09 18:46 <DIR> d-------- C:\WINDOWS\$regcmp$
2008-06-08 19:50 . 2008-06-08 19:50 137,344 --a------ C:\WINDOWS\system32\drivers\hwpsgt.sys
2008-06-08 19:50 . 2008-06-08 19:50 9,472 --a------ C:\WINDOWS\system32\drivers\lemsgt.sys
2008-06-08 13:30 . 2008-06-08 13:30 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Sega
2008-06-08 12:48 . 2008-06-08 13:10 <DIR> d-------- C:\Program Files\WinUHA
2008-06-07 23:23 . 2008-06-07 23:23 234 --a------ C:\WINDOWS\Pokemon.ini
2008-06-07 21:07 . 2008-06-10 12:27 <DIR> d-------- C:\Program Files\ChickenInvadersROTYXmas
2008-06-07 15:45 . 2008-06-07 15:45 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\URSoft
2008-06-07 14:40 . 2008-06-07 14:40 <DIR> d-------- C:\Program Files\MagicDisc
2008-06-07 14:40 . 2007-09-05 01:46 92,544 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2008-06-07 14:24 . 2008-06-07 15:24 290 --a------ C:\WINDOWS\SONIC.INI
2008-06-07 14:16 . 2008-06-07 14:16 <DIR> d-------- C:\Program Files\MagicISO
2008-06-07 13:56 . 2008-06-07 13:56 <DIR> d-------- C:\WINDOWS\Easy Rapidshare Points
2008-06-07 13:19 . 2008-06-11 13:22 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-06-06 11:55 . 2008-06-06 11:55 <DIR> d-------- C:\Program Files\Invisible Browsing
2008-06-06 11:55 . 2008-06-06 11:55 68 --a------ C:\WINDOWS\MyProg.ini
2008-06-03 18:35 . 2008-06-07 14:02 <DIR> d-------- C:\Program Files\JLC's Software
2008-06-03 18:35 . 2008-06-03 18:35 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\JLC's Software
2008-06-02 16:03 . 2008-06-02 16:03 <DIR> d-------- C:\Program Files\Vidalia Bundle
2008-06-02 16:03 . 2008-06-11 17:49 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Vidalia
2008-06-02 16:03 . 2008-06-11 18:13 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\tor
2008-06-01 22:09 . 2008-06-01 22:10 <DIR> d-------- C:\Program Files\MovieSpot
2008-05-31 22:48 . 2008-05-31 22:48 277 --a------ C:\WINDOWS\madagascar.ini
2008-05-29 15:37 . 2008-06-09 13:08 <DIR> d-------- C:\Games
2008-05-28 22:31 . 2008-05-28 22:31 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Disney Interactive Studios
2008-05-28 22:25 . 2008-05-28 22:25 <DIR> d-------- C:\Program Files\Disney Interactive Studios
2008-05-28 13:12 . 2008-05-28 13:12 <DIR> d-------- C:\WINDOWS\Sun
2008-05-23 22:23 . 2008-05-28 22:10 <DIR> d-------- C:\Program Files\Caesar III
2008-05-23 20:32 . 2008-05-24 11:48 <DIR> d-------- C:\Program Files\Star Defender 4
2008-05-23 20:24 . 2008-05-24 11:30 <DIR> d-------- C:\Program Files\Star Defender 3
2008-05-23 20:16 . 2008-05-23 20:23 <DIR> d-------- C:\Program Files\Star Defender 2
2008-05-23 19:36 . 2008-05-23 20:36 <DIR> d-------- C:\Program Files\Kennys Adventure
2008-05-23 19:34 . 2008-05-23 19:34 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-23 17:57 . 2008-06-11 08:39 <DIR> d-------- C:\Downloads
2008-05-23 17:53 . 2008-05-23 17:53 <DIR> d-------- C:\Program Files\Orbitdownloader
2008-05-23 17:53 . 2008-06-11 10:35 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Orbit
2008-05-22 23:20 . 2008-05-22 23:20 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Ashampoo
2008-05-22 22:09 . 2008-05-31 22:47 <DIR> d-------- C:\Program Files\Activision
2008-05-22 10:02 . 2008-05-22 10:02 <DIR> d-------- C:\Program Files\FDRLab
2008-05-22 10:02 . 2008-05-22 10:02 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\FDRLab
2008-05-22 09:35 . 2008-05-22 15:14 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\OpenOffice.org2
2008-05-22 09:33 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-22 09:32 . 2008-05-25 11:00 <DIR> d-------- C:\Program Files\Java
2008-05-22 09:32 . 2008-05-22 09:32 <DIR> d-------- C:\Program Files\Common Files\Java
2008-05-22 09:30 . 2008-05-22 09:30 <DIR> d-------- C:\Program Files\oo
2008-05-21 15:37 . 2008-05-22 09:57 <DIR> d-------- C:\Program Files\AbiSuite2
2008-05-21 15:37 . 2008-05-21 15:37 <DIR> d-------- C:\Documents and Settings\XPPRESP3\AbiSuite
2008-05-21 15:06 . 2008-05-21 15:06 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-05-21 15:05 . 2008-05-21 15:06 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-05-21 15:05 . 2008-05-21 15:05 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-05-21 15:00 . 2008-05-21 15:00 <DIR> dr-h----- C:\MSOCache
2008-05-12 17:19 . 2008-05-28 22:24 382 --a------ C:\WINDOWS\disneysy.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 16:34 --------- d-----w C:\Program Files\HP
2008-06-09 16:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-09 16:33 --------- d-----w C:\Program Files\Disney Interactive
2008-05-29 08:48 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\AdobeUM
2008-05-28 20:11 --------- d-----w C:\Program Files\Rockstar Games
2008-05-22 13:34 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\XnView
2008-05-10 17:08 --------- d-----w C:\Program Files\FreeGamePick.com
2008-05-08 09:07 --------- d-----w C:\Program Files\Phime
2008-05-04 13:57 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Pirates of the Atlantic
2008-05-02 11:25 --------- d-----w C:\Program Files\Internet Jamb 2005
2008-04-27 12:33 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-04-25 19:43 --------- d-----w C:\Program Files\Registry Clean Expert
2008-04-25 19:43 --------- d-----w C:\Program Files\Innovative Solutions
2008-04-25 19:42 --------- d-----w C:\Program Files\Yahoo!
2008-04-25 19:42 --------- d-----w C:\Program Files\IObit
2008-04-25 19:42 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Yahoo!
2008-04-25 19:42 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-04-23 18:41 --------- d-----w C:\Program Files\Picasa2
2008-04-22 15:23 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Image Zone Express
2008-04-20 17:56 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-04-20 17:50 --------- d-----w C:\Program Files\Phenomedia
2008-04-20 17:28 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Winamp
2008-04-20 17:26 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\OrbNetworks
2008-04-20 17:25 --------- d-----w C:\Program Files\Winamp
2008-04-20 17:19 --------- d-----w C:\Program Files\Winamp Toolbar
2008-04-20 17:19 --------- d-----w C:\Program Files\Winamp Remote
2008-04-20 17:19 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Winamp Toolbar
2008-04-20 17:11 --------- d-----w C:\Program Files\Dfx
2008-04-20 15:50 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\MusicIP
2008-04-19 09:38 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\TVU Networks
2008-04-17 19:07 --------- d-----w C:\Program Files\ESET
2008-04-13 20:06 --------- d-----w C:\Program Files\Google
2008-04-13 17:50 --------- d-----w C:\Program Files\AtomixMP3
2008-04-12 16:37 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Ahead
2008-04-12 09:36 --------- d-----w C:\Program Files\Common Files\Adobe
.
------- Sigcheck -------
2007-08-08 18:28 360704 a11391be25035570ae4b8970920f2c74 C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-29 16:33 2321792 37b69e310d2ef2cdef0a3207f7619cd7 C:\WINDOWS\system32\ntoskrnl.exe
2007-08-08 18:40 950784 396acc64ecec61d7b2f8b53151b37028 C:\WINDOWS\explorer.exe
2007-08-08 18:40 950784 396acc64ecec61d7b2f8b53151b37028 C:\WINDOWS\XPize\Backup\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-11_16.22.07.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-11 14:18:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-11 16:14:40 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-08-08 16:20:58 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-30 17:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2007-08-08 16:24:27 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
+ 2007-07-30 17:19:10 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
- 2007-08-08 16:24:27 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2007-07-30 17:19:04 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2007-08-08 16:23:50 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 17:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2007-08-08 16:23:50 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 17:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2007-08-08 16:23:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2007-08-08 16:23:55 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 17:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2007-08-08 16:23:55 33,624 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
- 2007-08-08 16:24:34 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
- 2007-08-08 16:23:55 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 17:19:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2008-03-20 00:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:00 15360]
"Vidalia"="C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe" [2007-11-22 23:49 12889088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [2006-10-05 20:56 280779]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-19 12:27 65536]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-07 20:10 949376]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 16:00 15360]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-19 00:05 630784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-08 18:24 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-04-07 23:33:44 1205840]
Privoxy.lnk - C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 16:30:54 250368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56179:TCP"= 56179:TCP:Pando P2P TCP Listening Port
"56179:UDP"= 56179:UDP:Pando P2P UDP Listening Port
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 11:22]
R1 as6eio;as6eio;C:\WINDOWS\system32\drivers\as6eio.SYS [1997-12-09 02:33]
R2 IBService;IBService;C:\Program Files\Invisible Browsing\servers\IBService.exe [2007-01-09 15:38]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 13:48]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 23:01]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 13:47]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-02-17 21:34]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2006-02-17 21:34]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2006-02-17 21:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-06-11 18:15:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\nod32krn.exe
C:\Program Files\Invisible Browsing\servers\socks\IBSocksManager.exe
C:\Program Files\Invisible Browsing\servers\socks\IBSocks.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Invisible Browsing\servers\Http\ibhttp.exe
C:\Program Files\Vidalia Bundle\Tor\tor.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-06-11 18:17:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-11 16:17:43
ComboFix2.txt 2008-06-11 14:22:57
Pre-Run: 5,900,562,432 bytes free
Post-Run: 5,894,017,024 bytes free
264
Dopuna: 11 Jun 2008 19:10
Postupak uspesan.. evo loga
ComboFix 08-06-10.5 - XPPRESP3 2008-06-11 18:54:53.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.208 [GMT 2:00]
Running from: C:\Documents and Settings\XPPRESP3\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-11 to 2008-06-11 )))))))))))))))))))))))))))))))
.
2008-06-09 18:46 . 2008-06-09 18:46 <DIR> d-------- C:\WINDOWS\$regcmp$
2008-06-08 19:50 . 2008-06-08 19:50 137,344 --a------ C:\WINDOWS\system32\drivers\hwpsgt.sys
2008-06-08 19:50 . 2008-06-08 19:50 9,472 --a------ C:\WINDOWS\system32\drivers\lemsgt.sys
2008-06-08 13:30 . 2008-06-08 13:30 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Sega
2008-06-08 12:48 . 2008-06-08 13:10 <DIR> d-------- C:\Program Files\WinUHA
2008-06-07 23:23 . 2008-06-07 23:23 234 --a------ C:\WINDOWS\Pokemon.ini
2008-06-07 21:07 . 2008-06-10 12:27 <DIR> d-------- C:\Program Files\ChickenInvadersROTYXmas
2008-06-07 15:45 . 2008-06-07 15:45 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\URSoft
2008-06-07 14:40 . 2008-06-07 14:40 <DIR> d-------- C:\Program Files\MagicDisc
2008-06-07 14:40 . 2007-09-05 01:46 92,544 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2008-06-07 14:24 . 2008-06-07 15:24 290 --a------ C:\WINDOWS\SONIC.INI
2008-06-07 14:16 . 2008-06-07 14:16 <DIR> d-------- C:\Program Files\MagicISO
2008-06-07 13:56 . 2008-06-07 13:56 <DIR> d-------- C:\WINDOWS\Easy Rapidshare Points
2008-06-07 13:19 . 2008-06-11 13:22 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-06-06 11:55 . 2008-06-06 11:55 <DIR> d-------- C:\Program Files\Invisible Browsing
2008-06-06 11:55 . 2008-06-06 11:55 68 --a------ C:\WINDOWS\MyProg.ini
2008-06-03 18:35 . 2008-06-07 14:02 <DIR> d-------- C:\Program Files\JLC's Software
2008-06-03 18:35 . 2008-06-03 18:35 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\JLC's Software
2008-06-02 16:03 . 2008-06-02 16:03 <DIR> d-------- C:\Program Files\Vidalia Bundle
2008-06-02 16:03 . 2008-06-11 18:28 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Vidalia
2008-06-02 16:03 . 2008-06-11 18:37 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\tor
2008-06-01 22:09 . 2008-06-01 22:10 <DIR> d-------- C:\Program Files\MovieSpot
2008-05-31 22:48 . 2008-05-31 22:48 277 --a------ C:\WINDOWS\madagascar.ini
2008-05-29 15:37 . 2008-06-09 13:08 <DIR> d-------- C:\Games
2008-05-28 22:31 . 2008-05-28 22:31 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Disney Interactive Studios
2008-05-28 22:25 . 2008-05-28 22:25 <DIR> d-------- C:\Program Files\Disney Interactive Studios
2008-05-28 13:12 . 2008-05-28 13:12 <DIR> d-------- C:\WINDOWS\Sun
2008-05-23 22:23 . 2008-05-28 22:10 <DIR> d-------- C:\Program Files\Caesar III
2008-05-23 20:32 . 2008-05-24 11:48 <DIR> d-------- C:\Program Files\Star Defender 4
2008-05-23 20:24 . 2008-05-24 11:30 <DIR> d-------- C:\Program Files\Star Defender 3
2008-05-23 20:16 . 2008-05-23 20:23 <DIR> d-------- C:\Program Files\Star Defender 2
2008-05-23 19:36 . 2008-05-23 20:36 <DIR> d-------- C:\Program Files\Kennys Adventure
2008-05-23 19:34 . 2008-05-23 19:34 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-23 17:57 . 2008-06-11 08:39 <DIR> d-------- C:\Downloads
2008-05-23 17:53 . 2008-05-23 17:53 <DIR> d-------- C:\Program Files\Orbitdownloader
2008-05-23 17:53 . 2008-06-11 10:35 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Orbit
2008-05-22 23:20 . 2008-05-22 23:20 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Ashampoo
2008-05-22 22:09 . 2008-05-31 22:47 <DIR> d-------- C:\Program Files\Activision
2008-05-22 10:02 . 2008-05-22 10:02 <DIR> d-------- C:\Program Files\FDRLab
2008-05-22 10:02 . 2008-05-22 10:02 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\FDRLab
2008-05-22 09:35 . 2008-05-22 15:14 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\OpenOffice.org2
2008-05-22 09:33 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-22 09:32 . 2008-05-25 11:00 <DIR> d-------- C:\Program Files\Java
2008-05-22 09:32 . 2008-05-22 09:32 <DIR> d-------- C:\Program Files\Common Files\Java
2008-05-22 09:30 . 2008-05-22 09:30 <DIR> d-------- C:\Program Files\oo
2008-05-21 15:37 . 2008-05-22 09:57 <DIR> d-------- C:\Program Files\AbiSuite2
2008-05-21 15:37 . 2008-05-21 15:37 <DIR> d-------- C:\Documents and Settings\XPPRESP3\AbiSuite
2008-05-21 15:06 . 2008-05-21 15:06 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-05-21 15:05 . 2008-05-21 15:06 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-05-21 15:05 . 2008-05-21 15:05 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-05-21 15:00 . 2008-05-21 15:00 <DIR> dr-h----- C:\MSOCache
2008-05-12 17:19 . 2008-05-28 22:24 382 --a------ C:\WINDOWS\disneysy.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 16:34 --------- d-----w C:\Program Files\HP
2008-06-09 16:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-09 16:33 --------- d-----w C:\Program Files\Disney Interactive
2008-05-29 08:48 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\AdobeUM
2008-05-28 20:11 --------- d-----w C:\Program Files\Rockstar Games
2008-05-22 13:34 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\XnView
2008-05-10 17:08 --------- d-----w C:\Program Files\FreeGamePick.com
2008-05-08 09:07 --------- d-----w C:\Program Files\Phime
2008-05-04 13:57 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Pirates of the Atlantic
2008-05-02 11:25 --------- d-----w C:\Program Files\Internet Jamb 2005
2008-04-27 12:33 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-04-25 19:43 --------- d-----w C:\Program Files\Registry Clean Expert
2008-04-25 19:43 --------- d-----w C:\Program Files\Innovative Solutions
2008-04-25 19:42 --------- d-----w C:\Program Files\Yahoo!
2008-04-25 19:42 --------- d-----w C:\Program Files\IObit
2008-04-25 19:42 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Yahoo!
2008-04-25 19:42 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-04-23 18:41 --------- d-----w C:\Program Files\Picasa2
2008-04-22 15:23 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Image Zone Express
2008-04-20 17:56 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-04-20 17:50 --------- d-----w C:\Program Files\Phenomedia
2008-04-20 17:28 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Winamp
2008-04-20 17:26 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\OrbNetworks
2008-04-20 17:25 --------- d-----w C:\Program Files\Winamp
2008-04-20 17:19 --------- d-----w C:\Program Files\Winamp Toolbar
2008-04-20 17:19 --------- d-----w C:\Program Files\Winamp Remote
2008-04-20 17:19 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Winamp Toolbar
2008-04-20 17:11 --------- d-----w C:\Program Files\Dfx
2008-04-20 15:50 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\MusicIP
2008-04-19 09:38 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\TVU Networks
2008-04-17 19:07 --------- d-----w C:\Program Files\ESET
2008-04-13 20:06 --------- d-----w C:\Program Files\Google
2008-04-13 17:50 --------- d-----w C:\Program Files\AtomixMP3
2008-04-12 16:37 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Ahead
2008-04-12 09:36 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-07 18:10 298,104 ----a-w C:\WINDOWS\system32\imon.dll
.
------- Sigcheck -------
2007-08-08 18:28 360704 a11391be25035570ae4b8970920f2c74 C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-29 16:33 2321792 37b69e310d2ef2cdef0a3207f7619cd7 C:\WINDOWS\system32\ntoskrnl.exe
2007-08-08 18:40 950784 396acc64ecec61d7b2f8b53151b37028 C:\WINDOWS\explorer.exe
2007-08-08 18:40 950784 396acc64ecec61d7b2f8b53151b37028 C:\WINDOWS\XPize\Backup\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-11_16.22.07.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-11 14:18:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-11 16:33:28 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-08-08 16:20:58 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-30 17:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2007-08-08 16:24:27 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
+ 2007-07-30 17:19:10 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
- 2007-08-08 16:24:27 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2007-07-30 17:19:04 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2007-08-08 16:23:50 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 17:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2007-08-08 16:23:50 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 17:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2007-08-08 16:23:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2007-08-08 16:23:55 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 17:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2007-08-08 16:23:55 33,624 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
- 2007-08-08 16:24:34 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
- 2007-08-08 16:23:55 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 17:19:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2008-03-20 00:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [2006-10-05 20:56 280779]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-07 20:10 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 16:00 15360]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-19 00:05 630784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-08 18:24 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-04-07 23:33:44 1205840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56179:TCP"= 56179:TCP:Pando P2P TCP Listening Port
"56179:UDP"= 56179:UDP:Pando P2P UDP Listening Port
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 11:22]
R1 as6eio;as6eio;C:\WINDOWS\system32\drivers\as6eio.SYS [1997-12-09 02:33]
R2 IBService;IBService;C:\Program Files\Invisible Browsing\servers\IBService.exe [2007-01-09 15:38]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 13:48]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 23:01]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 13:47]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-02-17 21:34]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2006-02-17 21:34]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2006-02-17 21:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-06-11 18:57:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-11 18:58:19
ComboFix-quarantined-files.txt 2008-06-11 16:58:12
ComboFix2.txt 2008-06-11 16:17:50
ComboFix3.txt 2008-06-11 14:22:57
Pre-Run: 5,818,322,944 bytes free
Post-Run: 5,810,151,424 bytes free
211
|