ComboFix 08-05-01.3 - Semenka 2008-05-07 23:41:21.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.36 [GMT 2:00]
Running from: C:\Documents and Settings\Semenka\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-04-07 to 2008-05-07 )))))))))))))))))))))))))))))))
.
2021-04-18 22:01 . 2007-07-22 13:05 <DIR> d-------- C:\Program Files\Eset
2021-04-18 22:01 . 2021-04-18 22:00 245,760 --a------ C:\WINDOWS\system32\imon.dll
2021-04-18 22:01 . 2021-04-18 22:00 114,688 --a------ C:\WINDOWS\system32\nms32.dll
2008-05-03 18:09 . 2008-05-03 18:09 <DIR> d-------- C:\WINDOWS\system32\WebsmartzBackup
2008-05-03 18:08 . 2008-05-03 18:12 <DIR> d-------- C:\Program Files\Websmartz 2.2
2008-05-03 18:08 . 1996-11-08 02:48 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2008-05-03 18:08 . 2007-10-03 10:49 45,056 --a------ C:\WINDOWS\system32\ExecuteUtilities.exe
2008-05-03 18:08 . 2007-10-03 10:49 29,184 --a------ C:\WINDOWS\system32\MSINET.oca
2008-05-03 18:08 . 2007-10-03 10:49 24,576 --a------ C:\WINDOWS\system32\ProjectIcon.exe
2008-05-03 18:08 . 2007-09-18 11:08 20,480 --a------ C:\WINDOWS\system32\ExtWzz.exe
2008-05-03 18:08 . 2007-10-03 10:49 24 --a------ C:\WINDOWS\WebSmartzServer.cfg
2008-05-03 18:08 . 2007-10-03 10:49 11 --a------ C:\WINDOWS\WebSmartz.cfg
2008-04-27 10:49 . 2008-04-27 10:50 4 --a------ C:\WINDOWS\INI2=No
2008-04-27 10:49 . 2008-04-27 10:50 4 --a------ C:\WINDOWS\INI1=No
2008-04-22 10:14 . 2008-04-22 10:14 241 --a------ C:\WINDOWS\hpqcopy.INI
2008-04-21 17:36 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-04-21 17:36 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-04-07 19:04 . 2008-04-07 19:25 <DIR> d-------- C:\Program Files\Babylon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2021-04-18 20:00 300,048 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-05-07 21:50 --------- d-----w C:\Documents and Settings\Semenka\Application Data\Skype
2008-05-07 21:29 --------- d-----w C:\Documents and Settings\Semenka\Application Data\skypePM
2008-05-03 15:54 131,584 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-04-19 21:04 --------- d-----w C:\Program Files\FlashGet
2008-04-06 15:33 304,160 ----a-w C:\StiImg.dat
2008-03-27 18:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-27 17:58 --------- d-----w C:\Program Files\Common Files\Hypnotizer
2008-03-23 12:44 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-23 12:44 --------- d-----w C:\Program Files\Common Files\Real
2008-03-23 12:43 --------- d-----w C:\Program Files\Real
2008-03-16 16:53 --------- d-----w C:\Program Files\Puzzle 48er
2008-03-08 17:43 --------- d-----w C:\Program Files\DivX
2008-03-08 14:20 --------- d-----w C:\Program Files\Java
2008-02-08 17:46 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-23 14:34 20 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-09-10 23:03 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2007-04-19 23:28 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-04-18 19:54 56 --sh--r C:\WINDOWS\system32\FB1B3CBE4A.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 12:57 94208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-13 23:16 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"Gadwin PrintScreen 3.5"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2006-07-08 10:57 1101824]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 18:22 21898024]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:07 15360]
"Avi Player"="C:\Program Files\Avi Player\AviPlayer.exe" [ ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-11 12:06 3144800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2021-04-18 22:00 847872]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2004-10-22 00:41 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-18 21:55 77824]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-11 12:06 3144800]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-23 14:43 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 03:07 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-04-18 21:27:36 113664]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2007-07-29 15:59:34 118784]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-18 21:55 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a------ 2002-04-17 10:42 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 18:22 21898024 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\totalcmd\\TOTALCMD.EXE"=
"C:\\Program Files\\JAlbum7.1\\JAlbumWin.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 PAC207;VideoCAM GE111;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-08 10:46]
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-05-07 23:52:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 3
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\PAStiSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2008-05-08 0:05:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-07 22:04:43
ComboFix2.txt 2008-03-23 21:17:25
Pre-Run: 3,485,626,368 bytes free
Post-Run: 3,462,402,048 bytes free
160
Dopuna: 08 Maj 2008 16:46
Da li je sve OK?
|