offline
- Source
- Legendarni građanin
- Pridružio: 10 Jan 2005
- Poruke: 3319
- Gde živiš: Stara Pazova
|
ComboFix 08-05-01.3 - Fireslasher 2008-05-06 17:49:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.509 [GMT 2:00]
Running from: C:\Documents and Settings\Fireslasher\Desktop\New Folder\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.
2008-05-06 13:03 . 2008-05-06 13:04 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-06 13:03 . 2008-05-06 16:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-05 22:31 . 2008-05-05 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-05 22:24 . 2008-05-05 22:24 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-05 11:37 . 2008-05-05 11:37 <DIR> d-------- C:\Program Files\Electronic Arts
2008-05-05 11:37 . 1999-04-02 16:37 33,792 -ra------ C:\WINDOWS\NPSExec.exe
2008-05-05 11:37 . 2008-05-05 11:37 495 --a------ C:\WINDOWS\eReg.dat
2008-05-04 20:11 . 2008-05-04 20:11 <DIR> d-------- C:\Documents and Settings\Fireslasher\Application Data\FDRLab
2008-05-04 18:19 . 2008-05-04 18:19 <DIR> d-------- C:\Games
2008-05-04 18:09 . 2008-05-04 18:09 <DIR> d-------- C:\Documents and Settings\Fireslasher\Application Data\DAEMON Tools Pro
2008-05-04 18:08 . 2008-05-04 18:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-05-04 18:07 . 2008-05-04 18:11 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2008-05-04 18:04 . 2008-05-04 18:04 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-05-03 15:57 . 2002-05-27 13:37 1,953,792 --------- C:\WINDOWS\system32\pcldll6l.dll
2008-05-03 15:57 . 2002-05-27 13:37 233,525 --------- C:\WINDOWS\system32\isutil.dll
2008-05-03 15:57 . 2002-05-27 13:37 90,112 --------- C:\WINDOWS\apptune.exe
2008-05-03 15:57 . 2002-05-27 13:37 36,864 --------- C:\WINDOWS\system32\zpppcl.dll
2008-05-03 15:57 . 2002-05-27 13:37 271 --------- C:\WINDOWS\apptune.ini
2008-05-03 15:56 . 2008-05-03 15:57 <DIR> d-------- C:\Program Files\hp LaserJet 1000
2008-05-03 15:56 . 2002-05-27 13:37 151,552 --------- C:\WINDOWS\system32\SDhp1000.DLL
2008-05-03 15:56 . 2002-05-27 13:37 45,056 --------- C:\WINDOWS\system32\zpp.dll
2008-05-03 15:56 . 2008-05-03 15:56 32,768 --a------ C:\WINDOWS\closewnd.exe
2008-05-02 17:11 . 2008-05-05 18:50 <DIR> d-------- C:\Program Files\Gigatron Konfygurator
2008-05-02 14:36 . 2008-05-02 17:05 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-05-02 14:10 . 2008-05-02 14:35 <DIR> d-------- C:\Program Files\uTorrent
2008-05-02 14:10 . 2008-05-04 16:30 <DIR> d-------- C:\Documents and Settings\Fireslasher\Application Data\uTorrent
2008-05-01 18:47 . 2008-05-03 17:36 647 --a------ C:\WINDOWS\settings.cfg
2008-05-01 18:16 . 2008-05-01 18:19 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-05-01 15:12 . 2008-05-01 15:12 35,358 --a------ C:\logo1.png
2008-05-01 14:56 . 2008-05-01 14:56 <DIR> d-------- C:\logo
2008-05-01 14:55 . 2008-05-01 14:55 124,303 --a------ C:\logo...psd
2008-05-01 14:54 . 2008-05-01 14:55 <DIR> d-------- C:\images
2008-05-01 14:44 . 2008-05-01 14:44 31,566 --a------ C:\logo...gif
2008-05-01 14:38 . 2008-03-30 11:20 169 --a------ C:\scanline.gif
2008-05-01 14:26 . 2008-05-01 14:26 <DIR> d-------- C:\Program Files\IrfanView
2008-04-30 12:49 . 2008-04-30 12:49 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Xfire
2008-04-30 11:51 . 2008-04-30 11:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-30 00:09 . 2008-04-14 05:40 102,912 -----c--- C:\WINDOWS\system32\dllcache\dpcdll.dll
2008-04-30 00:09 . 2008-04-14 05:42 10,752 --------- C:\WINDOWS\system32\smtpapi.dll
2008-04-30 00:09 . 2008-04-14 05:42 9,728 --------- C:\WINDOWS\system32\rwnh.dll
2008-04-30 00:08 . 2008-04-30 00:08 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-04-30 00:08 . 2008-04-14 05:42 380,416 --a------ C:\WINDOWS\system32\irprops.cpl
2008-04-30 00:02 . 2008-04-13 22:06 144,384 --------- C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-04-30 00:01 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\000001_.tmp
2008-04-29 23:42 . 2008-04-29 17:40 331,805,736 --a------ C:\windowsxp-kb936929-sp3-x86-enu_c81472f7eeea2eca421e116cd4c03e2300ebfde4.exe
2008-04-29 19:18 . 2008-04-29 19:18 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-04-28 23:34 . 2008-05-05 21:45 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-28 01:20 . 2008-04-28 01:24 <DIR> d-------- C:\Documents and Settings\Fireslasher\Application Data\Ahead
2008-04-28 01:17 . 2008-04-28 01:17 <DIR> d-------- C:\Program Files\Nero
2008-04-28 01:17 . 2008-04-28 01:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-04-28 01:15 . 2008-04-28 01:20 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-04-27 20:19 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-27 20:19 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-04-27 20:19 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-27 19:40 . 2008-05-02 18:28 <DIR> d-------- C:\Program Files\Xfire
2008-04-27 19:40 . 2008-05-06 17:25 <DIR> d-------- C:\Documents and Settings\Fireslasher\Application Data\Xfire
2008-04-27 15:04 . 2008-04-27 15:04 <DIR> d-------- C:\Program Files\ffdshow
2008-04-27 15:04 . 2008-04-21 15:00 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-04-27 15:04 . 2008-04-21 15:00 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-04-27 15:04 . 2008-04-21 15:00 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll
2008-04-27 15:04 . 2008-04-21 15:00 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-04-27 15:04 . 2008-04-21 15:00 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-04-27 14:59 . 2008-04-27 14:59 <DIR> d-------- C:\Documents and Settings\Fireslasher\Application Data\Media Player Classic
2008-04-27 14:40 . 2008-04-27 14:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-04-27 14:39 . 2008-04-27 14:39 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-04-27 14:25 . 2008-04-27 14:43 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-04-27 11:33 . 2006-10-26 19:58 30,512 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-27 11:32 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-04-27 11:30 . 2008-04-27 11:30 <DIR> d-------- C:\Program Files\Microsoft Works
2008-04-27 11:29 . 2008-04-27 11:29 <DIR> d-------- C:\Program Files\MSBuild
2008-04-27 11:19 . 2008-04-27 11:28 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-27 11:17 . 2008-04-28 01:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-27 11:16 . 2008-04-27 11:16 <DIR> dr-h----- C:\MSOCache
2008-04-27 11:13 . 2008-04-27 11:13 <DIR> d-------- C:\Program Files\Real Alternative
2008-04-27 11:13 . 2008-04-27 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-27 11:13 . 2006-05-04 17:35 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-04-27 11:13 . 2006-05-04 17:35 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-04-27 11:12 . 2008-04-27 11:13 <DIR> d-------- C:\Program Files\QuickTime Alternative
2008-04-27 11:12 . 2008-04-27 11:12 <DIR> d-------- C:\Program Files\Media Player Classic
2008-04-27 01:42 . 2008-04-27 01:42 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-04-27 01:42 . 2008-05-06 09:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-27 01:42 . 2008-05-06 17:56 13,074,464 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-27 01:42 . 2008-05-06 17:55 210,464 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-27 01:42 . 2008-05-06 00:37 178,892 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-27 01:42 . 2008-04-27 01:55 96,645 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-04-27 01:42 . 2008-04-27 01:55 87,941 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-04-27 01:42 . 2008-05-06 00:37 23,384 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-27 01:24 . 2008-04-27 01:24 <DIR> d-------- C:\Program Files\Lanmisoft
2008-04-27 01:18 . 2008-04-27 01:18 <DIR> d-------- C:\Program Files\MSECache
2008-04-27 00:57 . 2008-04-27 00:57 <DIR> d-------- C:\Program Files\MSN BackUp
2008-04-27 00:43 . 2008-04-27 00:43 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-27 00:43 . 2008-04-27 00:43 <DIR> d-------- C:\Documents and Settings\Fireslasher\Contacts
2008-04-27 00:34 . 2008-04-27 00:42 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-27 00:33 . 2008-04-27 00:43 <DIR> d-------- C:\Program Files\Windows Live
2008-04-27 00:33 . 2008-04-27 00:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-27 00:21 . 2008-04-27 00:21 <DIR> d-------- C:\WINDOWS\system32\en
2008-04-27 00:21 . 2008-04-30 00:08 <DIR> d-------- C:\WINDOWS\system32\bits
2008-04-27 00:21 . 2008-04-27 00:21 <DIR> d-------- C:\WINDOWS\l2schemas
2008-04-27 00:19 . 2008-04-27 00:19 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-04-27 00:18 . 2008-04-14 05:42 294,912 -----c--- C:\WINDOWS\system32\dllcache\dlimport.exe
2008-04-27 00:14 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\002874_.tmp
2008-04-27 00:05 . 2008-04-14 00:17 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-27 00:05 . 2001-08-17 15:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-04-27 00:04 . 2007-12-05 01:41 7,435,392 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-27 00:04 . 2007-12-05 01:41 7,435,392 --a--c--- C:\WINDOWS\system32\dllcache\nv4_mini.sys
2008-04-27 00:04 . 2007-12-05 01:41 5,773,568 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-04-27 00:04 . 2008-04-14 00:10 57,600 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-04-27 00:03 . 2008-04-14 05:42 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2008-04-27 00:03 . 2008-04-14 00:06 44,672 --a------ C:\WINDOWS\system32\drivers\uagp35.sys
2008-04-27 00:03 . 2004-08-04 00:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2008-04-27 00:03 . 2008-04-14 00:15 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2008-04-27 00:01 . 2008-04-27 14:43 <DIR> dr------- C:\Documents and Settings\All Users\Documents
2008-04-27 00:00 . 2008-05-06 09:57 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-04-27 00:00 . 2008-04-30 00:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2008-04-27 00:00 . 2008-04-26 22:24 <DIR> d--h----- C:\Documents and Settings\Default User
2008-04-27 00:00 . 2008-04-26 22:17 <DIR> d-------- C:\Documents and Settings\All Users
2008-04-27 00:00 . 2008-04-26 22:24 <DIR> d-------- C:\Documents and Settings
2008-04-23 00:29 . 2008-04-23 00:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-04-14 05:39 . 2008-04-14 05:39 24,064 -----c--- C:\WINDOWS\system32\dllcache\pidgen.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 18:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-04 16:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-26 21:34 --------- d-----w C:\Program Files\AIMP2
2008-04-26 21:25 --------- d-----w C:\Program Files\Opera
2008-04-26 20:40 --------- d-----w C:\Program Files\A4Tech
2008-04-26 20:34 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-04-26 20:34 --------- d-----w C:\Program Files\AvRack
2008-04-26 20:32 --------- d-----w C:\Program Files\Gigabyte
2008-04-26 20:19 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-14 03:55 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 03:46 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 03:43 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 03:43 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 03:43 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 03:43 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 03:43 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 03:43 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 03:43 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 03:43 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 03:41 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 03:40 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 03:40 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 03:40 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 03:40 102,912 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 23:00 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 22:58 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 22:57 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 22:51 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 22:50 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 22:50 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 22:50 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 22:49 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 22:49 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 22:49 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 22:49 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 22:49 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 22:48 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 22:47 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 22:47 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 22:47 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 22:46 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 22:46 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 22:45 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 22:45 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 22:45 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 22:45 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 22:44 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 22:44 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 22:30 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 22:30 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 22:30 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 22:27 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 22:27 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 22:27 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 22:27 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 22:27 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 22:27 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 22:27 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 22:26 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 22:26 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 22:26 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 22:26 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 22:26 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 22:26 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 22:26 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 22:26 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 22:26 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 22:26 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 22:25 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 22:24 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 22:23 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 22:23 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 22:23 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 22:23 264,832 ----a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 22:21 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 22:21 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 22:21 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 22:21 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 22:21 101,120 ----a-w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 22:16 59,136 ----a-w C:\WINDOWS\system32\drivers\rfcomm.sys
2008-04-13 22:16 37,888 ------w C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-13 22:16 36,480 ------w C:\WINDOWS\system32\drivers\bthprint.sys
2008-04-13 22:16 273,024 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 22:16 25,600 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 22:16 25,344 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2008-04-13 22:16 18,944 ----a-w C:\WINDOWS\system32\drivers\bthusb.sys
2008-04-13 22:16 17,024 ----a-w C:\WINDOWS\system32\drivers\bthenum.sys
2008-04-13 22:16 121,984 ------w C:\WINDOWS\system32\drivers\usbvideo.sys
2008-04-13 22:14 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 22:14 799,744 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 22:14 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 22:14 153,344 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 22:13 9,728 ------w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 22:13 14,208 ------w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 22:13 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 22:13 12,672 ------w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 22:11 52,352 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 22:11 42,112 ----a-w C:\WINDOWS\system32\drivers\imapi.sys
2008-04-13 22:09 92,544 ----a-w C:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 22:09 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-01-08 20:54 65536 C:\WINDOWS\SOUNDMAN.EXE]
"iKeyWorks"="C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe" [2006-09-07 17:21 65536]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 05:42 110592 C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51 218376]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 05:42 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 n558;N558 Bluetooth USB Filter Driver;C:\WINDOWS\system32\Drivers\n558.sys [2007-08-15 07:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aced0cb2-15db-11dd-8c58-000c76486739}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 17:56:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-06 17:58:34
ComboFix-quarantined-files.txt 2008-05-06 15:58:19
Pre-Run: 18,332,434,432 bytes free
Post-Run: 18,403,725,312 bytes free
294 --- E O F --- 2008-04-27 23:33:17
|