offline
- Evil Ghost
- Ugledni građanin
- Pridružio: 15 Feb 2007
- Poruke: 443
|
ComboFix 07-11-19.4C - Dejan 2007-11-28 16:20:56.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.202 [GMT 1:00]
Running from: E:\P R O G R A M I\Nenarezani programi\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\bsnzafqa.bin
C:\WINDOWS\system32\cfg.dat
.
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-28 )))))))))))))))))))))))))))))))
.
2007-11-28 13:35 <DIR> d-------- C:\Program Files\Reši ovo
2007-11-27 02:14 <DIR> d-------- C:\Program Files\Windows Live
2007-11-27 02:14 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-27 02:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-26 16:53 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winzm.ime
2007-11-26 16:53 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winsp.ime
2007-11-26 16:53 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winpy.ime
2007-11-26 16:53 79,360 --a--c--- C:\WINDOWS\system32\dllcache\winar30.ime
2007-11-26 16:53 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2007-11-26 16:53 65,536 --a--c--- C:\WINDOWS\system32\dllcache\winime.ime
2007-11-26 16:53 41,600 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.dll
2007-11-26 16:53 31,232 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.sys
2007-11-26 16:53 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2007-11-26 16:52 15,872 --a--c--- C:\WINDOWS\system32\dllcache\padrs404.dll
2007-11-26 16:52 7,680 --a--c--- C:\WINDOWS\system32\dllcache\kbdnecnt.dll
2007-11-26 16:51 66,082 --a--c--- C:\WINDOWS\system32\dllcache\c_20290.nls
2007-11-26 16:51 54,528 --a--c--- C:\WINDOWS\system32\dllcache\cap7146.sys
2007-11-26 16:51 24,632 --a--c--- C:\WINDOWS\system32\dllcache\fpadmcgi.exe
2007-11-26 16:51 20,541 --a--c--- C:\WINDOWS\system32\dllcache\fpadmdll.dll
2007-11-26 16:50 275,968 --a--c--- C:\WINDOWS\system32\dllcache\certwiz.ocx
2007-11-26 16:50 189,440 --a--c--- C:\WINDOWS\system32\dllcache\smtpadm.dll
2007-11-26 16:50 188,494 --a--c--- C:\WINDOWS\system32\dllcache\fpcount.exe
2007-11-26 16:50 188,480 --a--c--- C:\WINDOWS\system32\dllcache\cfgwiz.exe
2007-11-26 16:50 94,720 --a--c--- C:\WINDOWS\system32\dllcache\certmap.ocx
2007-11-26 16:50 76,800 --a--c--- C:\WINDOWS\system32\dllcache\logui.ocx
2007-11-26 16:50 76,288 --a--c--- C:\WINDOWS\system32\dllcache\cnfgprts.ocx
2007-11-26 16:50 68,608 --a--c--- C:\WINDOWS\system32\dllcache\iisext51.dll
2007-11-26 16:50 45,056 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_aqadmin.dll
2007-11-26 16:50 20,536 --a--c--- C:\WINDOWS\system32\dllcache\shtml.dll
2007-11-26 16:50 16,437 --a--c--- C:\WINDOWS\system32\dllcache\shtml.exe
2007-11-26 16:50 7,168 --a--c--- C:\WINDOWS\system32\dllcache\wamregps.dll
2007-11-26 16:50 5,632 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
2007-11-26 16:49 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2007-11-26 16:40 1,042,903 --a--c--- C:\WINDOWS\system32\dllcache\SP2.CAT
2007-11-26 16:40 31,281 --a--c--- C:\WINDOWS\system32\dllcache\FP4.CAT
2007-11-26 16:40 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2007-11-26 16:40 13,753 --a--c--- C:\WINDOWS\system32\dllcache\IMS.CAT
2007-11-26 16:40 13,472 --a--c--- C:\WINDOWS\system32\dllcache\HPCRDP.CAT
2007-11-26 16:40 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-11-26 16:40 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2007-11-26 16:40 9,581 --a--c--- C:\WINDOWS\system32\dllcache\MSMSGS.CAT
2007-11-26 10:00 <DIR> d-------- C:\Program Files\CryptLoad - Download Manager
2007-11-25 14:12 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\Winamp
2007-11-24 16:22 155,648 --a------ C:\WINDOWS\system32\adadix32.dll
2007-11-24 16:22 127,456 --a------ C:\WINDOWS\system32\IPDETECT.EXE
2007-11-24 16:22 46,892 --a------ C:\WINDOWS\system32\ADADIX16.DLL
2007-11-24 16:22 32,768 --a------ C:\WINDOWS\adiras.exe
2007-11-24 16:22 4,981 --a------ C:\WINDOWS\system32\ADADIX2K.DLL
2007-11-24 02:22 44,544 --a------ C:\WINDOWS\AWuninstall.exe
2007-11-23 11:31 147,456 --a------ C:\WINDOWS\AVUNTOOL.EXE
2007-11-18 20:36 7,334 --a--c--- C:\WINDOWS\system32\dllcache\wmerrenu.cat
2007-11-18 18:27 <DIR> d-------- C:\Program Files\Nero
2007-11-18 18:27 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-11-17 16:51 <DIR> d-------- C:\Program Files\LightWave 3D 9.2
2007-11-17 16:51 1,219,950 --a------ C:\WINDOWS\LightWave 3D 9.2 Uninstaller.exe
2007-11-17 12:34 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\Thinstall
2007-11-16 21:02 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-11-16 21:01 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-11-14 16:48 <DIR> d-------- C:\Program Files\MSECache
2007-11-12 18:58 <DIR> d-------- C:\Program Files\MakeHuman
2007-11-12 12:00 <DIR> d-------- C:\Program Files\QuickTime
2007-11-12 11:59 <DIR> d-------- C:\Program Files\Apple Software Update
2007-11-12 11:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-12 11:44 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\Poser 7
2007-11-12 11:42 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-11-12 11:20 <DIR> d-------- C:\Program Files\Poser 7
2007-11-11 01:43 <DIR> d-------- C:\Program Files\MSN Messenger
2007-11-07 16:21 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\ESET
2007-11-07 02:34 <DIR> dr------- C:\FlexLM
2007-11-07 02:18 <DIR> d-------- C:\Program Files\Common Files\Alias Shared
2007-11-07 02:18 <DIR> d-------- C:\Program Files\Autodesk
2007-11-06 12:36 <DIR> d-------- C:\Program Files\InfinaDyne
2007-11-06 01:01 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\InfinaDyne
2007-11-06 00:58 <DIR> d-------- C:\Program Files\Shared
2007-11-05 23:29 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\Imagenomic
2007-11-05 23:17 <DIR> d-------- C:\Program Files\Imagenomic
2007-11-05 23:07 <DIR> d-------- C:\Program Files\Bonjour
2007-11-05 14:39 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-11-05 14:26 <DIR> d-------- C:\Program Files\WinXP Manager
2007-11-04 18:06 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\Ahead
2007-11-03 19:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2007-10-30 08:32 87,040 --a------ C:\WINDOWS\UnGins.exe
2007-10-29 19:26 <DIR> d-------- C:\Program Files\Folderico
2007-10-29 19:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
2007-10-29 19:20 <DIR> d-------- C:\Program Files\Gom Player
2007-10-29 19:20 <DIR> d-------- C:\Documents and Settings\korisnik\Application Data\GRETECH
2007-10-28 23:47 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-10-28 21:11 <DIR> d-------- C:\Program Files\Screamer Radio
2007-10-28 14:40 <DIR> d-------- C:\WINDOWS\system32\RNBOSENT
2007-10-28 14:40 20,032 -ra------ C:\WINDOWS\system32\drivers\SNTNLUSB.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-28 03:16 --------- d-----w C:\Documents and Settings\korisnik\Application Data\POP Peeper
2007-11-28 01:25 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-26 17:55 --------- d-----w C:\Program Files\Tutorials
2007-11-25 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-25 13:17 --------- d-----w C:\Program Files\Winamp
2007-11-24 15:25 26 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2007-11-24 15:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-24 15:10 --------- d-----w C:\Program Files\Bluetooth
2007-11-18 15:17 85 --sh--w C:\Program Files\desktop.ini
2007-11-18 15:17 15,086 --sha-w C:\Program Files\ShedkoFolderico3_0627.ico
2007-11-18 13:46 --------- d-----w C:\Program Files\POP Peeper
2007-11-13 20:14 --------- d-----w C:\Program Files\Microsoft
2007-11-07 21:47 --------- d-----w C:\Program Files\Opera
2007-11-05 22:07 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-05 13:56 --------- d-----w C:\Program Files\YuRecnik
2007-11-05 13:56 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-05 13:56 --------- d-----w C:\Program Files\Lexmark_HostCD
2007-10-28 13:41 47,616 ----a-w C:\WINDOWS\system32\drivers\Haspnt.sys
2007-10-27 19:35 --------- d-----w C:\Program Files\Java
2007-10-25 08:27 53,768 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-10-25 08:27 50,696 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2007-10-25 08:27 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2007-10-25 08:25 33,800 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-10-25 08:25 27,144 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-10-22 13:07 --------- d-----w C:\Program Files\Corel
2007-10-22 13:06 --------- d-----w C:\Documents and Settings\korisnik\Application Data\Corel
2007-10-22 12:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Corel
2007-10-21 13:01 --------- d-----w C:\Program Files\MSBuild
2007-10-21 03:41 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-21 03:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-21 03:39 --------- d-----w C:\Program Files\Common Files\Protexis
2007-10-21 03:29 --------- d--h--w C:\Program Files\Give4Free Plugin
2007-10-17 20:46 --------- d-----w C:\Program Files\Common Files\WhenU
2007-10-17 20:35 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-15 13:59 --------- d-----w C:\Program Files\MP3, WAV, WMA, OGG Converter
2007-10-14 02:51 --------- d-----w C:\Program Files\Common Files\Download Manager
2007-10-01 12:43 --------- d-----w C:\Program Files\CCleaner
2007-10-01 10:03 --------- d-----w C:\Program Files\Boilsoft MOV Converter - QuickTime(.mov, .qt), 3GP, mp4 to avi, mpeg, vcd, dvd, wmv
2007-09-29 19:44 --------- d-----w C:\Documents and Settings\korisnik\Application Data\ACD Systems
2007-09-29 18:36 --------- d-----w C:\Program Files\Common Files\ACD Systems
2007-09-29 18:36 --------- d-----w C:\Program Files\ACD Systems
2007-09-10 07:43 2,380,800 ----a-w C:\WINDOWS\SaveTo.exe
2007-09-03 18:32 47,360 ----a-w C:\Documents and Settings\korisnik\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"POP Peeper"="C:\Program Files\POP Peeper\POPPeeper.exe" [2006-11-16 05:02]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 15:15]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-10-25 09:26]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 10:09 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\ASUS USB ADSL Modem\ASUS USB ADSL Modem\dslmon.exe [2007-11-24 16:22:21]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2007-08-03 19:03:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogOff"= 1
"NoRecentDocsMenu"= 1
"NoToolbarCustomize"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^korisnik^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-02-07 15:21 54832 --a------ C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-02-07 15:24 71216 --a------ C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-25 00:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys
R1 epfwtdi;epfwtdi;C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\C:\Program Files\CyberLink\PowerDVD\000.fcl
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys
R2 ekrn;Eset Service;"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"
R2 epfw;epfw;C:\WINDOWS\system32\DRIVERS\epfw.sys
R3 Epfwndis;Eset Personal Firewall;C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
S3 EhttpSrv;Eset HTTP Server;"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"C:\Program Files\MSN Messenger\usnsvc.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7ae3923-8dfc-11dc-b5ef-4d6564696130}]
\Shell\Auto\command - activexdebugger32.exe f
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f
\Shell\explore\Command - activexdebugger32.exe f
\Shell\open\Command - activexdebugger32.exe f
.
Contents of the 'Scheduled Tasks' folder
"2007-11-12 10:59:47 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-28 16:29:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-28 16:32:12
.
--- E O F ---
|