offline
- ][v][ A T R I X™
- Legendarni građanin
- Pridružio: 28 Apr 2005
- Poruke: 3686
- Gde živiš: The Circle
|
ComboFix 08-09-13.02 - AMDx64 2008-09-13 20:11:48.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.874.1.1033.18.583 [GMT 2:00]
Running from: D:\Documents and Settings\AMDx64\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-13 to 2008-09-13 )))))))))))))))))))))))))))))))
.
2008-09-05 20:24 . 2008-09-05 20:24 <DIR> d-------- D:\Program Files\Bonjour
2008-09-03 03:32 . 2008-09-03 03:32 <DIR> d-------- D:\Program Files\HooTech
2008-09-03 03:32 . 2008-09-03 03:32 <DIR> d-------- D:\Documents and Settings\AMDx64\Application Data\HTNetMeter
2008-09-02 15:27 . 2008-09-02 15:27 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\espionServerData
2008-08-31 00:22 . 2008-08-31 00:22 55,904 --a------ D:\WINDOWS\FontData.fdb
2008-08-31 00:19 . 2008-08-31 00:21 3,140 --ahs---- D:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
2008-08-31 00:19 . 2008-08-31 00:19 8 -r-hs---- D:\Documents and Settings\All Users\Application Data\A9B75ECCB9.sys
2008-08-31 00:18 . 2008-08-31 00:19 <DIR> d-------- D:\Documents and Settings\AMDx64\Application Data\Corel
2008-08-31 00:15 . 2008-08-31 00:15 <DIR> d-------- D:\Program Files\Common Files\Protexis
2008-08-31 00:15 . 2008-08-31 00:15 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Corel
2008-08-31 00:13 . 2008-08-31 00:13 <DIR> d-------- D:\Program Files\Common Files\Corel
2008-08-28 14:53 . 2008-09-10 07:45 <DIR> d-------- D:\Documents and Settings\AMDx64\Application Data\gtk-2.0
2008-08-28 14:53 . 2008-08-28 14:53 <DIR> d-------- D:\Documents and Settings\AMDx64\.thumbnails
2008-08-28 14:48 . 2008-09-10 08:49 <DIR> d-------- D:\Documents and Settings\AMDx64\.gimp-2.4
2008-08-28 14:47 . 2008-08-28 14:48 <DIR> d-------- D:\Program Files\GIMP-2.0
2008-08-26 22:49 . 2008-09-11 03:07 <DIR> d-a------ D:\Documents and Settings\All Users\Application Data\TEMP
2008-08-26 12:06 . 2008-08-26 12:06 <DIR> d-------- D:\Documents and Settings\AMDx64\Application Data\VoipBuster
2008-08-26 12:05 . 2008-08-26 12:05 <DIR> d-------- D:\Program Files\VoipBuster.com
2008-08-24 23:20 . 2008-06-24 18:43 74,240 --------- D:\WINDOWS\system32\dllcache\mscms.dll
2008-08-24 23:19 . 2008-07-07 22:26 253,952 --------- D:\WINDOWS\system32\dllcache\es.dll
2008-08-24 23:16 . 2008-05-01 16:33 331,776 --------- D:\WINDOWS\system32\dllcache\msadce.dll
2008-08-24 23:15 . 2008-04-11 21:04 691,712 --------- D:\WINDOWS\system32\dllcache\inetcomm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 17:12 --------- d-----w D:\Program Files\WinFlip
2008-09-13 17:12 --------- d-----w D:\Program Files\ViStart
2008-09-13 17:12 --------- d-----w D:\Program Files\Drive Space Indicator
2008-09-12 17:20 --------- d-----w D:\Program Files\WallCooler
2008-09-11 18:29 --------- d-----w D:\Program Files\Ahead
2008-09-11 17:38 --------- d-----w D:\Documents and Settings\AMDx64\Application Data\OpenOffice.org2
2008-09-10 03:48 --------- d-----w D:\Documents and Settings\AMDx64\Application Data\Skype
2008-09-10 03:36 --------- d-----w D:\Documents and Settings\AMDx64\Application Data\skypePM
2008-09-10 01:05 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-07 15:02 --------- d-----w D:\Program Files\Java
2008-09-05 18:24 --------- d-----w D:\Program Files\Common Files\Adobe
2008-09-04 02:00 --------- d-----w D:\Program Files\Spybot - Search & Destroy
2008-09-03 15:52 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-24 21:57 --------- d-----w D:\Program Files\Microsoft Silverlight
2008-08-10 03:43 --------- d-----w D:\Program Files\Webserver Stress Tool 7
2008-08-06 22:08 --------- d-----w D:\Program Files\Lexmark_HostCD
2008-08-06 22:08 --------- d-----w D:\Program Files\Lexmark
2008-07-29 05:01 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-07-29 05:01 --------- d-----w D:\Program Files\hotkey
2008-07-29 05:01 --------- d-----w D:\Program Files\Common Files\InstallShield
2008-07-27 01:15 --------- d-----w D:\Documents and Settings\AMDx64\Application Data\.purple
2008-07-26 02:17 --------- d-----w D:\Program Files\Mozilla Thunderbird
2008-07-26 01:48 --------- d-----w D:\Documents and Settings\All Users\Application Data\pdf995
2008-07-18 20:10 94,920 ----a-w D:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w D:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w D:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w D:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w D:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w D:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w D:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w D:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w D:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w D:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w D:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w D:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w D:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w D:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w D:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w D:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w D:\WINDOWS\system32\muweb.dll
2008-07-17 02:02 --------- d-----w D:\Documents and Settings\AMDx64\Application Data\TeamViewer
2008-07-16 19:46 --------- d-----w D:\Program Files\Pidgin
2008-07-16 04:57 9,464 ------w D:\WINDOWS\system32\drivers\cdralw2k.sys
2008-07-16 04:57 9,336 ------w D:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-07-16 04:57 43,528 ------w D:\WINDOWS\system32\drivers\PxHelp20.sys
2008-07-16 04:57 129,784 ------w D:\WINDOWS\system32\pxafs.dll
2008-07-16 04:57 118,520 ------w D:\WINDOWS\system32\pxinsi64.exe
2008-07-16 04:57 116,472 ------w D:\WINDOWS\system32\pxcpyi64.exe
2008-07-15 21:37 --------- d-----w D:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-15 21:11 --------- d-----w D:\Program Files\MUP RS
2008-07-15 02:46 --------- d-----w D:\Program Files\Common Files\Macrovision Shared
2008-07-07 20:26 253,952 ----a-w D:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w D:\WINDOWS\system32\mscms.dll
2008-06-24 16:12 295,936 ----a-w D:\WINDOWS\system32\wmpeffects.dll
2008-06-24 08:57 3,592,192 ------w D:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w D:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w D:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w D:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w D:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46 245,248 ----a-w D:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w D:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w D:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w D:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w D:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w D:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 11:05 272,128 ------w D:\WINDOWS\system32\dllcache\bthport.sys
2008-02-27 10:42 32 ----a-w D:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-05-24 02:15 32,768 --sha-w D:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052420080525\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ViStart"="D:\Program Files\ViStart\ViStart" [X]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"VisualTaskTips"="D:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe" [2007-08-15 36352]
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Sidebar"="D:\Program Files\Windows Sidebar\sidebar.exe" [2007-08-29 1232384]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"VoipBuster"="D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" [2008-01-17 8811824]
"MSMSGS"="D:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"NetMeter"="D:\Program Files\HooTech\NetMeter\HooNetMeter.exe" [2008-06-17 569344]
"Google Update"="D:\Documents and Settings\AMDx64\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WINFLIP"="D:\Program Files\WinFlip\WinFlip.exe" [2007-11-02 462848]
"UnlockerAssistant"="D:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"DriveSpace"="D:\Program Files\Drive Space Indicator\DrvSpace.exe" [2007-11-10 247949]
"LClock"="D:\Program Files\LClock\LClock.exe" [2004-09-19 65536]
"tsnpstd3"="D:\WINDOWS\tsnpstd3.exe" [2007-03-30 262144]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"GrooveMonitor"="D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"avgnt"="D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"UpdReg"="D:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"Jet Detection"="D:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"EPoXUSDM"="D:\Program Files\EPoX\USDM\USDM.EXE" [2004-01-05 1016320]
"WallCooler"="D:\Program Files\WallCooler\WallCoolerConsole.exe" [2008-06-20 328192]
"Adobe Photo Downloader"="D:\Program Files\Adobe\Photoshop Elements 6ins\apdproxy.exe" [2007-09-11 67488]
"snpstd3"="D:\WINDOWS\vsnpstd3.exe" [2006-09-18 843776]
"HotKey"="D:\Program Files\HotKey\hotkey.exe" [2006-11-03 81920]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 D:\WINDOWS\system32\CTHELPER.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ViStart"="D:\Program Files\ViStart\ViStart" [X]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
"Sidebar"="D:\Program Files\Windows Sidebar\sidebar.exe" [2007-08-29 1232384]
"VisualTaskTips"="D:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe" [2007-08-15 36352]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-06-23 D:\WINDOWS\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Psi\\psi.exe"=
"D:\\Program Files\\BORGChat\\BORGChat.exe"=
"D:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"D:\\Program Files\\map&guide\\map&guide base\\bin\\MGBase.exe"=
"D:\\Program Files\\WallCooler\\WallCoolerService.exe"=
"D:\\Program Files\\WallCooler\\WallCoolerConsole.exe"=
"D:\\Documents and Settings\\AMDx64\\temp\\TeamViewer3\\TeamViewer.exe"=
"J:\\BEA\\jrockit_150_11\\bin\\javaw.exe"=
"J:\\BEA\\jdk150_11\\jre\\bin\\javaw.exe"=
"J:\\BEA\\jrockit_150_11\\bin\\java.exe"=
"D:\\WINDOWS\\system32\\LMabcoms.exe"=
"J:\\server\\xampplite\\apache\\bin\\apache.exe"=
"J:\\server\\xampplite\\mysql\\bin\\mysqld.exe"=
"D:\\Documents and Settings\\AMDx64\\Desktop\\UsbWebserver_en\\UsbWebserver\\Apache\\bin\\httpd_usb.exe"=
"D:\\Documents and Settings\\AMDx64\\Desktop\\UsbWebserver_en\\UsbWebserver\\Mysql\\bin\\mysqld-nt_usb.exe"=
"D:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"D:\\Documents and Settings\\AMDx64\\Desktop\\Thunder\\FlashFXP.v3.6.0.1240.(zabranjeno)ed-NoPE\\FlashFXP.v3.6.0.1240.(zabranjeno)ed-NoPE\\NoPE\\FlashFXP.exe"=
"D:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\WINDOWS\\system32\\ftp.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;D:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2006-02-26 16640]
R1 VBoxDrv;VirtualBox Service;D:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2008-04-30 55424]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;D:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2008-04-30 42048]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;D:\Program Files\Adobe\Photoshop Elements 6ins\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 PSI_SVC_2;Protexis Licensing V2;D:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 WallCoolerService;WallCoolerService;D:\Program Files\WallCooler\WallCoolerService.exe [2008-06-20 187904]
R3 NPF;NetGroup Packet Filter Driver;D:\WINDOWS\system32\drivers\npf.sys [2007-06-29 42512]
S2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [ ]
S3 2WIREPCP;2Wire USB;D:\WINDOWS\system32\DRIVERS\2WirePCP.sys [2002-09-23 68672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
Notify-WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - D:\Documents and Settings\AMDx64\Application Data\Mozilla\Firefox\Profiles\ok6pvv0v.default\
FF -: plugin - D:\Documents and Settings\AMDx64\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-13 20:14:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
Completion time: 2008-09-13 20:15:32
ComboFix-quarantined-files.txt 2008-09-13 18:15:25
ComboFix2.txt 2008-06-30 23:47:31
Pre-Run: 372,666,368 bytes free
Post-Run: 655,183,872 bytes free
238 --- E O F --- 2008-09-12 01:01:10
|