offline
- l00ney
- Novi MyCity građanin
- Pridružio: 26 Jan 2008
- Poruke: 6
|
ComboFix 08-10-30.13 - fim1 2008-10-31 21:23:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.135 [GMT 1:00]
Running from: C:\Documents and Settings\fim1\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\fim1\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\msmsn.exe
C:\WINDOWS\system32\msudf.exe
.
/wow section - STAGE 41
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127\SearchSettings.dll
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\WINDOWS\system32\msmsn.exe
C:\WINDOWS\system32\msudf.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSMSNKD
-------\Service_msmsnkd
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.
2008-10-31 17:26 . 2008-10-31 17:26 <DIR> d-------- C:\Program Files\AVG
2008-10-31 17:26 . 2008-10-31 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-31 17:03 . 2008-10-31 17:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-02 22:52 . 2008-10-02 22:52 <DIR> d-------- C:\Program Files\Real
2008-10-02 22:52 . 2008-10-02 22:52 <DIR> d-------- C:\Program Files\PeerWeb DC++
2008-10-02 22:46 . 2008-10-02 22:46 <DIR> d-------- C:\Program Files\MP4Tool
2008-10-02 22:46 . 2008-10-02 22:46 <DIR> d-------- C:\Program Files\Audio Mid Recorder
2008-10-02 22:46 . 2008-10-02 22:46 <DIR> d-------- C:\Program Files\Any Audio Converter
2008-10-02 22:42 . 2008-10-02 22:42 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-10-02 22:42 . 2008-10-02 22:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-26 23:00 . 2008-09-26 23:00 <DIR> d-------- C:\Documents and Settings\fim1\.borland
2008-09-26 20:39 . 2008-09-26 20:39 1,129,472 --a------ C:\WINDOWS\system32\vclAbsDbd7.bpl
2008-09-22 22:20 . 2008-10-26 21:24 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-22 22:20 . 2008-09-22 22:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-14 11:23 . 2008-09-14 11:23 <DIR> d-------- C:\Program Files\%temp&
2008-09-13 23:33 . 2008-09-13 23:33 <DIR> d-------- C:\Program Files\GSpot
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 20:18 --------- d-----w C:\Documents and Settings\fim1\Application Data\MegauploadToolbar
2008-10-31 15:53 --------- d-----w C:\Documents and Settings\fim1\Application Data\Skype
2008-10-31 15:46 --------- d-----w C:\Documents and Settings\fim1\Application Data\skypePM
2008-10-31 14:50 --------- d-----w C:\Program Files\ESET
2008-10-31 14:47 --------- d-----w C:\Documents and Settings\fim1\Application Data\uTorrent
2008-10-31 13:47 1,820,672 ----a-w C:\WINDOWS\Internet Logs\xDB253.tmp
2008-10-31 13:45 3,279,872 ----a-w C:\WINDOWS\Internet Logs\xDB252.tmp
2008-10-27 18:21 --------- d-----w C:\Documents and Settings\fim1\Application Data\TransRender
2008-10-26 19:46 3,171,840 ----a-w C:\WINDOWS\Internet Logs\xDB250.tmp
2008-10-26 19:46 1,699,328 ----a-w C:\WINDOWS\Internet Logs\xDB251.tmp
2008-10-19 14:38 1,595,904 ----a-w C:\WINDOWS\Internet Logs\xDB24F.tmp
2008-10-19 14:20 3,137,536 ----a-w C:\WINDOWS\Internet Logs\xDB24E.tmp
2008-10-12 20:55 3,140,096 ----a-w C:\WINDOWS\Internet Logs\xDB24D.tmp
2008-10-10 11:00 2,667,520 ----a-w C:\WINDOWS\Internet Logs\xDB24C.tmp
2008-10-10 10:59 3,131,392 ----a-w C:\WINDOWS\Internet Logs\xDB24B.tmp
2008-10-02 21:44 45,056 ----a-w C:\WINDOWS\Internet Logs\xDB24A.tmp
2008-10-02 21:44 3,124,224 ----a-w C:\WINDOWS\Internet Logs\xDB249.tmp
2008-10-02 21:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-02 21:28 --------- d-----w C:\Program Files\AudioConvert
2008-10-02 12:56 696,832 ----a-w C:\WINDOWS\Internet Logs\xDB248.tmp
2008-10-02 12:56 3,122,688 ----a-w C:\WINDOWS\Internet Logs\xDB247.tmp
2008-09-30 10:52 --------- d-----w C:\Program Files\Winamp
2008-09-27 09:15 225,280 ----a-w C:\WINDOWS\Internet Logs\xDB246.tmp
2008-09-27 09:14 3,223,552 ----a-w C:\WINDOWS\Internet Logs\xDB245.tmp
2008-09-26 21:46 --------- d-----w C:\Program Files\TP
2008-09-26 13:50 7,392,332 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-09-26 13:49 3,119,616 ----a-w C:\WINDOWS\Internet Logs\xDB243.tmp
2008-09-26 13:49 2,663,424 ----a-w C:\WINDOWS\Internet Logs\xDB244.tmp
2008-09-20 14:10 3,116,032 ----a-w C:\WINDOWS\Internet Logs\xDB241.tmp
2008-09-20 14:10 1,232,384 ----a-w C:\WINDOWS\Internet Logs\xDB242.tmp
2008-09-16 17:12 44,032 ----a-w C:\WINDOWS\Internet Logs\xDB240.tmp
2008-09-16 17:10 3,104,768 ----a-w C:\WINDOWS\Internet Logs\xDB23F.tmp
2008-09-16 12:08 651,776 ----a-w C:\WINDOWS\Internet Logs\xDB23E.tmp
2008-09-16 11:59 3,105,280 ----a-w C:\WINDOWS\Internet Logs\xDB23D.tmp
2008-09-12 11:56 3,104,768 ----a-w C:\WINDOWS\Internet Logs\xDB23B.tmp
2008-09-12 11:56 18,944 ----a-w C:\WINDOWS\Internet Logs\xDB23C.tmp
2008-09-12 11:48 429,056 ----a-w C:\WINDOWS\Internet Logs\xDB23A.tmp
2008-09-12 11:48 3,104,768 ----a-w C:\WINDOWS\Internet Logs\xDB239.tmp
2008-09-10 07:27 3,100,160 ----a-w C:\WINDOWS\Internet Logs\xDB237.tmp
2008-09-10 07:27 1,137,152 ----a-w C:\WINDOWS\Internet Logs\xDB238.tmp
2008-09-08 14:45 844,288 ----a-w C:\WINDOWS\Internet Logs\xDB236.tmp
2008-09-08 14:45 3,095,552 ----a-w C:\WINDOWS\Internet Logs\xDB235.tmp
2008-09-04 10:54 594,432 ----a-w C:\WINDOWS\Internet Logs\xDB234.tmp
2008-09-04 10:52 3,091,456 ----a-w C:\WINDOWS\Internet Logs\xDB233.tmp
2008-09-02 12:04 1,456,640 ----a-w C:\WINDOWS\Internet Logs\xDB232.tmp
2008-09-02 12:00 3,096,064 ----a-w C:\WINDOWS\Internet Logs\xDB231.tmp
2008-08-31 13:04 231,720 ----a-w C:\mediamp3.dat
2008-07-30 21:49 444,416 ----a-w C:\WINDOWS\Internet Logs\xDB230.tmp
2008-07-30 21:49 3,096,576 ----a-w C:\WINDOWS\Internet Logs\xDB22F.tmp
2008-07-29 21:33 3,082 ----a-w C:\WINDOWS\system32\affv11300p4now.sys
2008-07-29 18:24 95,232 ----a-w C:\WINDOWS\Internet Logs\xDB22E.tmp
2008-07-29 18:24 3,080,704 ----a-w C:\WINDOWS\Internet Logs\xDB22D.tmp
2008-07-18 07:42 506,368 ----a-w C:\WINDOWS\Internet Logs\xDB22C.tmp
2008-07-18 07:42 3,078,656 ----a-w C:\WINDOWS\Internet Logs\xDB22B.tmp
2008-07-14 19:55 3,078,144 ----a-w C:\WINDOWS\Internet Logs\xDB229.tmp
2008-07-14 19:55 263,168 ----a-w C:\WINDOWS\Internet Logs\xDB22A.tmp
2008-07-13 07:35 360,448 ----a-w C:\WINDOWS\Internet Logs\xDB228.tmp
2008-07-13 07:35 3,078,144 ----a-w C:\WINDOWS\Internet Logs\xDB227.tmp
2008-07-10 15:45 3,076,608 ----a-w C:\WINDOWS\Internet Logs\xDB225.tmp
2008-07-10 15:45 1,323,008 ----a-w C:\WINDOWS\Internet Logs\xDB226.tmp
2007-04-19 17:13 56 --sh--r C:\WINDOWS\system32\7DB451F885.sys
2008-04-11 15:14 1,838 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-10-31_18.36.56,32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MemoryWasher"="C:\Program Files\Memory Washer\MemoryWasher.exe" [2008-03-19 2088960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-06-10 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-28 98304]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-07 185896]
"RemoteControl8"="C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-04-03 65588]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2007-11-28 151552]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2007-11-28 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Miroslav\\programi\\utorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Nemanja\\Manager\\fm.exe"=
"D:\\pes 2008\\PES2008.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WebSTARNdis;WebSTAR DPX USB Cable Modem Adapter;C:\WINDOWS\system32\DRIVERS\WebSTAR.sys [2001-12-17 15417]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea800f53-3b82-11dd-9bf2-001a4d761a5c}]
\Shell\Auto\command - H:\Autorun.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Autorun.exe
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-10-31 21:25:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-31 21:32:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-31 20:31:39
ComboFix2.txt 2008-10-31 17:38:12
Pre-Run: 2.885.287.936 bytes free
Post-Run: 2,821,599,232 bytes free
190 --- E O F --- 2007-10-10 07:41:57
|