offline
- Aco
- Moderator foruma
- Pridružio: 12 Maj 2006
- Poruke: 16823
- Gde živiš: /home/aco
|
Evo logo dr Bora..
ComboFix 08-11-07.01 - Aco29 2008-11-08 13:42:49.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1010 [GMT 1:00]
Running from: c:\documents and settings\Aco29\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Aco29\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
c:\documents and settings\Aco29\Application Data\comrepl.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Aco29\Application Data\comrepl.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 )))))))))))))))))))))))))))))))
.
2008-11-08 13:35 . 2008-11-08 13:35 <DIR> d-------- c:\windows\LastGood
2008-11-08 13:31 . 2008-11-08 13:32 <DIR> d-------- c:\program files\direkt
2008-11-07 18:45 . 2008-11-07 18:45 <DIR> d-------- c:\program files\Uniblue
2008-11-07 11:13 . 2008-11-07 11:13 244 --ah----- C:\sqmnoopt02.sqm
2008-11-07 11:13 . 2008-11-07 11:13 232 --ah----- C:\sqmdata02.sqm
2008-11-05 15:18 . 2008-11-05 15:18 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-04 17:02 . 2008-11-04 17:02 <DIR> d-------- c:\windows\Performance
2008-11-04 17:02 . 2008-11-04 17:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Corporation
2008-11-02 20:50 . 2008-11-02 20:50 <DIR> d--h----- c:\windows\PIF
2008-11-01 17:42 . 2008-11-01 17:42 <DIR> d--hs---- c:\windows\ftpcache
2008-11-01 12:48 . 2008-11-01 12:51 <DIR> d-------- c:\program files\MP3Gain
2008-11-01 11:59 . 2008-11-07 19:06 <DIR> d-------- c:\program files\Lavalys
2008-11-01 11:39 . 2008-11-01 11:39 <DIR> d-------- c:\program files\PC Wizard 2008
2008-11-01 11:39 . 2007-09-15 16:11 27,136 --a------ c:\windows\system32\PCWizard.cpl
2008-11-01 00:46 . 2008-11-04 17:15 <DIR> d-------- c:\windows\BDOSCAN8
2008-10-31 19:23 . 2008-10-31 19:23 <DIR> d-------- c:\program files\Common Files\VCAMEye
2008-10-31 19:23 . 2005-06-20 21:27 390,912 --a------ c:\windows\system32\drivers\snpstd.sys
2008-10-31 19:23 . 2004-06-10 13:48 286,720 --a------ c:\windows\vsnpstd.exe
2008-10-31 19:23 . 2005-04-15 06:20 98,304 --a------ c:\windows\system32\rsnpstd.dll
2008-10-31 19:23 . 2004-02-16 13:59 61,440 --a------ c:\windows\system32\csnpstd.dll
2008-10-31 19:23 . 2004-05-06 11:22 53,248 --a------ c:\windows\system32\dsnpstd.dll
2008-10-31 19:23 . 2004-09-24 10:58 36,864 --a------ c:\windows\system32\vsnpstd.dll
2008-10-31 19:23 . 2005-05-30 23:09 36,864 --a------ c:\windows\system32\dsnpstd.ax
2008-10-31 19:23 . 2003-01-17 17:34 15,541 --a------ c:\windows\snpstd.ini
2008-10-31 19:23 . 2003-01-17 17:35 13,023 --a------ c:\windows\snpstd.src
2008-10-31 18:09 . 2008-10-31 18:10 <DIR> d-------- c:\program files\QuickTime
2008-10-31 18:09 . 2008-10-31 18:09 <DIR> d-------- c:\program files\Apple Software Update
2008-10-31 18:09 . 2008-10-31 22:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-31 18:09 . 2008-10-31 18:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-10-31 18:03 . 2008-10-31 18:03 0 --a------ c:\windows\mngui.INI
2008-10-31 17:54 . 2008-10-31 22:53 <DIR> d-------- c:\documents and settings\Aco29\Application Data\Teleca
2008-10-31 17:54 . 2007-04-23 15:54 108,680 -ra------ c:\windows\system32\drivers\s115mdm.sys
2008-10-31 17:54 . 2007-04-23 15:54 100,488 -ra------ c:\windows\system32\drivers\s115mgmt.sys
2008-10-31 17:54 . 2007-04-23 15:54 98,568 -ra------ c:\windows\system32\drivers\s115obex.sys
2008-10-31 17:54 . 2007-04-23 15:54 83,208 -ra------ c:\windows\system32\drivers\s115bus.sys
2008-10-31 17:54 . 2007-04-23 15:54 15,112 -ra------ c:\windows\system32\drivers\s115mdfl.sys
2008-10-31 17:54 . 2007-04-23 15:54 12,424 -ra------ c:\windows\system32\drivers\s115whnt.sys
2008-10-31 17:54 . 2007-04-23 15:54 12,424 -ra------ c:\windows\system32\drivers\s115wh.sys
2008-10-31 17:54 . 2007-04-23 15:54 12,424 -ra------ c:\windows\system32\drivers\s115cmnt.sys
2008-10-31 17:54 . 2007-04-23 15:54 12,424 -ra------ c:\windows\system32\drivers\s115cm.sys
2008-10-31 17:52 . 2008-10-31 22:53 <DIR> d-------- c:\program files\Common Files\Teleca Shared
2008-10-31 17:52 . 2008-10-31 17:52 <DIR> d-------- c:\documents and settings\Aco29\Application Data\Sony Ericsson
2008-10-31 17:51 . 2008-10-31 22:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Teleca
2008-10-31 17:51 . 2008-10-31 22:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-10-30 19:22 . 2008-10-30 19:22 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-10-30 18:15 . 2008-10-30 18:15 <DIR> d-------- c:\documents and settings\Aco29\Application Data\Lavasoft
2008-10-30 18:08 . 2008-11-06 00:30 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-10-30 17:51 . 2008-10-31 22:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-30 17:50 . 2008-10-31 22:44 <DIR> d-------- c:\program files\Lavasoft
2008-10-30 17:49 . 2008-10-30 17:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Prevx
2008-10-30 17:26 . 2008-10-30 17:26 <DIR> d-------- c:\windows\system32\GroupPolicy
2008-10-30 17:26 . 2004-03-09 00:00 1,081,616 --a------ c:\windows\system32\MSCOMCTL.OCX
2008-10-29 19:10 . 2008-10-29 19:12 90 --a------ c:\windows\ae_mini.INI
2008-10-29 19:07 . 2008-10-29 19:07 399 --a------ c:\windows\asr.INI
2008-10-29 19:04 . 2008-10-29 19:04 <DIR> d-------- c:\program files\Common Files\Adobe
2008-10-29 19:00 . 2008-10-29 19:05 <DIR> d-------- c:\documents and settings\Aco29\dwhelper
2008-10-29 18:49 . 2008-10-29 18:49 <DIR> d-------- c:\windows\Sun
2008-10-28 00:40 . 2008-10-28 00:40 355,584 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-10-28 00:40 . 2008-05-29 09:28 28,416 --a------ c:\windows\system32\uxtuneup.dll
2008-10-27 23:38 . 2008-10-27 23:55 2,211,894 --a------ c:\windows\ACD Wallpaper.bmp
2008-10-27 21:20 . 2008-10-27 21:20 <DIR> d-------- c:\documents and settings\Aco29\Application Data\dvdcss
2008-10-27 20:07 . 2008-11-06 22:10 <DIR> d-------- c:\program files\eMule
2008-10-27 19:24 . 2008-10-28 16:05 <DIR> d-------- c:\documents and settings\Aco29\Application Data\skypePM
2008-10-27 19:24 . 2008-10-27 19:24 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-10-27 17:18 . 2008-10-27 17:18 <DIR> d-------- c:\documents and settings\Aco29\Application Data\CyberLink
2008-10-27 14:54 . 2008-10-27 14:54 <DIR> d-------- c:\program files\VSO
2008-10-27 14:54 . 2008-10-27 21:12 <DIR> d-------- c:\documents and settings\Aco29\Application Data\Vso
2008-10-27 14:54 . 2004-05-04 12:53 1,645,320 --a------ c:\windows\gdiplus.dll
2008-10-27 14:54 . 2006-05-20 17:16 1,184,984 --a------ c:\windows\system32\wvc1dmod.dll
2008-10-27 14:54 . 2006-05-11 20:21 626,688 --a------ c:\windows\system32\vp7vfw.dll
2008-10-27 14:54 . 2006-09-29 13:24 217,127 --a------ c:\windows\system32\drv43260.dll
2008-10-27 14:54 . 2006-09-29 13:25 208,935 --a------ c:\windows\system32\drv33260.dll
2008-10-27 14:54 . 2006-09-29 13:26 176,165 --a------ c:\windows\system32\drv23260.dll
2008-10-27 14:54 . 2007-03-18 21:37 65,602 --a------ c:\windows\system32\cook3260.dll
2008-10-27 14:54 . 2008-10-27 14:54 47,360 --a------ c:\documents and settings\Aco29\Application Data\pcouffin.sys
2008-10-26 10:01 . 2008-10-26 10:20 <DIR> d-------- c:\program files\Readon Technology
2008-10-25 13:12 . 2008-04-13 23:15 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2008-10-25 13:12 . 2008-04-13 23:15 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-10-25 11:51 . 2008-10-25 12:46 <DIR> d-------- c:\program files\Webteh
2008-10-24 18:57 . 2007-07-30 18:19 271,224 --a------ c:\windows\system32\mucltui.dll
2008-10-24 18:57 . 2007-07-30 18:19 207,736 --a------ c:\windows\system32\muweb.dll
2008-10-24 18:57 . 2007-07-30 18:19 30,072 --a------ c:\windows\system32\mucltui.dll.mui
2008-10-24 18:29 . 2008-10-24 18:29 <DIR> d-------- c:\documents and settings\Aco29\Application Data\vlc
2008-10-24 16:23 . 2008-04-13 23:15 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-10-24 10:54 . 2008-10-24 11:01 <DIR> d-------- c:\program files\Windows Live
2008-10-24 10:54 . 2008-10-24 10:56 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-10-24 10:53 . 2008-10-24 10:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-24 10:50 . 2008-10-24 10:50 <DIR> d-------- c:\documents and settings\Aco29\Contacts
2008-10-24 10:47 . 2008-10-22 15:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-24 10:20 . 2008-10-24 10:20 <DIR> d-------- c:\documents and settings\Aco29\Application Data\Uniblue
2008-10-24 10:18 . 2008-10-24 10:16 737,280 --a------ c:\windows\iun6002.exe
2008-10-24 10:17 . 2008-10-24 10:18 <DIR> d-------- c:\program files\Codec Pack - All In 1
2008-10-24 10:12 . 2008-10-24 10:12 <DIR> d-------- c:\program files\VS Revo Group
2008-10-24 09:10 . 2008-10-24 09:10 <DIR> d-------- c:\program files\FLV Player
2008-10-24 08:38 . 2008-10-24 08:38 <DIR> d-------- c:\program files\Unlocker
2008-10-24 08:35 . 2008-10-24 08:35 <DIR> d-------- c:\program files\Real
2008-10-24 08:35 . 2008-10-24 08:35 <DIR> d-------- c:\program files\Common Files\xing shared
2008-10-24 08:35 . 2008-10-24 08:35 <DIR> d-------- c:\program files\Common Files\Real
2008-10-24 08:35 . 2008-10-24 08:35 499,712 --a------ c:\windows\system32\msvcp71.dll
2008-10-24 08:10 . 2008-10-25 10:20 <DIR> d-------- c:\documents and settings\Aco29\Application Data\ACD Systems
2008-10-24 00:01 . 2008-10-24 00:23 <DIR> d-------- c:\windows\NV38202988.TMP
2008-10-24 00:01 . 2008-09-17 22:55 201,050 --a------ c:\windows\system32\nvapps.nvb
2008-10-23 22:40 . 2008-10-23 22:40 <DIR> d--hs---- c:\documents and settings\Aco29\UserData
2008-10-23 22:21 . 2008-10-28 23:35 <DIR> d-------- c:\documents and settings\Aco29\Application Data\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-08 11:22 196,608 ----a-w c:\windows\system32\drivers\nAsmedia.bin
2008-11-06 16:08 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-01 16:51 196,608 ----a-w c:\windows\system32\drivers\nStandard.bin
2008-10-31 18:06 --------- d-----w c:\program files\TuneUp Utilities 2008
2008-10-31 17:21 --------- d-----w c:\program files\IObit
2008-10-29 19:17 --------- d-----w c:\program files\ESET
2008-10-29 19:17 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-10-29 19:16 --------- d-----w c:\program files\Ashampoo
2008-10-27 13:54 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-10-27 09:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-24 09:48 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-24 09:18 --------- d-----w c:\program files\Mv2Player
2008-10-24 07:35 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-10-23 22:28 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-23 21:23 --------- d-----w c:\program files\Picasa2
2008-10-23 21:23 --------- d-----w c:\program files\Google
2008-10-23 21:21 --------- d-----w c:\program files\Skype
2008-10-23 21:21 --------- d-----w c:\program files\NetMeter
2008-10-23 21:21 --------- d-----w c:\program files\Common Files\Skype
2008-10-23 21:20 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-23 21:19 --------- d-----w c:\program files\Java
2008-10-23 21:19 --------- d-----w c:\program files\EASEUS
2008-10-23 21:19 --------- d-----w c:\program files\Common Files\Java
2008-10-23 21:17 --------- d-----w c:\program files\VideoLAN
2008-10-23 21:10 --------- d-----w c:\program files\TechSmith
2008-10-23 21:07 --------- d-----w c:\program files\Reference Assemblies
2008-10-23 21:07 --------- d-----w c:\program files\MSBuild
2008-10-23 20:59 --------- d-----w c:\program files\Video Convert Master
2008-10-23 20:59 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-23 20:59 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-10-23 20:59 --------- d-----w c:\documents and settings\Aco29\Application Data\TuneUp Software
2008-10-23 20:58 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-23 20:58 --------- d-----w c:\program files\ASUSTeK
2008-10-23 20:57 --------- d-----w c:\program files\AC3Filter
2008-10-23 20:54 --------- d-----w c:\program files\Common Files\ACD Systems
2008-10-23 20:54 --------- d-----w c:\program files\ACD Systems
2008-10-23 20:54 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2008-10-23 20:53 --------- d-----w c:\documents and settings\Aco29\Application Data\Winamp
2008-10-23 20:51 --------- d-----w c:\program files\Winamp
2008-10-23 20:48 --------- d-----w c:\program files\CDex_140b9
2008-10-23 20:48 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-10-23 20:44 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-23 20:44 --------- d-----w c:\documents and settings\Aco29\Application Data\Malwarebytes
2008-10-23 20:43 --------- d-----w c:\documents and settings\Aco29\Application Data\Ashampoo
2008-10-23 20:42 --------- d-----w c:\documents and settings\All Users\Application Data\ashampoo
2008-10-23 20:41 21,419 ----a-w c:\windows\system32\drivers\AegisP.sys
2008-10-23 20:41 --------- d-----w c:\program files\OVISLINK
2008-10-23 20:41 --------- d-----w c:\documents and settings\Aco29\Application Data\InstallShield
2008-10-23 20:38 --------- d-----w c:\program files\ASUS
2008-10-23 20:35 12,288 ----a-w c:\windows\system32\drivers\EIO64_xp.sys
2008-10-23 20:33 --------- d-----w c:\program files\My Company Name
2008-10-23 20:28 315,392 ----a-w c:\windows\HideWin.exe
2008-10-23 20:28 --------- d-----w c:\program files\Realtek
2008-10-23 20:26 --------- d-----w c:\program files\VIA
2008-10-23 20:20 --------- d-----w c:\program files\microsoft frontpage
2008-10-22 14:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-10 03:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
2008-09-20 07:16 170,496 ----a-w c:\windows\system32\BootMan.exe
2008-09-19 18:42 86,408 ----a-w c:\windows\system32\setupempdrv03.exe
2008-09-19 18:42 8,704 ----a-w c:\windows\system32\epmntdrv.sys
2008-09-19 18:42 3,072 ----a-w c:\windows\system32\EuGdiDrv.sys
2008-09-19 18:42 14,848 ----a-w c:\windows\system32\EuEpmGdi.dll
2008-09-19 16:10 86,016 ----a-w c:\windows\system32\ResizeNTFS.dll
2008-09-19 16:10 61,952 ----a-w c:\windows\system32\FatResizeMove.dll
2008-09-19 16:10 472,576 ----a-w c:\windows\system32\NTFSFormat.dll
2008-09-19 16:10 22,016 ----a-w c:\windows\system32\FatFormat.dll
2008-09-19 16:09 92,672 ----a-w c:\windows\system32\Partition.dll
2008-09-19 16:09 31,744 ----a-w c:\windows\system32\FatLib.dll
2008-09-19 16:09 179,200 ----a-w c:\windows\system32\DeviceManager.dll
2008-09-19 16:09 124,416 ----a-w c:\windows\system32\NTFSCopy.dll
2008-09-19 16:08 86,528 ----a-w c:\windows\system32\NTFSLib.dll
2008-09-19 16:08 68,096 ----a-w c:\windows\system32\Device.dll
2008-09-19 16:08 6,144 ----a-w c:\windows\system32\CallbackOperator.dll
2008-09-19 16:08 44,032 ----a-w c:\windows\system32\FileSystemCheck.dll
2008-09-19 16:08 25,088 ----a-w c:\windows\system32\FATFileSystemAnalyser.dll
2008-09-19 16:08 24,576 ----a-w c:\windows\system32\NTFSFileSystemAnalyser.dll
2008-09-19 16:08 21,504 ----a-w c:\windows\system32\Fixup.dll
2008-09-19 16:08 14,848 ----a-w c:\windows\system32\FileSystemAnalyser.dll
2008-09-19 16:08 10,752 ----a-w c:\windows\system32\DeviceAdapter.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-14 10:11 2,189,184 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ----a-w c:\windows\system32\ntkrnlpa.exe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\program files\My Company Name ----
((((((((((((((((((((((((((((( snapshot@2008-11-07_19.56.52.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-01 09:06:24 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-11-08 12:32:39 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-11-01 09:06:24 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-11-08 12:32:39 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-11-01 09:06:24 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-11-08 12:32:39 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-11-01 09:06:22 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:37 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:22 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:37 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:37 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:37 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:38 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:38 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:38 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:38 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:23 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:38 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:24 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 12:32:39 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-11-01 09:06:24 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-11-08 12:32:39 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-11-01 09:06:25 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-11-08 12:32:39 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-11-01 09:06:25 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-11-08 12:32:39 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-11-01 09:06:25 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-11-08 12:32:39 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-11-01 09:06:24 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-11-08 12:32:39 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-05-30 13:17:40 97,288 ----a-w c:\windows\LastGood\system32\directx\websetup\dsetup.dll
+ 2008-05-30 13:17:38 1,694,728 ----a-w c:\windows\LastGood\system32\directx\websetup\dsetup32.dll
+ 2007-03-12 15:42:30 1,123,696 ----a-w c:\windows\system32\D3DCompiler_33.dll
+ 2007-05-16 15:45:16 1,124,720 ----a-w c:\windows\system32\D3DCompiler_34.dll
+ 2007-07-19 17:14:42 1,358,192 ----a-w c:\windows\system32\D3DCompiler_35.dll
+ 2007-10-12 14:14:00 1,374,232 ----a-w c:\windows\system32\D3DCompiler_36.dll
+ 2008-03-05 14:56:58 1,420,824 ----a-w c:\windows\system32\D3DCompiler_37.dll
+ 2008-05-30 13:11:46 1,491,992 ----a-w c:\windows\system32\D3DCompiler_38.dll
+ 2008-07-10 10:00:58 1,493,528 ----a-w c:\windows\system32\D3DCompiler_39.dll
+ 2007-03-15 15:57:58 443,752 ----a-w c:\windows\system32\d3dx10_33.dll
+ 2007-05-16 15:45:16 443,752 ----a-w c:\windows\system32\d3dx10_34.dll
+ 2007-07-19 17:14:42 444,776 ----a-w c:\windows\system32\d3dx10_35.dll
+ 2007-10-02 08:56:34 444,776 ----a-w c:\windows\system32\d3dx10_36.dll
+ 2008-02-05 22:07:36 462,864 ----a-w c:\windows\system32\d3dx10_37.dll
+ 2008-05-30 13:11:46 467,984 ----a-w c:\windows\system32\d3dx10_38.dll
+ 2008-07-10 10:01:00 467,984 ----a-w c:\windows\system32\d3dx10_39.dll
+ 2006-09-28 15:05:20 2,414,360 ----a-w c:\windows\system32\d3dx9_31.dll
+ 2006-11-29 12:06:18 3,426,072 ----a-w c:\windows\system32\d3dx9_32.dll
+ 2007-03-12 15:42:30 3,495,784 ----a-w c:\windows\system32\d3dx9_33.dll
+ 2007-05-16 15:45:16 3,497,832 ----a-w c:\windows\system32\d3dx9_34.dll
+ 2007-07-19 17:14:42 3,727,720 ----a-w c:\windows\system32\d3dx9_35.dll
+ 2007-10-12 14:14:00 3,734,536 ----a-w c:\windows\system32\d3dx9_36.dll
+ 2008-03-05 14:56:58 3,786,760 ----a-w c:\windows\system32\D3DX9_37.dll
+ 2008-05-30 13:11:46 3,850,760 ----a-w c:\windows\system32\D3DX9_38.dll
+ 2008-07-10 10:00:58 3,851,784 ----a-w c:\windows\system32\D3DX9_39.dll
+ 2007-03-05 11:42:18 15,128 ----a-w c:\windows\system32\x3daudio1_1.dll
+ 2007-10-22 02:37:16 17,928 ----a-w c:\windows\system32\X3DAudio1_2.dll
+ 2008-03-05 15:00:06 25,608 ----a-w c:\windows\system32\X3DAudio1_3.dll
+ 2008-05-30 13:17:00 25,608 ----a-w c:\windows\system32\X3DAudio1_4.dll
+ 2007-10-22 02:39:54 267,272 ----a-w c:\windows\system32\xactengine2_10.dll
- 2006-07-28 07:30:32 236,824 ----a-w c:\windows\system32\xactengine2_3.dll
+ 2006-07-28 08:30:32 236,824 ----a-w c:\windows\system32\xactengine2_3.dll
+ 2006-09-28 15:05:56 237,848 ----a-w c:\windows\system32\xactengine2_4.dll
+ 2006-12-08 11:02:00 251,672 ----a-w c:\windows\system32\xactengine2_5.dll
+ 2007-01-24 14:27:30 255,848 ----a-w c:\windows\system32\xactengine2_6.dll
+ 2007-04-04 17:55:00 261,480 ----a-w c:\windows\system32\xactengine2_7.dll
+ 2007-06-20 19:46:04 266,088 ----a-w c:\windows\system32\xactengine2_8.dll
+ 2007-07-19 23:57:12 267,112 ----a-w c:\windows\system32\xactengine2_9.dll
+ 2008-03-05 15:03:20 238,088 ----a-w c:\windows\system32\xactengine3_0.dll
+ 2008-05-30 13:18:52 238,088 ----a-w c:\windows\system32\xactengine3_1.dll
+ 2008-07-30 05:20:54 238,088 ----a-w c:\windows\system32\xactengine3_2.dll
+ 2008-05-30 13:17:30 65,032 ----a-w c:\windows\system32\XAPOFX1_0.dll
+ 2008-07-30 05:20:56 68,616 ----a-w c:\windows\system32\XAPOFX1_1.dll
+ 2008-03-05 15:03:54 479,752 ----a-w c:\windows\system32\XAudio2_0.dll
+ 2008-05-30 13:19:18 507,400 ----a-w c:\windows\system32\XAudio2_1.dll
+ 2008-07-30 05:20:56 509,448 ----a-w c:\windows\system32\XAudio2_2.dll
- 2006-07-28 07:30:14 62,744 ----a-w c:\windows\system32\xinput1_2.dll
+ 2006-07-28 08:30:14 62,744 ----a-w c:\windows\system32\xinput1_2.dll
+ 2007-04-04 17:53:42 81,768 ----a-w c:\windows\system32\xinput1_3.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"c:\program files\NetMeter\NetMeter.exe"="c:\program files\NetMeter\NetMeter.exe" [2007-08-11 331264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-24 185872]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AirLive 802.11G Wireless Utility.lnk - c:\program files\OVISLINK\Common\AirliveUI.exe [2008-10-23 1290240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ASUS SmartDoctor"=c:\program files\ASUS\SmartDoctor\SmartDoctor.exe /start
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ASUSGamerOSD"=c:\program files\ASUS\GamerOSD\GamerOSD.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"RemoteControl"="c:\program files\ASUSTeK\ASUSDVD\PDVDServ.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"snpstd"=c:\windows\vsnpstd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 ViBus;ViBus;c:\windows\system32\DRIVERS\ViBus.sys [2007-03-26 16896]
R0 videX32;videX32;c:\windows\system32\DRIVERS\videX32.sys [2007-03-29 9216]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\DRIVERS\ViPrt.sys [2007-03-26 52224]
R1 EIO_XP;EIO_XP;c:\windows\system32\drivers\EIO_XP.sys [2006-06-14 12288]
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe [2008-04-14 14336]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;c:\windows\system32\drivers\asusgsb.sys [2007-10-23 12416]
R3 Video3D;ASUS Video3D Service;c:\windows\system32\Drivers\Video3D32.sys [2007-10-23 10752]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2008-09-19 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2008-09-19 3072]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;c:\windows\system32\DRIVERS\fetnd5bv.sys [2007-02-27 42496]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-10-28 355584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2008-11-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:09]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 13:45:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-08 13:45:33
ComboFix-quarantined-files.txt 2008-11-08 12:45:30
ComboFix2.txt 2008-11-08 00:51:33
ComboFix3.txt 2008-11-07 18:57:20
Pre-Run: 45,134,987,264 bytes free
Post-Run: 45,137,432,576 bytes free
397 --- E O F --- 2008-11-05 14:18:43
|