offline
- Pridružio: 25 Okt 2006
- Poruke: 276
|
ComboFix 08-08-26.02 - Administrator 2008-08-28 7:06:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.477 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Program Files\KB27888.exe
C:\Program Files\KB51942.exe
C:\WINDOWS\winxml2a.dll
C:\WINDOWS\wxml56164.dll
C:\WINDOWS\wxmlua.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\KB27888.exe
C:\Program Files\KB51942.exe
C:\WINDOWS\winxml2a.dll
C:\WINDOWS\wxml56164.dll
C:\WINDOWS\wxmlua.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-28 )))))))))))))))))))))))))))))))
.
2008-08-27 11:43 . 2008-08-27 11:43 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-08-27 10:32 . 2008-08-27 10:32 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Orbit
2008-08-27 10:28 . 2008-08-27 10:35 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\GrabPro
2008-08-27 09:35 . 2008-08-27 09:35 <DIR> d-------- C:\Program Files\Lavasoft
2008-08-27 09:35 . 2008-08-27 09:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-27 09:34 . 2008-08-27 09:34 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-26 15:09 . 2008-08-26 15:09 0 --a------ C:\WINDOWS\BM43138f7b.xml
2008-08-26 09:31 . 2008-08-26 10:31 149 --a------ C:\WINDOWS\wininit.ini
2008-08-22 10:49 . 2008-08-22 10:49 <DIR> d-------- C:\Program Files\Cosmi
2008-08-22 10:49 . 2008-08-22 10:49 <DIR> d-------- C:\Program Files\Common Files\Cosmi
2008-08-22 10:49 . 2008-08-22 10:49 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-08-22 10:49 . 1997-07-10 10:36 299,008 --a------ C:\WINDOWS\system32\SKY32V3C.DLL
2008-08-22 10:49 . 1996-05-07 19:59 47,104 --a------ C:\WINDOWS\system32\D2HTLS32.DLL
2008-08-22 10:49 . 1996-02-28 15:47 28,976 --a------ C:\WINDOWS\system32\D2HTOOLS.DLL
2008-08-22 10:49 . 2008-08-22 10:49 0 --a------ C:\WINDOWS\PROTOCOL.INI
2008-08-21 07:59 . 2008-08-21 07:59 <DIR> d-------- C:\Program Files\MagicISO
2008-08-20 12:05 . 2008-08-20 12:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\ABBYY
2008-08-20 12:00 . 2008-08-20 12:00 <DIR> d-------- C:\Program Files\Common Files\ABBYY
2008-08-20 11:58 . 2008-08-20 12:04 <DIR> d-------- C:\Program Files\ABBYY FineReader 9.0
2008-08-20 11:58 . 2008-08-21 08:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ABBYY
2008-08-20 07:26 . 2008-08-25 11:31 2,828 --ahs---- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
2008-08-20 07:26 . 2008-08-20 07:26 8 -r-hs---- C:\Documents and Settings\All Users\Application Data\F99E9C3E86.sys
2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d-------- C:\Program Files\Common Files\Protexis
2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Corel
2008-08-20 07:22 . 2008-08-20 07:30 <DIR> d-------- C:\Program Files\Corel
2008-08-20 07:22 . 2008-08-20 07:22 <DIR> d-------- C:\Program Files\Common Files\Corel
2008-08-18 08:29 . 2008-08-18 08:29 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Nero
2008-08-18 08:27 . 2008-08-18 08:27 <DIR> d-------- C:\Program Files\Nero
2008-08-18 08:27 . 2008-08-18 08:28 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-08-18 08:27 . 2008-08-18 08:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-08-05 09:17 . 2008-08-05 09:17 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-30 13:20 . 2008-07-30 13:20 <DIR> d-------- C:\WINDOWS\system32\ivtMobCache
2008-07-30 13:20 . 2008-07-30 13:20 1,260 --a------ C:\WINDOWS\system32\SHORTCUT.INI
2008-07-30 13:20 . 2008-08-15 13:34 215 --a------ C:\WINDOWS\BsMobileModel.ini
2008-07-30 13:19 . 2008-08-25 11:24 4,535 --a------ C:\WINDOWS\system32\LOCALSERVICE.INI
2008-07-30 13:19 . 2008-08-25 11:23 126 --a------ C:\WINDOWS\system32\REMOTEDEVICE.INI
2008-07-30 13:19 . 2008-08-25 11:21 107 --a------ C:\WINDOWS\system32\LOCALDEVICE.INI
2008-07-30 13:10 . 2008-07-30 13:10 0 --a------ C:\WINDOWS\system32\BSPRINT.INI
2008-07-30 13:09 . 2008-07-30 13:09 <DIR> d-------- C:\Program Files\IVT Corporation
2008-07-30 13:09 . 2008-07-30 13:10 32 --a------ C:\WINDOWS\0
2008-07-30 13:09 . 2008-07-30 13:09 0 --a------ C:\WINDOWS\system32\0
2008-07-28 14:24 . 2008-07-28 14:24 <DIR> d-------- C:\Program Files\Manage PC Shut Down
2008-07-28 08:35 . 2008-08-28 07:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-07-28 08:34 . 2008-07-28 08:34 <DIR> d-------- C:\Program Files\DNA
2008-07-28 08:34 . 2008-07-28 08:34 <DIR> d-------- C:\Program Files\BitTorrent
2008-07-28 08:34 . 2008-08-28 06:50 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DNA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 05:09 8,278,048 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-28 05:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-08-28 05:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Orbit
2008-08-28 04:51 98,432 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-27 11:04 4,021,760 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-08-27 11:04 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-08-27 08:35 --------- d-----w C:\Program Files\Orbitdownloader
2008-08-26 12:39 4,646,954 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-08-26 12:25 2,384,384 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-08-22 05:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-21 12:43 --------- d-----w C:\Program Files\Opera
2008-08-21 05:11 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-20 10:31 --------- d-----w C:\Program Files\Java
2008-08-20 05:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Corel
2008-08-08 11:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Shareaza
2008-08-06 10:39 --------- d-----w C:\Program Files\Winamp
2008-08-06 10:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-08-01 11:03 --------- d-----w C:\Program Files\Foxit Software
2008-07-30 11:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-17 11:07 40,960 ----a-w C:\WINDOWS\BMW 6 Series Coupé.dll
2008-07-17 11:07 302,244 ----a-w C:\WINDOWS\BMW 6 Series Coupé.scr
2008-07-17 11:07 3,623,851 ----a-w C:\WINDOWS\BMW 6 Series Coupé.exe
2008-07-16 11:59 --------- d-----w C:\Program Files\Microsoft Bootvis
2008-07-10 11:00 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-10 10:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-10 10:23 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-09 18:40 98,403 ----a-w C:\WINDOWS\system32\Bs2Res.dll
2008-07-09 12:19 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-07-09 08:48 540,758 ----a-w C:\WINDOWS\system32\Bscdlg.dll
2008-07-09 07:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-07-09 07:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-07-07 09:52 --------- d-----w C:\Program Files\Avant Browser
2008-07-03 12:15 143,450 ----a-w C:\WINDOWS\system32\BsCommon.dll
2008-06-24 14:06 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-06-10 13:00 225,364 ----a-w C:\WINDOWS\system32\BsSDK.dll
2008-06-09 06:01 1,419,232 ----a-w C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-06 12:54 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2008-06-06 12:54 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
2008-06-04 16:30 9,728 ----a-w C:\WINDOWS\system32\BsMonUI.dll
2008-06-04 16:30 57,430 ----a-w C:\WINDOWS\system32\btfunc.dll
2008-06-04 16:30 53,248 ----a-w C:\WINDOWS\system32\HtmPrintHelper.dll
2008-06-04 16:30 405,589 ----a-w C:\WINDOWS\system32\BsUI.dll
2008-06-04 16:30 278,647 ----a-w C:\WINDOWS\system32\outlookAddin.dll
2008-06-04 16:30 18,432 ----a-w C:\WINDOWS\system32\BsMonSvr.dll
2008-06-04 16:29 622,693 ----a-w C:\WINDOWS\system32\BSShell.dll
2008-06-04 16:29 114,788 ----a-w C:\WINDOWS\system32\BsProfileFunc.dll
2008-06-04 16:29 114,774 ----a-w C:\WINDOWS\system32\versit.dll
2008-06-04 16:28 94,314 ----a-w C:\WINDOWS\system32\BsHelpCSps.dll
2008-06-04 16:28 520,307 ----a-w C:\WINDOWS\system32\BlueSoleilCSps.dll
2008-06-04 16:27 28,766 ----a-w C:\WINDOWS\system32\PlayerCtrl.dll
2008-06-04 16:27 28,672 ----a-w C:\WINDOWS\system32\BsMobileCSps.dll
2008-06-04 16:27 118,880 ----a-w C:\WINDOWS\system32\BsMobileSDK.dll
2008-06-04 16:26 28,760 ----a-w C:\WINDOWS\system32\BsTrace.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2006-05-03 10:06 163,328 --sha-r C:\WINDOWS\system32\flvDX.dll
2007-02-21 11:47 31,232 --sha-r C:\WINDOWS\system32\msfDX.dll
2007-12-17 13:43 27,648 --sha-w C:\WINDOWS\system32\Smab0.dll
.
((((((((((((((((((((((((((((( snapshot@2008-08-27_13.10.23.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-27 10:49:14 62,490 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-28 05:03:30 62,490 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-27 10:49:14 400,954 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-28 05:03:30 400,954 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-07-28 08:34 341824]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 16:06 1840424]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 11:22 7618560]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-04-17 12:30 85184]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 09:16 528384]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 18:30 45632]
"GrooveMonitor"="E:\Microsoft Office 2007\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 23:49 3116768]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 09:05 919016]
"BtTray"="C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe" [2008-07-09 20:51 229888]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 09:53 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 09:31 2221352]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 09:28 16126464 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 11:22 1822720 C:\WINDOWS\SkyTel.exe]
"nwiz"="nwiz.exe" [2006-06-01 11:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 11:22 86016 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 05:42 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [5/15/2003 2:19:50 AM 217193]
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [11/20/2007 9:14:02 AM 1707208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"E:\\Microsoft Office 2007\\Office12\\GROOVE.EXE"=
"E:\\Microsoft Office 2007\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;C:\WINDOWS\system32\Drivers\BtHidBus.sys [2008-01-21 19:28]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 21:03]
R2 BlueSoleilCS;BlueSoleilCS;C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe [2008-07-09 20:51]
R2 BsMobileCS;BsMobileCS;C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2008-06-04 18:26]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2005-06-10 11:01]
R2 PSI_SVC_2;Protexis Licensing V2;c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 11:15]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-07-03 12:33]
R3 BsHelpCS;BsHelpCS;C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe [2008-06-04 18:28]
R3 IvtBtBUs;IVT Bluetooth Bus Service;C:\WINDOWS\system32\Drivers\IvtBtBus.sys [2008-01-21 19:28]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-06-09 08:01]
S3 usb2vcom;USB to Serial Bridge Controller;C:\WINDOWS\system32\Drivers\usb2vcom.sys [2005-09-02 18:49]
S3 Usbtmc;ausbtmc;C:\WINDOWS\system32\Drivers\ausbtmc.sys [2003-04-10 13:35]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f2e6fa3-62ad-11dd-abc5-001583b3d1a5}]
\Shell\AutoRun\command - F:\WD_Windows_Tools\Setup.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 07:09:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-28 7:11:03
ComboFix-quarantined-files.txt 2008-08-28 05:10:56
ComboFix2.txt 2008-08-27 11:10:53
Pre-Run: 63,461,769,216 bytes free
Post-Run: 63,434,088,448 bytes free
225 --- E O F --- 2007-10-30 11:34:27
|