offline
- bogibogo
- Novi MyCity građanin
- Pridružio: 04 Apr 2008
- Poruke: 15
|
ComboFix 08-04-08.10 - XP 2008-04-18 11:32:17.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.548 [GMT 2:00]
Running from: C:\Documents and Settings\XP\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
TimedOut: progfile.dat
((((((((((((((((((((((((( Files Created from 2008-03-18 to 2008-04-18 )))))))))))))))))))))))))))))))
.
2008-04-17 12:47 . 2008-04-17 12:48 <DIR> d-------- C:\Program Files\Dictionary
2008-04-17 11:22 . 2008-04-17 11:30 <DIR> d-------- C:\Program Files\eMule
2008-04-17 08:29 . 2008-04-17 08:30 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-04-17 08:29 . 2008-04-17 08:30 <DIR> d-------- C:\Program Files\AVSMedia
2008-04-17 08:23 . 2008-04-17 08:23 <DIR> d-------- C:\Program Files\GNU
2008-04-16 08:31 . 2008-04-16 08:31 250 --a------ C:\WINDOWS\gmer.ini
2008-04-16 08:30 . 2008-04-16 08:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-04-09 15:06 . 2008-04-09 15:06 <DIR> d-------- C:\VundoFix Backups
2008-04-09 14:15 . 2008-04-09 14:15 <DIR> d-------- C:\WINDOWS\system32\sl-SI
2008-04-09 13:53 . 2008-03-01 15:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-09 13:53 . 2007-07-01 05:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-09 13:53 . 2007-07-01 05:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-09 13:53 . 2008-03-01 15:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-09 13:53 . 2008-03-01 15:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-09 13:53 . 2008-03-01 15:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-09 13:53 . 2008-03-01 15:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-09 13:53 . 2008-03-01 15:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-09 13:53 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-04 13:10 . 2008-04-04 13:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-04 09:44 . 2008-04-04 09:44 <DIR> d-------- C:\Program Files\Windows Defender
2008-04-04 08:55 . 2008-04-04 08:55 1,823 --a------ C:\WINDOWS\mozver.dat
2008-04-04 08:09 . 2008-04-04 08:13 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-01 10:44 . 2008-04-01 10:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-01 10:44 . 2008-04-01 10:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-01 10:44 . 2008-04-01 10:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-28 10:43 . 2008-03-31 09:11 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-03-26 15:24 . 2008-04-17 15:02 16 --a------ C:\WINDOWS\popcinfo.dat
2008-03-26 14:54 . 2008-03-26 14:57 <DIR> d-------- C:\Program Files\Bejeweled 2 Deluxe
2008-03-26 14:54 . 2008-03-26 14:54 720,896 --a------ C:\WINDOWS\iun6002ev.exe
2008-03-26 14:27 . 2008-03-26 14:54 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-26 11:30 . 2008-03-26 11:30 <DIR> d-------- C:\Documents and Settings\XP\Application Data\GRETECH
2008-03-26 11:30 . 2008-03-26 11:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
2008-03-26 08:57 . 2008-04-09 09:18 564 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-26 08:56 . 2008-03-26 08:56 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-03-25 15:07 . 2008-03-25 15:07 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2008-03-25 14:54 . 2008-03-25 14:54 <DIR> d-------- C:\Program Files\ESET
2008-03-25 14:54 . 2008-03-25 14:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-03-25 11:29 . 2008-03-25 11:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-03-25 11:11 . 2008-03-25 11:11 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-03-25 11:09 . 2008-03-25 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ALM
2008-03-25 10:56 . 2008-03-25 10:56 <DIR> d-------- C:\Program Files\QuickTime
2008-03-25 10:48 . 2007-02-20 17:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-03-25 10:48 . 2007-02-20 17:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-03-25 10:41 . 2008-03-25 10:41 <DIR> d-------- C:\Program Files\Bonjour
2008-03-25 10:37 . 2008-03-25 10:37 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-03-25 10:27 . 2008-03-25 10:27 <DIR> d-------- C:\Documents and Settings\XP\Application Data\Nero
2008-03-25 10:23 . 2008-03-25 10:23 <DIR> d-------- C:\Program Files\Nero
2008-03-25 10:23 . 2008-03-28 10:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-25 10:01 . 2008-03-25 10:03 <DIR> d-------- C:\Program Files\TIS 2008
2008-03-20 14:26 . 2008-03-20 14:26 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-25 12:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-03-25 09:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-22 08:05 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-02-22 08:05 --------- d-----w C:\Program Files\Autodesk
2008-02-22 08:05 --------- d-----w C:\Program Files\AutoCAD 2005
2008-02-22 08:04 --------- d-----w C:\Program Files\AnswerWorks 4.0
2008-02-22 08:00 --------- d-----w C:\Documents and Settings\XP\Application Data\Autodesk
2008-02-22 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-02-20 10:11 33,800 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-02-20 10:02 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-02-20 10:01 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\SET9B76.tmp
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\SETC3E7.tmp
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\SET9B05.tmp
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\SETC3DF.tmp
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\SET9B06.tmp
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\SETC3E0.tmp
2008-02-16 22:29 3,059,712 ----a-w C:\WINDOWS\system32\SET9B93.tmp
2008-02-16 22:29 3,059,712 ------w C:\WINDOWS\system32\SETC3F5.tmp
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\SET9B8A.tmp
2008-02-16 08:59 659,456 ------w C:\WINDOWS\system32\SETC3F1.tmp
2008-02-16 08:59 615,936 ----a-w C:\WINDOWS\system32\SET9B8B.tmp
2008-02-16 08:59 615,936 ------w C:\WINDOWS\system32\SETC3F2.tmp
2008-02-16 08:59 474,112 ----a-w C:\WINDOWS\system32\SET9B8C.tmp
2008-02-16 08:59 474,112 ------w C:\WINDOWS\system32\SETC3F3.tmp
2008-02-16 08:59 1,494,528 ----a-w C:\WINDOWS\system32\SET9B8D.tmp
2008-02-16 08:59 1,494,528 ------w C:\WINDOWS\system32\SETC3F4.tmp
2008-02-16 08:59 1,023,488 ----a-w C:\WINDOWS\system32\SET9B9D.tmp
2008-02-16 08:59 1,023,488 ------w C:\WINDOWS\system32\SETC3F7.tmp
2008-02-15 09:06 351,744 ----a-w C:\WINDOWS\system32\SETC3F8.tmp
2008-02-15 09:06 351,744 ----a-w C:\WINDOWS\system32\SET9BA0.tmp
.
((((((((((((((((((((((((((((( snapshot@2008-04-09_14.42.10.73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
+ 2008-04-16 06:31:25 819,200 ----a-w C:\WINDOWS\gmer.dll
+ 2008-03-03 18:29:06 761,856 ----a-w C:\WINDOWS\gmer.exe
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:54:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2008-04-16 06:30:29 632,320 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}\IconCD95F66110.exe
+ 2008-04-16 06:30:29 29,184 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}\IconCD95F6617.exe
+ 2003-05-22 11:26:16 638,976 ----a-w C:\WINDOWS\system32\divx.dll
- 2007-08-14 01:54:10 765,952 -c--a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2008-04-16 06:31:25 86,097 ----a-w C:\WINDOWS\system32\drivers\gmer.sys
- 2008-04-09 07:22:51 1,481,392 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-17 08:14:29 1,481,416 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2003-05-21 22:50:34 1,700,352 ----a-w C:\WINDOWS\system32\GdiPlus.dll
+ 2003-05-21 22:50:36 261,632 ----a-w C:\WINDOWS\system32\mcdvd_32.dll
+ 2002-01-05 14:48:16 974,848 ----a-w C:\WINDOWS\system32\mfc70.dll
+ 2002-08-19 23:41:12 413,760 ----a-w C:\WINDOWS\system32\mpg4c32.dll
+ 2002-01-05 13:40:18 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
+ 2002-01-05 01:37:26 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
+ 2003-05-21 11:50:38 24,576 ----a-w C:\WINDOWS\system32\msxml3a.dll
- 2006-09-07 00:43:16 14,048 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 12:44:58 282,624 ----a-w C:\WINDOWS\system32\spool\drivers\color\MXF_SDK_GenericContainer_DV_r.4.1.1.223.dll
+ 2007-11-30 12:44:58 151,552 ----a-w C:\WINDOWS\system32\spool\drivers\color\MXF_SDK_GenericContainer_MPEG_ESAudio_r.4.1.1.223.dll
+ 2007-11-30 12:44:56 401,408 ----a-w C:\WINDOWS\system32\spool\drivers\color\MXF_SDK_GenericContainer_Wave_r.4.1.1.223.dll
+ 2004-07-03 19:59:06 524,288 ----a-w C:\WINDOWS\system32\xvidcore.dll
+ 2004-07-03 20:08:04 139,264 ----a-w C:\WINDOWS\system32\xvidvfw.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-07-27 14:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 12:12 90112]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 17:40 1884160]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 12:06 1443072]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 14:06 40048]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-07-27 14:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-02-25 02:35:22 10872]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-04-13 11:20:00 415072]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-02-20 12:11]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-18 09:32:42 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-04-18 11:34:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
? [1324]
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-18 11:35:25
ComboFix-quarantined-files.txt 2008-04-18 09:35:20
ComboFix2.txt 2008-04-15 06:38:29
ComboFix3.txt 2008-04-14 07:06:16
ComboFix4.txt 2008-04-11 06:21:59
ComboFix5.txt 2008-04-09 12:42:24
Pre-Run: 229,750,632,448 bytes free
Post-Run: 229,738,762,240 bytes free
.
2008-04-18 06:33:31 --- E O F ---
|