offline
- prepek2000
- Novi MyCity građanin
- Pridružio: 24 Jun 2005
- Poruke: 5
|
ComboFix 09-02-17.02 - prepek2000 2009-02-18 21:09:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.333 [GMT 1:00]
Running from: c:\documents and settings\prepek2000\Desktop\ComboFix.exe
AV: Windows Live OneCare *On-access scanning disabled* (Updated)
FW: Windows Live OneCare Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-18 to 2009-02-18 )))))))))))))))))))))))))))))))
.
2009-02-18 21:04 . 2009-02-18 21:03 388,608 --a------ c:\windows\system32\CF27689.exe
2009-02-18 17:28 . 2009-02-18 17:28 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_18_17_28_7.dmp
2009-02-18 17:20 . 2009-02-18 17:20 0 --a------ c:\windows\system32\nmesrvc_core_2009_2_18_17_20_48.dmp
2009-02-18 17:12 . 2009-02-18 17:12 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_18_17_12_35.dmp
2009-02-18 17:04 . 2009-02-18 17:04 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_18_17_4_30.dmp
2009-02-18 15:58 . 2009-02-18 15:58 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_18_15_58_16.dmp
2009-02-17 23:45 . 2007-11-27 22:56 116,416 --a------ c:\windows\system32\drivers\msfwhlpr.sys
2009-02-17 23:45 . 2007-11-27 22:56 91,328 --a------ c:\windows\system32\drivers\msfwdrv.sys
2009-02-17 23:44 . 2009-02-17 23:44 <DIR> d-------- c:\windows\system32\bits
2009-02-17 23:44 . 2008-05-15 16:15 53,168 --a------ c:\windows\system32\drivers\MpFilter.sys
2009-02-17 23:43 . 2007-03-29 13:56 7,168 -----c--- c:\windows\system32\dllcache\bitsprx4.dll
2009-02-17 23:43 . 2007-03-29 13:56 7,168 --------- c:\windows\system32\bitsprx4.dll
2009-02-17 23:22 . 2009-02-18 00:12 <DIR> d-------- c:\program files\Microsoft Windows OneCare Live
2009-02-17 23:20 . 2009-02-17 23:20 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_17_23_20_16.dmp
2009-02-17 17:06 . 2009-02-17 17:06 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_17_17_6_22.dmp
2009-02-17 16:04 . 2009-02-17 16:04 21,614 --a------ c:\windows\system32\nmesrvc_core_2009_2_17_16_4_24.dmp
2009-02-17 11:46 . 2009-02-17 11:46 22,350 --a------ c:\windows\system32\nmesrvc_core_2009_2_17_11_46_7.dmp
2009-02-16 22:51 . 2009-02-16 22:51 21,614 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_22_51_20.dmp
2009-02-16 22:43 . 2009-02-16 22:43 22,350 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_22_43_27.dmp
2009-02-16 21:53 . 2009-02-16 21:53 22,350 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_21_53_47.dmp
2009-02-16 17:23 . 2009-02-16 17:23 230 --a------ c:\windows\system32\spupdsvc.inf
2009-02-16 16:07 . 2009-02-16 16:07 22,350 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_16_7_22.dmp
2009-02-16 11:50 . 2009-02-16 11:50 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\SoftInform
2009-02-16 11:49 . 2009-02-16 12:01 <DIR> d-------- c:\program files\iNetFormFiller Trial
2009-02-16 11:44 . 2009-02-16 11:44 <DIR> d-------- c:\program files\SoftInform
2009-02-16 11:44 . 2009-02-16 12:00 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\AdsCleaner
2009-02-16 11:31 . 2009-02-16 11:31 21,614 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_11_31_24.dmp
2009-02-16 10:45 . 2009-02-16 10:45 21,614 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_10_45_45.dmp
2009-02-16 10:15 . 2009-02-16 10:15 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_10_15_40.dmp
2009-02-16 10:13 . 2009-02-16 10:13 268 --ah----- C:\sqmdata00.sqm
2009-02-16 10:13 . 2009-02-16 10:13 244 --ah----- C:\sqmnoopt00.sqm
2009-02-16 10:07 . 2009-02-16 10:07 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_10_7_20.dmp
2009-02-16 10:04 . 2009-02-16 10:04 <DIR> d-------- c:\program files\NHN USA
2009-02-16 10:04 . 2009-02-16 10:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\IJJIGame
2009-02-16 10:04 . 2009-02-16 10:04 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\PC Tools
2009-02-16 10:03 . 2009-02-16 10:03 <DIR> d-------- c:\program files\Zone Labs
2009-02-16 00:31 . 2009-02-16 10:01 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\MailFrontier(3)
2009-02-16 00:29 . 2009-02-16 00:29 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_0_29_8.dmp
2009-02-16 00:21 . 2009-02-16 10:01 <DIR> d-------- c:\windows\system32\ZoneLabs(3)
2009-02-16 00:18 . 2009-02-16 00:18 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_16_0_18_42.dmp
2009-02-15 10:20 . 2009-02-15 10:20 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_10_20_29.dmp
2009-02-15 10:07 . 2009-02-15 10:07 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_10_7_24.dmp
2009-02-15 10:03 . 2009-02-16 10:02 <DIR> d-------- c:\program files\Zone Labs(3)
2009-02-15 02:36 . 2009-02-15 02:36 0 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_2_36_35.dmp
2009-02-15 02:18 . 2009-02-16 10:03 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\MailFrontier(2)
2009-02-15 02:04 . 2009-02-16 10:03 <DIR> d-------- c:\windows\system32\ZoneLabs(2)
2009-02-15 02:04 . 2009-02-16 10:03 <DIR> d-------- c:\program files\Zone Labs(2)
2009-02-15 02:04 . 2009-02-16 09:56 49,616 --a------ c:\windows\system32\vsconfig.xml
2009-02-15 02:02 . 2009-02-15 02:02 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_2_2_44.dmp
2009-02-15 01:44 . 2009-02-16 01:22 356,640 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-02-15 01:44 . 2009-02-15 01:44 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_1_44_30.dmp
2009-02-15 01:44 . 2009-02-16 01:26 11,040 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-02-15 01:44 . 2009-02-15 02:33 4,448 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-02-15 01:44 . 2009-02-15 02:33 1,580 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-02-15 01:37 . 2009-02-16 00:29 4,212 ---h----- c:\windows\system32\zllictbl.dat
2009-02-15 01:34 . 2009-02-15 01:34 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_1_34_18.dmp
2009-02-15 01:31 . 2009-02-15 01:31 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_1_31_3.dmp
2009-02-15 01:21 . 2009-02-15 01:21 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_15_1_21_21.dmp
2009-02-14 11:29 . 2009-02-14 11:29 <DIR> d-------- c:\program files\Lavasoft
2009-02-14 11:29 . 2009-02-14 11:29 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\Lavasoft
2009-02-14 10:07 . 2009-02-14 10:07 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_14_10_7_10.dmp
2009-02-14 09:44 . 2009-02-14 09:44 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_14_9_44_19.dmp
2009-02-13 22:51 . 2009-02-13 22:51 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_13_22_51_34.dmp
2009-02-13 22:15 . 2009-02-13 22:15 250 --a------ c:\windows\gmer.ini
2009-02-13 22:13 . 2009-02-13 22:13 <DIR> d-------- C:\rsit
2009-02-13 22:13 . 2009-02-13 22:13 <DIR> d-------- c:\program files\trend micro
2009-02-13 22:08 . 2009-02-13 22:08 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_13_22_8_12.dmp
2009-02-13 20:04 . 2009-02-13 20:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-13 20:04 . 2009-02-13 20:04 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\Malwarebytes
2009-02-13 19:50 . 2009-02-13 19:50 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_13_19_50_31.dmp
2009-02-13 15:53 . 2009-02-13 15:53 15,854 --a------ c:\windows\system32\nmesrvc_core_2009_2_13_15_53_5.dmp
2009-02-12 18:34 . 2009-02-12 18:34 <DIR> d--h----- C:\BJPrinter
2009-02-12 18:34 . 2004-04-23 07:00 116,736 --a------ c:\windows\system32\CNMLM5y.DLL
2009-02-12 18:34 . 2004-03-11 18:06 86,016 --a------ c:\windows\system32\CNMCP5y.exe
2009-02-12 18:34 . 2004-04-23 07:00 7,680 --a------ c:\windows\system32\CNMVS5y.DLL
2009-02-12 18:12 . 2009-02-12 18:12 <DIR> d-------- c:\program files\Common Files\Cisco Systems
2009-02-12 18:12 . 2006-12-19 15:06 1,495,552 --a------ c:\windows\system32\epoPGPsdk.dll
2009-02-12 15:54 . 2009-02-12 15:54 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_12_15_54_22.dmp
2009-02-11 22:13 . 2009-02-11 22:13 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_11_22_13_55.dmp
2009-02-11 11:56 . 2009-02-11 11:56 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_11_11_56_59.dmp
2009-02-10 22:52 . 2009-02-10 22:52 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_10_22_52_34.dmp
2009-02-10 22:35 . 2009-02-10 22:35 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-02-10 22:35 . 2009-02-10 22:35 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-02-10 22:35 . 2009-02-10 22:35 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-02-10 22:35 . 2009-02-10 22:35 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-02-10 22:30 . 2009-02-16 10:14 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-10 22:30 . 2009-02-16 10:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-10 22:06 . 2009-02-18 21:10 158 --a------ c:\windows\pop.htm
2009-02-10 22:05 . 2009-02-10 22:05 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_10_22_5_15.dmp
2009-02-10 15:51 . 2009-02-10 15:51 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_10_15_51_45.dmp
2009-02-09 22:02 . 2009-02-09 22:02 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_9_22_2_28.dmp
2009-02-09 20:09 . 2008-10-10 04:52 4,379,984 --a------ c:\windows\system32\D3DX9_40.dll
2009-02-09 20:09 . 2008-07-10 11:00 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2009-02-09 20:09 . 2008-10-27 10:04 514,384 --a------ c:\windows\system32\XAudio2_3.dll
2009-02-09 20:09 . 2008-07-30 06:20 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2009-02-09 20:09 . 2007-04-04 18:53 81,768 --a------ c:\windows\system32\xinput1_3.dll
2009-02-09 20:09 . 2008-10-27 10:04 70,992 --a------ c:\windows\system32\XAPOFX1_2.dll
2009-02-09 20:09 . 2008-07-30 06:20 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2009-02-09 20:09 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2009-02-09 20:09 . 2008-10-27 10:04 23,376 --a------ c:\windows\system32\X3DAudio1_5.dll
2009-02-09 20:08 . 2009-02-06 20:51 24,064 --a------ c:\windows\system32\jwtch32.exe
2009-02-09 20:08 . 2009-02-09 20:08 5,632 --a------ c:\windows\system32\otmspr.exe
2009-02-09 19:59 . 2009-02-09 19:59 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_9_19_59_44.dmp
2009-02-08 22:57 . 2009-02-08 22:57 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_8_22_57_49.dmp
2009-02-08 16:26 . 2009-02-08 16:26 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_8_16_26_36.dmp
2009-02-08 11:16 . 2009-02-08 11:16 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_8_11_16_6.dmp
2009-02-08 01:46 . 2009-02-08 01:46 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_8_1_46_24.dmp
2009-02-07 22:08 . 2009-02-07 22:08 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_7_22_8_46.dmp
2009-02-07 11:02 . 2009-02-07 11:02 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_7_11_2_21.dmp
2009-02-06 20:26 . 2009-02-06 20:26 15,642 --a------ c:\windows\system32\nmesrvc_core_2009_2_6_20_26_32.dmp
2009-02-04 19:57 . 2009-02-04 19:57 376 --a------ c:\windows\ODBC.INI
2009-02-04 19:56 . 2009-02-04 19:56 <DIR> d-------- c:\windows\ShellNew
2009-02-03 23:12 . 2009-02-03 23:12 162,816 --a------ c:\windows\system32\fmod.dll
2009-02-01 10:04 . 2009-02-01 10:04 0 --a------ c:\windows\system32\nmesrvc_core_2009_2_1_10_4_44.dmp
2009-02-01 01:23 . 2009-02-06 11:41 <DIR> d-------- C:\TEMP
2009-02-01 01:15 . 2009-02-01 01:15 <DIR> d-------- c:\program files\Microsoft Visual Studio .NET
2009-01-31 01:38 . 2009-01-31 01:47 <DIR> d-------- c:\documents and settings\prepek2000\Application Data\GetRight
2009-01-31 01:20 . 2009-01-31 02:01 <DIR> d-------- c:\program files\DAP
2009-01-31 01:20 . 2009-01-31 02:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\SpeedBit
2009-01-30 22:40 . 2009-01-30 22:41 242 --a------ c:\windows\wcx_ftp.ini
2009-01-30 22:08 . 2009-01-30 22:08 <DIR> d-------- c:\program files\FreeUndelete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-18 16:20 --------- d-----w c:\documents and settings\prepek2000\Application Data\uTorrent
2009-02-17 16:04 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-17 16:04 --------- d-----w c:\program files\Spyware Doctor
2009-02-15 01:12 35,328 ----a-w c:\windows\Internet Logs\xDB4.tmp
2009-02-15 01:10 60,928 ----a-w c:\windows\Internet Logs\xDB3.tmp
2009-02-15 01:06 76,288 ----a-w c:\windows\Internet Logs\xDB1.tmp
2009-02-15 01:06 1,248,768 ----a-w c:\windows\Internet Logs\xDB2.tmp
2009-02-12 18:05 --------- d-----w c:\program files\Euro Gunz V 8.5.5
2009-02-12 17:09 --------- d-----w c:\program files\Symantec AntiVirus
2009-02-12 17:09 --------- d-----w c:\program files\Symantec
2009-02-12 17:09 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-12 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-02-11 21:20 --------- d-----w c:\program files\Microsoft ActiveSync
2009-02-07 00:55 --------- d-----w c:\documents and settings\prepek2000\Application Data\Skype
2009-02-01 00:15 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-31 00:58 --------- d-----w c:\program files\IDA
2008-12-27 11:20 --------- d-----w c:\program files\Real Alternative
2008-12-27 11:20 --------- d-----w c:\program files\Media Player Classic
2008-12-21 17:49 --------- d-----w c:\documents and settings\prepek2000\Application Data\combustion2008
2008-12-04 13:13 409,600 ----a-w c:\windows\system32\wrap_oal.dll
2008-12-04 13:13 114,688 ----a-w c:\windows\system32\OpenAL32.dll
2008-12-04 13:13 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-13 14:09 56 --sh--r c:\windows\system32\B0B00FC1E7.sys
2008-11-13 14:09 1,682 --sha-w c:\windows\system32\KGyGaAvL.sys
2004-08-03 22:56 4,096 --sha-w c:\windows\system32\nfhfynbyj.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2004-12-22 266240]
"Microsoft netswitch"="c:\windows\system32\jwtch32.exe" [2009-02-06 24064]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-11-05 64880]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"vidc.CDVC"= cdvccodc.dll
"vidc.CDVH"= cdvhcodc.dll
"vidc.CUVC"= cuvccodc.dll
"vidc.CLLC"= cllccodc.dll
"vidc.CDV5"= cdv5codc.dll
"MSVideo"= CSvidcap.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit.exe]
"Debugger"=0
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=c:\windows\pss\VPN Client.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
--a------ 2004-07-29 15:04 2052173 c:\program files\Babylon\Babylon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Download Accelerator]
--a------ 2006-10-31 13:17 2309632 c:\program files\IDA\ida.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
--a------ 2008-11-05 21:59 4347120 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NexusServer]
--a------ 2007-03-26 17:45 389120 c:\program files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-15 13:59 155648 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2008-01-21 12:17 61440 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-11-10 05:43 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\µTorrent]
--a------ 2006-07-02 17:29 174163 c:\program files\uTorrent\utorrent.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Xming\\Xming.exe"=
"d:\\DOWNLOAD\\Gunz\\GunzLauncher.exe"=
"d:\\DOWNLOAD\\Gunz\\Gunz.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\Combustion 2008\\combustion.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\oracle\\product\\10.2.0\\db_2\\jdk\\jre\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\otmspr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2008-11-07 75925]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-11-05 25968]
R2 OracleOraDb10g_home2iSQL*Plus;OracleOraDb10g_home2iSQL*Plus;c:\oracle\product\10.2.0\db_2\BIN\isqlplussvc.exe [2009-02-01 53248]
R2 OracleServiceTEST;OracleServiceTEST;c:\oracle\product\10.2.0\db_2\bin\ORACLE.EXE TEST --> c:\oracle\product\10.2.0\db_2\bin\ORACLE.EXE TEST [?]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;c:\windows\system32\drivers\wf2ktunr.sys [2008-11-07 36423]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;c:\windows\system32\drivers\wf2kXbar.sys [2008-11-07 10005]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [2008-11-07 9510]
S2 OracleDBConsoletest;OracleDBConsoletest;c:\oracle\product\10.2.0\db_2\BIN\nmesrvc.exe [2009-02-01 24064]
S2 OracleOraDb10g_home2TNSListener;OracleOraDb10g_home2TNSListener;c:\oracle\product\10.2.0\db_2\BIN\TNSLSNR --> c:\oracle\product\10.2.0\db_2\BIN\TNSLSNR [?]
S3 XDva120;XDva120;\??\c:\windows\system32\XDva120.sys --> c:\windows\system32\XDva120.sys [?]
S4 I3svhotkcstd;I3svhotkcstd;c:\windows\system32\drivers\http.sys [2004-08-03 262784]
S4 OracleJobSchedulerTEST;OracleJobSchedulerTEST;c:\oracle\product\10.2.0\db_2\Bin\extjob.exe TEST --> c:\oracle\product\10.2.0\db_2\Bin\extjob.exe TEST [?]
.
- - - - ORPHANS REMOVED - - - -
BHO-{6BC5DA72-D280-4E9C-AEDB-54AF1625A634} - c:\windows\system32\khfFXpmL.dll
Notify-NavLogon - (no file)
Notify-opnNFWMf - opnNFWMf.dll
Notify-WRNotifier - (no file)
MSConfigStartUp-48ab136a - c:\windows\system32\oaypvefy.dll
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: Download ALL with IDA - c:\program files\IDA\idaieall.htm
IE: Download with IDA - c:\program files\IDA\idaie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
TCP: {C45FACAD-2E5B-4A13-BDCE-9C0E1BCDFB9C} = 80.93.224.1
FF - ProfilePath - c:\documents and settings\prepek2000\Application Data\Mozilla\Firefox\Profiles\ghp2zgus.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-18 21:10:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraDb10g_home2TNSListener]
"ImagePath"="c:\oracle\product\10.2.0\db_2\BIN\TNSLSNR "
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1177238915-1844823847-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4068FE62-3273-B598-9A5B-1F406C1DF020}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jafbkomeccjbchikojlc"=hex:61,61,00,00
"kafbkomeacbohfppihfgkn"=hex:61,61,00,00
"fafbkomebcdl"=hex:66,61,6c,63,62,69,63,6f,66,61,61,65,00,00
[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"
[HKEY_LOCAL_MACHINE\software\Microsoft\DirectInput\Compatibility\CLIENT2._EXE35FEFABD00088200*]
@DACL=
"MaxDeviceNameLen"="6dÍåb9\140000жæ1562\1b"
"NoPollSucceed"="{E7711B87-0007-97DF-741C-D5B92EE132CE}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2454785:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{3601791B-53FE-13D0-60B1-EA5E69C7ACC9}\Version 1.1]
@DACL=
"dat"="806585365:{C6F8059B-8F35-8C8F-D2DF-11340CEBDAA6}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2454806:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\{C6165FC9-360C-7D04-E5C4-DB62E7CF48E6}*\Install*Loc\xga-3\dat]
@DACL=
"default"="516231424:{F5C1ED5F-D3D7-29DC-2F01-83D967A6A00C}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{3601791B-53FE-13D0-60B1-EA5E69C7ACC9}\Version 3.x]
@DACL=
"dat"="1767914624:{62F38F1B-B766-5CAE-7D00-4E62C9C825BD}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smase._dll*]
@DACL=
"AplicationGoo"="0b(L37j268b^È)7351Õ"
"ChkAppHelp"="{BD814CAC-8494-6473-A32C-B4737B034F74}"
[HKEY_LOCAL_MACHINE\software\Microsoft\WinXGA*\Providers*\{D41D8CD9-8F00-B204-E980-0998ECF8427E}\Current*Set\xga-3\ver]
@DACL=
"KnownSvcs"="923715583:{F97C40F9-73CA-4531-4420-7512DFEDDA76}"
[HKEY_LOCAL_MACHINE\software\XBMga*\UUIDs\{1CE370F5-FD0B-643D-D4EE-BD5FCD9A7D69}\xga-3\Install*Loc]
@DACL=
"{19620715-0001-1211-574574-30001}"="234522155:{9C5F3000-E542-91BF-1C9F-C1EB0434D06C}"
[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="1:{19C42D30-D844-8A07-12A4-E783E7D228F7}"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(888-)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-18 21:11:46
ComboFix-quarantined-files.txt 2009-02-18 20:11:44
Pre-Run: 166,092,800 bytes free
Post-Run: 203,284,480 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
343 --- E O F --- 2009-02-18 15:02:08
Dopuna: 18 Feb 2009 22:02
Samo da dodam dok je radio program iskljucio sam antivirus/firewall jer je trazio da pobijem procese koji muljaju u pozadini i GRESKOM sam u logu promenio username pc-ja....
NAdam se da cete mi pomoci sa ovim problemom....
|