offline
- SlobaBgd
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Mod u pemziji
- Pridružio: 10 Okt 2005
- Poruke: 13526
- Gde živiš: Beograd
|
Evo ComboFix loga:
ComboFix 08-02-16.2 - Sloba 2008-02-15 22:43:30.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.145 [GMT 1:00]
Running from: D:\Documents and Settings\Sloba\My Documents\My Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\WINDOWS\system32\kdrth.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.
2008-02-14 23:29 . 2008-02-14 23:06 921,654 --a------ D:\BACK.BMP
2008-02-14 23:28 . 2008-02-14 23:28 5,998 --a------ D:\Hiren_s_BootCD.gif
2008-02-14 23:25 . 2008-02-14 23:25 14,182 --a------ D:\vc_logo2.gif
2008-02-14 23:23 . 2008-02-14 23:23 2,151 --a------ D:\button.gif
2008-02-14 23:14 . 2008-02-14 23:14 3,036 --a------ D:\m2klogobig.gif
2008-02-14 23:13 . 2008-02-14 23:13 4,740 --a------ D:\top_logo03.gif
2008-02-14 23:13 . 2008-02-14 23:13 3,972 --a------ D:\logo_m2k.gif
2008-02-14 12:18 . 2008-02-14 12:18 <DIR> d-------- D:\Program Files\Passware
2008-02-14 12:17 . 2008-02-14 12:17 <DIR> d-------- D:\Passware_Kit_Enterprise_v8.1.2807
2008-02-14 00:33 . 2008-02-14 00:36 1,147 --a------ D:\WINDOWS\AZPR3.INI
2008-02-14 00:31 . 2008-02-14 12:03 1,164 --a------ D:\WINDOWS\ARCHPR.INI
2008-02-13 23:28 . 2008-02-13 23:28 <DIR> d-------- D:\how do I get UBCD4 into my easyboot disk_files
2008-02-13 23:28 . 2008-02-13 23:28 51,039 --a------ D:\how do I get UBCD4 into my easyboot disk.htm
2008-02-13 22:32 . 2008-02-13 23:36 214 --a------ D:\WINDOWS\OB1.INI
2008-02-13 15:01 . 2008-02-15 00:35 1,330,933,760 --a------ D:\mboot.iso.uibak
2008-02-13 15:01 . 2008-02-15 00:42 1,330,933,760 --a------ D:\mboot.iso
2008-02-13 14:51 . 2008-02-13 14:51 <DIR> d-------- D:\WINDOWS\vbSkinner
2008-02-13 00:14 . 2008-02-13 00:14 45,798 --a------ D:\MultiBootCD_by_Pretorian.3785014.TPB.torrent
2008-02-13 00:02 . 2008-02-13 00:02 <DIR> d-------- D:\Program Files\uTorrent
2008-02-12 23:40 . 2008-02-12 23:40 6,444 --a------ D:\Rmn-military-header.png
2008-02-12 17:06 . 2008-02-12 17:06 <DIR> d-------- D:\Program Files\SiteEntry
2008-02-12 01:29 . 2008-02-12 01:29 <DIR> d-------- D:\Program Files\REATOGO
2008-02-11 23:11 . 2008-02-11 23:11 <DIR> d-------- D:\Program Files\Google
2008-02-10 01:39 . 2008-02-10 01:39 <DIR> d-------- D:\Program Files\MediaAccumulativeCodec
2008-02-08 22:16 . 2008-02-08 22:16 <DIR> d-------- D:\Program Files\Add Remove Pro
2008-02-08 21:13 . 2008-02-08 21:13 <DIR> d-------- D:\Documents and Settings\Sloba\dwhelper
2008-02-07 23:34 . 2008-02-07 23:34 <DIR> d-------- D:\WINDOWS\AllMedia Grabber
2008-02-07 22:21 . 2008-02-07 22:21 <DIR> d-------- D:\Documents and Settings\Sloba\Application Data\Linterweb
2008-02-06 20:46 . 2008-02-06 20:46 <DIR> d-------- D:\Program Files\Lavasoft
2008-02-06 20:46 . 2008-02-06 20:46 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 20:44 . 2008-02-06 20:44 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-02-04 22:35 . 2008-02-04 22:35 <DIR> d-------- D:\Documents and Settings\Sloba\Application Data\uTorrent
2008-02-03 21:32 . 2008-02-03 21:32 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Hagel Technologies
2008-02-02 22:00 . 2008-02-02 22:00 <DIR> d-------- D:\Program Files\ConsoleClassix.com
2008-02-02 21:13 . 2001-08-17 12:11 66,591 --a------ D:\WINDOWS\system32\drivers\el90xbc5.sys
2008-02-02 21:13 . 2001-08-17 12:11 66,591 --a------ D:\WINDOWS\system32\dllcache\el90xbc5.sys
2008-01-31 20:35 . 2008-01-31 20:35 <DIR> d-------- D:\Documents and Settings\Sale\Senegal (srpski)_files
2008-01-31 20:34 . 2008-01-31 20:34 <DIR> d-------- D:\Documents and Settings\Sale\Senegal (hrvatski)_files
2008-01-31 20:32 . 2008-01-31 20:32 <DIR> d-------- D:\Documents and Settings\Sale\Senegal_files
2008-01-31 17:02 . 2008-01-31 17:02 <DIR> d-------- D:\Documents and Settings\Sloba\Application Data\SumatraPDF
2008-01-30 01:13 . 2008-01-30 01:13 <DIR> d-------- D:\Program Files\Christian Ministries Software
2008-01-30 00:50 . 2008-01-30 00:50 <DIR> d-------- D:\Program Files\Total Commander 7.0
2008-01-29 22:45 . 2008-01-29 22:45 <DIR> d-------- D:\Program Files\Setup2Go
2008-01-28 02:18 . 2008-01-30 08:34 532 --a------ D:\WINDOWS\system32\InTLub1.sys
2008-01-28 00:55 . 2008-01-28 00:55 <DIR> d-------- D:\Program Files\Axialis
2008-01-28 00:55 . 2008-01-28 00:55 <DIR> d-------- D:\Documents and Settings\Sloba\Application Data\Axialis
2008-01-27 00:52 . 2008-01-27 00:52 <DIR> d-------- D:\Program Files\Innovative Solutions
2008-01-23 21:34 . 2008-01-23 21:34 <DIR> d-------- D:\Esprimo Mobile V5515
2008-01-16 21:59 . 2008-01-16 22:00 <DIR> d-------- D:\Temp\CDCheck
2008-01-16 21:59 . 2008-01-16 22:00 <DIR> d-------- D:\Temp\Cd check
2008-01-16 01:41 . 2008-01-16 01:41 <DIR> d-------- D:\Program Files\DVDInfoPro
2008-01-16 01:08 . 2008-01-16 01:08 <DIR> d-------- D:\Program Files\DVD Identifier
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 21:51 32 --sha-w D:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-16 21:51 32 --sha-w D:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-16 21:51 32 --sha-w D:\WINDOWS\system32\drivers\fidbox.idx
2008-02-16 21:51 32 --sha-w D:\WINDOWS\system32\drivers\fidbox.dat
2008-02-14 23:51 1,945,088 ------w D:\WINDOWS\Internet Logs\xDBA.tmp
2008-02-11 23:27 2,676,736 ------w D:\WINDOWS\Internet Logs\xDB8.tmp
2008-02-11 23:27 1,933,312 ------w D:\WINDOWS\Internet Logs\xDB9.tmp
2008-01-21 23:14 716,272 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2008-01-17 09:55 11,254,022 ------w D:\WINDOWS\Internet Logs\tvDebug.zip
2008-01-12 23:34 --------- d-----w D:\Program Files\Nero
2008-01-12 23:08 --------- d-----w D:\Documents and Settings\Sloba\Application Data\Nero
2008-01-12 23:05 --------- d-----w D:\Program Files\Common Files\Nero
2008-01-12 11:42 --------- d-----w D:\Program Files\Common Files\SureThing Shared
2008-01-12 11:41 --------- d-----w D:\Program Files\SureThing CD Labeler 5
2008-01-07 00:14 --------- d-----w D:\Program Files\Advanced Font Viewer
2008-01-06 23:38 --------- d-----w D:\Program Files\MikSoftware
2008-01-06 23:22 --------- d-----w D:\Program Files\FontPage
2008-01-06 21:22 693,760 ----a-w D:\WINDOWS\GPInstall.exe
2008-01-05 14:05 1,900 ----a-w D:\Program Files\CFontPro.lnk
2008-01-05 14:05 --------- d-----w D:\Program Files\C Font Pro
2008-01-04 23:52 --------- d-----w D:\Program Files\Light Scribe Tools
2008-01-04 23:15 --------- d-----w D:\Program Files\Acoustica CD Label Maker
2008-01-04 23:15 --------- d-----w D:\Documents and Settings\Sloba\Application Data\Acoustica
2008-01-03 19:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\LightScribe
2008-01-03 19:31 --------- d-----w D:\Program Files\LightScribeTemplateLabeler
2008-01-03 19:29 --------- d-----w D:\Program Files\LightScribe
2008-01-03 19:28 --------- d-----w D:\Program Files\LightScribe Diagnostic Utility
2008-01-02 23:59 --------- d-----w D:\Documents and Settings\Sloba\Application Data\DISCo
2008-01-01 01:51 --------- d-----w D:\Documents and Settings\Sloba\Application Data\NeroDCTemplates
2008-01-01 01:01 --------- d-----w D:\Program Files\Common Files\LightScribe
2008-01-01 00:57 --------- d-----w D:\Documents and Settings\All Users\Application Data\Nero
2007-12-30 18:21 3,148,800 ------w D:\WINDOWS\Internet Logs\xDB7.tmp
2007-12-28 17:39 43,520 ----a-w D:\WINDOWS\system32\CmdLineExt03.dll
2007-12-27 21:11 --------- d-----w D:\Documents and Settings\Sloba\Application Data\Emulators
2007-12-26 18:50 --------- d-----w D:\Program Files\Aeromgr
2007-12-20 22:06 --------- d-----w D:\Program Files\WexTech
2007-12-20 22:06 --------- d-----w D:\Program Files\Common Files\LHSPF
2007-12-20 22:04 --------- d-----w D:\Program Files\MDT6
2007-12-20 22:04 --------- d-----w D:\Program Files\Common Files\Wextech Shared
2007-12-14 10:32 12,632 ----a-w D:\WINDOWS\system32\lsdelete.exe
2007-12-05 21:02 74,552 ----a-w D:\Documents and Settings\Sloba\Application Data\GDIPFONTCACHEV1.DAT
2007-12-01 19:15 218,624 ----a-w D:\WINDOWS\system32\dllcache\uxtheme.dll
2007-11-15 23:33 3,637,248 ------w D:\WINDOWS\Internet Logs\xDB5.tmp
2007-11-15 23:33 1,745,408 ------w D:\WINDOWS\Internet Logs\xDB6.tmp
2007-10-13 15:50 2,751,488 ------w D:\WINDOWS\Internet Logs\xDB3.tmp
2007-10-13 15:50 1,675,264 ------w D:\WINDOWS\Internet Logs\xDB4.tmp
2007-08-31 12:25 2,933,760 ------w D:\WINDOWS\Internet Logs\xDB2.tmp
2007-07-30 18:45 332,288 ------w D:\WINDOWS\Internet Logs\xDB1.tmp
2000-07-23 11:27 16 ----a-w D:\Documents and Settings\Sloba\Application Data\mrsvr92d.dat
2001-08-23 11:00 253,952 --sha-w D:\WINDOWS\system32\msvcrt20.dll
2004-08-03 21:56 343,040 --sha-w D:\WINDOWS\system32\msvcrt.dll
2004-08-03 21:56 611,328 --sha-w D:\WINDOWS\system32\comctl32.dll
2004-08-03 21:56 413,696 --sha-w D:\WINDOWS\system32\msvcp60.dll
2004-08-03 21:56 1,028,096 --sha-w D:\WINDOWS\system32\mfc42.dll
2004-08-03 21:56 30,749 --sha-w D:\WINDOWS\system32\vbajet32.dll
2007-11-11 22:04 952 --sha-w D:\WINDOWS\system32\KGyGaAvL.sys
2007-11-11 22:04 8 --sh--r D:\WINDOWS\system32\F99EB917F5.sys
2004-08-03 21:56 611,328 --sha-w D:\WINDOWS\system32\dllcache\comctl32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2002-10-16 12:24 47104 D:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 21:10 339968]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 16:03 106544 D:\WINDOWS\system32\TWEAKUI.CPL]
"AVP"="D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-11-08 18:28 155751]
"IE Privacy Keeper"="D:\Program Files\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-04-30 11:12 962560]
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02 919280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 22:56 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=D:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=D:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
--a------ 2006-11-08 18:28 155751 D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CoolWallpaperSoftware]
--a------ 2005-08-08 09:50 57344 D:\Program Files\Coolwallpaper\cwm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Di dictionary]
--a------ 2005-11-17 12:05 497152 D:\Program Files\Di recnik\Di.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-02-11 23:11 29744 D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HEXelon MAX]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-03 20:32 208952 D:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2005-09-25 19:11 155648 D:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-03 20:32 455168 D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-03 20:32 455168 D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerMenu]
D:\WINDOWS\system32\powermenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QNPlus]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
-ra------ 2004-08-11 06:42 548864 D:\WINDOWS\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-03-04 03:36 36975 D:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
--a------ 2007-03-09 01:02 919280 D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Autodesk Licensing Service"=3 (0x3)
R0 sojubus;sojubus;D:\WINDOWS\system32\DRIVERS\sojubus.sys [2003-10-05 10:41]
R0 sojuscsi;sojuscsi;D:\WINDOWS\system32\DRIVERS\sojuscsi.sys [2003-09-28 10:57]
R2 nxsIO32;NextSensor Kernel I/O Driver;D:\WINDOWS\System32\DRIVERS\nxsIO32.sys [2007-08-19 02:43]
S3 GoogleDesktopManager-010108-205858;Google Desktop Manager 5.7.801.1629;"D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-11 23:11]
S3 iadusb;MT882;D:\WINDOWS\system32\DRIVERS\glauiad.sys []
S3 mpr_freader;MPR FileReader Driver;D:\DOCUME~1\Sloba\LOCALS~1\Temp\RarSFX0\mpr_freader.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{67505836-a766-11dc-8c28-ad6d44594a9c}]
\Shell\AutoRun\command - H:\PStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"D:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 22:54:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
D:\WINDOWS\system32\PSIService.exe
D:\WINDOWS\system32\tcpsvcs.exe
D:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-02-16 22:56:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 21:56:28
|