offline
- KoZaK82
- Novi MyCity građanin
- Pridružio: 14 Nov 2007
- Poruke: 12
|
Evo me, rezultati combofixa:
ComboFix 07-11-08.1 - Bojan 2007-11-16 16:51:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223 [GMT 1:00]
Running from: C:\Documents and Settings\Bojan\Desktop\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Bojan\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Bojan\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Bojan\Favorites\Online Security Guide.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ggjlm.bak1
C:\WINDOWS\system32\ggjlm.bak2
C:\WINDOWS\system32\ggjlm.ini
C:\WINDOWS\system32\ggjlm.ini2
C:\WINDOWS\system32\ggjlm.tmp
C:\WINDOWS\system32\lcch.dat
C:\WINDOWS\system32\lut.dat
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\sxhnbzkl.dllbox
C:\WINDOWS\system32\tconini.dat
C:\WINDOWS\system32\tisa.cnf
C:\WINDOWS\system32\ubodpnte.dllbox
C:\WINDOWS\system32\wtnekdjt.dllbox
C:\WINDOWS\winshow.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 )))))))))))))))))))))))))))))))
.
2007-11-16 16:48 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-16 13:39 81,984 --a------ C:\WINDOWS\system32\lpfqadhp.dll
2007-11-16 13:38 85,056 --a------ C:\WINDOWS\system32\xikniwto.dll
2007-11-15 09:24 79,936 --a------ C:\WINDOWS\system32\imaaegvx.dll
2007-11-14 23:03 79,424 --a------ C:\WINDOWS\system32\piqbkabl.dll
2007-11-14 23:00 85,056 --a------ C:\WINDOWS\system32\shuxngbo.dll
2007-11-14 22:53 144,480 --a------ C:\WINDOWS\system32\ubodpnte.dll
2007-11-14 22:52 144,480 --a------ C:\WINDOWS\system32\prjgmicw.dll
2007-11-14 22:52 85,056 --a------ C:\WINDOWS\system32\qmiwwbun.dll
2007-11-14 22:23 79,424 --a------ C:\WINDOWS\system32\rwwvtosr.dll
2007-11-14 22:13 144,480 --a------ C:\WINDOWS\system32\sxhnbzkl.dll
2007-11-14 22:13 85,056 --a------ C:\WINDOWS\system32\pwddhsqg.dll
2007-11-14 22:13 79,424 --a------ C:\WINDOWS\system32\qqdrtfqe.dll
2007-11-14 22:12 144,480 --a------ C:\WINDOWS\system32\kiaujpyq.dll
2007-11-14 21:55 79,424 --a------ C:\WINDOWS\system32\yrmnuwlx.dll
2007-11-14 21:49 <DIR> d-------- C:\VundoFix Backups
2007-11-14 21:01 144,480 --a------ C:\WINDOWS\system32\wohketyj.dll
2007-11-14 20:58 79,424 --a------ C:\WINDOWS\system32\jmijvdio.dll
2007-11-14 20:55 85,056 --a------ C:\WINDOWS\system32\rxhcvfdc.dll
2007-11-14 20:24 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Thinstall
2007-11-14 09:34 81,472 --a------ C:\WINDOWS\system32\pqvdlpub.dll
2007-11-14 09:30 85,056 --a------ C:\WINDOWS\system32\cxhsusej.dll
2007-11-14 09:26 <DIR> d-------- C:\Program Files\Navilog1
2007-11-14 08:54 85,056 --a------ C:\WINDOWS\system32\sxvhjuor.dll
2007-11-14 08:53 81,472 --a------ C:\WINDOWS\system32\lqtqbasa.dll
2007-11-14 00:02 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-11-14 00:02 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-11-14 00:02 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-11-13 23:46 80,448 --a------ C:\WINDOWS\system32\gcewkauj.dll
2007-11-13 23:43 85,056 --a------ C:\WINDOWS\system32\kujoviwq.dll
2007-11-12 23:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-12 22:54 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-12 22:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-12 22:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-12 21:52 144,480 --a------ C:\WINDOWS\system32\qagbqfdp.dll
2007-11-12 21:49 81,472 --a------ C:\WINDOWS\system32\kvdnxagh.dll
2007-11-12 17:06 <DIR> d-------- C:\Program Files\RegCure
2007-11-12 16:54 81,472 --a------ C:\WINDOWS\system32\nrnpugii.dll
2007-11-12 15:37 81,472 --a------ C:\WINDOWS\system32\xiacdoul.dll
2007-11-12 09:33 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Systweak
2007-11-12 09:33 89,664 --a------ C:\WINDOWS\system32\kwysjeyu.dll
2007-11-12 09:33 81,472 --a------ C:\WINDOWS\system32\oljtdvqq.dll
2007-11-12 09:32 <DIR> d-------- C:\Program Files\Advanced System Optimizer
2007-11-12 00:10 79,936 --a------ C:\WINDOWS\system32\urasxfhh.dll
2007-11-12 00:07 88,128 --a------ C:\WINDOWS\system32\shlfdqgd.dll
2007-11-11 22:21 79,936 --a------ C:\WINDOWS\system32\cfmmjncv.dll
2007-11-11 22:15 88,128 --a------ C:\WINDOWS\system32\palskmfj.dll
2007-11-11 13:31 79,936 --a------ C:\WINDOWS\system32\pjtucjkk.dll
2007-11-11 13:27 88,128 --a------ C:\WINDOWS\system32\ulyhbdgv.dll
2007-11-11 10:04 79,936 --a------ C:\WINDOWS\system32\ookrjbsy.dll
2007-11-11 10:01 88,128 --a------ C:\WINDOWS\system32\stxudpnu.dll
2007-11-11 09:15 79,936 --a------ C:\WINDOWS\system32\vdahondm.dll
2007-11-11 09:09 88,128 --a------ C:\WINDOWS\system32\whdnjxkr.dll
2007-11-11 00:02 81,472 --a------ C:\WINDOWS\system32\clkftbqk.dll
2007-11-10 23:56 85,056 --a------ C:\WINDOWS\system32\mgeoorie.dll
2007-11-10 22:55 81,472 --a------ C:\WINDOWS\system32\dubjgmvc.dll
2007-11-10 21:26 85,056 --a------ C:\WINDOWS\system32\vxvyikcc.dll
2007-11-10 21:23 81,472 --a------ C:\WINDOWS\system32\rwxycuxe.dll
2007-11-10 19:40 81,472 --a------ C:\WINDOWS\system32\rnxbduyv.dll
2007-11-10 19:37 85,056 --a------ C:\WINDOWS\system32\wdlkyghl.dll
2007-11-10 19:06 85,056 --a------ C:\WINDOWS\system32\bqwsxthh.dll
2007-11-10 19:03 81,472 --a------ C:\WINDOWS\system32\uiwqogga.dll
2007-11-09 20:30 88,128 --a------ C:\WINDOWS\system32\ttmfnsox.dll
2007-11-09 20:24 77,888 --a------ C:\WINDOWS\system32\brlnrmnu.dll
2007-11-09 20:17 88,128 --a------ C:\WINDOWS\system32\flurenpi.dll
2007-11-09 20:17 77,888 --a------ C:\WINDOWS\system32\hfnbibxq.dll
2007-11-09 13:16 88,128 --a------ C:\WINDOWS\system32\lcqbpvte.dll
2007-11-09 13:13 77,888 --a------ C:\WINDOWS\system32\rsjkkmev.dll
2007-11-09 10:48 88,128 --a------ C:\WINDOWS\system32\aqfyqvsa.dll
2007-11-09 10:44 77,888 --a------ C:\WINDOWS\system32\qydsascv.dll
2007-11-09 10:21 88,128 --a------ C:\WINDOWS\system32\nqbeghgo.dll
2007-11-09 10:18 77,888 --a------ C:\WINDOWS\system32\vttvfjyx.dll
2007-11-09 10:14 77,888 --a------ C:\WINDOWS\system32\qxtckoju.dll
2007-11-09 10:11 88,128 --a------ C:\WINDOWS\system32\jmljyirb.dll
2007-11-09 00:23 86,080 --a------ C:\WINDOWS\system32\wrnbqedb.dll
2007-11-07 10:31 <DIR> d-------- C:\Program Files\AVIcodec
2007-11-07 07:02 86,080 --a------ C:\WINDOWS\system32\utaxmrnh.dll
2007-11-07 06:59 79,936 --a------ C:\WINDOWS\system32\nnilbthp.dll
2007-11-07 00:36 <DIR> d-------- C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2007-11-07 00:27 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2007-11-07 00:27 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
2007-11-06 18:57 35,328 --a------ C:\WINDOWS\system32\opnlihe.dll
2007-11-06 18:53 35,328 --a------ C:\WINDOWS\system32\khfdbbb.dll
2007-11-06 18:53 35,328 --a------ C:\WINDOWS\system32\ddcdbxw.dll
2007-11-03 21:01 <DIR> d-------- C:\Program Files\YouTube Downloader
2007-10-31 20:04 12,208 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-10-31 20:01 56 -r-hs---- C:\WINDOWS\system32\27733E6785.sys
2007-10-23 12:08 <DIR> d-------- C:\Program Files\uTorrent
2007-10-18 16:08 <DIR> d-------- C:\Program Files\Total Video Converter
2007-10-18 15:57 90,112 --a------ C:\WINDOWS\unvise32.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-16 16:04 --------- d-----w C:\Documents and Settings\Bojan\Application Data\uTorrent
2007-11-08 06:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-07 09:23 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-06 23:29 --------- d-----w C:\Program Files\XviD
2007-11-05 18:24 --------- d-----w C:\Program Files\PeerWeb DC++
2007-11-02 16:27 --------- d-----w C:\Documents and Settings\Bojan\Application Data\Skype
2007-11-01 15:17 --------- d-----w C:\Program Files\Google
2007-10-31 19:03 --------- d-----w C:\Program Files\DivX
2007-10-30 08:52 3,001 --sha-w C:\Documents and Settings\Bojan\ppUser.dat
2007-10-09 22:33 --------- d-----w C:\Program Files\MSN Messenger
2007-09-30 10:59 --------- d-----w C:\Program Files\EA SPORTS
2007-09-23 21:14 --------- d-----w C:\Documents and Settings\Bojan\Application Data\Nokia Multimedia Player
2007-09-22 19:31 --------- d-----w C:\Documents and Settings\Bojan\Application Data\Contrast
2007-09-22 19:26 --------- d-----w C:\Program Files\Contrast
2007-09-22 19:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Contrast
2007-09-22 19:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Laconic Software
2003-09-04 12:20 811,008 ----a-w C:\Program Files\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2520BA45-3D97-4864-82FF-F47F951727BA}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9B053E00-78D3-47AE-B763-60FF36FF2886}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-14 22:53 144480 --a------ C:\WINDOWS\system32\ubodpnte.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b7465988-49f1-420b-8a16-59d52bb4808e}]
2007-11-16 13:39 81984 --a------ C:\WINDOWS\system32\lpfqadhp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\ubodpnte.dll [2007-11-14 22:53 144480]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 16:36]
"RegistryMechanic"="" []
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-14 00:01]
"68c63ec9"="C:\WINDOWS\system32\xikniwto.dll" [2007-11-16 13:38]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll 2005-01-31 14:13 49152 C:\PROGRA~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ubodpnte]
ubodpnte.dll 2007-11-14 22:53 144480 C:\WINDOWS\system32\ubodpnte.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljgg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fantastic Flame Agent.lnk]
backup=C:\WINDOWS\pss\Fantastic Flame Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
backup=C:\WINDOWS\pss\Metacafe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Bojan^Start Menu^Programs^Startup^Metacafe.lnk]
backup=C:\WINDOWS\pss\Metacafe.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\68c63ec9]
rundll32.exe "C:\WINDOWS\system32\lcqbpvte.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANR]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreePDF Assistant]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
"C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2 (0x2)
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 16:06:46 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-11-15 08:14:06 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2007-11-16 17:07:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\ubodpnte.dllbox 20810 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2007-11-16 17:09:17 - machine was rebooted
.
--- E O F ---
|