offline
- Pridružio: 17 Jul 2005
- Poruke: 3097
- Gde živiš: "Daleko od Negdje"
|
ComboFix 08-11-21.05 - Compaq_Administrator 2008-11-25 19:16:25.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.765 [GMT -7:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-26 to 2008-11-26 )))))))))))))))))))))))))))))))
.
2008-11-22 08:23 . 2008-11-22 08:23 <DIR> d--h----- C:\_Memeo
2008-11-21 19:25 . 2008-11-25 15:18 4,782 --a------ C:\logfile
2008-11-20 20:06 . 2008-11-20 20:06 <DIR> d-------- c:\program files\Avira
2008-11-20 20:06 . 2008-11-20 20:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-17 13:04 . 2008-11-17 13:04 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-12 06:50 . 2008-11-22 09:29 <DIR> d-------- c:\program files\Picasa2
2008-11-12 06:44 . 2008-11-12 06:44 <DIR> d-------- c:\program files\CCleaner
2008-11-12 06:43 . 2008-11-12 06:43 <DIR> d-------- c:\program files\Common Files\eSellerate
2008-11-12 06:41 . 2008-11-12 06:41 <DIR> d-------- c:\program files\Western Digital Technologies
2008-11-12 06:41 . 2008-11-12 06:43 <DIR> d-------- c:\program files\Memeo
2008-11-12 06:41 . 2008-11-12 06:43 <DIR> d---s---- c:\documents and settings\All Users\Application Data\Memeo
2008-11-10 21:47 . 2008-11-10 21:47 <DIR> d-------- c:\program files\iPod
2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-04 06:38 . 2008-02-05 19:20 628,760 -ra------ c:\windows\system32\drivers\lvrs.sys
2008-11-04 06:38 . 2008-02-05 18:40 25,056 -ra------ c:\windows\system32\Repository.reg
2008-11-04 06:37 . 2008-11-25 15:07 0 --a------ c:\windows\system32\drivers\lvuvc.hs
2008-11-04 06:36 . 2008-02-05 19:21 4,658,456 -ra------ c:\windows\system32\drivers\lvuvc.sys
2008-11-04 06:36 . 2008-02-05 19:21 490,008 -ra------ c:\windows\system32\LVUI2.dll
2008-11-04 06:36 . 2008-02-05 19:21 465,432 -ra------ c:\windows\system32\LVUI2RC.dll
2008-11-04 06:36 . 2008-02-05 19:18 416,280 -ra------ c:\windows\system32\lvcodec2.dll
2008-11-04 06:36 . 2008-02-05 19:18 195,096 -ra------ c:\windows\system32\lvci11701196.dll
2008-11-04 06:36 . 2008-02-05 18:37 66,482 -ra------ c:\windows\system32\lvcoinst.ini
2008-11-04 06:36 . 2008-02-05 19:21 41,752 -ra------ c:\windows\system32\drivers\LVUSBSta.sys
2008-11-04 06:36 . 2008-02-05 19:21 23,832 -ra------ c:\windows\system32\drivers\lvuvcflt.sys
2008-11-04 06:36 . 2008-11-25 15:07 0 --a------ c:\windows\system32\drivers\logiflt.iad
2008-11-04 00:19 . 2008-11-04 00:19 <DIR> d-------- c:\windows\system32\IOSUBSYS
2008-11-04 00:00 . 2008-11-03 23:59 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-03 22:03 . 2008-11-03 22:03 127,034 -r------- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2008-11-03 21:58 . 2008-11-03 22:03 <DIR> d-------- c:\program files\Logitech
2008-11-03 21:58 . 2008-11-04 06:36 <DIR> d-------- c:\program files\Common Files\LogiShrd
2008-11-03 21:58 . 2008-11-03 21:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logitech
2008-11-03 21:58 . 2008-11-03 21:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logishrd
2008-11-03 21:06 . 2008-11-03 21:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Last.fm
2008-11-03 21:05 . 2008-11-03 21:05 <DIR> d-------- c:\program files\Last.fm
2008-11-03 20:46 . 2008-11-03 20:46 <DIR> d-------- c:\program files\Western Digital
2008-11-03 20:27 . 2008-08-14 03:00 2,180,352 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-03 20:27 . 2008-08-14 02:58 2,136,064 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-03 20:27 . 2008-08-14 02:22 2,057,728 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-03 20:27 . 2008-08-14 02:22 2,015,744 --------- c:\windows\system32\dllcache\ntkrpamp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 13:24 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-11-25 13:13 --------- d-----w c:\program files\ScreenshotCaptor
2008-11-22 16:27 --------- d-----w c:\program files\Google
2008-11-20 13:31 --------- d-----w c:\program files\Java
2008-11-20 13:29 --------- d-----w c:\program files\Bonjour
2008-11-12 13:44 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-12 13:43 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-11 04:48 --------- d-----w c:\program files\iTunes
2008-11-11 04:42 --------- d-----w c:\program files\QuickTime
2008-11-11 04:40 --------- d-----w c:\program files\Common Files\Apple
2008-11-04 13:30 --------- d-----w c:\program files\Microsoft Silverlight
2008-11-04 04:19 --------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\Shareaza
2008-11-04 04:12 --------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\Skype
2008-10-24 11:10 453,632 ------w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 21:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 21:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 16:57 332,800 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-11 01:54 --------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\skypePM
2008-10-11 01:51 --------- d-----w c:\program files\Skype
2008-10-11 01:51 --------- d-----w c:\program files\Common Files\Skype
2008-10-11 01:51 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-07 00:51 24 ----a-w c:\documents and settings\Compaq_Administrator\jagex_runescape_preferences.dat
2008-10-03 17:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-10-01 20:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-30 23:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-26 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ------w c:\windows\system32\dllcache\msxml3.dll
2008-08-30 03:06 1,350,664 ----a-w c:\windows\system32\msxml6.dll
2008-08-29 17:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-08-29 16:53 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-08-28 10:04 333,056 ------w c:\windows\system32\dllcache\srv.sys
2008-08-27 08:24 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-05-21 00:47 47,736 ----a-w c:\documents and settings\Compaq_Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-11-22_ 9.11.46.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-22 15:20:12 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-25 10:51:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-22 15:20:12 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-25 10:51:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-22 15:20:12 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-25 10:51:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-25 22:08:30 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_1f4.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 180,269 2006-06-16 05:57:43 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 180,269 2006-06-16 05:57:43 c:\program files\Common Files\Real\Update_OB\realsched.exe
----a-w 249,856 2006-02-16 05:34:58 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe
----a-w 249,856 2006-02-16 05:34:58 c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
----a-w 49,152 2006-02-19 09:41:10 c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 49,152 2006-02-19 08:41:10 c:\program files\HP\HP Software Update\hpwuSchd2.exe
----a-w 282,624 2007-01-01 21:11:46 c:\program files\QuickTime\bak\qttask.exe
----a-w 413,696 2008-09-06 22:09:14 c:\program files\QuickTime\QTTask.exe
----a-w 4,468,736 2006-11-04 10:28:18 c:\program files\Shareaza\bak\Shareaza.exe
----a-w 129,536 2006-07-21 23:19:46 c:\program files\Yahoo!\browser\bak\ybrwicon.exe
----a-w 663,552 2004-12-14 09:23:44 c:\windows\CREATOR\bak\Remind_XP.exe
----a-w 663,552 2004-12-14 09:23:44 c:\windows\CREATOR\Remind_XP.exe
----a-w 67,584 2005-09-30 04:01:14 c:\windows\ehome\bak\ehtray.exe
----a-w 67,584 2005-09-30 04:01:14 c:\windows\ehome\ehtray.exe
----a-w 237,568 2005-07-23 05:14:00 c:\windows\SMINST\bak\RECGUARD.EXE
----a-w 237,568 2005-07-23 05:14:00 c:\windows\SMINST\Recguard.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-09 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Aim6"="c:\program files\AIM6\aim6.exe" [2007-12-18 50528]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 95800]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"LogitechSetup"="F:\setup.exe" [N/A]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-11-22 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-06-15 180269]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-03 136600]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-22 29744]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-20 366400]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]
"nwiz"="nwiz.exe" [2006-01-24 c:\windows\system32\nwiz.exe]
"PCDrProfiler"="" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-20 366400]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-02-20 282624]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 16423]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-11-03 66864]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-01-08 24652]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-11-04 628760]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-22 29744]
S4 AutoSyncService;Memeo AutoSync ;"c:\program files\Memeo\AutoSync\MemeoService.exe" [2007-07-06 31768]
.
Contents of the 'Scheduled Tasks' folder
2008-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\u3ax5njc.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 19:20:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-11-25 19:24:02
ComboFix-quarantined-files.txt 2008-11-26 02:22:41
ComboFix2.txt 2008-11-25 13:46:29
ComboFix3.txt 2008-11-22 16:14:44
Pre-Run: 127,100,248,064 bytes free
Post-Run: 127,078,232,064 bytes free
243 --- E O F --- 2008-11-12 10:06:46
Jel' lici ovo i na sta?
|