offline
- Darko_M18
- Novi MyCity građanin
- Pridružio: 24 Feb 2008
- Poruke: 4
|
Evo sta mi daje kad zavrsi sa skeniranjem
ComboFix 08-02-24.4 - Monev 2008-02-24 14:39:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.215 [GMT 1:00]
Running from: E:\New Folder\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.
2008-02-21 13:37 . 2008-02-21 13:37 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-02-21 13:35 . 2002-11-27 12:30 237,624 -ra------ C:\WINDOWS\system32\HPZidr12.dll
2008-02-21 13:35 . 2002-11-27 12:30 172,032 -ra------ C:\WINDOWS\system32\HPZipr12.dll
2008-02-21 13:35 . 2002-11-27 12:30 94,208 -ra------ C:\WINDOWS\system32\HPZipt12.dll
2008-02-21 13:35 . 2002-11-27 12:30 65,536 -ra------ C:\WINDOWS\system32\HPZipm12.exe
2008-02-21 13:35 . 2002-11-27 12:30 61,440 -ra------ C:\WINDOWS\system32\HPZinw12.exe
2008-02-21 13:35 . 2002-11-27 12:30 57,344 -ra------ C:\WINDOWS\system32\HPZisn12.dll
2008-02-21 13:35 . 2002-11-27 12:30 50,960 -ra------ C:\WINDOWS\system32\drivers\hpzid412.sys
2008-02-21 13:35 . 2002-12-03 03:04 20,639 --------- C:\WINDOWS\hpoins01.dat
2008-02-21 13:35 . 2002-12-03 03:04 16,622 --------- C:\WINDOWS\hpomdl01.dat
2008-02-21 13:35 . 2002-11-27 12:30 16,080 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-02-21 13:32 . 2002-11-27 12:30 22,384 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-02-21 13:31 . 2002-08-29 01:50 24,960 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-21 13:31 . 2002-08-29 01:50 24,960 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-21 13:30 . 2002-11-27 12:30 561,152 -ra------ C:\WINDOWS\system32\hpotscl.dll
2008-02-21 13:30 . 2002-11-27 12:30 274,432 -ra------ C:\WINDOWS\system32\hpgwiamd.dll
2008-02-21 13:30 . 2002-11-27 12:29 237,568 -ra------ C:\WINDOWS\system32\HPZc3212.dll
2008-02-21 13:30 . 2002-11-27 12:30 94,208 -ra------ C:\WINDOWS\system32\hpovst08.dll
2008-02-21 13:30 . 2002-08-29 01:48 14,208 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-21 13:30 . 2002-08-29 01:48 14,208 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-21 13:26 . 2002-08-29 01:32 28,160 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-21 13:26 . 2002-08-29 01:32 28,160 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-17 14:35 . 2008-02-19 12:58 45 --a------ C:\TEST.XML
2008-02-16 22:03 . 2002-08-29 02:01 134,272 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-02-16 22:03 . 2002-08-29 02:01 134,272 --a--c--- C:\WINDOWS\system32\dllcache\portcls.sys
2008-02-16 22:03 . 2002-08-29 01:32 57,856 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-02-16 22:03 . 2002-08-29 01:32 57,856 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys
2008-02-16 22:02 . 2000-10-20 11:28 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-02-16 22:02 . 2001-11-23 05:08 712,704 --a------ C:\WINDOWS\system32\Audio3D.dll
2008-02-16 22:02 . 2001-11-23 05:08 712,704 --a------ C:\WINDOWS\system32\a3d.dll
2008-02-16 22:02 . 2002-09-30 13:24 417,999 --a------ C:\WINDOWS\system32\drivers\cmuda.sys
2008-02-16 22:02 . 2002-08-12 12:18 380,928 --a------ C:\WINDOWS\system\cmicnfg.cpl
2008-02-16 22:02 . 2002-09-30 10:02 49,152 --a------ C:\WINDOWS\system32\cmuda.dll
2008-02-16 22:02 . 2002-08-01 06:54 28,672 --a------ C:\WINDOWS\system32\udaprop.dll
2008-02-16 22:01 . 2008-02-16 22:01 <DIR> d-------- C:\Program Files\C-Media 3D Audio
2008-02-16 22:01 . 2000-10-24 17:12 352,256 --------- C:\WINDOWS\system32\ActiveSkin.ocx
2008-02-16 22:01 . 2002-07-01 12:01 212,992 --a------ C:\WINDOWS\CmiRmRedundDir.exe
2008-02-16 22:01 . 2002-10-04 12:20 188,416 --------- C:\WINDOWS\system32\CMIMPEG2V.ax
2008-02-16 22:01 . 2001-11-28 18:35 114,688 --------- C:\WINDOWS\system32\CMIEffect.ax
2008-02-16 22:01 . 2002-07-25 16:57 98,304 --------- C:\WINDOWS\system32\CMIVCDNav.ax
2008-02-16 22:01 . 2002-02-19 15:27 65,536 --------- C:\WINDOWS\system32\CMIEchoFilter.ax
2008-02-16 22:01 . 2002-06-28 16:37 61,440 --------- C:\WINDOWS\system32\CMICDDAFilter.ax
2008-02-16 22:01 . 2002-02-27 17:14 28,672 --------- C:\WINDOWS\CMIRmDriver.dll
2008-02-16 21:59 . 2008-02-16 21:59 76 --a------ C:\BIOSVIEW.INI
2008-02-14 16:45 . 2008-02-14 16:45 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-02-13 14:15 . 2008-02-13 14:15 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-13 13:49 . 2008-02-13 20:47 <DIR> d-------- C:\Documents and Settings\Monev\Application Data\AdobeUM
2008-02-13 13:32 . 2003-08-25 18:06 182,880 --a------ C:\WINDOWS\system32\iuenginenew.dll
2008-02-12 23:00 . 2008-02-12 23:00 <DIR> d-------- C:\Program Files\SsWin
2008-02-12 22:40 . 2008-02-12 22:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-12 17:40 . 2008-02-12 17:40 <DIR> d-------- C:\Program Files\TGTSoft
2008-02-12 15:51 . 2008-02-12 15:51 <DIR> d-------- C:\WINDOWS\Full Speed
2008-02-12 15:51 . 2008-02-12 15:56 <DIR> d-------- C:\Program Files\Full Speed
2008-02-12 12:11 . 2008-02-12 12:11 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-12 12:10 . 2008-02-12 12:34 2,941 --a------ C:\WINDOWS\mozver.dat
2008-02-11 14:17 . 2008-02-13 11:55 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-02-11 14:17 . 2008-02-11 14:17 <DIR> d-------- C:\Program Files\Crawler
2008-02-11 14:17 . 2008-02-11 14:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-02-10 12:33 . 2002-08-29 03:41 150,528 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-02-10 12:33 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-02-09 18:38 . 2008-02-16 22:02 92 --a------ C:\WINDOWS\CMISETUP.INI
2008-02-09 18:38 . 2008-02-16 22:02 26 --a------ C:\WINDOWS\CMCDPLAY.INI
2008-02-09 18:37 . 2002-10-09 11:12 237,568 --a------ C:\WINDOWS\CMIUninstall.exe
2008-02-09 18:37 . 2008-02-09 18:37 0 --a------ C:\WINDOWS\Wininit.ini
2008-02-09 18:36 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-02-09 13:47 . 2008-02-24 14:27 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-09 12:34 . 2008-02-23 17:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NFS Underground
2008-02-09 12:33 . 2008-02-09 12:33 <DIR> d-------- C:\Program Files\Common Files\DirectX
2008-02-08 10:01 . 2002-08-29 01:32 21,760 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-07 20:03 . 2008-02-07 20:03 <DIR> d-------- C:\Program Files\MSN Messenger
2008-02-07 19:59 . 2008-02-07 20:41 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-07 17:26 . 2008-02-07 17:26 <DIR> d---s---- C:\Documents and Settings\Monev\UserData
2008-02-07 17:25 . 2008-02-07 17:25 <DIR> d-------- C:\Program Files\Status
2008-02-07 17:20 . 2008-02-07 17:21 <DIR> d-------- C:\Program Files\Ares
2008-02-07 17:18 . 2008-02-07 17:19 <DIR> d-------- C:\Documents and Settings\Monev\Contacts
2008-02-07 17:15 . 2008-02-07 17:15 268 --ah----- C:\sqmdata00.sqm
2008-02-07 17:15 . 2008-02-07 17:15 244 --ah----- C:\sqmnoopt00.sqm
2008-02-07 17:14 . 2008-02-07 17:14 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-02-07 17:09 . 2008-02-13 11:55 <DIR> d-------- C:\Documents and Settings\Monev\Application Data\Spyware Terminator
2008-02-07 13:49 . 2008-02-07 13:49 <DIR> d-------- C:\Documents and Settings\Monev\Application Data\CyberLink
2008-02-07 13:48 . 2008-02-07 13:48 <DIR> d-------- C:\Documents and Settings\Monev\Application Data\TrojanHunter
2008-02-07 13:45 . 2008-02-07 13:45 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-02-07 13:45 . 2008-02-07 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-02-07 13:44 . 2008-02-07 13:44 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-07 13:41 . 2008-02-07 13:41 <DIR> d-------- C:\Program Files\Skype
2008-02-07 13:41 . 2008-02-07 13:41 <DIR> d-------- C:\Program Files\Google
2008-02-07 13:41 . 2008-02-07 13:41 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-02-07 13:41 . 2008-02-24 14:23 <DIR> d-------- C:\Documents and Settings\Monev\Application Data\Skype
2008-02-07 13:41 . 2008-02-07 13:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-02-07 13:26 . 2008-02-07 13:48 <DIR> d-------- C:\Program Files\TrojanHunter 4.7
2008-02-07 13:24 . 2008-02-07 13:29 <DIR> d-------- C:\Program Files\NetMeter
2008-02-07 13:22 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-02-07 13:22 . 2008-02-07 13:22 376 --a------ C:\WINDOWS\ODBC.INI
2008-02-07 13:19 . 2008-02-07 13:19 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-02-07 13:19 . 2008-02-07 13:19 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-02-07 13:18 . 2008-02-07 13:18 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-02-07 13:17 . 2008-02-07 13:17 <DIR> d-------- C:\Program Files\Microsoft Works
2008-02-07 13:16 . 2008-02-07 13:18 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-02-07 13:02 . 2008-02-07 13:01 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-02-07 13:02 . 2008-02-07 13:01 274,432 --a------ C:\WINDOWS\system32\imon.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 22:12 558,142 ----a-w C:\WINDOWS\java\Packages\4UVLV131.ZIP
2008-02-06 22:12 155,995 ----a-w C:\WINDOWS\java\Packages\K41JFFXR.ZIP
2008-02-06 22:12 --------- d-----w C:\Program Files\microsoft frontpage
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 04:41 13312]
"C:\Program Files\NetMeter\NetMeter.exe"="C:\Program Files\NetMeter\NetMeter.exe" [2007-08-11 15:50 331264]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2005-08-18 14:15 1359872]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-11-23 17:18 962560]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 08:18 307200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2002-09-27 07:44 47104 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 12:22 7700480]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 12:22 86016]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-02-07 13:01 921600]
"THGuard"="C:\Program Files\TrojanHunter 4.7\THGuard.exe" [2011-06-26 23:07 523264]
"SpywareTerminator"="C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe" [2008-02-07 17:13 2834432]
"Cmaudio"="cmicnfg.cpl" []
"FreeSpyKeylogger.exe"="C:\Program Files\Free Spy Keylogger\FreeSpyKeylogger.exe" [2006-03-20 11:10 224768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 04:41 13312]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 11:10:00 394856]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-11-23 17:18 962560 C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-07 12:28 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-02-07 12:59 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2003-12-13 01:50 33792 C:\Program Files\Winamp\winampa.exe
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\System32\drivers\sp_rsdrv2.sys [2008-02-07 17:14]
R2 BT848;BtCap, WDM Video Capture;C:\WINDOWS\System32\drivers\BT848.sys [2003-06-26 04:56]
R2 BTTUNER;MPEG.TV, WDM TvTuner;C:\WINDOWS\System32\drivers\BTTUNER.sys [2003-06-26 04:56]
R2 BTXBAR;MPEG.TV, WDM Crossbar;C:\WINDOWS\System32\drivers\BTXBAR.sys [2003-06-26 04:56]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 13:24:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-02-24 14:40:49
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\\Program Files\\NetMeter\\NetMeter.exe"="C:\\Program Files\\NetMeter\\NetMeter.exe"
.
Completion time: 2008-02-24 14:41:47
|