ComboFix 07-11-08.1 - Operater123 2007-11-17 17:30:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.381.1033.18.1008 [GMT 1:00]
Running from: C:\Documents and Settings\Operater123\Local Settings\Temporary Internet Files\Content.IE5\QB61YDG5\ComboFix[4].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\Operater123\Application Data\install.dat
C:\Documents and Settings\Operater123\ravmonlog
C:\Program Files\bravesentry
C:\Program Files\bravesentry\BraveSentry0.bs
C:\Program Files\bravesentry\BraveSentry1.bs
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\devenu.dll
C:\WINDOWS\system32\dllh8jkd1q8(2).exe
C:\WINDOWS\system32\dllh8jkd1q8(3).exe
C:\WINDOWS\system32\drivers\jwoxwojj.dat
C:\WINDOWS\system32\drivers\vswzpvnv.dat
C:\WINDOWS\system32\kr_done1
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\vx.tll
C:\WINDOWS\system32\winsub.xml
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NEVMZAZH
-------\nevmzazh
-------\nm
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 17:08 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 19:27 3,499 --a------ C:\WINDOWS\mozver.dat
2007-11-06 17:11 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-11-06 17:11 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-11-06 17:10 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-11-06 17:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-06 17:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-11-06 17:10 4,118,048 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-06 17:10 43,808 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-06 17:09 <DIR> d-------- C:\kav
2007-11-06 16:35 <DIR> d---s---- C:\Documents and Settings\Operater123\UserData
2007-11-06 15:31 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-11-06 14:07 15,360 --a------ C:\WINDOWS\system32\drivers\NetMotCM.sys
2007-11-06 13:14 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2007-11-06 13:14 <DIR> d-------- C:\Documents and Settings\Operater123\Application Data\Thunderbird
2007-11-06 13:14 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-05 14:07 1 --a------ C:\WINDOWS\system32\rc.dat
2007-11-05 14:07 1 --a------ C:\WINDOWS\system32\ps1.dat
2007-11-05 14:07 1 --a------ C:\WINDOWS\system32\cookie1.dat
2007-10-22 17:04 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-10-22 17:04 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-10-17 13:04 <DIR> d-------- C:\Program Files\Milka
2007-10-17 13:04 4,096 --a------ C:\WINDOWS\d3dx.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 17:00 59,360 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 17:00 5,132 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-05 13:25 --------- d-----w C:\Program Files\Microsoft Visual FoxPro 9
2007-11-05 13:25 --------- d-----w C:\Program Files\Microsoft Visual FoxPro 7
2007-11-05 13:24 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-11-05 13:24 --------- d-----w C:\Program Files\HTML Help Workshop
2007-11-05 13:21 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-10-14 15:02 --------- d-----w C:\Documents and Settings\Operater123\Application Data\Image Zone Express
2007-10-14 12:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Barbie Fashion Show
2007-10-14 12:05 --------- d-----w C:\Program Files\Common Files\Vivendi Universal Games
2007-10-14 12:05 --------- d-----w C:\Program Files\Barbie(TM)
2007-10-14 09:37 --------- d-----w C:\Program Files\EA GAMES
2007-10-13 13:55 --------- d-----w C:\Documents and Settings\Operater123\Application Data\Media Player Classic
2007-10-13 12:38 --------- d-----w C:\Documents and Settings\Operater123\Application Data\HP
2007-10-13 12:11 --------- d-----w C:\Program Files\HP
2007-10-13 12:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2007-10-13 12:10 --------- d-----w C:\Program Files\Common Files\HP
2007-10-13 12:09 --------- d-----w C:\Program Files\Hewlett-Packard
2007-10-13 10:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-13 10:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-13 10:39 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-13 10:39 --------- d-----w C:\Documents and Settings\Operater123\Application Data\InstallShield
2007-10-09 16:02 --------- d-----w C:\Documents and Settings\Operater123\Application Data\CyberLink
2007-10-09 16:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-09 16:01 --------- d-----w C:\Program Files\CyberLink
2007-10-07 10:59 --------- d-----w C:\Program Files\TuneUp Utilities 2006
2007-10-07 10:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-07 10:59 --------- d-----w C:\Documents and Settings\Operater123\Application Data\TuneUp Software
2007-10-07 10:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-07 10:47 --------- d-----w C:\Documents and Settings\Operater123\Application Data\Canon
2007-10-01 15:26 --------- d-----w C:\Program Files\Genie-Soft
2007-09-27 17:33 --------- d-----w C:\Documents and Settings\Operater123\Application Data\Ahead
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 16:06 C:\WINDOWS\system32\ptipbmf.dll]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 19:24]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 01:41]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-05-16 16:58]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 18:25]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{07157305-3d1a-11dc-adda-806d6172696f}]
\Shell\AutoRun\command - E:\autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 16:16:25 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2007-11-17 18:01:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 18:02:29 - machine was rebooted
.
--- E O F ---
Dopuna: 17 Nov 2007 19:37
Veliko hvala i Vama i Dubari,koji me uputio na Vas!
Rijesili ste moj problem.
Veliki pozdrav iz Doboja!
MELJO
|