offline
- zeljko f
- Legendarni građanin
- Pridružio: 20 Jul 2008
- Poruke: 4682
|
ComboFix 08-11-05.02 - Administrator 2008-11-06 20:18:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.563 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system\oeminfo.ini
.
((((((((((((((((((((((((( Files Created from 2008-10-06 to 2008-11-06 )))))))))))))))))))))))))))))))
.
2008-11-02 16:22 . 2008-11-02 16:22 <DIR> d-------- c:\documents and settings\Administrator\Application Data\uniblue
2008-10-27 22:48 . 2008-10-27 22:48 410,976 --a------ c:\windows\system32\deploytk.dll
2008-10-25 13:11 . 2004-07-26 15:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
2008-10-25 13:11 . 2004-07-09 07:43 364,544 --------- c:\windows\system32\TwnLib4.dll
2008-10-25 13:11 . 2005-09-01 10:03 127,488 --------- c:\windows\system32\drivers\imagesrv.sys
2008-10-25 13:11 . 2000-06-26 09:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2008-10-25 13:11 . 2005-09-01 10:03 5,888 --------- c:\windows\system32\drivers\imagedrv.sys
2008-10-25 13:10 . 2001-07-09 09:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
2008-10-25 02:52 . 2008-10-25 02:52 <DIR> d-------- c:\program files\MSXML 4.0
2008-10-25 02:40 . 2008-10-15 17:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-25 02:23 . 2008-06-23 16:36 773,120 --a------ c:\windows\system32\NEROINSTAEC43759.DB
2008-10-25 02:22 . 2008-10-25 02:22 0 --a------ c:\windows\Irremote.ini
2008-10-24 23:03 . 2008-10-24 23:03 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Nero
2008-10-24 23:00 . 2008-10-25 13:06 <DIR> d-------- c:\program files\Common Files\Nero
2008-10-24 23:00 . 2008-10-25 13:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2008-10-16 15:50 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-16 15:44 . 2008-09-15 13:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-10-16 15:43 . 2008-08-14 11:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 15:43 . 2008-08-14 11:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-16 15:43 . 2008-08-14 10:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-16 15:43 . 2008-08-14 10:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-11 22:38 . 2008-10-11 22:38 3,120 --a------ c:\windows\system32\2JPNHCQE.ocx
2008-10-11 22:38 . 2008-10-11 22:38 3,120 --a------ c:\windows\6GNVR6C2.ocx
2008-10-10 23:00 . 2008-10-10 23:00 <DIR> d-------- c:\program files\Common Files\NSV
2008-10-09 16:12 . 2008-10-10 04:00 <DIR> d-------- c:\program files\AIMP2
2008-10-08 16:22 . 2008-10-10 04:00 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AIMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-06 16:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-06 14:44 --------- d-----w c:\program files\Spyware Doctor
2008-11-06 13:04 --------- d-----w c:\documents and settings\Administrator\Application Data\XnView
2008-11-06 13:02 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-05 21:17 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-04 17:59 --------- d-----w c:\program files\a-squared Free
2008-11-03 22:10 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2008-11-03 22:05 --------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
2008-11-02 00:57 --------- d-----w c:\program files\Defraggler
2008-10-27 21:50 --------- d-----w c:\program files\Java
2008-10-25 13:13 --------- d-----w c:\program files\Ahead
2008-10-25 12:10 --------- d-----w c:\program files\Common Files\Ahead
2008-10-24 13:48 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-23 18:29 --------- d-----w c:\program files\K-Lite Codec Pack
2008-10-22 14:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 14:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-08 21:37 --------- d-----w c:\documents and settings\Administrator\Application Data\Winamp
2008-10-05 21:27 --------- d-----w c:\program files\Winamp
2008-10-04 21:43 --------- d-----w c:\program files\WinASO
2008-10-04 21:20 --------- d-----w c:\documents and settings\Administrator\Application Data\TrojanHunter
2008-10-03 19:38 81,288 ----a-w c:\windows\system32\drivers\iksyssec.sys
2008-10-03 19:38 66,952 ----a-w c:\windows\system32\drivers\iksysflt.sys
2008-10-03 19:38 40,840 ----a-w c:\windows\system32\drivers\ikfilesec.sys
2008-10-03 19:27 --------- d-----w c:\documents and settings\Administrator\Application Data\PC Tools
2008-10-01 17:17 --------- d-----w c:\program files\ESET
2008-10-01 17:17 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-09-29 15:20 --------- d-----w c:\documents and settings\Administrator\Application Data\Simply Super Software
2008-09-28 17:18 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2008-09-28 17:18 --------- d-----w c:\documents and settings\Administrator\Application Data\Grisoft
2008-09-25 13:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-09-25 13:56 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\divx.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-15 05:11 --------- d-----w c:\program files\Common Files\Adobe
2008-09-15 04:55 --------- d-----w c:\documents and settings\All Users\Application Data\Adobe(2)
2008-09-14 15:16 --------- d-----w c:\documents and settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-09-14 15:14 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-09-13 17:19 --------- d-----w c:\program files\InCode Solutions
2008-09-12 20:12 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-09-12 20:12 --------- d-----w c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-09-12 13:18 --------- d-----w c:\program files\IObit
2008-09-12 08:20 --------- d-----w c:\documents and settings\Administrator\Application Data\IObit
2008-09-11 16:17 --------- d-----w c:\documents and settings\Administrator\Application Data\Smart PC Solutions
2008-09-10 14:31 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-09-10 14:31 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-09-10 14:31 --------- d-----w c:\program files\Real
2008-09-10 14:31 --------- d-----w c:\program files\Common Files\xing shared
2008-09-10 14:31 --------- d-----w c:\program files\Common Files\Real
2008-09-10 13:56 --------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-09-09 10:58 --------- d-----w c:\program files\Google
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-08-22 01:08 878,592 ----a-w c:\windows\system32\wininet.dll
2008-08-22 01:08 43,008 ----a-w c:\windows\system32\licmgr10.dll
2008-08-22 01:06 72,704 ----a-w c:\windows\system32\admparse.dll
2008-08-22 01:06 71,680 ----a-w c:\windows\system32\iesetup.dll
2008-08-22 01:06 434,176 ----a-w c:\windows\system32\vbscript.dll
2008-08-22 01:05 48,128 ----a-w c:\windows\system32\mshtmler.dll
2008-08-22 01:05 35,840 ----a-w c:\windows\system32\imgutil.dll
2008-08-22 01:04 45,568 ----a-w c:\windows\system32\mshta.exe
2008-08-22 00:57 156,160 ----a-w c:\windows\system32\msls31.dll
2008-08-14 10:11 2,189,184 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-08 19:54 724,992 ----a-w c:\windows\iun6002.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-30 32768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-05 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-05 114688]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-27 136600]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 c:\windows\RTHDCPL.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 04:42 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-09-10 15:31 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-10-27 152984]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\DRIVERS\l251x86.sys [2007-07-03 29696]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\149iuvmf.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-06 20:20:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-06 20:20:35
ComboFix-quarantined-files.txt 2008-11-06 19:20:32
Pre-Run: 21.603.360.768 bytes free
Post-Run: 21,594,189,824 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
183 --- E O F --- 2008-10-25 01:53:08
Sto me poplasi ovaj kombo, dao mi je da instaliram neku recovery consolu, jeli to treba tako.
|