offline
- Pridružio: 01 Mar 2008
- Poruke: 245
|
ComboFix 08-11-18.A2 - VooDoo 2008-11-19 23:19:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.204 [GMT 1:00]
Running from: c:\documents and settings\VooDoo\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\SZComp5.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-19 to 2008-11-19 )))))))))))))))))))))))))))))))
.
2008-11-19 19:36 . 2008-11-19 19:37 1,120 --a------ c:\windows\system32\drivers\kgpfr2.cfg
2008-11-19 18:36 . 2008-11-19 22:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\SITEguard
2008-11-18 19:46 . 2008-11-18 19:46 <DIR> d-------- c:\program files\Skype
2008-11-18 19:46 . 2008-11-18 19:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2008-11-16 17:19 . 2008-11-16 17:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-15 22:24 . 2008-11-15 22:24 428,365 --a------ c:\windows\system32\BtAssSvc.exe
2008-11-15 17:42 . 2008-11-15 17:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\PY_Software
2008-11-15 16:46 . 2008-11-15 16:46 <DIR> d-------- c:\program files\Macrogaming
2008-11-15 16:45 . 2008-11-15 16:45 <DIR> d-------- c:\program files\IGC
2008-11-15 16:45 . 2003-03-18 22:20 1,060,864 --------- c:\windows\system32\MFC7ec9b.rra
2008-11-15 16:45 . 2003-03-18 21:14 499,712 --------- c:\windows\system32\msvced47.rra
2008-11-15 16:45 . 2003-02-21 05:42 348,160 --------- c:\windows\system32\msvcedb4.rra
2008-11-15 16:45 . 2003-05-28 12:19 245,408 -r------- c:\windows\system32\unicows.dll
2008-11-15 16:42 . 2008-11-15 16:42 <DIR> d-------- c:\program files\Common Files\Xara
2008-11-15 16:40 . 2008-11-15 16:42 <DIR> d-------- c:\program files\Xara
2008-11-15 16:38 . 2008-11-15 16:39 <DIR> d-------- c:\program files\Antenna
2008-11-15 16:31 . 2008-11-15 16:31 <DIR> d-------- c:\program files\Bonjour
2008-11-15 16:20 . 2008-11-15 16:20 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-15 16:18 . 2008-11-15 22:31 <DIR> d-------- c:\program files\Actual Drawing
2008-11-15 16:16 . 2008-11-15 16:44 <DIR> d-------- c:\program files\A4Desk
2008-11-15 16:14 . 2008-11-15 16:15 <DIR> d-------- c:\program files\iColorFolder
2008-11-13 21:29 . 2008-11-13 21:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\MumboJumbo
2008-11-13 21:29 . 2008-11-13 21:29 22 --a------ c:\windows\msnmsgr.exe.ini
2008-11-13 20:57 . 2008-11-13 20:58 69 --a------ c:\windows\NeroDigital.ini
2008-11-13 19:27 . 2008-11-19 12:39 32 --a------ c:\windows\CatElett.INI
2008-11-13 18:22 . 2008-11-13 18:22 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-12 20:48 . 2001-08-17 13:57 16,128 --a------ c:\windows\system32\drivers\MODEMCSA.sys
2008-11-12 20:48 . 2001-08-17 13:57 16,128 --a--c--- c:\windows\system32\dllcache\modemcsa.sys
2008-11-12 15:06 . 2008-11-12 15:06 0 --a------ c:\windows\Irremote.ini
2008-11-12 12:58 . 2008-11-12 12:58 40 --a------ c:\windows\nero.INI
2008-11-11 14:35 . 2008-11-11 14:35 364,544 -ra------ c:\windows\system32\IS3DBA5.dll
2008-11-10 23:32 . 2008-11-10 23:32 <DIR> d-------- c:\program files\Stardock
2008-11-10 23:32 . 2008-11-10 23:32 <DIR> d-------- c:\program files\Common Files\Stardock
2008-11-10 21:59 . 2008-11-10 21:59 <DIR> d-------- c:\windows\system32\CatRoot_bak
2008-11-10 19:14 . 2008-08-14 10:58 2,136,064 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-10 19:14 . 2008-08-14 10:22 2,015,744 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-10 14:21 . 2008-06-13 14:10 272,128 --------- c:\windows\system32\drivers\bthport.sys
2008-11-10 14:21 . 2008-06-13 14:10 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-11-10 00:33 . 2008-11-13 11:25 <DIR> d--h----- c:\windows\$hf_mig$
2008-11-10 00:33 . 2005-02-25 04:35 22,752 --a------ c:\windows\system32\spupdsvc.exe
2008-11-09 23:54 . 2008-11-09 23:54 <DIR> d---s---- c:\documents and settings\VooDoo\UserData
2008-11-09 19:11 . 2007-07-30 19:19 271,224 --a------ c:\windows\system32\mucltui.dll
2008-11-09 19:11 . 2007-07-30 19:19 207,736 --a------ c:\windows\system32\muweb.dll
2008-11-09 19:11 . 2007-07-30 19:19 30,072 --a------ c:\windows\system32\mucltui.dll.mui
2008-11-09 19:04 . 2008-11-09 19:04 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-09 19:04 . 2008-11-09 19:04 <DIR> d-------- c:\program files\Adobe Media Player
2008-11-09 18:48 . 2008-11-11 18:14 <DIR> d-------- c:\program files\Lexmark X1100 Series
2008-11-09 18:48 . 2001-08-17 22:36 87,040 --a------ c:\windows\system32\wiafbdrv.dll
2008-11-09 18:48 . 2001-08-17 22:36 87,040 --a--c--- c:\windows\system32\dllcache\wiafbdrv.dll
2008-11-09 18:48 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-11-09 18:48 . 2004-08-03 22:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-11-09 18:40 . 2008-11-09 18:40 101 --a------ c:\windows\lexstat.ini
2008-11-09 18:33 . 2008-11-09 18:33 <DIR> d-------- c:\program files\ACD Systems
2008-11-09 18:33 . 2008-11-09 18:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\ACD Systems
2008-11-09 18:30 . 2008-11-09 18:30 <DIR> d-------- c:\documents and settings\VooDoo\WINDOWS
2008-11-09 18:26 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-11-09 18:26 . 2004-08-03 23:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-11-09 18:16 . 2008-11-09 18:16 <DIR> d-------- c:\documents and settings\VooDoo\Application Data\ACD Systems
2008-11-09 18:15 . 2008-11-09 18:34 <DIR> d-------- c:\program files\Common Files\ACD Systems
2008-11-09 17:13 . 2008-11-09 15:16 58,952 --a------ c:\windows\system32\MsgPlusLoader.dll
2008-11-09 17:11 . 2008-11-09 17:11 <DIR> d-------- c:\documents and settings\VooDoo\Application Data\Uniblue
2008-11-09 16:42 . 2008-11-09 16:42 <DIR> d-------- c:\program files\Common Files\xing shared
2008-11-09 16:42 . 2008-11-09 16:42 25 --a------ c:\windows\cdplayer.ini
2008-11-09 16:41 . 2008-11-09 16:41 <DIR> d-------- c:\program files\Real
2008-11-09 16:41 . 2008-11-09 16:42 <DIR> d-------- c:\program files\Common Files\Real
2008-11-09 16:37 . 2008-01-12 14:13 <DIR> d-------- c:\program files\Ahead
2008-11-09 16:22 . 2008-11-09 16:22 <DIR> d-------- c:\program files\uTorrent
2008-11-09 16:22 . 2008-11-15 17:53 <DIR> d-------- c:\documents and settings\VooDoo\Application Data\uTorrent
2008-11-09 16:19 . 2008-11-09 16:19 0 --a------ c:\windows\nsreg.dat
2008-11-09 15:53 . 2008-11-09 15:53 <DIR> d-------- c:\program files\Common Files\iS3
2008-11-09 15:53 . 2008-11-19 18:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\ZILLAbar
2008-11-09 15:53 . 2008-11-19 23:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\STOPzilla!
2008-11-09 15:25 . 2008-11-11 16:23 <DIR> d-------- c:\documents and settings\VooDoo\Contacts
2008-11-09 15:24 . 2008-11-09 15:24 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-09 15:22 . 2008-11-09 15:24 <DIR> d-------- c:\program files\Windows Live
2008-11-09 15:22 . 2008-11-09 15:23 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-11-09 15:22 . 2008-11-09 15:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-09 15:16 . 2008-11-09 15:16 <DIR> d-------- c:\program files\MessengerPlus! 3
2008-11-09 15:09 . 2008-11-09 15:11 <DIR> d-------- c:\program files\RegCleaner
2008-11-09 15:09 . 2008-11-09 15:09 <DIR> d-------- c:\program files\CCleaner
2008-11-09 14:46 . 2003-06-18 17:31 17,920 --a------ c:\windows\system32\mdimon.dll
2008-11-09 14:45 . 2008-11-09 14:45 <DIR> d-------- c:\program files\Common Files\L&H
2008-11-09 14:44 . 2008-11-09 14:44 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-09 14:44 . 2008-11-09 14:44 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-11-09 14:43 . 2008-11-09 14:44 <DIR> d-------- c:\windows\SHELLNEW
2008-11-09 14:43 . 2008-11-09 14:44 <DIR> d-------- c:\program files\Microsoft Works
2008-11-09 14:16 . 2008-11-09 14:16 <DIR> d-------- c:\program files\Microsoft
2008-11-09 14:15 . 2008-11-09 15:03 478 --a------ c:\windows\ODBC.INI
2008-11-09 14:14 . 2008-11-09 14:14 <DIR> d-------- c:\program files\Alwil Software
2008-11-09 14:14 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-11-09 14:14 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\MSVCP71.dll
2008-11-09 14:14 . 2003-02-21 04:42 348,160 --a------ c:\windows\system32\MSVCR71.dll
2008-11-09 14:12 . 2008-11-09 14:13 <DIR> d-------- c:\program files\TuneUp Utilities 2007
2008-11-09 14:12 . 2008-11-09 14:12 <DIR> d-------- c:\documents and settings\VooDoo\Application Data\TuneUp Software
2008-11-09 14:12 . 2007-03-29 04:42 29,704 --a------ c:\windows\system32\uxtuneup.dll
2008-11-09 14:11 . 2008-11-09 14:11 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-09 14:11 . 2008-11-09 14:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-09 14:07 . 2008-11-09 14:25 <DIR> d-------- C:\totalcmd
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\UC.PIF
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\RAR.PIF
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\PKZIP.PIF
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\PKUNZIP.PIF
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\NOCLOSE.PIF
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\LHA.PIF
2008-11-09 14:07 . 2005-04-30 06:52 545 --a------ c:\windows\ARJ.PIF
2008-11-09 14:07 . 2008-11-10 23:27 445 --a------ c:\windows\wincmd.ini
2008-11-09 14:03 . 2008-11-18 19:46 <DIR> d-------- c:\documents and settings\VooDoo\Application Data\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 18:37 --------- d-----w c:\program files\STOPzilla!
2008-11-15 15:45 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-15 15:41 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-15 15:31 --------- d-----w c:\program files\Common Files\Adobe
2008-11-13 10:54 --------- d-----w c:\program files\Common Files\Nero
2008-11-13 10:52 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-11-09 18:32 --------- d-----w c:\program files\DC++
2008-11-09 16:45 --------- d-----w c:\program files\Google
2008-11-09 12:58 --------- d-----w c:\program files\Winamp
2008-11-09 12:58 --------- d-----w c:\documents and settings\VooDoo\Application Data\Winamp
2008-11-09 12:57 --------- d-----w c:\program files\Winamp Toolbar
2008-11-09 12:57 --------- d-----w c:\program files\Winamp Remote
2008-11-09 12:57 --------- d-----w c:\documents and settings\All Users\Application Data\Winamp Toolbar
2008-11-09 12:57 --------- d-----w c:\documents and settings\All Users\Application Data\OrbNetworks
2008-11-09 12:51 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-11-09 12:50 --------- d-----w c:\program files\Combined Community Codec Pack
2008-11-09 12:45 --------- d-----w c:\documents and settings\VooDoo\Application Data\STOPzilla!
2008-11-09 12:44 --------- d-----w c:\program files\TotalAudioConverter
2008-11-09 12:44 --------- d-----w c:\documents and settings\VooDoo\Application Data\Softplicity
2008-11-09 12:43 --------- d-----w c:\program files\YouTube Downloader
2008-11-09 12:43 --------- d-----w c:\program files\ODM
2008-11-09 12:42 4,608 ----a-w c:\windows\system32\w95inf32.dll
2008-11-09 12:42 2,272 ----a-w c:\windows\system32\w95inf16.dll
2008-11-09 12:42 --------- d-----w c:\program files\directx
2008-11-09 12:42 --------- d-----w c:\program files\ArcSoft
2008-11-09 12:08 --------- d-----w c:\program files\microsoft frontpage
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 09:01 17,408 ----a-r c:\windows\system32\SZIO5.dll
2008-10-23 09:00 278,528 ----a-r c:\windows\system32\SZBase5.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 -c--a-w c:\windows\system32\wups.dll
2008-10-08 12:27 49,664 ----a-r c:\windows\system32\drivers\SZKG.sys
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-29 12:08 126,976 ----a-r c:\windows\system32\IS3HTUI5.dll
2008-09-29 12:07 61,440 ----a-r c:\windows\system32\IS3Hks5.dll
2008-09-29 12:07 372,736 ----a-r c:\windows\system32\IS3UI5.dll
2008-09-29 12:07 23,040 ----a-r c:\windows\system32\IS3XDat5.dll
2008-09-29 12:06 94,208 ----a-r c:\windows\system32\IS3Inet5.dll
2008-09-29 12:06 90,112 ----a-r c:\windows\system32\IS3Svc5.dll
2008-09-29 12:06 212,992 ----a-r c:\windows\system32\IS3Win325.dll
2008-09-29 12:03 708,608 ----a-r c:\windows\system32\IS3Base5.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-20 05:38 659,456 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=MsgPlusLoader.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 szkg5;szkg5;c:\windows\system32\drivers\szkg.sys [2008-10-08 49664]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-09 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-09 20560]
R2 BluetoothAssistant;Bluetooth Assistant;c:\windows\system32\BtAssSvc.exe [2008-11-15 428365]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe -k netsvcs [2002-12-31 14336]
R3 snpstd2;VideoCAM Look;c:\windows\system32\DRIVERS\snpstd2.sys [2004-07-28 334080]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;"c:\program files\Windows Live\Messenger\usnsvc.exe" [2007-10-18 98328]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-11-09 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-27 06:51]
2008-11-19 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\VooDoo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-09 23:12]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\VooDoo\Application Data\Mozilla\Firefox\Profiles\b6x4i2ic.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://btjunkie.org/
FF -: plugin - c:\documents and settings\VooDoo\Local Settings\Application Data\Google\Update\1.2.131.27\npGoogleOneClick6.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-19 23:21:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-19 23:23:26
ComboFix-quarantined-files.txt 2008-11-19 22:23:00
Pre-Run: 7.853.207.552 bytes free
Post-Run: 7,859,580,928 bytes free
241 --- E O F --- 2008-11-14 12:02:34
Dopuna: 20 Nov 2008 12:47
Posle ovoga mi STOPzilla javlja da je hijack inficiran i sad jel to treba obrisati ili ne...
|