Tu je log :
ComboFix 07-10-12.4 - zeke 2007-10-15 21:05:39.2 -
FAT32x86
Running from: F:\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-15 to 2007-10-15 )))))))))))))))))))))))))))))))
.
2007-10-14 17:46 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-14 17:37 <DIR> d-------- C:\Program Files\S3
2007-10-14 14:07 <DIR> d--hs---- C:\FOUND.000
2007-10-14 13:50 40,960 --a------ C:\WINDOWS\system32\s3hotkey.exe
2007-10-13 22:49 <DIR> d-------- C:\Program Files\Electronic Arts
2007-10-12 19:23 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\ICQ
2007-10-11 12:31 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\Thunderbird
2007-10-06 20:00 <DIR> d-------- C:\Terep
2007-10-05 15:39 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\ACD Systems
2007-10-05 15:37 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2007-10-05 15:37 <DIR> d-------- C:\Program Files\ACD Systems
2007-10-05 15:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems
2007-10-03 07:41 <DIR> d-------- C:\Program Files\Microprose
2007-10-02 15:42 <DIR> d-------- C:\Documents and Settings\zeke\.xmoto
2007-10-02 13:41 <DIR> d-------- C:\Program Files\ElastoManiaRegistered
2007-09-30 13:35 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\Apple Computer
2007-09-30 13:34 <DIR> d-------- C:\Program Files\iTunes
2007-09-30 13:34 <DIR> d-------- C:\Program Files\iPod
2007-09-30 13:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-30 13:31 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-09-30 13:31 <DIR> d-------- C:\Program Files\Apple Software Update
2007-09-30 13:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-09-30 13:21 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-09-30 13:16 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-09-30 13:16 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-09-28 16:22 <DIR> d-------- C:\Program Files\FLVPlayer
2007-09-28 11:58 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-09-28 11:42 <DIR> d-------- C:\WINDOWS\EHome
2007-09-27 14:55 <DIR> d-------- C:\Program Files\themexp
2007-09-27 14:55 <DIR> d-------- C:\Program Files\OneStepSearch
2007-09-27 11:28 61,440 --a------ C:\WINDOWS\system32\WMErrSKY.dll
2007-09-27 11:27 <DIR> d-------- C:\WINDOWS\system32\1051
2007-09-27 10:55 2,318,976 --a------ C:\WINDOWS\system32\TUKernel.exe
2007-09-27 10:46 <DIR> d-------- C:\Program Files\TuneUp Utilities 2007
2007-09-27 10:46 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\TuneUp Software
2007-09-27 10:46 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-09-27 10:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 10:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-09-24 21:13 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\Media Player Classic
2007-09-22 12:03 <DIR> d-------- C:\Program Files\Final Fantasy VII
2007-09-20 17:45 <DIR> d-------- C:\DRIVERS
2007-09-18 17:59 <DIR> d-------- C:\Program Files\QIP
2007-09-15 22:13 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\vlc
2007-09-15 21:14 <DIR> d-------- C:\Program Files\XMoto
2007-09-15 21:14 <DIR> d-------- C:\Program Files\ElastoMania111
2007-09-15 20:34 <DIR> d-------- C:\Program Files\CGN
2007-09-15 19:49 708,608 --a------ C:\WINDOWS\system32\Mxicd.dll
2007-09-15 19:49 268,672 --a------ C:\WINDOWS\system32\s3gsavmx.dll
2007-09-15 19:49 69,690 --a------ C:\WINDOWS\system32\S3uninst.exe
2007-09-15 19:27 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-09-15 19:13 2,854,400 --a------ C:\WINDOWS\system32\msi.dll
2007-09-15 18:53 <DIR> d-------- C:\Program Files\DriverScan
2007-09-15 16:28 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\DivX
2007-09-15 15:50 <DIR> d-------- C:\Intel
2007-09-15 15:17 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\Ahead
2007-09-15 14:16 <DIR> d-------- C:\Documents and Settings\zeke\WINDOWS
2007-09-15 13:50 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\Nokia
2007-09-15 12:06 <DIR> d-------- C:\Documents and Settings\zeke\Application Data\PC Suite
2007-09-15 10:45 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-09-15 10:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-09-15 09:10 <DIR> d-------- C:\Documents and Settings\ewa\Application Data\Thunderbird
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-14 19:41 --------- d-----w C:\Documents and Settings\ewa\Application Data\Media Player Classic
2007-09-14 19:39 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-09-14 16:45 --------- d-----w C:\Program Files\PC Wizard 2007
2007-09-14 16:06 --------- d-----w C:\Program Files\MagicISO
2007-09-14 12:52 --------- d-----w C:\Program Files\Valve
2007-09-06 13:55 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2007-09-06 13:55 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2007-09-06 13:55 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2007-09-06 13:45 --------- d-----w C:\Program Files\DAEMON Tools
2007-09-06 12:22 26,056 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2007-09-06 12:22 --------- d-----w C:\Program Files\Hamachi
2007-09-06 12:22 --------- d-----w C:\Documents and Settings\ewa\Application Data\Hamachi
2007-09-06 04:04 --------- d-----w C:\Program Files\Canon
2007-09-03 18:12 --------- d-----w C:\Program Files\TP
2007-09-03 15:28 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-09-03 14:09 --------- d-----w C:\Documents and Settings\LocalService\Application Data\X10 Commander
2007-09-01 19:50 --------- d-----w C:\Program Files\3wPlayer
2007-08-31 04:11 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-08-30 14:24 --------- d-----w C:\Program Files\Object Desktop
2007-08-30 14:24 --------- d-----w C:\Program Files\Common Files\Stardock
2007-08-29 22:05 --------- d-----w C:\Documents and Settings\ewa\Application Data\DWMRCMSI
2007-08-29 21:36 --------- d-----w C:\Documents and Settings\ewa\Application Data\DameWare Development
2007-08-29 21:33 --------- d-----w C:\Program Files\DameWare Development
2007-08-28 14:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2007-08-28 14:05 --------- d-----w C:\Program Files\IVT Corporation
2007-08-26 00:05 36,864 ----a-w C:\WINDOWS\system32\scio.dll
2007-08-26 00:05 3,072 ----a-w C:\WINDOWS\system32\drivers\scio.sys
2007-08-26 00:04 --------- d-----w C:\Program Files\SoftCollection LED Line
2007-08-26 00:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Protexis
2007-08-23 13:00 65,536 ----a-w C:\WINDOWS\system32\DWRCShell.DLL
2007-08-22 17:42 --------- d-----w C:\Documents and Settings\ewa\Application Data\River Past G5
2007-08-22 17:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\River Past G5
2007-08-22 17:29 796,672 ----a-w C:\WINDOWS\GPInstall.exe
2007-08-22 09:37 --------- d-----w C:\Program Files\ASIO4ALL v2
2007-08-22 08:59 --------- d-----w C:\Program Files\RMAA6
2007-08-22 00:30 --------- d-----w C:\Program Files\Realtek Sound Manager
2007-08-19 14:16 --------- d-----w C:\Documents and Settings\ewa\Application Data\n-Track Studio5
2007-08-19 14:15 --------- d-----w C:\Program Files\FASoft
2007-08-14 14:09 19,178 ----a-w C:\net.reg
2007-08-14 05:30 18,013 ----a-w C:\config.dll
2007-08-08 02:27 456,032 ----a-w C:\WINDOWS\system32\js3250.dll
2007-08-07 12:46 2,893,768 ----a-w C:\WINDOWS\system32\TCMD.EXE
2007-08-06 18:04 230,784 ----a-w C:\WINDOWS\system32\psexec.exe
2007-08-06 00:30 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-07-31 16:33 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-07-31 16:33 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-19 22:57 267,112 ----a-w C:\WINDOWS\system32\xactengine2_9.dll
2007-07-19 22:54 66,408 ----a-w C:\WINDOWS\system32\dxdllreg.exe
2007-07-19 22:54 18,280 ----a-w C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-19 16:14 444,776 ----a-w C:\WINDOWS\system32\d3dx10_35.dll
2007-07-19 16:14 3,727,720 ----a-w C:\WINDOWS\system32\d3dx9_35.dll
2007-07-19 16:14 1,358,192 ----a-w C:\WINDOWS\system32\D3DCompiler_35.dll
.
((((((((((((((((((((((((((((( snapshot@2007-10-14_17.55.54.82 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 08:57:12 163,328 ----a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundFusion"="cwcprops.cpl" [2001-04-10 11:42 C:\WINDOWS\system32\cwcprops.cpl]
"S3Hotkey"="s3hotkey.exe" [2001-09-12 20:27 C:\WINDOWS\system32\s3hotkey.exe]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-06 15:55]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
"Device Detector"="DevDetect.exe" []
"BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2005-04-20 01:38]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-20 01:38]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
C:\Documents and Settings\ewa\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-09-06 14:22:20]
R1 scio;scio;C:\WINDOWS\system32\Drivers\scio.sys
R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys
R2 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 apmbatt;Microsoft APM Legacy Battery Driver;C:\WINDOWS\system32\DRIVERS\apmbatt.sys
R3 EL556;3Com 10/100 Mini PCI Ethernet Adapter NDIS 5.0 Driver;C:\WINDOWS\system32\DRIVERS\EL556ND5.sys
R3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys
R3 S3GSavageMX;S3GSavageMX;C:\WINDOWS\system32\DRIVERS\s3gsavm.sys
R3 WDHAALBA;WDHAALBAMiniPCI Winmodem;C:\WINDOWS\system32\DRIVERS\WDHAALBA.sys
S1 ntmcdd;ntmcdd;C:\WINDOWS\system32\drivers\ntmcdd.sys
S1 ntmcmsdd;ntmcmsdd;C:\WINDOWS\system32\drivers\ntmcmsdd.sys
S3 BTCAMDRV;Mobiola Web Camera driver;C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\windows\system32\drivers\BTNetFilter.sys
S3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\EL556ND5.sys
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys
S3 TPISYSID3;SWI32;\??\C:\windows\_tpi0000.tmp\SWI32.sys
S3 XUIF;X10 USB Wireless Transceiver;C:\WINDOWS\system32\Drivers\x10ufx2.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2007-10-15 18:09:50 C:\WINDOWS\Tasks\BMMTask.job"
"2007-10-12 15:18:34 C:\WINDOWS\Tasks\1-Click Maintenance.job"
"2007-09-30 11:31:58 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-15 21:08:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-15 21:10:26
C:\ComboFix2.txt ... 2007-10-14 17:56
.
--- E O F ---