offline
- GTA
- Počasni građanin
- Pridružio: 14 Avg 2008
- Poruke: 717
|
ComboFix 09-04-03.01 - Administrator 2009-04-04 17:04:19.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1024.673 [GMT 2:00]
Running from: c:\documents and settings\Administrator\My Documents\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\paso.el
c:\windows\system32\wpcap.dll
c:\windows\ynh.dx
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-03-04 to 2009-04-04 )))))))))))))))))))))))))))))))
.
2009-03-24 14:22 . 2009-03-24 14:22 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Ipref
2009-03-23 10:48 . 2009-04-02 16:15 <DIR> d-------- c:\documents and settings\Administrator\Application Data\mIRC
2009-03-14 23:39 . 2009-04-02 19:01 <DIR> d-------- C:\Picture This
2009-03-14 23:39 . 2009-03-14 23:39 32,768 --ahs---- C:\Thumbs.db
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-04 14:58 --------- d-----w c:\program files\Crawler
2009-04-04 14:53 --------- d-----w c:\program files\Winamp
2009-04-04 14:53 --------- d-----w c:\program files\MetFileRegenerator
2009-04-04 14:53 --------- d-----w c:\program files\D-Tools
2009-04-04 14:13 --------- d-----w c:\program files\Spyware Terminator
2009-04-04 14:10 61,952 ----a-w c:\windows\system32\alg.exe
2009-04-02 16:38 --------- d-----w c:\documents and settings\Administrator\Application Data\Spyware Terminator
2009-03-27 21:41 --------- d-----w c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-03-27 14:40 --------- d-----w c:\program files\Java
2009-03-24 16:42 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 04:19 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-03-04 17:51 --------- d-----w c:\program files\Avanquest update
2009-02-28 15:08 --------- d-----w c:\documents and settings\Administrator\Application Data\GameHouse
2009-02-26 19:54 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2009-02-24 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2009-02-24 18:30 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2009-02-23 16:47 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2009-02-23 16:47 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2009-02-23 16:30 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2009-02-23 16:23 --------- d-----w c:\documents and settings\Administrator\Application Data\PlayFirst
2009-02-22 17:29 --------- d-----w c:\documents and settings\All Users\Application Data\Tarma Installer
2009-02-16 11:39 --------- d-----w c:\program files\ESET
2009-02-04 13:12 --------- d-----w c:\program files\Microsoft VM
2009-02-04 11:08 --------- d-----w c:\documents and settings\Administrator\Application Data\TeamViewer
.
------- Sigcheck -------
2007-06-13 12:23 3195392 3be4584f9ac9b9094c634f9348a57fe2 c:\windows\EXPLORER.EXE
2007-06-13 13:26 1052160 601400ee02323db6408f22d1d35b1c69 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2001-08-23 11:00 1051136 306594b0cee0a5424b9ec25de203a9b4 c:\windows\$NtUninstallKB938828$\explorer.exe
2007-06-13 12:23 3214336 83b8d1426c4835b3511fcf0485c12fcb c:\windows\system32\dllcache\explorer.exe
2001-08-23 11:00 34304 576ce88a37d9911d17c9f6f4700e6e09 c:\windows\system32\ctfmon.exe
2001-08-23 11:00 34304 9d3cdaa8506a15348724f44c5f6d6caa c:\windows\system32\dllcache\ctfmon.exe
2005-06-11 02:17 76800 2b374ca1dec942bf6c6c8c8a28cc889e c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2001-08-23 11:00 76800 52f2707cae30824ca53dd35bb9f0dd25 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2005-06-11 01:53 75264 4fae26cdc82923a92c85f57fb7cfe177 c:\windows\system32\SPOOLSV.EXE
2005-06-11 01:53 76800 b2278c918267cd9885da0450ff5b2daa c:\windows\system32\dllcache\spoolsv.exe
2001-08-23 11:00 24576 a6469e376946ac97e397ad2543bf62f9 c:\windows\system32\USERINIT.EXE
2001-08-23 11:00 43520 cbdf7b7ec638ea54f5b16da39e78e95c c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-26 185896]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
PartMetBackup.lnk - c:\program files\Java\jre6\bin\javaw.exe [2009-01-04 144792]
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-05-14 344064]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-09-29 90112]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-04-12 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.CDVC"= cdvccodc.dll
"MSACM.pcdv"= pcdv.acm
"vidc.CDV5"= cdv5codc.dll
"vidc.CLLC"= cllccodc.dll
"vidc.CUVC"= cuvccodc.dll
"vidc.CDVH"= cdvhcodc.dll
"vidc.CMIC"= cmiccodc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\igrica2\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Sony\\Vegas Pro 8.0\\VegSrv80.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrblock.sys [2008-12-17 20864]
R1 cdrport;cdrport;c:\windows\system32\drivers\cdrport.sys [2008-12-17 4608]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-02-20 33800]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2008-05-20 141312]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\REGEDT32.EXE [2001-08-23 20992]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [2008-04-26 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [2008-04-26 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [2008-04-26 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [2008-04-26 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [2008-04-26 83344]
S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSONY_MEDIAMGR2 --> c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [?]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2008-10-15 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2008-10-15 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2008-10-15 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2008-10-15 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2008-10-15 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2008-10-15 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2008-10-15 115752]
.
Contents of the 'Scheduled Tasks' folder
2009-04-03 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe []
2009-02-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
HKLM-Run-SpywareTerminator - c:\program files\Spyware Terminator\SpywareTerminatorShield.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL =
uSearchURL,(Default) = hxxp://www.searchgateway.net/search-Google-Gateway.php?sa=Search+Here&client=pub-4642981363251965&forid=1&ie=ISO-8859-1&oe=ISO-8859-1&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A11&q=%s
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://www.gamehouse.com/games/DoggieDash.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {74EF5274-F439-2168-B543-14745B625C72} - hxxp://www.gamehouse.com/games/WeddingDash2.cab
DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} - hxxp://www.gamehouse.com/games/JBGamePlayer.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://www.gamehouse.com/games/zylom/zylomplayer.cab
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://www.gamehouse.com/games/Chocolatier2.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\krdyd8eg.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\progra~1\Crawler\firefox\components\xcomm.dll
FF - component: c:\progra~1\Crawler\firefox\components\xshared.dll
FF - component: c:\progra~1\Crawler\firefox\components\xsupport.dll
FF - component: c:\progra~1\Crawler\firefox\components\xwsg.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-04 17:06:43
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1659004503-764733703-682003330-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:10,a8,30,d3,b8,33,00,8f,fc,ad,fd,0d,76,5a,ce,7c,4c,c5,d0,2d,c1,00,ab,
e2,32,1a,58,0b,6d,4b,57,a0,c0,af,28,a6,00,0c,5c,e7,9b,51,de,34,80,c4,5c,77,\
"??"=hex:07,49,a2,2d,fb,b0,e3,48,51,fa,5f,01,d8,8c,79,84
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-04 17:08:56
ComboFix-quarantined-files.txt 2009-04-04 15:08:39
Pre-Run: 20,138,151,936 bytes free
Post-Run: 20,118,212,608 bytes free
195 --- E O F --- 2009-01-13 21:10:23
|