offline
- Pridružio: 15 Feb 2012
- Poruke: 77
|
ComboFix 12-02-15.01 - Administrator 16.02.2012 14:42:23.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.387.1033.18.511.310 [GMT 1:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\cfscript
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\PC Cleaners
c:\documents and settings\Administrator\Application Data\PC Cleaners\app.log
c:\documents and settings\Administrator\Application Data\PCPro
c:\documents and settings\All Users\Application Data\PC1Data
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_PFSVGAE
-------\Service_pfsvgae
.
.
((((((((((((((((((((((((( Files Created from 2012-01-16 to 2012-02-16 )))))))))))))))))))))))))))))))
.
.
2012-02-16 10:40 . 2012-02-16 11:09 -------- d-----w- c:\documents and settings\Administrator\dwhelper
2012-02-16 10:12 . 2012-02-16 10:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Ilivid Player
2012-02-16 07:38 . 2012-02-16 07:38 -------- d-----w- c:\windows\system32\wbem\snmp
2012-02-16 07:38 . 2012-02-16 07:38 -------- d-----w- c:\windows\system32\xircom
2012-02-16 07:38 . 2012-02-16 07:38 -------- d-----w- c:\program files\microsoft frontpage
2012-02-15 22:58 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-15 22:58 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 22:53 . 2011-10-14 14:47 23040 ------w- c:\windows\system32\dllcache\mciseq.dll
2012-02-15 22:53 . 2011-10-14 14:47 176128 ------w- c:\windows\system32\dllcache\winmm.dll
2012-02-15 22:47 . 2011-11-03 15:27 386048 ------w- c:\windows\system32\dllcache\qdvd.dll
2012-02-15 22:45 . 2011-11-18 12:35 60416 ------w- c:\windows\system32\dllcache\packager.exe
2012-02-15 22:42 . 2011-09-28 07:05 599552 ------w- c:\windows\system32\dllcache\crypt32.dll
2012-02-15 22:41 . 2011-08-16 10:45 6144 ------w- c:\windows\system32\dllcache\iecompat.dll
2012-02-15 22:39 . 2011-06-24 14:09 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys
2012-02-15 22:38 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2012-02-15 22:37 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2012-02-15 22:36 . 2011-04-21 13:52 105472 ------w- c:\windows\system32\dllcache\mup.sys
2012-02-15 22:35 . 2011-08-17 13:41 138496 ------w- c:\windows\system32\dllcache\afd.sys
2012-02-15 22:35 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2012-02-15 22:35 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2012-02-15 22:35 . 2009-04-20 17:06 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2012-02-15 22:35 . 2008-06-20 17:43 245248 ------w- c:\windows\system32\dllcache\mswsock.dll
2012-02-15 22:29 . 2011-12-30 16:03 21336 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-02-15 22:13 . 2012-02-15 22:13 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\IObit
2012-02-15 22:01 . 2012-02-15 22:01 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2012-02-15 22:01 . 2012-02-15 22:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
2012-02-15 22:00 . 2012-02-15 22:00 -------- d-----w- c:\program files\IObit
2012-02-15 21:13 . 2012-02-15 21:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Finder
2012-02-15 09:38 . 2012-02-15 09:38 240 ----a-w- C:\user.js
2012-02-15 08:39 . 2012-02-15 08:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\DriverCure
2012-02-15 08:39 . 2012-02-15 08:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\SpeedyPC Software
2012-02-15 08:38 . 2012-02-15 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC Software
2012-02-15 08:38 . 2012-02-15 08:38 -------- d-----w- c:\program files\SpeedyPC Software
2012-02-04 10:33 . 2012-02-04 10:33 -------- d-----w- c:\program files\Activision
2012-01-29 09:32 . 2012-01-29 09:33 -------- d-----w- c:\program files\Hard Truck 18 Wheels
2012-01-26 18:34 . 2012-01-26 18:34 -------- d-----w- c:\program files\ijji
2012-01-26 18:34 . 2012-01-26 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\IBUpdaterService
2012-01-24 17:25 . 2012-01-25 14:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Capcom
2012-01-24 17:15 . 2012-01-24 17:15 -------- d-----w- c:\program files\Capcom
2012-01-20 00:44 . 2012-02-03 11:48 -------- d-----w- C:\LFS
2012-01-18 00:48 . 2012-01-18 02:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\.minecraft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2060-08-19 01:02 . 2011-09-28 23:02 2023424 ------w- c:\windows\system32\Vcl50.bpl
2060-08-19 01:02 . 2011-09-28 23:02 1496064 ------w- c:\windows\system32\Cc3250mt.dll
2060-08-19 01:02 . 2011-09-28 23:02 248832 ------w- c:\windows\system32\Vclx50.bpl
2060-08-19 00:40 . 2011-09-28 23:02 909824 ------w- c:\windows\system32\Cp3245mt.dll
2060-08-19 00:40 . 2011-09-28 23:02 24064 ------w- c:\windows\system32\Borlndmm.dll
2012-02-15 14:10 . 2011-02-06 17:35 5276432 ----a-w- c:\windows\uninst.exe
2012-02-04 07:32 . 2011-03-26 01:04 21840 ----atw- c:\windows\system32\SIntfNT.dll
2012-02-04 07:32 . 2011-03-26 01:04 17212 ----atw- c:\windows\system32\SIntf32.dll
2012-02-04 07:32 . 2011-03-26 01:04 12067 ----atw- c:\windows\system32\SIntf16.dll
2012-01-23 16:54 . 2011-12-26 06:04 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-01-12 16:54 . 2008-10-31 13:52 1869056 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2008-04-14 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2008-04-14 10:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2008-04-14 10:00 385024 ----a-w- c:\windows\system32\html.iec
2011-12-10 14:24 . 2011-04-26 22:26 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-12 19:47 . 2011-05-07 23:52 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-09-30 . 038CA45522FE9B756EFB90DBFA9141EA . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2012-02-16_07.40.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-16 13:52 . 2012-02-16 13:52 16384 c:\windows\Temp\Perflib_Perfdata_688.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 15:31 1514152 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-11-02 641400]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-29 620376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-29 126976]
"TWCU"="c:\program files\TP-LINK\TP-LINK 54M Wireless Client Utility\TWCU.exe" [2008-03-27 479412]
"Olympus ib"="c:\program files\Olympus\ib\olycamdetect.exe" [2010-09-30 93360]
"MDS_Menu"="c:\program files\Olympus\ib\MUITransfer\MUIStartMenu.exe" [2010-07-01 220336]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-29 155648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-03 25626408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2011-12-13 225280]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-11-02 00:28 641400 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Readon Technology\\Readon TV Movie Radio Player 7.5.0.0\\internettv.exe"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
.
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2.5.2011 5:31 30656]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [15.2.2012 23:00 497496]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20.5.2011 1:07 136360]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [21.3.2011 2:01 27632]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.4.2011 6:07 136176]
S3 gupdatem;Usluga Google ažuriranje (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [23.4.2011 6:07 136176]
S3 ip100xp;TP-LINK 10/100Mbps PCI Network Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [1.6.2011 17:47 26752]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASPI32
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 05:07]
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 05:07]
.
2012-02-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 15:31]
.
2012-02-15 c:\windows\Tasks\SpeedyPC Pro.job
- c:\program files\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2011-10-09 01:19]
.
2012-02-16 c:\windows\Tasks\User_Feed_Synchronization-{226F826B-D51C-4C13-8859-F3BA7BF943F8}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.searchqu.com/406
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
LSP: c:\windows\system32\XDogcat.dll
TCP: DhcpNameServer = 192.168.88.1 192.168.11.5 8.8.8.8
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hbdif0er.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ba/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - tt=090212_noffx
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.hardId - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15385
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1710:38
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2012-02-16 14:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-436374069-1637723038-1417001333-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{28387537-E3F9-4ED7-860C-11E69AF4A8A0}"=hex:51,66,7a,6c,4c,1d,3b,1b,27,6f,29,
37,cd,b7,bc,03,9c,0e,4e,ba,9c,b4,ea,bb
"{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}"=hex:51,66,7a,6c,4c,1d,3b,1b,e5,3e,6b,
a1,ff,3d,63,0a,ad,79,ee,b1,a0,44,79,8e
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,66,13,
cb,7e,41,0d,0d,bb,af,1d,1f,de,52,36,5b
"{99079A25-328F-4BD4-BE04-00955ACAA0A7}"=hex:51,66,7a,6c,4c,1d,3b,1b,35,80,16,
86,bb,66,bf,06,a4,06,5f,c9,5c,8a,e2,bc
"{9D717F81-9148-4F12-8568-69135F087DB0}"=hex:51,66,7a,6c,4c,1d,3b,1b,91,65,60,
82,7c,c5,79,02,9f,6a,36,4f,59,48,3f,ab
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(904)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(992)
c:\windows\system32\XDogcat.dll
.
- - - - - - - > 'explorer.exe'(2592)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\XDogcat.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Completion time: 2012-02-16 14:58:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-16 13:58
ComboFix2.txt 2012-02-16 07:45
.
Pre-Run: 18.696.757.248 bytes free
Post-Run: 18.718.175.232 bytes free
.
- - End Of File - - 71A0ADFF6FEA14CD4087D7189F13CF1C
|