Caoss, evo loga
ComboFix 09-02-08.02 - Jelena 2009-02-10 0:43:01.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1256.971.1033.18.2037.974 [GMT 4:00]
Running from: c:\users\Jelena\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-09 to 2009-02-09 )))))))))))))))))))))))))))))))
.
2009-02-09 14:55 . 2009-02-09 14:55 <DIR> d-------- c:\users\All Users\Office Genuine Advantage
2009-02-09 14:55 . 2009-02-09 14:55 <DIR> d-------- c:\programdata\Office Genuine Advantage
2009-02-09 14:39 . 2008-06-20 05:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-09 14:39 . 2008-06-20 05:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-09 14:39 . 2008-06-20 05:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-09 14:39 . 2008-06-20 05:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-09 14:39 . 2008-06-20 05:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-09 14:39 . 2008-06-20 05:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-09 14:39 . 2008-06-20 05:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-09 14:39 . 2008-06-20 05:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-09 14:32 . 2008-07-27 22:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-09 14:32 . 2008-07-27 22:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-09 14:32 . 2008-07-27 22:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-09 14:32 . 2008-07-27 22:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-09 14:32 . 2008-07-27 22:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-02 19:04 . 2009-02-02 19:06 <DIR> d-------- c:\program files\Hotspot Shield
2009-02-02 19:04 . 2009-02-06 01:55 31,704 --a------ c:\windows\System32\drivers\hssdrv.sys
2009-02-02 12:12 . 2009-02-02 12:12 <DIR> d-------- c:\users\Jelena\AppData\Roaming\FlashGet
2009-01-14 07:26 . 2008-12-16 06:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-11 22:55 . 2009-01-11 22:55 <DIR> d-------- c:\program files\MSN Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 10:33 --------- d-----w c:\programdata\Google Updater
2009-02-07 23:07 --------- d-----w c:\users\Jelena\AppData\Roaming\Skype
2009-02-07 20:04 --------- d-----w c:\users\Jelena\AppData\Roaming\skypePM
2009-02-06 16:28 --------- d-----w c:\programdata\Roxio
2009-01-21 04:30 --------- d-----w c:\program files\ESET
2009-01-18 12:00 2,560 ----a-w c:\windows\_MSRSTRT.EXE
2009-01-17 20:21 --------- d-----w c:\program files\Conduit
2009-01-14 23:44 --------- d-----w c:\program files\Windows Mail
2009-01-02 18:07 --------- d-----w c:\program files\TorrentMan
2008-12-31 13:04 691,560 ----a-w c:\windows\System32\OGACheckControl.dll
2008-12-31 13:04 528,744 ----a-w c:\windows\System32\OGAVerify.exe
2008-12-31 13:04 502,120 ----a-w c:\windows\System32\OGAAddin.dll
2008-11-23 16:08 298,104 ----a-w c:\windows\System32\imon.dll
2008-08-16 23:17 691 ----a-w c:\users\Jelena\AppData\Roaming\GetValue.vbs
2008-08-16 23:17 35 ----a-w c:\users\Jelena\AppData\Roaming\SetValue.bat
2008-07-28 12:34 174 --sha-w c:\program files\desktop.ini
2008-06-19 16:33 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-06-19 16:33 56 ---ha-w c:\programdata\ezsidmv.dat
2006-10-11 08:04 61,036 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-04-04 15:39 76 --sh--r c:\windows\CT4CET.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-02-06 19:11 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-06 39408]
"iDailyDiary"="c:\progra~1\IDAILY~1\iDD.exe" [2007-05-27 1245184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-10-25 167936]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-28 36864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2008-04-04 77824]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-12 3444736]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-13 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-11-01 189736]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-09-12 36352]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-02 185896]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-11-23 949376]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-03 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-04-04 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-09-07 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0E076F42-8BC3-40BE-AFE5-9E8B3ACDD76D}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{5939451A-83A8-4ADA-B8E8-0B77C391383E}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{644F1925-973F-4A3B-BB08-8668DA414A75}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{63FCFDBA-6958-42DA-8CD4-91BB83C87E02}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{DB9F0F77-FAC9-41E7-9ADA-90C86DB6B7F7}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{6EF1264F-784B-4B33-A856-C209EC5ABC88}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{A4DEACD6-CCD5-4F96-B552-7AE233B48CE0}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{9FC5617B-918D-41D4-BBCB-03925918B2C6}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{8B676522-B88F-4E88-8119-9B51BBD7501E}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"{34A4DE61-4A86-4EF0-87B0-2C8741D37F59}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{23F78EDF-624B-4F31-839A-F95EFAFC8917}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{A7AE804C-E8DA-4549-AAE7-FDCFF3EC30DA}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{ED9D98F8-5CCE-42D7-BF17-7C9E9458F3F9}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"TCP Query User{EAB028B2-2384-4B0C-A061-D6B7A5269615}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{EE71A126-AC60-490A-A86D-88A531265D12}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet
R1 nod32drv;nod32drv;c:\windows\System32\drivers\nod32drv.sys [2008-11-23 15424]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [2008-04-04 73728]
R2 HssSrv;Hotspot Shield Helper Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [2009-02-06 117208]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\System32\drivers\hssdrv.sys [2009-02-02 31704]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [2008-04-05 111616]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2008-04-05 235520]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2008-04-05 7424]
S3 iadusb;MT882;c:\windows\System32\drivers\glauiad.sys [2008-11-20 30336]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-ares - c:\program files\Ares\Ares.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\users\Jelena\AppData\Roaming\Mozilla\Firefox\Profiles\m7f6nc52.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1640187&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFAlert.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&mozver={moz:version}-{moz:buildid}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&mozver={moz:version}-{moz:buildid}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-10 00:46:54
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-10 0:48:58
ComboFix-quarantined-files.txt 2009-02-09 20:48:55
Pre-Run: 25.905.582.080 bytes free
Post-Run: 25,984,552,960 bytes free
189 --- E O F --- 2009-02-09 10:44:46
|