offline
- Delete
- Ugledni građanin
- Pridružio: 24 Feb 2006
- Poruke: 435
|
ComboFix 08-08-08.07 - zerocool 2008-08-09 15:13:37.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.227 [GMT 2:00]
Running from: C:\Documents and Settings\zerocool\Desktop\cfix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\beep.sys
C:\Documents and Settings\All Users\Desktop\XPSecurityCenter.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\XPSecurityCenter
C:\Documents and Settings\All Users\Start Menu\Programs\XPSecurityCenter\Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\XPSecurityCenter\XPSecurityCenter.lnk
C:\Documents and Settings\zerocool\Application Data\macromedia\Flash Player\#SharedObjects\XJMCXY7T\interclick.com
C:\Documents and Settings\zerocool\Application Data\macromedia\Flash Player\#SharedObjects\XJMCXY7T\interclick.com\ud.sol
C:\Documents and Settings\zerocool\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\zerocool\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\apeluzah.bat
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\deta.ban
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\epefoquzof.bin
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\osepuderuh.reg
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\owat.ban
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\pysemog.inf
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\qimaz.bat
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\unoq.pif
C:\Documents and Settings\zerocool\Local Settings\Temporary Internet Files\zegimom.dl
C:\Documents and Settings\zerocool\new.txt
C:\Program Files\XPSecurityCenter
C:\Program Files\XPSecurityCenter\data\daily.cvd
C:\Program Files\XPSecurityCenter\htmlayout.dll
C:\Program Files\XPSecurityCenter\install.exe
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\msvcm80.dll
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\XPSecurityCenter\pthreadVC2.dll
C:\Program Files\XPSecurityCenter\un.ico
C:\Program Files\XPSecurityCenter\unzip32.dll
C:\Program Files\XPSecurityCenter\wscui.cpl
C:\Program Files\XPSecurityCenter\XP_SecurityCenter.cfg
C:\Program Files\XPSecurityCenter\XPSecurityCenter.dll
C:\Program Files\XPSecurityCenter\XPSecurityCenter.exe
C:\WINDOWS\buritos.exe
C:\WINDOWS\karina.dat
C:\WINDOWS\services.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\buritos.exe
C:\WINDOWS\system32\karina.dat
C:\WINDOWS\system32\lsass2.exe
C:\WINDOWS\system32\windll.exe
C:\WINDOWS\system32\winivstr.exe
C:\WINDOWS\wkssvr.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.
2008-08-09 15:12 . 2008-08-09 15:12 12,584 --a------ C:\Documents and Settings\zerocool\Application Data\obavycag.sys
2008-08-09 15:12 . 2008-08-09 15:12 10,523 --a------ C:\Documents and Settings\All Users\Application Data\ygecynyn.reg
2008-08-09 11:54 . 2008-08-09 11:54 19,656 --a------ C:\WINDOWS\yjylawymo.com
2008-08-09 11:54 . 2008-08-09 11:54 19,648 --a------ C:\Documents and Settings\All Users\Application Data\uhavuja.sys
2008-08-09 11:54 . 2008-08-09 11:54 19,604 --a------ C:\Documents and Settings\All Users\Application Data\cugagujese.vbs
2008-08-09 11:54 . 2008-08-09 11:54 19,455 --a------ C:\WINDOWS\system32\deva.pif
2008-08-09 11:54 . 2008-08-09 11:54 16,849 --a------ C:\WINDOWS\system32\hizigyxul.bin
2008-08-09 11:54 . 2008-08-09 11:54 15,337 --a------ C:\WINDOWS\liluqut.dll
2008-08-09 11:54 . 2008-08-09 11:54 15,003 --a------ C:\Documents and Settings\zerocool\Application Data\owadini.vbs
2008-08-09 11:54 . 2008-08-09 11:54 14,712 --a------ C:\WINDOWS\faco.inf
2008-08-09 11:54 . 2008-08-09 11:54 13,433 --a------ C:\WINDOWS\system32\opoq.ban
2008-08-09 11:54 . 2008-08-09 11:54 12,703 --a------ C:\Program Files\Common Files\exyjasac.reg
2008-08-09 11:54 . 2008-08-09 11:54 10,690 --a------ C:\WINDOWS\system32\bufotixyji.com
2008-08-09 11:54 . 2008-08-09 11:54 10,274 --a------ C:\WINDOWS\qory.dl
2008-08-09 11:43 . 2008-08-09 11:43 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-08-08 00:38 . 2008-08-08 00:38 19,713 --a------ C:\Program Files\Common Files\rabuh.scr
2008-08-07 01:33 . 2008-08-07 01:33 19,338 --a------ C:\WINDOWS\owytazica.dll
2008-08-07 01:33 . 2008-08-07 01:33 19,231 --a------ C:\WINDOWS\system32\polysiko.dll
2008-08-07 01:33 . 2008-08-07 01:33 18,453 --a------ C:\WINDOWS\esypuworip.ban
2008-08-07 01:33 . 2008-08-07 01:33 18,116 --a------ C:\WINDOWS\system32\goruwiropa.exe
2008-08-07 01:33 . 2008-08-07 01:33 17,860 --a------ C:\WINDOWS\nevyl._dl
2008-08-07 01:33 . 2008-08-07 01:33 15,853 --a------ C:\WINDOWS\system32\akykohobe.exe
2008-08-07 01:33 . 2008-08-07 01:33 13,915 --a------ C:\Documents and Settings\All Users\Application Data\ananuloji.scr
2008-08-07 01:33 . 2008-08-07 01:33 13,348 --a------ C:\WINDOWS\okylim.pif
2008-08-07 01:33 . 2008-08-07 01:33 11,833 --a------ C:\WINDOWS\system32\manyhat.lib
2008-08-07 01:33 . 2008-08-07 01:33 11,667 --a------ C:\Documents and Settings\zerocool\Application Data\upewuw.exe
2008-08-07 01:33 . 2008-08-07 01:33 11,171 --a------ C:\Documents and Settings\All Users\Application Data\xamuw.vbs
2008-08-07 01:33 . 2008-08-07 01:33 10,709 --a------ C:\WINDOWS\mamomuki.bat
2008-08-07 01:32 . 2008-08-06 23:34 195,921 --a------ C:\WINDOWS\system32\_scui.cpl
2008-08-07 01:27 . 2008-08-07 02:41 16,728 --a------ C:\WINDOWS\system32\Windll.dll
2008-08-06 18:35 . 2002-10-05 01:04 921,600 --a------ C:\WINDOWS\system32\vorbisenc.dll
2008-08-06 18:35 . 2002-10-06 20:42 237,568 --a------ C:\WINDOWS\system32\OggDS.dll
2008-08-06 18:35 . 2002-10-05 01:04 188,416 --a------ C:\WINDOWS\system32\vorbis.dll
2008-08-06 18:35 . 2002-10-05 01:04 45,056 --a------ C:\WINDOWS\system32\ogg.dll
2008-08-06 14:51 . 2008-08-06 23:55 243,504 --a------ C:\WINDOWS\fail.exe
2008-08-06 14:51 . 2008-08-06 14:54 307 --a------ C:\WINDOWS\system32\r0lf.dat
2008-08-03 19:56 . 2008-08-03 19:56 243,504 --a------ C:\WINDOWS\nigr.exe
2008-08-03 19:54 . 2008-08-03 19:54 243,504 --a------ C:\WINDOWS\ngrs.exe
2008-08-01 11:55 . 2008-08-01 11:55 150 --a------ C:\WINDOWS\delself.bat
2008-08-01 11:49 . 2008-08-01 11:55 65,536 --a------ C:\WINDOWS\Setup_ver1.1631.0.exe
2008-08-01 11:02 . 2008-08-01 11:02 27,057 -r-hs---- C:\WINDOWS\crsr.exe
2008-07-31 19:56 . 2008-08-01 10:04 113,011 --a------ C:\WINDOWS\system32\windll32lol.exe
2008-07-31 19:56 . 2008-07-31 19:56 69,095 --a------ C:\WINDOWS\lolngr.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-09 13:12 19,733 ----a-w C:\WINDOWS\ydyfowyba.com
2008-08-09 13:12 19,378 ----a-w C:\WINDOWS\ojijo.bin
2008-08-09 13:12 16,456 ----a-w C:\WINDOWS\sezyn.com
2008-08-09 13:12 16,017 ----a-w C:\WINDOWS\tedy.exe
2008-08-09 13:12 14,571 ----a-w C:\WINDOWS\adefejy.com
2008-08-09 13:12 11,259 ----a-w C:\WINDOWS\yjagacam.com
2008-08-09 09:54 19,043 ----a-w C:\Program Files\Common Files\wuqowafywa.ban
2008-08-09 09:54 17,782 ----a-w C:\Program Files\Common Files\uzyre._sy
2008-08-09 09:54 15,992 ----a-w C:\Program Files\Common Files\iwahenepug._dl
2008-08-09 09:54 15,887 ----a-w C:\Program Files\Common Files\aromuqog.inf
2008-08-09 09:54 15,117 ----a-w C:\Program Files\Common Files\jufumavoc.db
2008-08-09 09:54 13,922 ----a-w C:\Program Files\Common Files\fyjiq.inf
2008-08-06 23:33 11,874 ----a-w C:\Program Files\Common Files\mafu.ban
2008-08-06 23:27 --------- d-----w C:\Documents and Settings\zerocool\Application Data\uTorrent
2008-07-08 22:20 --------- d-----w C:\Documents and Settings\zerocool\Application Data\PlayFirst
2008-07-03 21:30 --------- d-----w C:\Documents and Settings\zerocool\Application Data\mIRC
2008-07-03 20:43 --------- d-----w C:\Program Files\mIRC
2008-07-03 20:40 --------- d-----w C:\Program Files\dellete
2008-07-03 07:54 --------- d-----w C:\Documents and Settings\zerocool\Application Data\LimeWire
2008-06-25 14:59 --------- d-----w C:\Program Files\SaljiPoruke-desktop
2008-01-24 10:12 374 ----a-w C:\Documents and Settings\zerocool\Application Data\internaldb6334.dat
2008-01-24 10:11 555 ----a-w C:\Documents and Settings\zerocool\Application Data\internaldb8467.dat
2008-01-24 10:11 18,432 ----a-w C:\Documents and Settings\zerocool\Application Data\internaldb41.dat
2005-08-24 21:10 174,592 --sha-w C:\WINDOWS\system32\ncfpsys.exe
2004-08-03 22:56 195,072 --sh--r C:\WINDOWS\system32\phqghum.exe
.
------- Sigcheck -------
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-03 23:14 359040 6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"Adobe SpeedLaunch"="phqghum.exe" [2004-08-04 00:56 195072 C:\WINDOWS\system32\phqghum.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NAV Agent"="C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe" [2001-07-21 10:09 50256]
"WFXSwtch"="C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe" [2001-07-19 09:04 26624]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-22 23:21 185896]
"Password Protect USB 3.6.1"="C:\WINDOWS\system32\ncfpsys.exe" [2005-08-24 23:10 174592]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-07-19 09:04 43520 C:\WINDOWS\system32\WFXSNT40.EXE]
"Adobe SpeedLaunch"="phqghum.exe" [2004-08-04 00:56 195072 C:\WINDOWS\system32\phqghum.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Adobe SpeedLaunch"="phqghum.exe" [2004-08-04 00:56 195072 C:\WINDOWS\system32\phqghum.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CleanSweep Smart Sweep-Internet Sweep.lnk - C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe [2007-11-01 14:19:25 221184]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIVF"= DivX412.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R3 KCIRDA;%KCIRDA.ServiceDesc%;C:\WINDOWS\system32\DRIVERS\KCIrNet.sys [2001-10-04 10:23]
R3 QDFSDRV;QDFSDRV;C:\WINDOWS\system32\drivers\qdfsdrv.sys [2001-07-26 12:17]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2001-10-11 08:51]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2669e613-8bc8-11dc-8f43-0007951fccfb}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL nircmd.exe execmd CALL batexe\progstart.bat
.
Contents of the 'Scheduled Tasks' folder
2008-07-25 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exe [2001-07-21 10:14]
2008-07-25 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
- C:\Program Files\Common Files\Symantec Shared\NMAIN.EXE [2001-07-24 17:35]
2008-08-09 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2001-07-26 13:23]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Dcom Helper2 - lsass2.exe
HKLM-Run-etMonitor - C:\WINDOWS\etMon.exe
HKLM-Run-XP SecurityCenter - C:\Program Files\XPSecurityCenter\xpsecuritycenter.exe
HKLM-Run-NWEReboot - (no file)
HKLM-Run-Windows Protector - windll.exe
HKLM-Run-Dcom Helper2 - lsass2.exe
HKLM-RunServices-Windows Protector - windll.exe
HKLM-RunServices-Dcom Helper2 - lsass2.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\zerocool\Application Data\Mozilla\Firefox\Profiles\gx5wm0rj.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 15:17:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Dcom Helper2 = lsass2.exe?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-08-09 15:29:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-09 13:29:14
ComboFix2.txt 2008-05-17 20:32:38
ComboFix3.txt 2008-05-05 08:37:07
ComboFix4.txt 2008-02-02 18:57:27
ComboFix5.txt 2008-08-09 13:12:54
Pre-Run: 8,224,440,320 bytes free
Post-Run: 8,264,024,064 bytes free
237
|