Van bizony, nem mindenki szereti a sört, van aki a málnát jobban
Nagy nehezen sikerült, azt hittem sosem lesz kesz kész.
ComboFix 09-01-12.04 - xy 2009-01-13 18:09:17.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.126.17 [GMT 1:00]
Running from: c:\documents and settings\xy\Asztal\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090113-0] *On-access scanning disabled* (Outdated)
AV: NOD32 Antivirus System 2.51 *On-access scanning disabled* (Outdated)
FW: ZoneAlarm Firewall *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-12-13 to 2009-01-13 )))))))))))))))))))))))))))))))
.
2009-01-11 16:53 . 2009-01-11 16:53 <DIR> d-------- c:\documents and settings\xy\Application Data\Malwarebytes
2009-01-11 16:52 . 2009-01-11 16:53 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-11 16:52 . 2009-01-11 16:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-11 16:52 . 2009-01-04 18:38 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-11 16:52 . 2009-01-04 18:38 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-11 14:29 . 2009-01-11 14:29 <DIR> d-------- c:\program files\thor
2009-01-08 20:46 . 2009-01-08 20:48 <DIR> d-------- c:\program files\SweetIM
2009-01-08 20:46 . 2009-01-08 20:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\SweetIM
2009-01-03 06:48 . 2009-01-03 06:48 <DIR> d-------- c:\program files\Magic Tea
2009-01-03 06:47 . 2009-01-03 06:47 <DIR> d-------- c:\program files\ReflexiveArcade
2009-01-02 09:50 . 2009-01-02 09:50 <DIR> d-------- c:\program files\Zuma deluxe
2009-01-02 09:15 . 2009-01-02 14:27 <DIR> d-------- c:\program files\GameHouse
2008-12-31 09:36 . 2008-12-31 09:36 <DIR> d-------- c:\program files\JoWooD
2008-12-31 09:13 . 2008-12-31 09:19 <DIR> d-------- c:\documents and settings\xy\Pokoli2
2008-12-30 14:06 . 2008-12-30 14:04 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-28 17:11 . 2008-12-28 21:04 <DIR> d-------- c:\program files\RSL
2008-12-28 16:15 . 2009-01-02 19:44 <DIR> d-------- C:\totalcmd
2008-12-28 09:44 . 2008-12-28 09:44 <DIR> d-------- c:\documents and settings\xy\Application Data\Apple Computer
2008-12-14 11:12 . 2008-12-14 11:12 <DIR> d-------- c:\program files\ZoneAlarmSB
2008-12-14 11:09 . 2008-12-14 11:09 4,212 --ah----- c:\windows\system32\zllictbl.dat
2008-12-14 11:08 . 2008-12-14 11:09 <DIR> d-------- c:\windows\system32\ZoneLabs
2008-12-14 11:08 . 2008-12-14 11:08 <DIR> d-------- c:\program files\Zone Labs
2008-12-14 11:08 . 2008-08-21 20:41 1,221,008 --a------ c:\windows\system32\zpeng25.dll
2008-12-14 11:08 . 2009-01-13 18:18 348,371 --a------ c:\windows\system32\vsconfig.xml
2008-12-14 11:07 . 2009-01-13 18:17 <DIR> d-------- c:\windows\Internet Logs
2008-12-14 10:34 . 2008-12-14 10:34 <DIR> d-------- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 08:32 --------- d-----w c:\program files\Common Files\Adobe
2009-01-09 12:47 --------- d-----w c:\documents and settings\xy\Application Data\Wildfire
2009-01-03 20:26 --------- d-----w c:\documents and settings\xy\Application Data\MSN6
2009-01-02 13:13 --------- d-----w c:\program files\Google
2008-12-22 16:50 --------- d-----w c:\program files\Opera
2008-12-11 17:23 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 16:29 --------- d-----w c:\program files\MSECache
2008-11-19 16:32 --------- d-----w c:\documents and settings\xy\Application Data\mbin.jp
2008-11-17 17:20 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-11-16 09:58 --------- d-----w c:\program files\Sebran
2008-11-16 07:30 --------- d-----w c:\documents and settings\xy\Application Data\OpenOffice.org2
2008-11-15 10:27 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-15 10:26 --------- d--h--w c:\program files\InstallShield Installation Information
2008-01-13 13:29 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 12:22 1172792 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-02 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-08-21 981904]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-01-01 111928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\All Users\Start Menu\Programs\Indˇt˘pult\
Adobe Reader gyorsindˇt˘.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
c:\program files\QuickTime\QTTask.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
c:\program files\Java\jre6\bin\jusched.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2009-01-02 14:13 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9699:TCP"= 9699:TCP:BitComet 9699 TCP
"9699:UDP"= 9699:UDP:BitComet 9699 UDP
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-20 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-20 20560]
.
Contents of the 'Scheduled Tasks' folder
2009-01-10 c:\windows\Tasks\{06C4A412-99DD-4FF5-AAF0-1A9F333550B5}_OTTHONI_xy.job
- c:\windows\system32\mobsync.exe [2004-08-17 15:48]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.allat-nevelde.hu/
uSearch Page =
hxxp://www.google.com
uSearch Bar =
hxxp://www.google.com/ie
mDefault_Search_URL =
hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant =
hxxp://www.google.com/ie
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
mSearchAssistant =
hxxp://www.google.com/ie
FF - ProfilePath - c:\documents and settings\xy\Application Data\Mozilla\Firefox\Profiles\ldl76qqr.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.live.com/
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt ... =MICPHU&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-13 18:23:27
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-01-13 18:34:51 - machine was rebooted [xy]
ComboFix-quarantined-files.txt 2009-01-13 17:34:34
Pre-Run: 798,494,720 bájt szabad
Post-Run: 784,015,360 bájt szabad
162 --- E O F --- 2008-02-03 06:29:34