ComboFix 09-06-05.07 - Rendszergazda 009.06.08. 12:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.36.1038.18.958.658 [GMT 2:00]
Running from: c:\documents and settings\Rendszergazda\Asztal\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Rendszergazda\Rendszergazda.exe
c:\windows\system32\drivers\xhcpl.sys
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.
2009-06-08 10:45 . 2009-06-08 10:45 -------- d-----w- c:\windows\LastGood
2009-06-07 05:31 . 2009-06-07 05:31 50176 --sh--r- c:\windows\system32\1041b.exe
2009-06-06 21:04 . 2009-03-24 14:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-06 21:04 . 2009-06-06 21:04 -------- d-----w- c:\program files\Avira
2009-06-06 20:01 . 2001-10-26 17:01 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-06-06 20:01 . 2001-08-17 20:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-06-05 18:50 . 2009-06-05 18:50 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Malwarebytes
2009-06-05 18:50 . 2009-06-05 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-01 10:49 . 2009-06-01 10:49 -------- d-----w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\ESET
2009-06-01 10:13 . 2009-06-01 10:13 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-05-29 13:01 . 2009-05-29 13:03 -------- d-----w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 10:45 . 2007-09-19 19:12 -------- d-----w- c:\program files\Eset
2009-06-08 10:31 . 2007-11-25 16:08 -------- d-----w- c:\program files\Spyware Terminator
2009-06-05 18:58 . 2007-11-25 16:08 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Spyware Terminator
2009-06-05 18:03 . 2007-11-25 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-04-22 13:01 . 2009-04-22 13:01 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-22 13:01 . 2007-11-25 16:31 -------- d-----w- c:\program files\Java
2009-04-22 13:00 . 2009-04-22 13:00 152576 ----a-w- c:\documents and settings\Rendszergazda\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-29 11:59 . 2006-11-14 12:00 59292 ----a-w- c:\windows\system32\perfc00E.dat
2009-03-29 11:59 . 2006-11-14 12:00 307046 ----a-w- c:\windows\system32\perfh00E.dat
2006-11-14 12:00 . 2006-11-14 12:00 168096 --sha-r- c:\windows\system32\unsav.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-11-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-06-26 20005928]
"OM_Monitor"="d:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-06-02 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AllSnap"="c:\windows\allsnap.exe" [2006-11-14 81920]
"MakeFolder"="c:\windows\makefolder.exe" [2006-11-14 69632]
"AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2006-06-01 536576]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-04-05 565248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-01 729177]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-11-25 2776576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-22 148888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-08-03 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2006-08-30 180224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-11-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Indˇt˘pult\
HotKeyDriver.lnk - c:\program files\HotKey_Driver\HotKeyDriver.exe [2007-9-19 4239360]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"ForceCopyAclwithFile"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"ForceCopyAclwithFile"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\winver.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10720:TCP"= 10720:TCP:BitComet 10720 TCP
"10720:UDP"= 10720:UDP:BitComet 10720 UDP
"6696:TCP"= 6696:TCP:wmejhrb
--- Other Services/Drivers In Memory ---
*NewlyCreated* - APPMGMT
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AntiVirSchedulerService
*Deregistered* - AppMgmt
*Deregistered* - Aspi32
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avgio
*Deregistered* - avipbb
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - eamon
*Deregistered* - easdrv
*Deregistered* - epfwtdir
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - MSIServer
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - osvorejoe
*Deregistered* - PartMgr
*Deregistered* - PCIIde
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - sp_rsdrv2
*Deregistered* - sp_rssrv
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - WZCSVC
*Deregistered* - xfilt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
osvorejoe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Active Captions - c:\windows\activecaptions.exe
HKLM-Run-c:\windows\system32\kdkdy.exe - c:\windows\system32\kdkdy.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.co.hu/
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
.
------- File Associations -------
.
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-08 13:09
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = c:\program files\VIAudioi\SBADeck\ADeck.exe 1???\ ?|????e:\drivers\
03_Au???|???|?????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\osvorejoe]
"ServiceDll"="c:\windows\system32\unsav.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\sfc_os.dll
.
Completion time: 2009-06-08 13:33
ComboFix-quarantined-files.txt 2009-06-08 11:15
Pre-Run: 1 701 568 512 bájt szabad
Post-Run: 1 696 370 688 bájt szabad
240