ComboFix 09-12-16.05 - Rendszergazda 009.12.18. 20:31:32.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.36.1038.18.223.113 [GMT 1:00]
Running from: c:\documents and settings\Rendszergazda\Asztal\KittyFix.exe
Command switches used :: c:\documents and settings\Rendszergazda\Asztal\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\utils\HDD_THER
c:\utils\HDD_THER\HDD_THER.EXE
.
((((((((((((((((((((((((( Files Created from 2009-11-18 to 2009-12-18 )))))))))))))))))))))))))))))))
.
2009-12-17 09:37 . 2009-12-17 09:37 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\BSplayer Pro
2009-12-16 23:08 . 2009-12-16 23:08 -------- d-----w- C:\rsit
2009-12-15 08:51 . 2009-12-15 09:25 -------- d-----w- c:\windows\Corel
2009-12-14 00:12 . 2009-12-14 00:12 -------- d-----w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\Adobe
2009-12-13 09:42 . 2009-12-18 19:38 -------- d-----w- c:\documents and settings\Rendszergazda\Tracing
2009-12-13 09:40 . 2009-12-13 09:41 -------- d-----w- c:\program files\Windows Live
2009-12-13 00:21 . 2009-12-17 09:37 -------- d-----w- c:\program files\webteh
2009-12-12 18:13 . 2009-12-18 18:55 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\HDD Thermometer
2009-12-12 18:08 . 2009-12-12 18:08 -------- d-----w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\Opera
2009-12-12 18:08 . 2009-12-12 18:08 -------- d-----w- c:\program files\Opera
2009-12-12 17:15 . 2003-06-19 00:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2009-12-12 17:15 . 2003-06-19 00:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-12-12 17:06 . 2009-12-12 17:06 -------- d-----w- c:\program files\Microsoft.NET
2009-12-12 17:03 . 2009-12-12 17:03 -------- d-----r- C:\MSOCache
2009-12-12 17:01 . 2009-12-12 17:01 223128 ----a-w- c:\windows\system32\drivers\dtscsi.sys
2009-12-12 17:01 . 2009-12-12 17:01 -------- d-----w- c:\program files\DAEMON Tools
2009-12-12 14:42 . 2009-12-18 08:12 54888 ----a-w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-12 12:20 . 2004-08-03 22:07 6400 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-12-12 12:20 . 2004-08-03 22:15 82944 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2009-12-12 12:20 . 2004-08-03 22:07 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2009-12-12 12:20 . 2001-08-17 21:00 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys
2009-12-12 12:18 . 2003-04-24 10:28 41984 ----a-r- c:\windows\system32\drivers\fetnd5b.sys
2009-12-12 12:18 . 2003-04-10 10:27 7040 ----a-r- c:\windows\system32\ntsim.sys
2009-12-12 11:33 . 2004-09-20 11:02 69722 ----a-w- c:\windows\system32\SynTPFcs.dll
2009-12-12 11:33 . 2004-09-20 11:04 81920 ----a-w- c:\windows\system32\SynTPCo2.dll
2009-12-12 11:33 . 2004-09-20 10:53 90202 ----a-w- c:\windows\system32\SynTPAPI.dll
2009-12-12 11:33 . 2004-09-20 10:53 114688 ----a-w- c:\windows\system32\SynCtrl.dll
2009-12-12 11:33 . 2004-09-20 10:53 77917 ----a-w- c:\windows\system32\SynCOM.dll
2009-12-12 11:33 . 2004-09-20 10:51 188672 ----a-w- c:\windows\system32\drivers\SynTP.sys
2009-12-12 11:33 . 2009-12-12 11:33 -------- d-----w- c:\program files\Synaptics
2009-12-12 11:26 . 2009-12-12 11:26 -------- d-----w- c:\program files\S3
2009-12-12 11:25 . 2005-06-20 15:21 1875968 ----a-w- c:\windows\system32\vticd.dll
2009-12-12 11:25 . 2005-06-20 15:17 225920 ----a-w- c:\windows\system32\drivers\vtmini.sys
2009-12-12 11:25 . 2005-03-11 16:45 360448 ----a-w- c:\windows\system32\VTGamma2.dll
2009-12-12 11:25 . 2005-03-11 16:43 262144 ----a-w- c:\windows\system32\VTInfo2.dll
2009-12-12 11:25 . 2005-03-11 16:36 397312 ----a-w- c:\windows\system32\VTovrlay.dll
2009-12-12 11:25 . 2005-03-08 02:33 53248 ----a-w- c:\windows\system32\VTTimer.exe
2009-12-12 11:25 . 2005-06-20 15:17 3494144 ----a-w- c:\windows\system32\vtdisp.dll
2009-12-12 11:25 . 2005-05-24 01:36 581632 ----a-w- c:\windows\system32\VTDisply.dll
2009-12-12 11:25 . 2005-04-18 10:15 40960 ----a-w- c:\windows\system32\VModes.exe
2009-12-12 11:25 . 2003-05-27 14:01 159792 ----a-w- c:\windows\system32\S3hotkey.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-17 08:59 . 2009-12-11 20:15 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Media Player Classic
2009-12-16 17:02 . 2009-12-11 20:07 -------- d-----w- c:\program files\Unlocker
2009-12-15 09:00 . 2009-12-11 20:18 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Corel
2009-12-14 22:42 . 2009-12-11 20:18 -------- d-----w- c:\program files\Winamp
2009-12-12 12:19 . 2009-12-12 12:19 -------- d-----w- c:\program files\VIA Technologies, INC
2009-12-12 11:26 . 2009-12-11 20:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-12 11:26 . 2009-12-11 20:04 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-11 20:18 . 2009-12-11 20:18 8704 ----a-r- c:\documents and settings\Rendszergazda\Application Data\Microsoft\Installer\{A16BE761-139E-40D8-826F-F6D077CDFDAD}\IconA16BE7611.exe
2009-12-11 20:18 . 2009-12-11 20:18 80896 ----a-r- c:\documents and settings\Rendszergazda\Application Data\Microsoft\Installer\{A16BE761-139E-40D8-826F-F6D077CDFDAD}\IconA16BE761.exe
2009-12-11 20:18 . 2009-12-11 20:18 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-12-11 20:17 . 2009-12-11 20:17 -------- d-----w- c:\program files\Corel
2009-12-11 20:17 . 2009-12-11 20:17 -------- d-----w- c:\program files\Common Files\Corel
2009-12-11 20:17 . 2009-12-11 20:16 -------- d-----w- c:\program files\CyberLink
2009-12-11 20:15 . 2009-12-11 20:15 -------- d-----w- c:\program files\MSN Messenger
2009-12-11 20:15 . 2009-12-11 20:14 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-11 20:14 . 2009-12-11 20:14 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 20:13 . 2001-10-26 10:00 90012 ----a-w- c:\windows\system32\perfc00E.dat
2009-12-11 20:13 . 2001-10-26 10:00 406250 ----a-w- c:\windows\system32\perfh00E.dat
2009-12-11 20:13 . 2009-12-11 20:13 136 ----a-w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\fusioncache.dat
2009-12-11 20:07 . 2009-12-11 20:07 -------- d-----w- c:\program files\AutoIt3
2009-12-11 20:06 . 2009-12-11 20:06 -------- d-----w- c:\program files\Java
2009-12-11 20:06 . 2009-12-11 20:06 -------- d-----w- c:\program files\Common Files\Java
2009-12-11 20:05 . 2009-12-11 20:05 96256 ----a-w- c:\windows\system32\drivers\sptd0269.sys
2009-12-11 20:05 . 2009-12-11 20:05 643072 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-11 20:03 . 2009-12-11 20:11 10134 ----a-r- c:\documents and settings\Rendszergazda\Application Data\Microsoft\Installer\{F3CA9611-CD42-4562-ADAB-A554CF8E17F1}\ARPPRODUCTICON.exe
2009-12-11 20:03 . 2009-12-11 20:03 -------- d-----w- c:\program files\Microsoft WSE
2009-12-11 19:54 . 2009-12-11 19:53 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-11 19:49 . 2009-12-11 19:49 21948 ----a-w- c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2006-11-14 . DE891AD282E856ACFD40990094A63B6F . 359808 . . [5.1.2600.2892] . . c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerMenu"="c:\windows\powermenu.exe" [2002-12-20 57344]
"AllSnap"="c:\windows\allsnap.exe" [2006-11-14 81920]
"MakeFolder"="c:\windows\makefolder.exe" [2006-11-14 69632]
"S3hotkey"="S3hotkey.exe" [2003-05-27 159792]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-09-20 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-09-20 684122]
"Corel Reminder"="d:\corel\Register\NAVBrowser.exe" [2000-10-04 208896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AfterPost"="c:\windows\afterpost.cmd" [2006-09-22 1322]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"ForceCopyAclwithFile"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"ForceCopyAclwithFile"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2005-11-08 22:00 128920 ----a-w- c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\wincmd\\WINCMD32.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Corel\\Register\\NAVBrowser.exe"=
"c:\\Documents and Settings\\Rendszergazda\\Asztal\\utorrent_1.8.5_17414_EN.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009.12.11. 21:05 643072]
S3 ZD1211BU(TP-LINK);TL-WN322G/WN322G+ Wireless USB Adapter Driver(TP-LINK);c:\windows\system32\drivers\ZD1211BU.sys [2009.12.11. 21:21 500736]
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-18 20:39
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe >>UNKNOWN [0x812FAA40]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x812faa40
\Driver\ACPI -> ACPI.sys @ 0xf9d7acb8
\Driver\atapi -> atapi.sys @ 0xf9d112f0
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a1afe
ParseProcedure -> ntoskrnl.exe @ 0x80570a6e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a1afe
ParseProcedure -> ntoskrnl.exe @ 0x80570a6e
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf9c19ba0
PacketIndicateHandler -> NDIS.sys @ 0xf9c26b21
SendHandler -> NDIS.sys @ 0xf9c0487b
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\sfc_os.dll
- - - - - - - > 'explorer.exe'(4040)
c:\windows\PowerMenuHook.dll
c:\windows\snap_libW.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\S3hotkey.exe
c:\windows\system32\VTTimer.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-12-18 20:41:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-18 19:41
ComboFix2.txt 2009-12-17 10:30
Pre-Run: 7 003 324 416 bájt szabad
Post-Run: 6 978 535 424 bájt szabad
- - End Of File - - EDEA295F4E3000049106B0260BF335BF