ComboFix 09-01-01.02 - Jáger Szilárd 2009-01-02 21:27:53.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.255.81 [GMT 1:00]
Running from: c:\documents and settings\Jáger Szilárd\Asztal\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Jáger Szilárd\Application Data\Adobe\Manager.exe
c:\program files\myglobalsearch
c:\program files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
c:\program files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
c:\program files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
c:\program files\myglobalsearch\bar\1.bin\MGSBAR.DLL
c:\program files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
c:\program files\myglobalsearch\bar\Cache\
00019B7D
c:\program files\myglobalsearch\bar\Cache\
0002CC61.bin
c:\program files\myglobalsearch\bar\Cache\
0012CF3E.bin
c:\program files\myglobalsearch\bar\Cache\
0012D22D.bin
c:\program files\myglobalsearch\bar\Cache\
0012D364.bin
c:\program files\myglobalsearch\bar\Cache\files.ini
c:\program files\myglobalsearch\bar\History\search
c:\program files\myglobalsearch\bar\Settings\prevcfg.htm
c:\program files\myglobalsearch\bar\Settings\settings.dat
c:\program files\myglobalsearch\bar\Settings\settings.dat.bak
c:\program files\myglobalsearch\bar\Settings\settings.htm
c:\program files\myglobalsearch\bar\Settings\settings.htm.bak
----- BITS: Possible infected sites -----
hxxp://91.203.93.21
hxxp://pornotube30.net
hxxp://78.157.143.217
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 18:15 . 2009-01-02 18:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-12-22 09:20 . 2008-12-22 09:20 2,560 --a------ c:\windows\_MSRSTRT.EXE
2008-12-21 12:52 . 2008-12-21 12:52 <DIR> d-------- C:\Downloads
2008-12-21 12:51 . 2008-12-21 12:51 <DIR> d-------- c:\program files\FlashGet
2008-12-18 18:41 . 2008-12-18 18:41 <DIR> d-------- c:\documents and settings\Jáger Szilárd\Phone Browser
2008-12-18 18:41 . 2008-12-18 18:41 <DIR> d-------- c:\documents and settings\Jáger Szilárd\Phone Browser
2008-12-17 21:46 . 2008-12-17 21:46 <DIR> d-------- c:\documents and settings\JERSZI~1\Dokumentumok
2008-12-17 21:46 . 2008-12-17 21:46 <DIR> d-------- c:\documents and settings\J?er Szil?d
2008-12-17 18:30 . 2008-12-17 18:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite
2008-12-17 18:29 . 2008-12-17 18:29 <DIR> d-------- c:\documents and settings\Jáger Szilárd\Application Data\Nokia
2008-12-17 18:27 . 2008-12-17 18:27 <DIR> d-------- c:\program files\Common Files\PCSuite
2008-12-17 18:27 . 2008-12-17 18:27 <DIR> d-------- c:\program files\Common Files\Nokia
2008-12-17 18:26 . 2008-12-17 18:26 <DIR> d-------- c:\program files\DIFX
2008-12-17 18:26 . 2008-12-17 18:26 <DIR> d-------- c:\documents and settings\Jáger Szilárd\Application Data\PC Suite
2008-12-17 18:25 . 2008-12-17 18:25 <DIR> d-------- c:\program files\PC Connectivity Solution
2008-12-17 18:25 . 2007-02-22 10:15 137,216 --a------ c:\windows\system32\drivers\nmwcd.sys
2008-12-17 18:25 . 2007-02-22 10:15 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2008-12-17 18:25 . 2007-02-22 10:15 65,536 --a------ c:\windows\system32\nmwcdcocls.dll
2008-12-17 18:25 . 2007-02-22 10:15 12,288 --a------ c:\windows\system32\drivers\nmwcdcm.sys
2008-12-17 18:25 . 2007-02-22 10:15 12,288 --a------ c:\windows\system32\drivers\nmwcdcj.sys
2008-12-17 18:25 . 2007-02-22 10:15 8,320 --a------ c:\windows\system32\drivers\nmwcdc.sys
2008-12-17 18:22 . 2008-12-17 18:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-26 17:10 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-22 08:52 --------- d-----w c:\program files\Common Files\Ahead
2008-11-22 08:52 --------- d-----w c:\program files\Ahead
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"="c:\program files\ASUS\Probe\AsusProb.exe" [2001-12-17 617984]
"Pop3trap.exe"="c:\program files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [2001-09-13 294982]
"WebTrapNT.exe"="c:\program files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [2001-09-13 235520]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-06 77824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"PCSuiteTrayApplication"="g:\nokia pc suite 6\LaunchApplication.exe" [2007-03-23 227328]
"C-Media Mixer"="Mixer.exe" [2001-12-07 c:\windows\Mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
"Nokia.PCSync"="g:\nokia pc suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\All Users\Start Menu\Programs\Indˇt˘pult\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Trend Micro\\PC-cillin 2000\\WebTrapNT.exe"=
"c:\\WINDOWS\\System32\\rtcshare.exe"=
"d:\\BCDC++\\DCPlusPlus.exe"=
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [2005-02-13 9344]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys [2008-02-16 85760]
R2 tmfilter;tmfilter;c:\windows\system32\DRIVERS\tmxpflt.sys [2001-08-02 148192]
R2 Tmntsrv;Trend NT Realtime Service;"c:\program files\Trend Micro\PC-cillin 2000\Tmntsrv.exe" [2001-09-13 121856]
R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2001-08-02 16064]
R3 cxbu0wdm;CardMan 3x21;c:\windows\system32\DRIVERS\cxbu0wdm.sys [2005-12-12 59151]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2009-01-02 c:\windows\Tasks\Norton Security Scan for Jáger Szilárd.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MSMSGS - c:\program files\Messenger\msmsgs.exe
HKCU-Run-OM_Monitor - c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe
HKLM-Run-PCI Audio Applications - h:\smvalue5.1\W2K-ME\app\Setup.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\wianmpa.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.startlap.hu/
uInternet Connection Wizard,ShellNext = iexplore
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Letöltés a FlashGet-tel - c:\progra~1\FLASHGET\jc_link.htm
IE: Minden letöltése a FlashGet-tel - c:\progra~1\FLASHGET\jc_all.htm
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-02 21:29:42
Windows 5.1.2600 Szervizcsomag 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-02 21:30:34
ComboFix-quarantined-files.txt 2009-01-02 20:30:32
Pre-Run: 392 904 704 bájt szabad
Post-Run: 989,220,864 bájt szabad
155