[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
това е единият лог а ето го и другият...
ComboFix 11-03-08.09 - DJ_XD 03.2011 г. 20:06:15.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.2047.1461 [GMT 2:00]
Running from: c:\documents and settings\DJ_XD\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\regedit.exe . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2011-02-09 to 2011-03-09 )))))))))))))))))))))))))))))))
.
.
2011-03-08 16:17 . 2009-10-21 05:50 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll
2011-03-08 16:17 . 2009-10-21 05:50 25088 ------w- c:\windows\system32\dllcache\httpapi.dll
2011-03-08 16:17 . 2009-10-20 14:41 265728 ------w- c:\windows\system32\dllcache\http.sys
2011-03-08 05:03 . 2011-03-08 05:03 -------- d-sh--w- c:\documents and settings\DJ_XD\IETldCache
2011-03-07 21:11 . 2011-03-07 21:11 -------- d-----w- c:\documents and settings\DJ_XD\Application Data\Avira
2011-03-07 21:11 . 2011-03-08 07:51 -------- d-----w- c:\windows\system32\NtmsData
2011-03-07 21:08 . 2011-01-10 12:23 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-03-07 21:08 . 2011-01-10 12:23 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-03-07 21:08 . 2010-06-17 12:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-03-07 21:08 . 2010-06-17 12:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-03-07 21:08 . 2011-03-07 21:08 -------- d-----w- c:\program files\Avira
2011-03-07 21:08 . 2011-03-07 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-03-07 21:05 . 2011-03-08 20:31 -------- d-----w- c:\program files\Kaspersky Lab
2011-03-07 20:01 . 2010-05-06 10:41 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2011-03-07 20:01 . 2010-05-06 10:41 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll
2011-03-07 20:01 . 2010-05-06 10:41 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-03-07 20:01 . 2010-05-06 10:41 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2011-03-07 20:01 . 2010-05-06 10:41 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2011-03-07 20:01 . 2010-05-06 10:41 11076096 ------w- c:\windows\system32\dllcache\ieframe.dll
2011-03-07 20:01 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2011-03-07 20:00 . 2011-03-07 20:01 -------- dc-h--w- c:\windows\ie8
2011-03-07 19:50 . 2008-02-26 11:48 297984 ------w- c:\windows\system32\dllcache\msctf.dll
2011-03-07 19:48 . 2011-03-07 19:48 -------- d-----w- c:\windows\ServicePackFiles
2011-03-07 19:34 . 2011-03-07 19:34 -------- d-----w- c:\program files\MSXML 4.0
2011-03-07 19:34 . 2011-03-08 18:43 -------- d--h--w- c:\windows\$hf_mig$
2011-03-07 19:06 . 2011-03-08 05:37 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-03-07 19:03 . 2008-06-12 13:47 956928 ------w- c:\windows\system32\dllcache\msdtctm.dll
2011-03-07 19:01 . 2009-06-25 18:36 95744 ------w- c:\windows\system32\dllcache\mqsec.dll
2011-03-07 19:00 . 2010-05-06 10:41 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll
2011-03-07 18:59 . 2010-02-24 12:48 457216 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2011-03-07 18:59 . 2009-11-21 16:24 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
2011-03-07 18:59 . 2010-06-14 14:30 743936 ------w- c:\windows\system32\dllcache\helpsvc.exe
2011-03-07 18:57 . 2011-03-07 18:57 -------- d-----w- c:\documents and settings\DJ_XD\Application Data\Malwarebytes
2011-03-07 18:57 . 2011-03-07 18:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-03-07 18:57 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-07 18:57 . 2011-03-07 18:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-07 18:57 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-07 18:57 . 2009-06-21 22:04 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2011-03-07 18:57 . 2009-10-23 14:27 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe
2011-03-07 18:55 . 2009-09-11 14:03 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2011-03-07 18:55 . 2009-06-25 08:17 729600 ------w- c:\windows\system32\dllcache\lsasrv.dll
2011-03-07 18:55 . 2009-06-25 08:17 59392 ------w- c:\windows\system32\dllcache\wdigest.dll
2011-03-07 18:55 . 2009-06-25 08:17 56320 ------w- c:\windows\system32\dllcache\secur32.dll
2011-03-07 18:55 . 2009-06-25 08:17 301568 ------w- c:\windows\system32\dllcache\kerberos.dll
2011-03-07 18:55 . 2009-06-25 08:17 168448 ------w- c:\windows\system32\dllcache\schannel.dll
2011-03-07 18:55 . 2009-06-22 11:35 92544 ------w- c:\windows\system32\dllcache\ksecdd.sys
2011-03-07 18:55 . 2009-02-06 18:46 408064 ------w- c:\windows\system32\dllcache\netlogon.dll
2011-03-07 18:53 . 2008-05-08 12:14 203008 ------w- c:\windows\system32\dllcache\rmcast.sys
2011-03-07 18:53 . 2008-05-01 14:30 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2011-03-07 18:53 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2011-03-07 18:52 . 2008-10-15 16:53 339456 ------w- c:\windows\system32\dllcache\netapi32.dll
2011-03-07 18:51 . 2009-07-31 04:57 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2011-03-07 18:51 . 2008-04-21 10:02 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2011-03-07 18:50 . 2009-12-09 05:53 726528 ----a-w- c:\windows\system32\dllcache\jscript.dll
2011-03-07 18:50 . 2009-12-24 07:05 177664 ------w- c:\windows\system32\dllcache\wintrust.dll
2011-03-07 18:50 . 2010-01-13 14:10 85504 ------w- c:\windows\system32\dllcache\cabview.dll
2011-03-07 18:42 . 2011-03-07 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2011-03-02 21:41 . 2011-03-02 21:41 -------- d-----w- c:\documents and settings\DJ_XD\Local Settings\Application Data\WinAVI
2011-03-02 21:41 . 2011-03-02 21:41 -------- d-----w- c:\documents and settings\DJ_XD\Application Data\WinAVI
2011-03-02 21:41 . 2011-03-02 21:41 -------- d-----w- c:\program files\Video Converter
2011-03-01 21:39 . 2011-03-01 21:39 -------- d-----w- c:\program files\Solveig Multimedia
2011-03-01 21:39 . 2011-03-01 21:39 -------- d-----w- c:\program files\Common Files\Solveig Multimedia
2011-02-22 20:36 . 2011-02-22 20:36 -------- d-----w- c:\program files\Common Files\PCSuite
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
------- Sigcheck -------
.
[-] 2008-04-14 00:11 . 1280A158C722FA95A80FB7AEBE78FA7D . 792064 . . [2001.12.4414.700] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\comres.dll
[-] 2007-11-19 23:00 . 2EA91A7FA49288C6030691C5817F2BC7 . 1526784 . . [2001.12.4414.258] . . c:\windows\system32\comres.dll
.
[-] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\asms\60\msft\windows\common\controls\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\comctl32.dll
[-] 2007-11-19 . 43A336FC1C015417D981B2D32B27B8FF . 643072 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2007-11-19 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[7] 2007-11-19 . C4E80875C1CF1222FC5EFD0314AE5C01 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
.
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\user32.dll
[-] 2007-11-19 . 7A540726CA75E1E988D56AB69925BA79 . 577536 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
.
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[-] 2007-11-19 . 3D8A3BA32663082A2256F0EB986C3025 . 1647616 . . [6.00.2900.3156] . . c:\windows\explorer.exe
.
[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ctfmon.exe
[-] 2007-11-19 . E00DFA816FA5521EB44C5D63109DE2A9 . 40448 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2010-07-28 1267024]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog0.dll" [2011-02-09 3911776]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2011-02-09 11:01 3911776 ----a-w- c:\program files\ToggleEN\tbTog0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-02-09 11:01 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngin1.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\DVDVideoSoftTB\tbDVD0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog0.dll" [2011-02-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin1.dll" [2011-02-09 3911776]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTog0.dll" [2011-02-09 3911776]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\tbDVD0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2010-11-11 570688]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-12-13 395640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-08-15 30003200]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-11-19 40448]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-08-29 1232384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\DJ_XD\Start Menu\Programs\Startup\
Styler.lnk - c:\documents and settings\DJ_XD\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2010-9-23 15086]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2010-9-23 95232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
2010-12-08 12:42 10811696 ----a-w- c:\program files\BitComet\BitComet.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ChrisTV Agent]
2008-11-11 12:35 275456 ----a-w- c:\program files\ChrisTV PVR Standard\ChrisTV_Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 15:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-11-04 13:10 136176 ----atw- c:\documents and settings\DJ_XD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LClock]
2004-09-19 05:27 65536 ----a-w- c:\program files\LClock\LClock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCM]
2009-08-21 12:06 2456064 ----a-w- c:\program files\Mp3 Convert Master\Mp3ConvertMaster.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 07:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
2010-03-04 12:10 2192672 ----a-w- c:\program files\Nokia\Ovi Player\NokiaOviPlayer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-01-31 10:16 703360 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-12-21 09:53 1483264 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Timezone]
2004-10-19 05:01 712704 ----a-w- c:\windows\system32\TimeZone.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2006-09-07 06:19 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-12-13 17:18 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Install\\LDC++_new_BG\\LDC++\\LDCPlusPlus.exe"=
"c:\\Program Files\\MixMeister Express 6\\MmExpressDemo.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\LDC++\\LDCPlusPlus.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20515:TCP"= 20515:TCP:BitComet 20515 TCP
"20515:UDP"= 20515:UDP:BitComet 20515 UDP
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [20.12.2010 і. 21:48 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [20.12.2010 і. 21:48 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.11.2010 і. 15:59 420920]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [07.3.2011 і. 23:08 135336]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [01.12.2003 і. 14:27 53248]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [23.9.2010 і. 14:01 845184]
S2 713xTVCard;SAA7131 TV Card;c:\windows\system32\drivers\SAA713x.sys [15.3.2005 і. 11:00 277504]
S2 FlexService;Remote Connections Service;c:\program files\RapidBIT\cisvc.exe [17.5.2009 і. 04:16 41984]
S3 FlyPCI;FlyPCI;c:\windows\system32\drivers\FlyPCI.sys [23.9.2010 і. 19:11 4134]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
2009-03-08 02:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-839522115-725345543-1003Core.job
- c:\documents and settings\DJ_XD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-04 13:10]
.
2011-03-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-839522115-725345543-1003UA.job
- c:\documents and settings\DJ_XD\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-11-04 13:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://bksly.startya.com/?cfg=2-564-0-0&engine_id=3&provider_id=3&product_id=564&country=BG
uDefault_Search_URL = hxxp://search.autocompletepro.com/?si=10182&bi=400
uInternet Connection Wizard,ShellNext = hxxp://google.bg/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\DJ_XD\Application Data\Mozilla\Firefox\Profiles\y64l02qb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://bksly.startya.com/?cfg=2-564-0-0&engine_id=3&provider_id=3&product_id=564&country=BG
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - %profile%\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - Ext: DAEMON Tools Toolbar:
[email protected] - %profile%\extensions\
[email protected]
FF - Ext: AutocompletePro - Your handy search suggestions tool:
[email protected] - %profile%\extensions\
[email protected]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
FF - Ext: PC Sync 2 Synchronisation Extension:
[email protected] - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-09 20:08
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(492)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'explorer.exe'(2848)
c:\windows\system32\WININET.dll
c:\windows\system32\msctfime.ime
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-03-09 20:09:04
ComboFix-quarantined-files.txt 2011-03-09 18:09
ComboFix2.txt 2011-03-09 18:03
.
Pre-Run: 5 854 232 576 bytes free
Post-Run: 5 840 924 672 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 613E7109384CBC82BC08934F1066E828