стана воина с нод 32ComboFix 09-04-04.01 - User 2008-04-09 21:22:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.1.1033.18.2047.1558 [GMT 3:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated)
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-04 to 2009-04-04 )))))))))))))))))))))))))))))))
.
2009-03-31 22:28 . 2009-03-31 22:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\TVU Networks
2009-03-31 21:19 . 2009-03-31 21:19 <DIR> d-------- c:\program files\DirectX
2009-03-30 21:37 . 2009-03-30 21:38 <DIR> d-------- c:\documents and settings\User\Application Data\Microsoft Games
2009-03-29 20:07 . 2009-03-29 20:07 29,360 --a------ c:\windows\_SETUPD_.EXE
2009-03-29 17:36 . 2009-01-04 12:35 31,232 --a------ c:\windows\system\vdremote.dll
2009-03-29 17:36 . 2009-01-04 12:35 25,088 --a------ c:\windows\system\vdsvrlnk.dll
2009-03-29 09:46 . 2009-03-29 09:46 <DIR> d-------- c:\documents and settings\User\LocalLow
2009-03-28 23:35 . 2002-01-05 05:37 344,064 --a------ c:\windows\system32\Msvcr70.dll
2009-03-26 00:37 . 2009-03-26 00:37 73 --a------ c:\windows\EurekaLog.ini
2009-03-25 23:58 . 2009-03-25 23:58 <DIR> d-------- c:\program files\OpenAL
2009-03-25 23:58 . 2008-04-08 21:00 418,480 --a------ c:\windows\system32\wrap_oal.dll
2009-03-25 23:58 . 2008-04-08 21:00 115,432 --a------ c:\windows\system32\OpenAL32.dll
2009-03-25 23:41 . 2009-03-27 19:59 <DIR> d-------- c:\documents and settings\User\Application Data\Godlike
2009-03-22 15:00 . 2009-03-22 15:01 <DIR> d-------- c:\documents and settings\User\Application Data\DC++
2009-03-20 19:43 . 2009-03-20 19:43 <DIR> d-------- c:\documents and settings\User\Application Data\Outerspace Software
2009-03-17 20:05 . 2009-03-17 20:05 <DIR> d-------- c:\documents and settings\User\Application Data\FastStone
2009-03-12 21:04 . 2009-03-12 21:06 <DIR> d-------- c:\documents and settings\User\Application Data\Marine Aquarium 3
2009-03-12 21:04 . 2009-03-03 16:14 6,545,408 --a------ c:\windows\system32\MarineAquarium3.scr
2009-03-12 20:07 . 2009-03-30 22:13 <DIR> d-------- c:\documents and settings\User\Application Data\Babylon
2009-03-12 20:07 . 2009-03-30 22:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Babylon
2009-03-10 21:04 . 2008-04-05 19:20 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2009-03-10 21:03 . 2008-04-05 19:20 103,736 --a------ c:\windows\system32\PnkBstrB.exe
2009-03-10 20:50 . 2009-03-10 20:50 <DIR> dr-h----- c:\documents and settings\User\Application Data\SecuROM
2009-03-10 20:42 . 2009-03-10 21:10 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-03-10 20:38 . 2008-04-05 19:05 22,328 --a------ c:\documents and settings\User\Application Data\PnkBstrK.sys
2009-03-10 20:37 . 2009-03-10 20:37 <DIR> d-------- c:\windows\system32\LogFiles
2009-03-10 20:37 . 2008-04-05 19:16 66,872 --a------ c:\windows\system32\PnkBstrA.exe
2009-03-10 19:13 . 2009-03-10 19:15 873,472 --a------ c:\windows\WATERYDS.SCR
2009-03-10 19:13 . 2008-12-08 04:02 69,120 --a------ c:\windows\WateryDesktop_vista.dll
2009-03-10 19:13 . 2008-12-08 04:02 53,248 --a------ c:\windows\WateryDesktop_xp.dll
2009-03-09 22:48 . 2009-03-09 22:48 <DIR> d-------- c:\documents and settings\User\Application Data\COWON
2009-03-09 22:47 . 2009-03-29 20:13 <DIR> d-------- c:\program files\JetAudio
2009-03-09 22:47 . 2009-03-09 22:47 <DIR> d-------- c:\program files\Common Files\COWON
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-06 12:32 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 12:32 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-24 19:03 --------- d-----w c:\documents and settings\User\Application Data\Dark Sector
2009-03-16 11:18 69,448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 11:18 517,448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 11:18 235,352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 11:18 22,360 ----a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 12:27 453,456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 12:27 4,178,264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-03-09 12:27 1,846,632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-06 14:01 --------- d-----w c:\documents and settings\User\Application Data\CyberLink
2009-03-03 19:05 --------- d-----w c:\program files\CyberLink
2009-03-03 18:41 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-03-03 18:09 --------- d-----w c:\program files\Common Files\CyberLink
2009-03-03 03:08 --------- d-----w c:\program files\TeamViewer
2009-03-03 02:58 --------- d-----w c:\documents and settings\User\Application Data\TeamViewer
2009-03-02 20:28 --------- d-----w c:\program files\AGEIA Technologies
2009-03-02 20:03 --------- d-----w c:\documents and settings\User\Application Data\DAEMON Tools Lite
2009-03-02 19:00 --------- d-----w c:\documents and settings\User\Application Data\URSoft
2009-03-02 18:20 --------- d-----w c:\program files\Common Files\Adobe
2009-03-02 14:46 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-02 13:58 --------- d-----w c:\documents and settings\User\Application Data\Media Player Classic
2009-02-25 20:10 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-25 20:07 --------- d-----w c:\program files\NOS
2009-02-25 20:07 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2009-02-25 20:01 --------- d-----w c:\documents and settings\User\Application Data\AdobeUM
2009-02-22 19:41 --------- d-----w c:\program files\Common Files\TechSmith Shared
2009-02-22 19:41 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2009-02-12 18:48 --------- d-----w c:\program files\uTorrent
2009-02-12 18:42 --------- d-----w c:\documents and settings\User\Application Data\DAEMON Tools Pro
2009-02-12 18:42 --------- d-----w c:\documents and settings\User\Application Data\DAEMON Tools
2009-02-12 18:41 --------- d-----w c:\program files\DAEMON Tools Lite
2009-02-12 18:41 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-02-12 18:38 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-02-12 17:29 --------- d-----w c:\program files\Intel
2009-02-12 17:24 --------- d-----w c:\program files\microsoft frontpage
2009-02-12 17:20 --------- d-----w c:\program files\Windows Media Connect 2
2009-02-12 15:53 --------- d-----w c:\program files\Winamp
2009-02-12 15:51 --------- d-----w c:\program files\Nero
2009-02-12 15:51 --------- d-----w c:\program files\Common Files\Ahead
2009-02-12 15:49 --------- d-----w c:\program files\SA Dictionary 2004 Datacenter
2009-02-12 15:47 --------- d-----w c:\program files\Microsoft ActiveSync
2009-02-12 15:47 --------- d-----w c:\program files\Datecs
2009-02-12 15:44 --------- d-----w c:\program files\ESET
2009-02-12 15:44 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-02-12 15:40 --------- d-----w c:\program files\Skype
2009-02-12 15:40 --------- d-----w c:\program files\Common Files\Skype
2009-02-12 15:39 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-12 15:38 --------- d-----w c:\program files\Webteh
2009-02-12 15:37 --------- d-----w c:\program files\K-Lite Codec Pack
2009-02-12 15:33 --------- d-----w c:\program files\Realtek
2009-02-12 15:25 --------- d-----w c:\program files\Vimicro
2009-02-12 15:25 --------- d-----w c:\documents and settings\User\Application Data\InstallShield
2009-02-12 15:21 --------- d-----w c:\program files\Attansic
2009-02-12 15:18 315,392 ----a-w c:\windows\HideWin.exe
2006-06-23 06:48 32,768 ----a-r c:\windows\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BigDogPath323Domino"="c:\windows\Domino.exe" [2007-01-09 49152]
"BigDogPath323VMSnap"="c:\windows\VMSnap23.exe" [2007-01-09 212992]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-02-16 87336]
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2008-10-13 50472]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-02-12 95232]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 06:42 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:20 155648 c:\windows\system32\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"f:\\Dark Sector\\DS.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"f:\\Far Cry 2\\bin\\farcry2.exe"=
"f:\\New Folder\\GoW\\Binaries\\WarGame-G4WLive.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2007-12-21 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2009-02-12 38656]
R3 MaplomL;MaplomL;c:\windows\system32\drivers\maploml.sys [2009-03-02 38336]
R3 vmfilter323;323 filter service, Normal;c:\windows\system32\drivers\vmfilter323.sys [2009-02-12 476672]
R3 ZSMC326;Vimicro USB2.0 PC Camera(VC0323);c:\windows\system32\drivers\usbvm323.sys [2009-02-12 260224]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-02-25 33752]
S3 PPDrv;Protector Plus Driver (UnRegistered);\??\c:\protector plus\PPDrv.sys --> c:\protector plus\PPDrv.sys [?]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\PPEMSCAN.sys --> c:\protector plus\PPEMSCAN.sys [?]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PUSH Wallpaper - f:\installirani\Watery Desktop 3D\Watery Desktop 3D.exe
HKLM-Run-Babylon Client - f:\installirani\Babylon\Babylon.exe
HKLM-Run-TrojanScanner - f:\installirani\Your Uninstaller 2008\Trojan Remover\Trjscan.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.codecguide.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Translate with &Babylon - f:\babylon\Utils\BabylonIEPI.dll/Translate.htm
TCP: {069BED30-8EF9-4115-81EE-C8EF31C1EE66} = 83.143.183.7 83.143.183.2
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-04 21:23:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-790525478-1214440339-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:22,4d,4b,83,c4,e7,54,60,7a,8c,fd,83,48,df,52,d1,c6,26,04,be,de,
51,ad,a0,da,0f,3c,bb,a2,3b,d6,4d,59,5d,f7,97,7f,82,ef,a7,dc,31,0f,06,7b,32,\
"rkeysecu"=hex:9e,ce,99,94,3d,64,be,af,91,ba,01,59,7d,7c,6d,3e
.
Completion time: 2009-04-04 21:23:54
ComboFix-quarantined-files.txt 2009-04-04 18:23:52
Pre-Run: 35 859 423 232 bytes free
Post-Run: 35,964,002,304 bytes free
197