ComboFix 09-09-22.03 - Agel Peltekov 23.09.2009 21:07.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2047.1490 [GMT 3:00]
Running from: c:\documents and settings\Agel Peltekov\Desktop\tool.exe
Command switches used :: c:\documents and settings\Agel Peltekov\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FMove ---------------
c:\mspmsnsv.dll --> c:\windows\system32\mspmsnsv.dll
.
((((((((((((((((((((((((( Files Created from 2009-08-23 to 2009-09-23 )))))))))))))))))))))))))))))))
.
2009-09-23 17:35 . 2009-09-23 17:39 -------- d-----w- C:\tool5524t
2009-09-23 17:28 . 2009-09-23 17:28 0 ----a-w- C:\backup.reg
2009-09-23 16:05 . 2009-09-23 16:05 -------- d-----w- c:\windows\system32\xircom
2009-09-23 16:05 . 2009-09-23 16:05 -------- d-----w- c:\windows\system32\wbem\snmp
2009-09-23 16:05 . 2009-09-23 16:05 -------- d-----w- c:\program files\microsoft frontpage
2009-09-23 14:27 . 2009-09-23 14:31 -------- d-----w- C:\tool
2009-09-23 12:58 . 2009-09-23 12:58 -------- d-----w- c:\program files\Trend Micro
2009-09-23 11:30 . 2009-09-23 11:30 -------- d-----w- c:\documents and settings\Agel Peltekov\Application Data\Malwarebytes
2009-09-23 11:30 . 2009-09-23 11:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-23 11:23 . 2009-09-23 11:23 -------- d-----w- c:\documents and settings\Agel Peltekov\Application Data\PCToolsFirewallPlus
2009-09-23 11:23 . 2009-08-24 11:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-09-23 11:23 . 2009-08-19 08:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-09-23 11:23 . 2009-08-27 06:17 229176 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-09-23 11:23 . 2009-09-23 11:23 -------- d-----w- c:\program files\Common Files\PC Tools
2009-09-23 11:23 . 2009-08-14 09:44 32552 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2009-09-23 11:23 . 2009-08-14 09:44 70280 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2009-09-23 11:23 . 2009-07-29 06:54 46592 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2009-09-23 11:23 . 2009-08-14 09:44 114832 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2009-09-23 11:23 . 2009-09-23 11:24 -------- d-----w- c:\program files\PC Tools Firewall Plus
2009-09-16 08:21 . 2009-09-16 08:21 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-14 08:21 . 2009-09-14 08:21 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-09-14 08:21 . 2009-09-14 08:21 -------- d-----w- c:\program files\McAfee Security Scan
2009-09-14 08:20 . 2009-09-14 08:20 -------- d-----w- c:\documents and settings\Agel Peltekov\Local Settings\Application Data\Macromedia
2009-09-14 08:17 . 2009-09-14 08:17 -------- d-----w- c:\windows\system32\QuickTime
2009-09-14 08:17 . 2009-09-14 08:18 -------- d-----w- c:\program files\Common Files\Macromedia
2009-09-14 08:17 . 2009-09-14 08:17 -------- d-----w- c:\program files\Macromedia
2009-09-14 08:16 . 2009-09-14 08:16 -------- d-----w- c:\windows\Downloaded Installations
2009-09-09 07:34 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-07 12:00 . 2009-09-07 12:00 -------- d-----w- c:\windows\6FF543AB99B34120902C70A38314ABD8.TMP
2009-09-07 11:30 . 2009-09-07 11:30 -------- d-----w- c:\documents and settings\Agel Peltekov\Local Settings\Application Data\Adobe
2009-09-02 14:51 . 2009-09-02 15:56 -------- d-----w- c:\program files\Super Audio Converter
2009-09-02 13:28 . 2009-09-02 13:29 -------- d-----w- c:\program files\Adobe Photoshop CS4
2009-09-02 10:26 . 2009-09-02 10:26 -------- d-----w- c:\documents and settings\Agel Peltekov\Application Data\Corel
2009-09-02 10:15 . 1999-02-17 08:49 368912 ----a-w- c:\windows\system32\VBAR332.DLL
2009-09-02 10:15 . 1999-02-17 08:49 1039360 ----a-w- c:\windows\system32\MSJET35.DLL
2009-08-31 08:19 . 2009-08-31 08:19 -------- d-----w- c:\program files\FreeTime
2009-08-26 12:54 . 2008-04-04 18:00 147456 ----a-w- c:\windows\system32\hpcpn5r1.dll
2009-08-25 09:13 . 2009-08-25 09:22 -------- d-----w- c:\windows\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-23 18:12 . 2009-02-09 15:44 -------- d-----w- c:\documents and settings\Agel Peltekov\Application Data\Skype
2009-09-23 18:11 . 2009-07-12 06:52 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-23 17:59 . 2008-04-26 14:08 27136 ----a-w- c:\windows\system32\mspmsnsv.dll
2009-09-23 17:44 . 2009-02-07 18:00 -------- d-----w- c:\program files\Styler
2009-09-23 13:05 . 2009-02-09 15:45 -------- d-----w- c:\documents and settings\Agel Peltekov\Application Data\skypePM
2009-09-15 09:44 . 2009-02-07 18:24 -------- d-----w- c:\documents and settings\Agel Peltekov\Application Data\uTorrent
2009-09-14 08:27 . 2009-02-09 08:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-09 11:22 . 2009-02-09 15:35 75608 ----a-w- c:\documents and settings\Agel Peltekov\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-07 10:31 . 2009-02-07 18:53 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-03 07:55 . 2009-02-07 18:00 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-02 14:56 . 2009-07-12 06:52 -------- d-----w- c:\program files\AoA DVD Ripper
2009-09-02 14:48 . 2009-03-18 14:28 -------- d-----w- c:\program files\Witcobber
2009-09-02 10:14 . 2009-09-02 10:14 -------- d-----w- c:\program files\Corel
2009-08-14 03:58 . 2009-09-23 11:23 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-06 12:31 . 2009-02-13 15:30 -------- d-----w- c:\program files\DVD Audio Extractor
2009-08-05 09:01 . 2008-04-14 04:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-28 13:21 . 2009-02-07 18:19 -------- d-----w- c:\program files\LClock
2009-07-17 19:01 . 2008-04-14 04:41 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 20:43 . 2008-04-26 14:08 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:23 . 2008-04-26 14:38 828928 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:23 . 2008-04-26 14:37 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:23 . 2008-04-26 14:37 17408 ----a-w- c:\windows\system32\corpol.dll
.
------- Sigcheck -------
[-] 2009-09-23 17:59 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-23_14.30.19 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-08-23 12:00 . 2009-08-25 09:16 71196 c:\windows\system32\perfc009.dat
+ 2001-08-23 12:00 . 2009-09-23 16:09 71196 c:\windows\system32\perfc009.dat
+ 2001-08-23 12:00 . 2009-09-23 16:09 441260 c:\windows\system32\perfh009.dat
- 2001-08-23 12:00 . 2009-08-25 09:16 441260 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"True Transparency"="c:\program files\Utilities\True Transparency\TrueTransparency.exe" [2007-10-28 133120]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe" [2009-06-05 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-08-27 2971608]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-03-21 16126464]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-01-15 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"True Transparency"="c:\program files\Utilities\True Transparency\TrueTransparency.exe" [2007-10-28 133120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-06-29 124928]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [23.9.2009 14:23 229176]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [23.9.2009 14:23 86888]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [07.2.2009 22:51 36864]
R3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\system32\drivers\pctNdis-DNS.sys [23.9.2009 14:23 32552]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [23.9.2009 14:23 70280]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [23.9.2009 14:23 46592]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [23.9.2009 14:23 114832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mystart.incredimail.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: {889AA017-750E-4A46-8B36-CB91153A0B4D} = 212.39.90.42,212.39.90.43
FF - ProfilePath - c:\documents and settings\Agel Peltekov\Application Data\Mozilla\Firefox\Profiles\dg3z21by.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.bg/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-23 21:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1390067357-746137067-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Clsid]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3808)
c:\windows\system32\WININET.dll
c:\program files\Utilities\True Transparency\TrueTransparencyHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\rundll32.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Microsoft Office\Office12\ONENOTEM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-23 21:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-23 18:13
ComboFix2.txt 2009-09-23 17:39
ComboFix3.txt 2009-09-23 16:52
ComboFix4.txt 2009-09-23 14:31
Pre-Run: 33 101 680 640 bytes free
Post-Run: 33 064 886 272 bytes free
199 --- E O F --- 2009-09-09 17:30
Сега трябва да стана от този компютър довечера ще влезна от къщи. Напиши ми пост ако сме приключили ако не утре ще довършим. Чао за днес и мерси за омощта.