ComboFix 09-06-14.02 - Administrator 03/18/2009 17:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.306 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Cache
c:\windows\system32\aaJSrtwa.ini
c:\windows\system32\aaJSrtwa.ini2
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\opnmNdDT.dll.vir
c:\windows\system32\rapepute.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.
2009-03-18 15:31 . 2009-03-18 15:31 ——– d—–w- c:\windows\system32\xircom
2009-03-18 15:31 . 2009-03-18 15:31 ——– d—–w- c:\windows\system32\wbem\snmp
2009-03-18 15:31 . 2009-03-18 15:31 ——– d—–w- c:\program files\microsoft frontpage
2009-03-18 15:16 . 2008-12-11 06:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-03-18 15:16 . 2009-03-06 14:45 130424 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-03-18 15:16 . 2008-12-18 10:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-18 15:16 . 2009-03-18 15:17 ——– d—–w- c:\program files\Common Files\PC Tools
2009-03-18 15:16 . 2008-12-10 10:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-03-18 15:15 . 2009-03-18 15:18 ——– d—–w- c:\program files\Spyware Doctor
2009-03-18 15:15 . 2009-03-18 15:15 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-03-18 15:15 . 2009-03-18 15:15 ——– d—–w- c:\documents and settings\Administrator\Application Data\PC Tools
2009-03-18 15:07 . 2009-06-13 18:00 3015544 —-a-w- c:\documents and settings\Administrator\Application Data\Simply Super Software\Trojan Remover\evo44.exe
2009-03-18 14:47 . 2009-03-18 14:47 ——– d—–w- C:\VundoFix Backups
2009-03-18 14:42 . 2009-03-18 14:42 ——– d—–w- c:\program files\Trend Micro
2009-03-18 13:49 . 2009-03-18 13:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\AdwareAlert
2009-03-18 13:14 . 2006-06-19 11:01 69632 —-a-w- c:\windows\system32\ztvcabinet.dll
2009-03-18 13:14 . 2006-05-25 13:52 162304 —-a-w- c:\windows\system32\ztvunrar36.dll
2009-03-18 13:14 . 2005-08-25 23:50 77312 —-a-w- c:\windows\system32\ztvunace26.dll
2009-03-18 13:14 . 2003-02-02 18:06 153088 —-a-w- c:\windows\system32\UNRAR3.dll
2009-03-18 13:14 . 2002-03-05 23:00 75264 —-a-w- c:\windows\system32\unacev2.dll
2009-03-18 13:14 . 2009-03-18 13:14 ——– d—–w- c:\program files\Trojan Remover
2009-03-18 13:14 . 2009-03-18 13:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-03-18 13:14 . 2009-03-18 13:14 ——– d—–w- c:\documents and settings\Administrator\Application Data\Simply Super Software
2009-03-17 15:49 . 2009-03-17 15:49 236544 —-a-w- c:\windows\system32\awtrSJaa.dll.vir
2009-03-17 15:45 . 2009-03-18 13:08 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2009-03-17 13:48 . 2009-03-17 19:59 ——– d—–w- c:\program files\Download Direct
2009-03-17 10:49 . 2009-03-17 12:46 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Download_jocuri
2009-03-17 10:49 . 2009-03-17 10:49 ——– d—–w- c:\program files\Conduit
2009-03-17 10:49 . 2009-03-17 10:49 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2009-03-17 10:49 . 2009-03-17 10:49 ——– d—–w- c:\program files\Download_jocuri
2009-03-17 09:09 . 2009-03-17 09:09 ——– d—–w- c:\documents and settings\Administrator\WINDOWS
2009-03-17 08:58 . 2001-05-16 15:54 309616 —-a-w- c:\windows\system32\wmv8dmod.dll
2009-03-17 08:58 . 2001-05-11 11:18 420240 —-a-w- c:\windows\system32\mpg4c32.dll
2009-03-17 08:55 . 2009-03-17 08:55 217088 —-a-w- c:\windows\system32\srkey.exe
2009-03-17 08:55 . 2009-03-17 08:55 ——– d—–w- c:\documents and settings\Administrator\Application Data\Leadertech
2009-03-17 08:38 . 2009-03-17 08:38 4096 —-a-w- c:\windows\d3dx.dat
2009-03-17 08:04 . 2009-03-17 08:05 ——– d—–w- c:\documents and settings\Administrator\Application Data\Mysteryville2
2009-03-17 08:03 . 2009-03-18 13:07 ——– d—–w- c:\program files\iWin.com Games
2009-03-12 11:03 . 2009-03-12 11:03 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-03-12 10:16 . 2004-06-10 19:10 516096 —-a-w- c:\windows\system32\ati2sgag.exe
2009-03-12 10:16 . 2004-06-11 05:54 294912 —-a-r- c:\windows\system32\atiiiexx.dll
2009-03-12 10:16 . 2004-06-11 05:27 131072 —-a-r- c:\windows\system32\ATIDEMGR.dll
2009-03-12 09:19 . 2009-03-12 09:19 616 —-a-w- c:\windows\eReg.dat
2009-03-11 22:17 . 2009-03-11 22:17 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Ironclad Games
2009-03-11 22:13 . 2009-03-11 22:13 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Stardock
2009-03-11 21:15 . 2009-03-11 21:15 ——– d—–w- c:\documents and settings\Administrator\Application Data\springsettings
2009-03-11 20:56 . 2009-03-28 17:52 94208 —-a-w- c:\documents and settings\Administrator\Application Data\Soldat\Battleye\BEServer.dll
2009-03-11 20:56 . 2009-03-28 17:52 102400 —-a-w- c:\documents and settings\Administrator\Application Data\Soldat\Battleye\BEClient.dll
2009-03-11 20:54 . 2009-03-11 20:54 ——– d—–w- c:\documents and settings\Administrator\Application Data\Soldat
2009-03-11 20:31 . 1998-10-29 14:45 306688 —-a-w- c:\windows\IsUninst.exe
2009-03-11 20:24 . 2009-03-12 09:52 14200 —ha-w- c:\windows\system32\mlfcache.dat
2009-03-11 19:27 . 2009-03-18 15:49 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-03-11 19:22 . 2009-03-15 18:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Speedbit
2009-03-11 18:35 . 2009-03-11 18:35 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-03-11 18:35 . 2009-03-11 18:35 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-03-11 18:35 . 2009-03-11 18:35 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple
2009-03-11 18:35 . 2009-03-11 18:35 ——– d—–w- c:\program files\Apple Software Update
2009-03-11 18:35 . 2009-03-11 18:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-03-10 21:28 . 2009-03-10 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\NevoSoft Games
2009-03-10 21:03 . 2009-03-10 21:03 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\World in Conflict
2009-03-10 21:01 . 2007-04-04 16:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll
2009-03-10 21:01 . 2007-03-15 14:57 443752 —-a-w- c:\windows\system32\d3dx10_33.dll
2009-03-10 21:01 . 2007-03-12 14:42 3495784 —-a-w- c:\windows\system32\d3dx9_33.dll
2009-03-10 21:01 . 2007-03-12 14:42 1123696 —-a-w- c:\windows\system32\D3DCompiler_33.dll
2009-03-10 21:01 . 2006-09-28 14:05 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll
2009-03-10 08:14 . 2009-03-10 08:40 ——– d—–w- c:\program files\DC++
2009-03-09 22:47 . 2001-08-17 12:55 6144 —-a-w- c:\windows\system32\kbd101c.dll
2009-03-09 22:47 . 2001-08-17 12:55 6144 —-a-w- c:\windows\system32\kbd101b.dll
2009-03-09 22:47 . 2008-04-14 03:39 6144 —-a-w- c:\windows\system32\kbd106.dll
2009-03-09 18:59 . 2009-03-09 18:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2009-03-09 18:58 . 2009-03-09 18:58 ——– d—–w- c:\program files\VideoLAN
2009-03-09 12:04 . 2009-03-09 12:04 ——– d—–w- c:\program files\XP Codec Pack
2009-03-08 16:57 . 2009-03-08 16:57 ——– d–h–w- c:\windows\PIF
2009-03-08 12:52 . 2008-04-13 22:15 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-03-08 12:51 . 2009-03-08 12:51 ——– d—–w- c:\windows\USB Vibration
2009-03-08 12:51 . 2009-03-08 12:51 ——– d—–w- c:\program files\USB Vibration
2009-03-07 22:33 . 2009-03-18 13:09 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-03-07 18:35 . 2009-03-07 18:35 ——– d—–w- c:\windows\system32\skin
2009-03-07 18:35 . 2009-03-07 18:35 ——– d—–w- c:\windows\system32\languages
2009-03-07 18:35 . 2009-03-07 18:35 ——– d—–w- c:\windows\system32\adv
2009-03-07 10:17 . 2009-03-07 10:21 ——– d—–w- c:\program files\Counter-Strike 1.6 V35
2009-03-07 10:09 . 2009-03-12 09:16 ——– d—–w- c:\program files\EA GAMES
2009-03-07 10:08 . 2005-05-26 13:34 2297552 —-a-w- c:\windows\system32\d3dx9_26.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 17:36 . 2009-03-07 08:49 60273 —-a-w- c:\windows\system32\pthreadGC2.dll
2009-03-18 14:16 . 2009-03-07 08:28 ——– d—–w- c:\program files\Winamp
2009-03-18 06:40 . 1601-01-01 00:12 49664 –sha-w- c:\windows\system32\tupumogu.dll
2009-03-18 06:40 . 1601-01-01 00:12 81408 –sha-w- c:\windows\system32\hazikubu.dll
2009-03-17 15:55 . 1601-01-01 00:12 80896 –sha-w- c:\windows\system32\loviheti.dll
2009-03-17 15:55 . 1601-01-01 00:12 80384 —-a-w- c:\windows\system32\pirovowi.dll.vir
2009-03-17 09:13 . 2009-03-07 08:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-03-16 12:18 . 2009-03-11 21:21 69448 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2009-03-16 12:18 . 2009-03-11 21:21 517448 —-a-w- c:\windows\system32\XAudio2_4.dll
2009-03-16 12:18 . 2009-03-11 21:21 235352 —-a-w- c:\windows\system32\xactengine3_4.dll
2009-03-16 12:18 . 2009-03-11 21:21 22360 —-a-w- c:\windows\system32\X3DAudio1_6.dll
2009-03-14 17:36 . 2009-03-14 17:36 3072 —-a-w- c:\documents and settings\Administrator\tmp762.tmp
2009-03-11 22:07 . 2009-03-07 08:10 ——– d—–w- c:\program files\Common Files\InstallShield
2009-03-10 10:16 . 2009-03-07 08:01 ——– d—–w- c:\program files\Unlocker
2009-03-09 13:27 . 2009-03-11 21:21 453456 —-a-w- c:\windows\system32\d3dx10_41.dll
2009-03-09 13:27 . 2009-03-11 21:21 1846632 —-a-w- c:\windows\system32\D3DCompiler_41.dll
2009-03-09 13:27 . 2009-03-11 21:21 4178264 —-a-w- c:\windows\system32\D3DX9_41.dll
2009-03-08 10:18 . 2009-03-07 08:05 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-07 09:56 . 2009-03-07 09:56 ——– d—–w- c:\program files\EA SPORTS
2009-03-07 08:55 . 2009-03-07 08:28 ——– d—–w- c:\documents and settings\Administrator\Application Data\Winamp
2009-03-07 08:52 . 2009-03-07 08:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\BSplayer
2009-03-07 08:49 . 2009-03-07 08:49 ——– d—–w- c:\program files\ffdshow
2009-03-07 08:42 . 2009-03-07 08:42 ——– d—–w- c:\program files\DAEMON Tools
2009-03-07 08:41 . 2009-03-07 08:41 611064 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-03-07 08:39 . 2009-03-07 08:39 ——– d—–w- c:\program files\Opera
2009-03-07 08:37 . 2009-03-07 08:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-07 08:37 . 2009-03-07 08:37 ——– d—–w- c:\program files\Yahoo!
2009-03-07 08:34 . 2009-03-07 08:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\BSplayer Pro
2009-03-07 08:34 . 2009-03-07 08:34 ——– d—–w- c:\program files\Webteh
2009-03-07 08:22 . 2009-03-07 08:22 ——– d—–w- c:\program files\C-Media PCI Audio
2009-03-07 08:17 . 2009-03-07 08:10 ——– d—–w- c:\program files\ATI Technologies
2009-03-07 08:02 . 2009-03-07 08:02 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-03-07 08:01 . 2009-03-07 08:01 ——– d—–w- c:\program files\Microsoft PowerToys
2009-03-07 08:01 . 2009-03-07 08:01 ——– d—–w- c:\program files\HashTab Shell Extension
2008-12-30 04:52 . 2008-12-30 04:52 361600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2008-12-30 04:52 . 2008-12-30 04:52 218624 —-a-w- c:\windows\system32\uxtheme.dll
2008-12-30 04:52 . 2008-12-30 04:52 140288 —-a-w- c:\windows\system32\sfc_os.dll
2008-12-30 04:52 . 2008-12-30 11:32 990208 —-a-w- c:\windows\system32\syssetup.dll
2008-12-19 15:15 . 2009-03-07 08:34 4338246 —-a-w- c:\documents and settings\Administrator\Application Data\BSplayer\FFDShow\libavcodec.dll
2008-12-19 14:15 . 2008-12-19 14:15 4338246 —-a-w- c:\windows\system32\libavcodec.dll
1601-01-01 00:12 . 1601-01-01 00:12 49664 –sha-w- c:\windows\system32\doriyubi.dll
.
——- Sigcheck ——-
[-] 2008-12-30 04:52 361600 5AE1C2695F6523AD98B948F2887D8C5E c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"yeyeheziwe"="c:\windows\system32\doriyubi.dll" [1601-01-01 49664]
"CPM33172912"="c:\windows\system32\hazikubu.dll" [2009-03-18 81408]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\hazikubu.dll" [2009-03-18 81408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hazikubu.dll [2009-03-18 81408]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\system32\\sopocx.ocx"=
"%windir%\\system32\\tvu49.ocx"=
"c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"=
"c:\\WINDOWS\\explorer.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/18/2009 5:16 PM 130424]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/18/2009 5:15 PM 348752]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys –> e:\NTGLM7X.sys [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - ASPI32
.
Contents of the 'Scheduled Tasks' folder
2009-03-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{718b86df-ee44-4978-a8bd-637448662f28} - c:\windows\system32\jefizaya.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ro/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-18 17:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(824)
c:\windows\system32\msi.dll
c:\windows\system32\hazikubu.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\CF14059.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2009-03-18 17:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-18 15:59
Pre-Run: 16,008,867,840 bytes free
Post-Run: 16,204,607,488 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
233
📎ComboFix.txt This is ?