I have tried to fix the problem by runing Avast pre-boot scan (I have free home edition, latest update), I have also ran a-squared free and Spybot S&D. They all found something and cleaned it, but the problem is still here.
On Google I have found same topic on WhattheTech forum, but the topic was locked due to inactivity of user.
http://forums.whatthetech.com/Date_time_su…&pid=614680
I have the same problem as he/she had.
The problem is, I believe in c:\SUD\SSOW\sep.exe, but I am unable to find that folder and file.
Malwarebytes' Anti-Malware 1.42 Database version: 3355 can found the problem but it is unable to fix it.
[external image: Posted Image]
Malwarebytes' Anti-Malware 1.42
Database version: 3355
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
14.12.2009 12:14:28
MALWAREBYTE LOG - mbam-log-2009-12-14 (12-14-28).txt
Scan type: Quick Scan
Objects scanned: 111835
Time elapsed: 4 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-01we-aax2-5657qca554112} (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\SUD\SSOW\sep.exe (Backdoor.Bot) -> Delete on reboot.
—-> but it never deletes it on reboot. Why? Please help.
COMBOFIX LOG- ComboFix 09-09-25.01 - FT 14.12.2009 12:28.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1457 [GMT 1:00]
Running from: e:\desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091214-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-14 to 2009-12-14 )))))))))))))))))))))))))))))))
.
2016-04-12 01:58 . 2009-12-12 16:28 ——– d—–w- c:\documents and settings\FT\Application Data\DisplayTune
2016-04-12 01:56 . 2016-04-12 01:56 62009 —-a-w- c:\windows\system32\wpfb_ati2dvag.dll
2016-04-12 01:56 . 2016-04-12 01:56 ——– d—–w- e:\program files\Portrait Displays
2016-04-12 01:55 . 2004-08-03 23:56 1392671 —-a-w- c:\windows\msvbvm60.dll
2016-04-12 01:55 . 2002-01-05 02:40 487424 —-a-w- c:\windows\msvcp70.dll
2016-04-12 01:55 . 2002-01-05 02:37 344064 —-a-w- c:\windows\msvcr70.dll
2016-04-12 01:55 . 2016-04-12 01:55 ——– d—–w- e:\program files\Philips Display
2016-04-12 01:55 . 2009-12-12 16:28 ——– d—–w- c:\program files\Common Files\Portrait Displays
2009-12-14 10:58 . 2009-12-14 10:58 ——– d—–r- C:\SUD
2009-12-13 22:59 . 2009-12-13 22:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-12-13 22:21 . 2009-12-13 22:21 ——– d—–w- e:\program files\ESET
2009-12-13 20:17 . 2009-12-13 20:17 ——– d—–w- c:\documents and settings\FT\Application Data\Malwarebytes
2009-12-13 20:17 . 2009-12-03 15:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-13 20:17 . 2009-12-13 20:17 ——– d—–w- e:\program files\Malwarebytes' Anti-Malware
2009-12-13 20:17 . 2009-12-13 20:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-13 20:17 . 2009-12-03 15:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-13 19:22 . 2009-12-13 19:22 ——– d—–r- C:\Sandbox
2009-12-13 11:57 . 2009-12-14 00:19 ——– d—–w- e:\program files\Killing Floor - LAN EDITION v6.4 by jaug1337
2009-12-12 14:55 . 2004-08-03 21:07 67584 —-a-w- c:\windows\system32\drivers\sdbus.sys
2009-12-12 14:55 . 2004-08-03 20:59 11136 —-a-w- c:\windows\system32\drivers\sffdisk.sys
2009-12-12 14:55 . 2004-08-03 20:59 10240 —-a-w- c:\windows\system32\drivers\sffp_sd.sys
2009-12-11 13:49 . 2009-12-11 13:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Emberwind
2009-12-11 13:49 . 2009-12-11 13:49 ——– d—–w- e:\program files\Emberwind
2009-12-10 17:39 . 2009-12-10 17:40 ——– d—–w- c:\documents and settings\FT\Local Settings\Application Data\Easy CD-DA Extractor
2009-12-10 17:39 . 2009-12-10 17:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2009-12-10 17:39 . 2009-12-12 19:36 ——– d—–w- e:\program files\Easy CD-DA Extractor 12
2009-12-10 17:39 . 2009-12-10 17:39 ——– d—–w- c:\windows\Easy CD-DA Extractor 12
2009-12-09 18:38 . 2009-12-09 18:46 ——– d—–w- e:\program files\Zombie Driver
2009-12-09 10:44 . 2009-12-09 10:45 ——– d—–w- e:\program files\Dofus 2
2009-12-09 10:44 . 2009-12-09 10:44 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-08 10:29 . 2009-12-08 10:29 ——– d—–w- e:\program files\Paradox Interactive
2009-12-06 14:04 . 2009-12-06 14:04 ——– d—–w- c:\documents and settings\FT\Local Settings\Application Data\Phase_One
2009-12-06 13:52 . 2009-12-06 13:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Phase One
2009-12-06 13:52 . 2009-12-06 14:04 ——– d—–w- c:\documents and settings\FT\Local Settings\Application Data\CaptureOne
2009-12-06 13:48 . 2009-12-06 13:48 ——– d—–w- e:\program files\Phase One
2009-12-06 09:47 . 2009-12-06 09:47 616 —-a-w- c:\windows\eReg.dat
2009-12-05 22:10 . 2009-12-10 22:37 ——– d—–w- e:\program files\Codemasters
2009-12-05 19:24 . 2009-12-05 19:24 ——– d—–w- e:\program files\Topaz Labs
2009-12-05 00:29 . 2009-12-05 00:31 ——– d—–w- e:\program files\The KMPlayer
2009-11-26 20:06 . 2009-11-26 20:07 ——– d—–w- e:\program files\Serious Sam
2009-11-24 16:23 . 2009-11-24 16:23 ——– d—–w- c:\windows\WICCodecs
2009-11-16 22:40 . 2009-11-16 22:41 ——– d—–w- e:\program files\Hamachi
2009-11-16 21:59 . 2009-11-16 22:40 ——– d—–w- c:\documents and settings\FT\Local Settings\Application Data\LogMeIn Hamachi
2009-11-16 21:59 . 2009-12-14 11:30 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2009-11-16 21:58 . 2009-11-16 21:58 ——– d—–w- e:\program files\LogMeIn Hamachi
2009-11-14 15:48 . 2009-11-14 15:48 ——– d—–w- e:\program files\Microsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-14 10:42 . 2007-12-16 19:23 ——– d—–w- c:\documents and settings\FT\Application Data\uTorrent
2009-12-14 00:23 . 2008-08-20 10:04 ——– d—–w- c:\documents and settings\FT\Application Data\Hamachi
2009-12-13 23:57 . 2008-01-09 22:28 ——– d—–w- e:\program files\Steam
2009-12-13 19:38 . 2007-11-08 18:36 ——– d—–w- e:\program files\a-squared Free
2009-12-13 17:35 . 2008-12-10 09:26 ——– d—–w- c:\documents and settings\FT\Application Data\foobar2000
2009-12-12 16:29 . 2007-10-22 12:18 ——– d–h–w- e:\program files\InstallShield Installation Information
2009-12-12 16:21 . 2007-10-24 20:47 ——– d—–w- e:\program files\Spybot - Search & Destroy
2009-12-12 16:21 . 2008-06-18 09:11 ——– d—–w- c:\documents and settings\FT\Application Data\DNA
2009-12-12 16:17 . 2008-04-13 13:18 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-12 16:17 . 2007-10-20 20:04 ——– d—–w- e:\program files\SpywareBlaster
2009-12-12 15:38 . 2007-10-23 10:21 7412 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-12-11 10:49 . 2008-05-11 12:54 ——– d—–w- e:\program files\THQ
2009-12-10 05:42 . 2007-10-20 16:03 60888 —-a-w- c:\documents and settings\FT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-09 18:46 . 2007-10-20 16:40 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-12-09 18:44 . 2008-06-05 11:56 ——– d—–w- e:\program files\AGEIA Technologies
2009-12-09 18:42 . 2008-07-22 18:10 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2009-12-09 18:42 . 2008-07-22 18:10 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2009-12-09 11:41 . 2008-03-01 13:50 ——– d—–w- c:\documents and settings\FT\Application Data\LimeWire
2009-12-08 22:08 . 2008-10-05 19:05 ——– d—–w- c:\documents and settings\FT\Application Data\Mumble
2009-12-08 20:48 . 2008-04-23 15:31 ——– d—–w- e:\program files\DVBViewer
2009-12-07 13:35 . 2007-11-21 16:17 ——– d—–w- e:\program files\Ubisoft
2009-12-06 14:40 . 2009-08-22 12:24 ——– d—–w- c:\documents and settings\FT\Application Data\vlc
2009-12-06 10:51 . 2008-01-22 10:07 ——– d—–w- e:\program files\Rockstar Games
2009-12-06 10:42 . 2008-07-29 17:55 ——– d—–w- e:\program files\LucasArts
2009-12-05 16:30 . 2009-10-06 18:31 ——– d—–w- e:\program files\ISL
2009-12-04 23:01 . 2009-10-16 16:20 ——– d—–w- e:\program files\Eidos
2009-11-29 18:20 . 2008-12-24 20:35 ——– d—–w- e:\program files\EvilLyrics
2009-11-28 18:41 . 2008-05-11 11:56 ——– d—–w- c:\documents and settings\FT\Application Data\Bioshock
2009-11-25 14:51 . 2007-10-20 20:07 ——– d—–w- e:\program files\FastStone Image Viewer
2009-11-24 23:54 . 2007-10-20 16:16 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2007-10-20 16:16 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:49 . 2007-10-20 16:16 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2007-10-20 16:16 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2007-10-20 16:16 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2007-10-20 16:16 97480 —-a-w- c:\windows\system32\AVASTSS.scr
2009-11-24 16:23 . 2009-10-28 21:54 ——– d—–w- e:\program files\Opera
2009-11-17 22:43 . 2008-11-16 18:01 ——– d—–w- e:\program files\Microsoft Silverlight
2009-11-16 22:40 . 2008-08-20 10:04 17480 —-a-w- c:\windows\system32\drivers\hamachi.sys
2009-11-14 17:05 . 2009-02-27 19:13 ——– d—–w- c:\documents and settings\FT\Application Data\id Software
2009-11-14 17:03 . 2008-02-05 17:08 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-14 09:20 . 2007-11-08 11:15 ——– d—–w- e:\program files\IrfanView
2009-11-10 22:10 . 2009-10-03 17:58 ——– d—–w- e:\program files\DIFX
2009-11-06 14:38 . 2009-11-06 14:33 ——– d—–w- e:\program files\SignSIS-GUI
2009-11-03 11:09 . 2009-11-03 11:09 ——– d—–w- e:\program files\Lonely Cat Games
2009-10-31 23:17 . 2009-10-31 23:14 ——– d—–w- c:\documents and settings\FT\Application Data\Mp3tag
2009-10-31 23:14 . 2009-10-31 23:14 ——– d—–w- e:\program files\Mp3tag
2009-10-31 10:02 . 2008-08-20 07:55 ——– d—–w- e:\program files\FlashGet
2009-10-28 17:46 . 2009-10-28 17:46 0 —ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-10-28 17:46 . 2009-10-28 17:46 0 —ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-10-28 17:45 . 2009-10-03 18:09 ——– d—–w- c:\documents and settings\FT\Application Data\PC Suite
2009-10-28 17:45 . 2009-10-03 18:09 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Suite
2009-10-28 15:39 . 2009-10-28 15:39 ——– d—–w- c:\documents and settings\FT\Application Data\runic games
2009-10-28 15:32 . 2009-10-28 15:23 ——– d—–w- e:\program files\Runic Games
2009-10-28 13:30 . 2007-10-26 09:14 ——– d—–w- e:\program files\DupKiller
2009-10-25 21:33 . 2009-02-27 11:01 ——– d—–w- c:\documents and settings\FT\Application Data\Orbit
2009-10-17 17:57 . 2007-11-02 09:23 ——– d—–w- e:\program files\CureROM
2009-10-17 17:57 . 2008-04-05 18:45 ——– d—–w- e:\program files\Photomatix
2009-10-17 16:31 . 2009-10-03 18:09 ——– d—–w- c:\documents and settings\FT\Application Data\Nokia
2009-10-17 15:55 . 2008-05-17 21:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Installations
2009-10-17 15:54 . 2008-05-17 21:56 ——– d—–w- e:\program files\Nokia
2009-10-17 15:54 . 2008-05-17 21:56 ——– d—–w- c:\program files\Common Files\Nokia
2009-10-17 15:48 . 2009-10-02 11:55 ——– d—–w- e:\program files\Machinarium
2009-10-17 08:53 . 2007-12-16 19:23 ——– d—–w- e:\program files\uTorrent
2009-10-16 16:53 . 2009-06-07 09:22 174064 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-27 19:40 . 2009-02-27 18:46 139152 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-27 19:40 . 2009-02-27 18:46 139152 —-a-w- c:\documents and settings\FT\Application Data\PnkBstrK.sys
2009-09-27 19:40 . 2009-02-27 18:46 111928 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-27 19:40 . 2009-02-27 18:46 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-09-27 19:40 . 2009-02-27 18:46 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-05-06 18:37 . 2009-05-06 18:37 88 –sh–r- c:\windows\system32\3B471B2AEC.sys
2007-12-02 18:29 . 2007-10-23 10:32 104 –sh–r- c:\windows\system32\EC2A1B473B.sys
2006-05-03 09:06 . 2007-12-16 14:22 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-12-16 14:22 31232 –sh–r- c:\windows\system32\msfDX.dll
2007-11-10 08:20 . 2007-11-09 08:12 321568 –sha-w- c:\windows\system32\drivers\fidbox.dat
.
——- Sigcheck ——-
[-] 2008-03-13 . 2CD651C6AA18662D4B91112432C74D87 . 359040 . . [5.1.2600.2505] . . c:\windows\system32\drivers\TCPIP.SYS
[-] 2008-03-13 . 2CD651C6AA18662D4B91112432C74D87 . 359040 . . [5.1.2600.2505] . . c:\windows\system32\dllcache\TCPIP.SYS
[7] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB884020$\tcpip.sys
[-] 2009-02-04 11:15 . 18747FCB2508EEEC79415B32F63F3654 . 36864 . . [——] . . c:\windows\system32\ctfmon.exe
[-] 2009-02-04 11:15 . 18747FCB2508EEEC79415B32F63F3654 . 36864 . . [——] . . c:\windows\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-12-13_21.40.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-14 11:31 . 2009-12-14 11:31 16384 c:\windows\Temp\Perflib_Perfdata_208.dat
+ 2009-12-14 11:19 . 2009-12-14 11:19 16384 c:\windows\Temp\Perflib_Perfdata_204.dat
+ 2001-08-23 10:00 . 2009-12-14 10:33 68360 c:\windows\system32\perfc009.dat
- 2001-08-23 10:00 . 2009-12-09 21:57 68360 c:\windows\system32\perfc009.dat
+ 2001-08-23 10:00 . 2009-12-14 10:33 435590 c:\windows\system32\perfh009.dat
- 2001-08-23 10:00 . 2009-12-09 21:57 435590 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="e:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"SansaDispatch"="c:\documents and settings\FT\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-10-12 79872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="e:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Launchy.lnk - e:\program files\Launchy\Launchy.exe [2007-10-20 286720]
Logitech SetPoint.lnk - e:\program files\Logitech\SetPoint\SetPoint.exe [2009-2-9 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 15:41 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"HDDlife HDD Access service"=2 (0x2)
"CryptSvc"=3 (0x3)
"CiSvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"aawservice"=2 (0x2)
"a2free"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe"
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LanguageShortcut"="e:\program files\CyberLink\PowerDVD\Language\Language.exe"
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"RemoteControl"="e:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"SunJavaUpdateSched"="e:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"StartCCC"="e:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"QuickTime Task"="e:\program files\QuickTime Alternative\QTTask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Office2007\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\uTorrentBETA\\uTorrent.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\FlashGet\\flashget.exe"=
"e:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"e:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"e:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Program Files\\LimeWire\\LimeWire.exe"=
"e:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"=
"e:\\Program Files\\Steam\\steamapps\\00_d4210_11\\insurgency\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\00_d4210_11\\source sdk base\\hl2.exe"=
"f:\\Program Files\\Eidos\\Battlestations Pacific\\bsp.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Program Files\\Opera\\opera.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7728:TCP"= 7728:TCP:WWW
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [6.12.2005 16:11 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1.4.2008 22:48 114768]
R1 atitray;atitray;e:\program files\ATI Tray Tools\atitray.sys [22.5.2007 10:04 18088]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [23.4.2007 12:03 82200]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1.4.2008 22:48 20560]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;e:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [9.2.2009 10:42 10384]
R3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;c:\windows\system32\drivers\usb8023.sys [3.8.2004 22:04 12672]
S2 NtfsSvc;Microsoft NtfsSvc Manager Service;c:\windows\System\updates.exe /svc –> c:\windows\System\updates.exe [?]
S3 MODRC;DiBcom Infrared Receiver;c:\windows\system32\drivers\modrc.sys [8.5.2006 23:02 13056]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [3.10.2009 18:58 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [3.10.2009 18:58 8320]
S4 HDDlife HDD Access service;HDDlife HDD Access service;c:\program files\Common Files\BinarySense\hldasvc.exe [15.2.2008 13:17 832760]
S4 U7000RCService;U7000RCService;c:\program files\Gigabyte\RCService\U7000RCService.exe [11.10.2006 7:54 555520]
S4 WinTaskAdmin;WinTaskAdmin;e:\program files\WinTask\Bin\TaskAdmin.exe [14.11.2007 13:43 62232]
S4 WTScheduler;WTScheduler;e:\program files\WinTask\Bin\SchedSrv.exe [14.11.2007 13:43 136032]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
pyyttcnoe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0d7ab132-7f18-11dc-a95e-806d6172696f}]
\Shell\AutoRun\command - G:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{609eeb83-9441-11dc-9a5e-0a13d4d74469}]
\Shell\AutoRun\command - g:\sud\SSOW\sep.exe
\Shell\open\command - g:\sud\SSOW\sep.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6567a572-9d18-11dc-9a72-000272b03fc0}]
\Shell\AutoRun\command - g:\sud\SSOW\sep.exe
\Shell\open\command - g:\sud\SSOW\sep.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e583c90-9680-11dc-9a62-0a13d4d74469}]
\Shell\AutoRun\command - g:\sud\SSOW\sep.exe
\Shell\open\command - g:\sud\SSOW\sep.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8e63ff1-ae9c-11de-b056-0a13d4d74469}]
\Shell\AutoRun\command - g:\sud\SSOW\sep.exe
\Shell\open\command - g:\sud\SSOW\sep.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb63be23-d0fe-11de-b080-0a13d4d74469}]
\Shell\AutoRun\command - g:\sud\SSOW\sep.exe
\Shell\open\command - g:\sud\SSOW\sep.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da5bc945-7f27-11dc-93ad-0a13d4d74469}]
\Shell\AutoRun\command - J:\SETUP.EXE
\Shell\configure\command - J:\SETUP.EXE
\Shell\install\command - J:\SETUP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://codec.kiev.ua/
uInternet Settings,ProxyOverride = *.local
TCP: {493347CE-4F28-4194-A29F-A53C35D99AD4} = 85.94.64.10,85.94.64.11
FF - ProfilePath - c:\documents and settings\FT\Application Data\Mozilla\Firefox\Profiles\ryoqc39t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.hr/ig?hl=hr
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\FT\Application Data\Mozilla\Firefox\Profiles\ryoqc39t.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\FT\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\FT\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF - plugin: c:\program files\Windows Media Player\npdrmv2.dll
FF - plugin: c:\program files\Windows Media Player\npdsplay.dll
FF - plugin: c:\program files\Windows Media Player\npwmsdrm.dll
FF - plugin: e:\progra~1\SONYON~1\npsoe.dll
—- FIREFOX POLICIES —-
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-14 12:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-343818398-1606980848-1060284298-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-343818398-1606980848-1060284298-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:27,6c,11,77,56,8d,7e,ce,3d,54,0a,90,83,ce,c2,b1,6f,50,fe,69,1c,2a,20,
0b,6e,68,c6,b7,09,f1,cb,ce,f1,cd,23,29,27,f2,49,91,d7,ce,cb,dc,88,f7,4f,24,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-343818398-1606980848-1060284298-1003\Software\SecuROM\License information*]
"datasecu"=hex:3f,36,d7,d2,24,35,9b,25,c3,ae,92,c8,5f,35,b2,3b,27,2b,6a,3e,ed,
68,c5,99,0f,24,eb,ce,4a,aa,b4,0b,e6,5f,05,15,84,7b,31,73,4f,72,2c,e9,cf,c6,\
"rkeysecu"=hex:60,8e,d5,b7,5e,30,55,46,c5,fe,22,7b,93,8c,cf,ab
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\HID\Vid_046d&Pid_c517&MI_01&Col01\7&335c298e&0&0000\LogConf]
@DACL=(02 0000)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(2468)
e:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
e:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
e:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
e:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
e:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
e:\program files\Alwil Software\Avast4\aswUpdSv.exe
e:\program files\Alwil Software\Avast4\ashServ.exe
e:\program files\Alwil Software\Avast4\Setup\avast.setup
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Common Files\Logishrd\LVCOMSER\LVComSer.exe
e:\program files\NetLimiter 2 Pro\nlsvc.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\Logishrd\LVCOMSER\LVComSer.exe
e:\program files\Alwil Software\Avast4\ashMaiSv.exe
e:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
e:\program files\PC Connectivity Solution\ServiceLayer.exe
e:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
e:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
e:\program files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
.
**************************************************************************
.
Completion time: 2009-12-14 12:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-14 11:36
ComboFix2.txt 2009-12-14 10:52
ComboFix3.txt 2009-12-13 21:44
Pre-Run: 1.022.173.184 bytes free
Post-Run: 1.008.844.800 bytes free
352 — E O F — 2007-10-20 17:28