-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CnxDslTaskBar"="e:\program files\microcom\adsl deskporte usb\CnxDslTb.exe Microcom\ADSL DeskPorte USB" [X]
"AtiPTA"="atiptaxx.exe" [2006-02-22 344064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
e:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - e:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- e:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=e:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=e:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 21:10 1230704 ----a-w- e:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-04-26 17:24 136176 ----atw- e:\documents and settings\FF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 15:24 54840 ----a-w- e:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmcService]
2004-10-15 18:40 2577632 ----a-w- e:\progra~1\Sygate\SPF\Smc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44 248552 -c--a-w- e:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Microcom\\ADSL DeskPorte USB\\CnxDslTb.exe"=
"e:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Program Files\\Radeon Omega Drivers\\v4.8.442\\Setup.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"e:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"e:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7313:TCP"= 7313:TCP:joqmh
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 atitray;atitray;e:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [4. 2. 2011 8:38 17952]
R1 SASDIFSV;SASDIFSV;e:\program files\SUPERAntiSpyware\sasdifsv.sys [17. 2. 2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;e:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10. 5. 2010 20:41 67656]
R2 Angelnt;Angelnt;e:\windows\system32\drivers\ANGELNT.SYS [13. 2. 2011 13:49 51072]
R3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;e:\windows\system32\drivers\CnxEtP.sys [3. 2. 2011 18:25 131072]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;e:\windows\system32\drivers\CnxEtU.sys [3. 2. 2011 18:25 614272]
R3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;e:\windows\system32\drivers\CnxTgNP.sys [3. 2. 2011 18:25 60416]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);e:\windows\system32\drivers\sis7012.sys [4. 2. 2011 8:46 267136]
S2 katbisx;Shell Monitor;e:\windows\system32\svchost.exe -k netsvcs [4. 8. 2004 2:56 14336]
S3 FsUsbExDisk;FsUsbExDisk;e:\windows\system32\FsUsbExDisk.Sys [7. 4. 2011 14:13 36608]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\program files\Garena\safedrv.sys --> e:\program files\Garena\safedrv.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
katbisx
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-09 e:\windows\Tasks\1-Click Maintenance.job
- e:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]
.
2011-05-08 e:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1214440339-725345543-1003Core.job
- e:\documents and settings\FF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-26 17:24]
.
2011-05-09 e:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1214440339-725345543-1003UA.job
- e:\documents and settings\FF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-26 17:24]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {AD8FD7A5-0904-4A13-B144-189B15A34161} = 195.146.128.62 195.146.132.58
FF - ProfilePath - e:\documents and settings\FF\Application Data\Mozilla\Firefox\Profiles\9ak3nx9y.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - e:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter:
jqs@sun.com - e:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - e:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - e:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-NPSStartup - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-09 09:10
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\katbisx]
"ServiceDll"="e:\windows\system32\qcyqeh.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(716)
e:\program files\SUPERAntiSpyware\SASWINLO.DLL
e:\documents and settings\FF\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
e:\documents and settings\FF\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
e:\documents and settings\FF\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
e:\documents and settings\FF\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
e:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3008)
e:\windows\system32\msi.dll
.
Completion time: 2011-05-09 09:12:05
ComboFix-quarantined-files.txt 2011-05-09 07:11
ComboFix2.txt 2011-02-09 06:58
.
Pre-Run: 4 888 686 592 bytes free
Post-Run: 5 643 694 080 bytes free
.
- - End Of File - - 053294856633A2927FFFE60AC9944E36