Nezmazatelny Olmarik
Napsal: 03 črc 2010 13:10
Ahoj,
uz dlhsi cas mame problem s trojskym konom Olmarikom -> "Kontrola pri štarte operačná pamäť Operačná pamäť Win32/Olmarik trójsky kôň"
Skusal som robit scan s RootRepeal ale neuspesne... sekne sa pri obrazkoch zo zalohy Google Chrome (C:\Documents and Settings\Peshu\Local Settings\Application Data\Googles\Chrome\Application\3.0.195.32\Resources\Inspector\Images\ -> 8 .png suborov) ktore nejdu zmazat (zakazany pristup) ani vo Windows XP Safe Mode a nedostane sa do nich ani Nod32. (Crash Report na konci)
Podarilo sa mi ale spravit log z ComboFix (ma tu pri tom skoro vystrelo
) ktory je nizsie.
Dufam ze to zatial staci.
Za pomoc DAKUJEM
Log z ComboFix
ComboFix 10-07-01.02 - Peshu . 07. 2010 13:33:32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.1023.704 [GMT 2:00]
Running from: c:\documents and settings\Peshu\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Peshu\Desktop\EZ-Tracks.com.lnk
c:\documents and settings\Peshu\Start Menu\Programs\videosoft
C:\FirePassword.exe
C:\resycled
c:\windows\system32\drivers\msqpdxbhcvndes.sys
c:\windows\system32\drivers\msqpdxkbmnetqs.sys
c:\windows\system32\drivers\msqpdxomyfrlvr.sys
c:\windows\system32\drivers\msqpdxpdvbxhxi.sys
c:\windows\system32\drivers\msqpdxrnkvvvxe.sys
c:\windows\system32\drivers\msqpdxveuypdwk.sys
c:\windows\system32\drivers\msqpdxwvvmkhbo.sys
c:\windows\system32\msqpdxdqjnmewp.dll
D:\resycled
E:\resycled
F:\resycled
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_msqpdxserv.sys
-------\Legacy_msqpdxserv.sys
((((((((((((((((((((((((( Files Created from 2010-06-03 to 2010-07-03 )))))))))))))))))))))))))))))))
.
2010-06-25 08:02 . 2010-06-25 08:02 1 ----a-w- c:\documents and settings\Peshu\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-25 08:02 . 2010-06-25 08:02 -------- d-----w- c:\documents and settings\Peshu\Application Data\OpenOffice.org
2010-06-25 08:00 . 2010-06-25 08:00 -------- d-----w- c:\program files\OpenOffice.org 3
2010-06-05 14:46 . 2010-06-05 14:46 388096 ----a-r- c:\documents and settings\Peshu\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-05 14:46 . 2010-06-05 14:46 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-03 11:23 . 2008-12-29 09:25 -------- d-----w- c:\documents and settings\Peshu\Application Data\Skype
2010-07-03 11:13 . 2008-12-29 10:34 70400 ----a-w- c:\documents and settings\Peshu\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-03 10:11 . 2008-12-29 09:28 -------- d-----w- c:\documents and settings\Peshu\Application Data\skypePM
2010-06-28 09:50 . 2010-02-27 19:16 -------- d-----w- c:\program files\SPlayer
2010-06-28 09:50 . 2010-02-27 19:17 -------- d-----w- c:\documents and settings\Peshu\Application Data\SPlayer
2010-06-17 09:59 . 2010-03-27 13:52 -------- d-----w- c:\documents and settings\Peshu\Application Data\vlc
2010-05-26 16:56 . 2010-05-26 16:56 71960 ----a-w- c:\documents and settings\Peshu\Application Data\Mozilla\Plugins\npoctoshape.dll
2010-05-26 16:56 . 2010-05-26 16:56 -------- d-----w- c:\documents and settings\Peshu\Application Data\Octoshape
2010-05-25 06:56 . 2010-05-25 06:56 503808 ----a-w- c:\documents and settings\Peshu\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-49c10cda-n\msvcp71.dll
2010-05-25 06:56 . 2010-05-25 06:56 499712 ----a-w- c:\documents and settings\Peshu\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-49c10cda-n\jmc.dll
2010-05-25 06:56 . 2010-05-25 06:56 348160 ----a-w- c:\documents and settings\Peshu\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-49c10cda-n\msvcr71.dll
2010-05-17 19:48 . 2010-05-17 19:48 -------- d-----w- c:\documents and settings\Peshu\Application Data\HPAppData
2010-05-14 16:36 . 2009-04-01 14:09 -------- d-----w- c:\program files\Google
2010-05-09 12:16 . 2010-05-09 12:16 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2010-05-09 12:16 . 2010-05-09 12:14 -------- d-----w- c:\documents and settings\Peshu\Application Data\HP
2010-05-09 12:16 . 2010-05-09 12:04 166615 ----a-w- c:\windows\hpoins36.dat
2010-05-09 12:14 . 2010-05-09 12:07 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-05-09 12:10 . 2008-12-29 08:38 -------- d-----w- c:\program files\HP
2010-05-09 12:09 . 2010-05-09 12:09 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-05-09 12:08 . 2008-12-29 08:42 -------- d-----w- c:\program files\Common Files\HP
2010-04-24 13:32 . 2010-04-24 13:32 921632 ----a-w- C:\PA7311.DAT
2010-04-15 14:52 . 2008-12-29 16:21 65536 ----a-w- c:\windows\OLE2VBDB.DAT
2009-05-01 09:24 . 2009-05-01 09:23 24 --sh--w- c:\windows\S96149121.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-09 17:40 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 11:22 1172792 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Peshu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-29 133104]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2008-10-09 200136]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-12-06 2387968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Octoshape Streaming Services"="c:\documents and settings\Peshu\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Device Detector"="DevDetect.exe -autorun" [X]
"AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2004-06-24 7932416]
"Gainward"="c:\windows\TBPanel.exe" [2006-09-14 2162688]
"Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
"TC UP"="e:\programs\TC UP\TC UP.exe" [2008-10-13 36352]
"WinampAgent"="e:\programs\Winamp\winampa.exe" [2008-09-12 36352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"InCD"="e:\programs\Nero\InCD\InCD.exe" [2006-03-23 1398272]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-01-28 111928]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-03-16 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-03-16 110696]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-02-26 2140880]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Peshu\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-2-16 384512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"e:\\Programs\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [26. 2. 2010 6:41 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [10. 6. 2008 19:56 95872]
R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\vd_filedisk.sys [13. 1. 2006 15:00 15872]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [23. 1. 2009 17:51 51072]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [29. 12. 2008 12:34 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [29. 12. 2008 12:34 234888]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [26. 2. 2010 6:41 810120]
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [29. 12. 2008 10:22 44032]
R3 PAC7311;VGA SoC PC-Camera;c:\windows\system32\drivers\PA707UCM.SYS [8. 11. 2006 10:59 530304]
S2 gupdate1c9b2d377bba8bc;Služba Google Update (gupdate1c9b2d377bba8bc);c:\program files\Google\Update\GoogleUpdate.exe [1. 4. 2009 16:09 133104]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [28. 3. 2010 14:20 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [28. 3. 2010 14:20 8456]
S3 pspdisp;pspdisp;c:\windows\system32\drivers\pspdisp.sys [4. 8. 2009 18:04 3072]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [29. 12. 2008 15:13 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-12-06 22:18 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-01 14:09]
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-01 14:09]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484061587-839522115-1003Core.job
- c:\documents and settings\Peshu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-27 09:12]
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484061587-839522115-1003UA.job
- c:\documents and settings\Peshu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-27 09:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.ez-tracks.com/?fromOMB=1
mStart Page = hxxp://home.ez-tracks.com/?fromOMB=1
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nwiz - nwiz.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-03 13:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-07-03 13:39:17
ComboFix-quarantined-files.txt 2010-07-03 11:39
Pre-Run: 1 136 123 904 bytes free
Post-Run: 1 269 858 304 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B292DA82D2C5CE4210CD86DD1DFCDD5A
+ Crash report z RootRepeal
ROOTREPEAL CRASH REPORT
-------------------------
Windows Version: Windows XP SP2
Exception Code: 0xc0000005
Exception Address: 0x0041102f
Attempt to read from address: 0x10f6a860
uz dlhsi cas mame problem s trojskym konom Olmarikom -> "Kontrola pri štarte operačná pamäť Operačná pamäť Win32/Olmarik trójsky kôň"
Skusal som robit scan s RootRepeal ale neuspesne... sekne sa pri obrazkoch zo zalohy Google Chrome (C:\Documents and Settings\Peshu\Local Settings\Application Data\Googles\Chrome\Application\3.0.195.32\Resources\Inspector\Images\ -> 8 .png suborov) ktore nejdu zmazat (zakazany pristup) ani vo Windows XP Safe Mode a nedostane sa do nich ani Nod32. (Crash Report na konci)
Podarilo sa mi ale spravit log z ComboFix (ma tu pri tom skoro vystrelo

Dufam ze to zatial staci.
Za pomoc DAKUJEM

Log z ComboFix
ComboFix 10-07-01.02 - Peshu . 07. 2010 13:33:32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.1023.704 [GMT 2:00]
Running from: c:\documents and settings\Peshu\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Peshu\Desktop\EZ-Tracks.com.lnk
c:\documents and settings\Peshu\Start Menu\Programs\videosoft
C:\FirePassword.exe
C:\resycled
c:\windows\system32\drivers\msqpdxbhcvndes.sys
c:\windows\system32\drivers\msqpdxkbmnetqs.sys
c:\windows\system32\drivers\msqpdxomyfrlvr.sys
c:\windows\system32\drivers\msqpdxpdvbxhxi.sys
c:\windows\system32\drivers\msqpdxrnkvvvxe.sys
c:\windows\system32\drivers\msqpdxveuypdwk.sys
c:\windows\system32\drivers\msqpdxwvvmkhbo.sys
c:\windows\system32\msqpdxdqjnmewp.dll
D:\resycled
E:\resycled
F:\resycled
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_msqpdxserv.sys
-------\Legacy_msqpdxserv.sys
((((((((((((((((((((((((( Files Created from 2010-06-03 to 2010-07-03 )))))))))))))))))))))))))))))))
.
2010-06-25 08:02 . 2010-06-25 08:02 1 ----a-w- c:\documents and settings\Peshu\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-25 08:02 . 2010-06-25 08:02 -------- d-----w- c:\documents and settings\Peshu\Application Data\OpenOffice.org
2010-06-25 08:00 . 2010-06-25 08:00 -------- d-----w- c:\program files\OpenOffice.org 3
2010-06-05 14:46 . 2010-06-05 14:46 388096 ----a-r- c:\documents and settings\Peshu\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-05 14:46 . 2010-06-05 14:46 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-03 11:23 . 2008-12-29 09:25 -------- d-----w- c:\documents and settings\Peshu\Application Data\Skype
2010-07-03 11:13 . 2008-12-29 10:34 70400 ----a-w- c:\documents and settings\Peshu\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-03 10:11 . 2008-12-29 09:28 -------- d-----w- c:\documents and settings\Peshu\Application Data\skypePM
2010-06-28 09:50 . 2010-02-27 19:16 -------- d-----w- c:\program files\SPlayer
2010-06-28 09:50 . 2010-02-27 19:17 -------- d-----w- c:\documents and settings\Peshu\Application Data\SPlayer
2010-06-17 09:59 . 2010-03-27 13:52 -------- d-----w- c:\documents and settings\Peshu\Application Data\vlc
2010-05-26 16:56 . 2010-05-26 16:56 71960 ----a-w- c:\documents and settings\Peshu\Application Data\Mozilla\Plugins\npoctoshape.dll
2010-05-26 16:56 . 2010-05-26 16:56 -------- d-----w- c:\documents and settings\Peshu\Application Data\Octoshape
2010-05-25 06:56 . 2010-05-25 06:56 503808 ----a-w- c:\documents and settings\Peshu\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-49c10cda-n\msvcp71.dll
2010-05-25 06:56 . 2010-05-25 06:56 499712 ----a-w- c:\documents and settings\Peshu\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-49c10cda-n\jmc.dll
2010-05-25 06:56 . 2010-05-25 06:56 348160 ----a-w- c:\documents and settings\Peshu\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-49c10cda-n\msvcr71.dll
2010-05-17 19:48 . 2010-05-17 19:48 -------- d-----w- c:\documents and settings\Peshu\Application Data\HPAppData
2010-05-14 16:36 . 2009-04-01 14:09 -------- d-----w- c:\program files\Google
2010-05-09 12:16 . 2010-05-09 12:16 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2010-05-09 12:16 . 2010-05-09 12:14 -------- d-----w- c:\documents and settings\Peshu\Application Data\HP
2010-05-09 12:16 . 2010-05-09 12:04 166615 ----a-w- c:\windows\hpoins36.dat
2010-05-09 12:14 . 2010-05-09 12:07 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-05-09 12:10 . 2008-12-29 08:38 -------- d-----w- c:\program files\HP
2010-05-09 12:09 . 2010-05-09 12:09 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-05-09 12:08 . 2008-12-29 08:42 -------- d-----w- c:\program files\Common Files\HP
2010-04-24 13:32 . 2010-04-24 13:32 921632 ----a-w- C:\PA7311.DAT
2010-04-15 14:52 . 2008-12-29 16:21 65536 ----a-w- c:\windows\OLE2VBDB.DAT
2009-05-01 09:24 . 2009-05-01 09:23 24 --sh--w- c:\windows\S96149121.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-09 17:40 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 11:22 1172792 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Peshu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-29 133104]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2008-10-09 200136]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-12-06 2387968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Octoshape Streaming Services"="c:\documents and settings\Peshu\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Device Detector"="DevDetect.exe -autorun" [X]
"AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2004-06-24 7932416]
"Gainward"="c:\windows\TBPanel.exe" [2006-09-14 2162688]
"Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
"TC UP"="e:\programs\TC UP\TC UP.exe" [2008-10-13 36352]
"WinampAgent"="e:\programs\Winamp\winampa.exe" [2008-09-12 36352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"InCD"="e:\programs\Nero\InCD\InCD.exe" [2006-03-23 1398272]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-01-28 111928]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-03-16 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-03-16 110696]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-02-26 2140880]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Peshu\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-2-16 384512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"e:\\Programs\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [26. 2. 2010 6:41 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [10. 6. 2008 19:56 95872]
R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\vd_filedisk.sys [13. 1. 2006 15:00 15872]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [23. 1. 2009 17:51 51072]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [29. 12. 2008 12:34 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [29. 12. 2008 12:34 234888]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [26. 2. 2010 6:41 810120]
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [29. 12. 2008 10:22 44032]
R3 PAC7311;VGA SoC PC-Camera;c:\windows\system32\drivers\PA707UCM.SYS [8. 11. 2006 10:59 530304]
S2 gupdate1c9b2d377bba8bc;Služba Google Update (gupdate1c9b2d377bba8bc);c:\program files\Google\Update\GoogleUpdate.exe [1. 4. 2009 16:09 133104]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [28. 3. 2010 14:20 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [28. 3. 2010 14:20 8456]
S3 pspdisp;pspdisp;c:\windows\system32\drivers\pspdisp.sys [4. 8. 2009 18:04 3072]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [29. 12. 2008 15:13 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-12-06 22:18 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-01 14:09]
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-01 14:09]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484061587-839522115-1003Core.job
- c:\documents and settings\Peshu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-27 09:12]
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484061587-839522115-1003UA.job
- c:\documents and settings\Peshu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-27 09:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.ez-tracks.com/?fromOMB=1
mStart Page = hxxp://home.ez-tracks.com/?fromOMB=1
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nwiz - nwiz.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-03 13:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-07-03 13:39:17
ComboFix-quarantined-files.txt 2010-07-03 11:39
Pre-Run: 1 136 123 904 bytes free
Post-Run: 1 269 858 304 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B292DA82D2C5CE4210CD86DD1DFCDD5A
+ Crash report z RootRepeal
ROOTREPEAL CRASH REPORT
-------------------------
Windows Version: Windows XP SP2
Exception Code: 0xc0000005
Exception Address: 0x0041102f
Attempt to read from address: 0x10f6a860