ComboFix 10-11-07.09 - benıbo 08.11.2010 13:00:36.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1254.90.1055.18.1014.472 [GMT 2:00]
Running from: c:\documents and settings\benıbo\Belgelerim\Karşıdan Yüklenenler\ComboFix.v17.09.2010\ComboFix.v17.09.2010\ComboFix.v17.09.2010.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\benıbo\Application Data\BITS
c:\documents and settings\benıbo\Application Data\BITS\BITS.ini
c:\documents and settings\benıbo\Application Data\BITS\DHTTable.dat
c:\documents and settings\benıbo\Application Data\BITS\ProxyList.ini
c:\documents and settings\benıbo\Application Data\BITS\UPnP.ini
c:\documents and settings\benıbo\Application Data\EurekaLog
c:\documents and settings\benıbo\Belgelerim\mshearts.exe
c:\windows\libem.INI
c:\windows\system32\secustat.dat
.
((((((((((((((((((((((((( Files Created from 2010-10-08 to 2010-11-08 )))))))))))))))))))))))))))))))
.
2010-11-08 02:50 . 2010-11-08 02:50 -------- d-----w- c:\documents and settings\benıbo\Application Data\Avira
2010-11-08 02:49 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-08 02:49 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-08 02:49 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-11-08 02:49 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-11-08 01:24 . 2010-11-08 01:24 -------- d-----w- c:\program files\InCode Solutions
2010-11-07 23:58 . 2010-11-07 23:58 2 --shatr- c:\windows\winstart.bat
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\windows\system32\wbem\Repository
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\JDownloader
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\Your_Uninstaller__7.0.2010.7
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\Avira
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\USB Disk Security
2010-11-05 01:17 . 2010-11-05 01:17 -------- d-----w- c:\program files\Loaris
2010-11-03 20:48 . 2010-11-03 20:48 -------- d-----w- c:\documents and settings\benıbo\Application Data\ProgSense
2010-11-03 20:47 . 2010-11-03 20:50 -------- d-----w- c:\documents and settings\benıbo\Local Settings\Application Data\OpenCandy
2010-11-03 20:47 . 2010-11-03 20:47 -------- d-----w- c:\documents and settings\benıbo\Application Data\OpenCandy
2010-11-03 20:47 . 2010-11-03 21:22 -------- d-----w- c:\documents and settings\benıbo\Application Data\Orbit
2010-11-03 18:22 . 2010-11-03 19:38 -------- d-----w- c:\documents and settings\benıbo\Application Data\IDM
2010-11-02 17:09 . 2010-11-02 17:09 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-11-02 17:09 . 2010-11-02 17:09 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-11-02 01:34 . 2010-11-02 01:34 -------- d-----w- c:\documents and settings\benıbo\Application Data\TopcKit
2010-11-02 00:31 . 2010-11-02 00:31 -------- d-----w- c:\documents and settings\benıbo\Local Settings\Application Data\DFX
2010-11-01 21:53 . 2010-11-05 01:46 -------- d-----w- C:\Downloads
2010-10-18 13:41 . 2008-02-15 15:12 206256 ----a-w- c:\windows\system32\idmmbc(2).dll
2010-10-17 19:59 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-10-17 19:59 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-17 19:59 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-17 19:52 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 23:46 . 2010-10-22 23:14 -------- d-----w- c:\windows\system32\NtmsData
2010-10-12 23:31 . 2010-10-12 23:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-10-11 18:29 . 2010-10-11 18:29 -------- d-----w- c:\documents and settings\benıbo\Local Settings\Application Data\Thinstall
2010-10-11 18:29 . 2010-10-11 18:29 -------- d-----w- c:\documents and settings\benıbo\Application Data\Thinstall
2010-10-11 18:29 . 2010-10-11 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\DFX
2010-10-09 23:52 . 2010-10-09 23:52 -------- d-----w- c:\program files\Pool Billiard 1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-09 23:52 . 2010-09-17 14:13 75776 ----a-w- c:\windows\cadkasdeinst01e.exe
2010-09-18 09:23 . 2008-05-07 23:45 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-05-07 23:45 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-05-07 23:45 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-05-07 23:45 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-09 14:17 . 2008-05-07 23:45 666624 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 14:17 . 2008-05-07 23:45 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-09-09 14:17 . 2008-05-07 23:45 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-09-09 14:15 . 2008-05-07 23:45 369664 ----a-w- c:\windows\system32\html.iec
2010-09-01 11:51 . 2008-05-07 23:45 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:54 . 2008-05-07 23:45 1861888 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2008-05-07 23:45 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2008-05-07 23:45 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 12:25 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-05-07 23:45 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2008-05-07 23:45 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-05-07 23:45 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2008-05-07 23:45 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-01-04 23:00 . 2010-01-04 22:59 1924200 ----a-w- c:\program files\install_flash_player.exe
2010-01-02 00:04 . 2010-01-02 00:04 5846216 ----a-w- c:\program files\Firefox Setup 2.0.0.18.exe
2010-01-01 20:09 . 2010-01-01 20:09 6147544 ----a-w- c:\program files\3414-GOMPLAYERENSETUP.EXE
2010-01-01 19:28 . 2010-01-01 19:28 1604248 ----a-w- c:\program files\wrar391tr.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-03-29 2343120]
"RemoveIT Pro v7Ent"="c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe" [2010-11-04 2198528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-15 1434920]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-15 17529856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-15 137752]
"OA012Mon"="c:\windows\OA012Mon.exe" [2009-05-11 24576]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-01-06 2289664]
"WSED"="c:\program files\WSED\WSED.exe" [2009-03-31 251176]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-11-05 623912]
"CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-02-23 320808]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AutorunRemover.exe"="c:\program files\AutorunRemover\AutorunRemover.exe" [2009-10-21 1360896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2009-12-14 819200]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-11 2054360]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [20.09.2009 06:31 14248]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [11.09.2009 06:23 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [11.09.2009 06:26 96408]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [08.11.2010 04:49 135336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [11.09.2009 06:24 735960]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [20.09.2009 06:37 143840]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.;c:\windows\system32\drivers\OA012Afx.sys [20.09.2009 09:02 135168]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [20.09.2009 09:02 133632]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [20.09.2009 09:02 272032]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [20.09.2009 09:01 162816]
S2 gupdate;Google Güncelleme Hizmeti (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [08.06.2010 23:34 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.09.2009 09:00 1684736]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
2010-11-08 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-01-17 11:11]
2010-11-04 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-01-17 10:38]
2010-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-08 21:34]
2010-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-08 21:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://search.orbitdownloader.com
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Tüm Yüklemeler FlashGet3
IE: Yüklenen by FlashGet3
TCP: {163D3774-17BA-4A96-89FD-00DF3124019A} = 8.8.8.8
FF - ProfilePath - c:\documents and settings\benıbo\Application Data\Mozilla\Firefox\Profiles\bigz5v7y.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com.tr/
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\docume~1\BENBO~1\APPLIC~1\Flatcast\NpFv522.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-SolutoService
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-11-08 13:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\windows\System32\BCMLogon.dll
c:\windows\SYSTEM32\igfxdev.dll
.
Completion time: 2010-11-08 13:08:06
ComboFix-quarantined-files.txt 2010-11-08 11:08
Pre-Run: 112.678.760.448 bayt boş
Post-Run: 112.692.592.640 bayt boş
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - CE5116B63B8B92127D514803B96C6EFA