Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 12-05-16.01 - GEOMARSRV 05/16/2012 14:58:18.2.1 - x86
- Microsoft Windows XP Home Edition 5.1.2600.3.1250.385.1033.18.1023.588 [GMT 2:00]
- Running from: c:\documents and settings\GEOMARSRV\Desktop\ComboFix.exe
- Command switches used :: c:\documents and settings\GEOMARSRV\Desktop\CFScript.txt
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Legacy_LBD
- -------\Service_Lbd
- .
- .
- ((((((((((((((((((((((((( Files Created from 2012-04-16 to 2012-05-16 )))))))))))))))))))))))))))))))
- .
- .
- 2012-05-15 12:42 . 2012-05-15 12:42 -------- d-----w- C:\_OTL
- 2012-05-15 06:15 . 2012-05-15 06:15 -------- d-----w- c:\documents and settings\GEOMARSRV\Application Data\Malwarebytes
- 2012-05-15 06:03 . 2012-05-15 12:39 -------- d-----w- c:\documents and settings\GEOMARSRV\Application Data\Skype
- 2012-05-15 06:03 . 2012-05-15 06:03 -------- d-----w- c:\program files\Common Files\Skype
- 2012-05-15 06:03 . 2012-05-15 06:03 -------- d-----r- c:\program files\Skype
- 2012-05-15 06:03 . 2012-05-15 06:03 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Skype
- 2012-05-15 05:20 . 2012-05-15 05:20 -------- d-----w- c:\program files\RandyRants.com
- 2012-05-14 07:06 . 2012-05-14 07:06 -------- d-----w- c:\documents and settings\GEOMARSRV\Local Settings\Application Data\PDF-TIFF-Tools.com
- 2012-05-14 07:06 . 2012-05-14 07:06 -------- d-----w- c:\program files\JPG to PDF Converter
- 2012-05-07 05:12 . 2012-05-07 05:12 -------- d-----w- c:\program files\Mozilla Maintenance Service
- 2012-05-07 05:12 . 2012-05-07 05:12 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
- 2012-05-07 05:12 . 2012-05-07 05:12 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2012-05-08 05:10 . 2012-03-29 06:17 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
- 2012-05-08 05:10 . 2011-07-04 04:53 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
- 2012-04-11 13:12 . 2004-08-04 12:00 1862272 ----a-w- c:\windows\system32\win32k.sys
- 2012-04-11 13:10 . 2004-08-04 12:00 2192640 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2012-04-11 12:35 . 2004-08-03 22:59 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
- 2012-03-01 11:01 . 2004-08-04 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
- 2012-03-01 11:01 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
- 2012-03-01 11:01 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
- 2012-02-29 14:10 . 2004-08-04 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
- 2012-02-29 14:10 . 2004-08-04 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
- 2012-02-29 12:17 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
- 2012-05-07 05:12 . 2011-10-25 05:14 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
- .
- .
- ((((((((((((((((((((((((((((( SnapShot@2012-05-16_05.28.49 )))))))))))))))))))))))))))))))))))))))))
- .
- + 2012-05-16 13:06 . 2012-05-16 13:06 16384 c:\windows\Temp\Perflib_Perfdata_524.dat
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
- "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-12 68856]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "nForce Tray Options"="sstray.exe" [2003-06-17 73728]
- .
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
- .
- c:\documents and settings\Marko Server\Start Menu\Programs\Startup\
- OpenOffice.org 1.9.79.lnk - c:\program files\OpenOffice.org 1.9.79\program\quickstart.exe [N/A]
- .
- c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
- EPSON Status Monitor 3 Environment Check(2).lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-7-11 131584]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
- 2007-09-28 15:50 111616 ----a-w- c:\windows\system32\ackpbsc.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
- 2007-06-20 17:08 281088 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
- .
- [HKLM\~\startupfolder\C:^Documents and Settings^GEOMARSRV^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
- path=c:\documents and settings\GEOMARSRV\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
- backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
- .
- [HKLM\~\startupfolder\C:^Documents and Settings^GEOMARSRV^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
- path=c:\documents and settings\GEOMARSRV\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
- backup=c:\windows\pss\OpenOffice.org 3.3.lnkStartup
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\accrdsub]
- 2007-09-21 16:15 294440 ----a-w- c:\program files\ActivIdentity\ActivClient\accrdsub.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acsagent]
- 2007-06-20 17:08 130864 ----a-w- c:\program files\ActivIdentity\ActivClient\acsagent.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
- 2005-06-06 22:46 57344 -c--a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
- 2006-11-13 11:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
- 2004-03-24 10:41 1294446 ------w- c:\program files\Ahead\InCD\InCD.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
- 2006-06-11 08:26 155648 -c--a-w- c:\program files\QuickTime\qttask.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
- 2005-10-26 16:17 159744 ----a-w- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
- 2011-04-08 10:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
- 2008-05-12 05:21 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\WINDOWS\\system32\\msiexec.exe"=
- "c:\\Program Files\\Hewlett-Packard\\HP Designjet System Maintenance\\hp_dj_sme.exe"=
- "c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
- "c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
- "d:\\DOWNLOADS\\Xfire\\Xfire.exe"=
- "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
- "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
- "c:\\Program Files\\ZWCAD 2011 Eng\\ZWCAD.EXE"=
- "c:\\Program Files\\ZWCAD 2011 Eng\\zwlm_ts.exe"=
- "c:\\Program Files\\ZWCAD 2011 Eng\\CrashReportManagement.exe"=
- "c:\\Program Files\\ZWCAD 2011 Eng\\ZWErrorDialog.exe"=
- "c:\\Program Files\\Synkron\\Synkron.exe"=
- "c:\\Program Files\\ZWCAD 2012 Eng\\ZWCAD.EXE"=
- "c:\\Program Files\\ZWCAD 2012 Eng\\zwlm_ts.exe"=
- "c:\\Program Files\\ZWCAD 2012 Eng\\CrashReportManagement.exe"=
- "c:\\Program Files\\ZWCAD 2012 Eng\\ZWErrorDialog.exe"=
- "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
- "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
- "5769:TCP"= 5769:TCP:UPSTCP
- .
- R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [4/21/2005 3:58 AM 9600]
- R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [9/28/2007 5:50 PM 188456]
- R2 qHTTPs;UPSMAN HTTP;c:\program files\UPS\upsman\ServiceDriver.exe [8/22/2011 9:43 AM 225353]
- R2 UPSMan;UPSMan;c:\program files\UPS\upsman\upsman.exe [8/22/2011 9:43 AM 4042837]
- S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/8/2010 7:55 AM 136176]
- S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [5/3/2012 8:31 AM 158856]
- S3 actccid;ActivCard USB Reader V2;c:\windows\system32\drivers\actccid.sys [8/2/2002 2:41 PM 47660]
- S3 EZUSB;EZUSB PC/SC Smart Card Reader;c:\windows\system32\drivers\ezusb.sys [8/11/2008 9:30 AM 57356]
- S3 gupdatem;Usluga Google ažuriranje (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/8/2010 7:55 AM 136176]
- S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
- S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
- S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/7/2012 7:12 AM 129976]
- S3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\drivers\s816bus.sys [6/19/2007 8:51 AM 81832]
- S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\drivers\s816mdfl.sys [6/19/2007 8:51 AM 13864]
- S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\drivers\s816mdm.sys [6/19/2007 8:51 AM 107304]
- S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s816mgmt.sys [6/19/2007 8:51 AM 99112]
- S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);c:\windows\system32\drivers\s816nd5.sys [6/19/2007 8:51 AM 21928]
- S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;c:\windows\system32\drivers\s816obex.sys [6/19/2007 8:51 AM 97320]
- S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);c:\windows\system32\drivers\s816unic.sys [6/19/2007 8:51 AM 97704]
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-08 05:55]
- .
- 2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-08 05:55]
- .
- 2012-05-16 c:\windows\Tasks\User_Feed_Synchronization-{ECC3DC8F-3108-47C2-868F-C70316734A3C}.job
- - c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.tportal.hr/fset.html
- uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
- uInternet Connection Wizard,ShellNext = iexplore
- uSearchAssistant = hxxp://www.google.com/ie
- uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
- TCP: Interfaces\{3C9F0A57-FAF9-41E0-A008-544D3E4AB2FF}: NameServer = 192.168.168.230,195.29.150.3
- FF - ProfilePath - c:\documents and settings\GEOMARSRV\Application Data\Mozilla\Firefox\Profiles\0z9afk1o.default\
- FF - prefs.js: browser.search.selectedEngine - Google
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
- .
- .
- **************************************************************************
- .
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2012-05-16 15:06
- Windows 5.1.2600 Service Pack 3 NTFS
- .
- scanning hidden processes ...
- .
- scanning hidden autostart entries ...
- .
- scanning hidden files ...
- .
- scan completed successfully
- hidden files: 0
- .
- **************************************************************************
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- .
- - - - - - - - > 'winlogon.exe'(748)
- c:\windows\system32\ackpbsc.dll
- c:\windows\system32\aclog.dll
- c:\windows\system32\ACLIBEAY.dll
- c:\windows\system32\acevtsub.dll
- c:\windows\system32\asphat32.dll
- c:\windows\system32\acerrmes.dll
- c:\windows\system32\aspcom.dll
- c:\program files\ActivIdentity\ActivClient\Resources\Merged\acerrmrc.dll
- c:\program files\ActivIdentity\ActivClient\Resources\Merged\asphatrc.dll
- c:\windows\system32\msi.dll
- c:\program files\ActivIdentity\ActivClient\acunlock.dll
- c:\windows\system32\aipingui.dll
- c:\program files\ActivIdentity\ActivClient\Resources\Merged\aipinguirc.dll
- c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
- c:\program files\ActivIdentity\ActivClient\Resources\Merged\acunlockrc.dll
- .
- - - - - - - - > 'explorer.exe'(560)
- c:\windows\system32\WININET.dll
- c:\windows\system32\msi.dll
- c:\windows\system32\ieframe.dll
- c:\windows\system32\webcheck.dll
- c:\windows\system32\WPDShServiceObj.dll
- c:\windows\system32\PortableDeviceTypes.dll
- c:\windows\system32\PortableDeviceApi.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files\Ahead\InCD\InCDsrv.exe
- c:\program files\ActivIdentity\ActivClient\acevents.exe
- c:\windows\System32\SCardSvr.exe
- c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
- c:\program files\Common Files\EPSON\EBAPI\eEBAgent.exe
- c:\program files\Java\jre6\bin\jqs.exe
- c:\windows\system32\wscntfy.exe
- c:\windows\system32\sstray.exe
- c:\progra~1\MICROS~2\rapimgr.exe
- .
- **************************************************************************
- .
- Completion time: 2012-05-16 15:09:50 - machine was rebooted
- ComboFix-quarantined-files.txt 2012-05-16 13:09
- ComboFix2.txt 2012-05-16 05:31
- .
- Pre-Run: 14,054,387,712 bytes free
- Post-Run: 13,924,372,480 bytes free
- .
- - - End Of File - - 80A8C13042A79759441299AC395FAE59
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement