COmbo fix sonuçları
ComboFix 09-11-05.05 - Administrator 06.11.2009 15:10.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1254.90.1055.18.2038.1288 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\1.bat
c:\windows\system32\2.reg
c:\windows\system32\hidden.reg
c:\windows\system32\scrrntr.dll
.
((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 )))))))))))))))))))))))))))))))
.
2009-11-06 12:56 . 2009-11-06 12:56 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-06 12:55 . 2009-11-06 12:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-11-06 12:55 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-06 12:55 . 2009-11-06 12:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-06 12:55 . 2009-11-06 12:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-06 12:55 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-06 12:34 . 2009-11-06 12:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nero
2009-11-06 11:30 . 2009-11-06 11:30 -------- d-----w- c:\program files\Trend Micro
2009-11-04 23:59 . 2009-11-04 23:59 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2009-11-01 18:00 . 2009-11-01 18:00 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2009-11-01 17:47 . 2009-11-01 17:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\ViGlance
2009-11-01 17:46 . 2009-11-01 18:38 -------- d-----w- c:\program files\ViGlance
2009-11-01 17:37 . 2009-11-01 17:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\Styler
2009-11-01 17:33 . 2009-11-01 17:33 15086 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_7b12541d.exe
2009-11-01 17:33 . 2009-11-01 17:33 15086 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
2009-11-01 17:33 . 2009-11-01 17:37 -------- d-----w- c:\program files\Styler
2009-11-01 17:01 . 2009-10-30 13:08 29512 ----a-w- c:\windows\system32\TURegOpt.exe
2009-11-01 17:01 . 2009-10-30 13:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2009-11-01 17:01 . 2009-11-01 17:01 -------- d-----w- c:\program files\TuneUp Utilities 2010
2009-11-01 17:00 . 2009-11-01 17:00 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-10-31 20:45 . 2009-10-31 20:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-10-31 20:45 . 2009-10-31 20:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2009-10-31 20:44 . 2009-10-31 20:44 -------- d-----w- c:\program files\Nokia
2009-10-31 20:44 . 2009-10-31 20:44 -------- d-----w- c:\program files\DIFX
2009-10-31 20:44 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-10-31 20:44 . 2009-10-31 20:44 -------- d-----w- c:\program files\PC Connectivity Solution
2009-10-31 20:38 . 2009-11-01 12:21 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-31 20:38 . 2009-10-31 20:38 -------- d-----w- c:\program files\Reference Assemblies
2009-10-31 20:38 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-10-31 20:31 . 2009-10-31 20:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-31 14:58 . 2009-10-31 14:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-31 14:49 . 2009-10-31 14:49 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-10-31 14:48 . 2009-10-31 14:48 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-10-30 23:12 . 2009-10-30 23:12 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-30 19:42 . 2008-11-10 09:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2009-10-30 19:41 . 2009-11-03 16:28 -------- d-----w- c:\program files\Microsoft Works
2009-10-30 19:41 . 2009-10-30 19:41 -------- d-----w- c:\program files\MSBuild
2009-10-30 19:38 . 2009-10-30 19:41 -------- d-----w- c:\windows\SHELLNEW
2009-10-30 19:38 . 2009-10-30 19:38 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
2009-10-30 19:38 . 2009-11-05 00:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-30 19:37 . 2009-10-30 19:37 -------- d-----r- C:\MSOCache
2009-10-30 13:28 . 2009-10-30 13:28 -------- d-----w- c:\windows\ie8updates
2009-10-30 13:24 . 2009-07-17 19:02 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2009-10-30 13:23 . 2009-08-29 07:56 206848 -c----w- c:\windows\system32\dllcache\occache.dll
2009-10-30 13:23 . 2009-08-29 07:56 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-10-30 13:23 . 2009-08-29 07:56 1208832 -c----w- c:\windows\system32\dllcache\urlmon.dll
2009-10-30 13:23 . 2009-08-29 07:56 25600 -c----w- c:\windows\system32\dllcache\jsproxy.dll
2009-10-30 13:23 . 2009-08-29 07:56 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-10-30 13:23 . 2009-08-29 07:56 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-30 13:23 . 2009-08-29 07:56 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-30 13:23 . 2009-08-29 07:56 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-30 13:23 . 2009-08-29 07:56 387584 -c----w- c:\windows\system32\dllcache\iedkcs32.dll
2009-10-30 13:23 . 2009-08-28 10:39 173056 -c----w- c:\windows\system32\dllcache\ie4uinit.exe
2009-10-30 13:23 . 2009-08-29 07:56 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-10-30 13:20 . 2009-02-06 10:15 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-10-30 13:20 . 2009-03-06 13:50 283136 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-10-30 13:20 . 2009-02-09 10:55 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-10-30 13:20 . 2009-02-09 10:55 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-10-30 13:20 . 2009-02-09 11:16 111104 -c----w- c:\windows\system32\dllcache\services.exe
2009-10-30 13:20 . 2009-02-06 10:36 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2009-10-30 13:20 . 2009-02-09 10:55 710656 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-10-30 13:20 . 2009-02-09 10:55 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-10-30 13:20 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-10-30 13:19 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-10-30 13:18 . 2009-08-04 17:21 2147328 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-30 13:18 . 2009-08-04 20:52 2068096 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-30 13:18 . 2009-08-04 17:21 2025984 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-30 13:17 . 2009-06-22 06:47 726528 -c----w- c:\windows\system32\dllcache\jscript.dll
2009-10-30 13:17 . 2009-11-03 16:31 -------- d--h--w- c:\windows\$hf_mig$
2009-10-30 13:10 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-10-29 00:20 . 2009-10-29 00:21 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-10-28 23:12 . 2009-10-28 23:12 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-28 23:12 . 2009-10-28 23:12 -------- d-----w- c:\program files\McAfee Security Scan
2009-10-27 22:23 . 2009-10-27 22:23 0 ----a-w- c:\windows\nsreg.dat
2009-10-27 22:23 . 2009-10-27 22:23 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-10-27 21:08 . 2009-11-03 16:16 -------- d-----w- c:\program files\Farm Helper
2009-10-27 20:51 . 2009-11-03 16:16 -------- d-----w- c:\program files\FarmHelper
2009-10-23 14:45 . 2009-10-23 14:45 -------- d--h--w- c:\windows\PIF
2009-10-23 14:01 . 2009-10-23 14:01 -------- d-----w- c:\program files\CCleaner
2009-10-22 21:31 . 2009-10-22 21:31 -------- d-----w- c:\program files\DirectVobSub
2009-10-22 21:22 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-10-22 21:22 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-10-22 21:22 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-10-22 21:22 . 2009-10-16 18:53 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-10-22 20:19 . 2009-10-22 20:20 3119320 ----a-w- c:\documents and settings\Administrator\Application Data\IDM\idmupdt.exe
2009-10-22 20:19 . 2009-10-22 20:19 198064 ----a-w- c:\documents and settings\Administrator\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-10-22 20:18 . 2009-10-22 20:18 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2009-10-22 18:16 . 2009-10-22 18:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\BSplayer Pro
2009-10-22 18:16 . 2009-10-22 18:16 -------- d-----w- c:\program files\Webteh
2009-10-22 18:09 . 2004-01-11 22:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-10-22 17:59 . 2009-10-22 17:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\DFX
2009-10-22 15:58 . 2009-10-22 15:58 932368 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2009-10-22 15:58 . 2009-10-22 15:58 678416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2009-10-22 15:58 . 2009-10-22 15:58 604688 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2009-10-22 15:58 . 2009-10-22 15:58 522768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2009-10-22 15:58 . 2009-10-22 15:58 1096208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2009-10-22 15:57 . 2009-10-22 15:57 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2009-10-22 15:57 . 2009-10-22 15:57 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2009-10-22 15:57 . 2009-10-22 15:57 264720 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2009-10-22 15:57 . 2009-10-22 15:57 59920 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2009-10-22 15:57 . 2009-10-22 15:57 109072 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2009-10-22 15:57 . 2009-10-22 15:57 264720 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2009-10-22 15:26 . 2009-10-22 15:26 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-22 15:19 . 2009-10-22 15:57 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-22 15:19 . 2009-10-22 15:57 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-22 15:19 . 2009-11-03 22:14 -------- d-----w- c:\program files\Microsoft Goodies
2009-10-22 15:19 . 2009-11-06 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-22 15:19 . 2009-10-22 16:02 -------- d-----w- c:\program files\Kaspersky Lab
2009-10-21 22:49 . 2006-03-17 12:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2009-10-21 22:49 . 2006-03-17 09:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2009-10-21 22:49 . 2006-03-17 09:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2009-10-21 22:49 . 2006-03-17 09:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2009-10-21 22:49 . 2006-03-17 09:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2009-10-21 22:49 . 2009-10-21 22:49 -------- d-----w- c:\program files\Nero
2009-10-21 22:49 . 2009-10-21 22:49 -------- d-----w- c:\program files\Common Files\Nero
2009-10-21 22:49 . 2009-10-21 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-10-21 22:48 . 2009-10-21 22:48 -------- d-----w- c:\program files\7-Zip
2009-10-21 22:43 . 2009-10-21 22:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-10-21 22:43 . 2009-11-01 19:32 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-10-21 22:41 . 2009-10-21 22:43 -------- d-----w- c:\program files\Google
2009-10-21 22:40 . 2009-10-21 22:40 -------- d-----w- c:\documents and settings\All Users\Application Data\DFX
2009-10-21 22:40 . 2009-10-21 22:40 -------- d-----w- c:\program files\DFX
2009-10-21 22:40 . 2009-10-21 22:40 -------- d-----w- c:\program files\Common Files\DFX
2009-10-21 22:39 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-10-21 22:39 . 2009-10-22 21:23 -------- d-----w- c:\program files\K-Lite Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 14:55 . 2009-10-21 23:10 70144 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-03 01:03 . 2001-11-22 12:00 75394 ----a-w- c:\windows\system32\perfc01F.dat
2009-11-03 01:03 . 2001-11-22 12:00 417436 ----a-w- c:\windows\system32\perfh01F.dat
2009-11-01 16:43 . 2009-10-21 23:12 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-10-31 20:47 . 2009-10-22 11:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-22 15:14 . 2009-10-21 22:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-22 15:14 . 2009-10-21 22:52 -------- d-----w- c:\program files\Lavasoft
2009-10-22 15:13 . 2009-10-22 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-22 14:16 . 2009-10-22 12:43 -------- d-----w- c:\program files\Farmville
2009-10-21 23:34 . 2009-10-21 23:34 -------- d-----w- c:\program files\Microsoft
2009-10-21 23:34 . 2009-10-21 23:33 -------- d-----w- c:\program files\Windows Live
2009-10-21 23:34 . 2009-10-21 23:34 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-21 23:28 . 2009-10-21 23:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-10-21 23:10 . 2009-10-21 23:10 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-21 22:58 . 2009-10-21 15:41 -------- d-----w- c:\program files\Windows Sidebar
2009-10-21 16:05 . 2009-10-21 15:45 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-21 15:46 . 2009-10-21 15:46 295 ----a-w- c:\windows\system32\Find_Target.vbs
2009-10-21 15:46 . 2009-10-21 15:46 -------- d-----w- c:\program files\LClock
2009-10-21 15:42 . 2009-10-21 15:42 21736 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-21 15:42 . 2009-10-21 15:42 -------- d-----w- c:\program files\VistaExperience.org
2009-10-21 15:41 . 2009-10-21 15:41 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-11 14:14 . 2008-04-14 07:00 136704 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 10:43 . 2009-10-15 06:09 210352 ----a-w- c:\windows\system32\idmmbc.dll
2009-09-04 21:04 . 2008-04-14 07:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2009-05-08 20:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:01 . 2009-05-08 20:20 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
.
------- Sigcheck -------
[-] 2009-05-08 . 1254A5890C9F1ADA216BE0E0B5D5CF35 . 540672 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2009-05-08 . 2E1BE2B73E406E85211B0CC306BB1E56 . 662528 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2009-05-08 . B3A28AB23450EBFEAB3CEE207B97EAA5 . 639488 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2009-05-08 . 5C098BB8DDFD7C9DF4442474BD166D24 . 2509312 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2009-05-08 . 7D518D62725D520CC5A01AAD5074AD39 . 37888 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
c:\windows\system32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\lclock.exe" [2004-09-19 65536]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-10-22 3134896]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-05-08 37888]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-21 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-26 196608]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-05-22 413696]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
"combofix"="c:\combofix\CF9732.exe" [2009-11-06 387072]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-13 17508864]
"Alcmtr"="ALCMTR.EXE" - c:\windows\ALCMTR.EXE [2008-06-19 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-05-08 37888]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-05-08 128512]
c:\documents and settings\Administrator\Start Menu\Programlar\BaŸlang‡\
Styler.lnk - c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-11-1 15086]
c:\documents and settings\All Users\Start Menu\Programlar\BaŸlang‡\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2009-8-6 439648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"SfcDisable"=dword:ffffff9d
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15.12.2008 19:41 33808]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [30.10.2009 15:05 1021256]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13.05.2009 16:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16.05.2009 19:59 19472]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 07:24 10064]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [21.10.2009 23:57 1684736]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-11-06 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-10-30 13:12]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
IE: Açılır Pencere Engelleyicisine ekle - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: Bütün linkleri IDM ile indir - c:\program files\Internet Download Manager\IEGetAll.htm
IE: FLV video içeriğini IDM ile indir - c:\program files\Internet Download Manager\IEGetVL.htm
IE: IDM ile indir - c:\program files\Internet Download Manager\IEExt.htm
IE: Microsoft Excel'e &Ver - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {76B141BD-AE2B-4201-B616-A71A655E7439} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yjdxqr0q.default\
FF - component: c:\documents and settings\Administrator\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2009-11-06 15:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1004336348-1326574676-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,f1,91,97,06,ab,7e,4f,a6,69,9c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,f1,91,97,06,ab,7e,4f,a6,69,9c,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,f1,91,97,06,ab,7e,4f,a6,69,9c,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1856)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(1912)
c:\windows\system32\setupapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Apoint2K\Apntex.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Styler\Styler.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2009-11-06 15:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-06 13:20
Pre-Run: 13.088.309.248 bayt boş
Post-Run: 13.282.078.720 bayt boş
- - End Of File - - C231A0FBD62EB7ED6088201C0E8F0F07