Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:22:17 μμ, on 22/2/2010
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\USBRadio\QuickRadio.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Ραδιόφωνο - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickRADIO] C:\Program Files\USBRadio\\QuickRadio.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Έρευνα - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
--
End of file - 3295 bytes
ComboFix 10-02-21.02 - marina ltd 22/02/2010 22:29:44.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.1.1253.30.1032.18.1023.708 [GMT 2:00]
Running from: C:\Documents and Settings\marina ltd\Επιφάνεια εργασίας\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\Autorun.inf
Infected copy of C:\WINDOWS\system32\qmgr.dll was found and disinfected
Restored copy from - C:\WINDOWS\ERDNT\cache\qmgr.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-22 to 2010-02-22 )))))))))))))))))))))))))))))))
.
2010-02-22 19:27:01 . 2010-02-22 19:27:01 -------- d-----w- C:\Program Files\Trend Micro
2010-02-22 16:17:24 . 2010-02-22 16:17:25 -------- d-----w- C:\Program Files\MSN Messenger
2010-02-09 16:04:42 . 2010-02-09 16:04:42 81920 ----a-w- C:\WINDOWS\system32\W32N50.DLL
2010-02-09 16:04:42 . 2010-02-09 16:04:42 17134 ----a-w- C:\WINDOWS\system32\PCANDIS5.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-22 20:16:17 . 2003-04-17 12:00:00 73344 ----a-w- C:\WINDOWS\system32\perfc008.dat
2010-02-22 20:16:17 . 2003-04-17 12:00:00 480542 ----a-w- C:\WINDOWS\system32\perfh008.dat
2010-02-14 06:50:22 . 2009-02-16 14:01:54 -------- d-----w- C:\Documents and Settings\marina ltd\Application Data\uTorrent
2010-01-17 14:15:45 . 2010-01-17 14:15:45 -------- d-----w- C:\Documents and Settings\marina ltd\Application Data\InterVideo
2010-01-17 14:14:55 . 2010-01-17 14:14:55 -------- d-----w- C:\Program Files\InterVideo
2010-01-17 14:14:54 . 2009-02-13 11:24:36 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2009-12-28 18:47:00 . 2009-12-28 18:46:59 -------- d-----w- C:\Program Files\USBRadio
2003-04-17 12:00:00 . 2003-04-17 12:00:00 168989 --sha-r- C:\WINDOWS\system32\yptxc.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-02-22_20.14.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2003-04-17 12:00:00 . 2009-12-13 10:27:12 52962 C:\WINDOWS\system32\perfc009.dat
+ 2003-04-17 12:00:00 . 2010-02-22 20:16:17 52962 C:\WINDOWS\system32\perfc009.dat
- 2009-02-13 11:17:59 . 2010-02-22 13:22:52 49152 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet files\Content.IE5\index.dat
+ 2009-02-13 11:17:59 . 2010-02-22 20:14:20 49152 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet files\Content.IE5\index.dat
- 2009-02-13 11:17:59 . 2010-02-22 13:22:52 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-13 11:17:59 . 2010-02-22 20:14:20 32768 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-13 11:17:59 . 2010-02-22 13:22:52 16384 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-13 11:17:59 . 2010-02-22 20:14:20 16384 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2003-04-17 12:00:00 . 2010-02-22 20:16:17 380548 C:\WINDOWS\system32\perfh009.dat
- 2003-04-17 12:00:00 . 2009-12-13 10:27:12 380548 C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2006-01-24 09:37:02 7094272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2009-02-13 11:14:42 32881]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 19:10:00 339968]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 14:31:02 67584]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50:42 155648]
"QuickRADIO"="C:\Program Files\USBRadio\\QuickRadio.exe" [2004-01-12 15:13:54 184320]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2003-04-17 12:00:00 13312]
C:\Documents and Settings\All Users\Start Menu\¨¦š¨α££˜«˜\„΅΅ε¤ž©ž\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [13/2/2009 1:51:57 μμ 190465]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [13/2/2009 1:51:57 μμ 5817]
R3 PRISM_A00;PRISM 802.11 Driver;C:\WINDOWS\system32\drivers\PRISMA00.sys [13/2/2004 2:25:38 μμ 388448]
S2 ocrfsyr;Config Microsoft;C:\WINDOWS\system32\svchost.exe -k netsvcs [17/4/2003 2:00:00 μμ 12800]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ocrfsyr
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Ε&ξαγωγή στο Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
FF - ProfilePath - C:\Documents and Settings\marina ltd\Application Data\Mozilla\Firefox\Profiles\dwtk0gsk.default\
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: C:\Program Files\Java\j2re1.4.2_03\bin\NPOJI610.dll
.