first of all
all the programs are runing back again ! (before the combofix)
Combo Log :
ComboFix 08-01-23.2 - Admin 01/24/2008 16:23:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1255.1.1033.18.263 [GMT 2:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\fu1.exe
C:\WINDOWS\system32\setup_06801.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\nm
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 14:27 436,256 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-24 14:27 3,704 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-24 14:27 16,928 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-24 14:27 10,364 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-24 14:12 --------- d-----w C:\Program Files\NOD32
2008-01-24 13:55 --------- d-----w C:\Program Files\ICQ
2008-01-24 13:40 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-01-24 13:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-22 17:31 --------- d-----w C:\Program Files\eMule
2008-01-21 05:16 --------- d-----w C:\Program Files\FlashGet
2008-01-20 19:37 --------- d-----w C:\Program Files\Trojan Remover
2008-01-20 10:38 --------- d-----w C:\Program Files\Muti ID3 Tag Editor
2008-01-12 22:27 --------- d-----w C:\Program Files\Nero
2008-01-12 22:27 --------- d-----w C:\Program Files\Common Files\Ahead
2008-01-12 15:58 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-12 15:47 --------- d-----w C:\Program Files\FlashFXP
2008-01-12 15:41 361,344 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-12 15:41 361,344 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-01-12 14:29 --------- d-----w C:\Program Files\Spyware Doctor
2008-01-07 16:25 12,505,824 ----a-w C:\Program Files\signandverify.exe
2008-01-04 16:52 47,342 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-01-04 16:52 4,203 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-01-04 16:04 --------- d-----w C:\Program Files\Devious Codeworks
2008-01-04 15:45 --------- d-----w C:\Program Files\Tweak-XP Pro 4
2007-12-31 15:18 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-12-31 15:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 15:18 --------- d-----w C:\Program Files\TP-LINK
2007-12-21 14:42 --------- d-----w C:\Program Files\DivX
2007-12-21 13:56 --------- d-----w C:\Program Files\Serials 2000 7.1 Plus
2007-12-21 06:21 33,800 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-12-21 06:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 06:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-12-16 02:23 --------- d-----w C:\Program Files\PocketDVDStudio
2007-12-13 17:58 --------- d-----w C:\Program Files\CStrike_1.6
2007-12-11 20:31 --------- d-----w C:\Program Files\DIFX
2007-12-11 19:49 --------- d-----w C:\Program Files\ARAR
2007-12-10 12:53 81,288 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 12:53 66,952 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 12:53 41,864 ----a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 12:53 29,576 ----a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-12-09 11:38 724,992 ----a-w C:\WINDOWS\iun6002.exe
2007-12-07 13:12 --------- d-----w C:\Program Files\Your Uninstaller 2008
2007-12-07 11:35 --------- d-----w C:\Program Files\Windows Desktop Search
2007-12-02 07:40 --------- d-----w C:\Program Files\Common Files\ACD Systems
2007-12-02 07:40 --------- d-----w C:\Program Files\ACD Systems
2007-12-01 09:37 --------- d-----w C:\Program Files\MSBuild
2007-12-01 09:32 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-01 08:56 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-11-30 22:27 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2007-11-30 22:27 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2007-11-30 22:27 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2007-11-30 22:27 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2007-11-30 22:26 69,120 ----a-w C:\WINDOWS\notepad.exe
2007-11-30 22:26 50,688 ----a-w C:\WINDOWS\twain_32.dll
2007-11-30 22:26 32,866 ------w C:\WINDOWS\slrundll.exe
2007-11-30 22:26 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2007-11-30 22:26 146,432 ----a-w C:\WINDOWS\regedit.exe
2007-11-30 22:26 11,325 ------w C:\WINDOWS\system32\drivers\vchnt5.dll
2007-11-30 22:26 10,752 ----a-w C:\WINDOWS\hh.exe
2007-11-30 22:26 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2007-11-30 22:25 4,255 ------w C:\WINDOWS\system32\drivers\adv01nt5.dll
2007-11-30 22:25 3,967 ------w C:\WINDOWS\system32\drivers\adv02nt5.dll
2007-11-30 22:25 3,901 ------w C:\WINDOWS\system32\drivers\siint5.dll
2007-11-30 22:25 3,775 ------w C:\WINDOWS\system32\drivers\adv11nt5.dll
2007-11-30 22:25 3,711 ------w C:\WINDOWS\system32\drivers\adv09nt5.dll
2007-11-30 22:25 3,647 ------w C:\WINDOWS\system32\drivers\adv07nt5.dll
2007-11-30 22:25 3,615 ------w C:\WINDOWS\system32\drivers\adv05nt5.dll
2007-11-30 22:25 3,135 ------w C:\WINDOWS\system32\drivers\adv08nt5.dll
2007-11-30 22:25 25,471 ------w C:\WINDOWS\system32\drivers\atv04nt5.dll
2007-11-30 22:25 21,183 ------w C:\WINDOWS\system32\drivers\atv01nt5.dll
2007-11-30 22:25 17,279 ------w C:\WINDOWS\system32\drivers\atv10nt5.dll
2007-11-30 22:25 15,423 ------w C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2007-11-30 22:25 14,143 ------w C:\WINDOWS\system32\drivers\atv06nt5.dll
2007-11-30 22:25 11,359 ------w C:\WINDOWS\system32\drivers\atv02nt5.dll
2007-11-30 16:26 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2007-11-30 16:19 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2007-11-30 16:18 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2007-11-30 16:18 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2007-11-30 16:18 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2007-11-30 16:18 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2007-11-30 16:17 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2007-11-30 16:17 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2007-11-30 16:17 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2007-11-30 16:15 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2007-11-30 16:14 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2007-11-30 16:14 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2007-11-30 16:14 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2007-11-30 16:14 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2007-11-30 16:13 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2007-11-30 16:13 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2007-11-30 16:13 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2007-11-30 16:13 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2007-11-30 16:12 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2007-11-30 16:12 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2007-11-30 16:12 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2007-11-30 16:07 --------- d-----w C:\Program Files\RapidLeecher Ultimate 2007
2007-11-30 15:55 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2007-11-30 15:54 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2007-11-30 15:54 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2007-11-30 15:50 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [12/01/2007 12:26 AM 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/21/2007 02:06 PM 1318912]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/21/2008 02:21 AM 686915]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [10/15/2002 06:00 PM 1818624 C:\WINDOWS\mixer.exe]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [01/24/2008 12:45 PM 737872]
"egui"="C:\Program Files\NOD32\egui.exe" [12/21/2007 08:21 AM 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [12/01/2007 12:26 AM 15360]
"WMI Standard Event Consumer - Scripting"="C:\WINDOWS\System32\wbem\scrcons32.exe" [ ]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices]
"WMI Standard Event Consumer - Scripting"="C:\WINDOWS\System32\wbem\scrcons32.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
TL-WN321G Wireless Utility.lnk - C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe [12/31/2007 5:18:18 PM 622592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
WMI Standard Event Consumer - Scripting REG_SZ C:\WINDOWS\System32\wbem\scrcons32.exe
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 10/10/2007 07:51 PM 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage]
C:\Program Files\AdVantage\AdVantage.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 12/01/2007 12:26 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 12/28/2007 10:06 PM 2521088 C:\Program Files\eMule\emule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 09/25/2007 10:10 AM 2007088 C:\Program Files\FlashGet\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 06/26/2006 04:13 PM 1207080 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 08/31/2007 12:01 PM 1037736 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
--a------ 10/14/2003 06:36 PM 38984 C:\PROGRA~1\ICQ\ICQNet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmsass]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NodLogin]
C:\Program Files\NOD32\nodlogin.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia PC Suite\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 01/12/2005 03:01 AM 32768 C:\Program Files\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
--a------ 11/01/2007 04:01 PM 160832 C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 09/25/2007 01:11 AM 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMI Standard Event Consumer - Scripting]
C:\WINDOWS\System32\wbem\scrcons32.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCSuiteTrayApplication"=C:\Program Files\Nokia PC Suite\Nokia PC Suite 6\LaunchApplication.exe -startup
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [12/21/2007 08:21 AM]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [08/04/2004 07:29 AM]
S0 Ramdisk;Ramdisk Driver;C:\WINDOWS\system32\DRIVERS\ramdsk.sys [09/28/2004 04:00 AM]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [07/17/2002 09:05 AM]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2mpaa.sys [08/17/2001 02:48 PM]
S3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [08/17/2001 02:11 PM]
S3 netr73;TL-WN321G Wireless USB Adapter Driver for Vista;C:\WINDOWS\system32\DRIVERS\netr73.sys [01/04/2007 10:41 AM]
S3 nk4Seem;nk4Seem;C:\Documents and Settings\Admin\Desktop\Seem_v4.0.en\nk4Seem.sys [06/18/2006 06:08 PM]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [11/30/2007 05:31 PM]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-11 15:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-01-20 22:54:33 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- E:\Programs\Portable\SpyEraser_Portable\SpyEraser Portable\App\SpyEraser\SpyEraser.exe
"2008-01-24 10:40:34 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A860A66A-FF93-4FF4-AA6E-741273CED4BD}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-24 16:28:42
Windows 5.1.2600 Service Pack 3, v.3264 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
although everything works , there are still 2 problems
1. some of the programs almost stuck the computer (search&destroy for example)
2.
i cant load my computer on safemode ! it loads te drivers and restart itself !!!
i hope you can help me !
HIJT log in next replay