ComboFix 15-01-08.01 - Admin 18.01.2015 9:17.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.3326.2363 [GMT 4:00]
Running from: C:\ComboFix.exe
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\admin\locals~1\temp\kb00066906.exe
c:\documents and settings\Admin\Избранное\KmyKOvpesJ+7zyNki4oTF+eQiEKP296A3nO1oBCWxAk=.xtbl
c:\documents and settings\Admin\Главное меню\Программы\Автозагрузка\update.exe
c:\documents and settings\Admin\Application Data\12650675
c:\documents and settings\Admin\Application Data\12650675\svchost.exe
c:\documents and settings\Admin\Application Data\2FCC4E0CC765E9B2.bmp
c:\documents and settings\Admin\Application Data\Microsoft\Windows\gupdater.exe
c:\documents and settings\Admin\Application Data\SQLite3.dll
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\iImpy+Jo-Z5MSLXid5SiT8SVSh1a88Euw2LRH+QfMeY=.xtbl
c:\documents and settings\Admin\Recent\s4ECf6pqrIuZ2PmB4SqHpyZ7AQ4eI9Jdwvs5gOQFbvo=.xtbl
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\PostBuild.exe
c:\documents and settings\All Users\Application Data\windows
c:\documents and settings\All Users\mslmanq.exe
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\OT2QTOAZLwV1uCyxvgfQYiFINUNCp2LB1-Rdhk97bAE=.xtbl
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\dv0Nwn1yjImS+lZ+lWme38dPer2TQGlxFj-rKdqYr2c=.xtbl
c:\program files\safesurf
c:\program files\safesurf\auth.txt
c:\program files\safesurf\bl.txt
c:\program files\safesurf\block.txt
c:\program files\safesurf\crashes.txt
c:\program files\safesurf\debug.txt
c:\program files\safesurf\dotnetfx.exe
c:\program files\safesurf\f\1\AccessibleMarshal.dll
c:\program files\safesurf\f\1\breakpadinjector.dll
c:\program files\safesurf\f\1\D3DCompiler_43.dll
c:\program files\safesurf\f\1\freebl3.chk
c:\program files\safesurf\f\1\freebl3.dll
c:\program files\safesurf\f\1\gkmedias.dll
c:\program files\safesurf\f\1\IA2Marshal.dll
c:\program files\safesurf\f\1\js-gdb.py
c:\program files\safesurf\f\1\libEGL.dll
c:\program files\safesurf\f\1\libGLESv2.dll
c:\program files\safesurf\f\1\mozalloc.dll
c:\program files\safesurf\f\1\mozglue.dll
c:\program files\safesurf\f\1\mozjs.dll
c:\program files\safesurf\f\1\msvcp100.dll
c:\program files\safesurf\f\1\msvcr100.dll
c:\program files\safesurf\f\1\nss3.dll
c:\program files\safesurf\f\1\nssckbi.dll
c:\program files\safesurf\f\1\nssdbm3.chk
c:\program files\safesurf\f\1\nssdbm3.dll
c:\program files\safesurf\f\1\omni.ja
c:\program files\safesurf\f\1\plugin-container.exe
c:\program files\safesurf\f\1\plugin-hang-ui.exe
c:\program files\safesurf\f\1\plugins\NPSWF32_13_0_0_214.dll
c:\program files\safesurf\f\1\profile\_CACHE_CLEAN_
c:\program files\safesurf\f\1\profile\Cache\_CACHE_001_
c:\program files\safesurf\f\1\profile\Cache\_CACHE_002_
c:\program files\safesurf\f\1\profile\Cache\_CACHE_003_
c:\program files\safesurf\f\1\profile\Cache\_CACHE_MAP_
c:\program files\safesurf\f\1\profile\Cache\1\B4\C8751d01
c:\program files\safesurf\f\1\profile\Cache\2\07\A04FDd01
c:\program files\safesurf\f\1\profile\Cache\3\05\88454d01
c:\program files\safesurf\f\1\profile\Cache\3\84\ECF27d01
c:\program files\safesurf\f\1\profile\Cache\4\59\7BE96d01
c:\program files\safesurf\f\1\profile\Cache\4\D0\A831Bd01
c:\program files\safesurf\f\1\profile\Cache\5\6B\9C337d01
c:\program files\safesurf\f\1\profile\Cache\5\92\3A7B6d01
c:\program files\safesurf\f\1\profile\Cache\7\83\6F61Ed01
c:\program files\safesurf\f\1\profile\Cache\7\ED\463F8d01
c:\program files\safesurf\f\1\profile\Cache\8\CD\FFA82d01
c:\program files\safesurf\f\1\profile\Cache\9\A1\DFEBFd01
c:\program files\safesurf\f\1\profile\Cache\A\80\7AA10d01
c:\program files\safesurf\f\1\profile\Cache\A\96\342F4d01
c:\program files\safesurf\f\1\profile\Cache\A\F4\64147d01
c:\program files\safesurf\f\1\profile\Cache\B\4C\C778Ad01
c:\program files\safesurf\f\1\profile\Cache\B\E0\04EBCd01
c:\program files\safesurf\f\1\profile\Cache\C\B4\29186d01
c:\program files\safesurf\f\1\profile\Cache\C\D3\8E9C9d01
c:\program files\safesurf\f\1\profile\Cache\E\47\A2279d01
c:\program files\safesurf\f\1\profile\Cache\E\51\A6DF2d01
c:\program files\safesurf\f\1\profile\Cache\F\94\5906Fd01
c:\program files\safesurf\f\1\softokn3.chk
c:\program files\safesurf\f\1\softokn3.dll
c:\program files\safesurf\f\1\xul.dll
c:\program files\safesurf\f\bitsurf
c:\program files\safesurf\f\cg.exe
c:\program files\safesurf\f\crashinfo.txt
c:\program files\safesurf\f\jet.exe
c:\program files\safesurf\f\sfa.bin
c:\program files\safesurf\f\sfc.txt
c:\program files\safesurf\f\upcache
c:\program files\safesurf\f\upfilelist
c:\program files\safesurf\fon.jpg
c:\program files\safesurf\geckofx-core.dll
c:\program files\safesurf\geckofx-winforms.dll
c:\program files\safesurf\lastsid.txt
c:\program files\safesurf\log.txt
c:\program files\safesurf\poclbm130302GeForce GTS 250v1w256l4.bin
c:\program files\safesurf\poclbm130302GeForce GTX 650gv1w256l4.bin
c:\program files\safesurf\prevsid.txt
c:\program files\safesurf\prtest.exe
c:\program files\safesurf\SafeSurf ABUSE README.txt
c:\program files\SafeSurf\safesurf.exe
c:\program files\safesurf\sf.txt
c:\program files\safesurf\Skybound.Gecko.dll
c:\program files\safesurf\SurfGuard.exe
c:\program files\safesurf\unins000.dat
c:\program files\safesurf\unins000.exe
c:\windows\system32\Пузыри.scr
c:\windows\system32\wordpad.exe
E:\install.exe
E:\setup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BD0001
-------\Legacy_BD0002
-------\Service_bd0001
-------\Service_bd0002
.
.
((((((((((((((((((((((((( Files Created from 2014-12-18 to 2015-01-18 )))))))))))))))))))))))))))))))
.
.
2015-01-15 15:43 . 2015-01-15 15:45 -------- d-----w- C:\FRST
2015-01-15 11:56 . 2015-01-15 11:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Baidu
2015-01-15 05:48 . 2015-01-15 11:55 -------- d-----w- C:\AdwCleaner
2015-01-15 04:08 . 2015-01-15 04:08 -------- d-sh--w- c:\documents and settings\Admin\Application Data\AAN-DUPKSPPO
2015-01-14 16:51 . 2015-01-14 16:51 5013680 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2015-01-13 12:55 . 2015-01-13 12:55 -------- d--h--w- c:\windows\$hf_mig$
2015-01-08 19:02 . 2014-06-16 06:01 184192 ----a-w- c:\windows\system32\drivers\ssudserd.sys
2015-01-08 19:02 . 2014-06-16 06:01 184192 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2015-01-08 19:02 . 2014-06-16 06:01 89856 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2015-01-08 19:02 . 2014-06-16 06:01 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2015-01-08 17:59 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2015-01-08 17:59 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2015-01-08 17:32 . 2015-01-08 17:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Samsung
2015-01-08 17:00 . 2015-01-13 14:54 -------- d-----w- C:\WinSetupFromUSB
2015-01-08 05:18 . 2015-01-08 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2014-12-25 07:45 . 2014-12-25 07:45 -------- d-----w- c:\documents and settings\Admin\Application Data\WebMoneyAdvisor
2014-12-25 07:45 . 2014-12-25 07:45 -------- d-----w- c:\program files\WebMoney Agent
2014-12-25 07:44 . 2014-12-25 07:45 -------- d-----w- c:\program files\WebMoney
2014-12-25 07:43 . 2015-01-15 06:12 -------- d-sh--w- c:\documents and settings\Admin\IECompatCache
2014-12-20 05:37 . 2015-01-15 06:07 -------- d-----w- c:\program files\Mozilla Maintenance Service
2014-12-19 11:37 . 2014-12-19 11:37 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\game_release
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-01-14 16:51 . 2013-12-21 14:13 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-01-14 16:51 . 2013-12-21 14:13 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-27 01:40 . 2014-12-04 14:23 145224 ----a-w- c:\windows\system32\drivers\BDArKit.sys
2014-12-21 10:42 . 2014-12-05 02:50 245576 ----a-w- c:\windows\system32\drivers\BDMWrench.sys
2014-12-03 13:03 . 2014-10-07 17:01 185672 ----a-w- c:\windows\system32\drivers\bd0004.sys
2014-12-02 07:59 . 2014-10-07 17:01 67656 ----a-w- c:\windows\system32\drivers\BDSafeBrowser.sys
2010-12-20 14:08 . 2014-04-23 07:12 77648 ----a-w- c:\program files\mbamext.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-03-15 . B8F35C9F3938FCF8131E64918D2D447E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\e54644597fb5ba29bf4a386b93c95aec\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\e54644597fb5ba29bf4a386b93c95aec\SP3GDR\tcpip.sys
.
[-] 2011-03-15 12:37 . D642709203ADC066E35350591E4FD9C0 . 855040 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2011-03-15 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
.
[-] 2014-03-06 . E230193CC66982F0423384022BC96AF0 . 920064 . . [8.00.6001.23580] . . c:\windows\SoftwareDistribution\Download\5aa932222a68edb219a960afe7d16b41\SP3QFE\wininet.dll
[-] 2011-03-15 . ABD6BEB53BD656A6013CE62583C449EA . 1044480 . . [8.00.6001.23111] . . c:\windows\system32\wininet.dll
.
[-] 2011-03-15 . 6C16E975F7186845FA5A9A7DC449A152 . 226816 . . [5.1.2600.5512] . . c:\windows\regedit.exe
.
[-] 2011-03-15 . 8494518476E9E4E0CB49D69FA09CD65E . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0YndCase0Sync]
@="{63D48440-63AB-44D0-B323-4731DFCDE9E9}"
[HKEY_CLASSES_ROOT\CLSID\{63D48440-63AB-44D0-B323-4731DFCDE9E9}]
2013-12-17 09:59 1278752 ----a-w- c:\program files\Yandex\YandexDisk\bin\YandexDiskOverlays-2398.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0YndCase1Modified]
@="{7E7DC279-E6BE-4D57-9DEC-14FA0339DBC0}"
[HKEY_CLASSES_ROOT\CLSID\{7E7DC279-E6BE-4D57-9DEC-14FA0339DBC0}]
2013-12-17 09:59 1278752 ----a-w- c:\program files\Yandex\YandexDisk\bin\YandexDiskOverlays-2398.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0YndCase2Error]
@="{FB2FE984-05F5-4512-9D9B-69D3DE61F6D9}"
[HKEY_CLASSES_ROOT\CLSID\{FB2FE984-05F5-4512-9D9B-69D3DE61F6D9}]
2013-12-17 09:59 1278752 ----a-w- c:\program files\Yandex\YandexDisk\bin\YandexDiskOverlays-2398.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0YndCase3Shared]
@="{AF8D197E-7022-4c3d-BD88-68AD35C9C169}"
[HKEY_CLASSES_ROOT\CLSID\{AF8D197E-7022-4c3d-BD88-68AD35C9C169}]
2013-12-17 09:59 1278752 ----a-w- c:\program files\Yandex\YandexDisk\bin\YandexDiskOverlays-2398.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2012-11-27 1726976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-11-16 3117384]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2013-03-15 15668512]
"skytel.exe"="c:\documents and settings\Admin\Application Data\AAN-DUPKSPPO\skytel.exe" [2008-04-15 118272]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
c:\documents and settings\Default User\Главное меню\Программы\Автозагрузка\
bWlr8jwOycpYmuXfgoH7QVr-jFnDbrIUHmqcVT3yveo=.xtbl [2015-1-13 480]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 0 (0x0)
"HideSCAHealth"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
"TaskbarNoNotification"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Главное меню^Программы^Автозагрузка^Behold TV.lnk]
path=c:\documents and settings\Admin\Главное меню\Программы\Автозагрузка\Behold TV.lnk
backup=c:\windows\pss\Behold TV.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Главное меню^Программы^Автозагрузка^Nzj4KgKY2omCk6B+aUujj1QHzGTos7EwB7SiOphIa2w=.xtbl]
path=c:\documents and settings\Admin\Главное меню\Программы\Автозагрузка\Nzj4KgKY2omCk6B+aUujj1QHzGTos7EwB7SiOphIa2w=.xtbl
backup=c:\windows\pss\Nzj4KgKY2omCk6B+aUujj1QHzGTos7EwB7SiOphIa2w=.xtblStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Главное меню^Программы^Автозагрузка^ProfitTaskMonitor.lnk]
backup=c:\windows\pss\ProfitTaskMonitor.lnkStartup
path=c:\documents and settings\Admin\Главное меню\Программы\Автозагрузка\ProfitTaskMonitor.lnk
.
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Главное меню^Программы^Автозагрузка^System Check.lnk]
path=c:\documents and settings\Admin\Главное меню\Программы\Автозагрузка\System Check.lnk
backup=c:\windows\pss\System Check.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Z9qrXLW9Ua12VNBEqLoxC7HEgZpCkW5pi0ng-ULq+T8=.xtbl]
path=c:\documents and settings\All Users\Главное меню\Программы\Автозагрузка\Z9qrXLW9Ua12VNBEqLoxC7HEgZpCkW5pi0ng-ULq+T8=.xtbl
backup=c:\windows\pss\Z9qrXLW9Ua12VNBEqLoxC7HEgZpCkW5pi0ng-ULq+T8=.xtblCommon Startup
.
[HKLM\~\startupfolder\C:^Program Files^ProfitTask^ProfitTaskMonitor.exe]
backup=c:\program files\ProfitTask\ProfitTaskMonitor.exe\pss\ProfitTaskMonitor.lnk.Startup
path=c:\program files\ProfitTask\ProfitTaskMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell22]
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\531RRGKQ\su2f[1] [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2Gis Update Notifier]
2014-12-18 17:40 4582936 ----a-w- c:\program files\2gis\3.0\2GISTrayNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 00:44 500208 ----a-w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 11:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-15 13:00 110592 ----a-w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Coin Miner]
2015-01-12 13:19 15613824 ----a-w- c:\program files\CoinMiner\coinminer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-15 11:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2013-03-15 02:57 15668512 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2013-03-15 02:57 223008 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nvtmru]
2013-11-08 20:49 1028384 ----a-w- c:\program files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintDisp]
2013-06-25 09:44 877568 ----a-w- c:\windows\system32\PrintDisp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-06-12 11:10 17887232 ----a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkinClock]
2012-11-27 21:01 1726976 ----a-w- c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-07-24 14:26 21650016 ------w- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 06:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SyncManPath]
2014-08-27 20:27 17281312 ----a-w- c:\program files\Yandex\YandexDisk\bin\YandexDisk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB Antivirus]
2011-02-01 00:08 623520 ----a-w- c:\program files\USB Disk Security\USBGuard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-03-17 12:37 399736 ----a-w- c:\program files\uTorrent\utorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VistaIcon]
2008-01-02 10:52 132096 ----a-w- c:\program files\VistaDriveIcon\VistaDrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wmagent.exe]
2009-10-19 11:47 210400 ----a-w- c:\program files\WebMoney Agent\wmagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Agent"=2 (0x2)
"MSDTC"=3 (0x3)
"Printer Control"=2 (0x2)
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"srservice"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
R1 bd0004;bd0004;c:\windows\system32\drivers\bd0004.sys [07.10.2014 21:01 185672]
R1 BDMWrench;BDMWrench;c:\windows\system32\drivers\BDMWrench.sys [05.12.2014 6:50 245576]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.03.2012 7:40 120152]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.03.2012 7:40 104160]
R2 ABBYY.Licensing.FineReader.Corporate.11.0;ABBYY FineReader 11 CE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\11.00\Licensing\CE\NetworkLicenseServer.exe [18.08.2011 16:47 819976]
R2 BDArKit;BDArKit;c:\windows\system32\drivers\BDArKit.sys [04.12.2014 18:23 145224]
R2 BDSGRTP;BDSGRTP Service;c:\program files\Common Files\Baidu\BaiduProtect1.3\1.3.0.645\BaiduProtect.exe [05.12.2014 14:02 1940072]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2012 14:24 913184]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [03.04.2014 20:21 315008]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [08.01.2015 23:02 741640]
R2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [22.04.2014 9:40 4799760]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [08.01.2015 23:02 89856]
R3 SAA713x;Behold TV WDM Capture (SAA713x);c:\windows\system32\drivers\saa713x.sys [17.12.2013 13:21 279552]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [08.01.2015 23:02 184192]
R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [08.01.2015 23:02 184192]
S1 BDEnhanceBoost;BDEnhanceBoost;c:\windows\system32\DRIVERS\BDEnhanceBoost.sys --> c:\windows\system32\DRIVERS\BDEnhanceBoost.sys [?]
S2 BDSafeBrowser;BDSafeBrowser;c:\windows\system32\drivers\BDSafeBrowser.sys [07.10.2014 21:01 67656]
S2 KMService;KMService;c:\windows\system32\srvany.exe [17.12.2013 15:15 8192]
S3 2GISUpdateService;2GIS UpdateService;c:\program files\2gis\3.0\2GISUpdateService.exe [18.12.2014 21:40 3764760]
S3 4587704161521984;4587704161521984;\??\c:\documents and settings\admin\local settings\temp\11A7A9CC4.sys --> c:\documents and settings\admin\local settings\temp\11A7A9CC4.sys [?]
S3 458770516902D884;458770516902D884;\??\c:\documents and settings\admin\local settings\temp\5AC1FA511.sys --> c:\documents and settings\admin\local settings\temp\5AC1FA511.sys [?]
S3 45877F66D17C7F04;45877F66D17C7F04;\??\c:\documents and settings\admin\local settings\temp\30FC3BD06.sys --> c:\documents and settings\admin\local settings\temp\30FC3BD06.sys [?]
S3 4598BA4FF70D0BA2;4598BA4FF70D0BA2;\??\c:\documents and settings\admin\local settings\temp\72129873.sys --> c:\documents and settings\admin\local settings\temp\72129873.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [17.12.2013 13:43 1684736]
S3 eapihdrv;eapihdrv;\??\c:\docume~1\Admin\LOCALS~1\Temp\ehdrv.sys --> c:\docume~1\Admin\LOCALS~1\Temp\ehdrv.sys [?]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys --> c:\windows\system32\DRIVERS\ew_jubusenum.sys [?]
S3 zte_ecm_enum_filter;zte_ecm_enum_filter;c:\windows\system32\DRIVERS\zte_ecm_enum_filter.sys --> c:\windows\system32\DRIVERS\zte_ecm_enum_filter.sys [?]
S4 Agent;VPDAgent;c:\windows\VPDAgent.exe [13.05.2014 18:01 200704]
S4 Printer Control;Printer Control;c:\windows\system32\PrintCtrl.exe [11.11.2014 20:08 102400]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-01-15 07:04 1087816 ----a-w- c:\program files\Google\Chrome\Application\39.0.2171.99\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-01-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21 16:51]
.
2015-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2015-01-15 07:04]
.
2015-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2015-01-15 07:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mail.ru/cnt/10445
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.Google.com/
IE: &Отправить в OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: &Экспорт в Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 92.39.136.130 8.8.8.8
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\kwmsvgwf.default-1421337993328\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-ITBar7Position - (no file)
HKLM-Run-jsafesurf - c:\program files\SafeSurf\safesurf.exe
c:\documents and settings\Admin\Главное меню\Программы\Автозагрузка\AutorunsDisabled\winupdate.lnk - c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Windows\winupdate.exe /app 0A98F6B5D98732C4A93EB5423FE0CC9D
Notify-WgaLogon - (no file)
MSConfigStartUp-Client Server Runtime Subsystem - c:\documents and settings\All Users\Application Data\Windows\csrss.exe
MSConfigStartUp-explorer - c:\docume~1\Admin\LOCALS~1\Temp\324A.tmp
MSConfigStartUp-jsafesurf - c:\program files\SafeSurf\safesurf.exe
AddRemove-HashTab 4.0.0.2 - c:\windows\system32\Uninstall.exe
AddRemove-JetSwap SafeSurf_is1 - c:\program files\SafeSurf\unins000.exe
AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\SAMSUNG\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\SAMSUNG\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2015-01-18 09:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\.Default\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\AppGPFault\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\CCSelect\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\Close\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\CriticalBatteryAlarm\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\DeviceConnect\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\DeviceDisconnect\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\DeviceFail\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\InternetAlert\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\LowBatteryAlarm\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\MailBeep\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\Maximize\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\MenuCommand\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\MenuPopup\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\Minimize\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\Open\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\PrintComplete\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\RestoreDown\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\RestoreUp\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\ShowBand\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemAsterisk\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemExclamation\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemExit\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemHand\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemNotification\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemQuestion\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\SystemStart\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\WindowsLogoff\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\.Default\WindowsLogon\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\BlockedPopup\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\FeedDiscovered\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\MoveMenuItem\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\Navigating\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\SearchProviderDiscovered\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\Explorer\SecurityBand\%C90*nC]
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\PictureIt\PiDeleteObject\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\PictureIt\PiMiscue\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Apps\PictureIt\PiTaskButton\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@=""
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\AppEvents\Schemes\Names\%C90*nC]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="Хуй"
.
[HKEY_USERS\S-1-5-21-1708537768-1409082233-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,00,fd,6c,7e,43,00,8b,4a,98,48,8f,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,00,fd,6c,7e,43,00,8b,4a,98,48,8f,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\cscui.dll
.
- - - - - - - > 'explorer.exe'(2852)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\COMRes.dll
c:\program files\Yandex\YandexDisk\bin\YandexDiskOverlays-2398.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~1\Office14\1049\GrooveIntlResource.dll
c:\windows\System32\cscui.dll
c:\program files\Atomic Alarm Clock\Clock.dll
c:\windows\system32\msi.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\NETSHELL.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wudfhost.exe
c:\program files\Google\Update\1.3.25.11\GoogleCrashHandler.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\CNAB4RPK.EXE
c:\windows\system32\wscntfy.exe
c:\program files\TeamViewer\Version9\TeamViewer.exe
c:\program files\TeamViewer\Version9\tv_w32.exe
.
**************************************************************************
.
Completion time: 2015-01-18 09:27:16 - machine was rebooted
ComboFix-quarantined-files.txt 2015-01-18 05:27
.
Pre-Run: 25*211*592*704 байт свободно
Post-Run: 25*702*121*472 байт свободно
.
- - End Of File - - E16887874D38425F1E088BA2213AF478
8F558EB6672622401DA993E1E865C861
Скрыть