Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bltuitqy
*******************
Script file located at: \??\C:\WINDOWS\cenzura!.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\g653910.exe deleted successfully.
File C:\WINDOWS\g533747.exe deleted successfully.
File C:\WINDOWS\g3490278.exe deleted successfully.
File C:\WINDOWS\g2943642.exe deleted successfully.
File C:\WINDOWS\g1741383.exe deleted successfully.
File C:\WINDOWS\g563189.exe deleted successfully.
File C:\WINDOWS\g1461701.exe deleted successfully.
File C:\WINDOWS\g1708096.exe deleted successfully.
File C:\WINDOWS\system32\wudb.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
[ Dodano: Dzisiaj o 14:24 ] - Kod: Zaznacz wszystko
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bltuitqy
*******************
Script file located at: \??\C:\WINDOWS\cenzura!.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\g653910.exe deleted successfully.
File C:\WINDOWS\g533747.exe deleted successfully.
File C:\WINDOWS\g3490278.exe deleted successfully.
File C:\WINDOWS\g2943642.exe deleted successfully.
File C:\WINDOWS\g1741383.exe deleted successfully.
File C:\WINDOWS\g563189.exe deleted successfully.
File C:\WINDOWS\g1461701.exe deleted successfully.
File C:\WINDOWS\g1708096.exe deleted successfully.
File C:\WINDOWS\system32\wudb.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
- Kod: Zaznacz wszystko
"admin" - 2007-05-23 14:59:38 Dodatek Service Pack 2
ComboFix 07-05.21.6.V - Running from: "C:\Documents and Settings\admin\Pulpit\"
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-23 ))))))))))))))))))))))))))))))))))
2007-05-22 21:46 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-22 16:36 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\DivX
2007-05-22 16:32 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-05-22 16:32 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-05-22 16:32 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-05-22 16:32 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-05-22 16:32 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-05-22 16:00 <DIR> d-------- C:\WINDOWS\CSC
2007-05-22 15:24 <DIR> d-------- C:\Program Files\Audio WAV To MP3 Converter
2007-05-22 07:34 <DIR> d-------- C:\Program Files\BitDownload
2007-05-22 07:28 1 --a------ C:\WINDOWS\kimamiss.dat
2007-05-22 07:27 <DIR> d-------- C:\Program Files\AML Products
2007-05-22 01:02 <DIR> d-------- C:\Temp
2007-05-22 00:55 <DIR> d-------- C:\Program Files\Xilisoft
2007-05-22 00:51 987,136 --a------ C:\WINDOWS\system32\agsaamh.dll
2007-05-22 00:51 90,112 --a------ C:\WINDOWS\system32\agsaami.dll
2007-05-22 00:51 610,304 --a------ C:\WINDOWS\system32\agsaamg.dll
2007-05-22 00:51 53,760 --a------ C:\WINDOWS\system\ppacklib.dll
2007-05-22 00:51 46 --a------ C:\WINDOWS\system32\kakle.dll
2007-05-22 00:51 44 --a------ C:\WINDOWS\system32\winitn.dll
2007-05-22 00:51 372,736 --a------ C:\WINDOWS\system32\agsaamc.dll
2007-05-22 00:51 331,776 --a------ C:\WINDOWS\system32\agsaama.dll
2007-05-22 00:51 2,535,424 --a------ C:\WINDOWS\system32\agsaamj.dll
2007-05-22 00:51 196,608 --a------ C:\WINDOWS\system32\maag.dll
2007-05-22 00:51 1,986,560 --a------ C:\WINDOWS\system32\akll.dll
2007-05-22 00:51 1,245,184 --a------ C:\WINDOWS\system32\bkll.dll
2007-05-22 00:51 1,212,416 --a------ C:\WINDOWS\system32\ckll.dll
2007-05-22 00:50 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2007-05-22 00:50 <DIR> d-------- C:\WINDOWS\system32\RMBin
2007-05-22 00:50 <DIR> d-------- C:\Program Files\Akram
2007-05-21 22:49 <DIR> d-------- C:\Program Files\MixVibes6
2007-05-21 22:14 86,016 --a------ C:\WINDOWS\unvise32.exe
2007-05-21 22:14 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\Simple Star
2007-05-21 22:13 <DIR> d-------- C:\Program Files\Simple Star
2007-05-21 21:57 665,424 --a------ C:\WINDOWS\system32\wmv8dmoe.dll
2007-05-21 21:57 572,752 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2007-05-21 21:57 438,608 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2007-05-21 21:57 1,683,792 --a------ C:\WINDOWS\system32\wmvcore2.dll
2007-05-21 21:57 <DIR> d-------- C:\Program Files\Sonic Foundry
2007-05-21 21:54 <DIR> d-------- C:\Program Files\Sonic Foundry Setup
2007-05-21 21:46 <DIR> d-------- C:\Program Files\ARWizard3
2007-05-21 16:58 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\Gadu-Gadu
2007-05-21 14:45 <DIR> d-------- C:\Program Files\eMule
2007-05-19 15:35 <DIR> d-------- C:\Program Files\Sony Ericsson
2007-05-19 15:35 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2007-05-19 15:14 <DIR> d-------- C:\Program Files\VS Online
2007-05-18 16:15 <DIR> d-------- C:\Program Files\GG Skin Manager
2007-05-17 07:12 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-05-16 17:55 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2007-05-16 17:55 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2007-05-16 17:55 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2007-05-16 17:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Sony
2007-05-16 15:44 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\Sony
2007-05-16 15:44 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\Publish Providers
2007-05-16 15:42 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-05-16 15:29 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\BSplayer Pro
2007-05-16 15:29 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\BSplayer
2007-05-16 15:28 <DIR> d-------- C:\Program Files\Webteh
2007-05-16 15:21 934,576 --a------ C:\WINDOWS\system32\ltr13n.dll
2007-05-16 15:21 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2007-05-16 15:21 80,896 --a------ C:\WINDOWS\system32\lfwmf13s.dll
2007-05-16 15:21 79,360 --a------ C:\WINDOWS\system32\lfeps13s.dll
2007-05-16 15:21 74,752 --a------ C:\WINDOWS\system32\lfgif13s.dll
2007-05-16 15:21 73,728 --a------ C:\WINDOWS\system32\MMAviAx.dll
2007-05-16 15:21 70,144 --a------ C:\WINDOWS\system32\lfbmp13s.dll
2007-05-16 15:21 65,536 --a------ C:\WINDOWS\system32\lfpcx13s.dll
2007-05-16 15:21 64,000 --a------ C:\WINDOWS\system32\lftga13s.dll
2007-05-16 15:21 59,904 --a------ C:\WINDOWS\system32\lfpcd13s.dll
2007-05-16 15:21 466,624 --a------ C:\WINDOWS\system32\LTRPR13n.DLL
2007-05-16 15:21 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2007-05-16 15:21 401,408 --a------ C:\WINDOWS\system32\pvmjpg30.dll
2007-05-16 15:21 393,728 --a------ C:\WINDOWS\system32\LFCMP13s.DLL
2007-05-16 15:21 32,768 --a------ C:\WINDOWS\system32\MLPagAx.dll
2007-05-16 15:21 304,816 --a------ C:\WINDOWS\system32\LTRIO13N.DLL
2007-05-16 15:21 283,136 --a------ C:\WINDOWS\system32\LFJ2K13s.dll
2007-05-16 15:21 204,881 --a------ C:\WINDOWS\system32\DiskIO.dll
2007-05-16 15:21 194,248 --a------ C:\WINDOWS\system32\LTRFD13n.DLL
2007-05-16 15:21 185,856 --a------ C:\WINDOWS\system32\lfpng13s.dll
2007-05-16 15:21 166,400 --a------ C:\WINDOWS\system32\lftif13s.dll
2007-05-16 15:21 155,721 --a------ C:\WINDOWS\system32\RALMain.dll
2007-05-16 15:21 116,224 --a------ C:\WINDOWS\system32\lffax13s.dll
2007-05-16 15:21 114,759 --a------ C:\WINDOWS\system32\Aviprax.dll
2007-05-16 15:21 110,080 --a------ C:\WINDOWS\system32\lfpsd13s.dll
2007-05-16 15:21 104,960 --a------ C:\WINDOWS\system32\lfpct13s.dll
2007-05-16 15:21 1,772,032 --a------ C:\WINDOWS\system32\LTCLR13s.dll
2007-05-16 15:18 <DIR> d-------- C:\Program Files\SmartSound Software
2007-05-16 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\SmartSound Software Inc
2007-05-16 15:17 84,992 --a------ C:\WINDOWS\system32\ATL70.DLL
2007-05-16 15:17 57,856 --a------ C:\WINDOWS\system32\masd32.dll
2007-05-16 15:17 27,648 --a------ C:\WINDOWS\system32\ma32.dll
2007-05-16 15:17 196,096 --a------ C:\WINDOWS\system32\macd32.dll
2007-05-16 15:17 138,752 --a------ C:\WINDOWS\system32\mase32.dll
2007-05-16 15:17 136,192 --a------ C:\WINDOWS\system32\mamc32.dll
2007-05-16 15:16 964,608 --a------ C:\WINDOWS\system32\MFC70U.DLL
2007-05-16 15:16 65,536 --a------ C:\WINDOWS\system32\MFC71DEU.DLL
2007-05-16 15:16 61,440 --a------ C:\WINDOWS\system32\MFC71ITA.DLL
2007-05-16 15:16 61,440 --a------ C:\WINDOWS\system32\MFC71FRA.DLL
2007-05-16 15:16 61,440 --a------ C:\WINDOWS\system32\MFC71ESP.DLL
2007-05-16 15:16 57,344 --a------ C:\WINDOWS\system32\MFC71ENU.DLL
2007-05-16 15:16 54,784 --a------ C:\WINDOWS\system32\MSVCI70.DLL
2007-05-16 15:16 49,152 --a------ C:\WINDOWS\system32\PCLEGetGuid.dll
2007-05-16 15:16 49,152 --a------ C:\WINDOWS\system32\MFC71KOR.DLL
2007-05-16 15:16 49,152 --a------ C:\WINDOWS\system32\MFC71JPN.DLL
2007-05-16 15:16 45,056 --a------ C:\WINDOWS\system32\MFC71CHT.DLL
2007-05-16 15:16 40,960 --a------ C:\WINDOWS\system32\MFC71CHS.DLL
2007-05-16 15:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Pinnacle Studio
2007-05-16 15:13 14,165 --a------ C:\WINDOWS\system32\drivers\Pclepci.sys
2007-05-16 15:13 <DIR> d-------- C:\Program Files\Pinnacle
2007-05-16 15:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Pinnacle
2007-05-15 20:44 <DIR> d-------- C:\Program Files\SmartShopper
2007-05-15 20:44 <DIR> d-------- C:\Program Files\Share_Accelerator_MM
2007-05-15 20:44 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\SmartShopper
2007-05-15 20:43 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-05-15 20:43 <DIR> d-------- C:\Program Files\Zapu
2007-05-15 17:17 <DIR> d-------- C:\Program Files\Vstplugins
2007-05-15 17:16 <DIR> d-------- C:\Program Files\Sony
2007-05-15 17:05 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-05-15 16:52 <DIR> d-------- C:\DOCUME~1\admin\DANEAP~1\Sony Setup
2007-05-15 16:50 <DIR> d-------- C:\Program Files\Sony Setup
2007-05-11 19:54 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-05-11 06:37 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-05-11 06:37 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-05-11 06:37 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-05-11 06:37 740,442 --a------ C:\WINDOWS\system32\DivX.dll
2007-04-23 02:15 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 02:15 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-04-23 02:15 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-04-23 02:02 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-04-23 02:02 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 02:02 57,344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-04-23 02:02 53,248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 02:02 344,064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-04-23 02:02 294,912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-04-23 02:02 294,912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-04-23 02:02 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-04-23 02:01 124,472 --a------ C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-23 02:01 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-23 12:53:03 40 ----a-w C:\WINDOWS\system32\profile.dat
2007-05-22 16:35:27 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-05-22 14:32:26 -------- d-----w C:\Program Files\DivX
2007-05-21 13:12:25 -------- d-----w C:\Program Files\Gadu-Gadu
2007-05-19 13:34:59 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-16 15:56:06 74,982 ----a-w C:\WINDOWS\system32\perfc015.dat
2007-05-16 15:56:06 454,152 ----a-w C:\WINDOWS\system32\perfh015.dat
2007-05-16 13:17:27 95 ----a-w C:\AUTOEXEC.BAT
2007-04-23 00:15:25 36,624 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-04-20 19:43:58 -------- d-----w C:\DOCUME~1\admin\DANEAP~1\Skype
2007-03-24 14:50:30 -------- d-----w C:\DOCUME~1\admin\DANEAP~1\AdobeUM
2007-03-21 12:36:33 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-03-21 11:49:12 -------- d-----w C:\Program Files\Hewlett-Packard
2007-03-21 11:48:17 -------- d--h--w C:\Program Files\Zenographics
2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:38:47 579,072 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:38:47 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:38:47 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:37:33 1,843,840 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-05 20:19:48 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{2BA1C226-EC1B-4471-A65F-D0688AC6EE3A}=C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll [2006-12-31 13:42]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 02:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 14:02]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-03-17 07:34]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-01-11 20:07]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 13:18]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-11 00:26]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-05-10 16:36]
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-23 15:03:31
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-23 15:05:58
C:\ComboFix-quarantined-files.txt ... 2007-05-23 15:05
C:\ComboFix2.txt ... 2007-05-22 21:46
--- E O F ---