SmitFraudFix v2.274 Scan done at 21:24:08,07, 2007-12-22 Run from C:\Documents and Settings\wojtek\Pulpit\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Wersja 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !Attention, following keys are not inevitably infected! SrchSTS.exe by S!Ri Search SharedTaskScheduler’s .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri’s WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files »»»»»»»»»»»»»»»»»»»»»»»» IEDFix IEDFix.exe by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip…{FA3483E2-5A2A-4F4B-9AB0-9DC3560B78E3}: DhcpNameServer=88.156.65.12 88.156.65.10 88.156.63.9 HKLM\SYSTEM\CS1\Services\Tcpip…{FA3483E2-5A2A-4F4B-9AB0-9DC3560B78E3}: DhcpNameServer=88.156.65.12 88.156.65.10 88.156.63.9 HKLM\SYSTEM\CS2\Services\Tcpip…{FA3483E2-5A2A-4F4B-9AB0-9DC3560B78E3}: DhcpNameServer=88.156.65.12 88.156.65.10 88.156.63.9 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=88.156.65.12 88.156.65.10 88.156.63.9 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=88.156.65.12 88.156.65.10 88.156.63.9 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=88.156.65.12 88.156.65.10 88.156.63.9 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !Attention, following keys are not inevitably infected! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] “System”="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !Attention, following keys are not inevitably infected! SrchSTS.exe by S!Ri Search SharedTaskScheduler’s .dll »»»»»»»»»»»»»»»»»»»»»»»» End i Combo ComboFix 07-12-21.4 - wojtek 2007-12-22 21:16:53.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.573 [GMT 1:00] Running from: C:\Documents and Settings\wojtek\Pulpit\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 ))))))))))))))))))))))))))))))) . 2007-12-22 19:56 . 2007-12-22 19:56 2007-12-22 19:28 . 2007-12-22 19:28 2007-12-22 19:27 . 2007-07-25 14:24 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-12-22 19:27 . 2006-09-24 16:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm 2007-12-22 19:27 . 2007-03-10 12:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-12-22 19:27 . 2004-01-25 17:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-12-22 19:27 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll 2007-12-22 19:27 . 2007-09-21 01:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm 2007-12-22 19:27 . 2007-10-03 16:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml 2007-12-22 19:26 . 2007-12-22 19:26 2007-12-22 19:26 . 2007-09-28 17:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-12-22 19:26 . 2007-09-28 17:05 81,920 --a------ C:\WINDOWS\system32\dpl100.dll 2007-12-22 19:26 . 2007-07-29 16:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-12-22 19:26 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest 2007-12-21 20:36 . 2007-12-21 20:36 2007-12-21 17:31 . 2007-12-21 17:31 2007-12-20 17:47 . 2007-12-21 16:23 2007-12-20 17:36 . 2007-12-21 16:26 2007-12-20 17:33 . 2007-12-20 17:33 2007-12-20 14:34 . 2007-12-22 19:28 49 --a------ C:\WINDOWS\NeroDigital.ini 2007-12-20 06:39 . 2007-12-21 20:36 2007-12-20 06:39 . 2007-12-21 20:12 2007-12-20 06:38 . 2007-12-21 21:36 2007-12-20 06:38 . 2007-12-20 06:38 2007-12-20 06:38 . 2007-12-20 06:38 774,144 --a------ C:\Program Files\RngInterstitial.dll 2007-12-19 21:18 . 2007-12-19 21:18 2007-12-19 17:37 . 2007-12-19 17:37 2007-12-19 17:37 . 2007-12-19 17:37 917,504 --a------ C:\WINDOWS\system32\FLASH.OCX 2007-12-19 17:06 . 2007-12-19 17:06 2007-12-19 17:05 . 2007-12-19 17:05 2007-12-19 17:05 . 2000-06-23 14:05 136,704 --a------ C:\WINDOWS\system32\iacenc.dll 2007-12-19 17:05 . 2000-06-22 13:09 56,320 --------- C:\WINDOWS\system32\iyvu9_32.dll 2007-12-19 17:04 . 2007-12-19 17:04 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-12-19 17:02 . 2007-12-19 17:02 2007-12-19 17:02 . 2007-12-19 17:02 2007-12-19 17:02 . 2001-07-06 13:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll 2007-12-19 17:02 . 2001-07-06 11:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll 2007-12-19 17:02 . 2001-07-06 17:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll 2007-12-19 17:02 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-12-19 17:02 . 2003-12-19 19:48 89,184 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys 2007-12-19 17:02 . 2003-12-23 15:40 57,344 --a------ C:\WINDOWS\system32\ImageDrive.cpl 2007-12-19 17:02 . 2001-06-26 07:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll 2007-12-19 15:15 . 2007-12-19 15:16 2007-12-19 08:44 . 2007-12-20 06:36 2007-12-19 06:37 . 2007-12-19 06:37 2007-12-19 06:36 . 2006-11-24 14:47 40,136 --a------ C:\WINDOWS\system32\drivers\ET5Drv.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-22 18:56 --------- d-----w C:\Program Files\XnView 2007-12-19 05:36 --------- d-----w C:\Program Files\Google 2007-12-18 16:50 --------- d-----w C:\Program Files\Windows Media Bonus Pack for Windows XP 2007-12-18 16:47 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-12-18 16:47 --------- d-----w C:\Program Files\ToniArts 2007-12-18 16:45 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Rainlendar 2007-12-18 16:42 --------- d-----w C:\Program Files\Winamp 2007-12-18 16:34 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Lavasoft 2007-12-18 16:28 --------- d-----w C:\Program Files\Gigabyte 2007-12-18 16:27 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-12-18 16:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\InstallShield 2007-12-18 16:24 --------- d-----w C:\Program Files\Realtek 2007-12-18 16:23 4,716 ----a-w C:\WINDOWS\gdrv.sys 2007-12-18 16:23 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\InstallShield 2007-12-18 16:12 --------- d-----w C:\Program Files\Intel 2007-12-18 16:08 --------- d-----w C:\Program Files\Symantec 2007-12-18 16:08 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-12-18 16:08 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec 2007-12-18 16:07 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Symantec 2007-12-18 15:56 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Microsoft Web Folders 2007-12-18 15:55 --------- d-----w C:\Program Files\microsoft frontpage 2007-12-18 15:41 --------- d-----w C:\Program Files\Usługi online 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-10-29 22:44 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-22 02:49 867,848 ----a-w C:\Program Files\NOV2007_d3dx10_36_x64.cab 2007-10-22 02:49 807,132 ----a-w C:\Program Files\NOV2007_d3dx10_36_x86.cab 2007-10-22 02:49 49,392 ----a-w C:\Program Files\NOV2007_X3DAudio_x64.cab 2007-10-22 02:49 44,850 ----a-w C:\Program Files\dxdllreg_x86.cab 2007-10-22 02:49 21,744 ----a-w C:\Program Files\NOV2007_X3DAudio_x86.cab 2007-10-22 02:49 200,010 ----a-w C:\Program Files\NOV2007_XACT_x64.cab 2007-10-22 02:49 151,512 ----a-w C:\Program Files\NOV2007_XACT_x86.cab 2007-10-22 02:49 1,805,306 ----a-w C:\Program Files\NOV2007_d3dx9_36_x64.cab 2007-10-22 02:49 1,712,608 ----a-w C:\Program Files\NOV2007_d3dx9_36_x86.cab 2007-10-22 02:31 976,020 ------w C:\Program Files\BDAXP.cab 2007-10-22 02:31 917,318 ------w C:\Program Files\Apr2006_MDX1_x86.cab 2007-10-22 02:31 88,102 ------w C:\Program Files\AUG2006_xinput_x64.cab 2007-10-22 02:31 87,989 ------w C:\Program Files\Apr2006_xinput_x64.cab 2007-10-22 02:31 86,925 ------w C:\Program Files\Oct2005_xinput_x64.cab 2007-10-22 02:31 86,802 ----a-w C:\Program Files\dxupdate.cab 2007-10-22 02:31 855,886 ------w C:\Program Files\AUG2007_d3dx10_35_x64.cab 2007-10-22 02:31 800,467 ------w C:\Program Files\AUG2007_d3dx10_35_x86.cab 2007-10-22 02:31 76,808 ----a-w C:\Program Files\DSETUP.dll 2007-10-22 02:31 76,808 ----a-w C:\DSETUP.dll 2007-10-22 02:31 702,644 ------w C:\Program Files\JUN2007_d3dx10_34_x64.cab 2007-10-22 02:31 702,212 ------w C:\Program Files\APR2007_d3dx10_33_x64.cab 2007-10-22 02:31 702,072 ------w C:\Program Files\JUN2007_d3dx10_34_x86.cab 2007-10-22 02:31 699,465 ------w C:\Program Files\APR2007_d3dx10_33_x86.cab 2007-10-22 02:31 56,902 ------w C:\Program Files\APR2007_xinput_x86.cab 2007-10-22 02:31 502,792 ----a-w C:\Program Files\DXSETUP.exe 2007-10-22 02:31 502,792 ----a-w C:\DXSETUP.exe 2007-10-22 02:31 47,018 ------w C:\Program Files\AUG2006_xinput_x86.cab 2007-10-22 02:31 46,898 ------w C:\Program Files\Apr2006_xinput_x86.cab 2007-10-22 02:31 46,247 ------w C:\Program Files\Oct2005_xinput_x86.cab 2007-10-22 02:31 4,163,518 ------w C:\Program Files\Apr2006_MDX1_x86_Archive.cab 2007-10-22 02:31 213,767 ------w C:\Program Files\DEC2006_d3dx10_00_x64.cab 2007-10-22 02:31 201,696 ------w C:\Program Files\AUG2007_XACT_x64.cab 2007-10-22 02:31 200,722 ------w C:\Program Files\JUN2007_XACT_x64.cab 2007-10-22 02:31 199,366 ------w C:\Program Files\APR2007_XACT_x64.cab 2007-10-22 02:31 198,275 ------w C:\Program Files\FEB2007_XACT_x64.cab 2007-10-22 02:31 193,435 ------w C:\Program Files\DEC2006_XACT_x64.cab 2007-10-22 02:31 192,680 ------w C:\Program Files\DEC2006_d3dx10_00_x86.cab 2007-10-22 02:31 183,863 ------w C:\Program Files\AUG2006_XACT_x64.cab 2007-10-22 02:31 183,321 ------w C:\Program Files\OCT2006_XACT_x64.cab 2007-10-22 02:31 181,745 ------w C:\Program Files\JUN2006_XACT_x64.cab 2007-10-22 02:31 180,021 ------w C:\Program Files\Apr2006_XACT_x64.cab 2007-10-22 02:31 179,247 ------w C:\Program Files\Feb2006_XACT_x64.cab 2007-10-22 02:31 156,612 ------w C:\Program Files\AUG2007_XACT_x86.cab 2007-10-22 02:31 156,509 ------w C:\Program Files\JUN2007_XACT_x86.cab 2007-10-22 02:31 154,825 ------w C:\Program Files\APR2007_XACT_x86.cab 2007-10-22 02:31 151,583 ------w C:\Program Files\FEB2007_XACT_x86.cab 2007-10-22 02:31 146,559 ------w C:\Program Files\DEC2006_XACT_x86.cab 2007-10-22 02:31 138,977 ------w C:\Program Files\OCT2006_XACT_x86.cab 2007-10-22 02:31 138,195 ------w C:\Program Files\AUG2006_XACT_x86.cab 2007-10-22 02:31 134,631 ------w C:\Program Files\JUN2006_XACT_x86.cab 2007-10-22 02:31 133,991 ------w C:\Program Files\Apr2006_XACT_x86.cab 2007-10-22 02:31 133,297 ------w C:\Program Files\Feb2006_XACT_x86.cab 2007-10-22 02:31 13,265,040 ------w C:\Program Files\dxnt.cab 2007-10-22 02:31 100,417 ------w C:\Program Files\APR2007_xinput_x64.cab 2007-10-22 02:31 1,803,760 ------w C:\Program Files\AUG2007_d3dx9_35_x64.cab 2007-10-22 02:31 1,711,752 ------w C:\Program Files\AUG2007_d3dx9_35_x86.cab 2007-10-22 02:31 1,673,224 ----a-w C:\Program Files\dsetup32.dll 2007-10-22 02:31 1,673,224 ----a-w C:\dsetup32.dll 2007-10-22 02:31 1,611,374 ------w C:\Program Files\JUN2007_d3dx9_34_x64.cab 2007-10-22 02:31 1,610,958 ------w C:\Program Files\APR2007_d3dx9_33_x64.cab 2007-10-22 02:31 1,610,886 ------w C:\Program Files\JUN2007_d3dx9_34_x86.cab 2007-10-22 02:31 1,609,639 ------w C:\Program Files\APR2007_d3dx9_33_x86.cab 2007-10-22 02:31 1,575,336 ------w C:\Program Files\DEC2006_d3dx9_32_x86.cab 2007-10-22 02:31 1,572,114 ------w C:\Program Files\DEC2006_d3dx9_32_x64.cab 2007-10-22 02:31 1,413,862 ------w C:\Program Files\OCT2006_d3dx9_31_x64.cab 2007-10-22 02:31 1,398,718 ------w C:\Program Files\Apr2006_d3dx9_30_x64.cab 2007-10-22 02:31 1,363,684 ------w C:\Program Files\Feb2006_d3dx9_29_x64.cab 2007-10-22 02:31 1,358,864 ------w C:\Program Files\Dec2005_d3dx9_28_x64.cab 2007-10-22 02:31 1,351,430 ------w C:\Program Files\Aug2005_d3dx9_27_x64.cab 2007-10-22 02:31 1,348,242 ------w C:\Program Files\Apr2005_d3dx9_25_x64.cab 2007-10-22 02:31 1,336,890 ------w C:\Program Files\Jun2005_d3dx9_26_x64.cab 2007-10-22 02:31 1,248,387 ------w C:\Program Files\Feb2005_d3dx9_24_x64.cab 2007-10-22 02:31 1,156,363 ------w C:\Program Files\BDANT.cab 2007-10-22 02:31 1,128,177 ------w C:\Program Files\OCT2006_d3dx9_31_x86.cab 2007-10-22 02:31 1,116,109 ------w C:\Program Files\Apr2006_d3dx9_30_x86.cab 2007-10-22 02:31 1,085,608 ------w C:\Program Files\Feb2006_d3dx9_29_x86.cab . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:44] “Gadu-Gadu”=“D:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 08:39] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2003-08-28 09:09] “igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” [2005-11-28 06:55] “igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” [2005-11-28 06:52] “igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” [2005-11-28 06:55] “SkyTel”=“SkyTel.EXE” [2006-05-16 11:04 C:\WINDOWS\SkyTel.exe] “RTHDCPL”=“RTHDCPL.EXE” [2006-11-14 10:21 C:\WINDOWS\RTHDCPL.exe] “EasyTuneV”=“C:\Program Files\Gigabyte\ET5\ETcall.exe” [2006-12-15 14:13] “Media Codec Update Service”=“d:\Program Files\Essentials Codec Pack\update.exe” [] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-03 23:44] C:\Documents and Settings\wojtek\Menu Start\Programy\Autostart\ Rainlendar.lnk - D:\Program Files\Rainlendar\Rainlendar.exe [2004-03-20 21:49:15] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56] R3 MarkFun_NT;MarkFun_NT;C:\Program Files\Gigabyte\ET5\markfun.w32 [2006-11-21 20:20] S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-12-18 17:23] *Newly Created Service* - CATCHME *Newly Created Service* - MARKFUN_NT *Newly Created Service* - PROCEXP90 . Contents of the ‘Scheduled Tasks’ folder “2007-12-21 19:02:16 C:\WINDOWS\Tasks\Norton AntiVirus - Skanuj komputer.job” - D:\PROGRA~1\NORTON~1\Navw32.exef/task: “2007-12-22 20:08:39 C:\WINDOWS\Tasks\Symantec NetDetect.job” - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-22 21:17:59 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-22 21:18:22 . 2007-12-20 16:58:36 — E O F — A i jeszcze pytanie: przy odpalaniu Sdfix-a w okienku wyboru opcji było napisane coś takiego: joedanger is Not involved with Smithfraudfix in any way? U mnie takiego czegoś nie było.