HijackThis raporum

Darknes$

Rektör
Emektar
Müdavim
Katılım
13 Haziran 2008
Mesajlar
17,955
Reaksiyon puanı
351
Puanları
3,263
HijackThis raporum

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:09, on 11.2.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Oturum Açma Yardım Aracı - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: HP Kırpma Defteri - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Akıllı Seçim - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Araştır - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1223114775234
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira Premium Security Suite Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
O23 - Service: Avira Premium Security Suite Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Avira Premium Security Suite MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe

--
End of file - 4565 bytes

----*-*-*-*-**-**-*-**-*-*--**-**-*-*-*-*-*-*-*-*-*-*-*-*-*-*----

Combofix raporum

ComboFix 08-11-01.04 - Darknes$ 2008-11-02 11:11:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1254.1.1055.18.163 [GMT 2:00]
Running from: C:\Documents and Settings\Darknes$\Desktop\Download\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-10-02 to 2008-11-02 )))))))))))))))))))))))))))))))
.

2008-11-02 11:08 . 2008-11-02 11:08 <DIR> d-------- C:\Program Files\Trend Micro
2008-11-01 23:09 . 2008-11-01 23:09 <DIR> d-------- C:\Documents and Settings\Darknes$\Application Data\Avira
2008-11-01 23:00 . 2008-11-01 23:00 <DIR> d-------- C:\Program Files\Avira
2008-11-01 23:00 . 2008-11-01 23:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-11-01 23:00 . 2008-05-07 14:20 71,592 --a------ C:\WINDOWS\system32\drivers\avfwot.sys
2008-11-01 23:00 . 2008-05-07 10:51 71,464 --a------ C:\WINDOWS\system32\drivers\avfwim.sys
2008-11-01 22:33 . 2008-11-01 22:33 <DIR> d-------- C:\Program Files\Lavasoft
2008-11-01 22:33 . 2008-11-01 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-11-01 22:32 . 2008-11-01 22:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-01 11:10 . 2008-11-01 11:10 <DIR> d-------- C:\Documents and Settings\Darknes$\Application Data\GRETECH
2008-11-01 11:09 . 2008-11-01 11:09 <DIR> d-------- C:\Program Files\GRETECH
2008-11-01 11:09 . 2008-11-01 11:09 <DIR> d-------- C:\Program Files\CCleaner
2008-10-25 19:15 . 2004-08-03 22:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2008-10-25 19:15 . 2004-08-03 22:10 19,328 --a--c--- C:\WINDOWS\system32\dllcache\wstcodec.sys
2008-10-25 19:15 . 2004-08-03 23:45 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-10-25 19:15 . 2004-08-03 23:45 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-10-25 19:15 . 2004-08-03 22:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-10-25 19:15 . 2004-08-03 22:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-10-25 19:15 . 2004-08-03 22:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-10-25 19:15 . 2004-08-03 22:10 11,136 --a--c--- C:\WINDOWS\system32\dllcache\slip.sys
2008-10-25 19:15 . 2004-08-03 22:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-10-25 19:15 . 2004-08-03 22:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-10-25 19:15 . 2004-08-03 21:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-10-25 19:15 . 2004-08-03 21:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-10-23 17:17 . 2008-10-23 17:20 <DIR> d-------- C:\Program Files\Counter-Strike 1.6
2008-10-21 15:35 . 2008-10-21 15:35 <DIR> d-------- C:\Program Files\Smart Projects
2008-10-19 19:02 . 2008-10-19 19:02 <DIR> d-------- C:\Documents and Settings\Darknes$\WINDOWS
2008-10-19 19:02 . 1997-11-19 14:49 303,616 --a------ C:\WINDOWS\IsUninst.exe
2008-10-19 09:17 . 2008-10-19 09:41 133 --a------ C:\WINDOWS\system32\temp_0000_85-19.aok
2008-10-18 20:34 . 2008-10-19 09:38 134 --a------ C:\WINDOWS\system32\test.aok
2008-10-16 17:30 . 2008-11-01 21:27 <DIR> d-------- C:\Documents and Settings\Darknes$\Application Data\Hamachi
2008-10-16 17:29 . 2008-10-16 17:30 <DIR> d-------- C:\Program Files\Hamachi
2008-10-16 17:29 . 2008-10-16 17:29 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-10-16 16:40 . 2008-10-16 16:45 982 --a------ C:\WINDOWS\eReg.dat
2008-10-16 16:37 . 2008-10-16 16:42 <DIR> d-------- C:\Program Files\EA Games
2008-10-16 15:51 . 2008-10-16 17:44 32 --a------ C:\WINDOWS\CD_Start.INI
2008-10-13 21:54 . 2008-10-13 21:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-10-13 21:54 . 2007-03-29 01:29 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-10-13 21:54 . 2007-03-28 13:01 118,272 --a------ C:\WINDOWS\system32\hpz3l5ha.dll
2008-10-13 21:54 . 2007-03-06 14:20 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-10-13 21:54 . 2007-03-06 14:20 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-10-13 21:53 . 2007-03-15 16:39 958,464 -ra------ C:\WINDOWS\system32\hpotiop4.dll
2008-10-13 21:53 . 2007-03-15 16:39 675,840 -ra------ C:\WINDOWS\system32\hpowiax4.dll
2008-10-13 21:53 . 2007-03-06 14:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-10-13 21:53 . 2007-03-06 14:20 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-10-13 21:53 . 2007-03-15 16:39 303,104 -ra------ C:\WINDOWS\system32\hpovst11.dll
2008-10-13 21:53 . 2007-03-06 14:20 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-10-13 21:53 . 2004-08-03 21:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-13 21:53 . 2004-08-03 21:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-13 19:16 . 2008-10-13 19:16 <DIR> d-------- C:\Program Files\PDF to Word
2008-10-13 19:16 . 2008-11-01 12:55 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-12 17:10 . 2008-10-12 17:10 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-10-12 17:10 . 2008-10-12 17:10 <DIR> d-------- C:\Documents and Settings\Darknes$\Application Data\AdobeUM
2008-10-09 19:42 . 2007-04-18 18:14 2,854,400 --a------ C:\WINDOWS\system32\SET19A.tmp
2008-10-08 19:45 . 2008-10-08 19:46 <DIR> d-------- C:\Program Files\Ultra Mobile 3GP Video Converter
2008-10-08 19:45 . 2004-01-11 07:02 258,048 --a------ C:\WINDOWS\system32\GplMpgDec.ax
2008-10-08 19:45 . 2007-04-12 13:19 129,024 --a------ C:\WINDOWS\system32\AVERM.dll
2008-10-08 19:45 . 2006-09-26 12:57 28,672 --a------ C:\WINDOWS\system32\AVEQT.dll
2008-10-06 17:41 . 2008-10-06 17:41 0 --a------ C:\WINDOWS\Infob.dat
2008-10-06 17:41 . 2008-10-06 17:41 0 --a------ C:\WINDOWS\Infoa.dat
2008-10-05 15:10 . 2008-10-06 17:41 <DIR> d-------- C:\Program Files\Total Video Converter
2008-10-05 15:10 . 2000-05-22 21:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-10-04 20:04 . 2008-10-04 20:36 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-04 19:56 . 2008-10-04 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-10-04 19:53 . 2008-10-10 18:37 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-10-04 19:39 . 2008-07-18 21:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-10-04 19:39 . 2008-07-18 21:07 210,976 --a------ C:\WINDOWS\system32\muweb.dll
2008-10-04 19:39 . 2008-07-18 21:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-10-04 13:32 . 2008-10-08 20:53 <DIR> d-------- C:\Documents and Settings\Darknes$\Application Data\HPAppData
2008-10-04 13:11 . 2008-10-04 13:11 <DIR> d-------- C:\Documents and Settings\Darknes$\Application Data\ATI
2008-10-04 12:25 . 2008-10-28 20:54 <DIR> d-------- C:\Documents and Settings\Darknes$\Contacts
2008-10-04 12:05 . 2008-10-04 12:05 <DIR> d---s---- C:\Documents and Settings\Darknes$\UserData
2008-10-04 12:03 . 2008-10-04 12:04 <DIR> dr------- C:\Documents and Settings\Darknes$\Sık Kullanılanlar
2008-10-04 12:03 . 2008-11-01 18:55 <DIR> dr------- C:\Documents and Settings\Darknes$\Belgelerim
2008-10-04 12:01 . 2008-10-04 14:42 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Sık Kullanılanlar
2008-10-04 12:01 . 2008-10-04 14:42 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Belgelerim

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 09:12 --------- d-----w C:\Program Files\Opera
2008-10-25 17:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-25 17:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-04 11:32 --------- d-----w C:\Program Files\HP
2008-10-04 11:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-10-04 11:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-10-04 11:30 --------- d-----w C:\Program Files\Common Files\HP
2008-10-04 11:30 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-10-04 11:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-10-04 11:17 --------- d-----w C:\Program Files\Microsoft.NET
2008-10-04 11:08 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-10-04 11:08 --------- d-----w C:\Program Files\Realtek AC97
2008-10-04 11:08 --------- d-----w C:\Program Files\AvRack
2008-10-04 11:05 --------- d-----w C:\Program Files\ATI Technologies
2008-10-04 10:25 --------- d-----w C:\Program Files\Windows Live
2008-10-04 10:22 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-04 10:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-04 10:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-10-04 09:58 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-15 15:39 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-08-20 05:37 658,944 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:44 2,138,112 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:44 2,017,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [2008-06-12 266497]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programlar^Başlangıç^Catalyst System Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programlar\Başlangıç\Catalyst System Tray.lnk
backup=C:\WINDOWS\pss\Catalyst System Tray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 2005-08-12 12:43 45056 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-r------- 2005-10-24 08:45 90112 C:\WINDOWS\soundman.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Program Files\\Counter-Strike 1.6\\hl.exe"=

R1 avfwot;avfwot;C:\WINDOWS\system32\DRIVERS\avfwot.sys [2008-05-07 71592]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe [2008-05-16 344321]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [2008-07-11 164097]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [2008-06-12 258305]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [2008-05-09 41217]
R3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys [2008-05-07 71464]
S3 FXDRV;FXDRV;E:\Fxdrv.sys [ ]
S3 leafnets;Leaf Networks Adapter;C:\WINDOWS\system32\DRIVERS\leafnets.sys [2007-05-03 55296]
S3 WPRO_40_1123;WinPcap Packet Driver (WPRO_40_1123);C:\WINDOWS\system32\drivers\WPRO_40_1123.sys [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.tr/
O8 -: Microsoft Excel'e Gö&nder - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-02 11:12:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-02 11:14:21
ComboFix-quarantined-files.txt 2008-11-02 09:14:03
ComboFix2.txt 2008-11-02 09:05:10

Pre-Run: 29,906,714,624 bayt boş
Post-Run: 29,896,646,656 bayt boş

174 --- E O F --- 2008-10-25 20:25:55


İnceleyip nereleri fix lemeylimim rapoarlı bir incelermisiniz?
 
Üst