Thank you for your reply!
Firstly, there was some improvements after the initial malwarebytes and combofix scans. I was allowed to
browse my usb-flash drive, which I was unable to before. There still exists m.exe though...
Sorry, didn't notice that my logs were in finnish... Will try to choose the language with more thought next time!
By the way, when trying to upgrade to SP3 via windows update, it goes all way to 98% or so, and then fails. All security patches are updated fine. Maybe it has something to do with this?
Here is the combofix log after CFScript:
ComboFix 09-01-21.04 - KerDaNauer 2009-01-29 8:53:53.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.2046.1653 [GMT 2:00]
Sijainti: c:\documents and settings\KerDaNauer\Työpöytä\FIX\ComboFix.exe
Käytetyt komentorivivalitsimet :: c:\documents and settings\KerDaNauer\Työpöytä\FIX\CFScript.txt
FW: ZoneAlarm Firewall *enabled*
* Uusi palautuspiste luotu
FILE ::
C:\tmp___
c:\windows\system32\ddbaecafdf.dll
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\tmp___
c:\windows\system32\ddbaecafdf.dll
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-12-28 to 2009-01-29 )))))))))))))))))
.
2009-01-28 10:45 . 2009-01-28 10:45 <KANSIO> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-28 10:45 . 2009-01-28 10:45 <KANSIO> d-------- c:\documents and settings\KerDaNauer\Application Data\Malwarebytes
2009-01-28 10:45 . 2009-01-28 10:45 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-28 10:45 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-28 10:45 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-28 10:36 . 2009-01-28 10:44 <KANSIO> d-------- c:\program files\CCleaner
2009-01-27 20:18 . 2009-01-27 20:22 <KANSIO> d-------- c:\program files\Windows Live Safety Center
2009-01-27 19:52 . 2009-01-27 20:04 <KANSIO> d-------- c:\program files\EsetOnlineScanner
2009-01-27 19:27 . 2009-01-27 19:27 <KANSIO> d-------- C:\fsaua.data
2009-01-24 17:53 . 2009-01-24 17:53 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-24 17:53 . 2009-01-24 17:53 1,409 --a------ c:\windows\QTFont.for
2009-01-24 11:28 . 2009-01-24 11:42 5,115,511 --a------ C:\kauhea2.jpg
2009-01-24 11:27 . 2009-01-24 11:39 5,298,318 --a------ C:\kauhea.jpg
2009-01-22 16:47 . 2003-12-31 10:20 94,208 --a------ c:\windows\system32\DS232.dll
2009-01-06 01:20 . 2009-01-06 01:20 768 --a------ c:\windows\system32\d3d8caps.dat
2009-01-02 19:57 . 2009-01-02 19:57 410,984 --a------ c:\windows\system32\deploytk.dll
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 06:58 25,194,528 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-29 06:58 --------- d-----w c:\documents and settings\KerDaNauer\Application Data\OpenOffice.org2
2009-01-29 06:56 304,556 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-28 21:39 --------- d-----w c:\program files\trend micro
2009-01-28 18:23 --------- d-----w c:\program files\DVBViewer
2009-01-28 08:41 --------- d-----w c:\program files\MPEG-AVI 2 GIF 1
2009-01-28 08:40 --------- d-----w c:\program files\ASMT
2009-01-27 17:39 --------- d-----w c:\program files\mIRC
2009-01-24 10:46 --------- d-----w c:\documents and settings\KerDaNauer\Application Data\gtk-2.0
2009-01-18 11:14 --------- d-----w c:\program files\schism
2009-01-15 21:03 --------- d-----w c:\program files\FlashFXP
2009-01-10 01:10 --------- d-----w c:\documents and settings\KerDaNauer\Application Data\Audacity
2009-01-02 18:44 --------- d-----w c:\program files\Winamp
2009-01-02 17:57 --------- d-----w c:\program files\Java
2008-12-12 01:02 32,768 ----a-w c:\windows\system32\drivers\ati2psxx.sys
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-07 10:04 --------- d-----w c:\program files\Sonic Foundry
2008-12-07 07:58 119,808 ----a-w C:\VundoFix.exe
2008-12-06 16:28 170 ----a-w C:\ComboFix.txt.bat
2008-12-06 12:06 --------- d-----w c:\program files\Common Files\Adobe Systems Shared
2008-12-06 12:06 --------- d-----w c:\program files\Common Files\Adobe
2008-12-06 11:19 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-06 11:18 --------- d-----w c:\program files\Lavasoft
2008-12-06 11:18 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-09-15 15360]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-04 165784]
"JulaPan"="JulaPan.Exe" [2005-07-05 c:\windows\system32\JulaPan.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-02 136600]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 102400]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Matrox PowerDesk SE"="c:\program files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe" [2008-09-19 3907328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-09-15 15360]
c:\documents and settings\KerDaNauer\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-03-16 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XVID"= xvid.dll
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"msacm.imc"= imc32.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2psxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2007-03-22 46080]
R3 JULA_01;Service for Juli@ 1;c:\windows\system32\drivers\JulaWdm.sys [2007-03-22 22880]
R3 JULA_AA;Service for Juli@ Audio Driver (EWDM);c:\windows\system32\drivers\Jula.sys [2007-03-22 29472]
R4 Matrox Centering Service;Matrox Centering Service;c:\program files\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe [2008-09-19 1262336]
R4 Matrox.Pdesk.ServicesHost;Matrox.Pdesk.ServicesHost;c:\program files\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe [2008-09-19 343296]
R4 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\Smith Micro\StuffIt11\ArcNameService.exe [2007-07-18 157000]
S0 ati2psxx;ati2psxx;c:\windows\system32\drivers\ati2psxx.sys [2008-12-06 32768]
S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2004-08-11 77312]
S3 papycpu;papycpu;c:\windows\system32\drivers\papycpu.sys [2007-06-08 1888]
S3 UtilNT;UtilNT;c:\windows\system32\drivers\utilnt.sys [2008-10-21 5533]
S4 cdenable;cdenable;c:\windows\system32\Drivers\cdenable.sys --> c:\windows\system32\Drivers\cdenable.sys [?]
.
.
------- Täydentävä tarkistus -------
.
uStart Page = hxxp://www.dnainternet.fi/
FF - ProfilePath - c:\documents and settings\KerDaNauer\Application Data\Mozilla\Firefox\Profiles\zpi1g8iq.default\
FF - prefs.js: browser.search.selectedEngine - Ilmainen Sanakirja
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
https://www.gmer.net
Rootkit scan 2009-01-29 08:57:47
Windows 5.1.2600 Service Pack 2 NTFS
tarkistaa piilotettuja prosesseja ...
tarkistaa piilotettuja käynnistysarvoja ...
tarkistaa piilotettuja tiedostoja ...
c:\windows\system32\
0f16ccc987a73d99c3cab8d86438d296.sys 36864 bytes executable
c:\windows\system32\_0f16ccc987a73d99c3cab8d86438d296.sys_.vir 36864 bytes executable
tarkistus on valmis
piilotetut tiedostot: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\
0f16ccc987a73d99c3cab8d86438d296]
"ImagePath"="system32\
0f16ccc987a73d99c3cab8d86438d296.sys"
.
--------------------- LUKITUT REKISTERIAVAIMET ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\cfexefile\DefaultIcon]
@DACL=(02 0000)
@SACL=
@="%1"
[HKEY_LOCAL_MACHINE\software\Classes\cfexefile\shell]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Classes\cfexefile\shellex]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ów*]
"b049C053C7D38EE4AB9A00CB3B5D2472"="C?\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\PUBPLACE.HTT"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ów*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
------------------------ Muut prosessit ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\windows\system32\mgabg.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Valmistumisajankohta: 2009-01-29 9:00:51 - kone käynnistettiin uudelleen
ComboFix-quarantined-files.txt 2009-01-29 07:00:48
ComboFix2.txt 2009-01-28 13:29:56
ComboFix3.txt 2008-12-07 08:23:31
Ennen ajoa: 3 131 543 552 tavua vapaana
Ajon jälkeen: 3,111,370,752 tavua vapaana
178 --- E O F --- 2009-01-14 07:35:35