ComboFix 07-08-17.2 - "U§ivatel" 2007-08-20 13:48:52.1 - NTFSx86
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.639 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\_000003_.tmp.dll
C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))
2007-08-20 13:48 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-20 00:28 <DIR> d-------- C:\Program Files\Atomic Clock Sync
2007-08-19 11:56 <DIR> d-------- C:\Program Files\MSTpscre
2007-08-19 11:56 <DIR> d-------- C:\Program Files\FlashGet
2007-08-19 01:16 <DIR> d-------- C:\DOCUME~1\UIVATE~1\Incomplete
2007-08-19 01:16 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\LimeWire
2007-08-19 01:13 <DIR> d-------- C:\Program Files\LimeWire
2007-08-15 18:14 <DIR> d-------- C:\Program Files\Krteźek 1.9 beta 7
2007-08-15 18:10 <DIR> d-------- C:\Program Files\EurotelSMS
2007-08-15 18:00 <DIR> d-------- C:\Program Files\DreamCom SE
2007-08-15 10:31 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-08-14 23:14 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\SmartFTP
2007-08-13 00:30 <DIR> d-------- C:\DOCUME~1\UIVATE~1\Phone Browser
2007-08-12 16:51 86,016 -ra------ C:\WINDOWS\system32\CNMCP6e.exe
2007-08-12 16:51 7,680 --a------ C:\WINDOWS\system32\CNMVS6e.DLL
2007-08-12 16:51 116,736 --a------ C:\WINDOWS\system32\CNMLM6e.DLL
2007-08-12 16:51 <DIR> d--h----- C:\BJPrinter
2007-08-12 16:50 <DIR> d-------- C:\ip1000xp180en
2007-08-11 14:37 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2007-08-11 14:36 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\Nokia
2007-08-11 14:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DATAAP~1\PC Suite
2007-08-11 14:35 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2007-08-11 14:35 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-11 14:35 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2007-08-11 14:35 <DIR> d-------- C:\Program Files\Nokia
2007-08-11 14:35 <DIR> d-------- C:\Program Files\DIFX
2007-08-11 14:35 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2007-08-11 14:35 <DIR> d-------- C:\Program Files\Common Files\Nokia
2007-08-11 14:35 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\PC Suite
2007-08-11 14:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DATAAP~1\Installations
2007-08-08 19:27 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2007-08-08 19:27 59,648 --a------ C:\WINDOWS\system32\drivers\rfcomm.sys
2007-08-08 19:27 274,304 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2007-08-08 19:27 26,624 --a------ C:\WINDOWS\system32\irmon.dll
2007-08-08 19:27 18,944 --a------ C:\WINDOWS\system32\drivers\BTHUSB.SYS
2007-08-08 19:27 17,024 --a------ C:\WINDOWS\system32\drivers\BthEnum.sys
2007-08-08 19:27 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2007-08-08 19:27 100,992 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2007-08-08 19:07 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2007-08-08 19:07 69,632 --a------ C:\WINDOWS\system32\xmltok.dll
2007-08-08 19:07 36,864 --a------ C:\WINDOWS\system32\xmlparse.dll
2007-08-08 19:07 26,096 --a------ C:\WINDOWS\system32\xmlinst.exe
2007-08-08 19:07 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-08-08 19:07 <DIR> d-------- C:\Program Files\Ubisoft
2007-08-08 19:01 <DIR> d-------- C:\WINDOWS\Cache
2007-08-08 13:08 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2007-08-08 13:08 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\Thunderbird
2007-08-08 11:06 <DIR> d-------- C:\Program Files\DVDFab Platinum 3
2007-08-08 11:05 87,608 --a------ C:\DOCUME~1\UIVATE~1\DATAAP~1\inst.exe
2007-08-08 11:04 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-08-08 11:04 47,360 --a------ C:\DOCUME~1\UIVATE~1\DATAAP~1\pcouffin.sys
2007-08-08 11:04 <DIR> d-------- C:\Program Files\DVDFab Gold 3
2007-08-08 11:04 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\Vso
2007-08-08 11:03 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\WinRAR
2007-08-08 10:59 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\ESTsoft
2007-08-08 10:58 <DIR> d-------- C:\Program Files\ESTsoft
2007-08-08 10:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DATAAP~1\ESTsoft
2007-08-08 10:46 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-08-08 00:35 <DIR> d-------- C:\qipinfium9000
2007-08-08 00:25 <DIR> d-------- C:\DOCUME~1\UIVATE~1\DATAAP~1\Silver Style Entertainment
2007-08-08 00:19 <DIR> d-------- C:\Program Files\QIP
2007-08-08 00:13 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-08-08 00:07 86,016 --a------ C:\WINDOWS\system32\OpenAL32.dll
2007-08-08 00:07 413,696 --a------ C:\WINDOWS\system32\wrap_oal.dll
2007-08-08 00:07 <DIR> d-------- C:\Program Files\OpenAL
2007-08-08 00:06 <DIR> d-------- C:\Program Files\WMV9_VCM
2007-08-07 23:55 58,240 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-08-07 23:55 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-08-07 23:55 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-08-07 23:55 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-08-07 23:54 75,264 --a------ C:\WINDOWS\system32\usbui.dll
2007-08-07 23:54 32,768 --a------ C:\WINDOWS\system32\drivers\sisnic.sys
2007-08-07 23:53 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-08-07 23:53 9,291 --a------ C:\WINDOWS\system\VER.DLL
2007-08-07 23:53 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-08-07 23:53 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-08-07 23:53 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-08-07 23:53 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-08-07 23:53 75,264 --a------ C:\WINDOWS\system32\storprop.dll
2007-08-07 23:53 70,272 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-08-07 23:53 69,632 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-08-07 23:53 69,008 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-08-07 23:53 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\kbdpl.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll
2007-08-07 23:53 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-08-07 23:53 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-08-07 23:53 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-08-07 23:53 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-08-07 23:53 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-14 14:13 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-08-14 14:12 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-08-08 19:08 11973 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-06-27 04:27 44240 --a------ C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-06-27 03:59 344064 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
2007-06-27 03:58 269312 --a------ C:\WINDOWS\system32\ati2dvag.dll
2007-06-27 03:58 2303488 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-06-27 03:56 307200 --a------ C:\WINDOWS\system32\atiiiexx.dll
2007-06-27 03:51 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2007-06-27 03:51 143360 --a------ C:\WINDOWS\system32\atipdlxx.dll
2007-06-27 03:51 122880 --a------ C:\WINDOWS\system32\Oemdspif.dll
2007-06-27 03:50 43520 --a------ C:\WINDOWS\system32\ati2edxx.dll
2007-06-27 03:50 118784 --a------ C:\WINDOWS\system32\ati2evxx.dll
2007-06-27 03:49 483328 --a------ C:\WINDOWS\system32\ati2evxx.exe
2007-06-27 03:48 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2007-06-27 03:44 8232960 --a------ C:\WINDOWS\system32\atioglx2.dll
2007-06-27 03:41 2940992 --a------ C:\WINDOWS\system32\ati3duag.dll
2007-06-27 03:31 1519744 --a------ C:\WINDOWS\system32\ativvaxx.dll
2007-06-27 03:19 5435392 --a------ C:\WINDOWS\system32\atioglxx.dll
2007-06-27 03:17 266240 --a------ C:\WINDOWS\system32\atikvmag.dll
2007-06-27 03:16 17408 --a------ C:\WINDOWS\system32\atitvo32.dll
2007-06-27 03:15 49152 --a------ C:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-27 03:14 176128 --a------ C:\WINDOWS\system32\atiok3x2.dll
2007-06-27 03:10 376832 --a------ C:\WINDOWS\system32\ati2cqag.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 15:23 1033728 --a------ C:\WINDOWS\explorer.exe
2007-06-08 08:11 831048 --a------ C:\WINDOWS\system32\WudfUpdate_01005.dll
--------- C:\Program Files\Krteček 1.9 beta 7
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-10-27 08:49 C:\WINDOWS\SOUNDMAN.EXE]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-08-07 22:52]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 15:49 C:\WINDOWS\system32\bthprops.cpl]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Tpscrex"="C:\Program Files\MSTpscre\Tpscrex.exe" [2007-08-19 11:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
R0 SiSRaid;SiSRaid;C:\WINDOWS\system32\DRIVERS\SiSRaid.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys
S3 FXDRV;FXDRV;\??\F:\Fxdrv.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-20 13:51:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-20 13:52:06 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-20 13:52
--- E O F ---