ComboFix 07-11-08.3 - David Sojka 2007-11-14 20:37:32.5 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.454 [GMT 1:00]
Running from: C:\Documents and Settings\David Sojka\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\David Sojka\Plocha\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\ahrwpbnp.dll
C:\WINDOWS\system32\axvpfjut.exe
C:\WINDOWS\system32\byxwwvt.dll
C:\WINDOWS\system32\cntmfpfe.dll
C:\WINDOWS\system32\Down(1).exe
C:\WINDOWS\system32\gfkympml.exe
C:\WINDOWS\system32\hjnghmqh.exe
C:\WINDOWS\system32\iooudepe.dll
C:\WINDOWS\system32\jtvupcqm.exe
C:\WINDOWS\system32\kgogfyau.dll
C:\WINDOWS\system32\krumxqwa.dll
C:\WINDOWS\system32\meymjpby.exe
C:\WINDOWS\system32\mmlptxmm.dll
C:\WINDOWS\system32\ndbptevm.exe
C:\WINDOWS\system32\onystadi.dll
C:\WINDOWS\system32\oswwnyyn.dll
C:\WINDOWS\system32\phpdmtqe.dll
C:\WINDOWS\system32\qmkdlmst.dll
C:\WINDOWS\system32\wbflnily.dll
C:\WINDOWS\system32\yvxvbfpj.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Nabídka Start\Live Safety Center.lnk
C:\Documents and Settings\All Users\Nabídka Start\Online Security Guide.lnk
C:\Documents and Settings\David Sojka\Oblíbené položky\Online Security Guide.lnk
C:\Documents and Settings\David Sojka\Plocha\Live Safety Center.lnk
C:\Documents and Settings\David Sojka\Plocha\Online Security Guide.lnk
C:\WINDOWS\system32\ahrwpbnp.dll
C:\WINDOWS\system32\axvpfjut.exe
C:\WINDOWS\system32\byxwwvt.dll
C:\WINDOWS\system32\cntmfpfe.dll
C:\WINDOWS\system32\Down(1).exe
C:\WINDOWS\system32\ffhkj.ini
C:\WINDOWS\system32\ffhkj.ini2
C:\WINDOWS\system32\gfkympml.exe
C:\WINDOWS\system32\hjnghmqh.exe
C:\WINDOWS\system32\iooudepe.dll
C:\WINDOWS\system32\jkhff.dll
C:\WINDOWS\system32\jtvupcqm.exe
C:\WINDOWS\system32\kgogfyau.dll
C:\WINDOWS\system32\krumxqwa.dll
C:\WINDOWS\system32\meymjpby.exe
C:\WINDOWS\system32\mmlptxmm.dll
C:\WINDOWS\system32\ndbptevm.exe
C:\WINDOWS\system32\onystadi.dll
C:\WINDOWS\system32\onystadi.dllbox
C:\WINDOWS\system32\oswwnyyn.dll
C:\WINDOWS\system32\phpdmtqe.dll
C:\WINDOWS\system32\qmkdlmst.dll
C:\WINDOWS\system32\wbflnily.dll
C:\WINDOWS\system32\yvxvbfpj.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_WINDOWSREMOTE
-------\WindowsRemote
((((((((((((((((((((((((( Files Created from 2007-10-14 to 2007-11-14 )))))))))))))))))))))))))))))))
.
2007-11-13 19:27 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-12 22:34 3,282 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-12 21:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 21:36 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-07 21:52 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-11-06 21:14 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-06 20:20 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-11-06 20:20 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-06 17:18 145,984 --------- C:\WINDOWS\system32\onystadi.dll
2007-11-04 18:22 <DIR> d-------- C:\Program Files\Lighthouse Interactive
2007-10-31 19:34 <DIR> d-------- C:\Program Files\ABBYY FineReader 6.0 Sprint
2007-10-31 19:30 76,800 --a------ C:\WINDOWS\system32\E_FLBCDE.DLL
2007-10-31 19:30 62,976 --a------ C:\WINDOWS\system32\E_FD4BCDE.DLL
2007-10-31 19:30 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-10-31 19:30 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-10-31 19:28 <DIR> d-------- C:\Program Files\epson
2007-10-31 19:28 67,072 --a------ C:\WINDOWS\system32\escwiad.dll
2007-10-27 19:57 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-10-27 19:57 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-10-27 19:57 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-10-14 17:12 30,812 --a------ C:\WINDOWS\system32\temp_13.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 17:03 --------- d-----w C:\Program Files\ICQToolbar
2007-11-14 16:53 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-04 17:14 --------- d-----w C:\Program Files\Winamp
2007-11-04 06:59 --------- d-----w C:\Program Files\Common Files\Nero
2007-11-04 06:57 --------- d-----w C:\Program Files\Nero
2007-11-04 06:51 --------- d-----w C:\Program Files\Ahead
2007-11-03 14:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-01 05:09 --------- d-----w C:\Program Files\Orbitdownloader
2007-10-27 18:55 --------- d-----w C:\Program Files\Electronic Arts
2007-10-18 18:13 --------- d-----w C:\Program Files\Java
2007-10-14 06:42 --------- d-----w C:\Program Files\betway
2007-10-10 18:14 --------- d-----w C:\Program Files\Disc2Phone
2007-10-10 17:51 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2007-10-10 17:51 --------- d-----w C:\Program Files\Common Files\Sony Ericsson Shared
2007-10-10 17:50 --------- d-----w C:\Program Files\Sony Ericsson
2007-09-24 08:05 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys
2007-09-24 08:05 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys
2007-09-20 08:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-09-20 08:55 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-09-20 08:55 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-08-21 19:12 3,009 ----a-w C:\naver.vbs
.
((((((((((((((((((((((((((((( snapshot@2007-11-12_21.56.00.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-14 19:42:48 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_630.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-14 20:41 145984 --------- C:\WINDOWS\system32\onystadi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\onystadi.dll [2007-11-14 20:41 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 16:12]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 11:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 16:34]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 19:15]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 00:06]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []
"EPSON Stylus DX7400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.exe" [2007-04-12 07:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\onystadi]
onystadi.dll 2007-11-14 20:41 145984 C:\WINDOWS\system32\onystadi.dll
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 SE2Bbus;Sony Ericsson Device 043 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Bbus.sys
S3 SE2Bmdfl;Sony Ericsson Device 043 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Bmdfl.sys
S3 SE2Bmdm;Sony Ericsson Device 043 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Bmdm.sys
S3 SE2Bmgmt;Sony Ericsson Device 043 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Bmgmt.sys
S3 se2Bnd5;Sony Ericsson Device 043 USB Ethernet Emulation SEMC43 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Bnd5.sys
S3 SE2Bobex;Sony Ericsson Device 043 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Bobex.sys
S3 se2Bunic;Sony Ericsson Device 043 USB Ethernet Emulation SEMC43 (WDM);C:\WINDOWS\system32\DRIVERS\se2Bunic.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-08-22 10:51:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-14 20:45:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 20:46:32 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-14 18:00
C:\ComboFix3.txt ... 2007-11-12 22:05
.
--- E O F ---