ComboFix 08-07-02.5 - User 2008-07-03 23:17:33.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.625 [GMT 2:00]
Running from: C:\Documents and Settings\User\Plocha\ComboFix.exe
* Created a new restore point
* Resident AV is active
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\User\Data aplikací\inst.exe
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.
2008-07-02 17:09 . 2008-07-02 17:09 <DIR> d-------- C:\Program Files\CCleaner
2008-06-29 17:29 . 2008-06-29 17:30 <DIR> d-------- C:\Program Files\DVDFab 5
2008-06-29 17:28 . 2008-07-03 23:02 <DIR> d-------- C:\WINDOWS\system32\acfp
2008-06-24 16:43 . 2008-06-24 16:45 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-06-17 11:49 . 2008-06-17 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\TomTom
2008-06-17 11:47 . 2008-06-20 10:51 <DIR> d-------- C:\Program Files\TomTom HOME
2008-06-17 11:47 . 2008-06-17 11:47 <DIR> d-------- C:\Documents and Settings\User\Data aplikací\InstallShield
2008-06-17 11:42 . 2008-06-17 11:42 <DIR> d-------- C:\Program Files\TomTom DesktopSuite
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-03 21:10 --------- d-----w C:\Documents and Settings\User\Data aplikací\VMware
2008-07-03 21:09 --------- d-----w C:\Documents and Settings\LocalService\Data aplikací\VMware
2008-07-03 21:09 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\VMware
2008-07-03 20:13 --------- d-----w C:\Program Files\WinClamAVShield
2008-07-03 20:13 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-07-03 20:03 --------- d-----w C:\Documents and Settings\User\Data aplikací\Spyware Terminator
2008-07-03 20:01 --------- d-----w C:\Documents and Settings\User\Data aplikací\DAEMON Tools
2008-07-03 09:00 --------- d-----w C:\Program Files\Spyware Terminator
2008-07-01 22:16 --------- d-----w C:\Documents and Settings\User\Data aplikací\Vso
2008-07-01 14:54 6,206 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-01 12:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-29 15:24 --------- d-----w C:\Documents and Settings\User\Data aplikací\uTorrent
2008-06-29 15:18 --------- d-----w C:\Program Files\ESET
2008-06-29 15:17 47,360 ----a-w C:\Documents and Settings\User\Data aplikací\pcouffin.sys
2008-05-25 20:00 --------- d-----w C:\Documents and Settings\User\Data aplikací\Talkback
2008-05-18 13:37 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-05-11 14:56 --------- d-----w C:\Program Files\Winamp
2008-04-20 21:15 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-22 10:01 22,328 ----a-w C:\Documents and Settings\User\Data aplikací\PnkBstrK.sys
2008-01-15 13:30 357 ----a-w C:\Documents and Settings\User\.cb_layout.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-29 14:05 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-07-12 11:58 356352]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-01-20 09:09 200704]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-17 19:08 949376]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 18:17 159744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"vmware-tray"="C:\Program Files\VMware\VMware Workstation\vmware-tray.exe" [2007-10-08 10:27 72240]
"VMware hqtray"="C:\Program Files\VMware\VMware Workstation\hqtray.exe" [2007-10-08 10:26 55856]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"SpywareTerminator"="C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe" [2008-05-18 15:37 1817600]
"SkyTel"="SkyTel.EXE" [2006-05-16 19:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 18:21 16270848 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 03:48:00 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 02:01:00 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"H:\\Program files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"H:\\Program files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\acfp\\acFP.exe"=
"H:\\Program files\\Midway Home Entertainment\\BlackSite Area 51\\Binaries\\BlackSite.exe"=
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-02-20 14:34]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-02-20 14:34]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-05-18 15:37]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 18:39]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2006-03-13 19:34]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2006-03-13 19:34]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2006-03-13 19:34]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2006-03-13 19:34]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2006-03-13 19:34]
S3 kvpndev;Kerio VPN adapter;C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2007-05-25 15:55]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;C:\WINDOWS\system32\DRIVERS\kwflower.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{718c4ed2-3c4a-11dd-8f16-005056c00008}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
*Newly Created Service* - CATCHME
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-acfp - c:\WINDOWS\system32\acfp\as.exe
HKCU-Run-OEXPRESS - (no file)
HKLM-Run-NWEReboot - (no file)
ShellExecuteHooks-{D62A2513-0A8B-44F8-8479-3AFFAFC5FF82} - C:\WINDOWS\system32\wvUliHYs.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-03 23:22:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-03 23:23:32
ComboFix-quarantined-files.txt 2008-07-03 21:23:27
Adresářů: 12, Volných bajtů: 19,785,437,184
Adresářů: 14, Volných bajtů: 19,898,175,488
129