ComboFix 07-10-07.2 - J 2007-10-10 17:49:41.4 - NTFSx86
Syst‚m Microsoft Windows XP Professional 5.1.2600.1.1250.1.1029.18.157 [GMT 2:00]
Running from: C:\Documents and Settings\J \Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\J \Plocha\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\system\NOTEPAD.exe
C:\WINDOWS\System32\salvage.exe
C:\WINDOWS\System32\spread.exe
C:\WINDOWS\System32\systemconfig32.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system\NOTEPAD.exe
C:\WINDOWS\System32\salvage.exe
C:\WINDOWS\System32\spread.exe
C:\WINDOWS\System32\systemconfig32.exe
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2007-09-10 to 2007-10-10 )))))))))))))))))))))))))))))))
.
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\system32\systems.txt
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-10-09 16:54 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-10-08 21:09 135,680 --a------ C:\WINDOWS\R.COM
2007-10-08 21:09 130,048 --a------ C:\WINDOWS\system32\T.COM
2007-10-07 20:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-07 16:33 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-07 14:58 2,358 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-07 14:57 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-07 14:57 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-07 14:57 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-07 14:57 25,088 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-06 20:28 <DIR> d-------- C:\Program Files\Hard Truck 2
2007-09-30 21:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-30 20:41 <DIR> d-------- C:\Program Files\Eltima Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-10 17:48 --------- d-------- C:\Program Files\PeerGuardian2
2007-10-10 08:37 --------- d-------- C:\Program Files\Mozilla Thunderbird
2007-10-07 14:55 1969 --a--c--- C:\WINDOWS\system32\drivers\fwdrv.err
2007-09-30 21:22 --------- d-------- C:\Program Files\Zoner
2007-09-16 20:27 --------- d-------- C:\Program Files\VV3
2007-09-07 16:26 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-05 10:17 --------- d-------- C:\Program Files\Ubisoft
2007-09-04 20:09 --------- d-------- C:\Program Files\Microsoft ActiveSync
2007-09-04 20:09 --------- d-------- C:\Program Files\EurotelSMS
2007-09-04 20:08 --------- d-------- C:\Program Files\SANDYdemo
2007-09-04 20:08 --------- d-------- C:\Program Files\Psi
2007-09-04 20:08 --------- d-------- C:\Program Files\Hexacto Games
2007-09-04 20:08 --------- d-------- C:\Program Files\Banner Maker Pro 6
2007-09-04 20:07 --------- d-------- C:\Program Files\Penezni denik
2007-09-04 20:01 --------- d-------- C:\Program Files\BlueVoda Website Builder
2007-09-04 20:00 --------- d-------- C:\Program Files\HNR Game
2007-09-04 20:00 --------- d-------- C:\Program Files\Astraware
2007-09-04 19:59 --------- d-------- C:\Program Files\Web Gallery Wizard PRO
2007-09-04 19:58 --------- d-------- C:\Program Files\JAlbum
2007-09-04 19:50 --------- d-------- C:\Program Files\OpenTTD
2007-09-04 19:48 --------- d-------- C:\Program Files\PHP Home Edition 2
2007-09-04 19:45 --------- d-------- C:\Program Files\KONAMI
2007-08-30 10:39 --------- d-------- C:\Program Files\SMS Zdarma
2007-08-29 09:43 --------- d-------- C:\Program Files\Valve
2007-08-21 12:25 --------- d-------- C:\Program Files\PC Translator
2007-08-18 20:20 --------- d-------- C:\Program Files\Trymedia
2007-08-18 20:19 --------- d-------- C:\Program Files\Gold Miner
2007-08-16 20:36 --------- d-------- C:\Program Files\Common Files\Logitech
2007-08-16 14:53 --------- d-------- C:\Program Files\infium
2007-08-12 10:32 --------- d-------- C:\Program Files\EA SPORTS
2007-08-11 20:27 --------- d-------- C:\Program Files\Ubi Soft
2007-08-11 10:57 516096 --a------ C:\WINDOWS\UN32.EXE
2007-08-11 10:50 --------- d-------- C:\Program Files\Microton 2006
2007-08-10 21:23 294912 --a------ C:\WINDOWS\TrnWord.dll
1999-06-25 10:55 149504 --a--c--- C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((( snapshot@2007-10-07_16.46.03.52 )))))))))))))))))))))))))))))))))))))))))
.
----a-r 29,696 2007-10-07 18:51:42 C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
----a-r 18,944 2007-10-07 18:51:42 C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
----a-r 65,024 2007-10-07 18:51:42 C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
----a-w 262,144 2007-10-10 15:49:11 C:\WINDOWS\system32\config\systemprofile\NtUser.dat
-c--a-w 16,384 2007-10-09 14:27:30 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
-c--a-w 32,768 2007-10-09 14:27:30 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
----a-w 32,768 2007-10-09 14:27:30 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
----a-w 262,144 2007-10-07 14:34:52 C:\WINDOWS\system32\config\systemprofile\NtUser.dat
-c--a-w 16,384 2006-10-20 16:49:10 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
-c--a-w 32,768 2006-10-20 16:49:10 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
-c--a-w 49,152 2006-10-20 16:49:10 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-06-01 17:22]
"nwiz"="nwiz.exe" [2006-10-22 13:22 C:\WINDOWS\system32\nwiz.exe]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 05:49 C:\WINDOWS\system32\tweakui.cpl]
"MSConfig"="C:\WINDOWS\System32\msconfig.exe" [2005-04-02 17:11]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 22:09]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-30 21:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-20 19:05]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"ICQ Lite"=C:\Program Files\ICQLite\ICQLite.exe -trayboot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"RunStartupScriptSync"=0 (0x0)
"SynchronousMachineGroupPolicy"=0 (0x0)
"SynchronousUserGroupPolicy"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"=0 (0x0)
"NoStrCmpLogical"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=0 (0x0)
"NoSMBalloonTip"=0 (0x0)
"NoRecentDocsHistory"=0 (0x0)
"MemCheckBoxInRunDlg"=0 (0x0)
"NoAutoTrayNotify"=0 (0x0)
"NoResolveTrack"=0 (0x0)
"NoResolveSearch"=0 (0x0)
"NoWelcomeScreen"=1 (0x1)
"NoRecentDocsNetHood"=0 (0x0)
"NoDesktopCleanupWizard"=0 (0x0)
"NoSharedDocuments"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Já^Nabídka Start^Programy^Po spuštění^Snow for Windows.lnk]
path=C:\Documents and Settings\Já\Nabídka Start\Programy\Po spuštění\Snow for Windows.lnk
backup=C:\WINDOWS\pss\Snow for Windows.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Já^Nabídka Start^Programy^Po spuštění^WinMySQLadmin.lnk]
path=C:\Documents and Settings\Já\Nabídka Start\Programy\Po spuštění\WinMysqlAdmin.lnk
backup=C:\WINDOWS\pss\WinMysqlAdmin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Já^Nabídka Start^Programy^Po spuštění^Zástupce - ServiceMan.lnk]
path=C:\Documents and Settings\Já\Nabídka Start\Programy\Po spuštění\Zástupce - ServiceMan.lnk
backup=C:\WINDOWS\pss\Zástupce - ServiceMan.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApacheMonitor.exe]
C:\Program Files\PHP Home Edition 2\Apache2\bin\ApacheMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeMixer]
C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /T
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"C:\Program Files\D-Tools\daemon.exe" -lang 1029
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Disc Detector]
C:\Program Files\Creative\ShareDLL\CtNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
"C:\Program Files\ICQLite\ICQLite.exe" -minimize
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NewsUpd]
C:\Program Files\Creative\News\NewsUpd.EXE /q
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\WINDOWS\System32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcBoost]
"C:\Program Files\PcBoost\PcBoost.exe" /start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
C:\Program Files\PeerGuardian2\pg2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerStrip]
c:\program files\powerstrip\pstrip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP2005]
C:\Program Files\qip\qip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\supervisor.exe]
C:\WINDOWS\supervisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVNEWS]
C:\Program Files\VV3\main.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WEBTRAN]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampToQIP]
"C:\Program Files\qip\WinampToQIPSA.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Apache"=2 (0x2)
"StarWindService"=2 (0x2)
"LightScribeService"=2 (0x2)
"IDriverT"=3 (0x3)
"PHPGeekUtil"=2 (0x2)
"MySql"=2 (0x2)
"Apache2"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"NOTEPAD"=2 (0x2)
"MSN RAV"=2 (0x2)
R1 fwdrv;Firewall Driver;C:\WINDOWS\System32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\System32\drivers\khips.sys
R2 PStrip;PStrip;C:\WINDOWS\System32\drivers\pstrip.sys
R3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\System32\DRIVERS\psched.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\System32\drivers\WmBEnum.sys
R3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\System32\drivers\WmFilter.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\System32\drivers\WmXlCore.sys
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys
S3 GPU-Z;GPU-Z;\??\C:\DOCUME~1\J1EA4~1\LOCALS~1\Temp\GPU-Z.sys
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\System32\drivers\WmVirHid.sys
S4 MSN RAV;MSN RAV;"C:\WINDOWS\system\msnrav.exe"
S4 NOTEPAD;NOTEPAD;"C:\WINDOWS\system\NOTEPAD.exe"
S4 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" --ntservice
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
*Newly Created Service* - PGFILTER
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-10 17:55:59
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-10 17:58:34
C:\ComboFix-quarantined-files.txt ... 2007-10-10 17:58
C:\ComboFix2.txt ... 2007-10-08 20:55
C:\ComboFix3.txt ... 2007-10-07 20:47
.
--- E O F ---