ComboFix 08-01-23.1C - OVB-PC 2008-01-28 19:21:07.3 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.151 [GMT 1:00]Running from: C:\Documents and Settings\OVB-PC\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\OVB-PC\Plocha\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\Temp\tn3
C:\WINDOWS\system32\drivers\bthusbb.sys
C:\WINDOWS\system32\drivers\core.cache.dsk
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\WINDOWS\system32\drivers\bthusbb.sys
C:\WINDOWS\system32\drivers\core.cache.dsk
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_BTHUSBB
-------\bthusbb
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-28 )))))))))))))))))))))))))))))))
.
2008-01-28 17:11 . 2008-01-28 17:18 <DIR> d-------- C:\Program Files\Opera 9.5 beta
2008-01-27 20:04 . 2008-01-27 20:04 147,968 --a------ C:\WINDOWS\REGEDIT.EXE
2008-01-26 21:55 . 2008-01-27 10:32 226,304 --a------ C:\WINDOWS\system32\regedit.exe
2008-01-26 21:52 . 2008-01-27 17:03 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-26 21:50 . 2008-01-26 21:50 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-26 21:43 . 2008-01-26 21:43 <DIR> d-------- C:\WINDOWS\nview
2008-01-26 21:18 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-26 18:06 . 2007-09-19 11:19 503,808 --a------ C:\WINDOWS\system32\KuGoo3DownXControl.ocx
2008-01-26 18:05 . 2008-01-26 18:06 <DIR> d----c--- C:\Downloads
2008-01-24 22:50 . 2008-01-24 22:50 <DIR> d----c--- C:\MPS
2008-01-24 22:46 . 1996-09-30 19:46 24,576 --------- C:\WINDOWS\UniFISH.exe
2008-01-24 19:46 . 2008-01-24 19:46 <DIR> d-------- C:\Program Files\Plogue
2008-01-24 19:46 . 2007-10-01 14:19 212,992 --a------ C:\WINDOWS\system\ReWire.dll
2008-01-21 20:16 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-01-21 20:15 . 2007-08-07 18:33 4,108,992 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-01-21 20:13 . 2008-01-21 20:14 <DIR> d-------- C:\Program Files\Realtek AC97
2008-01-21 20:13 . 2006-11-17 05:40 18,804,736 --a------ C:\WINDOWS\system32\alsndmgr.cpl
2008-01-21 20:13 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-01-21 20:13 . 2007-04-16 15:28 577,536 --a------ C:\WINDOWS\soundman.exe
2008-01-21 20:13 . 2006-07-31 11:19 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-01-21 20:13 . 2006-07-31 11:27 217,088 --a------ C:\WINDOWS\Alcrmv.exe
2008-01-21 20:13 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
2008-01-21 20:13 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
2008-01-21 20:04 . 2008-01-21 20:04 <DIR> d----c--- C:\Intel
2008-01-21 20:02 . 2008-01-26 15:48 <DIR> d-------- C:\Program Files\Intel
2008-01-21 20:02 . 2002-10-15 00:00 101,431 --a------ C:\WINDOWS\system32\drivers\IdeChnDr.sys
2008-01-21 20:02 . 2002-10-15 00:00 44,875 --a------ C:\WINDOWS\system32\IPrtCnst.dll
2008-01-21 20:02 . 2002-10-15 00:00 13,891 --a------ C:\WINDOWS\system32\drivers\IdeBusDr.sys
2008-01-21 19:59 . 2008-01-21 19:59 <DIR> d----c--- C:\NVIDIA
2008-01-21 00:20 . 2008-01-21 00:20 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-20 17:21 . 2008-01-20 17:26 <DIR> d-------- C:\Program Files\OneNote
2008-01-20 13:02 . 2008-01-20 13:02 <DIR> d-------- C:\Program Files\Youdagames
2008-01-20 01:23 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-01-19 21:56 . 2008-01-19 21:56 4 --a--c--- C:\timestmp.tmp
2008-01-02 14:53 . 2008-01-02 14:53 <DIR> d-------- C:\Program Files\Dnote Software
2007-12-30 12:25 . 2004-08-17 15:49 21,504 --a------ C:\WINDOWS\system32\drivers\hidserv.dll
2007-12-30 12:25 . 2007-12-30 12:25 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 16:57 --------- d-----w C:\Program Files\Opera
2008-01-26 15:17 --------- d-----w C:\Program Files\Sony Ericsson
2008-01-26 15:16 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-01-26 15:04 --------- d-----w C:\Program Files\Teamspeak2_RC22
2008-01-26 15:03 --------- d-----w C:\Program Files\Skype
2008-01-26 15:01 --------- d-----w C:\Program Files\Sjboy Emulator
2008-01-26 15:00 --------- d-----w C:\Program Files\QuickTime
2008-01-26 14:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-23 19:43 --------- d-----w C:\Program Files\AIMP2
2008-01-23 18:54 --------- d-----w C:\Program Files\SwiftSwitch
2008-01-20 09:15 --------- d-----w C:\Program Files\Roguescanfix
2008-01-13 23:14 --------- d-----w C:\Program Files\Common Files\Ahead
2008-01-12 17:13 --------- d-----w C:\Program Files\TaskSwitchXP
2008-01-05 18:37 --------- d-----w C:\Program Files\ICQ6
2008-01-03 16:19 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-03 16:05 --------- d-----w C:\Program Files\Power MP3 Cutter
2007-12-25 17:26 --------- d-----w C:\Program Files\TomTom HOME 2
2007-12-25 17:08 --------- d-----w C:\Program Files\TomTom DesktopSuite
2007-12-24 03:16 --------- d-----w C:\Program Files\SWiSH v2.0
2007-12-21 19:38 --------- d-----w C:\Program Files\eMule
2007-12-21 19:31 --------- d-----w C:\Program Files\vso
2007-12-21 19:30 --------- d-----w C:\Program Files\Aspell
2007-12-21 07:21 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2007-12-21 07:21 53,768 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-12-21 07:21 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2007-12-21 07:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 07:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-12-15 23:38 --------- d-----w C:\Program Files\THQ
2007-12-15 23:18 --------- d-----w C:\Program Files\MotoRacer3
2007-12-15 11:04 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-12-15 07:38 18,048 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2007-12-15 07:38 165,376 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2007-12-15 07:36 --------- d-----w C:\Program Files\Ligos
2007-12-15 00:21 --------- d-----w C:\Program Files\Common Files\DirectX
2007-12-15 00:11 12,400 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-22 07:38 98,304 ----a-w C:\WINDOWS\DUMPfc22.tmp
2005-12-31 10:13 960 -c--a-w C:\Program Files\Briefcase Database
2002-01-12 22:29 53,248 ----a-w C:\Program Files\mmlang.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\MPS ----
2008-01-24 23:03 5162 --a--c--- C:\MPS\TTWin95\ttdpatch.cfg
2008-01-24 23:03 1695744 --a--c--- C:\MPS\TTWin95\TTDLOADW.OVL
((((((((((((((((((((((((((((( snapshot_2008-01-27_20.26.34.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 20:20:01 458,752 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-28 18:20:10 458,752 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-26 20:20:01 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-28 18:20:10 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-26 20:20:01 458,752 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-28 18:20:10 458,752 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-26 20:20:01 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-28 18:20:10 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-26 20:20:05 16,510,976 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-28 18:20:18 16,490,496 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-26 20:20:06 331,776 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-28 18:20:18 331,776 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2004-04-10 13:26:18 6,144 ----a-w C:\WINDOWS\system32\msufmas.dll
+ 2006-05-07 03:41:41 6,144 ----a-w C:\WINDOWS\system32\msufmas.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2004-12-05 11:20 543744]
"GoldenFTPserver"="C:\Program Files\Golden FTP Server Pro\gftppro.exe" [ ]
"SpyEmergency"="C:\Program Files\Netgate\Spy Emergency 2006\SpyEmergency.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 16:09 171464]
"nDVDControl"="C:\Program Files\DNsoft.be\nDVD\nDVDControl.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2006-03-10 08:05 347695]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVG7\avgemc.exe" [2005-12-06 08:45 233524]
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe" [2004-04-29 08:00 462848]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 13:01 188416]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 15:49 110592 C:\WINDOWS\system32\bthprops.cpl]
"Cmaudio"="cmicnfg.cpl" []
"gcasServ"="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"ioloDelayModule"="C:\Program Files\iolo\System Mechanic 6\delay.exe" [ ]
"WinVNC"="C:\Program Files\RealVNC\WinVNC\winvnc.exe" [ ]
"LClock"="C:\Program Files\LClock\LClock.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-10-31 10:19 378784]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2006-04-28 07:04 77870]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfSaver3]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2004-04-28 18:47]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2004-04-28 18:48]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2004-04-29 07:51]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys []
S1 SpyEmrg;Spy Emergency Driver;C:\WINDOWS\system32\Drivers\spyemrg.sys []
S2 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" [2002-01-25 05:30]
S3 CapFilt;CapFilt;C:\WINDOWS\system32\drivers\CapFilt.sys [2006-04-13 11:25]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;C:\WINDOWS\system32\Drivers\FTD2XX.sys [2003-09-19 15:38]
S3 kvpndev;Kerio VPN adapter;C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2007-05-25 13:55]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;C:\WINDOWS\system32\DRIVERS\kwflower.sys []
S3 MemStPCI;Řadič Sony Memory Stick (PCI);C:\WINDOWS\system32\DRIVERS\MemStPCI.SYS [2004-08-03 22:00]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 22:41]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c1ee2bf-f506-11d9-8778-000a94116f82}]
\Shell\AutoRun\command - G:\welcome.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a49891d-2620-11dc-bb10-000a94116f82}]
\Shell\AutoRun\command - D:\setup.exe /autorun
\Shell\dxsetup\command - D:\directx\dxsetup.exe
\Shell\openit\command - explorer Nordic
\Shell\setup\command - D:\setup.exe /autorun
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b012cd97-6bdb-11db-bf4e-000a94116f82}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9c90f84-b2f0-11dc-bc7e-000a94116f82}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff10ac09-b5ae-11db-bfe9-000a94116f82}]
\Shell\AutoRun\command - E:\MafiaLauncher.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-28 19:35:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="C:/Documents and Settings/OVB-PC/Dokumenty/Programky/mysql-noinstall-4.0.25-win32/mysql-4.0.25-win32/bin/mysqld-nt.exe"
.
Completion time: 2008-01-28 19:39:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-28 18:39:28
ComboFix2.txt 2008-01-27 19:27:07
ComboFix3.txt 2008-01-26 20:48:27