ComboFix 08-02.05.3 - Owner 2008-02-08 18:42:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.642 [GMT 1:00]
Running from: C:\Documents and Settings\Owner\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 16:30 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Logitech
2008-02-08 16:30 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Logitech
2008-02-08 16:30 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Logitech
2008-02-08 16:29 --------- d-----w C:\Program Files\Creative
2008-02-08 16:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-08 16:27 --------- d-----w C:\Program Files\Realtek AC97
2008-02-08 16:21 --------- d-----w C:\Program Files\Logitech
2008-02-08 16:21 --------- d-----w C:\Program Files\CyberLink
2008-02-08 16:21 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Logitech
2008-02-08 16:19 --------- d-----w C:\Program Files\Common Files\Logitech
2008-02-08 16:16 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ATI
2008-02-08 16:16 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ATI
2008-02-08 16:16 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ATI
2008-02-08 16:13 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-08 16:13 --------- d-----w C:\Program Files\ATI Technologies
2008-02-08 16:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-08 16:05 --------- d--h--w C:\Documents and Settings\All Users\Data aplikací\CanonBJ
2008-02-08 15:58 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ScanSoft
2008-02-08 15:58 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ScanSoft
2008-02-08 15:58 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ScanSoft
2008-02-08 15:58 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\SSScanWizard
2008-02-08 15:58 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\SSScanAppDataDir
2008-02-08 15:57 --------- d-----w C:\Program Files\ScanSoft
2008-02-08 15:57 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-02-08 15:56 --------- d-----w C:\Program Files\ArcSoft
2008-02-08 15:55 --------- d-----w C:\Program Files\Canon
2008-02-08 15:51 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Lavasoft
2008-02-08 15:51 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Lavasoft
2008-02-08 15:51 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Lavasoft
2008-02-08 15:49 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ESET
2008-02-08 15:49 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ESET
2008-02-08 15:49 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ESET
2008-02-08 15:47 --------- d-----w C:\Program Files\ESET
2008-02-08 15:47 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ESET
2008-02-08 15:25 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-21 07:21 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2007-12-21 07:21 53,768 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-12-21 07:21 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2007-12-21 07:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 07:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 13:00 15360]
"eMuleAutoStart"="D:\Program Files\eMule\emule.exe" [2007-05-13 15:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 11:00 49152]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-06 01:07 61440]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-06-08 12:31 29696 C:\WINDOWS\KHALMNPR.Exe]
"SoundMan"="SOUNDMAN.EXE" [2005-07-22 08:00 81920 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 13:00 15360]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Hlavnˇ panel ATI CATALYST.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-06 01:07:30 61440]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\KEM.exe [2008-02-08 17:19:37 581632]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-18 13:00]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 23:08]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-18 13:00]
R3 usbscan;Ovladač skeneru USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys [2005-04-21 12:02]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14de4b8d-d65d-11dc-b98a-806d6172696f}]
\Shell\AutoRun\command - E:\Setup.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-08 18:43:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\Program Files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2008-02-08 18:43:41