ComboFix 08-01-04.1 - kulik 2008-01-06 16:03:45.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1430 [GMT 1:00]
Running from: D:\DownloadS\FireFoX\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\rlvknlg.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.
2008-01-06 16:03 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-06 13:53 . 2008-01-06 13:53 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-06 13:53 . 2008-01-06 13:57 <DIR> d-------- C:\Program Files\OneStepSearch
2008-01-06 13:53 . 2007-07-13 21:33 266,240 --a------ C:\WINDOWS\system32\rkupginstaller.exe
2008-01-05 19:30 . 2008-01-05 19:30 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-05 13:31 . 2008-01-05 13:31 <DIR> d-------- C:\Documents and Settings\kulik\Data aplikací\Locktime
2008-01-05 13:31 . 2008-01-05 13:31 <DIR> d-------- C:\Documents and Settings\kulik\Data aplikací\Locktime
2008-01-05 13:31 . 2008-01-05 13:31 <DIR> d-------- C:\Documents and Settings\kulik\Data aplikací\Locktime
2008-01-05 13:29 . 2008-01-05 13:29 <DIR> d-------- C:\Program Files\NetLimiter 2 Pro
2008-01-05 13:29 . 2008-01-05 13:29 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Locktime
2008-01-05 12:12 . 2008-01-05 12:12 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-04 18:45 . 2008-01-04 18:45 <DIR> d-------- C:\Program Files\PowerQuest
2008-01-04 16:19 . 2008-01-05 11:48 <DIR> d-------- C:\Program Files\DiskInternals
2008-01-02 16:20 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-12-29 19:58 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2007-12-29 19:58 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2007-12-29 19:52 . 2007-12-29 19:52 <DIR> d-------- C:\Program Files\Codemasters
2007-12-28 20:48 . 2008-01-06 14:31 <DIR> d---s---- C:\Program Files\HLSW
2007-12-28 20:23 . 2007-12-28 20:23 <DIR> d-------- C:\Program Files\THQ
2007-12-28 20:16 . 2007-12-28 20:16 1,158 --a------ C:\WINDOWS\mozver.dat
2007-12-28 16:10 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-12-28 16:10 . 2008-01-06 14:31 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-28 16:10 . 2007-12-28 16:10 22,328 --a------ C:\Documents and Settings\kulik\Data aplikací\PnkBstrK.sys
2007-12-28 16:10 . 2007-12-28 16:10 22,328 --a------ C:\Documents and Settings\kulik\Data aplikací\PnkBstrK.sys
2007-12-28 16:10 . 2007-12-28 16:10 22,328 --a------ C:\Documents and Settings\kulik\Data aplikací\PnkBstrK.sys
2007-12-28 16:09 . 2007-12-28 16:09 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-28 16:09 . 2008-01-06 14:31 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-12-28 16:09 . 2007-12-28 20:42 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-12-28 16:09 . 2007-12-28 16:09 319 --a------ C:\WINDOWS\game.ini
2007-12-28 16:00 . 2007-12-28 16:00 <DIR> d-------- C:\Program Files\Activision
2007-12-28 15:52 . 2007-12-28 15:52 <DIR> d--hs---- C:\WINDOWS\ftpcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 22:54 --------- d-----w C:\Program Files\Warcraft III
2008-01-04 17:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-04 17:43 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-30 13:18 --------- d---a-w C:\Program Files\Miranda IM
2007-12-28 14:52 --------- d-----w C:\Program Files\WC3Banlist
2007-12-28 13:33 --------- d-----w C:\Program Files\Winamp Remote
2007-12-28 13:33 --------- d-----w C:\Program Files\Winamp
2007-12-28 13:33 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\Winamp
2007-12-28 13:33 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\Winamp
2007-12-28 13:33 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\Winamp
2007-12-28 13:33 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\OrbNetworks
2007-12-28 13:26 --------- d-----w C:\Program Files\RivaTuner v2.06
2007-12-28 13:22 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2007-12-28 13:13 --------- d-----w C:\Program Files\WinPcap
2007-12-28 13:11 --------- d-----w C:\Program Files\Ventrilo
2007-12-28 13:11 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-28 13:10 --------- d-----w C:\Program Files\Webteh
2007-12-28 13:10 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-28 13:10 --------- d-----w C:\Program Files\Combined Community Codec Pack
2007-12-28 13:08 --------- d-----w C:\Program Files\Razer Pro Solutions
2007-12-28 13:08 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\InstallShield
2007-12-28 13:08 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\InstallShield
2007-12-28 13:08 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\InstallShield
2007-12-28 13:07 --------- d-----w C:\Program Files\DAEMON Tools Lite
2007-12-28 13:05 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\DAEMON Tools
2007-12-28 13:05 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\DAEMON Tools
2007-12-28 13:05 --------- d-----w C:\Documents and Settings\kulik\Data aplikací\DAEMON Tools
2007-12-28 13:03 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-28 13:03 --------- d-----w C:\Program Files\AMD
2007-12-28 13:02 --------- d-----w C:\Program Files\ATI Technologies
2007-12-28 13:00 --------- d-----w C:\Program Files\Realtek
2007-12-28 12:58 --------- d-----w C:\Program Files\DIFX
2007-12-28 12:43 558,142 ----a-w C:\WINDOWS\java\Packages\XV7NF53B.ZIP
2007-12-28 12:43 155,995 ----a-w C:\WINDOWS\java\Packages\LB9FX7NV.ZIP
2007-12-28 12:43 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-05 13:17 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-12-05 05:26 2,782,208 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-12-05 03:05 368,640 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:54 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-12-05 02:53 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:16 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-12-05 02:14 180,224 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2007-12-18 02:02 471040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 04:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 11:06 77824]
"razer"="C:\Program Files\Razer Pro Solutions\ProClick v1.6\razerhid.exe" [2007-03-02 14:39 126976]
"RivaTuner"="C:\Program Files\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 19:05 2650112]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 19:05 2650112]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
R1 nltdi;nltdi;C:\WINDOWS\system32\drivers\nltdi.sys [2007-04-23 12:03]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
R3 Razerlow;Razerlow USB Filter Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-04-24 22:43]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2005-08-02 22:10]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49e8f389-b946-11dc-8ecd-001a4d80d5c9}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - Recycled\ctfmon.exe
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-06 16:04:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 16:04:31
ComboFix-quarantined-files.txt 2008-01-06 15:04:30