ComboFix 07-08-25.2 - "Goodmen" 2007-08-26 11:32:29.1 - NTFSx86
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.207 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\svchost.exe
((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 )))))))))))))))))))))))))))))))
2007-08-26 11:22 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-25 17:22 <DIR> d-------- C:\Program Files\uTorrent
2007-08-23 19:12 <DIR> d-------- C:\Program Files\directx
2007-08-20 18:30 <DIR> d-------- C:\sphere
2007-08-20 18:21 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-08-20 18:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DATAAP~1\Adobe Systems
2007-08-18 22:41 831,600 --a------ C:\WINDOWS\system32\Ctaa1.dat
2007-08-18 22:41 77,824 --a------ C:\WINDOWS\system32\ctdvda32.dll
2007-08-18 22:41 333,600 --a------ C:\WINDOWS\system32\drivers\ctdvda2k.sys
2007-08-18 22:41 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2007-08-18 22:41 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2007-08-18 22:41 20,480 --a------ C:\WINDOWS\system32\IVIresize.dll
2007-08-18 22:41 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2007-08-18 22:41 192,512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2007-08-18 22:41 188,416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2007-08-18 22:41 122,880 --a------ C:\WINDOWS\system32\cddvdint.dll
2007-08-18 22:41 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-08-18 22:41 <DIR> d-------- C:\Program Files\InterActual
2007-08-18 22:41 <DIR> d-------- C:\Program Files\Creative
2007-08-18 22:41 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2007-08-18 16:49 <DIR> d-------- C:\Temp
2007-08-17 19:30 138,368 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-08-17 19:07 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2007-08-17 19:01 <DIR> d-------- C:\Program Files\WinClamAVShield
2007-08-17 17:27 502,208 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-08-17 17:27 270,336 --a------ C:\WINDOWS\system32\imon.dll
2007-08-17 17:00 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2007-08-16 23:58 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-08-16 23:57 75,264 --a------ C:\WINDOWS\system32\usbui.dll
2007-08-16 23:57 58,240 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-08-16 23:55 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-08-16 23:55 9,291 --a------ C:\WINDOWS\system\VER.DLL
2007-08-16 23:55 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-08-16 23:55 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-08-16 23:55 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-08-16 23:55 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-08-16 23:55 75,264 --a------ C:\WINDOWS\system32\storprop.dll
2007-08-16 23:55 70,272 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-08-16 23:55 69,632 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-08-16 23:55 69,008 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-08-16 23:55 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\kbdpl.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll
2007-08-16 23:55 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-08-16 23:55 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-08-16 23:55 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-08-16 23:55 5,632 --a------ C:\WINDOWS\system32\kbdro.dll
2007-08-16 23:55 5,632 --a------ C:\WINDOWS\system32\kbdpl1.dll
2007-08-16 23:55 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll
2007-08-16 23:55 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-08-16 23:55 33,040 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-08-16 23:55 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-08-16 23:55 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-08-16 23:55 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-08-16 23:55 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-08-16 23:55 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-08-16 23:55 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-08-16 23:55 127,024 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-08-16 23:55 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-08-16 23:55 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-08-16 23:55 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-08-16 23:55 <DIR> dr-h----- C:\DOCUME~1\DEFAUL~1\Data aplikacˇ
2007-08-16 23:55 <DIR> dr-h----- C:\DOCUME~1\ALLUSE~1\Data aplikacˇ
2007-08-16 23:55 <DIR> dr------- C:\Program Files
2007-08-16 23:55 <DIR> dr------- C:\DOCUME~1\DEFAUL~1\Nabˇdka Start
2007-08-16 23:55 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Nabˇdka Start
2007-08-16 23:55 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Dokumenty
2007-08-16 23:55 <DIR> d--hs---- C:\WINDOWS\Installer
2007-08-16 23:55 <DIR> d--h----- C:\DOCUME~1\DEFAUL~1\ćablony
2007-08-16 23:55 <DIR> d--h----- C:\DOCUME~1\DEFAUL~1\Okolnˇ tisk rny
2007-08-16 23:55 <DIR> d--h----- C:\DOCUME~1\DEFAUL~1\Okolnˇ sˇś
2007-08-16 23:55 <DIR> d--h----- C:\DOCUME~1\ALLUSE~1\ćablony
2007-08-16 23:55 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-08-16 23:55 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-08-16 23:55 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-08-16 23:55 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-08-16 23:55 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\Plocha
2007-08-16 23:55 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\Oblˇben‚ polo§ky
2007-08-16 23:55 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\Dokumenty
2007-08-16 23:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Plocha
2007-08-16 23:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Oblˇben‚ polo§ky
2007-08-16 23:54 <DIR> d-------- C:\Documents and Settings
2007-08-16 23:53 <DIR> d--hs---- C:\System Volume Information
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-26 11:13 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\uTorrent
2007-08-20 20:59 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\Opera
2007-08-20 19:49 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\XnView
2007-08-19 09:40 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\teamspeak2
2007-08-18 22:43 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\InterVideo
2007-08-17 17:34 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\Avant Profiles
2007-08-17 17:06 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\ICQLite
2007-08-16 22:54 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\Ahead
2007-08-16 22:49 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\TuneUp Software
2007-08-16 22:40 --------- d-------- C:\DOCUME~1\Goodmen\DATAAP~1\Lavasoft
2007-08-16 22:15 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-08-16 22:15 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 11:20]
"nwiz"="nwiz.exe" [2005-06-15 11:20 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 11:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"nod32kui"="C:\Programy\Nod32\nod32kui.exe" [2007-08-17 17:26]
"SMail"="C:\Programy\Postak\Postak.exe" [2006-05-18 14:36]
"SpywareTerminator"="C:\Programy\Spyware Terminator\SpywareTerminatorShield.exe" [2007-08-17 19:30]
"WinampAgent"="C:\Programy\Winamp\Winampa.exe" [2004-12-20 20:41]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"ICQ Lite"=C:\Programy\ICQLite\ICQLite.exe -trayboot
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ICQ Lite"="C:\Programy\ICQLite\ICQLite.exe" -minimize
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"SoundMan"=SOUNDMAN.EXE
R0 pnpshark;pnpshark;C:\WINDOWS\system32\DRIVERS\pnpshark.sys
R0 st3shark;st3shark;C:\WINDOWS\system32\DRIVERS\st3shark.sys
R1 sp_rsdrv2;Spyware Terminator Driver 2;\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
R2 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" --ntservice
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
UxTuneUp
*Newly Created Service* - CATCHME
Contents of the 'Scheduled Tasks' folder
2007-08-24 15:17:58 C:\WINDOWS\Tasks\1-Click Maintenance.job - C:\Programy\TuneUp Utilities 2007\SystemOptimizer.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-26 11:33:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="c:/apache/mysql/bin/mysqld-nt.exe"
Completion time: 2007-08-26 11:33:43
C:\ComboFix-quarantined-files.txt ... 2007-08-26 11:33
--- E O F ---