pocitac nebol pocas skanu restartovany.
tu je log:
ComboFix 07-11-08.1 - martin 2007-11-17 22:54:48.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.433 [GMT 1:00]
Running from: C:\Documents and Settings\martin\Plocha\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 22:53 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-16 03:16 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\ESET
2007-11-16 02:24 <DIR> d-------- C:\Program Files\Ahead
2007-11-15 15:50 <DIR> d-------- C:\Program Files\FreeRIP2
2007-11-14 22:08 <DIR> d-------- C:\Program Files\OpenOffice.org1.0.2
2007-11-14 22:06 36,864 --a------ C:\WINDOWS\uinst001.exe
2007-11-14 17:35 17,664 --a------ C:\WINDOWS\system32\drivers\sermouse.sys
2007-11-13 23:03 <DIR> d-------- C:\Documents and Settings\All Users\Documents
2007-11-13 23:02 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2007-11-13 23:01 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2007-11-13 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Teleca
2007-11-13 22:48 90,800 -ra------ C:\WINDOWS\system32\drivers\se2Eunic.sys
2007-11-13 22:48 18,704 -ra------ C:\WINDOWS\system32\drivers\se2End5.sys
2007-11-13 22:48 4,128 -ra------ C:\WINDOWS\system32\drivers\se2Ecr.sys
2007-11-13 22:47 88,688 -ra------ C:\WINDOWS\system32\drivers\SE2Emgmt.sys
2007-11-13 22:47 86,560 -ra------ C:\WINDOWS\system32\drivers\SE2Eobex.sys
2007-11-13 22:46 97,184 -ra------ C:\WINDOWS\system32\drivers\SE2Emdm.sys
2007-11-13 22:46 9,360 -ra------ C:\WINDOWS\system32\drivers\SE2Emdfl.sys
2007-11-13 22:46 6,240 -ra------ C:\WINDOWS\system32\drivers\SE2Ecmnt.sys
2007-11-13 22:46 6,240 -ra------ C:\WINDOWS\system32\drivers\SE2Ecm.sys
2007-11-13 22:45 61,600 -ra------ C:\WINDOWS\system32\drivers\SE2Ebus.sys
2007-11-13 22:45 5,872 -ra------ C:\WINDOWS\system32\drivers\SE2Ewhnt.sys
2007-11-13 22:45 5,872 -ra------ C:\WINDOWS\system32\drivers\se2Ewh.sys
2007-11-13 22:35 <DIR> d-------- C:\Documents and Settings\martin\Data aplikací\Teleca
2007-11-13 22:31 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-11-13 22:30 <DIR> d-------- C:\Program Files\Sony Ericsson
2007-11-13 22:29 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-11-12 22:56 <DIR> d-------- C:\Documents and Settings\martin\Data aplikací\ICQ Toolbar
2007-11-12 22:54 <DIR> d-------- C:\Documents and Settings\martin\Data aplikací\BearShare
2007-11-12 22:52 <DIR> d-------- C:\Program Files\BearShare Applications
2007-11-12 01:38 <DIR> d-------- C:\Program Files\QuickTime
2007-11-12 01:38 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2007-11-12 01:26 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-11-10 13:52 611,064 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-11-10 11:00 138,624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-11-09 12:17 516,096 --a------ C:\WINDOWS\system32\ati2sgag.exe
2007-11-09 12:13 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-09 11:57 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2007-11-09 11:57 95,617 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2007-11-08 20:48 <DIR> d-------- C:\Documents and Settings\martin\Data aplikací\CyberLink
2007-11-08 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2007-11-08 20:47 <DIR> d-------- C:\Program Files\CyberLink
2007-11-08 20:34 <DIR> d-------- C:\Documents and Settings\martin\Data aplikací\COWON
2007-11-08 20:32 <DIR> d-------- C:\Program Files\directx
2007-11-08 20:22 <DIR> d-------- C:\Program Files\Activision
2007-11-08 19:07 <DIR> d-------- C:\Program Files\ICQToolbar
2007-11-08 16:19 <DIR> d-------- C:\Temp
2007-11-08 15:22 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Talkback
2007-11-08 15:12 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2007-11-08 15:12 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2007-11-08 15:12 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2007-11-08 15:12 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2007-11-08 15:12 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2007-11-08 15:12 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2007-11-08 15:12 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2007-11-08 15:12 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2007-11-08 14:43 <DIR> d-------- C:\Documents and Settings\NetworkService\Nabídka Start
2007-11-08 14:13 <DIR> d-------- C:\Program Files\Spyware Terminator
2007-11-08 14:13 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2007-11-08 12:55 <DIR> d-------- C:\Documents and Settings\martin\Data aplikací\Talkback
2007-11-08 12:55 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Hagel Technologies
2007-11-08 12:54 107,008 --a------ C:\WINDOWS\UninstallFirefox.exe
2007-11-08 12:54 3,441 --a------ C:\WINDOWS\mozver.dat
2007-11-08 12:54 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-08 12:41 57,404 -ra------ C:\WINDOWS\system32\drivers\ftser2k.sys
2007-11-08 12:41 51,821 -ra------ C:\WINDOWS\system32\ftserui2.dll
2007-11-08 12:41 36,864 -ra------ C:\WINDOWS\system32\FTLang.dll
2007-11-08 12:40 422,400 -ra------ C:\WINDOWS\system32\ftdiunin.exe
2007-11-08 12:40 24,209 -ra------ C:\WINDOWS\system32\drivers\ftdibus.sys
2007-10-30 10:29 30,728 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-10-30 10:27 33,800 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2007-10-30 10:27 27,144 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 00:29 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2007-11-16 02:50 9,728 ----a-w C:\WINDOWS\system32\reset.exe
2007-11-16 02:50 9,216 ----a-w C:\WINDOWS\system32\subst.exe
2007-11-16 02:50 9,216 ----a-w C:\WINDOWS\system32\scrnsave.scr
2007-11-16 02:50 8,192 ----a-w C:\WINDOWS\system32\winhlp32.exe
2007-11-16 02:50 8,192 ----a-w C:\WINDOWS\system32\smbinst.exe
2007-11-16 02:50 77,824 ----a-w C:\WINDOWS\system32\usrmlnka.exe
2007-11-16 02:50 77,824 ----a-w C:\WINDOWS\system32\shrpubw.exe
2007-11-16 02:50 77,824 ----a-w C:\WINDOWS\system32\sdbinst.exe
2007-11-16 02:50 77,312 ----a-w C:\WINDOWS\system32\telnet.exe
2007-11-16 02:50 77,312 ----a-w C:\WINDOWS\system32\rtcshare.exe
2007-11-16 02:50 708,608 ----a-w C:\WINDOWS\system32\ss3dfo.scr
2007-11-16 02:50 70,656 ----a-w C:\WINDOWS\system32\sigverif.exe
2007-11-16 02:50 7,168 ----a-w C:\WINDOWS\system32\recover.exe
2007-11-16 02:50 69,632 ----a-w C:\WINDOWS\system32\usrshuta.exe
2007-11-16 02:50 679,936 ----a-w C:\WINDOWS\system32\sstext3d.scr
2007-11-16 02:50 67,072 ----a-w C:\WINDOWS\system32\rdshost.exe
2007-11-16 02:50 65,024 ----a-w C:\WINDOWS\system32\wextract.exe
2007-11-16 02:50 62,464 ----a-w C:\WINDOWS\system32\rdpclip.exe
2007-11-16 02:50 610,304 ----a-w C:\WINDOWS\system32\sspipes.scr
2007-11-16 02:50 61,440 ----a-w C:\WINDOWS\system32\usrprbda.exe
2007-11-16 02:50 56,832 ----a-w C:\WINDOWS\system32\sol.exe
2007-11-16 02:50 56,832 ----a-w C:\WINDOWS\system32\rasphone.exe
2007-11-16 02:50 55,296 ----a-w C:\WINDOWS\system32\reg.exe
2007-11-16 02:50 538,624 ----a-w C:\WINDOWS\system32\spider.exe
2007-11-16 02:50 51,200 ----a-w C:\WINDOWS\system32\syncapp.exe
2007-11-16 02:50 51,200 ----a-w C:\WINDOWS\system32\rsm.exe
2007-11-16 02:50 50,176 ----a-w C:\WINDOWS\system32\w32tm.exe
2007-11-16 02:50 50,176 ----a-w C:\WINDOWS\system32\utilman.exe
2007-11-16 02:50 5,632 ----a-w C:\WINDOWS\system32\write.exe
2007-11-16 02:50 5,632 ----a-w C:\WINDOWS\system32\winver.exe
2007-11-16 02:50 49,152 ----a-w C:\WINDOWS\system32\rsmui.exe
2007-11-16 02:50 47,104 ----a-w C:\WINDOWS\system32\ssmypics.scr
2007-11-16 02:50 44,544 ----a-w C:\WINDOWS\system32\tscupgrd.exe
2007-11-16 02:50 433,664 ----a-w C:\WINDOWS\system32\wiaacmgr.exe
2007-11-16 02:50 4,608 ----a-w C:\WINDOWS\system32\regwiz.exe
2007-11-16 02:50 4,096 ----a-w C:\WINDOWS\system32\unlodctr.exe
2007-11-16 02:50 393,216 ----a-w C:\WINDOWS\system32\ssflwbox.scr
2007-11-16 02:50 36,864 ----a-w C:\WINDOWS\system32\syskey.exe
2007-11-16 02:50 35,840 ----a-w C:\WINDOWS\system32\rcimlby.exe
2007-11-16 02:50 33,792 ----a-w C:\WINDOWS\system32\vssadmin.exe
2007-11-16 02:50 33,792 ----a-w C:\WINDOWS\system32\regini.exe
2007-11-16 02:50 32,768 ----a-w C:\WINDOWS\system32\wpnpinst.exe
2007-11-16 02:50 32,768 ----a-w C:\WINDOWS\system32\sethc.exe
2007-11-16 02:50 32,256 ----a-w C:\WINDOWS\system32\wupdmgr.exe
2007-11-16 02:50 32,256 ----a-w C:\WINDOWS\system32\wpabaln.exe
2007-11-16 02:50 32,256 ----a-w C:\WINDOWS\system32\tracert6.exe
2007-11-16 02:50 31,232 ----a-w C:\WINDOWS\system32\sc.exe
2007-11-16 02:50 30,720 ----a-w C:\WINDOWS\system32\xcopy.exe
2007-11-16 02:50 3,584 ----a-w C:\WINDOWS\system32\regedt32.exe
2007-11-16 02:50 3,072 ----a-w C:\WINDOWS\system32\systray.exe
2007-11-16 02:50 26,112 ----a-w C:\WINDOWS\system32\skeys.exe
2007-11-16 02:50 25,600 ----a-w C:\WINDOWS\system32\routemon.exe
2007-11-16 02:50 24,576 ----a-w C:\WINDOWS\system32\sort.exe
2007-11-16 02:50 24,576 ----a-w C:\WINDOWS\system32\rsmsink.exe
2007-11-16 02:50 23,040 ----a-w C:\WINDOWS\system32\setup.exe
2007-11-16 02:50 22,528 ----a-w C:\WINDOWS\system32\rcp.exe
2007-11-16 02:50 22,528 ----a-w C:\WINDOWS\system32\qwinsta.exe
2007-11-16 02:50 20,992 ----a-w C:\WINDOWS\system32\ssmarque.scr
2007-11-16 02:50 20,480 ----a-w C:\WINDOWS\system32\qprocess.exe
2007-11-16 02:50 19,968 ----a-w C:\WINDOWS\system32\ssbezier.scr
2007-11-16 02:50 19,968 ----a-w C:\WINDOWS\system32\shutdown.exe
2007-11-16 02:50 19,968 ----a-w C:\WINDOWS\system32\route.exe
2007-11-16 02:50 19,456 ----a-w C:\WINDOWS\system32\tcpsvcs.exe
2007-11-16 02:50 18,944 ----a-w C:\WINDOWS\system32\ssmyst.scr
2007-11-16 02:50 17,408 ----a-w C:\WINDOWS\system32\qappsrv.exe
2007-11-16 02:50 166,912 ----a-w C:\WINDOWS\system32\wuauclt1.exe
2007-11-16 02:50 16,896 ----a-w C:\WINDOWS\system32\upnpcont.exe
2007-11-16 02:50 16,896 ----a-w C:\WINDOWS\system32\tsshutdn.exe
2007-11-16 02:50 16,896 ----a-w C:\WINDOWS\system32\tftp.exe
2007-11-16 02:50 16,896 ----a-w C:\WINDOWS\system32\runas.exe
2007-11-16 02:50 16,384 ----a-w C:\WINDOWS\system32\tskill.exe
2007-11-16 02:50 15,872 ----a-w C:\WINDOWS\system32\rwinsta.exe
2007-11-16 02:50 15,360 ----a-w C:\WINDOWS\system32\tscon.exe
2007-11-16 02:50 15,360 ----a-w C:\WINDOWS\system32\taskman.exe
2007-11-16 02:50 15,360 ----a-w C:\WINDOWS\system32\shadow.exe
2007-11-16 02:50 15,360 ----a-w C:\WINDOWS\system32\rsh.exe
2007-11-16 02:50 14,848 ----a-w C:\WINDOWS\system32\tsdiscon.exe
2007-11-16 02:50 14,848 ----a-w C:\WINDOWS\system32\stimon.exe
2007-11-16 02:50 14,336 ----a-w C:\WINDOWS\system32\ssstars.scr
2007-11-16 02:50 14,336 ----a-w C:\WINDOWS\system32\runonce.exe
2007-11-16 02:50 14,336 ----a-w C:\WINDOWS\system32\rexec.exe
2007-11-16 02:50 138,752 ----a-w C:\WINDOWS\system32\sndvol32.exe
2007-11-16 02:50 137,216 ----a-w C:\WINDOWS\system32\taskmgr.exe
2007-11-16 02:50 131,584 ----a-w C:\WINDOWS\system32\sndrec32.exe
2007-11-16 02:50 13,824 ----a-w C:\WINDOWS\system32\wscntfy.exe
2007-11-16 02:50 13,824 ----a-w C:\WINDOWS\system32\rdsaddin.exe
2007-11-16 02:50 13,312 ----a-w C:\WINDOWS\system32\savedump.exe
2007-11-16 02:50 12,800 ----a-w C:\WINDOWS\system32\tracert.exe
2007-11-16 02:50 12,800 ----a-w C:\WINDOWS\system32\tcmsetup.exe
2007-11-16 02:50 12,800 ----a-w C:\WINDOWS\system32\replace.exe
2007-11-16 02:50 119,808 ----a-w C:\WINDOWS\system32\winmine.exe
2007-11-16 02:50 114,688 ----a-w C:\WINDOWS\system32\wscript.exe
2007-11-16 02:50 11,776 ----a-w C:\WINDOWS\system32\winmsd.exe
2007-11-16 02:50 11,776 ----a-w C:\WINDOWS\system32\spnpinst.exe
2007-11-16 02:50 11,776 ----a-w C:\WINDOWS\system32\rasdial.exe
2007-11-16 02:50 11,776 ----a-w C:\WINDOWS\system32\rasautou.exe
2007-11-16 02:50 106,496 ----a-w C:\WINDOWS\system32\sysocmgr.exe
2007-11-16 02:50 100,864 ----a-w C:\WINDOWS\system32\verifier.exe
2007-11-16 02:50 10,240 ----a-w C:\WINDOWS\system32\sfc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-16 00:41]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2005-02-01 19:28]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-11-13 11:00]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-11 11:06]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-11-17 01:29]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2007-11-17 01:29]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-10-30 10:28]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-11-17 01:29]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-11-16 03:18]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"ICQ Lite"=C:\Program Files\ICQLite\ICQLite.exe -trayboot
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
R1 sp_rsdrv2;Spyware Terminator Driver 2;\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys
R2 ekrn;Eset Service;"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 EhttpSrv;Eset HTTP Server;"C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-17 22:56:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 22:57:08
.
--- E O F ---