oki:
ComboFix 08-02.05.3 - michal 2008-02-04 23:39:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.141 [GMT 1:00]
Running from: C:\Documents and Settings\michal\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\michal\Data aplikací\FunWebProducts
C:\Documents and Settings\michal\err.log
C:\Program Files\Common Files\Relive.dll
C:\Program Files\Online Video Add-on
C:\Program Files\Online Video Add-on\isfmdl.dll
C:\Program Files\Online Video Add-on\isfmm.txt
C:\Program Files\Online Video Add-on\isfmntr.pdf
C:\WINDOWS\system32\hteogat.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-04 to 2008-02-04 )))))))))))))))))))))))))))))))
.
2008-01-30 09:17 . 2008-02-04 08:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-30 09:17 . 2008-01-30 09:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-29 12:49 . 2008-01-29 12:49 <DIR> d-------- C:\Program Files\CyberLink
2008-01-29 12:49 . 2008-01-29 12:49 <DIR> d-------- C:\Program Files\ASUSTek
2008-01-29 12:49 . 2008-01-29 12:49 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2008-01-27 20:45 . 2008-01-27 20:45 <DIR> d-------- C:\spoolerlogs
2008-01-24 12:25 . 2008-01-24 12:25 <DIR> d-------- C:\MP3
2008-01-23 13:29 . 2008-01-26 17:52 <DIR> d-------- C:\Program Files\StrongDC++ ROBUR 2.11
2008-01-20 11:32 . 2008-01-20 11:32 <DIR> d-------- C:\Program Files\Google
2008-01-14 13:30 . 2008-01-14 13:30 <DIR> d-------- C:\Program Files\Hamachi
2008-01-13 13:46 . 2008-01-13 13:47 <DIR> d-------- C:\Documents and Settings\michal\Data aplikací\Teleca
2008-01-13 13:45 . 2008-01-13 13:45 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-01-13 13:45 . 2008-01-13 13:45 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-01-13 13:45 . 2008-01-13 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Documents
2008-01-13 13:45 . 2008-01-13 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Teleca
2008-01-13 13:45 . 2008-01-13 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2008-01-13 13:41 . 2008-01-13 13:41 55,216 --a------ C:\WINDOWS\system32\drivers\k750bus.sys
2008-01-13 13:41 . 2008-01-13 13:41 6,144 --a------ C:\WINDOWS\system32\drivers\k750cm.sys
2008-01-13 13:41 . 2008-01-13 13:41 5,744 --a------ C:\WINDOWS\system32\drivers\k750whnt.sys
2008-01-13 13:41 . 2008-01-13 13:41 5,744 --a------ C:\WINDOWS\system32\drivers\k750wh.sys
2008-01-13 13:40 . 2008-01-13 13:41 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-01-08 14:39 . 2008-01-08 14:40 <DIR> d-------- C:\Program Files\Counter-Strike 1.6 Patch Version 26
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-04 22:43 --------- d-----w C:\Documents and Settings\michal\Data aplikací\Azureus
2008-02-04 07:30 --------- d-----w C:\Program Files\Michal
2008-02-03 22:37 11,948 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-02-03 16:30 --------- d-----w C:\Program Files\Martinka
2008-01-31 13:51 --------- d-----w C:\Program Files\Warcraft III
2008-01-30 07:49 --------- d-----w C:\Documents and Settings\michal\Data aplikací\Skype
2008-01-29 20:40 --------- d-----w C:\Documents and Settings\michal\Data aplikací\Ahead
2008-01-29 11:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-25 12:09 --------- d-----w C:\Program Files\SubRip
2008-01-24 11:24 --------- d-----w C:\Program Files\StrongDC++
2008-01-23 12:55 --------- d-----w C:\Program Files\Maroš
2008-01-14 12:33 --------- d-----w C:\Documents and Settings\michal\Data aplikací\Hamachi
2008-01-14 12:30 25,544 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-01-01 08:04 --------- d-----w C:\Program Files\ICQLite
2007-12-22 17:52 --------- d-----w C:\Documents and Settings\michal\Data aplikací\InstallShield
2007-12-18 11:55 --------- d-----w C:\Program Files\YouTube Video Downloader
2007-12-13 00:29 --------- d-----w C:\Documents and Settings\michal\Data aplikací\Autodesk
2007-12-13 00:21 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-12-13 00:21 --------- d-----w C:\Program Files\Autodesk
2007-12-13 00:19 --------- d-----w C:\Program Files\AnswerWorks 4.0
2007-12-13 00:17 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Autodesk
2005-04-03 19:22 1,108,779 ----a-w C:\Program Files\sewer.dat
2005-04-03 13:42 841,839 ----a-w C:\Program Files\insanity.dat
2004-06-07 20:04 774 ----a-w C:\Program Files\sinister.epd
2004-06-06 20:28 3,643 ----a-w C:\Program Files\yard.dat
2007-07-16 14:01 56 --sh--r C:\WINDOWS\system32\7B77FC0151.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{84938242-5C5B-4A55-B6B9-A1507543B418}"= C:\Program Files\Video Access ActiveX Object\iesplugin.dll [ ]
[HKEY_CLASSES_ROOT\clsid\{84938242-5c5b-4a55-b6b9-a1507543b418}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-03-01 18:43 90112]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-13 17:20 20058152]
"E06AXLRD_5747609"="C:\Program Files\Microsoft Encarta\Encarta Premium DVD 2006\EDICT.exe" [2005-06-03 09:30 301776]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2007-03-13 12:09 3144800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 07:57 143360]
"AGRSMMSG"="AGRSMMSG.exe" [2002-09-25 11:44 87751 C:\WINDOWS\AGRSMMSG.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 16:22 7618560]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 16:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-11 14:02 155648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-11 14:04 180269]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 05:03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 05:03 81920]
"Siemens SmartSync - ScheduleSync"="C:\PROGRA~1\MOBILE~1\SMARTS~1\SCHEDU~1.EXE" [2005-03-16 09:15 45056]
"pdfFactory Pro Dispečér v2"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2006-08-03 15:33 503808]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-06-26 07:54 1115728]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-12-10 15:57 133016]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 14:49 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{634be415-da12-496b-b89e-329b73c4807f}"= C:\WINDOWS\system32\tvomnc.dll [ ]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{0CD68AC9-FF63-3E61-626B-B663E62F6236}"= C:\Program Files\Internet Explorer\romdrivers.dll [2008-02-04 23:39 14891]
R2 Vcs;Vcs support;C:\WINDOWS\system32\Drivers\Vcs.sys [2002-12-10 08:11]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 22:04]
S2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys []
S3 gel90xne;gel90xne;C:\DOCUME~1\michal\LOCALS~1\Temp\gel90xne.sys [2002-06-18 14:26]
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2005-10-14 02:53]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{add5994e-b7f9-11dc-ab34-000c6ee9fcb7}]
\Shell\Auto\command - G:\
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-04 23:44:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-04 23:46:27
ComboFix-quarantined-files.txt 2008-02-04 22:46:24