ComboFix 08-02.03.1 - Administrator 2008-02-04 20:41:47.1 - NTFSx86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.1.1250.1.1029.18.853 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\OPTIONS\CABS\_desktop.ini
C:\WINDOWS\system32\.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-04 to 2008-02-04 )))))))))))))))))))))))))))))))
.
2008-02-04 20:28 . 2008-02-04 20:30 60,928 --ah----- C:\WINDOWS\system32\vcdb.exe
2008-02-04 20:13 . 2008-02-04 20:13 19,711 --a------ C:\WINDOWS\system32\kxqzzrtg.exe
2008-02-04 20:13 . 2008-02-04 20:13 7,680 --a------ C:\WINDOWS\system32\ibfg.exe
2008-02-04 20:11 . 2008-02-04 20:11 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQ Toolbar
2008-02-04 20:11 . 2008-02-04 20:11 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQ Toolbar
2008-02-04 20:11 . 2008-02-04 20:11 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQ Toolbar
2008-02-04 19:36 . 2008-02-04 19:45 57,159 --ah----- C:\WINDOWS\system32\ymgrkaye.exe
2008-02-04 18:47 . 2008-02-04 18:47 19,711 --a------ C:\WINDOWS\system32\ambckvpm.exe
2008-02-04 18:47 . 2008-02-04 18:47 7,680 --a------ C:\WINDOWS\system32\navfmqi.exe
2008-02-04 18:27 . 2008-02-04 18:28 <DIR> d-------- C:\Downloads
2008-02-04 18:27 . 2008-02-04 18:27 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-02-04 18:26 . 2008-02-04 19:19 <DIR> d-------- C:\Program Files\BitComet
2008-02-04 18:18 . 2008-02-04 18:20 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2008-02-04 18:18 . 2008-02-04 18:20 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2008-02-04 18:18 . 2008-02-04 18:20 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2008-02-04 17:54 . 2008-02-04 17:54 <DIR> d-------- C:\Program Files\QIP
2008-02-04 16:32 . 2008-02-04 16:32 19,711 --a------ C:\WINDOWS\system32\nqpfvdol.exe
2008-02-04 16:32 . 2008-02-04 16:32 7,680 --a------ C:\WINDOWS\system32\unnoatb.exe
2008-02-04 16:09 . 2008-02-04 16:11 21,048 --ah----- C:\WINDOWS\system32\ypmw.exe
2008-02-04 16:04 . 2008-02-04 16:04 19,711 --a------ C:\WINDOWS\system32\xdjxlv.exe
2008-02-04 16:04 . 2008-02-04 16:04 7,680 --a------ C:\WINDOWS\system32\awlrqijb.exe
2008-02-04 15:55 . 2008-02-04 15:59 24,820 --ah----- C:\WINDOWS\system32\iloehhb.exe
2008-02-04 15:47 . 2008-02-04 15:47 138,624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-02-04 15:44 . 2008-02-04 15:44 <DIR> d-------- C:\Program Files\Crawler
2008-02-04 15:44 . 2008-02-04 17:48 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-02-04 15:43 . 2008-02-04 18:25 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-02-04 15:36 . 2008-02-04 15:36 19,711 --a------ C:\WINDOWS\system32\mutkmsnh.exe
2008-02-04 15:36 . 2008-02-04 15:36 7,680 --a------ C:\WINDOWS\system32\ssfdewux.exe
2008-02-04 15:21 . 2008-02-04 15:21 <DIR> d-------- C:\Program Files\Lavalys
2008-02-04 15:12 . 2008-02-04 20:11 <DIR> d-------- C:\Program Files\ICQToolbar
2008-02-04 15:12 . 2008-02-04 15:12 <DIR> d-------- C:\Program Files\ICQLite
2008-02-04 15:12 . 2008-02-04 15:12 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQLite
2008-02-04 15:12 . 2008-02-04 15:12 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQLite
2008-02-04 15:12 . 2008-02-04 15:12 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQLite
2008-02-04 15:09 . 2008-02-04 15:09 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-04 15:08 . 2008-02-04 15:08 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-04 15:07 . 2008-02-04 15:07 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-02-04 15:06 . 2008-02-04 15:06 <DIR> d-------- C:\Program Files\Webteh
2008-02-04 15:05 . 2008-02-04 15:05 <DIR> d-------- C:\Program Files\Opera
2008-02-04 15:02 . 2008-02-04 15:02 19,711 --a------ C:\WINDOWS\system32\rosd.exe
2008-02-04 15:02 . 2008-02-04 15:02 7,680 --a------ C:\WINDOWS\system32\ftgggtek.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-04 13:59 --------- d-----w C:\Program Files\totalcmd
2008-02-04 13:49 7,680 ----a-w C:\WINDOWS\system32\qcovfxk.exe
2008-02-04 13:49 19,711 ----a-w C:\WINDOWS\system32\xifztmu.exe
2008-02-04 13:47 --------- d-----w C:\Program Files\Alwil Software
2008-02-04 13:45 7,680 ----a-w C:\WINDOWS\system32\ikoqduo.exe
2008-02-04 13:45 19,711 ----a-w C:\WINDOWS\system32\mopidace.exe
2008-02-04 13:35 --------- d-----w C:\Program Files\ESET
2008-02-04 13:35 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ESET
2008-02-04 13:25 7,680 ----a-w C:\WINDOWS\system32\tiinwf.exe
2008-02-04 13:16 7,680 ----a-w C:\WINDOWS\system32\xewgqgw.exe
2008-02-04 13:16 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ATI
2008-02-04 13:16 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\ATI
2008-02-04 13:16 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\ATI
2008-02-04 13:16 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\ATI
2008-02-04 13:08 --------- d-----w C:\Program Files\ATI Technologies
2008-02-04 13:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 13:02 7,680 ----a-w C:\WINDOWS\system32\mwzun.exe
2008-02-04 13:02 19,711 ----a-w C:\WINDOWS\system32\bapvtd.exe
2008-02-04 12:55 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Logitech
2008-02-04 12:55 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Logitech
2008-02-04 12:55 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Logitech
2008-02-04 12:53 118,784 ------r C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
2008-02-04 12:53 --------- d-----w C:\Program Files\Logitech
2008-02-04 12:52 --------- d-----w C:\Program Files\Common Files\Logitech
2008-02-04 12:37 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-04 12:36 --------- d-----w C:\Program Files\Common Files\ATI Technologies
2008-02-04 12:29 423 ----a-w C:\Program Files\RHDSetup.log
2008-02-04 12:29 197 ----a-w C:\Program Files\csb.log
2008-02-04 12:28 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-02-04 12:28 --------- d-----w C:\Program Files\Realtek
2008-02-04 12:28 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\InstallShield
2008-02-04 12:28 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\InstallShield
2008-02-04 12:28 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\InstallShield
2008-02-04 12:27 15,600 ----a-w C:\WINDOWS\gdrv.sys
2008-02-04 12:25 --------- d-----w C:\Program Files\Yahoo!
2008-02-04 12:25 --------- d-----w C:\Program Files\Intel
2008-02-04 12:15 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-04 12:14 558,142 ----a-w C:\WINDOWS\java\Packages\VTRHJZ5N.ZIP
2008-02-04 12:14 155,995 ----a-w C:\WINDOWS\java\Packages\OIJ7P773.ZIP
2007-12-21 03:53 2,843,136 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-12-21 03:09 368,640 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-21 03:08 272,384 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-21 03:02 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-12-21 02:59 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-21 02:59 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-21 02:59 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-21 02:59 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-21 02:58 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-21 02:57 512,000 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-21 02:56 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-21 02:53 9,826,304 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-21 02:47 3,120,640 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-21 02:36 1,661,696 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-21 02:24 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-21 02:20 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-21 02:20 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-21 02:18 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-21 02:17 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-12-21 02:15 159,744 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-21 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-12-20 20:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-20 18:05 13312]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-02-04 13:53 32768]
"Steam"="C:\Games\Steam\Steam.exe" [2008-02-04 14:21 1266936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 10:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 12:45 49152 C:\WINDOWS\KHALMNPR.Exe]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-02-04 15:45 2776576]
"Application Layer Gateway Service"="C:\WINDOWS\System32\algs.exe" [2002-09-20 18:05 82882]
"Advanced DHTML Enable"="C:\WINDOWS\System32\kxqzzrtg.exe" [2008-02-04 20:13 19711]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-09-20 18:05 13312]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-02-04 13:53:14 450560]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-02-04 13:52:38 434176]
S1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\System32\drivers\sp_rsdrv2.sys [2008-02-04 15:47]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-02-04 13:27]
S3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\System32\DRIVERS\psched.sys [2002-08-29 01:35]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-04 20:42:57
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-04 20:43:22
ComboFix-quarantined-files.txt 2008-02-04 19:43:15
