ComboFix 08-02-16.2 - Administrator 2008-02-16 21:25:32.1 - NTFSx86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.800 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.
2008-02-16 20:23 . 2008-02-16 20:38 <DIR> d-------- C:\Program Files\TrackMania Nations ESWC
2008-02-16 17:48 . 2004-02-23 01:00 1,386,496 --a------ C:\WINDOWS\system32\MSVBVM60.DLL
2008-02-16 15:54 . 2008-02-16 15:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-16 02:18 . 2008-02-16 02:18 <DIR> d-------- C:\Program Files\Uniblue
2008-02-16 02:18 . 2008-02-16 02:18 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Uniblue
2008-02-15 21:16 . 2008-02-15 21:16 359,040 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-02-15 11:23 . 2008-02-15 11:23 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-02-15 11:23 . 2008-02-15 11:23 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-02-15 11:23 . 2008-02-15 11:23 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-02-15 11:23 . 2008-02-15 11:23 60,416 --a------ C:\WINDOWS\ALCFDRTM.VER
2008-02-15 11:23 . 2008-02-15 11:23 60,416 --a------ C:\WINDOWS\ALCFDRTM.EXE
2008-02-15 11:15 . 2008-02-15 11:15 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\LockTime
2008-02-15 01:52 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-02-15 01:52 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-02-06 02:04 . 2008-02-06 02:04 <DIR> d-------- C:\Program Files\Ping Plotter Freeware
2008-01-28 13:10 . 2008-01-28 13:13 <DIR> d-------- C:\Program Files\IrfanView
2008-01-26 01:04 . 2008-01-26 01:06 <DIR> d-------- C:\Documents and Settings\Administrator\Call of duty
2008-01-17 02:06 . 2008-01-17 02:07 <DIR> d-------- C:\Program Files\DU Meter
2008-01-17 02:06 . 2008-01-17 02:06 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Hagel Technologies
2008-01-16 23:32 . 2008-01-16 23:32 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-01-16 23:31 . 2008-01-16 23:31 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-01-16 20:42 . 2004-08-17 15:49 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2008-01-16 20:42 . 2004-08-17 15:49 153,088 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2008-01-16 20:42 . 2004-08-17 15:49 26,624 --a------ C:\WINDOWS\system32\irmon.dll
2008-01-16 20:42 . 2004-08-17 15:49 26,624 --a--c--- C:\WINDOWS\system32\dllcache\irmon.dll
2008-01-16 20:42 . 2004-08-17 15:49 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-01-16 20:42 . 2004-08-17 15:49 8,192 --a--c--- C:\WINDOWS\system32\dllcache\wshirda.dll
2008-01-16 15:46 . 2008-02-16 01:49 <DIR> dr-h----- C:\Documents and Settings\All Users\Data aplikací
2008-01-16 15:46 . 2008-02-16 01:49 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-01-16 15:32 . 2008-01-16 15:32 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Nero
2008-01-16 15:29 . 2008-01-16 15:29 <DIR> d-------- C:\Program Files\Nero
2008-01-16 15:29 . 2008-01-16 15:31 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-01-16 15:29 . 2008-01-16 15:29 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Nero
2008-01-16 00:17 . 2008-01-16 02:32 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-01-16 00:14 . 2008-01-16 00:14 <DIR> d-------- C:\Program Files\Alcohol Soft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 16:51 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Skype
2008-02-16 15:51 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\skypePM
2008-02-16 00:49 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2008-02-16 00:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-16 00:38 --------- d-----w C:\Program Files\Futuremark
2008-02-16 00:32 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Lavasoft
2008-02-15 22:26 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Nokia
2008-02-15 20:16 359,040 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-02-13 22:53 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-07 22:23 --------- d-----w C:\Program Files\ESET
2008-01-23 22:56 --------- d-----w C:\Program Files\Steam
2008-01-21 16:45 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Installations
2008-01-21 10:11 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\PC Suite
2008-01-16 22:32 --------- d-----w C:\Program Files\Nokia
2008-01-16 22:32 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-01-15 23:19 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Ahead
2008-01-15 23:09 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-19 14:53 --------- d-----w C:\Program Files\NVIDIA Corporation
2007-12-19 14:12 356,352 ----a-w C:\WINDOWS\eSellerateEngine.dll
2007-12-19 13:32 --------- d-----w C:\Program Files\AMD
2007-12-19 13:26 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-12-19 13:26 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-12-18 23:02 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-12-18 23:02 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-18 23:02 22,328 ----a-w C:\Documents and Settings\Administrator\Data aplikací\PnkBstrK.sys
2007-12-18 23:02 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-18 22:56 --------- d-----w C:\Program Files\Activision
2007-12-13 21:02 238,888 ----a-w C:\WINDOWS\NuNInst.exe
2007-12-13 18:09 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-12-04 08:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-12-03 17:04 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
2007-11-24 01:10 32 ----a-w C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@={8D2223A2-B3C6-4e32-B096-CDD11F628C60}
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2007-12-13 22:02 96552 --a------ C:\Program Files\Nero\Nero8\InCD\NBHShx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32 81920]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2007-11-13 20:23 2585360]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 14:49 110592 C:\WINDOWS\system32\bthprops.cpl]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-07-14 16:08 851968]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 07:45 90112 C:\WINDOWS\soundman.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 14:49 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 18:48 434528]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IETI"="C:\Program Files\Skype\Phone\IEPlugin\unins000.exe" [ ]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-17 14:42 44544]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Synchronizer.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RivaTunerStartupDaemon]
C:\Program Files\RivaTuner v2.06\RivaTuner.exe
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 22:08]
S2 DUMeterSvc;DU Meter Service;C:\Program Files\DU Meter\DUMeterSvc.exe [2007-11-10 10:02]
S2 LANPkt;Realtek LANPkt Protocol;C:\WINDOWS\system32\DRIVERS\LANPkt.sys [2003-09-17 15:57]
S2 NeroRegInCDSrv;Nero Registry InCD Service;C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe [2007-12-13 22:02]
S3 DCamUSBSTK014;STK014 Camera;C:\WINDOWS\system32\DRIVERS\STK014W2.sys []
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys [2001-10-25 15:00]
S3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 22:04]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
S3 WLANPIB;IEEE 802.11b PCMCIA Driver;C:\WINDOWS\system32\DRIVERS\WLANPIB.sys [2004-06-08 18:54]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 20:27:26 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-16 21:27:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\DUMeterSvc]
"ImagePath"="C:\Program Files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
Completion time: 2008-02-16 21:29:44
.
2008-02-16 14:49:28 --- E O F ---