ComboFix 07-08-17.2 - "pik" 2007-08-24 7:58:19.1 - NTFS x86
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.635 [GMT 2:00]
C:\WINDOWS\system32\chkdsk.exe not present
ADS removed - C:\WINDOWS\system32\ntoskrnl.exe: Systém nemôže nájsť zadaný súbor.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))
2007-08-24 07:56 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-23 14:24 <DIR> d-------- C:\Program Files\Gallery Creator
2007-08-23 11:45 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-08-23 09:50 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-08-23 08:46 <DIR> d-------- C:\Program Files\WinClamAVShield
2007-08-23 08:40 138,624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-08-23 08:06 <DIR> d-------- C:\Program Files\Spyware Terminator
2007-08-23 08:06 <DIR> d-------- C:\Program Files\Crawler
2007-08-23 08:06 <DIR> d-------- C:\DOCUME~1\pik\APPLIC~1\Spyware Terminator
2007-08-23 08:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spyware Terminator
2007-08-22 20:02 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-08-22 20:02 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-08-22 20:02 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-08-22 20:02 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-08-22 20:02 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-08-22 20:02 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-08-22 20:00 146,432 --a------ C:\WINDOWS\R.COM
2007-08-22 20:00 135,680 --a------ C:\WINDOWS\system32\T.COM
2007-08-22 19:10 <DIR> d-------- C:\Program Files\Clear FTP 2006
2007-08-22 18:48 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2007-08-22 18:00 <DIR> d-------- C:\WINDOWS\pss
2007-08-22 15:53 <DIR> d-------- C:\Program Files\Express Thumbnail Creator
2007-08-12 19:29 <DIR> d-------- C:\Program Files\Zoner
2007-08-08 16:30 19,456 --a------ C:\WINDOWS\system32\OnlineScannerLang.dll
2007-08-04 16:14 <DIR> d-------- C:\Program Files\Yahoo!
2007-08-04 16:14 <DIR> d-------- C:\Program Files\CCleaner
2007-08-04 09:33 7,502 --a------ C:\dnsbak.reg
2007-08-03 06:35 <DIR> d-------- C:\Program Files\IDLE DRIVE
2007-08-02 18:11 253,952 --a------ C:\WINDOWS\system32\OnlineScannerDLLA.dll
2007-08-02 18:11 241,664 --a------ C:\WINDOWS\system32\OnlineScannerDLLW.dll
2007-07-27 15:49 225,355 --a------ C:\WINDOWS\system32\lnod32apiW.dll
2007-07-27 15:49 196,683 --a------ C:\WINDOWS\system32\lnod32apiA.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-23 23:05 --------- d-------- C:\DOCUME~1\pik\APPLIC~1\Skype
2007-08-23 07:26 --------- d-------- C:\Program Files\ICQLite
2007-08-23 07:26 --------- d-------- C:\DOCUME~1\pik\APPLIC~1\Micropro
2007-08-23 07:13 1596 --a------ C:\Program Files\mrwuytgh.txt
2007-08-22 19:45 --------- d-------- C:\Program Files\Shrink Pic
2007-08-22 19:41 --------- d-------- C:\Program Files\Messenger
2007-08-12 19:53 --------- d-------- C:\DOCUME~1\pik\APPLIC~1\Zoner
2007-08-04 15:58 --------- d-------- C:\Program Files\microsoft frontpage
2007-07-15 15:29 --------- d-------- C:\DOCUME~1\pik\APPLIC~1\Happy Foto
2007-07-15 10:45 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-13 13:48 --------- d-------- C:\Program Files\Skype
2007-07-13 13:48 --------- d-------- C:\Program Files\Common Files\Skype
2007-07-08 15:36 --------- d-------- C:\Program Files\SourceTec
2007-07-07 16:21 --------- d-------- C:\Program Files\Oberon Media
2007-07-07 16:21 --------- d-------- C:\Program Files\Common Files\Oberon Media
2007-07-01 17:00 --------- d-------- C:\Program Files\GameSpy Arcade
2007-06-29 10:54 6363 --a------ C:\WINDOWS\system32\drivers\kwfupper.log
2007-06-29 10:54 4090 --a------ C:\WINDOWS\system32\drivers\kwflower.log
2007-06-29 09:32 --------- d-------- C:\Program Files\Jana2
2007-06-27 08:48 --------- d-------- C:\Program Files\Common Files\soft602
2007-06-13 11:10 77824 --a------ C:\WINDOWS\system32\OnlineScannerUninstaller.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CnxDslTaskBar"="c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" [2004-06-16 07:55]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-12-15 06:01]
"nwiz"="nwiz.exe" [2004-12-15 06:01 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-12-15 06:01]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 06:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 06:03]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 12:20 C:\WINDOWS\SOUNDMAN.EXE]
"WinampAgent"="C:\Software\Winamp\winampa.exe" [2004-12-20 20:41]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
"CCProxy"="C:\CCProxy\CCProxy.exe" []
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-08-23 08:41]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06]
"LDM"="C:\Software\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-27 16:51]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2005-08-18 15:15]
"SurfFast"="C:\DOCUME~1\pik\APPLIC~1\IDLEDR~1\datadrawwipe.exe" []
C:\Documents and Settings\pik\Start Menu\Programs\Startup\
Shrink Pic.lnk - C:\Program Files\Shrink Pic\shrink_pic.exe [2006-05-18 14:20:32]
Total Commander.lnk - C:\Software\totalcmd\TOTALCMD.EXE [2007-04-01 20:26:30]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Software\Adobe reader\Reader\reader_sl.exe [2005-09-24 08:05:26]
Logitech Desktop Messenger.lnk - C:\Software\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-27 16:51:36]
Logitech SetPoint.lnk - C:\Software\Logitech\SetPoint\SetPoint.exe [2006-10-28 11:46:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 23:05:56]
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
"C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
R0 sojubus;sojubus;C:\WINDOWS\system32\DRIVERS\sojubus.sys
R0 sojuscsi;sojuscsi;C:\WINDOWS\system32\DRIVERS\sojuscsi.sys
R1 sp_rsdrv2;Spyware Terminator Driver 2;\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
R2 Angelnt;Angelnt;C:\WINDOWS\system32\Drivers\ANGELNT.SYS
R3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys
R3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgNP.sys
R3 LUsbKbd;Logitech SetPoint USB Keyboard Filter;C:\WINDOWS\system32\Drivers\LUsbKbd.Sys
R3 PAC7311;Trust Webcam 14839;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys
S3 kvpndev;Kerio VPN adapter;C:\WINDOWS\system32\DRIVERS\kvpndrv.sys
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;C:\WINDOWS\system32\DRIVERS\kwflower.sys
S3 L8042mou;Logitech SetPoint PS/2 Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
Contents of the 'Scheduled Tasks' folder
2007-08-24 06:00:00 C:\WINDOWS\Tasks\A3062B739185DE43.job - c:\docume~1\pik\applic~1\idledr~1\Army Math Manager.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-24 08:01:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\srosa.sys
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\srosa]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\srosa.sys"
Completion time: 2007-08-24 8:02:39
C:\ComboFix-quarantined-files.txt ... 2007-08-24 08:02
--- E O F ---