ComboFix 08-02.03.1 - Owner 2008-02-05 15:05:30.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.564 [GMT 1:00]
Running from: C:\Documents and Settings\Owner\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Plocha\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.
2008-02-04 16:37 . 2008-02-04 16:37 1,953,792 --a------ C:\WINDOWS\obchod.scr
2008-02-04 15:07 . 2008-02-05 07:37 1,542 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-04 15:06 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-04 15:06 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-04 15:06 . 2008-02-04 12:47 83,456 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-04 15:06 . 2008-01-27 14:37 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-04 15:06 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-04 15:06 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-04 15:06 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-30 19:01 . 2008-01-30 19:01 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-01-30 19:00 . 2008-02-04 17:48 <DIR> d-------- C:\Program Files\Dragonball Z Desktop Friends
2008-01-29 16:31 . 2008-01-29 16:31 32 --a------ C:\WINDOWS\thxcfg.ini
2008-01-27 06:42 . 2008-01-27 06:41 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-01-27 06:42 . 2008-01-27 06:41 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-01-27 06:42 . 2008-01-27 06:41 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-01-26 20:14 . 2008-01-26 20:14 200 --a------ C:\WINDOWS\fd3.INI
2008-01-26 20:13 . 2008-01-26 20:13 <DIR> d-------- C:\Program Files\Eltima Software
2008-01-26 19:57 . 2008-01-26 22:03 <DIR> d-------- C:\Program Files\Flash 32
2008-01-26 16:57 . 2008-01-26 16:57 <DIR> d-------- C:\Documents and Settings\Owner\Data aplikací\Eltima Software
2008-01-26 15:27 . 2008-01-26 15:27 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-01-26 15:27 . 2008-01-26 15:27 <DIR> d-------- C:\Program Files\Opera 9
2008-01-26 15:27 . 2008-01-26 15:28 <DIR> d-------- C:\Program Files\Macromedia
2008-01-26 15:27 . 2008-01-26 15:29 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-01-26 15:09 . 2008-02-03 07:31 <DIR> d-------- C:\Program Files\MediaEntertainmentCodec
2008-01-26 10:43 . 2008-01-26 10:43 <DIR> d-------- C:\Documents and Settings\Owner\Data aplikací\FastStone
2008-01-26 09:55 . 2008-01-26 10:50 <DIR> d-------- C:\flash-intro
2008-01-26 09:30 . 2008-01-26 15:09 <DIR> d-------- C:\Program Files\Flash4D v4.4 - Home Edition Trial
2008-01-26 09:14 . 2008-01-26 09:14 1,953,792 --a------ C:\WINDOWS\ddd.scr
2008-01-26 08:51 . 2008-01-26 08:51 <DIR> d-------- C:\Program Files\Wondershare
2008-01-26 08:51 . 2007-11-23 16:56 1,435,272 --a------ C:\WINDOWS\system32\Flash8.ocx
2008-01-24 17:43 . 2008-01-26 17:50 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-24 17:43 . 2008-01-26 17:50 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-24 17:26 . 2008-02-03 12:43 <DIR> d-------- C:\Program Files\Norton Internet Security
2008-01-24 17:25 . 2008-02-03 07:27 <DIR> d-------- C:\Program Files\Symantec
2008-01-24 17:25 . 2008-01-26 17:50 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-24 17:25 . 2008-01-26 17:50 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-20 18:04 . 2008-01-20 18:04 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Cadsoft
2008-01-20 18:03 . 2008-01-20 18:03 <DIR> d-------- C:\Program Files\Common Files\Cadsoft
2008-01-20 18:02 . 2008-01-20 18:02 <DIR> d-------- C:\Program Files\3D Home Architect
2008-01-20 18:02 . 2008-01-20 18:02 0 --a------ C:\WINDOWS\system32\_r_a_p_.tmp
2008-01-09 19:35 . 2008-01-09 19:35 <DIR> d-------- C:\Program Files\Rockstar Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-04 13:59 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\Skype
2008-02-03 07:59 --------- d-----w C:\Program Files\ESET
2008-02-03 06:32 --------- d-----w C:\Program Files\TrojanHunter 4.2
2008-02-02 21:27 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-02 18:46 --------- d-----w C:\Program Files\FlashFXP
2008-02-01 14:38 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Symantec
2008-01-28 13:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-27 16:25 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-01-26 21:08 132,242 ----a-w C:\Documents and Settings\All Users\Data aplikací\firstlsp.reg.dat
2008-01-26 10:05 --------- d-----w C:\Program Files\SWiSH v2.01
2008-01-26 09:26 --------- d-----w C:\Program Files\Codec Pack - All In 1
2008-01-23 19:43 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\DivX
2008-01-20 17:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-14 13:26 --------- d-----w C:\Program Files\DivX
2008-01-13 12:52 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2008-01-02 19:22 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\PHP Designer 2007
2008-01-02 18:56 --------- d-----w C:\Program Files\EasyPHP1-8
2008-01-01 18:07 --------- d-----w C:\Program Files\Valve
2007-12-31 22:33 --------- d-----w C:\Program Files\Java
2007-12-31 22:32 --------- d-----w C:\Program Files\Common Files\Java
2007-12-31 08:52 --------- d-----w C:\Program Files\ElcomSoft
2007-12-31 08:52 --------- d-----w C:\Program Files\BitSpirit
2007-12-31 08:51 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\uTorrent
2007-12-27 15:35 --------- d-----w C:\Program Files\DVDVideoSoft
2007-12-27 15:35 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2007-12-27 15:27 --------- d-----w C:\Program Files\WAV To MP3 Plus
2007-12-27 12:14 --------- d-----w C:\Program Files\THQ
2007-12-23 16:10 --------- d-----w C:\Program Files\ScannerU
2007-12-23 09:53 --------- d-----w C:\Program Files\Groove Games
2007-12-23 09:24 --------- d-----w C:\Program Files\Counter-Strike 1.6 Patch Version 26
2007-12-15 20:27 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\ESET
2007-12-15 20:26 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Eset
2007-12-14 17:33 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-13 20:07 --------- d-----w C:\Documents and Settings\Owner\Data aplikací\DMCache
2007-12-07 09:54 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2007-12-06 14:10 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-12-05 16:39 --------- d-----w C:\Program Files\Play+Smile
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-11-29 22:30 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-07 09:29 720,896 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-07-06 06:55 13 ------w C:\Documents and Settings\All Users\Data aplikací\ÝĂÄ3113.sys
2004-10-01 14:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2007-07-08 07:11 6,465 --sha-w C:\WINDOWS\system32\pstwa.bak1
2007-07-19 11:16 885,814 --sha-w C:\WINDOWS\system32\pstwa.bak2
2007-07-20 05:35 1,025,948 --sh--w C:\WINDOWS\system32\pstwa.ini2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 10:26 86016]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"WEBTRAN"="" []
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2006-01-29 14:22 200747]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 13:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"EVEREST AutoStart"="C:\Program Files\Lavalys\EVEREST Ultimate Edition\everest.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-01-27 06:41 949376]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 14:43 7630848]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"aswmklt"= {B9C7E145-4440-4AB9-A0C6-5C7B53F53B98} - C:\WINDOWS\aswmklt.dll [ ]
R1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys [2007-10-11 13:53]
R2 InterBaseGuardian;InterBase Guardian;C:\Program Files\InterBase\bin\ibguard.exe [2001-01-05 11:41]
R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2007-07-17 15:53]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2004-01-08 07:54]
R2 Prvflder;Prvflder;C:\WINDOWS\system32\DRIVERS\prvflder.sys [2006-04-21 07:22]
R2 UMAXPCLS;Ovladač skeneru na portu tiskárny;C:\WINDOWS\system32\DRIVERS\umaxpcls.sys [2001-08-17 20:58]
R3 FlarionDTM;Flarion DTM Network Interface;C:\WINDOWS\system32\DRIVERS\FlrnDTM.sys [2005-05-26 14:06]
R3 InterBaseServer;InterBase Server;C:\Program Files\InterBase\bin\ibserver.exe [2001-01-05 11:40]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-18 13:00]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 GT680xNT;Astra 2600 USB Scanner Driver;C:\WINDOWS\system32\drivers\gt680x.sys [2002-10-03 16:32]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{357b444c-bf38-11db-9efa-001617d3d221}]
\Shell\AutoRun\command - F:\load.exe /CDROM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e193f5d8-ba10-11db-9edf-001617d3d221}]
\Shell\AutoRun\command - F:\load.exe /CDROM
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-05 15:11:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-05 15:14:46
ComboFix-quarantined-files.txt 2008-02-05 14:14:43
ComboFix2.txt 2008-02-04 13:13:14
ComboFix3.txt 2008-02-04 13:07:47
ComboFix4.txt 2008-02-03 09:31:49
ComboFix5.txt 2007-10-27 12:54:47
.
2008-01-09 20:57:29 --- E O F ---