ComboFix 08-01-23.1C - Rudo 2008-01-26 9:44:35.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.1.1250.1.1033.18.304 [GMT 1:00]
Running from: C:\Documents and Settings\Rudo\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\WINDOWS\system32\e1.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\xirxj77l.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-26 09:34 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-25 21:37 . 2008-01-25 21:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-22 19:34 . 2008-01-22 19:34 <DIR> d-------- C:\Program Files\Designsoft
2008-01-22 17:02 . 2008-01-22 19:34 32,230 --a------ C:\WINDOWS\Run32A50.mch
2008-01-22 17:01 . 2008-01-22 19:33 <DIR> d-------- C:\WINDOWS\A5W_DATA
2008-01-22 17:01 . 2008-01-22 19:33 35 --a------ C:\WINDOWS\A5W.INI
2008-01-22 06:03 . 2008-01-22 06:03 9,216 --a------ C:\WINDOWS\system32\e1.dll.vir
2008-01-22 06:03 . 2008-01-22 06:03 16 --a------ C:\WINDOWS\wensdw.dat
2008-01-22 06:02 . 2008-01-22 06:02 178,688 --a------ C:\WINDOWS\chater07.exe
2008-01-21 10:33 . 2008-01-26 07:14 <DIR> d-------- C:\Program Files\AdVantage
2008-01-16 16:16 . 2008-01-16 16:16 164 --a------ C:\WINDOWS\system32\1K0636o831.dat
2008-01-16 16:16 . 2008-01-16 16:16 160 --a------ C:\WINDOWS\system32\Ut33ubqXk7N.dat
2008-01-16 16:16 . 2008-01-16 16:16 148 --a------ C:\WINDOWS\system32\Ii3UG40OAx.dat
2008-01-16 16:16 . 2008-01-16 16:16 144 --a------ C:\WINDOWS\system32\sofdt-1760516353.dat
2008-01-16 16:13 . 2008-01-21 16:49 4 --a------ C:\WINDOWS\system32\davcgpte.dat
2008-01-16 14:57 . 2008-01-16 14:57 0 --a------ C:\WINDOWS\pensdw.s
2008-01-16 14:52 . 2008-01-16 15:13 5,440 --a------ C:\WINDOWS\pensdw.wax
2008-01-16 14:52 . 2008-01-16 14:52 16 --a------ C:\WINDOWS\pensdw.dat
2008-01-16 14:52 . 2008-01-16 14:52 0 --a------ C:\WINDOWS\pensdw.z
2008-01-16 05:07 . 2008-01-21 16:42 4,600 --a------ C:\WINDOWS\ferg.wax
2008-01-16 05:07 . 2008-01-16 05:07 16 --a------ C:\WINDOWS\ferg.dat
2008-01-16 04:57 . 2008-01-16 04:57 3,142,236 --a------ C:\WINDOWS\ow3g85.reg
2008-01-12 08:13 . 2008-01-22 06:02 4 --a------ C:\WINDOWS\system32\pngfuxth.dat
2008-01-07 19:04 . 2008-01-07 19:04 <DIR> d-------- C:\Program Files\Electronic Arts
2008-01-07 08:48 . 2008-01-07 08:48 <DIR> d-------- C:\EA Sports
2008-01-06 14:26 . 2008-01-10 16:41 13,030 --a------ C:\PDOXUSRS.NET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 06:15 439,552 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-01-25 19:08 --------- d-----w C:\Program Files\ICQToolbar
2008-01-23 16:49 --------- d-----w C:\Program Files\ICQLite
2008-01-22 05:02 178,688 ----a-w C:\WINDOWS\chater07.exe
2008-01-21 16:47 --------- d-----w C:\Program Files\OneStepSearch
2008-01-21 15:54 --------- d-----w C:\Program Files\Sunbelt Software
2008-01-21 09:33 --------- d-----w C:\Program Files\BSplayer Pro
2008-01-17 13:12 52,224 ----a-w C:\WINDOWS\system32\pop3enable.exe
2008-01-16 17:25 --------- d-----w C:\Program Files\Winamp
2008-01-13 13:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-06 19:17 --------- d-----w C:\Program Files\SopCast
2008-01-04 18:07 3,615 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-12-21 19:31 --------- d-----w C:\Program Files\QIP
2007-12-21 07:21 33,800 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-12-21 07:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 07:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-12-13 19:52 118,784 ----a-w C:\WINDOWS\system32\vp7vmcia.dll
2007-12-02 05:47 741,376 ----a-w C:\WINDOWS\system32\libeay32.dll
2007-12-02 05:47 155,648 ----a-w C:\WINDOWS\system32\ssleay32.dll
2007-11-24 16:11 41,984 ----a-w C:\WINDOWS\stk71.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 04:41 13312]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-11 06:21 1511453]
"RTEGPRS"="C:\Program Files\Common Files\RTE\RTEGPRS.exe" [2003-05-28 02:49 1056768]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-13 17:20 20058152]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"AdVantage"="C:\Program Files\AdVantage\AdVantage.exe" [2007-06-28 15:19 880080]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-27 19:12 3142236]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 15:07 49263]
"SmartSync - ScheduleSync"="C:\PROGRA~1\MOBILE~1\SMARTS~1\SCHEDU~1.EXE" [2006-03-31 00:49 45056]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 17:34 213936]
"CHotkey"="zHotkey.exe" [2003-07-29 17:06 515584 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 08:09 36864 C:\WINDOWS\ShowWnd.exe]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 15:17 159744]
"DAEMON Tools"="D:\DAEMON Tools\daemon.exe" [2005-12-10 16:57 133016]
"SoundMnEx32"="C:\WINDOWS\mmcc.exe" [ ]
"Sund32"="C:\WINDOWS\System32\gpthread32.exe" [ ]
"wmml1.101"="C:\WINDOWS\wmml1.101.exe" [ ]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]
"ferg"="C:\WINDOWS\ferg.exe" [ ]
"spup.exe"="C:\WINDOWS\chater07.exe" [2008-01-22 06:02 178688]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 08:21 1443072]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-27 19:12 3142236]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 04:41 13312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2001-08-23 13:00 51200 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Rudo\Start Menu\Programs\Startup\
Mobile Phone Manager.lnk - C:\Program Files\Mobile Phone Manager\bin\Mobile Phone Manager.exe [2006-04-04 04:49:24 503808]
PowerReg Scheduler V3.exe [2007-10-28 14:31:30 225280]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:00 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:00 734872]
Exif Launcher S.lnk - C:\Program Files\FinePixViewerS\QuickDCF2.exe [2007-07-10 20:15:43 303104]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 20:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\admewinr]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\davcgpte]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fpwprasa]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pngfuxth]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vdmdracp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vp7vmcia]
C:\WINDOWS\System32\vp7vmcia.dll 2007-12-13 20:52 118784 C:\WINDOWS\system32\vp7vmcia.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= comdavwa.dll ipxrir32.dll kbdgmqqm.dll inetcomu.dll s11twsht.dll ddragdi3.dll ru9j8i.dll e1.dll
R1 epfwtdir;epfwtdir;C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [2007-12-21 08:21]
R1 fwdrv;Firewall Driver;C:\WINDOWS\System32\drivers\fwdrv.sys [2007-02-20 12:34]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\System32\drivers\khips.sys [2007-02-20 12:34]
R2 MLPTDR_Q;MLPTDR_Q;C:\WINDOWS\System32\MLPTDR_Q.sys [2003-07-22 08:44]
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\System32\DRIVERS\psched.sys [2002-08-29 02:35]
S3 siusbmod;siusbmod;C:\WINDOWS\System32\DRIVERS\siusbmod.sys [2005-09-13 00:40]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\System32\DRIVERS\w200bus.sys [2006-11-07 08:42]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\System32\DRIVERS\w200mdfl.sys [2006-11-07 08:42]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\System32\DRIVERS\w200mdm.sys [2006-11-07 08:42]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\System32\DRIVERS\w200mgmt.sys [2006-11-07 08:42]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\System32\DRIVERS\w200obex.sys [2006-11-07 08:42]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SHAREDACCESS
.
Contents of the 'Scheduled Tasks' folder
"2008-01-19 16:53:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-26 08:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-26 09:49:13
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="zHotkey.exe"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\System32\e1.dll
-> C:\WINDOWS\System32\vp7vmcia.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.1106]
-> C:\WINDOWS\system32\e1.dll
.
Completion time: 2008-01-26 9:50:34
ComboFix-quarantined-files.txt 2008-01-26 08:50:27
..a mohol by mi niekto prosim potom aj povedat ci to je v poriadku alebo nie, diky