ComboFix 08-04-07.5 - Peter 2008-04-08 19:03:09.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1250.1.1029.18.554 [GMT 2:00]
Running from: C:\Users\Peter\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-08 to 2008-04-08 )))))))))))))))))))))))))))))))
.
2008-04-08 17:31 . 2008-04-08 17:31 1,086 --a------ C:\Windows\System32\tmp.reg
2008-04-08 17:30 . 2007-09-05 23:22 289,144 --a------ C:\Windows\System32\VCCLSID.exe
2008-04-08 17:30 . 2006-04-27 16:49 288,417 --a------ C:\Windows\System32\SrchSTS.exe
2008-04-08 17:30 . 2008-03-28 23:19 86,528 --a------ C:\Windows\System32\VACFix.exe
2008-04-08 17:30 . 2008-03-26 08:50 82,432 --a------ C:\Windows\System32\IEDFix.exe
2008-04-08 17:30 . 2003-06-05 20:13 53,248 --a------ C:\Windows\System32\Process.exe
2008-04-08 17:30 . 2004-07-31 17:50 51,200 --a------ C:\Windows\System32\dumphive.exe
2008-04-08 17:30 . 2007-10-03 23:36 25,600 --a------ C:\Windows\System32\WS2Fix.exe
2008-04-08 17:16 . 2008-04-08 16:23 <DIR> d-------- C:\Windows\Panther
2008-04-08 17:16 . 2006-11-02 11:53 438,840 -rahs---- C:\bootmgr
2008-04-08 17:16 . 2008-04-08 17:16 8,192 -ra-s---- C:\BOOTSECT.BAK
2008-04-08 17:11 . 2008-04-08 17:11 <DIR> d-------- C:\Users\Peter\AppData\Roaming\Talkback
2008-04-08 16:51 . 2008-04-08 16:51 <DIR> d-------- C:\Users\All Users\ESET
2008-04-08 16:51 . 2008-04-08 16:51 <DIR> d-------- C:\ProgramData\ESET
2008-04-08 16:51 . 2008-04-08 16:51 <DIR> d-------- C:\Program Files\ESET
2008-04-08 16:50 . 2008-04-08 16:52 <DIR> d--hs---- C:\Windows\Installer
2008-04-08 16:39 . 2008-04-08 16:39 1,712,984 --a------ C:\Windows\System32\wuaueng.dll
2008-04-08 16:39 . 2008-04-08 16:39 1,524,224 --a------ C:\Windows\System32\wucltux.dll
2008-04-08 16:39 . 2008-04-08 16:39 53,080 --a------ C:\Windows\System32\wuauclt.exe
2008-04-08 16:39 . 2008-04-08 16:39 43,352 --a------ C:\Windows\System32\wups2.dll
2008-04-08 16:36 . 2008-04-08 16:36 549,720 --a------ C:\Windows\System32\wuapi.dll
2008-04-08 16:36 . 2008-04-08 16:36 80,896 --a------ C:\Windows\System32\wudriver.dll
2008-04-08 16:36 . 2008-04-08 16:36 33,624 --a------ C:\Windows\System32\wups.dll
2008-04-08 16:35 . 2008-04-08 16:35 163,000 --a------ C:\Windows\System32\wuwebv.dll
2008-04-08 16:35 . 2008-04-08 16:35 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-04-08 16:30 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Searches
2008-04-08 16:30 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Contacts
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Videos
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Saved Games
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Pictures
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Music
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Links
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Downloads
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> dr------- C:\Users\Peter\Documents
2008-04-08 16:29 . 2006-11-02 14:35 <DIR> d-------- C:\Users\Peter\AppData\Roaming\Media Center Programs
2008-04-08 16:29 . 2008-04-08 16:30 <DIR> d--h----- C:\Users\Peter\AppData
2008-04-08 16:26 . 2008-04-08 16:26 <DIR> dr------- C:\Windows\System32\config\systemprofile\Contacts
2008-04-08 16:19 . 2008-04-08 17:27 <DIR> d-------- C:\Windows\System32\catroot2
2008-04-08 16:19 . 2008-04-08 16:26 <DIR> d-------- C:\Windows\Debug
2008-03-13 16:52 . 2008-03-13 16:52 33,800 --a------ C:\Windows\System32\drivers\epfwtdir.sys
2008-03-13 16:44 . 2008-03-13 16:44 29,704 --a------ C:\Windows\System32\drivers\easdrv.sys
2008-03-13 16:43 . 2008-03-13 16:43 40,456 --a------ C:\Windows\System32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 14:26 --------- d-sh--w C:\ProgramData\Plocha
2008-04-08 14:26 --------- d-sh--w C:\ProgramData\Oblíbené položky
2008-04-08 14:26 --------- d-sh--w C:\ProgramData\Šablony
2008-04-08 14:26 --------- d-sh--w C:\ProgramData\Nabídka Start
2008-04-08 14:26 --------- d-sh--w C:\ProgramData\Dokumenty
2008-04-08 14:26 --------- d-sh--w C:\ProgramData\Data aplikací
2006-11-02 12:49 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 14:33 1196032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 14:32 1004136]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R1 PSched;Plánovač paketů technologie QoS;C:\Windows\system32\DRIVERS\pacer.sys [2006-11-02 10:57]
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-08 19:05:02
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-08 19:05:44
ComboFix-quarantined-files.txt 2008-04-08 17:05:40
Adresářů: 5, Volných bajtů: 21,354,434,560
Adresářů: 10, Volných bajtů: 21,363,355,648
.
2008-04-08 15:30:18 --- E O F ---