Ti kokso to je ako Tutanchamonov rodný list či čo:
ComboFix 07-12-21.4 - tibi 2007-12-28 18:53:23.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.1.1250.1.1033.18.88 [GMT 1:00]
Running from: C:\Documents and Settings\tibi.SZABO\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\tibi.SZABO\Application Data\inst.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-28 )))))))))))))))))))))))))))))))
.
2007-12-28 14:58 . 2007-12-28 15:46 3,016 --a------ C:\WINDOWS\system32\tmp.reg
2007-12-28 01:42 . 2007-12-28 01:42 <DIR> d-------- C:\Program Files\VirusTotalUploader
2007-12-28 00:34 . 2007-12-28 00:34 <DIR> d-------- C:\Program Files\CCleaner
2007-12-27 00:39 . 2007-12-27 01:03 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\1Click DVD Copy
2007-12-26 21:24 . 2007-12-26 21:24 303 --a------ C:\WINDOWS\ST6UNST.000
2007-12-26 17:29 . 2007-12-28 00:44 <DIR> d-------- C:\Program Files\LG Software Innovations
2007-12-13 14:59 . 2007-12-13 14:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\vsosdk
2007-12-13 14:10 . 2007-12-27 01:00 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\1Click DVD Copy Pro
2007-12-13 14:08 . 2007-12-13 14:08 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-12-13 13:36 . 2007-12-13 13:38 <DIR> d-------- C:\Documents and Settings\tibi.SZABO\Application Data\dvdcss
2007-12-07 23:21 . 2007-12-11 00:35 <DIR> d-------- C:\WINDOWS\ULEAD.DAT
2007-12-07 23:21 . 2007-12-07 23:21 <DIR> d-------- C:\Program Files\iPhoto Plus 4
2007-12-07 23:21 . 1995-07-31 14:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2007-12-07 23:21 . 1996-03-16 01:00 39,936 --a------ C:\WINDOWS\system32\MFC40LOC.DLL
2007-12-07 23:21 . 1997-01-13 19:31 11,264 --a------ C:\WINDOWS\Ulead iPhoto Plus 4.SCR
2007-12-07 23:21 . 2007-12-20 17:02 869 --a------ C:\WINDOWS\Ulead32.ini
2007-12-07 23:18 . 2007-12-07 23:18 <DIR> d-------- C:\Documents and Settings\tibi.SZABO\WINDOWS
2007-12-07 23:17 . 2007-12-07 23:21 <DIR> d-------- C:\MSCAN
2007-12-04 20:28 . 2007-12-04 20:28 <DIR> d-------- C:\Program Files\xat.com JPEG Optimizer
2007-12-03 23:57 . 2007-12-03 23:57 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx
2007-12-03 23:56 . 2007-12-27 22:00 <DIR> d-------- C:\Documents and Settings\tibi.SZABO\Application Data\PrevxCSI
2007-12-02 22:59 . 2007-12-03 20:09 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-11-30 22:46 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-30 22:31 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-11-30 00:19 . 2007-11-30 00:19 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Tools
2007-11-29 23:25 . 2007-11-29 23:25 <DIR> d-------- C:\Documents and Settings\tibi.SZABO\Application Data\Grisoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-27 23:40 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-12-27 15:13 --------- d-----w C:\Documents and Settings\tibi.SZABO\Application Data\Skype
2007-12-26 23:55 --------- d-----w C:\Documents and Settings\tibi.SZABO\Application Data\Vso
2007-12-26 20:35 --------- d-----w C:\Program Files\Create-Ringtone
2007-12-26 20:34 --------- d-----w C:\Documents and Settings\tibi.SZABO\Application Data\AVG7
2007-12-26 16:29 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-26 16:29 47,360 ----a-w C:\Documents and Settings\tibi.SZABO\Application Data\pcouffin.sys
2007-12-23 19:08 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2007-12-22 16:33 --------- d-----w C:\Program Files\Visual Pinball
2007-12-22 16:33 --------- d-----w C:\Program Files\NCH Swift Sound
2007-12-22 16:33 --------- d-----w C:\Documents and Settings\tibi.SZABO\Application Data\NCH Swift Sound
2007-12-22 16:32 --------- d-----w C:\Program Files\NCH Software
2007-12-22 16:30 --------- d-----w C:\Program Files\Fastream NETFile
2007-12-22 15:34 --------- d-----w C:\Program Files\Perfect Keylogger Lite
2007-12-20 14:09 --------- d-----w C:\Program Files\autoUSD
2007-12-19 20:13 32,944 ----a-w C:\Documents and Settings\tibi.SZABO\Application Data\GDIPFONTCACHEV1.DAT
2007-12-18 08:37 --------- d-----w C:\Program Files\E404 Helper
2007-12-13 12:18 81,920 ----a-w C:\Documents and Settings\tibi.SZABO\Application Data\ezpinst.exe
2007-12-13 10:43 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\DVD Shrink
2007-11-30 21:33 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2007-11-29 22:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-11-25 10:46 19,200 ----a-w C:\WINDOWS\system32\drivers\xpnkgyxw.dat
2007-11-24 16:09 14,963,062 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_11_05_20_15_52_full.dmp.zip
2007-11-24 16:07 14,988,110 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_06_23_34_49_full.dmp.zip
2007-11-24 16:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-14 16:05 --------- d-----w C:\Program Files\Elaborate Bytes
2007-11-06 17:32 90,371 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_11_05_20_16_48_small.dmp.zip
2007-11-06 17:32 103,540 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_11_05_20_14_51_small.dmp.zip
2007-11-05 19:08 --------- d-----w C:\Documents and Settings\tibi.SZABO\Application Data\tor
2007-10-25 17:32 2,179,072 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-10-23 13:56 21 ----a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\emopts.dat
2007-10-08 18:18 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-10-07 06:57 102,339 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_06_23_33_29_small.dmp.zip
2007-09-30 15:09 52 ----a-w C:\re2.sys
2007-05-06 10:15 87,608 ----a-w C:\Documents and Settings\tibi\Application Data\ezpinst.exe
2007-05-06 10:15 47,360 ----a-w C:\Documents and Settings\tibi\Application Data\pcouffin.sys
2007-05-04 16:27 19,552 ----a-w C:\Documents and Settings\tibi\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC4A8086-CAF3-49D0-A168-54B9F35062EE}]
2001-08-23 12:00 83456 --a------ C:\WINDOWS\System32\d3di.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 03:41]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-06 13:30]
"BPK"="C:\Program Files\Perfect Keylogger Lite\bpk.exe" [2002-12-06 14:11]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-09-07 03:04]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-23 20:15]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-23 22:22]
"NeroFilterCheck"="C:\WINDOWS\System32\NeroCheck.exe" [2006-01-12 14:40]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2006-05-22 12:26]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-04-23 18:57]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 12:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"CleverCrypt"="C:\Program Files\Quantum Digital Security\CleverCrypt Lite\CleverCrypt.exe" [2005-01-14 11:56]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]
"combofix"="C:\WINDOWS\system32\cmd.exe" [2001-08-23 12:00]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 03:41]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58]
C:\Documents and Settings\tibi.SZABO\Start Menu\Programs\Startup\
Watch.lnk - C:\WINDOWS\twain_32\A4S2600X\WATCH.exe [2007-12-07 23:17:52]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winppl32]
winppl32.dll
R0 htecoioi;htecoioi;C:\WINDOWS\System32\drivers\xpnkgyxw.dat []
R3 mgau;mgau;C:\WINDOWS\System32\DRIVERS\mgaum.sys [2001-08-17 13:50]
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\System32\DRIVERS\psched.sys [2002-08-29 01:35]
R3 SFC4;SFC4;C:\WINDOWS\System32\drivers\SFC4.sys [1998-08-14 16:44]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-28 19:02:39
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2800.1106]
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\Program Files\Perfect Keylogger Lite\bsdhooks.dll
.
Completion time: 2007-12-28 19:05:18 - machine was rebooted