Kód:
ComboFix 07-08-14.4 - "Administrator" 2007-08-16 13:35:46.1 - NTFSx86 NETWORK
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.1799 [GMT 2:00]
((((((((((((((((((((((((( Files Created from 2007-07-16 to 2007-08-16 )))))))))))))))))))))))))))))))
2007-08-16 13:35 51,200 --a------ D:\WINDOWS2\nircmd.exe
2007-08-16 12:23 0 --a------ D:\WINDOWS2\nsreg.dat
2007-08-16 12:18 <DIR> d-------- D:\DOCUME~1\ADMINI~1\APPLIC~1\ICQ
2007-08-16 11:05 <DIR> d--hs---- D:\WINDOWS2\CSC
2007-08-16 10:46 <DIR> d-------- D:\WINDOWS2\LastGood.Tmp
2007-08-16 09:05 3,332 --a------ D:\WINDOWS2\mozver.dat
2007-08-16 09:03 <DIR> d-------- D:\DOCUME~1\JUNIBE~1.JUN\APPLIC~1\Opera
2007-08-16 09:02 229,376 --a------ D:\DOCUME~1\LOCALS~1.NTA\ntuser.dat
2007-08-16 09:02 1,835,008 --a------ D:\DOCUME~1\JUNIBE~1.JUN\ntuser.dat
2007-08-16 05:49 21,504 --a--c--- D:\WINDOWS2\system32\dllcache\hidserv.dll
2007-08-16 05:49 21,504 --a------ D:\WINDOWS2\system32\hidserv.dll
2007-08-16 05:49 14,848 --a--c--- D:\WINDOWS2\system32\dllcache\kbdhid.sys
2007-08-16 05:49 14,848 --a------ D:\WINDOWS2\system32\drivers\kbdhid.sys
2007-08-16 05:48 31,616 --a--c--- D:\WINDOWS2\system32\dllcache\usbccgp.sys
2007-08-16 05:48 31,616 --a------ D:\WINDOWS2\system32\drivers\usbccgp.sys
2007-08-15 22:06 <DIR> d-------- D:\Program Files\Logitech
2007-08-15 22:06 <DIR> d-------- D:\Program Files\Common Files\Logitech
2007-08-15 22:06 <DIR> d-------- D:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Logitech
2007-08-15 15:36 5,632 --a------ D:\WINDOWS2\system32\drivers\Entech64.sys
2007-08-15 15:36 3,972 --a------ D:\WINDOWS2\system32\drivers\PciBus.sys
2007-08-15 15:36 21,664 --a------ D:\WINDOWS2\system32\drivers\Entech.sys
2007-08-15 15:36 <DIR> d-------- D:\WINDOWS2\system32\Futuremark
2007-08-15 15:00 2,944 --a------ D:\WINDOWS2\system32\mbmiodrvr.sys
2007-08-15 14:11 <DIR> d-------- D:\DOCUME~1\JUNIBE~1.JUN\APPLIC~1\DisplayTune
2007-08-15 14:10 11,776 --a------ D:\WINDOWS2\system32\drivers\pdiddcci.sys
2007-08-15 14:09 974,848 --a------ D:\WINDOWS2\mfc70.dll
2007-08-15 14:09 95,744 --a------ D:\WINDOWS2\atl80.dll
2007-08-15 14:09 69,632 --a------ D:\WINDOWS2\mfcm80.dll
2007-08-15 14:09 626,688 --a------ D:\WINDOWS2\msvcr80.dll
2007-08-15 14:09 57,344 --a------ D:\WINDOWS2\mfcm80u.dll
2007-08-15 14:09 548,864 --a------ D:\WINDOWS2\msvcp80.dll
2007-08-15 14:09 487,424 --a------ D:\WINDOWS2\msvcp70.dll
2007-08-15 14:09 479,232 --a------ D:\WINDOWS2\msvcm80.dll
2007-08-15 14:09 372,736 --a------ D:\WINDOWS2\ijl15.dll
2007-08-15 14:09 344,064 --a------ D:\WINDOWS2\msvcr70.dll
2007-08-15 14:09 15,920 --a------ D:\WINDOWS2\system32\drivers\PdiPorts.sys
2007-08-15 14:09 1,392,671 --a------ D:\WINDOWS2\msvbvm60.dll
2007-08-15 14:09 1,093,632 --a------ D:\WINDOWS2\mfc80.dll
2007-08-15 14:09 1,079,808 --a------ D:\WINDOWS2\mfc80u.dll
2007-08-15 14:09 <DIR> d-------- D:\Program Files\Portrait Displays
2007-08-15 14:09 <DIR> d-------- D:\Program Files\Common Files\Portrait Displays
2007-08-02 07:22 765,952 --a------ D:\WINDOWS2\system32\xvidcore.dll
2007-08-02 07:22 740,442 --a------ D:\WINDOWS2\system32\divx.dll
2007-08-02 07:22 73,728 --a------ D:\WINDOWS2\system32\dpl100.dll
2007-08-02 07:22 7,680 --a------ D:\WINDOWS2\system32\ff_vfw.dll
2007-08-02 07:22 348,160 --a------ D:\WINDOWS2\system32\msvcr71.dll
2007-08-02 07:22 3,596,288 --a------ D:\WINDOWS2\system32\qt-dx331.dll
2007-08-02 07:22 217,088 --a------ D:\WINDOWS2\system32\yv12vfw.dll
2007-08-02 07:22 180,224 --a------ D:\WINDOWS2\system32\xvidvfw.dll
2007-08-02 07:22 163,840 --a------ D:\WINDOWS2\system32\unrar.dll
2007-08-02 07:20 <DIR> d-------- D:\WINDOWS2\pss
2007-08-02 07:19 85,376 --a------ D:\WINDOWS2\system32\drivers\NABTSFEC.sys
2007-08-02 07:19 53,760 --a------ D:\WINDOWS2\system32\vfwwdm32.dll
2007-08-02 07:19 5,504 --a------ D:\WINDOWS2\system32\drivers\MSTEE.sys
2007-08-02 07:19 363,520 --a------ D:\WINDOWS2\system32\PsisDecd.dll
2007-08-02 07:19 19,328 --a------ D:\WINDOWS2\system32\drivers\WSTCODEC.SYS
2007-08-02 07:19 17,024 --a------ D:\WINDOWS2\system32\drivers\CCDECODE.sys
2007-08-02 07:19 15,360 --a------ D:\WINDOWS2\system32\drivers\StreamIP.sys
2007-08-02 07:19 15,360 --a------ D:\WINDOWS2\system32\drivers\MPE.sys
2007-08-02 07:19 11,776 --a------ D:\WINDOWS2\system32\drivers\BdaSup.sys
2007-08-02 07:19 11,136 --a------ D:\WINDOWS2\system32\drivers\SLIP.sys
2007-08-02 07:19 10,880 --a------ D:\WINDOWS2\system32\drivers\NdisIP.sys
2007-08-02 07:12 169,344 --a------ D:\WINDOWS2\system32\drivers\atinavt2.sys
2007-08-02 07:11 520,192 --------- D:\WINDOWS2\system32\ati2sgag.exe
2007-08-01 19:17 3,072 --a------ D:\WINDOWS2\system32\drivers\audstub.sys
2007-08-01 19:17 25,856 --a------ D:\WINDOWS2\system32\drivers\usbprint.sys
2007-08-01 19:16 6,400 --a------ D:\WINDOWS2\system32\drivers\enum1394.sys
2007-08-01 19:16 57,472 --a------ D:\WINDOWS2\system32\drivers\redbook.sys
2007-08-01 19:15 74,240 --a--c--- D:\WINDOWS2\system32\dllcache\usbui.dll
2007-08-01 19:15 74,240 --a------ D:\WINDOWS2\system32\usbui.dll
2007-08-01 19:14 6,144 -ra------ D:\WINDOWS2\system32\kbdtuq.dll
2007-08-01 19:14 6,144 -ra------ D:\WINDOWS2\system32\kbdtuf.dll
2007-08-01 19:14 6,144 --a--c--- D:\WINDOWS2\system32\dllcache\kbdtuq.dll
2007-08-01 19:14 6,144 --a--c--- D:\WINDOWS2\system32\dllcache\kbdtuf.dll
2007-08-01 19:14 5,632 -ra------ D:\WINDOWS2\system32\kbdmon.dll
2007-08-01 19:14 5,632 -ra------ D:\WINDOWS2\system32\kbdkyr.dll
2007-08-01 19:14 5,632 -ra------ D:\WINDOWS2\system32\kbdazel.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdycc.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbduzb.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdur.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdtat.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdru1.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdru.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdmon.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdkyr.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdkaz.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdbu.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdblr.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdazel.dll
2007-08-01 19:14 5,632 --a--c--- D:\WINDOWS2\system32\dllcache\kbdaze.dll
2007-08-01 19:14 22,016 --a--c--- D:\WINDOWS2\system32\dllcache\agt0408.dll
2007-08-01 19:14 19,456 --a--c--- D:\WINDOWS2\system32\dllcache\agt041f.dll
2007-08-01 19:14 19,456 --a--c--- D:\WINDOWS2\system32\dllcache\agt0419.dll
2007-08-01 19:14 <DIR> d--hs---- D:\WINDOWS2\Installer
2007-08-01 19:13 9,936 --a------ D:\WINDOWS2\system\LZEXPAND.DLL
2007-08-01 19:13 9,008 --a------ D:\WINDOWS2\system\VER.DLL
2007-08-01 19:13 85,020 --a--c--- D:\WINDOWS2\system32\dllcache\dgsetup.dll
2007-08-01 19:13 85,020 --a------ D:\WINDOWS2\system32\dgsetup.dll
2007-08-01 19:13 82,944 --a------ D:\WINDOWS2\system\OLECLI.DLL
2007-08-01 19:13 8,704 --a--c--- D:\WINDOWS2\system32\dllcache\batt.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2017-05-04 19:43 --------- d-------- D:\Program Files\Microsoft.NET
2017-05-04 19:41 --------- d-------- D:\Program Files\Common Files\SpeechEngines
2017-05-04 19:41 --------- d-------- D:\Program Files\Common Files\ODBC
2017-05-04 19:11 --------- d-------- D:\Program Files\hp deskjet 3820 series
2017-05-04 19:10 --------- d-------- D:\Program Files\Hewlett-Packard
2017-05-04 18:46 --------- d-------- D:\Program Files\Common Files\Hewlett-Packard
2017-05-04 18:35 --------- d-------- D:\Program Files\My Company Name
2017-05-04 18:32 --------- d-------- D:\Program Files\Common Files\ATI Technologies
2017-05-04 18:19 --------- d-------- D:\Program Files\Realtek
2017-05-04 18:14 --------- d-------- D:\Program Files\Analog Devices
2017-05-04 18:07 --------- d-------- D:\Program Files\Intel
2017-05-04 17:51 --------- d-------- D:\Program Files\microsoft frontpage
2017-05-04 17:50 --------- d--h----- D:\Program Files\WindowsUpdate
2017-05-04 17:49 --------- d-------- D:\Program Files\Movie Maker
2017-05-04 17:49 --------- d-------- D:\Program Files\Common Files\MSSoap
2017-05-04 17:48 --------- d-------- D:\Program Files\Online Services
2017-05-04 17:48 --------- d-------- D:\Program Files\MSN Gaming Zone
2017-05-04 17:47 --------- d-------- D:\Program Files\Windows NT
2007-08-16 10:45 --------- d--h----- D:\Program Files\InstallShield Installation Information
2007-08-02 07:22 --------- d-------- D:\Program Files\K-Lite Codec Pack
2007-08-01 17:32 8972 --a------ D:\WINDOWS2\pchealth\helpctr\Config\Cntstore.bin
2007-08-01 17:32 5218 --a------ D:\WINDOWS2\pchealth\helpctr\PackageStore\SkuStore.bin
2007-08-01 17:22 --------- d-------- D:\Program Files\Messenger
2007-07-29 10:20 --------- d-------- D:\Program Files\ATI Technologies
2007-07-10 13:54 --------- d-------- D:\Program Files\GamePark
2007-07-09 15:04 --------- d-------- D:\Program Files\SmartSound Software
2007-07-09 06:26 --------- d-------- D:\Program Files\Live_TV
2007-06-29 13:53 --------- d-------- D:\Program Files\Nokia
2007-06-29 13:53 --------- d-------- D:\Program Files\Intuwave
2007-06-29 13:51 --------- d-------- D:\Program Files\Epocware
2007-06-27 04:27 44240 --a------ D:\WINDOWS2\system32\drivers\ativvpxx.vp
2007-06-27 03:59 344064 --a------ D:\WINDOWS2\system32\ATIDEMGX.dll
2007-06-27 03:58 269312 --a--c--- D:\WINDOWS2\system32\dllcache\ati2dvag.dll
2007-06-27 03:58 269312 --a------ D:\WINDOWS2\system32\ati2dvag.dll
2007-06-27 03:58 2303488 --a--c--- D:\WINDOWS2\system32\dllcache\ati2mtag.sys
2007-06-27 03:58 2303488 --a------ D:\WINDOWS2\system32\drivers\ati2mtag.sys
2007-06-27 03:56 307200 --a------ D:\WINDOWS2\system32\atiiiexx.dll
2007-06-27 03:51 26112 --a------ D:\WINDOWS2\system32\Ati2mdxx.exe
2007-06-27 03:51 143360 --a------ D:\WINDOWS2\system32\atipdlxx.dll
2007-06-27 03:51 122880 --a------ D:\WINDOWS2\system32\Oemdspif.dll
2007-06-27 03:50 43520 --a------ D:\WINDOWS2\system32\ati2edxx.dll
2007-06-27 03:50 118784 --a------ D:\WINDOWS2\system32\ati2evxx.dll
2007-06-27 03:49 483328 --a------ D:\WINDOWS2\system32\ati2evxx.exe
2007-06-27 03:48 53248 --a------ D:\WINDOWS2\system32\ATIDDC.DLL
2007-06-27 03:44 8232960 --a------ D:\WINDOWS2\system32\atioglx2.dll
2007-06-27 03:41 2940992 --a--c--- D:\WINDOWS2\system32\dllcache\ati3duag.dll
2007-06-27 03:41 2940992 --a------ D:\WINDOWS2\system32\ati3duag.dll
2007-06-27 03:31 1519744 --a--c--- D:\WINDOWS2\system32\dllcache\ativvaxx.dll
2007-06-27 03:31 1519744 --a------ D:\WINDOWS2\system32\ativvaxx.dll
2007-06-27 03:19 5435392 --a------ D:\WINDOWS2\system32\atioglxx.dll
2007-06-27 03:17 266240 --a------ D:\WINDOWS2\system32\atikvmag.dll
2007-06-27 03:16 17408 --a------ D:\WINDOWS2\system32\atitvo32.dll
2007-06-27 03:15 49152 --a------ D:\WINDOWS2\system32\drivers\ati2erec.dll
2007-06-27 03:14 176128 --a------ D:\WINDOWS2\system32\atiok3x2.dll
2007-06-27 03:10 376832 --a--c--- D:\WINDOWS2\system32\dllcache\ati2cqag.dll
2007-06-27 03:10 376832 --a------ D:\WINDOWS2\system32\ati2cqag.dll
2007-06-25 12:18 --------- d-------- D:\Program Files\Asus
2007-06-24 09:22 --------- d-------- D:\Program Files\LCDHype
2007-06-23 14:41 --------- d-------- D:\Program Files\Common Files\Macromedia Shared
2007-06-21 08:30 --------- d-------- D:\Program Files\Bonjour
2007-06-20 16:32 --------- d-------- D:\Program Files\Common Files\Macrovision Shared
2007-06-20 06:38 --------- d-------- D:\Program Files\VVSN
2007-06-18 17:59 --------- d-------- D:\Program Files\Common Files\LightScribe
2007-06-18 16:01 --------- d-------- D:\Program Files\Common Files\Ahead
2007-06-18 15:57 --------- d-------- D:\Program Files\Nero
2006-06-23 08:48 32768 -ra------ D:\WINDOWS2\inf\UpdateUSB.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="D:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 12:07]
"SoundMAX"="D:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 09:19]
"DT LGE"="D:\Program Files\Portrait Displays\forteManager\DTHtml.exe" [2007-02-01 15:07]
"Launch LGDCore"="D:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 03:22]
"MSConfig"="D:\WINDOWS2\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 14:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS2\system32\CTFMON.EXE" [2004-08-04 14:00]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X Configure]
D:\WINDOWS2\system32\JMRaidTool.exe boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon]
"D:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
R0 JGOGO;JMicron Hot-Plug Driver;D:\WINDOWS2\system32\DRIVERS\JGOGO.sys
R0 JRAID;JRAID;D:\WINDOWS2\system32\DRIVERS\jraid.sys
R0 speedfan;speedfan;D:\WINDOWS2\system32\speedfan.sys
R3 PSched;QoS Packet Scheduler;D:\WINDOWS2\system32\DRIVERS\psched.sys
S1 ATITool;ATITool Overclocking Utility;D:\WINDOWS2\system32\DRIVERS\ATITool.sys
S1 atitray;atitray;\??\E:\programy\overclocking\ATI Tray Tools\atitray.sys
S1 hwinterface;hwinterface;D:\WINDOWS2\system32\Drivers\hwinterface.sys
S3 pdiddcci;DDC/CI monitor;D:\WINDOWS2\system32\DRIVERS\pdiddcci.sys
S3 PdiPorts;Portrait Displays low level device driver;D:\WINDOWS2\system32\Drivers\PdiPorts.sys
S3 SenFiltService;SenFilt Service;D:\WINDOWS2\system32\drivers\Senfilt.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
Contents of the 'Scheduled Tasks' folder
2007-08-03 08:19:13 D:\WINDOWS2\Tasks\1-Click Maintenance.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-16 13:37:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-16 13:37:31
--- E O F ---