tak tu je ten log z ComboFix ale nebol robeny v nudzovom rezime!
ComboFix 07-11-19.3 - Dano 2007-11-23 22:01:45.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.442 [GMT 1:00]
Running from: C:\Documents and Settings\Dano\Dokumenty\Downloads\Programy\ComboFix\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.
2007-11-23 20:32 <DIR> d-------- C:\Documents and Settings\GARDENA\Data aplikací\GRETECH
2007-11-23 19:02 12,096 --a------ C:\WINDOWS\system32\drivers\AsInsHelp64.sys
2007-11-23 19:02 10,304 --a------ C:\WINDOWS\system32\drivers\AsInsHelp32.sys
2007-11-11 13:14 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-11-10 14:06 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Test Drive Unlimited
2007-11-10 14:00 <DIR> dr-h----- C:\Documents and Settings\Dano\Data aplikací\SecuROM
2007-11-09 23:05 <DIR> d-------- C:\Documents and Settings\Dano\Data aplikací\Symantec
2007-11-09 21:05 <DIR> d-------- C:\Documents and Settings\GARDENA\Data aplikací\Symantec
2007-11-09 20:35 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-11-09 20:34 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-09 20:33 <DIR> d-------- C:\Program Files\Symantec
2007-11-09 20:33 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-09 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Symantec
2007-11-09 20:32 <DIR> d-------- C:\norton
2007-11-08 18:42 <DIR> d-------- C:\Documents and Settings\GARDENA\Data aplikací\AdobeUM
2007-11-06 06:42 <DIR> d-------- C:\Documents and Settings\GARDENA\Plocha
2007-11-06 06:42 <DIR> d--h----- C:\Documents and Settings\GARDENA\Okolní tiskárny
2007-11-06 06:42 <DIR> d--h----- C:\Documents and Settings\GARDENA\Okolní síť
2007-11-06 06:42 <DIR> dr------- C:\Documents and Settings\GARDENA\Oblíbené položky
2007-11-06 06:42 <DIR> d--h----- C:\Documents and Settings\GARDENA\Šablony
2007-11-06 06:42 <DIR> dr------- C:\Documents and Settings\GARDENA\Nabídka Start
2007-11-06 06:42 <DIR> dr------- C:\Documents and Settings\GARDENA\Dokumenty
2007-11-06 06:42 <DIR> d-------- C:\Documents and Settings\GARDENA\Data aplikací\PC Suite
2007-11-06 06:42 <DIR> d-------- C:\Documents and Settings\GARDENA\Data aplikací\ATI
2007-11-06 06:42 <DIR> dr-h----- C:\Documents and Settings\GARDENA\Data aplikací
2007-10-30 20:21 29,808 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000003-00000000-00000006-00001102-00000002-80641102}.rfx
2007-10-30 20:21 29,808 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000003-00000000-00000006-00001102-00000002-80641102}.rfx
2007-10-30 20:21 17,500 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000003-00000000-00000006-00001102-00000002-80641102}.rfx
2007-10-30 20:21 17,500 --a------ C:\WINDOWS\system32\BMXState-{00000003-00000000-00000006-00001102-00000002-80641102}.rfx
2007-10-30 20:21 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000003-00000000-00000006-00001102-00000002-80641102}.dat
2007-10-30 20:21 24 --a------ C:\WINDOWS\system32\DVCState-{00000003-00000000-00000006-00001102-00000002-80641102}.dat
2007-10-30 19:02 837,548 --a------ C:\WINDOWS\system32\drivers\ctaud2k.sys
2007-10-30 19:02 195,432 --a------ C:\WINDOWS\system32\drivers\ctoss2k.sys
2007-10-30 19:02 127,948 --a------ C:\WINDOWS\system32\drivers\ctac32k.sys
2007-10-30 19:02 110,592 --a------ C:\WINDOWS\system32\PIAPROXY.DLL
2007-10-30 19:02 36,864 --a------ C:\WINDOWS\system32\REGPLIB.EXE
2007-10-30 19:01 32,768 --a------ C:\WINDOWS\system32\AudioHQU.cpl
2007-10-30 19:01 12,288 --a------ C:\WINDOWS\system32\AHQCpURes.dll
2007-10-30 19:00 6,752 --------- C:\WINDOWS\system32\PFMODNT.SYS
2007-10-30 18:59 <DIR> d-------- C:\Program Files\Creative
2007-10-29 14:46 8,576 --a--c--- C:\WINDOWS\system32\dllcache\hidgame.sys
2007-10-28 18:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-23 20:16 --------- d-----w C:\Program Files\SpeedFan
2007-11-23 15:15 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\Skype
2007-11-20 19:44 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\uTorrent
2007-11-18 10:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-18 10:15 --------- d-----w C:\Program Files\ASUS
2007-11-09 22:16 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-09 22:16 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-09 22:16 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-09 19:35 10,344 ----a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-11-09 19:27 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab
2007-11-08 18:40 --------- d-----w C:\Program Files\Java
2007-10-29 16:06 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\PC Suite
2007-10-22 20:25 491,520 ----a-w C:\WINDOWS\WebIE.dll
2007-10-22 20:25 45,056 ----a-w C:\WINDOWS\TRNOEH.DLL
2007-10-22 20:25 356,352 ----a-w C:\WINDOWS\TrnOutl.dll
2007-10-22 20:25 294,912 ----a-w C:\WINDOWS\TrnWord.dll
2007-10-22 20:25 26,624 ----a-w C:\WINDOWS\OETRN.EXE
2007-10-22 20:25 200,704 ----a-w C:\WINDOWS\TRNOET.DLL
2007-10-22 20:23 516,096 ----a-w C:\WINDOWS\UN32.EXE
2007-10-21 20:41 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\AdobeUM
2007-10-21 18:05 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\Miranda
2007-10-19 17:58 --------- d-----w C:\Program Files\Orban
2007-10-17 20:10 --------- d-----w C:\Program Files\hp deskjet 920c series
2007-10-17 20:06 --------- d-----w C:\Program Files\Hewlett-Packard
2007-10-16 18:38 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\GRETECH
2007-10-16 18:37 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\GRETECH
2007-10-16 18:19 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\Winamp 5.5
2007-10-16 17:36 --------- d-----w C:\Program Files\Winamp Remote
2007-10-16 17:32 --------- d-----w C:\Program Files\Winamp Toolbar
2007-10-16 17:32 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar
2007-10-16 17:32 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\OrbNetworks
2007-10-14 20:24 --------- d-----w C:\Program Files\ATI
2007-10-14 20:24 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ATI
2007-10-14 20:16 --------- d-----w C:\Program Files\ATI Technologies
2007-10-10 14:32 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\Apple Computer
2007-10-10 13:24 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-10-09 20:14 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2007-10-06 16:23 --------- d-----w C:\Documents and Settings\Dano\Data aplikací\Talkback
2007-10-05 17:36 12,528 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-01 13:49 98,184 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-01 13:49 542,088 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-01 13:49 31,624 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-01 13:49 28,040 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-01 13:49 23,944 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-01 13:49 189,320 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-01 13:49 161,160 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-01 13:48 12,680 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-09-30 05:44 --------- d-----w C:\Program Files\Common Files\DirectX
2007-09-29 12:31 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-29 12:29 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Adobe Systems
2007-09-29 12:28 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2007-09-29 07:42 --------- d-----w C:\Program Files\Futuremark
2007-09-29 06:35 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-09-29 05:46 47,376 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-09-29 03:21 9,854,976 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-09-29 03:07 356,352 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-09-29 03:06 268,800 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-09-29 03:05 2,456,064 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-09-29 02:58 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-09-29 02:58 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-09-29 02:58 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-09-29 02:58 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-09-29 02:57 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-09-29 02:56 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-09-29 02:55 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-09-29 02:49 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-09-29 02:47 3,130,720 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-09-29 02:47 172,032 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-09-29 02:36 1,593,600 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-09-29 02:23 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-09-29 02:22 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-09-29 02:20 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-09-29 02:19 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-09-29 02:14 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-09-28 19:08 --------- d-----w C:\Program Files\uTorrent
2007-09-28 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-09-28 13:26 451,072 ----a-w C:\WINDOWS\Radeon Omega Drivers v3.8.360 Uninstall.exe
2007-09-28 13:26 --------- d-----w C:\Program Files\Radeon Omega Drivers
2007-09-25 14:51 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-09-23 14:53 676,266 ----a-w C:\WINDOWS\unins000.exe
2007-09-07 17:58 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 21:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 21:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 21:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"AtiTrayTools"="D:\DANO\PROGRAMY\NAINSTALOVANÉ\ATI Tray Tools\atitray.exe" []
"updateMgr"="D:\DANO\PROGRAMY\NAINSTALOVANÉ\Acrobat Reader 7.0\Reader\AdobeUpdateManager.exe" []
"OEXPRESS"="C:\WINDOWS\OETRN.EXE" [2007-10-22 21:25]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"PCSuiteTrayApplication"="D:\DANO\PROGRAMY\NAINSTALOVANÉ\NOKIA PC Suite\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
"QuickTime Task"="D:\DANO\PROGRAMY\NAINSTALOVANÉ\QuickTime\qttask.exe" [2007-06-29 05:24]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-29 20:19]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 01:00]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2007-01-16 11:26]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 14:49]
"Nokia.PCSync"="D:\DANO\PROGRAMY\NAINSTALOVANÉ\NOKIA PC Suite\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17]
R1 ATITool;ATITool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\ATITool.sys
R1 atitray;atitray;\??\C:\Program Files\Radeon Omega Drivers\v3.8.360\ATI Tray Tools\atitray.sys
R2 ATIWebPAM;ATI WebPAM;"C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe" -s wrapper.conf
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 RivaTuner32;RivaTuner32;\??\D:\DANO\PROGRAMY\NAINSTALOVANÉ\RivaTuner v2.03\RivaTuner32.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45fe9788-ff85-11d5-b382-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - Recycled\ctfmon.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-05 10:00:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-23 19:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - GARDENA.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exee/TASK:
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-23 22:07:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-23 22:09:03
.
--- E O F ---