ComboFix 08-02.01.5 - Elevencards 2008-02-01 7:59:09.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.683 [GMT 1:00]
Running from: C:\Documents and Settings\Elevencards\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Elevencards\Data aplikací\PCPrivacyTool
C:\Documents and Settings\Elevencards\Data aplikací\PCPrivacyTool\Logs\update.log
C:\Documents and Settings\Elevencards\Data aplikací\SpyGuardPro
C:\Documents and Settings\Elevencards\Data aplikací\SpyGuardPro\avtasks.dat
C:\Documents and Settings\Elevencards\Data aplikací\SpyGuardPro\Logs\av.log
C:\Documents and Settings\Elevencards\Data aplikací\SpyGuardPro\Logs\ga6Support.log
C:\Documents and Settings\Elevencards\Data aplikací\SpyGuardPro\Logs\update.log
C:\Documents and Settings\Elevencards\Data aplikací\SpyGuardPro\PGE.dat
C:\Program Files\Common Files\DriveDefender
C:\Program Files\Common Files\PCPrivacyTool
C:\Program Files\DriveDefender
C:\Program Files\DriveDefender\sr.log
C:\UGA6P
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\5_exception.nls
C:\WINDOWS\system32\ati2ksag.sys . . . . failed to delete
C:\WINDOWS\system32\cryptsv.dll . . . . failed to delete
C:\WINDOWS\system32\hrpdcf.bin . . . . failed to delete
C:\WINDOWS\system32\kl80.bin
C:\WINDOWS\system32\cryptsv.dll . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://scarddlg.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ATI2KSAG
-------\LEGACY_NDNET1
-------\LEGACY_RUNTIME
-------\LEGACY_RUNTIME2
-------\ati2ksag
-------\NDnet1
-------\runtime
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.
2008-01-16 15:30 . 2008-02-01 08:05 53,876 --a------ C:\WINDOWS\system32\mswrcrt.dll
2008-01-16 15:30 . 2008-01-16 15:30 7,552 --a------ C:\WINDOWS\system32\drivers\SpyMng.sys
2008-01-16 15:21 . 2008-01-16 15:21 300,048 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-01-16 15:21 . 2008-01-16 15:21 245,760 --a------ C:\WINDOWS\system32\imon.dll
2008-01-16 15:21 . 2008-01-16 15:21 114,688 --a------ C:\WINDOWS\system32\nms32.dll
2008-01-16 09:36 . 2008-01-16 09:36 138,624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-01-16 09:30 . 2008-01-16 09:36 <DIR> d-------- C:\Program Files\WinClamAVShield
2008-01-16 09:26 . 2008-01-16 10:48 <DIR> d-------- C:\Program Files\Crawler
2008-01-16 09:25 . 2008-01-30 14:30 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-01-16 09:10 . 2008-01-16 14:51 <DIR> d-------- C:\Program Files\Common Files\SuspenzorPC
2008-01-09 16:03 . 2008-01-09 16:03 <DIR> d-------- C:\Program Files\Jasc Software Inc
2008-01-09 16:03 . 2008-01-09 16:03 <DIR> d-------- C:\Program Files\Dell Computer
2008-01-09 16:02 . 2008-01-09 16:03 <DIR> d-------- C:\Program Files\Dell Photo Printer 720
2008-01-09 16:00 . 2008-01-09 16:00 155 --a------ C:\WINDOWS\dellstat.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 14:02 --------- d-----w C:\Program Files\ICQ6
2008-01-06 10:56 --------- d-----w C:\Program Files\ICQToolbar
2007-12-28 10:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-26 15:38 --------- d-----w C:\Program Files\DIFX
2007-12-26 15:38 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-12-26 15:38 --------- d-----w C:\Program Files\Common Files\Nokia
2007-12-26 15:37 --------- d-----w C:\Program Files\PC Connectivity Solution
2007-12-19 10:57 --------- d-----w C:\Program Files\GIMP-2.0
2007-12-12 21:02 13,824 ----a-w C:\sysalio.exe
2007-12-07 22:44 19,456 ----a-w C:\WINDOWS\system32\drivers\hwixfwlz.dat
2007-12-02 19:44 --------- d-----w C:\Program Files\Xvid CZ
2007-12-02 19:34 --------- d-----w C:\Program Files\Codec Pack - All In 1
2007-12-02 19:33 737,280 ----a-w C:\WINDOWS\iun6002.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9113B6A9-13E2-4CE8-AEA2-C93F1C8EC751}]
2004-08-17 16:49 96256 --a------ C:\WINDOWS\system32\cryptsv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 16:49 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 18:42 32768]
"WinampAgent"="D:\programky\Winamp\winampa.exe" [2005-10-27 00:01 33792]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
"PCSuiteTrayApplication"="D:\programky\nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"Salestart(3)"="C:\Program Files\Common Files\SuspenzorPC\mc.exe" [2007-11-07 18:12 429056]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-01-16 09:29 2776576]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-01-16 15:21 851968]
"SpyMng"="D:\programky\záznamspy\SpyManager20.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 16:49 15360]
"Nokia.PCSync"="D:\programky\nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]
R0 jmbdltdh;jmbdltdh;C:\WINDOWS\system32\drivers\hwixfwlz.dat []
R0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys [2005-07-12 22:21]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-01-16 09:36]
R1 SpyMng;SpyMng;C:\WINDOWS\system32\Drivers\SpyMng.sys [2008-01-16 15:30]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 00:04]
S3 ICDSX;Sony IC Recorder (SX);C:\WINDOWS\system32\Drivers\ICDSX.sys [2003-10-01 17:44]
S3 kbeepm;kbeepm;C:\DOCUME~1\ELEVEN~1\LOCALS~1\Temp\kbeepm.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df9045c8-bc5a-11dc-990a-0050fc7d54f3}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-01 08:06:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\imon.dll
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
D:\programky\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\programky\nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\SuspenzorPC\mc.exe
C:\Program Files\Eset\nod32kui.exe
D:\programky\záznamspy\SpyManager20.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
.
**************************************************************************
.
Completion time: 2008-02-01 8:07:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 07:07:03