ComboFix 08-04-18.3 - Tóth Csaba 2008-04-19 11:29:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.907 [GMT 2:00]
Running from: C:\Documents and Settings\Tóth Csaba\Asztal\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 )))))))))))))))))))))))))))))))
.
2008-04-18 16:22 . 2008-04-18 16:22 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\HP
2008-04-18 16:22 . 2008-04-18 16:22 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\ATI
2008-04-18 16:21 . 2008-02-03 13:46 <DIR> d--h----- C:\Documents and Settings\Rendszergazda\Sablonok
2008-04-18 16:21 . 2008-04-18 16:21 <DIR> dr------- C:\Documents and Settings\Rendszergazda\Dokumentumok
2008-04-18 16:21 . 2008-02-03 14:38 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Asztal
2008-04-18 16:21 . 2008-04-18 16:47 <DIR> d-------- C:\Documents and Settings\Rendszergazda
2008-04-18 16:21 . 2008-04-19 11:29 1,024 --ah----- C:\Documents and Settings\Rendszergazda\NtUser.dat.LOG
2008-04-17 13:01 . 2008-04-17 13:01 <DIR> d-------- C:\Documents and Settings\Tóth Csaba\Application Data\Uniblue
2008-04-13 17:28 . 2008-04-13 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-04-13 12:05 . 2008-04-13 20:24 <DIR> d-------- C:\Documents and Settings\Tóth Csaba\Application Data\Winamp
2008-04-12 21:49 . 2008-04-12 21:50 <DIR> d-------- C:\Program Files\Panda Security
2008-04-12 21:24 . 2008-04-12 21:24 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-04-12 21:24 . 2008-04-12 21:24 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-04-12 21:23 . 2008-04-12 21:23 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-04-12 21:23 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-04-12 21:07 . 2008-04-12 21:07 268 --ah----- C:\sqmdata01.sqm
2008-04-12 21:07 . 2008-04-12 21:07 244 --ah----- C:\sqmnoopt01.sqm
2008-04-11 22:16 . 2008-04-11 22:16 268 --ah----- C:\sqmdata00.sqm
2008-04-11 22:16 . 2008-04-11 22:16 244 --ah----- C:\sqmnoopt00.sqm
2008-04-06 18:10 . 2008-04-19 11:26 246,728 --a------ C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2008-04-06 18:10 . 2008-04-12 21:09 13,880 --a------ C:\WINDOWS\system32\drivers\COMFiltr.sys
2008-04-06 18:10 . 2008-04-19 11:26 1,244 --a------ C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2008-04-06 18:06 . 2008-04-06 18:06 <DIR> d-------- C:\WINDOWS\system32\PAV
2008-04-06 18:06 . 2007-10-25 17:27 292,144 --a------ C:\WINDOWS\system32\PavSHook.dll
2008-04-06 18:06 . 2007-10-16 15:37 161,072 --a------ C:\WINDOWS\system32\TpUtil.dll
2008-04-06 18:06 . 2007-11-19 13:01 143,160 --a------ C:\WINDOWS\system32\drivers\netimflt.sys
2008-04-06 18:06 . 2007-02-08 10:53 107,568 --a------ C:\WINDOWS\system32\SYSTOOLS.DLL
2008-04-06 18:06 . 2007-02-28 17:04 63,024 --a------ C:\WINDOWS\system32\pavipc.dll
2008-04-06 18:06 . 2007-03-15 18:38 54,832 --a------ C:\WINDOWS\system32\pavcpl.cpl
2008-04-06 18:06 . 2007-02-15 19:02 50,736 --a------ C:\WINDOWS\system32\avldr.dll
2008-04-06 18:06 . 2007-06-08 07:44 24,760 --a------ C:\WINDOWS\system32\drivers\cpoint.sys
2008-04-06 17:54 . 2007-07-12 13:49 178,872 --a------ C:\WINDOWS\system32\drivers\PavProc.sys
2008-04-06 17:54 . 2007-05-23 15:40 38,968 --a------ C:\WINDOWS\system32\drivers\ShlDrv51.sys
2008-03-31 16:47 . 2008-03-31 16:47 <DIR> d-------- C:\Program Files\Nokia
2008-03-21 21:10 . 2008-04-12 20:40 115,224 --a------ C:\img2-001.raw
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 09:26 246,728 ----a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT
2008-04-19 09:26 1,244 ----a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG
2008-04-18 11:37 --------- d-----w C:\Documents and Settings\Tóth Csaba\Application Data\Skype
2008-04-18 10:27 --------- d-----w C:\Documents and Settings\Tóth Csaba\Application Data\skypePM
2008-04-16 16:59 --------- d-----w C:\Documents and Settings\Tóth Csaba\Application Data\DivX
2008-04-13 11:41 --------- d-----w C:\Program Files\ATI Technologies
2008-04-12 19:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-12 15:00 --------- d-----w C:\Documents and Settings\Tóth Csaba\Application Data\Ahead
2008-04-08 17:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-06 16:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-06 15:54 --------- d-----w C:\Program Files\Common Files\Panda Software
2008-03-20 08:10 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-15 17:17 --------- d-----w C:\Documents and Settings\Tóth Csaba\Application Data\PC Suite
2008-03-12 11:10 633,344 ------w C:\WINDOWS\system32\gpprefcl.dll
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 20:45 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-02-29 20:45 221,184 ----a-w C:\WINDOWS\system32\UAService7.exe
2008-02-29 20:45 --------- d--h--r C:\Documents and Settings\All Users\Application Data\SecuROM
2008-02-29 20:41 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-26 05:51 2,863,616 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-02-26 03:12 372,736 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-02-26 03:10 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-02-26 03:10 299,520 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-02-26 03:02 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-02-26 03:02 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-02-26 03:01 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-02-26 03:01 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-02-26 03:01 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-02-26 03:00 520,192 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-02-26 02:59 9,797,632 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-02-26 02:58 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-02-26 02:49 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-02-26 02:41 1,755,264 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-02-26 02:29 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-02-26 02:25 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-02-26 02:23 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-02-26 02:22 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-02-26 02:21 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-02-26 02:19 167,936 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-02-26 02:16 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-02-25 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-02-25 16:52 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-22 19:07 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-22 19:06 --------- d-----w C:\Program Files\Windows Sidebar
2008-02-22 19:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-02-20 06:52 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-03 17:04 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-03 12:07 315,392 ----a-w C:\WINDOWS\HideWin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 14:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 20:03 152872]
"Yahoo! Pager"="C:\Softver\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 18:43 4670704]
"PC Suite Tray"="C:\Hardver\Nokia\Nokia PC Suite 6\Nokia PC Suite 6\PCSuite.exe" [2008-03-28 11:20 1079296]
"Nokia.PCSync"="C:\Hardver\Nokia\Nokia PC Suite 6\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ABIT uGuru"="C:\Hardver\ABIT\ABIT uGuru\uGuru.exe" [2004-09-13 14:37 1695827]
"GuruClock"="C:\Hardver\ABIT\ABIT uGuru\GuruClock.exe" [2004-11-08 15:23 4489302]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-11-03 10:11 86016 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2007-11-03 10:11 2808832 C:\WINDOWS\alcwzrd.exe]
"HP Software Update"="C:\Hardver\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41 49152]
"WheelMouse"="C:\Hardver\A4Tech\Mouse\Amoumain.exe" [2003-07-18 00:53 147456]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 18:01 277296]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"APVXDWIN"="C:\Softver\Panda Security\APVXDWIN.exe" [2007-11-23 14:33 406832]
"SCANINICIO"="C:\Softver\Panda Security\Inicio.exe" [2007-07-11 14:17 27952]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-10-13 18:04 707376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 14:00 15360]
"Nokia.PCSync"="C:\Hardver\Nokia\Nokia PC Suite 6\PcSync2.exe" [ ]
C:\Documents and Settings\T˘th Csaba\Start Menu\Programs\Indˇt˘pult\
OneNote 2007 - K‚perny‹r‚sz kiv g sa ‚s gyorsindˇt s.lnk - C:\Softver\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]
C:\Documents and Settings\All Users\Start Menu\Programs\Indˇt˘pult\
AutoCAD indˇt sgyorsˇt˘.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 14:18:22 10872]
AutoStart IR.lnk - C:\Hardver\WinTV\Ir.exe [2008-02-03 14:48:16 102455]
Exif Launcher S.lnk - C:\Hardver\FinePixViewerS\QuickDCF2.exe [2008-02-03 18:17:55 303104]
HP Digital Imaging Monitor.lnk - C:\Hardver\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22 288472]
ImageMixer HDD Camera Monitor.lnk - C:\Hardver\PIXELA\ImageMixer3\HDDCameraMonitor.exe [2008-02-03 18:23:03 2117632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 19:02 50736 C:\WINDOWS\system32\avldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2004-08-18 14:00 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
--a------ 2002-07-05 17:37 491008 C:\WINDOWS\mHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
--a------ 2006-10-13 18:04 707376 C:\WINDOWS\vVX3000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-04-01 20:49 36352 C:\Softver\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Softver\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Softver\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Softver\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Softver\\Skype\\Phone\\Skype.exe"=
R0 uGuru;uGuru;C:\WINDOWS\system32\Drivers\uGuru.sys [2004-08-04 14:56]
R1 APPFLT;App Filter Plugin;C:\WINDOWS\system32\Drivers\APPFLT.SYS [2007-09-28 13:05]
R1 DSAFLT;DSA Filter Plugin;C:\WINDOWS\system32\Drivers\DSAFLT.SYS [2007-05-11 08:33]
R1 FNETMON;NetMon Filter Plugin;C:\WINDOWS\system32\Drivers\fnetmon.SYS [2007-11-14 17:48]
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS\system32\drivers\hcw88aud.sys [2005-05-31 20:34]
R1 IDSFLT;Ids Filter Plugin;C:\WINDOWS\system32\Drivers\IDSFLT.SYS [2007-07-11 10:39]
R1 NETFLTDI;Panda Net Driver [TDI Layer];C:\WINDOWS\system32\Drivers\NETFLTDI.SYS [2007-10-25 08:50]
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\Drivers\ShlDrv51.sys [2007-05-23 15:40]
R1 SMSFLT;SMS Filter Plugin;C:\WINDOWS\system32\Drivers\SMSFLT.SYS [2007-05-11 08:33]
R1 WNMFLT;Wifi Monitor Filter Plugin;C:\WINDOWS\system32\Drivers\WNMFLT.SYS [2007-05-11 08:33]
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys [2007-06-08 07:44]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 18:01]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2007-07-12 13:49]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2003-02-26 18:28]
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
R3 GT680xNT;ColorPage-Vivid 1200XE;C:\WINDOWS\system32\drivers\gt680x.sys [2003-02-27 00:55]
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS\system32\drivers\hcw88bda.sys [2005-05-31 20:34]
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;C:\WINDOWS\system32\Drivers\hcw88rc5.sys [2005-05-31 20:34]
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS\system32\drivers\hcw88tse.sys [2005-05-31 23:43]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS\system32\drivers\hcw88tun.sys [2005-05-31 20:34]
R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS\system32\drivers\hcw88vid.sys [2005-05-31 23:43]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS\system32\drivers\HCW88BAR.sys [2005-05-31 20:34]
R3 NETIMFLT01050097;PANDA NDIS IM Filter Miniport v1.5.0.97;C:\WINDOWS\system32\DRIVERS\netimflt.sys [2007-11-19 13:01]
R3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\system32\PavSRK.sys []
R3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\system32\PavTPK.sys []
S3 BTCOMM;BTCOMM;C:\WINDOWS\system32\drivers\Btcomm.sys []
S3 BTKRNBDG;Bluetooth COM Bridge;C:\WINDOWS\system32\DRIVERS\btkrnbdg.sys []
S3 ComFiltr;Panda Anti-Dialer;C:\WINDOWS\system32\DRIVERS\COMFiltr.sys [2008-04-12 21:09]
S3 CSRBC01;%CSRBC01.SvcDesc%;C:\WINDOWS\system32\Drivers\csrbc01.sys []
S3 vad_multi;Windigo Virtual Audio Device (WDM);C:\WINDOWS\system32\drivers\vadmulti.sys []
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-19 11:30:29
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo! Pager = "C:\Softver\Yahoo!\Messenger\YahooMessenger.exe" -quiet??\
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-19 11:31:21
ComboFix-quarantined-files.txt 2008-04-19 09:31:18
9 könyvtár 14,112,890,880 bájt szabad
13 könyvtár 14,137,233,408 bájt szabad
209 --- E O F --- 2008-03-12 18:59:41