Itt a txt fájl:
ComboFix 09-10-22.01 - Rendszergazda 2009/10/23 17:52.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.503.203 [GMT 2:00]
Running from: c:\documents and settings\Rendszergazda\Asztal\ComboFix.exe
AV: ESET NOD32 Antivirus System 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-09-23 to 2009-10-23 )))))))))))))))))))))))))))))))
.
2009-10-22 20:25 . 2009-10-22 20:25 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Registry Mechanic
2009-10-22 20:17 . 2009-10-22 20:17 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-22 19:13 . 2009-10-22 19:13 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Mael
2009-10-22 19:08 . 2009-10-22 19:08 -------- d-----w- c:\program files\HxD
2009-10-17 21:11 . 2009-10-17 21:10 737280 ----a-w- c:\windows\iun6002.exe
2009-10-17 21:11 . 2009-10-17 21:11 -------- d-----w- c:\program files\FireTune
2009-10-17 10:22 . 2009-10-17 10:22 -------- d-----w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\Downloaded Installations
2009-10-16 23:38 . 2003-11-15 20:27 118872 ----a-w- c:\windows\system32\PXC25uis.dll
2009-10-16 23:38 . 2003-02-05 19:06 45142 ----a-w- c:\windows\system32\PXC25s.dll
2009-10-16 23:38 . 2002-12-27 17:33 20569 ----a-w- c:\windows\system32\PXC25pm.dll
2009-10-16 23:38 . 2003-09-15 01:36 390656 ----a-w- c:\windows\system32\pdfxclib.dll
2009-10-16 23:38 . 2003-08-15 22:15 109568 ----a-w- c:\windows\system32\pdfxcpro.dll
2009-10-16 23:38 . 2003-08-15 22:12 144896 ----a-w- c:\windows\system32\xc_parse.dll
2009-10-16 23:38 . 2003-07-31 17:02 8704 ----a-w- c:\windows\system32\pdfxcds.dll
2009-10-16 23:38 . 2003-05-18 17:37 157184 ----a-w- c:\windows\system32\img_xchg.dll
2009-10-16 23:38 . 2003-04-13 23:08 185344 ----a-w- c:\windows\system32\Img_cdx.dll
2009-10-16 23:38 . 2002-01-05 05:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-10-16 23:38 . 2009-10-16 23:38 -------- d-----w- c:\program files\TTMessenger
2009-10-09 16:56 . 2009-10-10 11:45 -------- d-----w- c:\program files\Luxor Mahjong
2009-10-09 16:56 . 2009-10-09 16:56 -------- d-----w- c:\program files\BFG
2009-10-04 07:07 . 2009-10-17 10:44 -------- d-----w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\Adobe
2009-10-04 07:04 . 2009-10-17 10:42 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-04 00:45 . 2009-10-04 00:45 -------- d-----w- c:\windows\ServicePackFiles
2009-10-04 00:36 . 2009-10-04 04:49 -------- d-----w- c:\windows\SxsCaPendDel
2009-10-04 00:30 . 2009-10-04 00:30 -------- d-----w- c:\program files\MSXML 6.0
2009-10-04 00:23 . 2009-10-04 00:23 -------- d-----w- c:\program files\MSXML 4.0
2009-10-03 18:27 . 2009-10-03 22:03 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-10-03 15:46 . 2008-06-14 18:00 272512 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-10-03 15:46 . 2008-06-14 18:00 272512 ------w- c:\windows\system32\drivers\bthport.sys
2009-10-03 15:32 . 2009-06-09 14:56 53248 -c----w- c:\windows\system32\dllcache\tsgqec.dll
2009-10-03 15:32 . 2009-06-09 14:56 290816 -c----w- c:\windows\system32\dllcache\rhttpaa.dll
2009-10-03 15:32 . 2009-06-09 14:56 136192 -c----w- c:\windows\system32\dllcache\aaclient.dll
2009-10-03 15:32 . 2009-02-09 11:45 2064384 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-03 15:32 . 2009-02-09 11:45 2022400 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-03 15:31 . 2009-02-09 11:45 2187520 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-03 15:31 . 2009-02-09 11:45 2144256 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-03 15:24 . 2008-10-24 11:25 455936 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-03 15:02 . 2009-10-04 20:33 -------- d--h--w- c:\windows\$hf_mig$
2009-10-03 14:42 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-03 08:57 . 2009-10-03 08:57 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-03 07:17 . 2009-10-03 07:17 -------- d-----w- c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2009-10-03 07:17 . 2009-10-03 07:19 -------- d-----w- c:\program files\Windows Live
2009-10-03 07:17 . 2009-10-03 07:17 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-09-30 19:48 . 2001-03-28 14:38 69632 ----a-w- c:\windows\system32\GkSui18.EXE
2009-09-24 07:33 . 2009-09-24 07:34 -------- d-----w- c:\windows\ShellNew
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-23 15:52 . 2009-09-03 10:55 447052 ----a-w- c:\windows\system32\perfh00E.dat
2009-10-23 15:52 . 2009-09-03 10:55 99920 ----a-w- c:\windows\system32\perfc00E.dat
2009-10-23 15:49 . 2009-09-03 12:31 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\uTorrent
2009-10-23 15:09 . 2009-09-19 08:37 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\XnView
2009-10-22 20:32 . 2009-09-08 08:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-17 22:01 . 2009-09-05 15:00 -------- d-----w- c:\program files\Webteh
2009-10-17 22:01 . 2009-09-05 15:00 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\BSplayer PRO
2009-10-04 04:50 . 2009-09-03 12:00 16368 ----a-w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-03 11:02 . 2009-09-19 08:36 -------- d-----w- c:\program files\XnView
2009-09-29 18:41 . 2009-09-23 06:35 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\gtk-2.0
2009-09-23 06:23 . 2009-09-23 06:23 -------- d-----w- c:\program files\Gimp-2.0
2009-09-22 18:18 . 2009-09-22 18:16 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Super-Cow
2009-09-21 16:01 . 2009-09-21 16:01 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\ArGoSoft
2009-09-17 22:26 . 2009-09-17 20:48 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\EditPlus 3
2009-09-17 20:49 . 2009-09-17 20:48 -------- d-----w- c:\program files\EditPlus 3
2009-09-17 19:31 . 2009-09-09 23:20 -------- d-----w- c:\program files\Hide My IP 2009
2009-09-17 16:33 . 2009-09-17 16:33 581632 ----a-w- c:\documents and settings\Rendszergazda\plugin.dat
2009-09-11 09:32 . 2009-09-03 13:40 -------- d-----w- c:\program files\ESET
2009-09-11 06:47 . 2009-09-03 20:26 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\PC Suite
2009-09-11 06:47 . 2009-09-03 20:26 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Nokia
2009-09-09 22:36 . 2009-09-06 15:18 -------- d-----w- c:\program files\Virgin Interactive
2009-09-08 18:05 . 2009-09-08 18:05 -------- d-----w- c:\program files\Google Hacks
2009-09-08 08:17 . 2009-09-08 08:16 -------- d-----w- c:\program files\Smarty Uninstaller Pro
2009-09-07 20:14 . 2009-09-07 18:27 -------- d-----w- c:\program files\Game_Maker7
2009-09-07 18:37 . 2009-09-07 18:37 -------- d-----w- c:\program files\Game_Maker4
2009-09-07 18:37 . 2009-09-07 18:37 798720 ----a-w- c:\windows\GPInstall.exe
2009-09-06 10:49 . 2009-09-03 12:11 -------- d-----w- c:\program files\totalcmd
2009-09-05 12:03 . 2009-09-05 12:03 -------- d-----w- c:\program files\MSBuild
2009-09-05 12:03 . 2009-09-05 12:03 -------- d-----w- c:\program files\Reference Assemblies
2009-09-04 21:43 . 2009-09-04 21:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-09-04 21:43 . 2009-09-04 21:43 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-09-04 21:42 . 2009-09-03 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-09-04 21:34 . 2009-09-04 21:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-09-04 21:34 . 2009-09-04 21:34 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-09-04 20:26 . 2009-09-03 10:41 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-04 16:29 . 2009-09-04 16:29 -------- d-----w- c:\program files\Common Files\EZB Systems
2009-09-04 16:29 . 2009-09-04 16:29 -------- d-----w- c:\program files\UltraISO
2009-09-04 15:58 . 2009-09-04 15:58 -------- d-----w- c:\program files\PowerISO
2009-09-04 11:08 . 2009-09-04 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-03 21:58 . 2009-09-03 21:58 -------- d-----w- c:\program files\CCleaner
2009-09-03 19:53 . 2009-09-03 19:51 -------- d-----w- c:\program files\DIFX
2009-09-03 19:52 . 2009-09-03 19:52 -------- d-----w- c:\program files\Common Files\PCSuite
2009-09-03 19:52 . 2009-09-03 19:52 -------- d-----w- c:\program files\Common Files\Nokia
2009-09-03 19:52 . 2009-09-03 19:50 -------- d-----w- c:\program files\Nokia
2009-09-03 19:51 . 2009-09-03 19:51 -------- d-----w- c:\program files\PC Connectivity Solution
2009-09-03 19:50 . 2009-09-03 19:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-09-03 14:01 . 2009-09-03 14:01 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Media Player Classic
2009-09-03 13:52 . 2009-09-03 13:52 -------- d-----w- c:\program files\Microsoft Games
2009-09-03 13:40 . 2009-09-03 13:41 298104 ----a-w- c:\windows\system32\imon.dll
2009-09-03 13:40 . 2009-09-03 13:41 512096 ----a-w- c:\windows\system32\drivers\amon.sys
2009-09-03 13:40 . 2009-09-03 13:41 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
2009-09-03 13:28 . 2009-09-03 13:28 1174 ----a-w- c:\windows\mozver.dat
2009-09-03 13:24 . 2009-09-03 13:23 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-03 12:35 . 2009-09-03 12:35 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Talkback
2009-09-03 12:35 . 2009-09-03 12:35 0 ----a-w- c:\windows\nsreg.dat
2009-09-03 12:32 . 2009-09-03 12:31 -------- d-----w- c:\program files\uTorrent
2009-09-03 12:28 . 2009-09-03 12:26 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\DAEMON Tools
2009-09-03 12:26 . 2009-09-03 12:26 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-09-03 12:24 . 2009-09-03 12:24 715248 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-03 12:01 . 2009-09-03 11:20 -------- d-----w- c:\program files\Windows Media Connect
2009-09-03 12:00 . 2009-09-03 12:00 137 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\fusioncache.dat
2009-09-03 12:00 . 2009-09-03 11:08 -------- d-----w- c:\program files\HPQ
2009-09-03 11:38 . 2009-09-03 11:19 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Sonic
2009-09-03 11:37 . 2009-09-03 11:37 -------- d-----w- c:\documents and settings\Rendszergazda\Application Data\Leadertech
2009-09-03 11:35 . 2009-09-03 11:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-03 11:35 . 2009-09-03 11:19 -------- d-----w- c:\program files\Java
2009-09-03 11:23 . 2009-09-03 11:23 -------- d-----w- c:\program files\Intel
2009-09-03 11:22 . 2009-09-03 11:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-03 11:22 . 2009-09-03 11:06 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-03 11:20 . 2009-09-03 11:20 136 ----a-w- c:\documents and settings\Rendszergazda\Local Settings\Application Data\fusioncache.dat
2009-09-03 11:19 . 2009-09-03 11:19 -------- d-----w- c:\program files\Common Files\Java
2009-09-03 11:18 . 2009-09-03 11:18 108544 ------w- c:\windows\system32\pxcpyi64.exe
2009-09-03 11:18 . 2009-09-03 11:18 104960 ------w- c:\windows\system32\pxinsi64.exe
2009-09-03 11:13 . 2009-09-03 11:13 1749 --sha-r- c:\windows\system32\drivers\103C_HP_NTBK_HP Compaq nx6110 (PY439ES#AKC)_YN_0U_QCNU5352DWZ_EU_46_I3088_SHP_VKBC Version 39.2A_B68DTD Ver. F.14_T060727_WXP2_L40E_M504_J40_7Intel_8Celeron M_91.4_#090903_N14E4170C_(PY439ES#AKC)_XMOBILE_CN10.MRK
2009-09-03 11:08 . 2009-09-03 11:08 -------- d-----w- c:\program files\Broadcom
2009-09-03 11:06 . 2009-09-03 11:06 -------- d-----w- c:\program files\Analog Devices
2009-09-03 10:47 . 2009-09-03 10:47 -------- d-----w- c:\program files\microsoft frontpage
2009-09-03 10:42 . 2009-09-03 10:42 21948 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-05 09:08 . 2009-09-03 10:53 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:30 . 2009-09-03 10:58 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:30 . 2009-09-03 10:47 81920 ----a-w- c:\windows\system32\fontsub.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-09-03 288048]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"TTMessengerPDF"="c:\program files\TTMessenger\spool\PDFSaver.exe" [2004-03-22 61440]
"TTMessenger"="c:\program files\TTMessenger\ttmessenger2.exe" [2008-01-22 585728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-12-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-12-21 126976]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-03 149280]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-09-03 949376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-08-24 88363]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2008-01-30 12451]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti Trojan Elite
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cFosSpeed
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009/9/3 15:41 15424]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2009/10/22 22:17 583640]
S2 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - DMADMIN
*Deregistered* - mbr
*Deregistered* - pweyifob
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{O650WNCI-24L7-0X3Y-HUA8-M7W002RUUFTJ}]
Restart
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Rendszergazda\Application Data\Mozilla\Firefox\Profiles\iq0646oo.default\
FF - prefs.js: browser.startup.homepage -
hxxp://startlap.hu
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-23 17:58
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????2?5?4?7??????? ???B???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1240)
c:\windows\system32\WININET.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-23 18:00
ComboFix-quarantined-files.txt 2009-10-23 16:00
Pre-Run: 5 924 552 704 bájt szabad
Post-Run: 5 942 972 416 bájt szabad
- - End Of File - - 52CB7580C0132CE4F7B914306DDA8297