ComboFix 07-12-21.4 - Rendszergazda 2007-12-30 22:41:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.115 [GMT 1:00]
Running from: N:\féregkeresők\2007.12.29-én ajánlották\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-30 )))))))))))))))))))))))))))))))
.
2007-12-30 22:22 . 2007-12-30 22:22 60,416 --a------ C:\WINDOWS\system32\drivers\ge^fyuic.sys
2007-12-30 18:33 . 2007-12-29 21:53 130,048 --a------ C:\avenger.exe
2007-12-30 16:58 . 2007-12-29 17:56 401,720 --a------ C:\HiJackThis.exe
2007-12-27 12:55 . 2007-12-29 10:59 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-27 12:55 . 2007-12-27 12:55 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\PC Tools
2007-12-27 12:55 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-27 12:55 . 2007-12-27 12:56 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-27 12:55 . 2007-12-27 12:56 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-27 12:55 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-27 12:55 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-21 15:27 . 2007-12-21 15:27 239 --a------ C:\WINDOWS\system32\NVU001.nvu
2007-12-21 15:26 . 2003-06-05 08:00 1,431 -ra------ C:\WINDOWS\system32\nvgart.nvu
2007-12-21 15:26 . 2003-07-07 10:33 897 --------- C:\WINDOWS\system32\nvmctl.nvu
2007-12-19 21:33 . 2007-12-19 21:33 <DIR> d---s---- C:\Documents and Settings\Rendszergazda\UserData
2007-12-17 13:39 . 2004-06-25 10:47 3,377,466 --a------ C:\WINDOWS\{00000001-00000000-0000000A-00001102-00000002-100A1102}.CDF
2007-12-17 01:50 . 2007-12-28 19:41 <DIR> d-------- C:\Program Files\Replay Converter
2007-12-17 01:50 . 2007-03-04 13:55 1,936,528 --a------ C:\WINDOWS\system32\ltmm15.dll
2007-12-17 01:50 . 2007-03-04 13:55 135,168 --a------ C:\WINDOWS\system32\DSKernel2.dll
2007-12-17 01:48 . 2007-12-17 01:50 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\GetRightToGo
2007-12-17 01:44 . 2007-12-17 01:44 <DIR> d-------- C:\WINDOWS\Replay Media Catcher
2007-12-17 01:44 . 2007-12-17 13:36 <DIR> d-------- C:\Program Files\Replay Media Catcher
2007-12-14 19:41 . 2007-12-21 00:50 <DIR> d-------- C:\Program Files\KMPlayer-2.9.3.1427
2007-12-14 18:57 . 2007-12-14 18:57 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\CEZEO software
2007-12-13 17:09 . 2007-12-30 22:28 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-13 17:08 . 2007-12-13 17:17 <DIR> d-------- C:\Program Files\AoA MP4 Converter
2007-12-13 15:13 . 2007-12-13 15:13 <DIR> d-------- C:\Program Files\Orbitdownloader
2007-12-13 15:13 . 2007-12-13 15:13 <DIR> d-------- C:\Downloads
2007-12-13 15:13 . 2007-12-30 22:31 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\Orbit
2007-12-13 13:06 . 2007-12-13 13:08 2,634 --a------ C:\kabaré.PLC
2007-12-13 02:18 . 2007-12-13 02:18 <DIR> d-------- C:\Program Files\Makayama
2007-12-13 02:18 . 2004-11-01 12:38 57,344 --------- C:\WINDOWS\system32\XButton.ocx
2007-12-10 16:23 . 2007-12-08 23:19 <DIR> d-------- C:\Program Files\AIMP Classic
2007-12-10 03:37 . 2007-12-24 12:32 512 --a------ C:\ScanSectorLog.dat
2007-12-10 03:12 . 2007-12-27 17:01 2,082 --a------ C:\rollback.ini
2007-12-10 03:08 . 2007-12-10 03:08 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\MailFrontier
2007-12-10 02:47 . 2007-12-30 22:25 15,334,176 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-10 02:47 . 2007-12-30 22:25 563,744 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-10 02:47 . 2007-12-30 22:25 207,428 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-10 02:47 . 2007-12-30 22:25 52,064 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-10 02:40 . 2007-03-09 00:02 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-12-10 02:40 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-10 02:40 . 2007-12-30 22:33 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-12-10 02:39 . 2007-12-27 19:55 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-12-10 02:39 . 2007-03-09 00:01 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-12-10 02:39 . 2007-12-30 22:28 49,617 --a------ C:\WINDOWS\system32\vsconfig.xml
2007-12-10 02:37 . 2007-12-30 22:36 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-12-10 02:26 . 2007-12-10 02:26 0 --a------ C:\WINDOWS\system32\Ultra.dll
2007-12-10 02:07 . 2007-12-28 20:53 <DIR> d-------- C:\Program Files\Bug Doctor
2007-12-09 00:47 . 2007-12-09 00:47 <DIR> d-------- C:\Documents and Settings\Rendszergazda\WINDOWS
2007-12-07 20:43 . 2007-12-07 20:43 <DIR> d-------- C:\Quake III Arena
2007-12-04 20:38 . 2007-12-08 09:54 <DIR> d-------- C:\Program Files\JetAudio
2007-12-04 12:05 . 2007-12-04 12:05 101 --a------ C:\WINDOWS\wininit.ini
2007-12-01 05:22 . 2007-12-01 05:22 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-12-01 02:43 . 2007-12-09 00:27 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-01 02:43 . 2007-12-01 02:43 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-01 02:43 . 2007-12-01 02:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-01 02:31 . 2007-12-01 02:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-01 02:26 . 2007-12-01 02:26 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-30 14:31 . 2007-11-30 14:31 <DIR> d-------- C:\Program Files\Sprintbit Software
2007-11-29 18:11 . 2007-11-29 18:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic
2007-11-29 18:11 . 2007-11-29 18:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-29 17:36 . 2007-11-29 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2007-11-29 11:43 . 2007-11-29 11:43 <DIR> d-------- C:\WINDOWS\system32\3Planesoft
2007-11-29 11:43 . 2007-11-29 11:43 <DIR> d-------- C:\Program Files\The One Ring 3D Screensaver
2007-11-29 11:43 . 2007-11-29 11:43 <DIR> d-------- C:\Program Files\3Planesoft Screensaver Manager
2007-11-28 01:27 . 2007-12-10 03:24 18,432 --a------ C:\Documents and Settings\Rendszergazda\spydb.dat
2007-11-28 01:25 . 2007-11-28 01:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2007-11-28 00:24 . 2007-11-28 00:24 <DIR> d-------- C:\JHPMultimedia
2007-11-28 00:24 . 2002-09-17 10:18 63,488 --a------ C:\WINDOWS\system32\mci32.oca
2007-11-28 00:24 . 1998-06-17 23:00 2,396 --a------ C:\WINDOWS\system32\mci32.dep
2007-11-28 00:23 . 1998-06-17 23:00 2,496 --a------ C:\WINDOWS\system32\MSSTDFMT.DEP
2007-11-27 15:14 . 2007-11-27 15:14 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\Sunbelt Software
2007-11-27 00:10 . 2007-11-27 00:10 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\Media Player Classic
2007-11-25 22:35 . 2007-12-10 08:15 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\RaimaRadio
2007-11-25 22:11 . 2007-12-10 08:18 <DIR> d-------- C:\Program Files\Counter-Strike 1.6
2007-11-24 21:19 . 2007-11-24 21:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
2007-11-24 21:18 . 2007-11-24 21:18 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\GRETECH
2007-11-24 21:17 . 2007-11-24 21:17 <DIR> d-------- C:\Program Files\GRETECH
2007-11-24 20:46 . 2007-11-24 20:50 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\Zoom Player
2007-11-23 13:26 . 2007-11-23 13:26 244 --ah----- C:\sqmnoopt06.sqm
2007-11-23 13:26 . 2007-11-23 13:26 232 --ah----- C:\sqmdata06.sqm
2007-11-23 10:45 . 2007-11-23 10:45 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2007-11-23 10:45 . 2007-12-17 01:50 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-11-23 09:33 . 2007-11-23 09:33 <DIR> d-------- C:\Program Files\OpenSource Flash Video Splitter
2007-11-23 09:33 . 2007-11-23 09:33 <DIR> d-------- C:\Program Files\DScaler5
2007-11-23 09:33 . 2007-11-23 09:33 <DIR> d-------- C:\Program Files\CD Audio Reader Filter
2007-11-23 09:32 . 2007-11-23 09:32 <DIR> d-------- C:\Program Files\RealMedia
2007-11-23 09:29 . 2007-11-23 09:29 <DIR> d-------- C:\Program Files\SHOUTcast Source
2007-11-23 09:29 . 2007-11-23 09:29 <DIR> d-------- C:\Program Files\Haali
2007-11-23 09:28 . 2007-11-23 09:28 <DIR> d-------- C:\Program Files\DS-MP3 Source
2007-11-23 09:26 . 2007-11-23 09:26 <DIR> d-------- C:\Program Files\DirectVobSub
2007-11-22 14:58 . 2007-12-01 04:14 277 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2007-11-21 13:36 . 2006-08-25 06:26 95,760 -ra------ C:\WINDOWS\system32\isafeif.2
2007-11-21 13:36 . 2006-08-05 07:21 75,280 -ra------ C:\WINDOWS\system32\vetredir.2
2007-11-21 13:36 . 2006-08-25 06:26 75,280 -ra------ C:\WINDOWS\system32\isafprod.1
2007-11-21 13:09 . 2007-11-21 13:09 120,286 --a------ C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2007-11-20 23:52 . 2007-11-20 23:52 <DIR> d-------- C:\Program Files\sina SoftWare
2007-11-20 15:29 . 2007-11-20 15:29 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\ESET
2007-11-20 15:28 . 2007-11-20 15:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2007-11-20 12:56 . 2007-11-20 12:56 <DIR> d-------- C:\Program Files\Common Files\Agnitum Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-30 21:52 --------- d-----w C:\Program Files\PeerGuardian2
2007-12-30 21:51 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\utorrent
2007-12-30 21:34 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\Skype
2007-12-28 20:09 --------- d-----w C:\Program Files\MSN Messenger
2007-12-28 18:45 --------- d-----w C:\Program Files\Winamp
2007-12-27 18:55 1,922,178 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 18:42 --------- d-----w C:\Program Files\Jewel Quest
2007-12-17 21:03 --------- d-----w C:\Program Files\FSMaxView
2007-12-12 23:40 17,045,788 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_12_22_25_26_full.dmp.zip
2007-12-12 23:38 17,028,523 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_12_17_42_42_full.dmp.zip
2007-12-10 12:34 16,840,914 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_10_09_43_44_full.dmp.zip
2007-12-10 07:20 --------- d-----w C:\Program Files\EvilLyrics
2007-12-05 20:50 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\COWON
2007-11-30 13:04 --------- d-----w C:\Program Files\TC PowerPack
2007-11-20 11:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-19 17:38 --------- d-----w C:\Program Files\ABIT
2007-11-19 17:27 --------- d-----w C:\Program Files\uTorrent
2007-11-16 18:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-01 19:06 --------- d-----w C:\Program Files\Bejeweled 2 Deluxe
2007-11-01 18:34 --------- d-----w C:\Program Files\Eggsucker
2007-10-31 18:05 --------- d-----w C:\Program Files\FDRLab
2007-10-29 07:05 14 ----a-w C:\Documents and Settings\Rendszergazda\getfile.dat
2007-10-28 17:21 --------- d-----w C:\Program Files\D4
2007-09-28 17:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\WINDOWS\system32\divx.dll
2007-09-26 03:04 155,995 ----a-w C:\WINDOWS\java\Packages\U3RBR9JZ.ZIP
2007-09-04 17:56 164,352 ----a-w C:\WINDOWS\system32\unrar.dll
.
((((((((((((((((((((((((((((( snapshot@2007-12-29_19.03.49,54 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-29 17:05:29 880,612 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2007-12-30 21:26:33 880,612 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2007-12-29 18:02:49 1,587,712 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2007-12-30 21:42:24 1,587,712 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2007-12-30 21:27:05 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_444.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:47]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 11:48]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 13:31]
"µTorrent"="C:\WINDOWS\utorrent.exe" [2007-02-16 07:09]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2007-10-16 12:54]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 17:40]
"HomeAlarm"="C:\Program Files\Chameleon Clock\ChamClock.exe" [2003-01-10 12:22]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AllSnap"="C:\WINDOWS\allsnap.exe" [2006-11-14 13:00]
"AsioReg"="REGSVR32 /S CTASIO.DLL" []
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 C:\WINDOWS\system32\CTXFIHLP.EXE]
"ClocX"="C:\Program Files\ClocX\ClocX.exe" [2007-07-26 16:43]
"Dimension4"="C:\Program Files\D4\D4.exe" [2004-02-04 01:26]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 11:20 C:\WINDOWS\SOUNDMAN.EXE]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:47]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 18:48]
C:\Documents and Settings\All Users\Start Menu\Programs\Indˇt˘pult\
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2007-12-13 15:13:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"= 1 (0x1)
"NoStrCmpLogical"= 1 (0x1)
"ForceCopyAclwithFile"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"= 1 (0x1)
"NoStrCmpLogical"= 1 (0x1)
"ForceCopyAclwithFile"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
R2 FARBCopy;FAR Background Copy Service;C:\Program Files\far\plugins\bcopy\bcsvc.exe [2004-04-01 18:05]
R3 pgfilter;pgfilter;C:\Program Files\PeerGuardian2\pgfilter.sys [2005-09-18 17:02]
S0 hmjbgcbk;hmjbgcbk;C:\WINDOWS\system32\drivers\dftluqet.sys []
S1 SandBox;Outpost Firewall Sandbox Driver;C:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS []
S1 VFILT;Outpost Firewall Kernel Driver;C:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS []
S2 PctrlsInjectService;PctrlsInjectService;C:\Program Files\ParetoLogic\PGsurfer\InjectService.exe []
S2 SpySoapSysGuardService;System Guard(SpySoap);C:\Program Files\SpySoap\SysGuard.exe []
S3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL []
S3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL []
S3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL []
S3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL []
S3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL []
S3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL []
S3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL []
S3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL []
S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL []
S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL []
S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL []
S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL []
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []
S3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL []
S3 SpySoapSysGuardDriver;SpySoapSysGuardDriver;C:\Program Files\SpySoap\sysGuard.sys []
*Newly Created Service* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
"2007-12-30 17:31:00 C:\WINDOWS\Tasks\BugDoctorRendszergazda.job"
- C:\Program Files\Bug Doctor\BugDoctor.exe
"2007-12-30 21:29:25 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-12-25 17:00:01 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-30 22:52:17
Windows 5.1.2600 Szervizcsomag 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
Completion time: 2007-12-30 22:53:48
C:\ComboFix2.txt ... 2007-12-29 19:04
.
2007-12-01 01:42:04 --- E O F ---