Na végzett a Combo fix ezt írta ki:
ComboFix 08-02-12.1 - Andi 2008-02-11 21:57:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.567 [GMT 1:00]
Running from: C:\Documents and Settings\Andi\Asztal\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\search_res.txt
----- BITS: Possible infected sites -----
hxxp://77.91.228.180
hxxp://thenetworkcom.com
hxxp://77.91.228.182
hxxp://onsafepro.com
.
((((((((((((((((((((((((( Files Created from 2008-01-12 to 2008-02-12 )))))))))))))))))))))))))))))))
.
2008-02-07 19:18 . 2008-02-07 19:17 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-07 19:18 . 2008-02-07 19:18 3,442 --a------ C:\WINDOWS\unins000.dat
2008-01-29 11:31 . 2008-01-29 11:37 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-01-29 11:30 . 2004-02-23 01:00 1,386,496 --a------ C:\WINDOWS\system\MSVBVM60.DLL
2008-01-18 18:41 . 2008-01-18 18:41 <DIR> d-------- C:\Program Files\this ref window
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 19:54 --------- d-----w C:\Program Files\ESET
2008-02-07 18:50 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-06 17:47 --------- d-----w C:\Program Files\Circle Developement
2008-01-27 18:33 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-01-18 17:42 --------- d-----w C:\Documents and Settings\Andi\Application Data\this ref window
2008-01-18 17:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Name beep copy real
2008-01-18 08:32 --------- d-----w C:\Program Files\Filzip
2008-01-17 19:00 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-01-17 18:59 --------- d-----w C:\Program Files\Sim File Maid 2
2008-01-15 13:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-15 13:09 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-09 13:45 --------- d-----w C:\Documents and Settings\Andi\Application Data\DivX
2008-01-06 15:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-06 14:30 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-06 14:29 --------- d-----w C:\Program Files\Common Files\Real
2008-01-06 12:09 --------- d-----w C:\Program Files\ActiveX Control Pad
2007-12-25 13:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-25 13:44 --------- d-----w C:\Program Files\Strategy First
2007-12-24 15:51 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-12-24 15:51 --------- d--h--r C:\Documents and Settings\Andi\Application Data\SecuROM
2007-12-16 15:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-12-16 14:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-02 21:56 127,034 ------r C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-11-29 22:30 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-25 20:27 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2007-11-23 09:46 57,344 ----a-w C:\WINDOWS\system32\COMMTB32.DLL
2007-11-23 09:46 169,984 ----a-w C:\WINDOWS\system32\P2D.DLL
2007-11-23 09:46 161,552 ----a-w C:\WINDOWS\system32\ASYCPICT.DLL
2007-10-27 14:08 88 ----a-w C:\Program Files\Users.xml
2007-10-27 14:08 5,613 ----a-w C:\Program Files\DCPlusPlus.xml
2007-10-27 14:08 101 ----a-w C:\Program Files\ADLSearch.xml
2007-10-27 13:52 1,596,084 ----a-w C:\Program Files\HashIndex.xml
2007-10-27 13:52 1,048,576 ----a-w C:\Program Files\HashData.dat
2007-10-27 13:32 100 ----a-w C:\Program Files\Queue.xml
2006-02-12 19:32 189,392 ----a-w C:\Program Files\DCPlusPlus.chm
2006-02-12 19:32 115,585 ----a-w C:\Program Files\changelog.txt
2006-02-12 18:46 11,029,504 ----a-w C:\Program Files\DCPlusPlus.pdb
2006-02-12 18:46 1,462,272 ----a-w C:\Program Files\DCPlusPlus.exe
2006-02-12 18:43 38,318 ----a-w C:\Program Files\Example.xml
2006-02-01 13:32 5,878,634 ----a-w C:\Program Files\GeoIPCountryWhois.csv
2004-12-20 12:08 73,728 ----a-w C:\Program Files\opencow.dll
2004-09-03 18:48 18,581 ----a-w C:\Program Files\License.txt
2002-08-29 02:40 489,984 ----a-w C:\Program Files\dbghelp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D}
{3E57AE0B-0AAB-4919-B74E-8C29579C6CA5}
[HKEY_CLASSES_ROOT\clsid\{3e57ae0b-0aab-4919-b74e-8c29579c6ca5}]
[HKEY_CLASSES_ROOT\jokwmp.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{58D493B4-B144-4116-8FDA-A968563811C0}]
[HKEY_CLASSES_ROOT\jokwmp.ToolBar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:47 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 17:07 196608]
"knob wave"="C:\DOCUME~1\Andi\APPLIC~1\THISRE~1\math four.exe" [2008-01-18 18:41 433152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 15:41 45056]
"NWEReboot"="" []
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 15:31 67584 C:\WINDOWS\SOUNDMAN.EXE]
"PCTVRemote"="C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe" [2002-10-11 12:40 61699]
"EPSON Stylus DX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.exe" [2005-02-08 05:00 98304]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-27 19:30 917504]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-06 15:29 185896]
"copy real junk the"="C:\Documents and Settings\All Users\Application Data\Name beep copy real\Else Real.exe" [2008-02-11 18:24 824320]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:47 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Indˇt˘pult\
BOOKcase 4.0.lnk - C:\Program Files\TEXTware\BOOKcase40\BC40CASE.exe [2007-10-16 13:03:53 426028]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-02 22:57:11 67128]
Pinnacle Scheduler.lnk - C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe [2007-09-27 19:01:48 245760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"sapnet"= {A7A7D8F4-325B-48C7-B356-8DD1D4BEFE56} - C:\WINDOWS\sapnet.dll [ ]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Indítópult^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Indítópult\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
R3 3xHybrid;Pinnacle PCTV Stereo service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2004-11-22 10:33]
R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 17:52]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-12 22:49:59
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-12 22:51:04
ComboFix-quarantined-files.txt 2008-02-12 21:50:43
.
2008-01-09 20:49:09 --- E O F ---