ComboFix 08-11-18.A2 - Frédi 2008-11-19 20:19:03.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1038.18.137 [GMT 1:00]
Running from: c:\documents and settings\Frédi\Asztal\ComboFix.exe
Command switches used :: c:\documents and settings\Frédi\Asztal\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\documents and settings\All Users\Start Menu\Programs\Indítópult\svchost.exe
c:\windows\pss\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\outlook . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-10-19 to 2008-11-19 )))))))))))))))))))))))))))))))
.
2008-11-19 20:04 . 2008-11-19 20:04 <DIR> d-------- C:\ERDNT
2008-11-19 20:03 . 2008-11-19 20:04 <DIR> d-------- c:\windows\ERUNT
2008-11-19 20:03 . 2008-11-19 20:03 <DIR> d-------- C:\!FixIEDef
2008-11-18 07:00 . 2006-10-05 03:42 2,560 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-11-18 07:00 . 2006-10-05 03:42 2,432 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-11-16 10:10 . 2008-11-16 10:11 <DIR> d-------- c:\program files\RSL
2008-11-15 18:06 . 2008-11-15 18:19 <DIR> d-------- c:\program files\Starcrossed
2008-11-12 06:46 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 06:45 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-04 18:51 . 2008-11-04 18:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\EmailNotifier
2008-11-02 08:53 . 2008-11-02 08:53 <DIR> d-------- c:\program files\Nuclear Coffee
2008-11-02 00:56 . 2008-05-08 02:03 453,632 --a------ c:\windows\system32\SetACL.ocx
2008-10-30 18:54 . 2008-10-30 18:53 410,976 --a------ c:\windows\system32\deploytk.dll
2008-10-30 18:50 . 2008-10-30 18:50 <DIR> d-------- c:\program files\Sun
2008-10-25 11:04 . 2008-10-25 11:04 34,308 --a------ c:\windows\system32\Chip.dll
2008-10-25 11:03 . 2008-10-25 11:04 <DIR> d-------- c:\program files\MagicDVDRipper
2008-10-25 10:14 . 2008-10-25 10:32 <DIR> d-------- c:\documents and settings\Internet\Application Data\Personal Video Database
2008-10-25 10:11 . 2008-10-25 10:11 <DIR> d-------- c:\program files\Personal Video Database
2008-10-25 10:11 . 2008-10-25 10:12 <DIR> d-------- c:\documents and settings\Frédi\Application Data\Personal Video Database
2008-10-25 08:40 . 2008-10-25 08:46 <DIR> d-------- C:\tmpDownload
2008-10-25 07:53 . 2008-10-25 07:59 <DIR> d-------- c:\program files\eToro
2008-10-24 15:10 . 2008-10-24 15:13 <DIR> d-------- c:\program files\WhereIsIt
2008-10-24 08:08 . 2008-10-24 08:18 <DIR> d-------- c:\program files\FairUse Wizard 2
2008-10-24 07:29 . 2008-10-15 17:37 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 09:26 . 2008-10-23 09:26 <DIR> d-------- c:\documents and settings\Frédi\Application Data\Apple Computer
2008-10-22 18:09 . 2008-10-22 18:09 <DIR> d-------- c:\documents and settings\Internet\Application Data\Ashampoo
2008-10-22 17:54 . 2008-10-22 17:54 <DIR> d-------- c:\documents and settings\Frédi\Application Data\Ashampoo
2008-10-21 16:56 . 2008-10-21 16:56 <DIR> d-------- c:\program files\IObit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 18:01 --------- d-----w c:\documents and settings\Frédi\Application Data\Free Download Manager
2008-11-19 17:21 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-18 21:09 --------- d-----w c:\documents and settings\Internet\Application Data\JewelMatch2
2008-11-18 06:00 --------- d-----w c:\program files\Picasa2
2008-11-15 09:42 --------- d-----w c:\documents and settings\All Users\Application Data\Extra Audio Drive Software
2008-11-14 18:19 --------- d-----w c:\program files\Gabest
2008-11-14 17:56 --------- d-----w c:\program files\Magic Video Converter
2008-11-09 08:30 --------- d-----w c:\documents and settings\Internet\Application Data\Audacity
2008-11-09 07:55 --------- d-----w c:\documents and settings\Frédi\Application Data\Audacity
2008-11-08 15:49 --------- d-----w c:\documents and settings\Internet\Application Data\Skype
2008-11-03 05:28 --------- d-----w c:\documents and settings\Internet\Application Data\Free Download Manager
2008-11-02 07:44 --------- d-----w c:\program files\Ashampoo
2008-11-01 14:06 --------- d-----w c:\program files\Jewel Quest III
2008-11-01 11:17 --------- d-----w c:\documents and settings\Internet\Application Data\Vso
2008-11-01 10:08 --------- d-----w c:\program files\Zuma Deluxe
2008-11-01 10:07 --------- d-----w c:\program files\Jewel Quest 2
2008-11-01 10:06 --------- d-----w c:\program files\7 Wonders
2008-11-01 10:04 --------- d-----w c:\documents and settings\Frédi\Application Data\JewelMatch2
2008-10-30 17:53 --------- d-----w c:\program files\Java
2008-10-29 05:29 --------- d-----w c:\documents and settings\Frédi\Application Data\Vso
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 09:00 --------- d-----w c:\documents and settings\All Users\Application Data\ashampoo
2008-10-20 17:43 --------- d-----w c:\program files\LimeWire
2008-10-20 17:41 --------- d-----w c:\program files\El Dorado Quest
2008-10-18 19:02 --------- d-----w c:\program files\Aimersoft
2008-10-18 12:01 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-18 12:01 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-10-18 08:52 --------- d-----w c:\program files\Jewel Match 2
2008-10-17 15:58 43,698 ----a-w c:\windows\system32\xvid-uninstall.exe
2008-10-17 15:58 --------- d-----w c:\program files\AviSynth 2.5
2008-10-17 15:45 --------- d-----w c:\program files\DVDFab 5
2008-10-17 15:41 47,360 ----a-w c:\documents and settings\Frédi\Application Data\pcouffin.sys
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 17:32 --------- d-----w c:\program files\vso
2008-10-11 13:48 --------- d-----w c:\documents and settings\Internet\Application Data\LimeWire
2008-10-11 13:38 --------- d-----w c:\documents and settings\Internet\Application Data\Nokia
2008-10-11 13:37 --------- d-----w c:\documents and settings\Internet\Application Data\PC Suite
2008-10-11 13:37 --------- d-----w c:\documents and settings\Frédi\Application Data\PC Suite
2008-10-01 15:43 --------- d-----w c:\documents and settings\Frédi\Application Data\Ponys
2008-09-30 17:05 --------- d-----w c:\program files\Gamenext
2008-09-30 17:05 --------- d-----w c:\program files\Common Files\Oberon Media
2008-09-29 15:03 --------- d-----w c:\program files\Mah Jong Quest
2008-09-28 12:02 --------- d-----w c:\documents and settings\All Users\Application Data\vsosdk
2008-09-27 08:06 --------- d-----w c:\program files\Reference Assemblies
2008-09-27 08:06 --------- d-----w c:\program files\MSBuild
2008-09-26 18:14 --------- d-----w c:\program files\Sexy Poker 5
2008-09-26 18:11 --------- d-----w c:\program files\Age Of Japan
2008-09-25 15:40 --------- d-----w c:\program files\Luxor Five Star Pack
2008-09-25 15:38 --------- d-----w c:\program files\Yahoo!
2008-09-25 15:35 --------- d-----w c:\program files\Mario Forever
2008-09-25 15:31 --------- d-----w c:\program files\AimGames
2008-09-24 17:00 --------- d-----w c:\program files\BCDC++
2008-09-23 17:22 --------- d-----w c:\program files\ACE Mega CoDecS Pack
2008-09-22 17:55 --------- d-----w c:\program files\Circle Developement
2008-09-22 16:25 --------- d-----w c:\program files\ESET
2008-09-22 16:25 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-09-22 12:05 --------- d-----w c:\program files\GameHouse
2008-09-21 14:11 --------- d-----w c:\documents and settings\Frédi\Application Data\URSE Games
2008-09-21 10:39 --------- d-----w c:\program files\DivX
2008-09-20 17:57 --------- d-----w c:\documents and settings\Internet\Application Data\7Wonders
2008-09-20 16:17 --------- d-----w c:\documents and settings\Frédi\Application Data\7Wonders
2008-09-20 05:37 --------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2008-09-20 05:34 --------- d-----w c:\documents and settings\Frédi\Application Data\AVG7
2008-09-19 15:29 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-19 15:19 --------- d-----w c:\program files\Pastry Passion
2008-09-15 15:27 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:16 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 08:27 826,368 ----a-w c:\windows\system32\wininet.dll
2005-04-22 04:07 184 -c--a-w c:\program files\Free-Codecs.txt
2004-11-28 19:33 1,208,320 ----a-w c:\program files\IfoEdit.exe
2002-11-06 19:42 237,568 ----a-w c:\program files\VobEdit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-11-19_19.11.50.99 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 16:00:28 157,696 ----a-w c:\windows\ERUNT\ERUNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Free Uploader Oe Integration"="c:\program files\Free Download Manager\FUM\fumoei.exe" [2007-06-10 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-12-14 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-12-14 458752]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]
"DefragTaskBar"="c:\program files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2007-02-12 168120]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-12-14 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-30 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= c:\windows\Common\bin\iac25_32.ax
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MJPG"= JPEGCODE.DLL
"vidc.ffds"= c:\progra~1\ffdshow\ffdshow.ax
"VIDC.HFYU"= huffyuv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Indítópult^svchost.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Indítópult\svchost.exe
backup=c:\windows\pss\svchost.exeCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Gigabyte\\BIOS\\GWF32.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Java\\jre1.5.0_11\\bin\\javaw.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashGet\\FlashGet.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
R3 N100;Compaq Ethernet vagy Fast Ethernet hálózati adapter illesztőprogramja;c:\windows\system32\DRIVERS\n100325.sys [2006-09-09 131072]
S3 3dfxvs;3dfxvs;c:\windows\system32\DRIVERS\3dfxvsm.sys [2006-09-16 148352]
S3 pccsmcfd;PCCS Mode Change Filter Driver;c:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-24 21632]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\DRIVERS\WPN111.sys [2008-02-05 362944]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-19 20:24:53
Windows 5.1.2600 Szervizcsomag 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2008-11-19 20:33:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-19 19:33:23
ComboFix2.txt 2008-11-19 18:13:09
Pre-Run: 11 327 922 176 bájt szabad
Post-Run: 11,319,902,208 bájt szabad
216 --- E O F --- 2008-11-12 06:09:47