Ja itt van a log.txt:
Feltett a Combo futtatáskor egy kérdést a Recovery Console-ról... meg hogy ez Windows XP Home Edition... EZEN A GÉPEN WINDOWS XP Professional SP3 op. rendszer van!!!
A log végén is mi ez a WinXP_EN_HOM_BF.EXE ????
ComboFix 12-02-27.02 - Kovács Ferenc 012.02.28. 14:14:43.1.2 - x86
Running from: c:\documents and settings\Kovßcs Ferenc\Asztal\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: PC Tools Firewall Plus *Enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\tmp42.tmp
c:\windows\system32\tmp43.tmp
c:\windows\system32\TZLog.log
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-01-28 to 2012-02-28 )))))))))))))))))))))))))))))))
.
.
2012-02-27 09:32 . 2012-02-27 09:32 -------- d-----w- c:\windows\system32\NtmsData
2012-02-26 10:44 . 2012-02-26 10:44 -------- d-----w- c:\documents and settings\Kovács Ferenc\Application Data\PCToolsFirewallPlus
2012-02-26 10:43 . 2011-03-02 11:40 160576 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2012-02-26 10:43 . 2010-03-29 10:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2012-02-26 10:43 . 2011-01-17 08:10 251560 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2012-02-26 10:42 . 2012-02-26 10:43 -------- d-----w- c:\program files\Common Files\PC Tools
2012-02-26 10:42 . 2011-01-12 09:36 89472 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2012-02-26 10:42 . 2010-07-08 07:49 57536 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2012-02-26 10:42 . 2010-02-05 07:26 32808 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2012-02-26 10:42 . 2011-01-17 07:11 125248 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2012-02-26 10:42 . 2012-02-26 10:44 -------- d-----w- c:\program files\PC Tools Firewall Plus
2012-02-25 14:32 . 2012-02-25 14:32 -------- d-----w- c:\program files\Defraggler
2012-02-25 13:51 . 2012-02-25 13:51 -------- d-----w- c:\documents and settings\Kovács Ferenc\Application Data\Avira
2012-02-25 13:51 . 2012-02-26 13:52 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-02-25 13:51 . 2011-09-15 22:55 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-02-25 13:51 . 2011-09-15 22:55 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-02-25 13:51 . 2012-02-25 13:51 -------- d-----w- c:\program files\Avira
2012-02-25 13:51 . 2012-02-25 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2012-02-25 13:49 . 2012-02-25 13:49 -------- d--h--w- c:\windows\system32\GroupPolicy
2012-02-24 07:40 . 2012-02-24 07:40 -------- d-----w- c:\documents and settings\Kovács Ferenc\Application Data\Malwarebytes
2012-02-24 07:39 . 2012-02-24 07:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-02-24 07:39 . 2012-02-24 07:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-24 07:39 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-20 11:15 . 2012-02-20 11:15 -------- d-----w- c:\documents and settings\Kovács Ferenc\Application Data\Ace
2012-02-17 11:44 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-17 11:44 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-14 09:45 . 2012-02-14 09:45 -------- d-----w- c:\documents and settings\Kovács Ferenc\Local Settings\Application Data\Skyrim
2012-02-06 11:17 . 2012-02-06 11:17 -------- d-----w- c:\documents and settings\Kovács Ferenc\Local Settings\Application Data\BigHugeEngine
2012-02-05 06:57 . 2012-02-05 06:57 -------- d-----w- c:\documents and settings\Kovács Ferenc\Application Data\fizzy
2012-02-03 09:29 . 2012-02-03 09:29 42392 ----a-w- c:\windows\system32\xfcodec.dll
2012-01-30 09:17 . 2012-01-30 09:17 -------- d-----w- c:\program files\uTorrent
2012-01-30 08:42 . 2012-02-28 12:49 -------- d-----w- c:\documents and settings\Kovács Ferenc\Application Data\uTorrent
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-24 16:59 . 2011-07-26 09:47 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-02-24 16:59 . 2011-07-26 08:08 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-02-22 09:24 . 2011-07-20 16:46 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-13 15:08 . 2011-07-26 08:09 140232 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-02-13 15:08 . 2011-07-26 08:08 283416 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-02-12 19:49 . 2011-07-26 08:09 138904 ----a-w- c:\documents and settings\Kovács Ferenc\Application Data\PnkBstrK.sys
2012-02-12 19:49 . 2011-07-26 08:08 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-01-31 03:59 . 2011-07-21 19:24 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-12 17:20 . 2008-04-15 12:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2008-04-15 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2008-04-15 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:42 . 2008-04-15 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:23 . 2008-04-15 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-02-19 07:57 . 2011-07-20 16:46 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kovács Ferenc\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kovács Ferenc\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kovács Ferenc\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kovács Ferenc\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-13 16871936]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2011-04-07 2672600]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-07-24 17:37 136176 ----atw- c:\documents and settings\Kovács Ferenc\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-02-07 12:18 1987976 ----a-w- d:\hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-08-12 11:18 205336 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2011-12-28 22:03 3082320 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 11:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Documents and Settings\\Kovács Ferenc\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Steam\\steamapps\\thompson1999\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"d:\\PC-GAMES\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\warincbattlezone\\WarInc.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\mafia ii - public demo\\launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\warincbattlezone\\rsupdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\lead and gold gangs of the wild west\\lag_win32_public_dev.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\duke nukem forever demo\\System\\DukeForeverDemo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty black ops\\BlackOps.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Documents and Settings\\Kovács Ferenc\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\memoir '44 online\\Memoir'44 Online.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\apb reloaded\\Launcher\\APBLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"d:\\PC-GAMES\\Modern Warfare 2 - Multiplayer\\iw4mp.dat"=
"d:\\PC-GAMES\\3DO\\Heroes 3 Complete\\HEROES3.EXE"=
"d:\\PC-GAMES\\Heroes of Might and Magic V - Collectors Edition\\HMM5\\bina2\\bin\\H5_Game.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 3\\iw5mp_server.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 3\\iw5sp.exe"=
"c:\\Program Files\\Steam\\steamapps\\thompson1999\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 3\\iw5mp.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\apb reloaded\\Binaries\\APB.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\apb reloaded\\Binaries\\VivoxVoiceService.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead 2\\left4dead2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"d:\\PC-GAMES\\Ubisoft\\Assassin's Creed Revelations\\ACRSP.exe"=
"d:\\PC-GAMES\\Ubisoft\\Assassin's Creed Revelations\\ACRMP.exe"=
"d:\\PC-GAMES\\Ubisoft\\Assassin's Creed Revelations\\AssassinsCreedRevelations.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57992:TCP"= 57992:TCP:Pando Media Booster
"57992:UDP"= 57992:UDP:Pando Media Booster
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012.02.25. 14:51 36000]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2012.02.26. 11:43 251560]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2012.02.25. 14:51 86224]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\hamachi\hamachi-2.exe -s --> d:\hamachi\hamachi-2.exe -s [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011.10.08. 7:01 2253120]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2012.02.26. 11:43 160576]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [2011.08.19. 10:26 450848]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011.08.08. 0:43 232512]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2012.02.26. 11:42 89472]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2012.02.26. 11:42 57536]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2012.02.26. 11:42 125248]
S2 gupdate;Google frissítés Szolgáltatás (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2012.01.15. 11:01 136176]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 gupdatem;Google frissítés Szolgáltatás (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2012.01.15. 11:01 136176]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2012.02.26. 11:42 57536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 12:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-15 10:01]
.
2012-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-15 10:01]
.
.
------- Supplementary Scan -------
.
IE: E&xportálás a Microsoft Excel programba - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Kovács Ferenc\Application Data\Mozilla\Firefox\Profiles\l7g2kvp0.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - XfireXO Customized Web Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-02-28 14:29
Windows 5.1.2600 Szervizcsomag 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1004336348-1343024091-1417001333-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2012-02-28 14:34:56
ComboFix-quarantined-files.txt 2012-02-28 13:34
.
Pre-Run: 130 600 390 656 bájt szabad
Post-Run: 131 140 280 320 bájt szabad
.
WinXP_EN_HOM_BF.EXE
.
- - End Of File - - B15B19DB0A139893C40517DA5F8C25F0