Taky jsem si řikal, že je to dlouho.
Tady je log z ComboFixu:
"Mama" - 2007-07-07 18:02:11 - ComboFix 07-07-07.3 - Service Pack 2
FAT32
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\taskmgr.com
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-06-23 12:58 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-06-23 12:57 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-06-23 12:57 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-06-23 12:57 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-06-23 12:57 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-06-23 12:57 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-06-23 12:57 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-06-23 12:57 <DIR> d-------- C:\Program Files\Alwil Software
2007-06-16 19:05 <DIR> d-------- C:\Program Files\Miranda IM
2007-06-16 12:03 <DIR> d-------- C:\DOCUME~1\Kyta\DATAAP~1\Miranda IM
2007-06-12 15:19 <DIR> dr------- C:\DOCUME~1\NETWOR~1\Oblˇben‚ polo§ky
2007-06-08 18:24 51,200 --a------ C:\WINDOWS\nircmd.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-31 19:46:24 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-16 15:18:40 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-09 13:41:46 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-08 11:44:28 -------- d-----w C:\DOCUME~1\Mama\DATAAP~1\OpenOffice.org2
2007-04-26 12:54:18 46,016 ----a-w C:\WINDOWS\system32\perfc005.dat
2007-04-26 12:54:18 309,716 ----a-w C:\WINDOWS\system32\perfh005.dat
2007-04-25 14:22:50 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:15:26 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 20:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 20:43:40 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-12 00:47 50376 --a------ C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 10:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-02-24 21:10]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 19:19]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 14:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
Contents of the 'Scheduled Tasks' folder
2005-03-27 12:19:02 C:\WINDOWS\tasks\CAMEDIA Master.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-07 18:03:51
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 18:04:24
C:\ComboFix-quarantined-files.txt ... 2007-07-07 18:04
--- E O F ---
A tady z FindAWF:
Find AWF report by noahdfear ©2006
bak folders found
~~~~~~~~~~~
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
end of report