Zde je LOG z ComboFix:
(Spravce uloh začal fungovat) fakt diky,
Ale zjistila jsem ze mi z systemove listy zmizel antivir, ale to prozatim neva, nebot na tom PC nejsem pripojena k siti.
ComboFix 08-06-12.2 - Administrator 2008-06-15 20:20:59.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.192 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Data aplikací\Starware316
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\findithotxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\finditxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\Highlight.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\HighlightHot.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\highlighthotxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\highlightxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\Reference.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\ReferenceHot.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\referencehotxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\referencexp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\screensaver.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\starware_toolbar_icon.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\Weather.bmp
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\weatherhotxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\buttons\weatherxp.png
C:\Documents and Settings\All Users\Data aplikací\Starware316\contexts\error.xml
C:\Documents and Settings\All Users\Data aplikací\Starware316\contexts\related.xml
C:\Documents and Settings\All Users\Data aplikací\Starware316\contexts\travel.xml
C:\Program Files\PC-Cleaner
C:\RECYCLER\Desktop.ini
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\Fonts\FontLab\TransType Pro\Macros\System
C:\WINDOWS\Fonts\FontLab\TransType Pro\Macros\System\Modules\flsys.py
C:\WINDOWS\Fonts\FontLab\TransType Pro\Macros\System\Tool\demo.py
C:\WINDOWS\Fonts\FontLab\TransType Pro\Macros\System\Tool\shadow.py
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\resources\CDAvp.dll
C:\WINDOWS\system32\atmdkkva.ini
C:\WINDOWS\system32\atmwmaxu.dll
C:\WINDOWS\system32\bwbwohsb.ini
C:\WINDOWS\system32\bydfirkc.dll
C:\WINDOWS\system32\cawwgsnr.ini
C:\WINDOWS\system32\cefunkkr.dll
C:\WINDOWS\system32\fjiwfepg.dll
C:\WINDOWS\system32\fkymgwuj.dll
C:\WINDOWS\system32\gegdbxgs.ini
C:\WINDOWS\system32\geumecij.dll
C:\WINDOWS\system32\hngjkkas.dll
C:\WINDOWS\system32\huencqtg.dll
C:\WINDOWS\system32\ibcefbuf.dll
C:\WINDOWS\system32\ifapaiuu.ini
C:\WINDOWS\system32\ikefolna.dll
C:\WINDOWS\system32\iubfmfrb.ini
C:\WINDOWS\system32\jlriuvvf.dll
C:\WINDOWS\system32\kcvosxxe.dll
C:\WINDOWS\system32\kfkuueai.ini
C:\WINDOWS\system32\kodolnbr.ini
C:\WINDOWS\system32\luuopbru.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\menbqgkd.dll
C:\WINDOWS\system32\msrsjwps.dll
C:\WINDOWS\system32\mttpmqmq.dll
C:\WINDOWS\system32\nhqklokw.dll
C:\WINDOWS\system32\nnnnOfEt.dll
C:\WINDOWS\system32\olwnxyxk.dll
C:\WINDOWS\system32\osxtpbdj.dll
C:\WINDOWS\system32\owuqrruc.dll
C:\WINDOWS\system32\piicabrp.ini
C:\WINDOWS\system32\pywytxui.dll
C:\WINDOWS\system32\qhuvkbou.dll
C:\WINDOWS\system32\rehoongm.dll
C:\WINDOWS\system32\rqajuswv.dll
C:\WINDOWS\system32\sahggdeb.dll
C:\WINDOWS\system32\spwjsrsm.ini
C:\WINDOWS\system32\sxufqxai.dll
C:\WINDOWS\system32\tbtafekg.dll
C:\WINDOWS\system32\tEfOnnnn.ini
C:\WINDOWS\system32\tEfOnnnn.ini2
C:\WINDOWS\system32\tmorrhef.dll
C:\WINDOWS\system32\ttsqtqqp.ini
C:\WINDOWS\system32\ukpkogoh.dll
C:\WINDOWS\system32\vrfhiufs.dll
C:\WINDOWS\system32\wbixxgce.dll
C:\WINDOWS\system32\wfqjltjy.dll
C:\WINDOWS\system32\wfxtsdcc.dll
C:\WINDOWS\system32akttzn.exe
C:\WINDOWS\system32anticipator.dll
C:\WINDOWS\system32awtoolb.dll
C:\WINDOWS\system32bdn.com
C:\WINDOWS\system32bsva-egihsg52.exe
C:\WINDOWS\system32dpcproxy.exe
C:\WINDOWS\system32emesx.dll
C:\WINDOWS\system32h@tkeysh@@k.dll
C:\WINDOWS\system32hoproxy.dll
C:\WINDOWS\system32hxiwlgpm.dat
C:\WINDOWS\system32hxiwlgpm.exe
C:\WINDOWS\system32medup012.dll
C:\WINDOWS\system32medup020.dll
C:\WINDOWS\system32msgp.exe
C:\WINDOWS\system32msnbho.dll
C:\WINDOWS\system32mssecu.exe
C:\WINDOWS\system32msvchost.exe
C:\WINDOWS\system32mtr2.exe
C:\WINDOWS\system32mwin32.exe
C:\WINDOWS\system32netode.exe
C:\WINDOWS\system32newsd32.exe
C:\WINDOWS\system32ps1.exe
C:\WINDOWS\system32psof1.exe
C:\WINDOWS\system32psoft1.exe
C:\WINDOWS\system32regc64.dll
C:\WINDOWS\system32regm64.dll
C:\WINDOWS\system32Rundl1.exe
C:\WINDOWS\system32smp
C:\WINDOWS\system32smp\msrc.exe
C:\WINDOWS\system32sncntr.exe
C:\WINDOWS\system32ssurf022.dll
C:\WINDOWS\system32ssvchost.com
C:\WINDOWS\system32ssvchost.exe
C:\WINDOWS\system32sysreq.exe
C:\WINDOWS\system32taack.dat
C:\WINDOWS\system32taack.exe
C:\WINDOWS\system32temp#01.exe
C:\WINDOWS\system32thun.dll
C:\WINDOWS\system32thun32.dll
C:\WINDOWS\system32VBIEWER.OCX
C:\WINDOWS\system32vbsys2.dll
C:\WINDOWS\system32vcatchpi.dll
C:\WINDOWS\system32winlogonpc.exe
C:\WINDOWS\system32winsystem.exe
C:\WINDOWS\system32WINWGPX.EXE
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp
.
((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))
.
2008-06-15 19:10 . 2008-06-15 19:10 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-06-15 17:28 . 2008-06-15 19:09 <DIR> d-------- C:\Program Files\RegCleaner
2008-06-15 16:13 . 2008-06-15 16:13 <DIR> d-------- C:\Program Files\CCleaner
2008-06-15 15:27 . 2008-06-15 15:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-15 02:34 . 2008-06-15 02:34 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-06-15 02:34 . 2008-06-15 02:34 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-06-15 02:30 . 2008-06-15 02:30 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-06-15 01:35 . 2008-06-15 01:35 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-15 01:34 . 2008-06-15 02:09 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-06-09 19:39 . 2001-10-24 11:54 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-09 19:39 . 2001-10-24 11:54 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-09 19:39 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-09 19:39 . 2001-08-17 22:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-05-23 17:12 . 2008-05-23 17:12 <DIR> d-------- C:\Program Files\PCLinq2 Hi-Speed USB Bridge Cable
2008-05-23 17:12 . 2003-05-07 15:54 8,960 --a------ C:\WINDOWS\system32\drivers\usbbc2.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 11:16 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-14 23:53 --------- d-----w C:\Program Files\Nokia
2008-06-14 19:18 --------- d-----w C:\Program Files\Landi 2000
2008-06-14 18:56 --------- d-----w C:\Program Files\PortTrigger
2008-05-23 15:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 19:21 72,192 ----a-w C:\WINDOWS\cadkasdeinst01e.exe
2008-04-09 19:01 102,400 ------w C:\WINDOWS\system32\xidwlspg.exe
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 17:25 94208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"hhgrqigd"="C:\WINDOWS\system32\xidwlspg.exe" [2008-04-09 21:01 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 17:48 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 17:44 126976]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-12-10 16:57 133016]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SoundMan"="SOUNDMAN.EXE" [2002-02-05 08:05 46592 C:\WINDOWS\SOUNDMAN.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 07:24 286720]
"PivotSoftware"="C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe" [2005-10-28 13:54 800504]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2004-12-20 20:41 33792]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-06-15 01:35 1817600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUlLcBt]
vtUlLcBt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"C:\\Program Files\\Total Commander\\TOTALCMD.EXE"=
"C:\\Program Files\\Direct Conect\\StrongDC.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\QIP\\qip.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Edisk\\eDisk klient\\eDisk klient.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 Machnm32;Machnm32 Driver;C:\WINDOWS\system32\Machnm32.sys [2004-11-22 13:07]
R1 Pivot;Pivot;C:\WINDOWS\system32\drivers\pivot.sys [2005-10-28 13:54]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-06-15 01:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 cglptnt;cglptnt;C:\WINDOWS\system32\DRIVERS\cglptnt.sys [2005-05-31 07:53]
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 pivotmou;Pivot Mouse/Pointers Filter Driver;C:\WINDOWS\system32\drivers\pivotmou.sys [2005-10-28 13:54]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc2.sys [2003-05-07 15:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb3ff718-a441-11dc-a0d7-00012e02cd90}]
\Shell\AutoRun\command - ntde1ect.com
\Shell\explore\Command - ntde1ect.com
\Shell\open\Command - ntde1ect.com
.
Contents of the 'Scheduled Tasks' folder
"2008-01-28 08:30:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-15 20:32:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Portrait Displays\Pivot Software\winphook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Portrait Displays\Pivot Software\Floater.exe
.
**************************************************************************
.
Completion time: 2008-06-15 20:36:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-15 18:36:07
Adresářů: 9, Volných bajtů: 66,361,757,696
Adres ý…: 11, Volněch bajt…: 66,805,506,048
265 --- E O F --- 2008-04-09 19:16:12