A prepac predtym som zabudol vypnut tu obnovu systemu

.
Alwe ked je vypnuta a spustim ten Awanger tak mi nevyhodi po restarte log ale ked som ho stustil druhykrat tak napisal ze tie subory nemoze najst tak su asi vymazane.
Ale radsej som stiahol aj ten combofix
ComboFix 08-01-17.5 - Dusan 2008-01-17 15:23:42.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.640 [GMT 1:00]
Running from: C:\Documents and Settings\Dusan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\winsys.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.
2008-01-17 15:22 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 10:43 . 2008-01-17 00:11 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-16 10:31 . 2008-01-16 10:31 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\Nero
2008-01-16 10:28 . 2008-01-16 10:28 <DIR> d-------- C:\Program Files\Nero
2008-01-16 10:28 . 2008-01-16 10:29 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-01-16 10:28 . 2008-01-16 10:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-01-12 20:46 . 2008-01-12 20:46 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-12 20:46 . 2008-01-16 17:55 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-01-12 20:46 . 2008-01-12 20:46 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-01-12 20:46 . 2008-01-16 17:55 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-12 18:07 . 2008-01-12 18:07 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-01-12 18:07 . 2004-02-22 10:11 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-01-12 18:07 . 2006-10-07 17:43 502,784 --a------ C:\WINDOWS\x2.64.exe
2008-01-12 18:07 . 2007-05-14 15:24 394,240 --a------ C:\WINDOWS\system32\Smab.dll
2008-01-12 18:07 . 2007-05-17 17:30 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2008-01-12 18:07 . 2005-02-28 13:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2008-01-12 18:07 . 2006-04-12 09:47 217,073 --a------ C:\WINDOWS\meta4.exe
2008-01-12 18:07 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-01-12 18:07 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2008-01-12 18:07 . 2006-04-05 08:09 66,560 --a------ C:\WINDOWS\MOTA113.exe
2008-01-12 18:07 . 2005-07-14 12:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-01-12 18:06 . 2008-01-12 18:06 <DIR> d-------- C:\Program Files\eRightSoft
2008-01-12 14:42 . 2008-01-12 14:42 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\GlarySoft
2008-01-12 14:41 . 2008-01-12 14:41 <DIR> d-------- C:\Program Files\Absolute Uninstaller
2008-01-11 18:05 . 2008-01-11 18:06 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\RegClean
2008-01-11 16:12 . 2008-01-11 16:17 <DIR> d-------- C:\Program Files\AusLogics Registry Defrag
2008-01-11 09:56 . 2008-01-11 09:56 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-01-11 09:56 . 2008-01-11 09:56 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\TuneUp Software
2008-01-11 09:56 . 2008-01-11 09:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-01-11 09:56 . 2008-01-11 09:56 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-01-11 09:56 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-01-11 09:55 . 2008-01-11 09:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-10 00:48 . 2008-01-10 00:48 <DIR> d-------- C:\Program Files\Ashampoo
2008-01-09 18:21 . 2004-02-26 11:56 38,872 --------- C:\WINDOWS\hpomdl03.dat.temp
2008-01-09 18:21 . 2008-01-03 18:01 29,363 --------- C:\WINDOWS\hpoins03.dat.temp
2008-01-06 23:46 . 2008-01-06 23:46 <DIR> d-------- C:\Program Files\VentriloMIX
2008-01-06 23:22 . 2008-01-06 23:48 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\Ventrilo
2008-01-06 10:02 . 2008-01-07 09:55 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-01-06 09:56 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-06 09:56 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-06 09:56 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-05 19:10 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-01-05 19:09 . 2008-01-05 19:09 <DIR> d-------- C:\Program Files\MSBuild
2008-01-05 19:09 . 2008-01-05 19:09 <DIR> d-------- C:\Program Files\Microsoft Works
2008-01-05 19:08 . 2008-01-05 19:08 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-05 19:06 . 2008-01-05 19:09 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-05 19:05 . 2008-01-05 19:05 <DIR> d-------- C:\MSOCache
2008-01-05 19:05 . 2008-01-08 07:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-05 16:35 . 2008-01-05 16:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-05 02:29 . 2008-01-05 02:29 <DIR> d-------- C:\Program Files\Defraggler
2008-01-04 10:16 . 2008-01-04 10:16 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-03 21:21 . 2008-01-03 21:24 <DIR> d-------- C:\Program Files\ICQ6
2008-01-03 21:21 . 2008-01-03 21:24 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\ICQ
2008-01-03 18:00 . 2004-02-26 11:56 51,056 -ra------ C:\WINDOWS\system32\drivers\hpzid412.sys
2008-01-03 18:00 . 2004-02-26 11:56 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-01-03 17:59 . 2004-02-26 11:56 21,488 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-01-03 17:59 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-01-03 17:59 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-01-03 17:40 . 2008-01-03 17:40 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-01-03 17:40 . 2003-12-11 11:15 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2008-01-03 17:40 . 2003-12-11 11:15 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2008-01-03 17:40 . 2003-12-11 11:15 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2008-01-03 17:40 . 2003-12-11 11:15 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2008-01-03 17:35 . 2008-01-03 17:35 <DIR> d-------- C:\Program Files\Common Files\HP
2008-01-03 17:33 . 2008-01-03 17:34 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-01-03 17:28 . 2008-01-03 17:40 <DIR> d-------- C:\Program Files\HP
2008-01-03 17:26 . 2004-02-26 11:56 38,872 --------- C:\WINDOWS\hpomdl03.dat
2008-01-03 17:26 . 2008-01-03 18:01 29,363 --------- C:\WINDOWS\hpoins03.dat
2008-01-03 14:25 . 2008-01-03 14:25 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-03 14:25 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-01-03 14:25 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-03 14:25 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-03 14:25 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-03 14:25 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 14:25 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 14:25 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 14:25 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-03 14:25 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-02 22:18 . 2008-01-02 22:22 <DIR> d-------- C:\Program Files\ewido anti-malware
2008-01-02 19:18 . 2008-01-02 19:18 45,768 --a------ C:\WINDOWS\system32\drivers\MiniIcpt.sys
2008-01-01 10:40 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-01-01 10:40 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-01-01 10:31 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-01-01 10:31 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-12-26 23:49 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-12-21 16:37 . 2007-12-21 16:37 <DIR> d-------- C:\Documents and Settings\Dusan\UserData
2007-12-21 15:51 . 2007-12-21 15:51 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\InstallShield
2007-12-21 15:04 . 2007-12-21 15:04 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-12-21 14:48 . 2007-12-21 14:48 <DIR> d-------- C:\Program Files\QuickTime
2007-12-21 14:48 . 2007-12-21 14:48 <DIR> d-------- C:\Program Files\Apple Software Update
2007-12-21 14:48 . 2007-12-21 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-12-21 14:45 . 2007-12-21 15:22 <DIR> d-------- C:\Documents and Settings\Dusan\Graphisoft
2007-12-21 14:45 . 2007-12-21 14:52 <DIR> d-------- C:\Documents and Settings\Dusan\Application Data\Graphisoft
2007-12-21 13:55 . 2007-12-21 13:55 <DIR> d-------- C:\WINDOWS\system32\xlive
2007-12-21 13:55 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-12-21 13:55 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-12-21 13:55 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-12-21 13:55 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-12-21 13:55 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-12-21 13:55 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 20:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-02 18:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-20 21:59 --------- d-----w C:\Program Files\Codec Pack - All In 1
2007-12-20 21:58 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-20 21:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-20 21:36 --------- d-----w C:\Program Files\Realtek
2007-12-20 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2007-12-20 21:13 --------- d-----w C:\Program Files\BillP Studios
2007-12-20 21:11 --------- d-----w C:\Documents and Settings\Dusan\Application Data\WinPatrol
2007-12-20 21:03 --------- d-----w C:\Documents and Settings\Dusan\Application Data\Avant Profiles
2007-12-20 21:02 --------- d-----w C:\Program Files\Avant Browser
2007-12-20 20:21 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-13 18:09 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-12-04 08:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-12-03 17:04 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
2007-11-21 16:31 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys
2007-11-21 16:31 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys
2007-11-14 15:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-18 02:15 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 03:37 69632]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 17:06 292152]
"Task Catcher"="C:\PROGRA~1\BILLPS~1\TASKCA~1\tasktrap.exe" [2005-11-14 13:05 136760]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 10:22 7618560]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-06 04:44 16262656 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]
R0 tcdmeaan;tcdmeaan;C:\WINDOWS\system32\drivers\hocdralv.sys []
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:56]
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 22:04]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-11 09:56]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
*Newly Created Service* - TCDMEAAN
.
Contents of the 'Scheduled Tasks' folder
"2008-01-11 16:15:49 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-17 15:25:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-17 15:26:23
ComboFix-quarantined-files.txt 2008-01-17 14:26:20
.
2008-01-17 08:03:58 --- E O F ---