Tady je log z ComboFix:
ComboFix 08-08-21.02 - Libor Formánek 2008-08-23 20:10:42.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1029.18.240 [GMT 2:00]
Running from: C:\Documents and Settings\Libor Formánek\Plocha\TermVir.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Secure Solutions
C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Secure Solutions\Antispyware 2008 XP\LOG\20080817194709812.log
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@2o7[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@ad.yieldmanager[2].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@clicktorrent[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@counter.cnw[2].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@hits.gureport.co[2].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@indextools[2].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@pikant.centrum[6].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@pocitadlo[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@revsci[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@server.cpmstar[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@seznam[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@www.mp3search[1].txt
C:\Documents and Settings\Libor Formánek\Cookies\libor_formánek@www.pixmania[2].txt
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA.cfg
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA0.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA1.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA2.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA3.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA4.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA5.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA6.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA7.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA8.che
C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\MUZAoDA9.che
C:\WINDOWS\BM739564bf.txt
C:\WINDOWS\BM739564bf.xml
C:\WINDOWS\clofghls.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\jestertb.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cgqvnguc.ini
C:\WINDOWS\system32\cvudoora.ini
C:\WINDOWS\system32\dkgedjhu.dll
C:\WINDOWS\system32\dwymguby.dll
C:\WINDOWS\system32\hxnkcyke.dll
C:\WINDOWS\system32\lUBLUvut.ini
C:\WINDOWS\system32\lUBLUvut.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nuavypqs.ini
C:\WINDOWS\system32\oxphawbv.dll
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\rrcpbbfb.dll
C:\WINDOWS\system32\tuvutsfq.ini
C:\WINDOWS\system32\uhjdegkd.ini
C:\WINDOWS\system32\vdvehcew.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-23 to 2008-08-23 )))))))))))))))))))))))))))))))
.
2008-08-19 21:07 . 2008-08-19 21:07 578,560 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-08-19 20:49 . 2008-08-19 20:49 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-17 22:00 . 2008-08-17 22:00 <DIR> d-------- C:\Program Files\Windows Defender
2008-08-17 19:53 . 2008-08-23 12:18 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-17 19:50 . 2008-08-23 17:37 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-17 19:50 . 2008-08-17 19:50 <DIR> d-------- C:\Program Files\AVG
2008-08-17 19:50 . 2008-08-17 19:50 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-17 19:50 . 2008-08-17 19:50 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-17 19:50 . 2008-08-17 19:50 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-15 16:12 . 2008-08-15 16:12 <DIR> d-------- C:\WINDOWS\system32\The X-Files - I Want To Believe dir
2008-08-15 16:12 . 2008-08-15 16:12 520,192 --a------ C:\WINDOWS\system32\The X-Files - I Want To Believe.scr
2008-08-14 07:37 . 2008-05-01 16:37 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 07:35 . 2008-04-11 21:06 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-05 12:42 . 2008-08-15 16:49 <DIR> d-------- C:\Program Files\Pivot Stickfigure Animator
2008-08-02 18:23 . 2008-08-02 18:36 <DIR> d-------- C:\Program Files\MIKSOFT
2008-08-01 20:39 . 2008-08-01 20:39 <DIR> d-------- C:\Program Files\Ubisoft
2008-07-28 10:52 . 2008-07-28 10:53 <DIR> d-------- C:\Program Files\LEGO Software
2008-07-25 10:36 . 2008-07-25 10:36 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-07-25 10:36 . 2008-07-25 10:36 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-07-23 18:50 . 2008-07-23 18:50 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 18:48 . 2008-07-23 18:48 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-07-23 18:48 . 2008-07-23 18:48 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-07-23 18:47 . 2008-07-23 18:47 416 --a------ C:\WINDOWS\system32\dtu100.dll.manifest
2008-07-23 18:47 . 2008-07-23 18:47 416 --a------ C:\WINDOWS\system32\dpl100.dll.manifest
2008-07-23 18:46 . 2008-07-23 18:46 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-23 10:33 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-17 19:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-17 18:45 --------- d-----w C:\Program Files\Congoo NetPass
2008-08-17 18:06 --------- d-----w C:\Program Files\Phenomedia AG
2008-08-17 17:55 --------- d-----w C:\Program Files\AOL Security Toolbar
2008-08-15 12:50 --------- d-----w C:\Program Files\DivX
2008-08-02 16:23 --------- d-----w C:\Program Files\MediaCoder
2008-07-23 19:27 --------- d-----w C:\Program Files\Power Mp3 Cutter(Mp3 Sound Cutter)
2008-07-21 20:56 --------- d-----w C:\Program Files\Sony Corporation
2008-07-10 10:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 20:01 --------- d-----w C:\Program Files\VSTplugins
2008-07-09 19:50 --------- d-----w C:\Program Files\CENZURA
2008-07-09 19:16 --------- d-----w C:\Program Files\Sony
2008-07-09 19:13 --------- d-----w C:\Program Files\Microsoft Games
2008-07-07 10:06 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-07-07 10:04 --------- d-----w C:\Program Files\Sony Setup
2008-07-07 09:51 --------- d-----w C:\Program Files\MSBuild
2008-07-07 09:49 --------- d-----w C:\Program Files\Reference Assemblies
2008-07-04 15:02 --------- d-----w C:\Program Files\ElastoMania111
2008-07-03 11:21 --------- d-----w C:\Program Files\Mario Forever
2008-07-03 09:29 --------- d-----w C:\Program Files\city of world
2008-07-02 12:56 --------- d-----w C:\Program Files\Moucha
2008-07-01 13:27 --------- d-----w C:\Program Files\Project Zeit
2008-07-01 13:17 --------- d-----w C:\Program Files\WinMatrix XP
2008-07-01 12:32 --------- d-----w C:\Program Files\Blender Foundation
2008-06-27 13:27 --------- d-----w C:\Program Files\Rockstar Games
2008-06-25 11:38 2,813,952 ----a-w C:\WINDOWS\Mann-Filter Rallye.scr
2008-06-24 17:25 --------- d-----w C:\Program Files\Laser Dolphin
2008-06-23 14:24 352,256 ----a-w C:\WINDOWS\eSellerateEngine.dll
2006-03-31 11:56 917,318 -c--a-w C:\Program Files\Apr2006_MDX1_x86.cab
2006-03-31 11:56 87,989 -c--a-w C:\Program Files\Apr2006_xinput_x64.cab
2006-03-31 11:56 46,898 -c--a-w C:\Program Files\Apr2006_xinput_x86.cab
2006-03-31 11:56 41,890 -c--a-w C:\Program Files\dxdllreg_x86.cab
2006-03-31 11:56 4,163,518 -c--a-w C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2006-03-31 11:56 180,021 -c--a-w C:\Program Files\Apr2006_xact_x64.cab
2006-03-31 11:56 133,991 -c--a-w C:\Program Files\Apr2006_xact_x86.cab
2006-03-31 11:56 1,398,718 -c--a-w C:\Program Files\Apr2006_d3dx9_30_x64.cab
2006-03-31 11:56 1,116,109 -c--a-w C:\Program Files\Apr2006_d3dx9_30_x86.cab
2006-03-31 11:41 81,733 -c--a-w C:\Program Files\dxupdate.cab
2006-03-31 11:40 484,560 -c--a-w C:\Program Files\DXSETUP.exe
2006-03-31 11:40 2,248,912 -c--a-w C:\Program Files\dsetup32.dll
2006-03-31 11:39 74,448 -c--a-w C:\Program Files\DSETUP.dll
2006-02-03 08:00 179,247 -c----w C:\Program Files\Feb2006_xact_x64.cab
2006-02-03 08:00 133,297 -c----w C:\Program Files\Feb2006_xact_x86.cab
2006-02-03 08:00 1,363,684 -c----w C:\Program Files\Feb2006_d3dx9_29_x64.cab
2006-02-03 08:00 1,085,608 -c----w C:\Program Files\Feb2006_d3dx9_29_x86.cab
2005-12-05 17:31 86,925 -c----w C:\Program Files\Oct2005_xinput_x64.cab
2005-12-05 17:31 46,247 -c----w C:\Program Files\Oct2005_xinput_x86.cab
2005-12-05 17:31 1,358,864 -c----w C:\Program Files\Dec2005_d3dx9_28_x64.cab
2005-12-05 17:31 1,080,344 -c----w C:\Program Files\Dec2005_d3dx9_28_x86.cab
2005-07-22 18:14 1,351,430 -c----w C:\Program Files\Aug2005_d3dx9_27_x64.cab
2005-07-22 18:14 1,078,532 -c----w C:\Program Files\Aug2005_d3dx9_27_x86.cab
2005-05-26 13:49 1,336,890 -c----w C:\Program Files\Jun2005_d3dx9_26_x64.cab
2005-05-26 13:49 1,065,813 -c----w C:\Program Files\Jun2005_d3dx9_26_x86.cab
2005-03-18 16:40 1,348,242 -c----w C:\Program Files\Apr2005_d3dx9_25_x64.cab
2005-03-18 16:40 1,079,850 -c----w C:\Program Files\Apr2005_d3dx9_25_x86.cab
2005-02-05 19:03 1,248,387 -c----w C:\Program Files\Feb2005_d3dx9_24_x64.cab
2005-02-05 19:03 1,014,113 -c----w C:\Program Files\Feb2005_d3dx9_24_x86.cab
2004-09-27 10:29 976,020 -c----w C:\Program Files\BDAXP.cab
2004-09-27 10:29 703,080 -c----w C:\Program Files\BDA.cab
2004-09-27 10:29 15,493,481 -c----w C:\Program Files\DirectX.cab
2004-09-27 10:29 13,265,040 -c----w C:\Program Files\dxnt.cab
2004-09-27 10:29 1,156,363 -c----w C:\Program Files\BDANT.cab
2008-05-12 19:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051220080513\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 08:52 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 02:36 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-01 16:16 5562368]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-04-01 16:16 86016]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07 32768]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-17 19:50 1232152]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-06-15 16:12 577536 C:\WINDOWS\soundman.exe]
"nwiz"="nwiz.exe" [2005-04-01 16:16 1495040 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 08:52 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\UT2003\\System\\UT2003.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Unreal Anthology\\UnrealGold\\System\\Unreal.exe"=
"C:\\Unreal Anthology\\UT2004\\System\\UT2004.exe"=
"C:\\WINDOWS\\system32\\winver.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-17 19:50]
R1 SSHDRV65;SSHDRV65;C:\WINDOWS\system32\drivers\SSHDRV65.sys [2007-08-29 11:07]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-17 19:50]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-17 19:50]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-17 19:50]
R2 dvdmmg;dvdmmg;C:\WINDOWS\system32\drivers\dvdmmg.sys [2007-09-06 13:15]
R2 MLPTDR_C;MLPTDR_C;C:\WINDOWS\system32\MLPTDR_C.sys [2002-03-26 03:55]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2008-04-14 00:26]
S3 PCD65X3;PCD65X3;C:\DOCUME~1\LIBORF~1\LOCALS~1\Temp\PCD65X3.sys []
S3 PCD65X4;PCD65X4;C:\DOCUME~1\LIBORF~1\LOCALS~1\Temp\PCD65X4.sys []
S3 PCD65X5;PCD65X5;C:\DOCUME~1\LIBORF~1\LOCALS~1\Temp\PCD65X5.sys []
S3 PCD65X6;PCD65X6;C:\DOCUME~1\LIBORF~1\LOCALS~1\Temp\PCD65X6.sys []
S3 PCD65X7;PCD65X7;C:\DOCUME~1\LIBORF~1\LOCALS~1\Temp\PCD65X7.sys []
.
Contents of the 'Scheduled Tasks' folder
2008-08-23 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{EAD74E2E-677C-481A-A72E-DA35A2D36A6D} - C:\WINDOWS\system32\tuvULBUl.dll
HKCU-Run-MsgCenterExe - C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
HKCU-Run-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe
HKCU-Run-BackgroundCycler - C:\Documents and Settings\Libor Formánek\Local Settings\Temporary Internet Files\Content.IE5\PXKCTKBB\Cycler[1].exe
HKLM-Run-QuickTime Task - C:\Program Files\QuickTime\qttask.exe
HKLM-Run-70a65723 - C:\WINDOWS\system32\dkgedjhu.dll
HKLM-Run-BM739564bf - C:\WINDOWS\system32\rrcpbbfb.dll
Notify-winhdn32 - winhdn32.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.seznam.cz/R0 -: HKCU-Main,Default_Search_URL =
R0 -: HKCU-Main,SearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.comO8 -: E&xportovat do aplikace Microsoft Office Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Send To &Bluetooth - C:\Program Files\MSI\Bluetooth Software\btsendto_ie_ctx.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-23 20:19:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Program Files\MSI\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSI\Bluetooth Software\BTTray.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-08-23 20:26:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-23 18:26:42
Pre-Run: Volných bajtů: 60,760,760,320
Post-Run: Volněch bajt…: 62,359,650,304
251 --- E O F --- 2008-08-23 10:33:19