portmap.exe sem odstranil jako první, abych mohl pracovat v normálním režimu ještě ten den co sem ten vir chytl... a jinak tady je ten log:
ComboFix 09-08-10.06 - Administrator 15.08.2009 0:31.1.1 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.512.286 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ADMINI~1\LOCALS~1\Temp\delself.bat
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\_tm257.tmp
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\_tm26.tmp
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\_tm95.tmp
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\stb06759.tmp
c:\windows\system32\Drivers\qksnn.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_teahe
((((((((((((((((((((((((( Soubory vytvořené od 2009-07-14 do 2009-08-14 )))))))))))))))))))))))))))))))
.
2009-08-14 19:04 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 19:04 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-11 14:25 . 2009-08-11 14:25 -------- d-----w- c:\program files\Google
2009-08-10 11:54 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-10 11:54 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-08-10 11:53 . 2009-08-10 11:53 -------- d-----w- c:\program files\iPod
2009-08-10 11:52 . 2009-08-10 11:52 -------- d-----w- c:\program files\Bonjour
2009-08-10 11:51 . 2009-08-10 11:51 -------- d-----w- c:\program files\QuickTime
2009-08-10 11:50 . 2009-08-10 11:50 -------- d-----w- c:\program files\Apple Software Update
2009-08-10 11:49 . 2009-08-10 11:49 -------- d-----w- c:\program files\Common Files\Apple
2009-08-03 07:19 . 2009-08-03 07:19 -------- d-sh--w- C:\FOUND.008
2009-07-18 16:18 . 2009-07-18 16:18 -------- d-----w- c:\documents and settings\Administrator\fontconfig
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 19:39 . 2009-08-14 19:39 984 ----a-w- c:\program files\znjhr.txt
2009-08-06 13:01 . 2009-04-19 17:29 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-29 20:37 . 2009-06-29 20:37 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-18 04:53 . 2001-10-25 10:00 47206 ----a-w- c:\windows\system32\perfc005.dat
2009-06-18 04:53 . 2001-10-25 10:00 312970 ----a-w- c:\windows\system32\perfh005.dat
2009-06-15 17:18 . 2009-06-15 17:17 7 ----a-w- c:\windows\sbacknt.bin
2009-06-15 17:17 . 2009-06-15 17:17 152904 ----a-w- c:\windows\system32\vghd.scr
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Felix"="c:\program files\ScreenMates\1378.exe" [2008-12-10 307200]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-01-21 133104]
"QIP2005"="d:\qip\qip.exe" [2009-02-06 3367424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-04 7307264]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-11-04 86016]
"KooMail"="d:\koomail\KooMail.exe" [2008-10-16 2147840]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2009-07-13 292128]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-11-04 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\empires2.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"d:\\QIP\\qip.exe"=
"d:\\Miranda IM\\miranda32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\QIP Infium\\infium.exe"=
"d:\\Opera.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\java.exe"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Data aplikací\\Google\\Chrome\\Application\\chrome.exe"=
"d:\\VLC\\vlc.exe"=
"d:\\CSS\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [19.4.2009 19:29 108289]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [27.1.2009 18:28 10976]
S3 K320bus;Sony Ericsson K320 driver (WDM);c:\windows\system32\drivers\K320bus.sys [2.3.2008 12:46 61504]
S3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter;c:\windows\system32\drivers\K320mdfl.sys [8.8.2008 18:29 9328]
S3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver;c:\windows\system32\drivers\K320mdm.sys [8.8.2008 18:29 97056]
S3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\K320mgmt.sys [9.3.2008 23:17 88560]
S3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface;c:\windows\system32\drivers\K320obex.sys [9.3.2008 23:16 86368]
S3 s3legacy;s3legacy;c:\windows\system32\drivers\s3legacy.sys [28.2.2008 20:16 65664]
S3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);c:\windows\system32\drivers\opl3sax.sys [29.2.2008 18:59 54528]
.
Obsah adresáře 'Naplánované úlohy'
2009-08-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-CubeDesktop - (no file)
HKCU-Run-WEBTRAN - (no file)
HKLM-Run-pckukacky - (no file)
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.google.cz/uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - d:\pc translator 2005 - (11 jazyku)\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - d:\pc translator 2005 - (11 jazyku)\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - d:\pc translator 2005 - (11 jazyku)\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - d:\pc translator 2005 - (11 jazyku)\WEBIE.DLL
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} -
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\lp3exuvz.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://slirsredirect.search.aol.com/sli ... ie7&query=FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage -
www.google.czFF - prefs.js: keyword.URL - chrome://google-cjk-partner/locale/partner.properties
FF - component: c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\lp3exuvz.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampPlayer.dll
FF - component: d:\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
---- NASTAVENÍ FIREFOXU ----
d:\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-15 00:41
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1220945662-706699826-1202660629-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{56DC3683-BB2F-7DFE-01E8-4197BEEC4485}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hamgpappjndckjcf"=hex:61,61,00,7c
"jamgpappjndckjcfphbb"=hex:63,61,6a,61,63,67,00,7c
"paeffkollmogmkcefpiefhloakampmkl"=hex:62,61,61,70,00,67
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(4016)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\windows\system32\wscntfy.exe
c:\windows\SYSTEM32\RUNDLL32.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Celkový čas: 2009-08-14 0:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-08-14 22:48
Před spuštěním: Volných bajtů: 20 614 627 328
Po spuštění: Volných bajtů: 22 211 313 664
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
175 --- E O F --- 2009-04-15 18:54