ahoj, udělal jsem to a tady je ten log.
ComboFix 10-05-24.03 - Martin Žídek 25.05.2010 6:37.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.1.1250.420.1029.18.351.212 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\sstray.exe
c:\windows\system32\qmgr.dll . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-25 do 2010-05-25 )))))))))))))))))))))))))))))))
.
2010-05-25 13:32 . 2010-05-25 13:33 12320 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-05-25 04:15 . 2010-05-25 04:15 3696466 ----a-r- C:\ComboFix.exe
2010-05-24 19:49 . 2010-05-24 19:49 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-05-24 19:49 . 2010-05-24 19:49 -------- d-----w- c:\program files\ParetoLogic
2010-05-24 19:48 . 2010-05-24 19:48 11747656 ----a-w- C:\Pareto_AV_Setup_RW(2).exe
2010-05-24 19:48 . 2010-05-24 19:48 11747656 ----a-w- C:\Pareto_AV_Setup_RW.exe
2010-05-24 17:23 . 2010-05-24 17:23 50688 ----a-w- C:\ATF-Cleaner.exe
2010-05-24 04:14 . 2010-05-24 04:14 1402880 ----a-w- C:\HiJackThis.msi
2010-05-23 18:54 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-23 18:54 . 2010-04-29 13:39 19288 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-23 18:54 . 2010-05-23 18:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-23 18:53 . 2010-05-23 18:53 6153376 ----a-w- C:\mbam-setup.exe
2010-05-23 18:08 . 2010-05-23 18:08 2672312 ----a-w- C:\esetsmartinstaller_csy.exe
2010-05-23 17:49 . 2010-05-23 17:50 39502856 ----a-w- C:\setupcze(2).exe
2010-05-23 17:49 . 2010-05-24 17:08 -------- d-----w- c:\program files\Alwil Software
2010-05-23 17:47 . 2010-05-23 17:48 39502856 ----a-w- C:\setupcze.exe
2010-05-23 17:42 . 2010-05-24 04:14 -------- d-----w- c:\program files\Trend Micro
2010-05-23 17:28 . 2010-05-23 17:28 -------- d-----w- c:\windows\system32\wbem\Repository
2010-05-23 17:19 . 2010-05-23 17:19 -------- d-----w- c:\program files\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-25 13:32 . 2010-05-25 13:32 1056 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-05-25 13:32 . 2010-05-25 13:32 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-05-25 13:32 . 2010-05-25 13:32 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-05-02 17:12 . 2009-07-19 15:54 -------- d-----w- c:\program files\uTorrent
2010-04-16 16:12 . 2010-04-16 16:12 -------- d-----w- c:\program files\Common Files\Ahead
2010-04-16 16:12 . 2010-04-16 16:12 -------- d-----w- c:\program files\Ahead
2010-04-14 14:21 . 2010-04-14 14:21 -------- d-----w- c:\program files\TomTom DesktopSuite
2010-04-06 18:28 . 2010-04-06 18:27 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-31 17:33 . 2010-01-12 20:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-30 16:14 . 2010-03-30 16:14 -------- d-----w- c:\program files\Realtek AC97
2010-03-30 15:49 . 2010-03-30 15:49 -------- d-----w- c:\program files\iXi Tools Software
2010-03-30 15:41 . 2009-07-17 15:48 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-30 15:36 . 2010-03-30 15:36 -------- d-----w- c:\program files\C-Media
2010-03-30 07:41 . 2010-01-28 09:47 -------- d-----w- c:\program files\Fotolab
2010-03-28 16:05 . 2010-03-28 16:05 -------- d-----w- c:\program files\Winamp
2010-03-28 13:56 . 2001-10-25 12:00 46016 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 13:56 . 2001-10-25 12:00 309716 ----a-w- c:\windows\system32\perfh005.dat
2010-03-27 09:32 . 2010-03-27 09:31 -------- d-----w- c:\program files\EasyFrom
2010-03-27 09:32 . 2010-03-27 09:32 -------- d-----w- c:\program files\Microsoft Visual FoxPro OLE DB Provider
2010-03-23 17:58 . 2009-06-30 18:56 737280 ----a-w- c:\windows\iun6002.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-04-29 321328]
"DriverUpdaterPro"="c:\program files\iXi Tools Software\Driver Updater Pro\DriverUpdaterPro.exe" [2010-03-29 4353024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-07-12 7626752]
"nwiz"="nwiz.exe" [2006-07-12 1519616]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2006-07-12 86016]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"ParetoLogic Anti-Virus PLUS"="c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" [2010-05-25 2355]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2002-09-20 13312]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:Czech /KBD:2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
R2 ZeppelinService;plasservice;c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe [14.1.2010 11:27 587216]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - KLIF
.
Obsah adresáře 'Naplánované úlohy'
2010-05-25 c:\windows\Tasks\ParetoLogic Anti-Virus PLUS.job
- c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe [2010-01-14 09:28]
2010-05-24 c:\windows\Tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
- c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe [2010-01-14 09:28]
2010-05-24 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 10:25]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.cz/uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\windows\System32\INetHTTPFilter.dll
TCP: {160AE1E6-D18B-441A-84F1-010F65024626} = 172.23.76.1,10.153.195.1
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Martin Žídek\Data aplikací\Mozilla\Firefox\Profiles\5aojw4um.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.seznam.czFF - prefs.js: network.proxy.ftp - proxy.nasi.ova.czf
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.gopher - proxy.nasi.ova.czf
FF - prefs.js: network.proxy.gopher_port - 3128
FF - prefs.js: network.proxy.http - proxy.nasi.ova.czf
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - proxy.nasi.ova.czf
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - proxy.nasi.ova.czf
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-nForce Tray Options - sstray.exe
HKLM-Run-Adobe Reader Speed Launcher - d:\download\acrobat\Reader\Reader_sl.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-25 15:32
Windows 5.1.2600 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(508)
c:\windows\System32\ODBC32.dll
- - - - - - - > 'lsass.exe'(564)
c:\windows\System32\INetHTTPFilter.dll
c:\windows\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(3364)
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\program files\Common Files\Microsoft Shared\Web Components\10\1029\OWCI10.DLL
c:\windows\System32\MSCTF.dll
c:\windows\System32\MLANG.dll
c:\windows\System32\mshtml.dll
c:\windows\System32\msimtf.dll
c:\windows\System32\MSLS31.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\nvsvc32.exe
c:\windows\System32\RUNDLL32.EXE
c:\windows\SOUNDMAN.EXE
.
**************************************************************************
.
Celkový čas: 2010-05-25 15:34:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-05-25 13:34
Před spuštěním: 288 403 456
Po spuštění: 311 250 944
winxpsp1_cs_pro_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
- - End Of File - - 7686CB234EB148667884F15AC45F6442