omlouvám se, tohle je ten správný log:
ComboFix 11-04-06.01 - Admin 07.04.2011 0:06.1.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.2009.1739 [GMT 2:00]
Running from: c:\documents and settings\Admin\Đŕáî÷čé ńňîë\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\jDm24512pFoFb24512
c:\documents and settings\All Users\Application Data\jDm24512pFoFb24512\jDm24512pFoFb24512
c:\documents and settings\All Users\Application Data\jDm24512pFoFb24512\jDm24512pFoFb24512.exe
c:\windows\Delete.bat
c:\windows\system32\Ďóçűđč.scr
c:\windows\system32\ssField Lines.scr
c:\windows\system32\ssRibbons.scr
c:\windows\system32\SYSINTERNALS_BLUESCREEN.SCR
.
c:\windows\regedit.exe . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2011-03-06 to 2011-04-06 )))))))))))))))))))))))))))))))
.
.
2011-04-06 21:25 . 2011-04-06 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2011-04-06 21:18 . 2011-04-06 21:18 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2011-04-06 21:18 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-06 21:18 . 2011-04-06 21:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-06 21:18 . 2011-04-06 21:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-06 21:18 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-02 16:43 . 2011-04-02 16:43 -------- d-----w- c:\program files\CCleaner
2011-04-02 16:38 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-02 16:38 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-02 16:38 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-02 16:38 . 2004-01-09 08:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
2011-04-02 16:38 . 2011-04-02 16:38 -------- d-----w- c:\program files\Alwil Software
2011-03-27 15:47 . 2011-03-27 15:47 -------- d-----w- c:\program files\MegaFon
2011-03-21 11:59 . 2011-03-21 11:59 -------- d-----w- c:\documents and settings\Admin\Application Data\Media Player Classic
2011-03-08 11:46 . 2011-03-08 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-01 11:35 . 2011-02-01 11:35 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-02-01 11:34 . 2011-02-01 11:34 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-01 11:34 . 2011-02-01 11:34 410984 ----a-w- c:\windows\system32\deploytk.dll
.
.
------- Sigcheck -------
.
[-] 2008-12-25 . 6A104BA98D99D53AB0C91825CE659FC6 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
.
[-] 2008-12-25 18:59 . 7F37BFDC135A7F2459DE89D9A4964F97 . 855040 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2008-12-25 . A16B512841D703A84F773BD0DCC732DC . 78360 . . [7.2.6001.788] . . c:\windows\system32\wuauclt.exe
.
[-] 2008-12-25 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
.
[-] 2008-12-25 . B3F3C4C16539F0AC20306E2A56DF6AA6 . 952832 . . [7.00.6000.20935] . . c:\windows\system32\wininet.dll
.
[-] 2008-12-25 . 5D1804D43D799F7040AC1C2DF3EE137A . 1721344 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-12-25 . E52BB415E3A7106E0308A6EE75219F30 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[-] 2008-12-25 . E5EB62A6443A8720F7EC4941C42FAE67 . 30208 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
"HW_OPENEYE_OUC_MegaFon Internet"="c:\program files\MegaFon Internet\UpdateDog\ouc.exe" [2009-04-14 110592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"RTHDCPL"="RTHDCPL.EXE" [2009-12-25 18789408]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-12-08 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-12-08 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-12-08 142872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"actx.exe"="c:\program files\MegaFon\MultiFon\actx.exe" [2009-05-27 5458432]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-12-25 30208]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IE7_011"="shell32" [X]
"ZZZZ2_FirstLogonSetting"="advpack.dll" [2008-12-25 124928]
"IE7_012"="advpack.dll" [2008-12-25 124928]
.
c:\documents and settings\All Users\« ˘®Ą ¬Ąî\Źŕ®Łŕ ¬¬ë\€˘â®§ Łŕă§Ş \
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2011-2-19 1650688]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"UpdatesOverride"=dword:00000001
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14.10.2009 19:18 36880]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [01.02.2011 13:35 717296]
R2 DCService.exe;DCService.exe;c:\documents and settings\All Users\Application Data\DatacardService\DCService.exe [08.05.2010 13:48 229376]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\system32\StkCSrv.exe [01.02.2011 13:58 31248]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [12.02.2011 19:58 70656]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [01.02.2011 14:04 110080]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14.09.2009 12:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02.10.2009 17:39 19472]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\system32\drivers\StkCMini.sys [01.02.2011 13:58 1360016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [01.02.2011 14:07 1691480]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [12.02.2011 19:58 101504]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [12.02.2011 19:58 117504]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.01.2010 14:49 227232]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WUAUSERV
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://start.drp.su/IE: &Ýęńďîđň â Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Äîáŕâčňü â Ŕíňč-Áŕííĺđ - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\nmuhujcg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.type - 0
FF - Ext: Kaspersky URL Advisor:
linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-04-07 01:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1224)
c:\windows\system32\cscui.dll
.
- - - - - - - > 'explorer.exe'(2980)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\StkCWIA.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
c:\program files\WinRAR\rarext.dll
c:\program files\7-Zip\7-zip.dll
c:\windows\system32\igfxpph.dll
c:\windows\system32\hccutils.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\documents and settings\Admin\Application Data\MegaFon Internet\ouc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\McAfee Security Scan\2.0.181\McUICnt.exe
.
**************************************************************************
.
Completion time: 2011-04-07 01:51:25 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-06 23:29
.
Pre-Run: 62 051 885 056 áŕéň ńâîáîäíî
Post-Run: 61 868 912 640 áŕéň ńâîáîäíî
.
- - End Of File - - E01B66FD0BD27B13B20EF05B7272508B