Zdravím všechny! Nějak se mi zpomalil PC a tak prosím o kontrolu logu z HiJackThis a přikládám ještě výpis z MWAV logu. Tam je to asi nepřesný. MWAV mi našel 12 kritických a celkem 63 chyb. Já toho tolik nenašel Díky za pomoc.
Logfile of HijackThis v1.99.1
Scan saved at 16:40:03, on 19.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Timer Wizard\Timer Wizard.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Timer Wizard.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe
MWAV
Thu Jul 19 14:07:50 2007 => **********************************************************
Thu Jul 19 14:07:50 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Thu Jul 19 14:07:50 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Thu Jul 19 14:07:50 2007 => **********************************************************
Thu Jul 19 14:07:50 2007 => Source: C:\mwav.exe
Thu Jul 19 14:07:50 2007 => Verze 9.3.1 (C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\mexe.com)
Thu Jul 19 14:07:50 2007 => Log soubor: C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\MWAV.LOG
Thu Jul 19 14:07:50 2007 => Datum a čas posledního testu: 13.07.2007 23:44:47
Thu Jul 19 14:07:50 2007 => MWAV Registered: FALSE.
Thu Jul 19 14:07:50 2007 => User Account: Blue Spirit
Thu Jul 19 14:07:50 2007 => OS Type: Windows Workstation
Thu Jul 19 14:07:50 2007 => OS: Windows XP
Thu Jul 19 14:07:50 2007 => Ver: Service Pack 2 (Build 2600)
Thu Jul 19 14:07:50 2007 => Windows Root Folder: C:\WINDOWS
Thu Jul 19 14:07:50 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Thu Jul 19 14:07:50 2007 => DHCP NameServer: 172.16.0.1
Thu Jul 19 14:07:50 2007 => Interface0 DHCPNameServer: 172.16.0.1
Thu Jul 19 14:07:50 2007 => Local Fixed Drives: c:\,d:\,e:\
Thu Jul 19 14:07:50 2007 => MWAV Mode: Only Scan files.
C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\virus.avi
C:\Documents and Settings\Blue Spirit\.gimp-2.2\environ]
C:\Documents and Settings\Blue Spirit\Local Settings\Temp\virus.avi
C:\HRY_INSTALAČKY\Plane_Arc_R\Plane Arcade\Models\spitfire\enviro.bmp
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702f-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27032-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27034-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702d-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702e-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27031-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27033-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27036-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:45 2007 => Offending Key found: HKCU\\ssubtimer6.gsubclass !!!
Thu Jul 19 14:09:45 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:09:45 2007 => Offending Key found: HKCU\\ssubtimer6.isubclass !!!
Thu Jul 19 14:09:45 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:09:52 2007 => Offending file found: C:\WINDOWS\system32\unzip32.dll
Thu Jul 19 14:09:52 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:54 2007 => Checking MountPoints2 Registry Key...
Thu Jul 19 14:09:54 2007 => Invalid Command Found in {408d2b7d-2adc-11dc-ba0c-00120e2edf0c}\Shell\AutoRun\command: H:\LaunchU3.exe -a
Thu Jul 19 14:09:54 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c} !!!
Thu Jul 19 14:09:54 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
C:\WINDOWS\system32\netware.drvC:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\Spyware.sdb
C:\Documents and Settings\Blue Spirit\Local Settings\Temp\Spyware.sdb
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27032-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27034-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702d-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702e-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27031-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27033-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27036-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.ctimer !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.gsubclass !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.isubclass !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:21 2007 => Offending file found: C:\WINDOWS\system32\unzip32.dll
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:23 2007 => Checking MountPoints2 Registry Key...
Thu Jul 19 14:23:23 2007 => Invalid Command Found in {408d2b7d-2adc-11dc-ba0c-00120e2edf0c}\Shell\AutoRun\command: H:\LaunchU3.exe -a
Thu Jul 19 14:23:23 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c} !!!
Thu Jul 19 14:23:23 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo prov
Thu Jul 19 15:22:20 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:51:55 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:53:39 2007 => Testování souboru C:\WINDOWS\system32\netware.drv
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Prosím o kontrolu logu Vyřešeno
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
Vyřešeno
žádnej problém tam nevidím.
takže zkus vyloučit problém s HW(přehřívání je momentálnš aktuální)
a pošli log z Combofixu
- po spuštění se zobrazí podmínky užití, potvrď je stiskem klávesy 1
- dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem celý jeho obsah
(předpokládám,že jsi počítač softwareově vyčisti)
takže zkus vyloučit problém s HW(přehřívání je momentálnš aktuální)
a pošli log z Combofixu
- po spuštění se zobrazí podmínky užití, potvrď je stiskem klávesy 1
- dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem celý jeho obsah
(předpokládám,že jsi počítač softwareově vyčisti)
-
- Pohlaví:
-
- Pohlaví:
Zde je log z Combofixu :
"Blue Spirit" - 2007-07-19 17:34:36 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
((((((((((((((((((((((((( Files Created from 2007-06-19 to 2007-07-19 )))))))))))))))))))))))))))))))
2007-07-19 17:20 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 17:19 1,175,043 --a------ C:\ComboFix.exe
2007-07-14 16:11 529,508 --a------ C:\SuperAntiSpywarePRO_CZ_3_9.sfx.exe
2007-07-14 15:58 <DIR> d-------- C:\Program Files\JockerSoft
2007-07-14 15:57 678,125 --a------ C:\setup_CodecInstaller.exe
2007-07-14 04:14 <DIR> d-------- C:\!KillBox
2007-07-14 04:13 <DIR> d-------- C:\killbox_R
2007-07-14 02:45 <DIR> d-------- C:\upm_3_2_0a
2007-07-13 23:21 17,958,968 --a------ C:\mwav.exe
2007-07-13 17:26 <DIR> d-------- C:\WINDOWS\XXLGS
2007-07-13 17:12 <DIR> d-------- C:\Program Files\PC Translator 2005
2007-07-09 10:35 <DIR> d-------- C:\Programy ShutDown
2007-07-08 15:06 1,577,708 --a------ C:\BergmanIQ.exe
2007-07-08 14:32 <DIR> d-------- C:\DOCUME~1\BLUESP~1\.thumbnails
2007-07-08 14:27 <DIR> d-------- C:\DOCUME~1\BLUESP~1\.gimp-2.2
2007-07-08 14:24 <DIR> d-------- C:\gimp-2.2.13..R
2007-07-08 14:19 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-07-08 14:18 <DIR> d-------- C:\gtk+2.4.1_R
2007-07-08 13:47 <DIR> d-------- C:\cports_R
2007-07-08 13:31 8,215,349 --a------ C:\music_morpher_gold_cnt.exe
2007-07-07 21:52 <DIR> d-------- C:\HRY NA VíMAZ
2007-07-07 19:58 <DIR> d-------- C:\Free Translator_R
2007-07-07 19:49 <DIR> d-------- C:\Program Files\Recepty doma
2007-07-07 18:26 23,037,347 --a------ C:\World_Wind_1.4.0_RC3.exe
2007-07-07 18:22 <DIR> d-------- C:\dspeech_R
2007-07-07 14:04 102,400 --a------ C:\WINDOWS\system32\unzip32.dll
2007-07-07 13:52 <DIR> d-------- C:\DOCUME~1\BLUESP~1\DATAAP~1\ImgBurn
2007-07-07 13:51 <DIR> d-------- C:\Program Files\ImgBurn
2007-07-07 13:49 <DIR> d-------- C:\Opera854_USB
2007-07-07 13:49 <DIR> d-------- C:\ImgBurn_2_R
2007-07-07 12:55 <DIR> d-------- C:\Program Files\BinarySense
2007-07-07 12:21 <DIR> d-------- C:\Program Files\totalcmd
2007-07-07 11:40 <DIR> d-------- C:\pcst2007us_R
2007-07-07 11:28 110,592 --a------ C:\WINDOWS\system32\tsccvid.dll
2007-07-07 11:27 <DIR> d-------- C:\Photoshop_kurz
2007-07-07 10:11 <DIR> d-------- C:\Program Files\Diamond Hunter
2007-07-06 17:07 <DIR> d-------- C:\Program Files\FunGamesGalaxy.com
2007-07-06 12:58 598,016 --a------ C:\WINDOWS\system32\OOD2KCRS.dll
2007-07-06 12:58 29,272 --a------ C:\WINDOWS\system32\OOD2KBS.exe
2007-07-06 12:58 24,576 --a------ C:\WINDOWS\system32\OODCSPRO.dll
2007-07-06 12:58 238,080 --a------ C:\WINDOWS\system32\OOD2000.exe
2007-07-06 12:58 16,384 --a------ C:\WINDOWS\system32\ood2kmsg.dll
2007-07-06 12:58 <DIR> d-------- C:\Program Files\OOD2KFRE
2007-07-05 13:21 <DIR> d-------- C:\DOCUME~1\BLUESP~1\DATAAP~1\U3
2007-07-03 13:32 <DIR> d-------- C:\Program Files\PicturePuzzle
2007-06-30 08:58 <DIR> d-------- C:\Program Files\Penguin Adventure
2007-06-28 18:37 <DIR> d-------- C:\DOCUME~1\BLUESP~1\Bluetooth Software
2007-06-28 18:30 <DIR> d-------- C:\Program Files\WIDCOMM
2007-06-28 05:39 <DIR> d-------- C:\Program Files\phenomedia
2007-06-28 05:28 <DIR> d-------- C:\Program Files\DVD Shrink
2007-06-27 18:28 <DIR> d-------- C:\Program Files\Blockmania
2007-06-27 18:14 <DIR> d-------- C:\Bmania
2007-06-20 20:40 77,160 --a------ C:\Program Files\DSETUP.dll
2007-06-20 20:40 503,144 --a------ C:\Program Files\dxsetup.exe
2007-06-20 20:40 1,673,576 --a------ C:\Program Files\dsetup32.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-31 09:32:31 71,680 ----a-w C:\WINDOWS\system32\perfc005.dat
2007-07-31 09:32:31 395,956 ----a-w C:\WINDOWS\system32\perfh005.dat
2007-07-19 15:27:37 117,140 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-07-19 10:24:03 -------- d-----w C:\Program Files\Jardinains!
2007-07-19 10:24:00 -------- d-----w C:\Program Files\images
2007-07-19 10:24:00 -------- d-----w C:\Program Files\hp deskjet 5550 series
2007-07-19 10:23:59 15,360 --sha-w C:\Program Files\Thumbs.db
2007-07-19 10:23:57 -------- d-----w C:\Program Files\Timer Wizard
2007-07-19 10:23:57 -------- d-----w C:\Program Files\Swistakowy Klopot
2007-07-19 10:23:56 -------- d-----w C:\Program Files\Pekka Kana 2
2007-07-19 10:23:56 -------- d-----w C:\Program Files\OutbreakX_SE_Gamestar
2007-07-19 10:23:56 -------- d-----w C:\Program Files\Mouse
2007-07-19 10:23:55 -------- d-----w C:\Program Files\Messenger
2007-07-19 10:23:55 -------- d-----w C:\Program Files\MahJong Suite
2007-07-19 10:23:55 -------- d-----w C:\Program Files\Krteček 1.9 beta 7
2007-07-19 10:23:55 -------- d-----w C:\Program Files\Combined Community Codec Pack
2007-07-19 10:23:54 -------- d-----w C:\Program Files\Blip Blop
2007-07-19 10:23:54 -------- d-----w C:\Program Files\Amazonia
2007-07-19 10:23:54 -------- d-----w C:\Program Files\5star Free Lines
2007-07-14 14:17:43 -------- d-----w C:\Program Files\SUPERAntiSpyware
2007-07-08 11:58:35 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-07-08 11:58:35 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-07-06 17:52:36 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\Skype
2007-07-06 10:58:03 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-28 10:08:58 -------- d-----w C:\Program Files\CCleaner
2007-06-28 04:05:17 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\eBookPro6
2007-06-27 16:15:11 -------- d-----w C:\Program Files\GameTop.com
2007-06-20 19:00:58 702,644 ----a-w C:\Program Files\JUN2007_d3dx10_34_x64.cab
2007-06-20 19:00:56 702,072 ----a-w C:\Program Files\JUN2007_d3dx10_34_x86.cab
2007-06-20 19:00:56 1,611,374 ----a-w C:\Program Files\JUN2007_d3dx9_34_x64.cab
2007-06-20 19:00:54 200,722 ----a-w C:\Program Files\JUN2007_XACT_x64.cab
2007-06-20 19:00:54 156,509 ----a-w C:\Program Files\JUN2007_XACT_x86.cab
2007-06-20 19:00:54 1,610,886 ----a-w C:\Program Files\JUN2007_d3dx9_34_x86.cab
2007-06-20 19:00:52 45,302 ----a-w C:\Program Files\dxdllreg_x86.cab
2007-06-20 18:40:12 86,400 ----a-w C:\Program Files\dxupdate.cab
2007-06-20 18:40:10 88,102 ------w C:\Program Files\AUG2006_xinput_x64.cab
2007-06-20 18:40:10 86,925 ------w C:\Program Files\Oct2005_xinput_x64.cab
2007-06-20 18:40:10 47,018 ------w C:\Program Files\AUG2006_xinput_x86.cab
2007-06-20 18:40:10 46,247 ------w C:\Program Files\Oct2005_xinput_x86.cab
2007-06-20 18:40:10 213,767 ------w C:\Program Files\DEC2006_d3dx10_00_x64.cab
2007-06-20 18:40:10 198,275 ------w C:\Program Files\FEB2007_XACT_x64.cab
2007-06-20 18:40:10 193,435 ------w C:\Program Files\DEC2006_XACT_x64.cab
2007-06-20 18:40:10 192,680 ------w C:\Program Files\DEC2006_d3dx10_00_x86.cab
2007-06-20 18:40:10 183,321 ------w C:\Program Files\OCT2006_XACT_x64.cab
2007-06-20 18:40:10 181,745 ------w C:\Program Files\JUN2006_XACT_x64.cab
2007-06-20 18:40:10 179,247 ------w C:\Program Files\Feb2006_XACT_x64.cab
2007-06-20 18:40:10 151,583 ------w C:\Program Files\FEB2007_XACT_x86.cab
2007-06-20 18:40:10 146,559 ------w C:\Program Files\DEC2006_XACT_x86.cab
2007-06-20 18:40:10 138,977 ------w C:\Program Files\OCT2006_XACT_x86.cab
2007-06-20 18:40:10 134,631 ------w C:\Program Files\JUN2006_XACT_x86.cab
2007-06-20 18:40:10 133,297 ------w C:\Program Files\Feb2006_XACT_x86.cab
2007-06-20 18:40:10 1,575,336 ------w C:\Program Files\DEC2006_d3dx9_32_x86.cab
2007-06-20 18:40:10 1,572,114 ------w C:\Program Files\DEC2006_d3dx9_32_x64.cab
2007-06-20 18:40:10 1,413,862 ------w C:\Program Files\OCT2006_d3dx9_31_x64.cab
2007-06-20 18:40:10 1,363,684 ------w C:\Program Files\Feb2006_d3dx9_29_x64.cab
2007-06-20 18:40:10 1,358,864 ------w C:\Program Files\Dec2005_d3dx9_28_x64.cab
2007-06-20 18:40:10 1,336,890 ------w C:\Program Files\Jun2005_d3dx9_26_x64.cab
2007-06-20 18:40:10 1,248,387 ------w C:\Program Files\Feb2005_d3dx9_24_x64.cab
2007-06-20 18:40:10 1,128,177 ------w C:\Program Files\OCT2006_d3dx9_31_x86.cab
2007-06-20 18:40:10 1,085,608 ------w C:\Program Files\Feb2006_d3dx9_29_x86.cab
2007-06-20 18:40:10 1,080,344 ------w C:\Program Files\Dec2005_d3dx9_28_x86.cab
2007-06-20 18:40:10 1,065,813 ------w C:\Program Files\Jun2005_d3dx9_26_x86.cab
2007-06-20 18:40:10 1,014,113 ------w C:\Program Files\Feb2005_d3dx9_24_x86.cab
2007-06-20 18:40:08 917,318 ------w C:\Program Files\Apr2006_MDX1_x86.cab
2007-06-20 18:40:08 87,989 ------w C:\Program Files\Apr2006_xinput_x64.cab
2007-06-20 18:40:08 702,212 ------w C:\Program Files\APR2007_d3dx10_33_x64.cab
2007-06-20 18:40:08 699,465 ------w C:\Program Files\APR2007_d3dx10_33_x86.cab
2007-06-20 18:40:08 56,902 ------w C:\Program Files\APR2007_xinput_x86.cab
2007-06-20 18:40:08 46,898 ------w C:\Program Files\Apr2006_xinput_x86.cab
2007-06-20 18:40:08 4,163,518 ------w C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2007-06-20 18:40:08 199,366 ------w C:\Program Files\APR2007_XACT_x64.cab
2007-06-20 18:40:08 183,863 ------w C:\Program Files\AUG2006_XACT_x64.cab
2007-06-20 18:40:08 180,021 ------w C:\Program Files\Apr2006_XACT_x64.cab
2007-06-20 18:40:08 154,825 ------w C:\Program Files\APR2007_XACT_x86.cab
2007-06-20 18:40:08 138,195 ------w C:\Program Files\AUG2006_XACT_x86.cab
2007-06-20 18:40:08 133,991 ------w C:\Program Files\Apr2006_XACT_x86.cab
2007-06-20 18:40:08 100,417 ------w C:\Program Files\APR2007_xinput_x64.cab
2007-06-20 18:40:08 1,610,958 ------w C:\Program Files\APR2007_d3dx9_33_x64.cab
2007-06-20 18:40:08 1,609,639 ------w C:\Program Files\APR2007_d3dx9_33_x86.cab
2007-06-20 18:40:08 1,398,718 ------w C:\Program Files\Apr2006_d3dx9_30_x64.cab
2007-06-20 18:40:08 1,351,430 ------w C:\Program Files\Aug2005_d3dx9_27_x64.cab
2007-06-20 18:40:08 1,348,242 ------w C:\Program Files\Apr2005_d3dx9_25_x64.cab
2007-06-20 18:40:08 1,116,109 ------w C:\Program Files\Apr2006_d3dx9_30_x86.cab
2007-06-20 18:40:08 1,079,850 ------w C:\Program Files\Apr2005_d3dx9_25_x86.cab
2007-06-20 18:40:08 1,078,532 ------w C:\Program Files\Aug2005_d3dx9_27_x86.cab
2007-06-20 18:40:06 976,020 ------w C:\Program Files\BDAXP.cab
2007-06-20 18:40:06 13,265,040 ------w C:\Program Files\dxnt.cab
2007-06-20 18:40:06 1,156,363 ------w C:\Program Files\BDANT.cab
2007-06-17 00:20:27 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\vlc
2007-06-15 04:36:58 4,096 ----a-w C:\WINDOWS\d3dx.dat
2007-06-15 04:35:29 -------- d-----w C:\Program Files\Alawar
2007-06-14 19:21:43 -------- d-----w C:\Program Files\RamCleaner
2007-06-13 15:59:02 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\URSE Games
2007-06-13 05:12:02 -------- d-----w C:\Program Files\VideoLAN
2007-06-12 16:15:44 -------- d-----w C:\Program Files\Data
2007-06-01 03:26:57 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\SUPERAntiSpyware.com
2007-06-01 03:26:19 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-25 09:32:31 -------- d-----w C:\Program Files\Pctranslator 2000
2007-05-24 06:31:47 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\Zoner
2007-05-24 02:23:08 -------- d-----w C:\Program Files\Loco
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2005-09-24 07:12 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 02:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-07-12 17:50 C:\WINDOWS\system32\nwiz.exe]
"WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2003-05-23 12:38]
"BootSkin Startup Jobs"="C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 17:21]
"SoundMan"="SOUNDMAN.EXE" [2003-01-07 12:09 C:\WINDOWS\SOUNDMAN.EXE]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-04-06 06:12]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-07-12 17:50]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-07-12 17:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49]
"AWMON"="C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" [2005-05-25 13:12]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll --a------ 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c}]
AutoRun\command- H:\LaunchU3.exe -a
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-19 17:37:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\system32\cmd.exe [2224] 0x8204FB38
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-19 17:38:47
C:\ComboFix-quarantined-files.txt ... 2007-07-19 17:38
--- E O F ---
"Blue Spirit" - 2007-07-19 17:34:36 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
((((((((((((((((((((((((( Files Created from 2007-06-19 to 2007-07-19 )))))))))))))))))))))))))))))))
2007-07-19 17:20 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 17:19 1,175,043 --a------ C:\ComboFix.exe
2007-07-14 16:11 529,508 --a------ C:\SuperAntiSpywarePRO_CZ_3_9.sfx.exe
2007-07-14 15:58 <DIR> d-------- C:\Program Files\JockerSoft
2007-07-14 15:57 678,125 --a------ C:\setup_CodecInstaller.exe
2007-07-14 04:14 <DIR> d-------- C:\!KillBox
2007-07-14 04:13 <DIR> d-------- C:\killbox_R
2007-07-14 02:45 <DIR> d-------- C:\upm_3_2_0a
2007-07-13 23:21 17,958,968 --a------ C:\mwav.exe
2007-07-13 17:26 <DIR> d-------- C:\WINDOWS\XXLGS
2007-07-13 17:12 <DIR> d-------- C:\Program Files\PC Translator 2005
2007-07-09 10:35 <DIR> d-------- C:\Programy ShutDown
2007-07-08 15:06 1,577,708 --a------ C:\BergmanIQ.exe
2007-07-08 14:32 <DIR> d-------- C:\DOCUME~1\BLUESP~1\.thumbnails
2007-07-08 14:27 <DIR> d-------- C:\DOCUME~1\BLUESP~1\.gimp-2.2
2007-07-08 14:24 <DIR> d-------- C:\gimp-2.2.13..R
2007-07-08 14:19 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-07-08 14:18 <DIR> d-------- C:\gtk+2.4.1_R
2007-07-08 13:47 <DIR> d-------- C:\cports_R
2007-07-08 13:31 8,215,349 --a------ C:\music_morpher_gold_cnt.exe
2007-07-07 21:52 <DIR> d-------- C:\HRY NA VíMAZ
2007-07-07 19:58 <DIR> d-------- C:\Free Translator_R
2007-07-07 19:49 <DIR> d-------- C:\Program Files\Recepty doma
2007-07-07 18:26 23,037,347 --a------ C:\World_Wind_1.4.0_RC3.exe
2007-07-07 18:22 <DIR> d-------- C:\dspeech_R
2007-07-07 14:04 102,400 --a------ C:\WINDOWS\system32\unzip32.dll
2007-07-07 13:52 <DIR> d-------- C:\DOCUME~1\BLUESP~1\DATAAP~1\ImgBurn
2007-07-07 13:51 <DIR> d-------- C:\Program Files\ImgBurn
2007-07-07 13:49 <DIR> d-------- C:\Opera854_USB
2007-07-07 13:49 <DIR> d-------- C:\ImgBurn_2_R
2007-07-07 12:55 <DIR> d-------- C:\Program Files\BinarySense
2007-07-07 12:21 <DIR> d-------- C:\Program Files\totalcmd
2007-07-07 11:40 <DIR> d-------- C:\pcst2007us_R
2007-07-07 11:28 110,592 --a------ C:\WINDOWS\system32\tsccvid.dll
2007-07-07 11:27 <DIR> d-------- C:\Photoshop_kurz
2007-07-07 10:11 <DIR> d-------- C:\Program Files\Diamond Hunter
2007-07-06 17:07 <DIR> d-------- C:\Program Files\FunGamesGalaxy.com
2007-07-06 12:58 598,016 --a------ C:\WINDOWS\system32\OOD2KCRS.dll
2007-07-06 12:58 29,272 --a------ C:\WINDOWS\system32\OOD2KBS.exe
2007-07-06 12:58 24,576 --a------ C:\WINDOWS\system32\OODCSPRO.dll
2007-07-06 12:58 238,080 --a------ C:\WINDOWS\system32\OOD2000.exe
2007-07-06 12:58 16,384 --a------ C:\WINDOWS\system32\ood2kmsg.dll
2007-07-06 12:58 <DIR> d-------- C:\Program Files\OOD2KFRE
2007-07-05 13:21 <DIR> d-------- C:\DOCUME~1\BLUESP~1\DATAAP~1\U3
2007-07-03 13:32 <DIR> d-------- C:\Program Files\PicturePuzzle
2007-06-30 08:58 <DIR> d-------- C:\Program Files\Penguin Adventure
2007-06-28 18:37 <DIR> d-------- C:\DOCUME~1\BLUESP~1\Bluetooth Software
2007-06-28 18:30 <DIR> d-------- C:\Program Files\WIDCOMM
2007-06-28 05:39 <DIR> d-------- C:\Program Files\phenomedia
2007-06-28 05:28 <DIR> d-------- C:\Program Files\DVD Shrink
2007-06-27 18:28 <DIR> d-------- C:\Program Files\Blockmania
2007-06-27 18:14 <DIR> d-------- C:\Bmania
2007-06-20 20:40 77,160 --a------ C:\Program Files\DSETUP.dll
2007-06-20 20:40 503,144 --a------ C:\Program Files\dxsetup.exe
2007-06-20 20:40 1,673,576 --a------ C:\Program Files\dsetup32.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-31 09:32:31 71,680 ----a-w C:\WINDOWS\system32\perfc005.dat
2007-07-31 09:32:31 395,956 ----a-w C:\WINDOWS\system32\perfh005.dat
2007-07-19 15:27:37 117,140 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-07-19 10:24:03 -------- d-----w C:\Program Files\Jardinains!
2007-07-19 10:24:00 -------- d-----w C:\Program Files\images
2007-07-19 10:24:00 -------- d-----w C:\Program Files\hp deskjet 5550 series
2007-07-19 10:23:59 15,360 --sha-w C:\Program Files\Thumbs.db
2007-07-19 10:23:57 -------- d-----w C:\Program Files\Timer Wizard
2007-07-19 10:23:57 -------- d-----w C:\Program Files\Swistakowy Klopot
2007-07-19 10:23:56 -------- d-----w C:\Program Files\Pekka Kana 2
2007-07-19 10:23:56 -------- d-----w C:\Program Files\OutbreakX_SE_Gamestar
2007-07-19 10:23:56 -------- d-----w C:\Program Files\Mouse
2007-07-19 10:23:55 -------- d-----w C:\Program Files\Messenger
2007-07-19 10:23:55 -------- d-----w C:\Program Files\MahJong Suite
2007-07-19 10:23:55 -------- d-----w C:\Program Files\Krteček 1.9 beta 7
2007-07-19 10:23:55 -------- d-----w C:\Program Files\Combined Community Codec Pack
2007-07-19 10:23:54 -------- d-----w C:\Program Files\Blip Blop
2007-07-19 10:23:54 -------- d-----w C:\Program Files\Amazonia
2007-07-19 10:23:54 -------- d-----w C:\Program Files\5star Free Lines
2007-07-14 14:17:43 -------- d-----w C:\Program Files\SUPERAntiSpyware
2007-07-08 11:58:35 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-07-08 11:58:35 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-07-06 17:52:36 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\Skype
2007-07-06 10:58:03 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-28 10:08:58 -------- d-----w C:\Program Files\CCleaner
2007-06-28 04:05:17 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\eBookPro6
2007-06-27 16:15:11 -------- d-----w C:\Program Files\GameTop.com
2007-06-20 19:00:58 702,644 ----a-w C:\Program Files\JUN2007_d3dx10_34_x64.cab
2007-06-20 19:00:56 702,072 ----a-w C:\Program Files\JUN2007_d3dx10_34_x86.cab
2007-06-20 19:00:56 1,611,374 ----a-w C:\Program Files\JUN2007_d3dx9_34_x64.cab
2007-06-20 19:00:54 200,722 ----a-w C:\Program Files\JUN2007_XACT_x64.cab
2007-06-20 19:00:54 156,509 ----a-w C:\Program Files\JUN2007_XACT_x86.cab
2007-06-20 19:00:54 1,610,886 ----a-w C:\Program Files\JUN2007_d3dx9_34_x86.cab
2007-06-20 19:00:52 45,302 ----a-w C:\Program Files\dxdllreg_x86.cab
2007-06-20 18:40:12 86,400 ----a-w C:\Program Files\dxupdate.cab
2007-06-20 18:40:10 88,102 ------w C:\Program Files\AUG2006_xinput_x64.cab
2007-06-20 18:40:10 86,925 ------w C:\Program Files\Oct2005_xinput_x64.cab
2007-06-20 18:40:10 47,018 ------w C:\Program Files\AUG2006_xinput_x86.cab
2007-06-20 18:40:10 46,247 ------w C:\Program Files\Oct2005_xinput_x86.cab
2007-06-20 18:40:10 213,767 ------w C:\Program Files\DEC2006_d3dx10_00_x64.cab
2007-06-20 18:40:10 198,275 ------w C:\Program Files\FEB2007_XACT_x64.cab
2007-06-20 18:40:10 193,435 ------w C:\Program Files\DEC2006_XACT_x64.cab
2007-06-20 18:40:10 192,680 ------w C:\Program Files\DEC2006_d3dx10_00_x86.cab
2007-06-20 18:40:10 183,321 ------w C:\Program Files\OCT2006_XACT_x64.cab
2007-06-20 18:40:10 181,745 ------w C:\Program Files\JUN2006_XACT_x64.cab
2007-06-20 18:40:10 179,247 ------w C:\Program Files\Feb2006_XACT_x64.cab
2007-06-20 18:40:10 151,583 ------w C:\Program Files\FEB2007_XACT_x86.cab
2007-06-20 18:40:10 146,559 ------w C:\Program Files\DEC2006_XACT_x86.cab
2007-06-20 18:40:10 138,977 ------w C:\Program Files\OCT2006_XACT_x86.cab
2007-06-20 18:40:10 134,631 ------w C:\Program Files\JUN2006_XACT_x86.cab
2007-06-20 18:40:10 133,297 ------w C:\Program Files\Feb2006_XACT_x86.cab
2007-06-20 18:40:10 1,575,336 ------w C:\Program Files\DEC2006_d3dx9_32_x86.cab
2007-06-20 18:40:10 1,572,114 ------w C:\Program Files\DEC2006_d3dx9_32_x64.cab
2007-06-20 18:40:10 1,413,862 ------w C:\Program Files\OCT2006_d3dx9_31_x64.cab
2007-06-20 18:40:10 1,363,684 ------w C:\Program Files\Feb2006_d3dx9_29_x64.cab
2007-06-20 18:40:10 1,358,864 ------w C:\Program Files\Dec2005_d3dx9_28_x64.cab
2007-06-20 18:40:10 1,336,890 ------w C:\Program Files\Jun2005_d3dx9_26_x64.cab
2007-06-20 18:40:10 1,248,387 ------w C:\Program Files\Feb2005_d3dx9_24_x64.cab
2007-06-20 18:40:10 1,128,177 ------w C:\Program Files\OCT2006_d3dx9_31_x86.cab
2007-06-20 18:40:10 1,085,608 ------w C:\Program Files\Feb2006_d3dx9_29_x86.cab
2007-06-20 18:40:10 1,080,344 ------w C:\Program Files\Dec2005_d3dx9_28_x86.cab
2007-06-20 18:40:10 1,065,813 ------w C:\Program Files\Jun2005_d3dx9_26_x86.cab
2007-06-20 18:40:10 1,014,113 ------w C:\Program Files\Feb2005_d3dx9_24_x86.cab
2007-06-20 18:40:08 917,318 ------w C:\Program Files\Apr2006_MDX1_x86.cab
2007-06-20 18:40:08 87,989 ------w C:\Program Files\Apr2006_xinput_x64.cab
2007-06-20 18:40:08 702,212 ------w C:\Program Files\APR2007_d3dx10_33_x64.cab
2007-06-20 18:40:08 699,465 ------w C:\Program Files\APR2007_d3dx10_33_x86.cab
2007-06-20 18:40:08 56,902 ------w C:\Program Files\APR2007_xinput_x86.cab
2007-06-20 18:40:08 46,898 ------w C:\Program Files\Apr2006_xinput_x86.cab
2007-06-20 18:40:08 4,163,518 ------w C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2007-06-20 18:40:08 199,366 ------w C:\Program Files\APR2007_XACT_x64.cab
2007-06-20 18:40:08 183,863 ------w C:\Program Files\AUG2006_XACT_x64.cab
2007-06-20 18:40:08 180,021 ------w C:\Program Files\Apr2006_XACT_x64.cab
2007-06-20 18:40:08 154,825 ------w C:\Program Files\APR2007_XACT_x86.cab
2007-06-20 18:40:08 138,195 ------w C:\Program Files\AUG2006_XACT_x86.cab
2007-06-20 18:40:08 133,991 ------w C:\Program Files\Apr2006_XACT_x86.cab
2007-06-20 18:40:08 100,417 ------w C:\Program Files\APR2007_xinput_x64.cab
2007-06-20 18:40:08 1,610,958 ------w C:\Program Files\APR2007_d3dx9_33_x64.cab
2007-06-20 18:40:08 1,609,639 ------w C:\Program Files\APR2007_d3dx9_33_x86.cab
2007-06-20 18:40:08 1,398,718 ------w C:\Program Files\Apr2006_d3dx9_30_x64.cab
2007-06-20 18:40:08 1,351,430 ------w C:\Program Files\Aug2005_d3dx9_27_x64.cab
2007-06-20 18:40:08 1,348,242 ------w C:\Program Files\Apr2005_d3dx9_25_x64.cab
2007-06-20 18:40:08 1,116,109 ------w C:\Program Files\Apr2006_d3dx9_30_x86.cab
2007-06-20 18:40:08 1,079,850 ------w C:\Program Files\Apr2005_d3dx9_25_x86.cab
2007-06-20 18:40:08 1,078,532 ------w C:\Program Files\Aug2005_d3dx9_27_x86.cab
2007-06-20 18:40:06 976,020 ------w C:\Program Files\BDAXP.cab
2007-06-20 18:40:06 13,265,040 ------w C:\Program Files\dxnt.cab
2007-06-20 18:40:06 1,156,363 ------w C:\Program Files\BDANT.cab
2007-06-17 00:20:27 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\vlc
2007-06-15 04:36:58 4,096 ----a-w C:\WINDOWS\d3dx.dat
2007-06-15 04:35:29 -------- d-----w C:\Program Files\Alawar
2007-06-14 19:21:43 -------- d-----w C:\Program Files\RamCleaner
2007-06-13 15:59:02 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\URSE Games
2007-06-13 05:12:02 -------- d-----w C:\Program Files\VideoLAN
2007-06-12 16:15:44 -------- d-----w C:\Program Files\Data
2007-06-01 03:26:57 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\SUPERAntiSpyware.com
2007-06-01 03:26:19 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-25 09:32:31 -------- d-----w C:\Program Files\Pctranslator 2000
2007-05-24 06:31:47 -------- d-----w C:\DOCUME~1\BLUESP~1\DATAAP~1\Zoner
2007-05-24 02:23:08 -------- d-----w C:\Program Files\Loco
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2005-09-24 07:12 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 02:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-07-12 17:50 C:\WINDOWS\system32\nwiz.exe]
"WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2003-05-23 12:38]
"BootSkin Startup Jobs"="C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 17:21]
"SoundMan"="SOUNDMAN.EXE" [2003-01-07 12:09 C:\WINDOWS\SOUNDMAN.EXE]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-04-06 06:12]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-07-12 17:50]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-07-12 17:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49]
"AWMON"="C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" [2005-05-25 13:12]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll --a------ 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c}]
AutoRun\command- H:\LaunchU3.exe -a
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-19 17:37:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\system32\cmd.exe [2224] 0x8204FB38
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-19 17:38:47
C:\ComboFix-quarantined-files.txt ... 2007-07-19 17:38
--- E O F ---
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
já tam nic nevidim
nech tady http://www.virustotal.com/
pro jistotu zkontrolovat toto
C:\WINDOWS\system32\unzip32.dll
nech tady http://www.virustotal.com/
pro jistotu zkontrolovat toto
C:\WINDOWS\system32\unzip32.dll
-
- Pohlaví:
VirustTotal nenašel nic. Proč mi teda MWAV hlásí hromadu chyb. Např. toto:
Thu Jul 19 14:23:23 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo prov
Thu Jul 19 15:22:20 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:51:55 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:53:39 2007 => Testování souboru C:\WINDOWS\system32\netware.drv
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Nejde mi to do hlavy. Může mi to někdo vysvětlit?
Thu Jul 19 14:23:23 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo prov
Thu Jul 19 15:22:20 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:51:55 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:53:39 2007 => Testování souboru C:\WINDOWS\system32\netware.drv
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Nejde mi to do hlavy. Může mi to někdo vysvětlit?

Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 79 hostů