Tak tady je log po přetáhnutí texťáku na
ComboFix.exe. A potom jeste jednou spustit CF a další log (po restartu)?
ComboFix 08-02.01.6 - WarezBos 2008-02-02 20:17:42.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.215 [GMT 1:00]
Running from: C:\Documents and Settings\WarezBos\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\WarezBos\Plocha\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\system32\Drivers\spyemrg.sys
C:\WINDOWS\system32\Drivers\spyemrg_guard.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\system32\Drivers\spyemrg.sys
C:\WINDOWS\system32\Drivers\spyemrg_guard.sys
.
((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.
2008-02-01 13:21 . 2008-02-01 13:21 <DIR> d-------- C:\Program Files\Kerio
2008-02-01 12:55 . 2008-02-01 13:04 <DIR> dr------- C:\My Software
2008-01-29 14:02 . 2008-01-29 14:02 <DIR> d-------- C:\Documents and Settings\NetworkService\Data aplikací\AVG7
2008-01-29 14:02 . 2008-01-29 14:02 <DIR> d-------- C:\Documents and Settings\NetworkService\Data aplikací\AVG7
2008-01-29 14:02 . 2008-01-29 14:02 <DIR> d-------- C:\Documents and Settings\NetworkService\Data aplikací\AVG7
2008-01-29 14:02 . 2008-01-29 14:02 <DIR> d-------- C:\Documents and Settings\NetworkService\Data aplikací\AVG7
2008-01-28 18:21 . 2008-02-02 19:05 <DIR> d-------- C:\Documents and Settings\WarezBos\Data aplikací\AVG7
2008-01-28 18:21 . 2008-01-28 18:21 <DIR> d-------- C:\Documents and Settings\LocalService\Data aplikací\AVG7
2008-01-28 18:21 . 2008-01-28 18:21 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Grisoft
2008-01-28 18:21 . 2008-01-28 18:22 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\avg7
2008-01-27 19:36 . 2008-01-27 19:36 <DIR> d-------- C:\Program Files\Common Files\Everstrike Software
2008-01-27 18:28 . 2008-01-27 18:28 <DIR> d-------- C:\Documents and Settings\Tiger\Data aplikací\Talkback
2008-01-27 18:24 . 2007-07-30 19:07 <DIR> d-------- C:\Documents and Settings\Tiger\Plocha
2008-01-27 18:24 . 2007-07-30 13:04 <DIR> d--h----- C:\Documents and Settings\Tiger\Okolní tiskárny
2008-01-27 18:24 . 2007-07-30 13:04 <DIR> d--h----- C:\Documents and Settings\Tiger\Okolní síť
2008-01-27 18:24 . 2007-07-30 13:04 <DIR> d-------- C:\Documents and Settings\Tiger\Oblíbené položky
2008-01-27 18:24 . 2007-07-30 11:12 <DIR> d--h----- C:\Documents and Settings\Tiger\Šablony
2008-01-27 18:24 . 2007-07-30 13:04 <DIR> dr------- C:\Documents and Settings\Tiger\Nabídka Start
2008-01-27 18:24 . 2007-07-30 13:04 <DIR> d-------- C:\Documents and Settings\Tiger\Dokumenty
2008-01-27 18:24 . 2007-07-30 11:17 <DIR> dr-h----- C:\Documents and Settings\Tiger\Data aplikací
2008-01-24 17:54 . 2008-02-01 12:57 <DIR> d-------- C:\Program Files\URUSoft
2008-01-15 20:12 . 2008-01-15 20:12 2,745 --a------ C:\WINDOWS\wtran32.INI
2008-01-15 20:12 . 2008-01-20 16:37 1,154 --a------ C:\WINDOWS\wdict32.INI
2008-01-10 18:15 . 2008-01-10 18:15 <DIR> d-------- C:\Program Files\Webteh
2008-01-05 21:58 . 2008-02-02 20:15 <DIR> d-------- C:\Incomplete
2008-01-03 21:16 . 2008-01-03 21:16 <DIR> d-------- C:\Documents and Settings\WarezBos\Data aplikací\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 11:43 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\wsInspector
2008-01-31 21:36 --------- d-----w C:\Program Files\DOSBox-0.65
2008-01-27 13:47 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\uTorrent
2008-01-26 13:01 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-01-24 17:18 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\Vso
2008-01-21 17:20 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\Skype
2008-01-21 17:05 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\skypePM
2008-01-02 21:40 --------- d-----w C:\Program Files\styler
2008-01-02 15:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 10:54 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\LockTime
2007-12-30 15:05 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\VSO_HWE
2007-12-29 20:54 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-12-29 20:54 249,856 ------w C:\WINDOWS\Setup1.exe
2007-12-29 14:34 --------- d-----w C:\Documents and Settings\WarezBos\Data aplikací\Ahead
2007-12-29 11:55 47,360 ----a-w C:\WINDOWS\system32\drivers\Pcouffin.sys
2007-12-29 11:55 --------- d-----w C:\Program Files\vso
2007-12-28 21:06 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2007-12-28 19:54 --------- d-----w C:\Documents and Settings\LocalService\Data aplikací\Ahead
2007-12-26 17:23 --------- d-----w C:\Program Files\GDS
2007-12-26 12:38 --------- d-----w C:\Program Files\Polda 5
2007-12-25 18:11 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-25 18:08 --------- d-----w C:\Program Files\Nero
2007-12-25 18:08 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Nero
2007-11-24 12:30 32 ----a-w C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
2007-11-18 17:59 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2007-11-18 17:59 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2007-11-18 17:59 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2007-11-15 14:01 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 23:05 630784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 16:49 25088]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RAM Idle Professional"="C:\Program Files\RAM Idle\RAM_XP.exe" [2004-06-11 15:28 133632]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2006-09-09 10:16 196608]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-28 18:21 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 16:49 25088]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-28 18:21 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys [2005-04-26 10:22]
R1 SpyEmrg;Spy Emergency Driver;C:\WINDOWS\system32\Drivers\spyemrg.sys []
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2007-08-29 12:07]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 00:04]
S2 LF30FS;LF30FS;C:\Porgramy\LockFolder\LF30XP.sys []
S3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver;C:\WINDOWS\system32\Drivers\spyemrg_guard.sys []
.
Contents of the 'Scheduled Tasks' folder
"2007-09-23 17:40:56 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-17 10:09:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-02 20:19:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-02 20:20:17
ComboFix-quarantined-files.txt 2008-02-02 19:20:03