prosim vas podivej te se mi na to nekdo mam tedkom v compu trojany a naskakuje mi stale internet explorer s nejakou strankou i kdyz mam tedkom mozzilu.
Running from: C:\Documents and Settings\Marek ćamaj.MAREK-A888F1DC5\Plocha\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\awtst.dll
C:\WINDOWS\system32\lmnrsamx.ini
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.bak2
C:\WINDOWS\system32\tstwa.ini
C:\WINDOWS\system32\tstwa.ini2
C:\WINDOWS\system32\tstwa.tmp
C:\WINDOWS\system32\xmasrnml.dll
C:\WINDOWS\system32\yayyxyw.dll
.
((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-28 )))))))))))))))))))))))))))))))
.
2007-09-28 17:53 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-28 17:35 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-09-28 17:11 <DIR> d-------- C:\VundoFix Backups
2007-09-27 10:19 1,156 --a------ C:\WINDOWS\mozver.dat
2007-09-27 10:02 0 --a------ C:\WINDOWS\nsreg.dat
2007-09-04 15:44 <DIR> d-------- C:\Program Files\CCleaner
2007-09-02 13:25 82,248 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-09-02 13:25 57,672 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-09-02 13:25 40,264 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-02 13:25 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-09-02 13:24 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-09-02 12:25 <DIR> d-------- C:\Program Files\OpenOffice.org 2.2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-28 22:27 --------- d-------- C:\Program Files\ICQToolbar
2007-09-28 16:58 3710 --a------ C:\delete.bat
2007-09-28 11:29 --------- d-------- C:\Program Files\Lavalys
2007-09-21 13:42 35328 --a------ C:\WINDOWS\cygz.dll
2007-09-21 13:42 1126281 --a------ C:\WINDOWS\cygwin1.dll
2007-09-02 15:01 --------- d-------- C:\Program Files\TuneUp Utilities 2007
2007-09-02 12:24 --------- d-------- C:\Program Files\OpenOffice.org 2.1
2007-08-26 14:02 --------- d-------- C:\Program Files\VirusTotalUploader
2007-08-25 19:58 --------- d-------- C:\Program Files\TubeSucker
2007-08-24 12:55 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-24 12:55 --------- d-------- C:\Program Files\Common Files\Symbian
2007-08-22 14:03 --------- d-------- C:\Program Files\AnonymMailer
2007-08-21 20:35 --------- d-------- C:\Program Files\ICQ6
2007-08-12 17:36 --------- d-------- C:\Program Files\Replay Converter
2007-08-03 15:11 --------- d-------- C:\Program Files\Easy CD-DA Extractor 7
2007-08-03 14:10 737280 --a------ C:\WINDOWS\iun6002.exe
2007-08-02 18:38 --------- d-------- C:\Program Files\Ahead
2007-03-09 07:12:32 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-03-27 13:36]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 03:36]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 02:07]
"PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" [2004-10-22 19:29]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [2006-05-18 15:36]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 06:42 C:\WINDOWS\soundman.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 14:00]
"WEBTRAN"="" []
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 20:25]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
R3 TNET1130;D-Link AirPlus G+ Wireless Adapter;C:\WINDOWS\system32\DRIVERS\GPlus.sys
R3 Tunx00;FunTV Video Capture;C:\WINDOWS\system32\DRIVERS\Tunx00.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2007-07-17 15:34:34 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-28 22:35:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-28 22:36:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-28 22:36
.
--- E O F ---