Nechci to zakřiknout, ale zdá se mi ten pc nějak živější.
Trvalo mi to, nepřišla jsem hned na to, že nesmí být při stahování spuštěný Firewall.
ComboFix 07-09-07.4 - "xxxx" 2007-09-07 17:54:57.2 - NTFSx86
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.33 [GMT 2:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\xxxx\DATAAP~1.\Ultimate Cleaner
C:\DOCUME~1\xxxx\DATAAP~1.\Ultimate Cleaner\settings.dat
C:\DOCUME~1\xxxx\Plocha\Error Cleaner.url
C:\DOCUME~1\xxxx\Plocha\Spyware&Malware Protection.url
C:\DOCUME~1\xxxx\ResErrors.log
C:\Program Files\Ultimate Cleaner
C:\Program Files\Ultimate Cleaner\com\ucsecuredelete.dll
C:\UGA6P
C:\WINDOWS\dat.txt
C:\WINDOWS\regedit.com
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\taskmgr.com
((((((((((((((((((((((((( Files Created from 2007-08-07 to 2007-09-07 )))))))))))))))))))))))))))))))
.
2007-09-07 17:51 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-07 17:12 <DIR> d-------- C:\Program Files\PhotoFiltre
2007-09-07 16:57 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-09-07 16:57 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-09-07 16:57 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-09-07 16:57 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-09-07 16:57 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-09-07 16:57 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-09-07 16:33 92,928 --------- C:\WINDOWS\system32\drivers\InCDfs.sys
2007-09-07 16:33 7,680 --------- C:\WINDOWS\system32\drivers\InCDrec.sys
2007-09-07 16:33 28,672 --------- C:\WINDOWS\system32\drivers\InCDpass.sys
2007-09-07 16:33 2,142,208 --------- C:\WINDOWS\NuNinst.exe
2007-09-07 16:33 <DIR> d-------- C:\WINDOWS\InCD
2007-09-07 16:31 2,285,568 --------- C:\WINDOWS\UNNeroVision.exe
2007-09-07 16:28 106,496 --------- C:\WINDOWS\system32\TwnLib20.dll
2007-09-07 16:27 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-09-07 16:27 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-09-07 16:27 38,912 --------- C:\WINDOWS\system32\picn20.dll
2007-09-07 16:27 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-09-07 16:27 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-09-07 16:27 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-09-07 16:25 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-09-07 16:25 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-09-07 15:53 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-07 15:53 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-07 15:53 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-09-07 15:53 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-07 15:53 1,868 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-07 15:53 <DIR> d-------- C:\Program Files\SmitfraudFix
2007-09-07 15:52 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1.000\Data aplikacˇ
2007-09-07 15:52 <DIR> dr------- C:\DOCUME~1\ADMINI~1.000\Nabˇdka Start
2007-09-07 15:52 <DIR> d--h----- C:\DOCUME~1\ADMINI~1.000\ćablony
2007-09-07 15:52 <DIR> d--h----- C:\DOCUME~1\ADMINI~1.000\Okolnˇ tisk rny
2007-09-07 15:52 <DIR> d--h----- C:\DOCUME~1\ADMINI~1.000\Okolnˇ sˇś
2007-09-07 15:52 <DIR> d-------- C:\DOCUME~1\ADMINI~1.000\Plocha
2007-09-07 15:52 <DIR> d-------- C:\DOCUME~1\ADMINI~1.000\Oblˇben‚ polo§ky
2007-09-07 15:52 <DIR> d-------- C:\DOCUME~1\ADMINI~1.000\Dokumenty
2007-09-07 15:50 1,003,789 --a------ C:\Program Files\SmitfraudFix.exe
2007-09-07 15:46 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1.YYY\Data aplikacˇ
2007-09-07 15:46 <DIR> dr------- C:\DOCUME~1\ADMINI~1.YYY\Nabˇdka Start
2007-09-07 15:46 <DIR> d--h----- C:\DOCUME~1\ADMINI~1.YYY\ćablony
2007-09-07 15:46 <DIR> d--h----- C:\DOCUME~1\ADMINI~1.YYY\Okolnˇ tisk rny
2007-09-07 15:46 <DIR> d--h----- C:\DOCUME~1\ADMINI~1.YYY\Okolnˇ sˇś
2007-09-07 15:46 <DIR> d-------- C:\DOCUME~1\ADMINI~1.YYY\Plocha
2007-09-07 15:46 <DIR> d-------- C:\DOCUME~1\ADMINI~1.YYY\Oblˇben‚ polo§ky
2007-09-07 15:46 <DIR> d-------- C:\DOCUME~1\ADMINI~1.YYY\Dokumenty
2007-09-07 15:34 <DIR> d-------- C:\Program Files\RegCleaner
2007-09-07 15:26 <DIR> d-------- C:\DOCUME~1\ADMINI~1\ćablony
2007-09-07 15:26 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Data aplikacˇ
2007-09-07 12:45 147,968 --a------ C:\WINDOWS\R.COM
2007-09-07 12:45 137,216 --a------ C:\WINDOWS\system32\T.COM
2007-09-07 11:27 <DIR> d-------- C:\Program Files\Maxthon2
2007-09-07 11:21 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-09-07 11:21 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-09-07 11:21 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-09-07 11:03 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-09-07 03:16 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-09-04 18:18 <DIR> d-------- C:\Program Files\Rage
2007-09-04 18:05 <DIR> d-------- C:\Program Files\Activision
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-07 16:33 --------- d-------- C:\Program Files\Ahead
2007-09-07 15:52 489 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2007-09-07 10:43 --------- d-------- C:\Program Files\ICQToolbar
2007-09-07 10:42 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-05 18:30 --------- d-------- C:\Program Files\Boiling Point - Cesta do pekel
2007-08-29 15:49 --------- d-------- C:\Program Files\Warcraft III
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-20 21:33 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-07-13 15:00 --------- d-------- C:\Program Files\Ubisoft
2007-07-13 14:58 --------- d-------- C:\Program Files\Codec Pack - All In 1
2007-07-13 14:55 737280 --a------ C:\WINDOWS\iun6002.exe
2007-06-26 08:10 1104896 --------- C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 15:23 1033728 --a------ C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-07 21:33 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-01-11 01:33 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 11:09 C:\WINDOWS\SOUNDMAN.EXE]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 15:47]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-12 10:13]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-07 11:19]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-08-27 04:01]
C:\DOCUME~1\ALLUSE~1\NABDKA~1\Programy\POSPUT~1\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-26 09:52:33]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2005-09-20 10:28:16]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2006-09-24 22:37:23]
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-07 18:00:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-07 18:03:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-07 18:03
.
--- E O F ---