Posielam ten log.
ComboFix 08-08-03.05 - Brumteles 2008-08-04 15:23:07.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.2086 [GMT 2:00]
Running from: C:\Documents and Settings\Brumteles\Plocha\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\btfunc.dll
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{DEF85C80-216A-43AB-AF70-1665EDBE2780}
-------\Service_{DEF85C80-216A-43ab-AF70-1665EDBE2780}
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-08-04 13:14 . 2008-08-04 13:14 0 --a------ C:\23990098.$$$
2008-08-04 11:59 . 2008-08-04 12:41 50 --a------ C:\WINDOWS\Lic.xxx
2008-08-04 11:58 . 2004-08-17 15:49 418,304 --a------ C:\WINDOWS\R.COM
2008-08-04 11:58 . 2004-08-17 15:49 353,280 --a------ C:\WINDOWS\system32\T.COM
2008-08-01 22:10 . 2008-08-01 22:10 <DIR> d-------- C:\Program Files\Sun
2008-08-01 22:10 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-01 22:09 . 2008-08-01 22:09 <DIR> d-------- C:\Program Files\Java
2008-08-01 22:08 . 2008-08-01 22:08 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-01 21:58 . 2008-08-01 21:58 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-01 21:29 . 2008-08-01 23:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-31 10:49 . 2008-07-31 10:49 <DIR> d-------- C:\Program Files\Piranha Bytes
2008-07-31 10:24 . 2008-07-31 10:24 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-31 10:23 . 2008-08-01 21:29 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-31 10:15 . 2008-07-31 10:15 <DIR> d-------- C:\NVIDIA
2008-07-31 10:15 . 2008-05-19 18:16 186,407 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-07-31 10:02 . 2008-07-31 10:02 <DIR> d-------- C:\WINDOWS\system32\windows media
2008-07-31 10:02 . 2008-07-31 10:02 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-07-29 19:23 . 2008-08-02 09:36 654 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-27 15:44 . 2008-07-27 15:44 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-07-24 19:00 . 2008-07-31 10:02 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-07-23 11:29 . 2008-07-23 11:29 <DIR> d-------- C:\Program Files\Ligos
2008-07-23 10:55 . 2008-07-23 10:55 <DIR> d-------- C:\Program Files\Intel
2008-07-23 10:55 . 2000-06-23 14:05 136,704 --a------ C:\WINDOWS\system32\iacenc.dll
2008-07-23 10:55 . 2000-06-22 13:09 56,320 --------- C:\WINDOWS\system32\iyvu9_32.dll
2008-07-23 10:51 . 2008-07-23 10:51 <DIR> d-------- C:\Program Files\Windows Media Components
2008-07-19 17:37 . 2008-07-28 16:00 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-07-19 17:31 . 2008-07-31 10:02 <DIR> d-------- C:\Program Files\GameSpy Arcade
2008-07-19 17:31 . 2005-12-22 15:00 15,790,080 -ra------ C:\WINDOWS\UnWSetup.exe
2008-07-19 17:27 . 2008-07-31 10:02 <DIR> d-------- C:\Program Files\Outbreak
2008-07-19 17:21 . 2008-07-23 17:59 53,248 --a------ C:\WINDOWS\unrar.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-03 19:45 --------- d-----w C:\Program Files\Crawler
2008-08-02 09:19 --------- d-----w C:\Program Files\totalcmd
2008-07-31 14:28 --------- d-----w C:\Program Files\ICQToolbar
2008-07-31 08:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-31 08:01 --------- d-----w C:\Program Files\Spyware Terminator
2008-07-31 08:01 --------- d-----w C:\Program Files\Common Files\PCCamera
2008-07-31 07:44 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-07-28 22:38 --------- d-----w C:\Program Files\ESET
2008-07-24 16:46 --------- d-----w C:\Program Files\Ahead
2008-07-23 08:51 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-16 13:04 --------- d-----w C:\Program Files\Transform XP to Vista
2008-07-16 12:05 --------- d-----w C:\Program Files\ICQ6
2008-07-03 21:40 --------- d-----w C:\Program Files\Yahoo!
2008-07-01 11:04 --------- d-----w C:\Program Files\IObit
2008-06-27 08:57 921,632 ----a-w C:\PA7311.DAT
2008-06-19 16:14 --------- d-----w C:\Program Files\Trend Micro
2008-06-19 15:54 --------- d-----w C:\Program Files\DVD Shrink
2008-06-19 14:01 48,675 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-06-19 14:01 1,705 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-06-19 13:28 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-06-19 13:23 --------- d-----w C:\Program Files\CCleaner
2008-06-19 10:47 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-06-17 12:56 --------- d-----w C:\Program Files\ToniArts
2008-06-16 16:00 --------- d-----w C:\Program Files\Google
2008-06-16 13:13 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-06-16 13:13 --------- d-----w C:\Program Files\Common Files\HP
2008-06-16 13:11 --------- d-----w C:\Program Files\HP
2008-06-16 13:11 --------- d-----w C:\Program Files\Hewlett-Packard
2008-06-16 13:10 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-06-16 13:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-16 12:24 --------- d-----w C:\Program Files\Skype
2008-06-14 17:20 --------- d-----w C:\Program Files\ROUTE66
2008-06-14 14:43 --------- d-----w C:\Program Files\IVT Corporation
2008-06-14 14:18 --------- d-----w C:\Program Files\Phenix-Q8
2008-06-14 14:00 --------- d-----w C:\Program Files\Alcohol Soft
2008-06-14 13:46 --------- d-----w C:\Program Files\WinFast
2008-06-14 13:37 --------- d-----w C:\Program Files\InterVideo
2008-06-14 13:33 --------- d-----w C:\Program Files\BillP Studios
2008-06-14 13:12 --------- d-----w C:\Program Files\Winamp
2008-06-14 13:05 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-14 12:55 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-14 12:17 502,368 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-06-14 12:17 274,432 ----a-w C:\WINDOWS\system32\imon.dll
2008-06-14 12:17 --------- d-----w C:\Program Files\Sunbelt Software
2008-06-14 11:54 --------- d-----w C:\Program Files\ASUS
2008-06-14 11:51 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-06-14 11:32 --------- d-----w C:\Program Files\Realtek AC97
2008-06-14 10:44 558,142 ----a-w C:\WINDOWS\java\Packages\UV53XR9N.ZIP
2008-06-14 10:44 155,995 ----a-w C:\WINDOWS\java\Packages\IVBXR9ZT.ZIP
2008-06-14 10:44 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-16 09:48 446,464 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
.
------- Sigcheck -------
2002-09-20 18:05 600064 d1a616d5337e344a0dd6c6df7733a6c3 C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-17 15:49 1217024 010e00fba1d7afcc639710cdc010218c C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2004-08-17 15:49 1217024 010e00fba1d7afcc639710cdc010218c C:\WINDOWS\system32\wininet.dll
2004-08-17 15:49 1881088 3ca180b1d5bd5cc22374b2fb77491ee8 C:\WINDOWS\explorer.exe
2002-09-20 18:05 1004544 11d80755545cfb5eb9659ee88440eae2 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-17 15:49 1881088 3ca180b1d5bd5cc22374b2fb77491ee8 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-13 05:20 1314032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SW20"="C:\WINDOWS\System32\sw20.exe" [2005-06-30 08:03 200704]
"SW24"="C:\WINDOWS\System32\sw24.exe" [2005-07-04 07:29 69632]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-14 14:17 921600]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-06-14 14:55 1817600]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-01-27 07:38 316728]
"WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2005-03-02 13:21 278528]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 14:01 13529088]
"nwiz"="nwiz.exe" [2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-06-14 14:55]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
R2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;C:\WINDOWS\system32\drivers\wf88vcap.sys [2004-10-18 11:25]
R2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;C:\WINDOWS\system32\drivers\WF88XBAR.sys [2004-10-18 11:25]
R2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;C:\WINDOWS\system32\drivers\WF88TUNE.sys [2004-10-18 11:25]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 23:08]
R3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 16:55]
S3 PAC7311;Phenix-Q8;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 11:48]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 23:08]
S3 usbscan;Ovladač skeneru USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Brumteles\Data aplikací\Mozilla\Firefox\Profiles\37n9fc8w.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-04 15:31:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\PAStiSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
.
**************************************************************************
.
Completion time: 2008-08-04 15:34:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 13:34:07
Pre-Run: Volných bajtů: 11,435,954,176
Post-Run: Volněch bajt…: 11,465,113,600
214
K8N Neo4 Platinum, AMD Athlon64 3000+,RAM 2x256MB+2x1024MB, WDC WD1600JS 160GB, GeForce 6200 TurboCache, Tv WinFast PVR, WiFi Asus 802.11b/g+ruter WL-520GC,Win. XP pro. CZ