tak ten krok s TeaTimerem jsem nezvládl provést...
ale tady je ten log:
ComboFix 08-10-24.02 - Soňa 2008-10-26 11:30:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.234 [GMT 1:00]
Spuštěný z: C:\Documents and Settings\Soňa\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
ADS - svchost.exe: deleted 36864 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\Documents and Settings\LocalService\ftpdll.dll
C:\Documents and Settings\Peťa\ftpdll.dll
C:\Documents and Settings\Soňa\Data aplikací\WinAntiSpyware 2006
C:\Documents and Settings\Soňa\Data aplikací\WinAntiSpyware 2006\Logs\update.log
C:\Documents and Settings\Soňa\ftpdll.dll
C:\Documents and Settings\Soňa\Local Settings\Temporary Internet Files\fbk.sts
C:\Documents and Settings\Soňa\Nabídka Start\NOCREDITCARD.lnk
C:\Documents and Settings\Soňa\Nabídka Start\Programy\Po spuštění\ctfmon.exe
C:\Recycled\Recycled
C:\Recycled\Recycled\ctfmon.exe
C:\WINDOWS\BM3b532fcc.txt
C:\WINDOWS\BM3b532fcc.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\ctfmon.exe
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\_000115_.tmp.dll
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\B.tmp
C:\WINDOWS\system32\blphctfej0e17t.scr
C:\WINDOWS\system32\C.tmp
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\system32\dlds1.exe
C:\WINDOWS\system32\dlds2.exe
C:\WINDOWS\system32\dlds5.exe
C:\WINDOWS\system32\dlds6.exe
C:\WINDOWS\system32\dlds7.exe
C:\WINDOWS\system32\dlds8.exe
C:\WINDOWS\system32\drivers\109.exe
C:\WINDOWS\system32\drivers\125.exe
C:\WINDOWS\system32\drivers\140.exe
C:\WINDOWS\system32\drivers\187.exe
C:\WINDOWS\system32\drivers\203.exe
C:\WINDOWS\system32\drivers\218.exe
C:\WINDOWS\system32\drivers\234.exe
C:\WINDOWS\system32\drivers\250.exe
C:\WINDOWS\system32\drivers\31.exe
C:\WINDOWS\system32\drivers\312.exe
C:\WINDOWS\system32\drivers\343.exe
C:\WINDOWS\system32\drivers\375.exe
C:\WINDOWS\system32\drivers\421.exe
C:\WINDOWS\system32\drivers\437.exe
C:\WINDOWS\system32\drivers\453.exe
C:\WINDOWS\system32\drivers\468.exe
C:\WINDOWS\system32\drivers\484.exe
C:\WINDOWS\system32\drivers\562.exe
C:\WINDOWS\system32\drivers\578.exe
C:\WINDOWS\system32\drivers\609.exe
C:\WINDOWS\system32\drivers\625.exe
C:\WINDOWS\system32\drivers\671.exe
C:\WINDOWS\system32\drivers\687.exe
C:\WINDOWS\system32\drivers\6877a942.sys
C:\WINDOWS\system32\drivers\703.exe
C:\WINDOWS\system32\drivers\718.exe
C:\WINDOWS\system32\drivers\750.exe
C:\WINDOWS\system32\drivers\765.exe
C:\WINDOWS\system32\drivers\781.exe
C:\WINDOWS\system32\drivers\796.exe
C:\WINDOWS\system32\drivers\843.exe
C:\WINDOWS\system32\drivers\859.exe
C:\WINDOWS\system32\drivers\906.exe
C:\WINDOWS\system32\drivers\921.exe
C:\WINDOWS\system32\drivers\93.exe
C:\WINDOWS\system32\drivers\nqynwxmn.sys
C:\WINDOWS\system32\drivers\Winta73.sys
C:\WINDOWS\system32\ftpdll.dll
C:\WINDOWS\system32\icf.exe.exe
C:\WINDOWS\system32\inxoojxc.ini
C:\WINDOWS\system32\khfGawvU.dll
C:\WINDOWS\system32\kjsoft64.dll
C:\WINDOWS\system32\lphctfej0e17t.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\NnUuCJjl.ini
C:\WINDOWS\system32\NnUuCJjl.ini2
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ojltma.dat
C:\WINDOWS\system32\ojltma.exe
C:\WINDOWS\system32\ojltma_navup.dat
C:\WINDOWS\system32\phctfej0e17t.bmp
C:\WINDOWS\system32\rcsoft32.dll
C:\WINDOWS\system32\rs32net.exe
C:\WINDOWS\system32\rszyuds.dll
C:\WINDOWS\system32\rszyuds32.dll
C:\WINDOWS\system32\tpptaetd.ini
C:\WINDOWS\system32\update32.exe
C:\WINDOWS\system32\WinCtrl32.dl_
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\wjcqoydu.ini
D:\Autorun.inf
C:\WINDOWS\system32\drivers\str.sys . . . . nemohl být smazán
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_icf
-------\Legacy_lptrdcsrv
-------\Legacy_mickey32
-------\Legacy_nqynwxmn
-------\Legacy_tcpsr
-------\Legacy_winta73
-------\Service_icf
-------\Service_mickey32
-------\Service_nqynwxmn
-------\Service_tcpsr
-------\Service_winta73
((((((((((((((((((((((((( Soubory vytvořené od 2008-09-26 do 2008-10-26 )))))))))))))))))))))))))))))))
.
2008-10-25 21:24 . 2008-10-25 21:24 <DIR> d-------- C:\WINDOWS\system32\bfubackups
2008-10-25 21:03 . 2008-10-25 21:12 <DIR> d-------- C:\bfu
2008-10-25 21:03 . 2008-10-25 21:03 8,192 --ahs---- C:\WINDOWS\Thumbs.db
2008-10-25 18:37 . 2008-10-25 18:37 18 --a------ C:\WINDOWS\system32\25.tmp
2008-10-25 18:36 . 2008-10-25 18:36 136 --a------ C:\WINDOWS\system32\20.tmp
2008-10-24 22:03 . 2008-10-24 22:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-24 19:13 . 2007-07-11 22:18 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-10-24 19:13 . 2005-12-23 03:57 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-10-24 19:13 . 2005-12-23 03:57 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-10-24 19:13 . 2005-12-23 03:57 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-10-24 19:13 . 2005-12-22 20:00 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2008-10-24 19:13 . 2005-12-23 03:57 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-10-24 19:13 . 2005-12-23 03:57 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-10-24 19:13 . 2007-07-11 22:18 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-10-24 19:13 . 2008-10-24 19:13 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-24 18:05 . 2008-10-24 18:05 294,912 --a------ C:\WINDOWS\system32\usaesug.exe
2008-10-24 18:05 . 2008-10-24 19:36 5,148 --a------ C:\WINDOWS\system32\usaesug.dat
2008-10-24 18:05 . 2008-10-24 18:05 18 --a------ C:\WINDOWS\system32\2D.tmp
2008-10-24 18:04 . 2008-10-24 18:05 136 --a------ C:\WINDOWS\system32\1F.tmp
2008-10-24 16:12 . 2008-10-24 16:13 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-10-24 13:51 . 2008-10-24 13:51 323,584 --a------ C:\WINDOWS\system32\qywiwwk.exe
2008-10-24 13:51 . 2008-10-24 17:56 5,039 --a------ C:\WINDOWS\system32\qywiwwk.dat
2008-10-24 09:50 . 2008-10-24 09:50 172,032 --a------ C:\WINDOWS\system32\1A.tmp
2008-10-24 09:50 . 2008-10-24 09:50 45,056 --a------ C:\WINDOWS\system32\1D.tmp
2008-10-24 09:50 . 2008-10-24 09:50 45,056 --a------ C:\WINDOWS\system32\1C.tmp
2008-10-24 09:50 . 2008-10-24 09:50 18 --a------ C:\WINDOWS\system32\1E.tmp
2008-10-24 09:49 . 2008-10-24 09:50 128 --a------ C:\WINDOWS\system32\19.tmp
2008-10-24 09:46 . 2008-10-24 09:46 172,032 --a------ C:\WINDOWS\system32\18.tmp
2008-10-24 09:46 . 2008-10-24 09:46 18 --a------ C:\WINDOWS\system32\1B.tmp
2008-10-24 09:45 . 2008-10-24 09:46 128 --a------ C:\WINDOWS\system32\16.tmp
2008-10-24 09:21 . 2008-10-24 09:21 45,056 --a------ C:\WINDOWS\system32\13.tmp
2008-10-24 09:21 . 2008-10-24 09:21 31,894 --a------ C:\WINDOWS\system32\15.tmp
2008-10-24 09:21 . 2008-10-24 09:21 128 --a------ C:\WINDOWS\system32\4.tmp
2008-10-24 07:19 . 2008-10-26 11:38 93,918 --a------ C:\WINDOWS\system32\drivers\5d068ef2.sys
2008-10-24 07:16 . 2008-10-24 07:16 172,032 --a------ C:\WINDOWS\system32\12.tmp
2008-10-24 07:16 . 2008-10-24 07:16 128 --a------ C:\WINDOWS\system32\6.tmp
2008-10-24 07:16 . 2008-10-24 07:16 18 --a------ C:\WINDOWS\system32\17.tmp
2008-10-23 22:06 . 2007-04-18 17:15 2,854,400 --a------ C:\WINDOWS\system32\msi.dll
2008-10-23 22:06 . 2005-05-04 14:45 884,736 --a------ C:\WINDOWS\system32\msimsg.dll
2008-10-23 22:06 . 2005-05-04 14:45 271,360 --a------ C:\WINDOWS\system32\msihnd.dll
2008-10-23 22:06 . 2005-05-04 13:45 87,040 --a------ C:\WINDOWS\system32\msiexec.exe
2008-10-23 22:06 . 2005-05-04 14:45 15,360 --a------ C:\WINDOWS\system32\msisip.dll
2008-10-23 21:55 . 2008-10-23 21:55 135,392 --a------ C:\WINDOWS\system32\drivers\etheyizl.sys
2008-10-23 21:40 . 2008-10-24 22:48 381 --a------ C:\WINDOWS\wininit.ini
2008-10-23 21:39 . 2008-10-23 21:39 18 --a------ C:\WINDOWS\system32\B1.tmp
2008-10-23 21:38 . 2008-10-23 21:39 92 --a------ C:\WINDOWS\system32\AE.tmp
2008-10-23 21:28 . 2008-10-23 21:28 <DIR> d-------- C:\Documents and Settings\Soňa\Data aplikací\LangSoft
2008-10-23 21:28 . 2008-10-23 21:28 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\LangSoft
2008-10-23 20:14 . 2008-10-23 20:14 <DIR> dr------- C:\Documents and Settings\NetworkService\Oblíbené položky
2008-10-23 20:14 . 2008-10-23 20:14 <DIR> d-------- C:\Documents and Settings\NetworkService\Data aplikací\ICQ Toolbar
2008-10-23 20:06 . 2008-10-25 09:03 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-23 20:06 . 2008-10-24 23:05 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-10-23 18:41 . 2008-10-23 18:41 88 --a------ C:\WINDOWS\system32\639.tmp
2008-10-23 18:41 . 2008-10-23 18:41 18 --a------ C:\WINDOWS\system32\63C.tmp
2008-10-23 18:22 . 2008-10-23 18:22 2,842 --a------ C:\WINDOWS\system32\cnf.dat
2008-10-23 17:59 . 2008-10-23 17:59 180,224 --a------ C:\WINDOWS\system32\10.tmp
2008-10-23 17:59 . 2008-10-23 17:59 128 --a------ C:\WINDOWS\system32\F.tmp
2008-10-23 17:59 . 2008-10-23 17:59 18 --a------ C:\WINDOWS\system32\14.tmp
2008-10-23 17:03 . 2008-10-23 17:03 <DIR> d-------- C:\Documents and Settings\Peťa\Data aplikací\Spyware Terminator
2008-10-23 17:01 . 2008-10-23 17:01 128 --a------ C:\WINDOWS\system32\A.tmp
2008-10-23 17:01 . 2008-10-23 17:01 18 --a------ C:\WINDOWS\system32\11.tmp
2008-10-23 16:59 . 2008-10-23 16:59 141,740 --a------ C:\WINDOWS\system32\bio-22-10-1.exe
2008-10-23 16:59 . 2008-10-23 16:59 18 --a------ C:\WINDOWS\system32\E.tmp
2008-10-23 16:58 . 2008-10-23 16:58 128 --a------ C:\WINDOWS\system32\9.tmp
2008-10-23 13:37 . 2008-10-23 16:55 <DIR> d-------- C:\Program Files\Mjcore
2008-10-23 09:29 . 2008-10-23 09:29 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Data aplikací\ICQ Toolbar
2008-10-23 09:29 . 2008-10-23 09:29 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Data aplikací\ICQ Toolbar
2008-10-23 09:29 . 2008-10-23 09:29 29 --a------ C:\WINDOWS\system32\eysyohwh.tmp
2008-10-23 09:28 . 2008-10-26 11:35 32,768 --a------ C:\WINDOWS\system32\drivers\ati1afxx.sys
2008-10-23 09:27 . 2008-10-23 09:27 136 --a------ C:\WINDOWS\system32\2.tmp
2008-10-23 09:27 . 2008-10-23 09:27 18 --a------ C:\WINDOWS\system32\8.tmp
2008-10-23 08:24 . 2008-10-23 08:24 10,240 --a------ C:\WINDOWS\system32\rtvatbyx.exe
2008-10-22 07:19 . 2008-10-23 16:55 <DIR> d-------- C:\Documents and Settings\Soňa\Data aplikací\Facegame
2008-10-22 07:12 . 2008-10-22 07:12 34,304 --a------ C:\WINDOWS\system32\byXPHbBs.dll.ren
2008-10-22 07:12 . 2008-10-23 20:13 0 --a------ C:\WINDOWS\system32\drivers\442fe661.sys
2008-10-22 07:04 . 2008-10-22 07:04 <DIR> d-------- C:\Documents and Settings\Soňa\Data aplikací\Leadertech
2008-10-22 07:04 . 2008-10-22 07:04 4,034 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
2008-10-22 06:52 . 2008-03-05 14:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-10-18 11:37 . 2008-10-18 11:37 <DIR> d-------- C:\Program Files\Drive this data
2008-10-09 21:44 . 2008-10-09 21:44 <DIR> d-------- C:\Program Files\VS Revo Group
2008-10-08 16:03 . 2008-10-08 16:03 <DIR> d-------- C:\Program Files\eRightSoft
2008-10-08 16:03 . 2008-10-08 16:03 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-10-07 11:03 . 2008-10-09 21:54 <DIR> d-------- C:\Program Files\EvidenceDVD3
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 10:35 --------- d-----w C:\Program Files\ICQToolbar
2008-10-24 18:23 --------- d-----w C:\Documents and Settings\Peťa\Data aplikací\Skype
2008-10-23 16:07 --------- d-----w C:\Documents and Settings\Soňa\Data aplikací\Skype
2008-10-23 15:57 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Proxy Long Chin Ping
2008-10-23 15:55 --------- d-----w C:\Program Files\WakeMeUp
2008-10-23 15:55 --------- d-----w C:\Documents and Settings\Soňa\Data aplikací\Drive this data
2008-10-23 15:16 --------- d-----w C:\Program Files\YouTube Video Downloader
2008-10-22 05:34 --------- d-----w C:\Documents and Settings\Soňa\Data aplikací\Azureus
2008-10-18 10:49 --------- d-----w C:\Program Files\bwin
2008-10-18 10:38 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\comp 32 support htm
2008-10-09 20:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-08 14:45 --------- d-----w C:\Program Files\MediaCoder
2008-09-29 10:25 --------- d-----w C:\Documents and Settings\Soňa\Data aplikací\DivX
2008-09-23 12:26 --------- d-----w C:\Program Files\ICQ6
2008-09-17 18:07 --------- d-----w C:\Program Files\Code-it Software
2008-09-16 16:08 --------- d-----w C:\Program Files\DivX
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2004-04-20 21:42 5 ------w C:\Program Files\start.dat
2004-04-19 20:41 12 ----a-w C:\Program Files\gfx.ini
2003-12-21 19:58 4,807,440 ----a-w C:\Program Files\data.res
2003-08-05 01:06 1,975 ----a-w C:\Program Files\readme.txt
.
------- Sigcheck -------
2008-04-14 04:22 22528 ba83ad4e340d389b559b8a8e1d87375f C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\svchost.exe
2008-10-26 11:35 22528 8aff881bf21ab2c644ba75dc33a40793 C:\WINDOWS\system32\svchost.exe
2004-08-18 13:00 22528 eda9d726c8eddce785c2b177e40f7388 C:\WINDOWS\system32\dllcache\svchost.exe
2007-06-13 14:23 1041920 2d5aca8eed2fbfd9811f4c4c3d0ccf62 C:\WINDOWS\explorer.exe
2007-06-13 14:11 1041920 60b39d97c36da1e9671a57d4210989ac C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-18 13:00 1040896 ab2a4e35ae3e7ee67ae16d786ee49e3b C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-14 04:22 1042432 14eea6f911c5b86b1ce2ac8c932a9664 C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\explorer.exe
2007-06-13 14:23 1041920 a7d9c5c8a3ae0bc81b0514ff6259d471 C:\WINDOWS\system32\dllcache\explorer.exe
2008-04-14 04:22 23552 80a793a8c47f04cfcfbedf198339b1b6 C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ctfmon.exe
2004-08-18 13:00 23552 35b3bbe6a80a363972523ce6c96ea9e4 C:\WINDOWS\system32\ctfmon.exe
2004-08-18 13:00 23552 5052fa95aa003aed3da5ed157bcebd53 C:\WINDOWS\system32\dllcache\ctfmon.exe
2005-06-11 01:17 66048 c4736144453bee5735ac01f9a74dbd7f C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2004-08-18 13:00 66048 693f6fa95a32c0c830439907d37227af C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-14 04:22 66048 8a06754f94c5b17ea982760c1b946950 C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\spoolsv.exe
2005-06-11 00:53 66048 7b565d58d31ef740b7f86614ba4e8cc3 C:\WINDOWS\system32\spoolsv.exe
2005-06-11 00:53 66048 bf88488909df69d63e3a511987075ffc C:\WINDOWS\system32\dllcache\spoolsv.exe
2008-04-14 04:22 34304 8fb7882eaacba58a703f16240b80e348 C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\userinit.exe
2004-08-18 13:00 32768 ff28f6853e46ca90d0bacd2f7eca5a50 C:\WINDOWS\system32\userinit.exe
2004-08-18 13:00 32768 9263faa8422d8d919b11b8bad2e69cf0 C:\WINDOWS\system32\dllcache\userinit.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 23552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 7110656]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 163840]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 23552]
C:\Documents and Settings\Soĺa\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Rapidown.lnk.disabled [2007-03-31 808]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.iv31"= C:\WINDOWS\system32\ir32_32.dll
"vidc.iv32"= C:\WINDOWS\system32\ir32_32.dll
"VIDC.DIV3"= DivXc32.dll
"VIDC.DIV4"= DivXc32f.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"VIDC.MPG4"= msmpeg4.dll
"VIDC.MP42"= msmpeg4.dll
"VIDC.MP43"= msmpeg4.dll
"msacm.l3fhg"= mp3fhg.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1afxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DAEMON Tools"="D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:@xpsp2res.dll,-22004
R0 ati1afxx;ati1afxx;C:\WINDOWS\system32\Drivers\ati1afxx.sys [2008-10-26 32768]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-18 69120]
S1 442fe661;442fe661;C:\WINDOWS\system32\drivers\442fe661.sys [2008-10-23 0]
S1 6877a942;6877a942;C:\WINDOWS\system32\drivers\6877a942.sys [ ]
S1 etheyizl;etheyizl;C:\WINDOWS\system32\drivers\etheyizl.sys [2008-10-23 135392]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\Recycled\ctfmon.exe
\Shell\Open(O)\command - C:\Recycled\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - D:\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\Autorun.exe
.
Obsah adresáře 'Naplánované úlohy'
2008-10-23 C:\WINDOWS\Tasks\AEF7DBE891944C5C.job
- c:\docume~1\soa~1\dataap~1\drivet~1\Sect sixth pure.exe [2008-10-18 11:39]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-Eggs rule - C:\DOCUME~1\SOA~1\DATAAP~1\DRIVET~1\Anti Test.exe
HKCU-Run-Facegame - C:\Documents and Settings\Soňa\Data aplikací\Facegame\Facegame.exe
HKCU-Run-WMUTray.exe - C:\Program Files\WakeMeUp\WMUTray.exe
HKLM-Run-lphctfej0e17t - C:\WINDOWS\system32\lphctfej0e17t.exe
HKLM-Run-SoundMAXPnP - C:\Program Files\Analog Devices\Core\smax4pnp.exe
HKLM-Run-Gainward - C:\WINDOWS\TBPanel.exe
HKLM-Run-PCSuiteTrayApplication - C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
HKLM-Run-SSBkgdUpdate - C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
HKLM-Run-OpwareSE4 - C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
HKLM-Run-Sony Ericsson PC Suite - C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
HKLM-Run-CHIN PING PHONE PILE - C:\Documents and Settings\All Users\Data aplikací\Proxy Long Chin Ping\16 mess.exe
HKLM-Run-WMUAgent.exe - C:\Program Files\WakeMeUp\WMUAgent.exe
SharedTaskScheduler-coursings - (no file)
ShellExecuteHooks-{46D7049A-9DB9-4AEC-82B1-F101B9367CB1} - C:\WINDOWS\system32\byXPHbBs.dll
Notify-byXPHbBs - byXPHbBs.dll
Notify-rszyuds - rszyuds.dll
.
------- Doplňkový sken -------
.
FireFox -: Profile - C:\Documents and Settings\Soňa\Data aplikací\Mozilla\Firefox\Profiles\y1bspw5z.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.seznam.cz/FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-26 11:36:14
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
C:\WINDOWS\system32\drivers\kjpwicpqrp.sys 30848 bytes executable
C:\WINDOWS\system32\drivers\str.sys 135199 bytes executable
C:\WINDOWS\system32\svchost.exe:ext.exe 25088 bytes executable
sken byl úspešně dokončen
skryté soubory: 3
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\oxigsglwawgafwh]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\kjpwicpqrp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\5d068ef2]
"ImagePath"="\SystemRoot\System32\drivers\5d068ef2.sys"
.
------------------------ Jiné spuštené procesy ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WakeMeUp\WMUSvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Celkový čas: 2008-10-26 11:43:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2008-10-26 10:43:10
Před spuštěním: Volných bajtů: 18 482 241 536
Po spuštění: Volných bajtů: 18,722,709,504
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
371 --- E O F --- 2008-10-16 15:09:18