Tak tady je odkaz na virustotal:
[url=]http://www.virustotal.com/cs/analisis/22254c4f37d81d18840fed464b80e0cf283c3c0593719ccd691e425ea757d5ee-1244555633
[/url]
Log z Combofixu:
ComboFix 09-06-08.03 - ota 09.06.2009 16:00.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.1.1250.420.1029.18.255.85 [GMT 2:00]
Spuštěný z: c:\documents and settings\ota\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\ota\Plocha\CFScript.txt
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
FILE ::
"C:\FOUND.014"
"C:\FOUND.015"
"C:\FOUND.016"
"C:\FOUND.017"
"C:\FOUND.018"
"C:\FOUND.019"
"C:\FOUND.020"
"c:\program files\folder.htt"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\FOUND.014
c:\found.014\FILE0000.CHK
c:\found.014\FILE0001.CHK
c:\found.014\FILE0002.CHK
c:\found.014\FILE0003.CHK
c:\found.014\FILE0004.CHK
c:\found.014\FILE0005.CHK
c:\found.014\FILE0006.CHK
c:\found.014\FILE0007.CHK
c:\found.014\FILE0008.CHK
c:\found.014\FILE0009.CHK
c:\found.014\FILE0010.CHK
c:\found.014\FILE0011.CHK
c:\found.014\FILE0012.CHK
c:\found.014\FILE0013.CHK
c:\found.014\FILE0014.CHK
c:\found.014\FILE0015.CHK
c:\found.014\FILE0016.CHK
c:\found.014\FILE0017.CHK
C:\FOUND.015
c:\found.015\FILE0000.CHK
c:\found.015\FILE0001.CHK
c:\found.015\FILE0002.CHK
C:\FOUND.016
c:\found.016\FILE0000.CHK
c:\found.016\FILE0001.CHK
c:\found.016\FILE0002.CHK
c:\found.016\FILE0003.CHK
c:\found.016\FILE0004.CHK
c:\found.016\FILE0005.CHK
c:\found.016\FILE0006.CHK
c:\found.016\FILE0007.CHK
c:\found.016\FILE0008.CHK
c:\found.016\FILE0009.CHK
c:\found.016\FILE0010.CHK
c:\found.016\FILE0011.CHK
c:\found.016\FILE0012.CHK
c:\found.016\FILE0013.CHK
C:\FOUND.017
c:\found.017\FILE0000.CHK
c:\found.017\FILE0001.CHK
c:\found.017\FILE0002.CHK
C:\FOUND.018
c:\found.018\FILE0000.CHK
c:\found.018\FILE0001.CHK
C:\FOUND.019
c:\found.019\FILE0000.CHK
c:\found.019\FILE0001.CHK
c:\found.019\FILE0002.CHK
C:\FOUND.020
c:\found.020\FILE0000.CHK
c:\found.020\FILE0001.CHK
c:\found.020\FILE0002.CHK
c:\found.020\FILE0003.CHK
c:\found.020\FILE0004.CHK
c:\program files\folder.htt
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FILEOBJINFO
-------\Service_FileObjInfo
((((((((((((((((((((((((( Soubory vytvořené od 2009-05-09 do 2009-06-09 )))))))))))))))))))))))))))))))
.
2009-06-09 07:20 . 2009-05-26 11:20 40160 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-06-09 07:20 . 2009-06-09 07:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-09 07:20 . 2009-05-26 11:19 18456 ----a-w- c:\winnt\system32\drivers\mbam.sys
2009-06-08 19:58 . 2009-06-08 19:58 -------- d-----w- c:\program files\Trend Micro
2009-06-08 18:29 . 2009-06-08 18:29 -------- d-----w- C:\Symbols
2009-06-08 17:49 . 2009-06-08 17:49 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
2009-06-08 17:15 . 2009-06-08 17:15 -------- d-----w- c:\program files\Support Tools
2009-05-18 19:42 . 2008-06-09 13:16 147456 ----a-w- c:\winnt\system32\bzpdf101c.dll
2009-05-18 19:41 . 2009-05-18 19:41 -------- d-----w- c:\program files\Common Files\STORMWARE Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 09:03 . 2004-05-13 15:48 46196 ----a-w- c:\winnt\system32\perfc005.dat
2009-06-09 09:03 . 2004-05-13 15:48 309990 ----a-w- c:\winnt\system32\perfh005.dat
2009-06-08 17:15 . 2004-05-13 16:04 2888 ----a-w- c:\winnt\PCHealth\HelpCtr\PackageStore\SkuStore.bin
2009-06-08 10:36 . 2004-05-16 17:20 9 ----a-w- c:\winnt\im32st.dat
2009-03-14 16:54 . 2004-05-13 15:46 50620 ----a-w- c:\winnt\system32\command.com
2005-04-29 17:47 . 2005-04-29 17:47 107 ----a-w- c:\program files\GPRSpeed Plus Client setup.log
2005-02-07 21:52 . 2004-06-21 22:55 1682 --sha-w- c:\winnt\system32\KGyGaAvL.sys
2004-06-21 22:55 . 2004-06-21 22:55 8 --sh--r- c:\winnt\system32\3F2DDCA2D4.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-06-09_08.16.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-05-13 15:47 . 2009-06-09 09:03 40128 c:\winnt\system32\perfc009.dat
- 2004-05-13 15:47 . 2006-09-17 17:22 40128 c:\winnt\system32\perfc009.dat
+ 2004-05-13 15:47 . 2009-06-09 09:03 311740 c:\winnt\system32\perfh009.dat
- 2004-05-13 15:47 . 2006-09-17 17:22 311740 c:\winnt\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-11-15 1670144]
"ICQ"="c:\program files\ICQ6\ICQ.exe" [2008-09-01 173304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SoundMan"="SOUNDMAN.EXE" - c:\winnt\SOUNDMAN.EXE [2002-08-02 46592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\winnt\System32\CTFMON.EXE" [2003-04-16 13312]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Ulead Photo Express 4.0 SE Calendar Checker .lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Ulead Photo Express 4.0 SE Calendar Checker .lnk
backup=c:\winnt\pss\Ulead Photo Express 4.0 SE Calendar Checker .lnkCommon Startup
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [23.7.2008 18:23 222456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2008-06-29 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 12:21]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.atlas.cz/?from=icqhpuInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
TCP: {35FD5611-4120-4831-8CEF-FBA1F00CCD1E} = 193.179.148.42
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-09 16:07
Windows 5.1.2600 Service Pack 1 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(584)
c:\winnt\system32\ODBC32.dll
- - - - - - - > 'lsass.exe'(640)
c:\winnt\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(3464)
c:\winnt\System32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\winnt\SYSTEM32\ACS.EXE
c:\program files\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
c:\winnt\SYSTEM32\WDFMGR.EXE
.
**************************************************************************
.
Celkový čas: 2009-06-09 16:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-06-09 14:09
ComboFix2.txt 2009-06-09 08:18
Před spuštěním: Volných bajtů: 52 488 142 848
Po spuštění: Volných bajtů: 52 427 030 528
175 --- E O F --- 2009-06-07 19:25
a tady log z HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:10:28, on 9.6.2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\acs.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ICQ6\ICQ.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.atlas.cz/?from=icqhpR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &ICQ Toolbar Search -
res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/pub/s ... wflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{35FD5611-4120-4831-8CEF-FBA1F00CCD1E}: NameServer = 193.179.148.42
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: TP-LINK Configuration Service (ACS) - Unknown owner - C:\WINNT\System32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
--
End of file - 5782 bytes