Vše jsem udělal podle plánu, připojuji požadovaný log, jen jsem chtěl ještě sdělit, že mám naistalováný XP profi a že to našlo spoustu poškozených souborů a chce to spusitit "chkdsk". Jinak připojuji ten log :
Díky.
ComboFix 10-01-16.03 - Administrator 17.01.2010 9:32.1.2 - x86
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ICQ6.5\ICQLRun.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-17 do 2010-01-17 )))))))))))))))))))))))))))))))
.
2010-01-15 19:53 . 2010-01-15 19:53 -------- d-----w- c:\program files\TrendMicro
2010-01-13 18:00 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2009-12-29 19:43 . 2010-01-11 18:09 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-25 15:58 . 2008-04-14 06:44 58496 -c--a-w- c:\windows\system32\dllcache\redbook.sys
2009-12-25 15:58 . 2008-04-14 06:44 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-12-23 13:07 . 2009-12-23 13:07 -------- d-----w- c:\program files\IVT Corporation
2009-12-22 15:46 . 2008-04-14 07:52 152064 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2009-12-22 15:46 . 2008-04-14 07:52 152064 ----a-w- c:\windows\system32\irftp.exe
2009-12-22 15:46 . 2008-04-14 07:52 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2009-12-22 15:46 . 2008-04-14 07:52 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-12-22 15:46 . 2008-04-14 07:51 27648 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2009-12-22 15:46 . 2008-04-14 07:51 27648 ----a-w- c:\windows\system32\irmon.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 08:38 . 2009-10-07 07:31 -------- d-----w- c:\program files\ICQ6.5
2010-01-13 19:28 . 2009-10-07 07:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 15:07 . 2009-10-07 07:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-10-07 07:45 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-29 20:01 . 2009-12-04 16:38 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-12-29 17:19 . 2009-07-29 21:26 313482 ----a-w- c:\windows\system32\perfh005.dat
2009-12-29 17:19 . 2009-07-29 21:26 47584 ----a-w- c:\windows\system32\perfc005.dat
2009-12-23 19:04 . 2009-12-23 19:03 8530 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1029.dat
2009-11-26 20:20 . 2009-11-03 19:41 -------- d-----w- c:\program files\Google
2009-11-26 20:10 . 2009-11-26 20:10 -------- d-----w- c:\program files\MSECache
2009-11-21 16:03 . 2009-07-29 21:12 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-09 18:23 . 2009-11-09 18:23 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-09 18:23 . 2009-11-09 18:23 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-09 18:23 . 2009-11-09 18:23 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-09 18:22 . 2009-11-09 18:22 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-06 19:16 . 2009-11-06 19:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-02 19:42 . 2009-11-07 12:00 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:43 . 2009-07-29 21:32 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:40 . 2009-07-29 21:29 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:40 . 2009-07-29 21:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2009-07-29 21:18 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 12:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-03 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"M3000Mnt"="M3000Rmv.dll " [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-04 2033432]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-09 18:23 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\VertrigoServ\\Mysql\\bin\\v_mysqld.exe"=
"c:\\Program Files\\VertrigoServ\\Apache\\bin\\v_apache.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 diskfp;FlashPoint;c:\windows\system32\drivers\diskfp.sys [7.10.2009 7:55 10624]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9.11.2009 19:23 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9.11.2009 19:23 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [9.11.2009 19:15 285392]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [7.10.2009 7:35 96856]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [7.10.2009 7:43 254976]
S2 gupdate1ca6ed5551b87fc;Služba Google Update (gupdate1ca6ed5551b87fc);c:\program files\Google\Update\GoogleUpdate.exe [26.11.2009 21:16 133104]
.
Obsah adresáře 'Naplánované úlohy'
2010-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-26 20:16]
2010-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-26 20:16]
2010-01-17 c:\windows\Tasks\User_Feed_Synchronization-{BDD66D25-9A12-4FFF-A55A-5002D1E0722D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://seznam.cz/IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-17 09:46
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-842925246-1085031214-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c5,9e,88,47,cc,20,6f,44,9c,08,68,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c5,9e,88,47,cc,20,6f,44,9c,08,68,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c5,9e,88,47,cc,20,6f,44,9c,08,68,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\igfxdev.dll
.
Celkový čas: 2010-01-17 09:46:43
ComboFix-quarantined-files.txt 2010-01-17 08:46
Před spuštěním: 4 246 196 224
Po spuštění: 4 772 352 000
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="USB Repair NOT to Start Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - CE6E3CCE562E9F4DBAD793C2A6A3FC8C