Tak snad jsem to udělal správně. Rozjed se mi to podařilo až podruhé a jestli nevadí, když jsem při tom pár krát odklikl Comodo a STerminatora.
ComboFix 08-01-30.6 - Mirek 2008-01-30 17:33:34.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.264 [GMT 1:00]
Running from: C:\Documents and Settings\Mirek\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\WINDOWS\system32\guard32.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.
2008-01-28 15:53 . 2001-08-17 21:28 771,581 --a--c--- C:\WINDOWS\system32\dllcache\winacisa.sys
2008-01-28 15:53 . 2001-08-17 21:28 701,386 --a--c--- C:\WINDOWS\system32\dllcache\wdhaalba.sys
2008-01-28 15:53 . 2004-08-03 22:31 154,624 --a--c--- C:\WINDOWS\system32\dllcache\wlluc48.sys
2008-01-28 15:53 . 2001-10-24 12:25 87,040 --a--c--- C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-01-28 15:53 . 2001-10-24 12:25 54,272 --a--c--- C:\WINDOWS\system32\dllcache\wiamsmud.dll
2008-01-28 15:53 . 2001-10-24 11:57 34,890 --a--c--- C:\WINDOWS\system32\dllcache\wlandrv2.sys
2008-01-28 15:53 . 2004-08-17 15:44 31,744 --a--c--- C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-01-28 15:53 . 2004-08-03 22:29 23,615 --a--c--- C:\WINDOWS\system32\dllcache\wch7xxnt.sys
2008-01-28 15:53 . 2004-08-03 23:07 8,832 --a--c--- C:\WINDOWS\system32\dllcache\wmiacpi.sys
2008-01-28 15:51 . 2001-08-17 21:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2008-01-28 15:50 . 2001-10-24 12:25 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll
2008-01-28 15:49 . 2001-10-24 12:24 315,520 --a--c--- C:\WINDOWS\system32\dllcache\trid3d.dll
2008-01-28 15:48 . 2001-10-24 12:24 172,768 --a--c--- C:\WINDOWS\system32\dllcache\t2r4disp.dll
2008-01-28 15:47 . 2001-10-24 11:43 285,792 --a--c--- C:\WINDOWS\system32\dllcache\stlnata.sys
2008-01-28 15:46 . 2004-08-03 22:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys
2008-01-28 15:45 . 2001-10-24 12:24 386,560 --a--c--- C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-01-28 15:44 . 2001-10-24 12:24 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2008-01-28 15:43 . 2004-08-17 15:49 397,056 --a--c--- C:\WINDOWS\system32\dllcache\s3gnb.dll
2008-01-28 15:42 . 2001-10-24 11:58 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-01-28 15:41 . 2004-08-17 15:49 363,520 --a--c--- C:\WINDOWS\system32\dllcache\psisdecd.dll
2008-01-28 15:40 . 2004-08-17 15:48 259,328 --a--c--- C:\WINDOWS\system32\dllcache\perm3dd.dll
2008-01-28 15:39 . 2001-08-17 22:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-01-28 15:38 . 2004-08-17 15:45 132,695 --a--c--- C:\WINDOWS\system32\dllcache\netwlan5.sys
2008-01-28 15:37 . 2004-08-17 15:49 1,737,856 --a--c--- C:\WINDOWS\system32\dllcache\mtxparhd.dll
2008-01-27 20:51 . 2004-08-03 23:10 49,024 --a--c--- C:\WINDOWS\system32\dllcache\mstape.sys
2008-01-27 20:51 . 2001-08-17 21:48 12,416 --a--c--- C:\WINDOWS\system32\dllcache\msriffwv.sys
2008-01-27 20:51 . 2004-08-03 22:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-01-27 20:50 . 2004-08-17 15:49 56,832 --a--c--- C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-01-27 20:50 . 2004-08-03 23:10 51,328 --a--c--- C:\WINDOWS\system32\dllcache\msdv.sys
2008-01-27 20:50 . 2001-08-17 22:02 35,200 --a--c--- C:\WINDOWS\system32\dllcache\msgame.sys
2008-01-27 20:50 . 2004-08-03 23:00 22,016 --a--c--- C:\WINDOWS\system32\dllcache\msircomm.sys
2008-01-27 20:50 . 2001-08-17 21:48 6,016 --a--c--- C:\WINDOWS\system32\dllcache\msfsio.sys
2008-01-27 20:49 . 2001-08-17 21:52 17,280 --a--c--- C:\WINDOWS\system32\dllcache\mraid35x.sys
2008-01-27 20:49 . 2001-08-17 21:57 16,128 --a--c--- C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-01-27 20:49 . 2004-08-03 23:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\mpe.sys
2008-01-27 20:49 . 2001-08-17 21:52 6,528 --a--c--- C:\WINDOWS\system32\dllcache\miniqic.sys
2008-01-27 20:47 . 2001-08-17 21:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2008-01-27 20:46 . 2001-08-18 06:36 8,704 --a--c--- C:\WINDOWS\system32\dllcache\kbdjpn.dll
2008-01-27 20:46 . 2001-08-18 06:36 8,192 --a--c--- C:\WINDOWS\system32\dllcache\kbdkor.dll
2008-01-27 20:44 . 2001-10-24 12:24 372,824 --a--c--- C:\WINDOWS\system32\dllcache\iconf32.dll
2008-01-27 20:44 . 2001-08-17 22:06 154,496 --a--c--- C:\WINDOWS\system32\dllcache\icam4usb.sys
2008-01-27 20:44 . 2001-08-17 22:06 100,992 --a--c--- C:\WINDOWS\system32\dllcache\icam5usb.sys
2008-01-27 20:44 . 2001-10-24 12:24 62,464 --a--c--- C:\WINDOWS\system32\dllcache\icam4ext.dll
2008-01-27 20:44 . 2001-10-24 12:24 45,056 --a--c--- C:\WINDOWS\system32\dllcache\icam5com.dll
2008-01-27 20:44 . 2001-10-24 12:24 20,480 --a--c--- C:\WINDOWS\system32\dllcache\icam5ext.dll
2008-01-27 20:42 . 2001-08-17 21:28 542,879 --a--c--- C:\WINDOWS\system32\dllcache\hsf_msft.sys
2008-01-27 20:41 . 2001-10-24 11:58 907,456 --a--c--- C:\WINDOWS\system32\dllcache\hcf_msft.sys
2008-01-27 20:40 . 2001-10-24 12:24 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-01-27 20:39 . 2001-10-24 11:53 595,647 --a--c--- C:\WINDOWS\system32\dllcache\es56cvmp.sys
2008-01-27 20:38 . 2001-10-24 11:48 634,134 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys
2008-01-27 20:37 . 2001-08-17 20:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2008-01-27 20:36 . 2001-10-24 12:25 618,525 --a--c--- C:\WINDOWS\system32\dllcache\digiview.exe
2008-01-27 20:35 . 2004-08-17 15:49 250,880 --a--c--- C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-01-27 20:34 . 2001-10-24 11:52 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-01-27 20:33 . 2001-10-24 11:51 714,698 --a--c--- C:\WINDOWS\system32\dllcache\cbmdmkxx.sys
2008-01-27 20:32 . 2001-08-17 21:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-01-27 20:31 . 2004-08-17 15:49 1,888,992 --a--c--- C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-01-27 20:30 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-01-27 20:29 . 2004-08-03 23:10 53,248 --a--c--- C:\WINDOWS\system32\dllcache\1394bus.sys
2008-01-27 20:29 . 2001-08-17 22:06 11,264 --a--c--- C:\WINDOWS\system32\dllcache\1394vdbg.sys
2008-01-27 20:28 . 2001-10-24 12:24 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-01-23 15:40 . 2008-01-23 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Yahoo! Companion
2008-01-22 09:46 . 2008-01-22 09:46 <DIR> d-------- C:\Documents and Settings\M pracovní\Data aplikací\ACD Systems
2008-01-08 09:41 . 2008-01-08 09:37 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-01-08 09:41 . 2008-01-08 09:38 274,432 --a------ C:\WINDOWS\system32\imon.dll
2008-01-07 12:00 . 2008-01-07 12:00 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Creative Labs
2008-01-07 11:59 . 2008-01-07 11:59 <DIR> d-------- C:\Program Files\Common Files\Creative Labs Shared
2007-12-20 12:17 . 2007-12-20 12:17 <DIR> d-------- C:\Program Files\InterActual
2007-12-05 17:23 . 2007-12-05 17:23 <DIR> d-------- C:\Documents and Settings\Mirek\Data aplikací\SlySoft
2007-12-05 17:23 . 2007-12-05 17:23 <DIR> d-------- C:\Documents and Settings\Mirek\Data aplikací\SlySoft
2007-12-05 17:23 . 2007-12-05 17:23 <DIR> d-------- C:\Documents and Settings\Mirek\Data aplikací\SlySoft
2007-12-02 22:07 . 2007-12-03 11:21 <DIR> d-------- C:\Program Files\Google
2007-12-02 21:20 . 2007-12-02 21:20 <DIR> d-------- C:\Documents and Settings\Mirek\Data aplikací\MetaProducts
2007-12-02 21:20 . 2007-12-02 21:20 <DIR> d-------- C:\Documents and Settings\Mirek\Data aplikací\MetaProducts
2007-12-02 21:20 . 2007-12-02 21:20 <DIR> d-------- C:\Documents and Settings\Mirek\Data aplikací\MetaProducts
2007-12-02 21:20 . 2007-12-02 21:20 <DIR> d-------- C:\Documents and Settings\M pracovní\Data aplikací\MetaProducts
2007-12-02 21:20 . 2007-12-02 21:20 <DIR> d-------- C:\Documents and Settings\Default User\Data aplikací\MetaProducts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-29 05:54 --------- d-----w C:\Program Files\WinClamAVShield
2008-01-23 01:23 --------- d-----w C:\Program Files\CCleaner
2008-01-23 01:14 --------- d-----w C:\Program Files\Yahoo!
2008-01-22 16:19 --------- d-----w C:\Program Files\Opera
2008-01-16 13:05 --------- d-----w C:\Documents and Settings\Mirek\Data aplikací\Image Zone Express
2008-01-16 13:05 --------- d-----w C:\Documents and Settings\Mirek\Data aplikací\Image Zone Express
2008-01-16 13:05 --------- d-----w C:\Documents and Settings\Mirek\Data aplikací\Image Zone Express
2008-01-12 00:19 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-06 03:36 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-12-05 19:38 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2007-12-05 09:36 138,752 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-12-04 14:07 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\DVD Shrink
2007-12-03 17:25 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2007-11-22 23:31 139,008 ----a-w C:\WINDOWS\system32\guard32.dll.vir
2007-11-07 09:29 720,896 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:44 1,290,240 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-10 23:50 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-08-19 01:24 61,440 ----a-w C:\Documents and Settings\Mirek\cpil.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-09-20 14:50 1404928]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" [2004-09-23 12:28 708608]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 11:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 11:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"SpywareTerminator"="C:\Vedlejší programy\Spyware Terminator\SpywareTerminatorShield.exe" [2007-12-05 10:36 2834432]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2007-11-23 00:31 1481984]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-01-08 09:36 921600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 13:00 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Browser"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
R0 psdrv02;CD Guard Environment Driver (v2);C:\WINDOWS\system32\drivers\psdrv02.sys [2006-09-11 13:01]
R0 pssync05;CD Guard Synchronization Driver (v5);C:\WINDOWS\system32\drivers\pssync05.sys [2006-11-03 09:24]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2007-11-23 00:31]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2007-11-23 00:31]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2007-12-05 10:36]
S2 psrem02;CD Guard Drivers Auto Removal (v2);C:\WINDOWS\system32\psrem02.exe svc []
S3 CTSFSYN;Creative SoundFont Synth;C:\WINDOWS\system32\drivers\ctsfsyn.sys [2004-08-24 08:03]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE31bus.sys [2006-11-10 08:45]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys [2006-11-10 08:45]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE31mdm.sys [2006-11-10 08:45]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys [2006-11-10 08:45]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);C:\WINDOWS\system32\DRIVERS\se31nd5.sys [2006-11-10 08:46]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE31obex.sys [2006-11-10 08:46]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);C:\WINDOWS\system32\DRIVERS\se31unic.sys [2006-11-10 08:46]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-27 10:40:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-30 18:21:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\guard32.dll
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time: 2008-01-30 18:22:23
ComboFix-quarantined-files.txt 2008-01-30 17:22:20
.
2008-01-27 10:37:52 --- E O F ---