Zapomněla jsem. Tady je log
ComboFix 08-02-20.1 - Administrator 2008-02-21 9:44:13.3 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.265 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-01-21 to 2008-02-21 )))))))))))))))))))))))))))))))
.
2008-02-20 19:45 . 2004-08-17 14:49 147,968 --a------ C:\WINDOWS\R.COM
2008-02-20 19:45 . 2004-08-17 14:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-02-20 19:45 . 2008-02-20 19:46 50 --a------ C:\WINDOWS\Lic.xxx
2008-02-19 19:04 . 2008-02-19 19:04 <DIR> dr------- C:\Documents and Settings\NetworkService\Oblíbené položky
2008-02-19 11:14 . 2008-02-19 17:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-19 11:14 . 2008-02-19 12:16 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-02-19 09:20 . 2008-02-19 09:20 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\SuspenzorPC
2008-02-19 09:14 . 2008-02-19 09:14 <DIR> d-------- C:\Program Files\Common Files\SuspenzorPC
2008-02-19 09:14 . 2008-02-19 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SuspenzorPC
2008-02-19 09:13 . 2007-02-13 08:09 388,126 --a------ C:\WINDOWS\system32\sqlite3.dll
2008-02-19 09:13 . 2008-02-19 09:13 253,448 --a------ C:\Documents and Settings\Administrator\Data aplikací\installer_cz[3].exe
2008-02-19 09:02 . 2008-02-19 09:02 18,944 --a------ C:\WINDOWS\system32\drvgof.dll
2008-02-18 17:52 . 2008-02-18 17:52 26,624 --a------ C:\WINDOWS\system32\winexy32.dll
2008-02-13 14:01 . 2008-02-13 14:01 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Avg7
2008-02-13 13:48 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-13 13:48 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-13 13:48 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-13 13:48 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-07 12:29 . 2008-02-07 12:29 <DIR> d-------- C:\Documents and Settings\Administrator\Různé
2008-02-01 19:31 . 2008-02-01 19:31 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQ Toolbar
2008-02-01 19:06 . 2008-02-20 19:35 <DIR> d-------- C:\Program Files\ICQToolbar
2008-02-01 19:06 . 2008-02-01 19:20 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2008-02-01 19:05 . 2008-02-01 19:20 <DIR> d-------- C:\Program Files\ICQ6
2008-02-01 19:03 . 2008-02-01 19:03 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\InstallShield
2008-01-31 21:33 . 2008-02-19 17:40 521 --a------ C:\hpfr3420.xml
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 17:55 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 21:10 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\MSN6
2008-02-01 18:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-31 19:02 --------- d-----w C:\Program Files\Google
2007-12-27 21:50 --------- d-----w C:\Program Files\SigmaTel
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-01-09 20:43 42,288 ----a-w C:\Documents and Settings\Administrator\Data aplikací\GDIPFONTCACHEV1.DAT
2005-08-28 19:28 0 ---ha-w C:\Documents and Settings\Administrator\hpothb07.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-17 14:49 1667584]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49 15360]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 17:51 57344]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-31 15:25 171448]
"ICQ"="C:\Program Files\ICQ6\ICQ.exe" [2007-12-17 16:12 172280]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-07-15 10:42 4112384]
"nwiz"="nwiz.exe" [2004-07-15 10:42 843776 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-07-15 10:42 81920]
"mouseElf"="C:\PROGRA~1\GENIUS~1\GNETMOUS.EXE" [2002-08-20 10:59 172032]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"Cmaudio"="cmicnfg.cpl" []
"MSys32"="D:\Hry\Tetris 3000\data\morfitwebentrance.exe" [ ]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003-10-14 11:20 1224754]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-04 17:18 77824]
"DAEMON Tools-1033"="D:\Různé\daemon.exe" [2004-08-22 17:05 81920]
"CHotkey"="mHotkey.exe" [2002-07-05 15:37 491008 C:\WINDOWS\mHotkey.exe]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 17:50 40960]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"MSDisp32"="C:\WINDOWS\system32\drvgof.dll" [2008-02-19 09:02 18944]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 14:49 15360]
C:\Documents and Settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
PowerReg Scheduler.exe [2005-09-04 11:46:41 256000]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58 28672]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
R3 genmcmn;Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gmfiltr.sys [2002-05-29 19:21]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 22:04]
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2006-01-20 14:48]
.
Contents of the 'Scheduled Tasks' folder
"2005-09-12 06:00:58 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1100415536.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-21 09:45:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"CHotkey"="mHotkey.exe"
.
Completion time: 2008-02-21 9:46:13
ComboFix-quarantined-files.txt 2008-02-21 08:45:57
ComboFix2.txt 2008-02-20 18:33:44