Zrobil jsem, jak jsi mi řekl, nevím, jestli stojí za zmínku, že na poprvé mi napsal Combo Fix, že nelze spustit, že není kompatibilní s mým OS, podruhé napsal, že u chybí dávkovací soubor. Na potřetí už to vyšlo.
Tady je log:
ComboFix 09-03-03.01 - doma 2009-03-04 19:59:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.767.314 [GMT 1:00]
Spuštěný z: c:\documents and settings\doma\Plocha\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET personal firewall *disabled*
* Vytvořen nový Bod Obnovení
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\regedit.com
c:\windows\system32\_004197_.tmp.dll
c:\windows\system32\_004198_.tmp.dll
c:\windows\system32\_004199_.tmp.dll
c:\windows\system32\_004200_.tmp.dll
c:\windows\system32\_004202_.tmp.dll
c:\windows\system32\_004203_.tmp.dll
c:\windows\system32\_004204_.tmp.dll
c:\windows\system32\_004205_.tmp.dll
c:\windows\system32\_004207_.tmp.dll
c:\windows\system32\_004208_.tmp.dll
c:\windows\system32\_004209_.tmp.dll
c:\windows\system32\_004210_.tmp.dll
c:\windows\system32\_004211_.tmp.dll
c:\windows\system32\_004212_.tmp.dll
c:\windows\system32\_004213_.tmp.dll
c:\windows\system32\_004214_.tmp.dll
c:\windows\system32\_004215_.tmp.dll
c:\windows\system32\_004216_.tmp.dll
c:\windows\system32\_004217_.tmp.dll
c:\windows\system32\_004218_.tmp.dll
c:\windows\system32\_004219_.tmp.dll
c:\windows\system32\_004220_.tmp.dll
c:\windows\system32\_004221_.tmp.dll
c:\windows\system32\_004222_.tmp.dll
c:\windows\system32\_004223_.tmp.dll
c:\windows\system32\_004224_.tmp.dll
c:\windows\system32\_004225_.tmp.dll
c:\windows\system32\_004226_.tmp.dll
c:\windows\system32\_004227_.tmp.dll
c:\windows\system32\_004228_.tmp.dll
c:\windows\system32\_004229_.tmp.dll
c:\windows\system32\_004230_.tmp.dll
c:\windows\system32\_004231_.tmp.dll
c:\windows\system32\_004232_.tmp.dll
c:\windows\system32\_004233_.tmp.dll
c:\windows\system32\_004234_.tmp.dll
c:\windows\system32\_004235_.tmp.dll
c:\windows\system32\_004236_.tmp.dll
c:\windows\system32\_004237_.tmp.dll
c:\windows\system32\_004238_.tmp.dll
c:\windows\system32\_004239_.tmp.dll
c:\windows\system32\_004240_.tmp.dll
c:\windows\system32\_004241_.tmp.dll
c:\windows\system32\_004242_.tmp.dll
c:\windows\system32\_004243_.tmp.dll
c:\windows\system32\_004244_.tmp.dll
c:\windows\system32\_004245_.tmp.dll
c:\windows\system32\_004246_.tmp.dll
c:\windows\system32\_004247_.tmp.dll
c:\windows\system32\_004248_.tmp.dll
c:\windows\system32\_004249_.tmp.dll
c:\windows\system32\_004250_.tmp.dll
c:\windows\system32\_004251_.tmp.dll
c:\windows\system32\_004252_.tmp.dll
c:\windows\system32\_004253_.tmp.dll
c:\windows\system32\_004254_.tmp.dll
c:\windows\system32\_004255_.tmp.dll
c:\windows\system32\_004256_.tmp.dll
c:\windows\system32\_004257_.tmp.dll
c:\windows\system32\_004258_.tmp.dll
c:\windows\system32\_004259_.tmp.dll
c:\windows\system32\_004260_.tmp.dll
c:\windows\system32\_004261_.tmp.dll
c:\windows\system32\_004262_.tmp.dll
c:\windows\system32\_004263_.tmp.dll
c:\windows\system32\_004264_.tmp.dll
c:\windows\system32\_004265_.tmp.dll
c:\windows\system32\_004266_.tmp.dll
c:\windows\system32\_004267_.tmp.dll
c:\windows\system32\_004269_.tmp.dll
c:\windows\system32\_004270_.tmp.dll
c:\windows\system32\_004271_.tmp.dll
c:\windows\system32\_004272_.tmp.dll
c:\windows\system32\_004273_.tmp.dll
c:\windows\system32\_004274_.tmp.dll
c:\windows\system32\_004275_.tmp.dll
c:\windows\system32\_004276_.tmp.dll
c:\windows\system32\_004277_.tmp.dll
c:\windows\system32\_004278_.tmp.dll
c:\windows\system32\_004279_.tmp.dll
c:\windows\system32\_004280_.tmp.dll
c:\windows\system32\_004281_.tmp.dll
c:\windows\system32\_004282_.tmp.dll
c:\windows\system32\_004283_.tmp.dll
c:\windows\system32\_004284_.tmp.dll
c:\windows\system32\_004285_.tmp.dll
c:\windows\system32\_004286_.tmp.dll
c:\windows\system32\_004287_.tmp.dll
c:\windows\system32\_004288_.tmp.dll
c:\windows\system32\_004289_.tmp.dll
c:\windows\system32\_004290_.tmp.dll
c:\windows\system32\_004291_.tmp.dll
c:\windows\system32\_004292_.tmp.dll
c:\windows\system32\_004293_.tmp.dll
c:\windows\system32\_004294_.tmp.dll
c:\windows\system32\_004295_.tmp.dll
c:\windows\system32\_004296_.tmp.dll
c:\windows\system32\_004297_.tmp.dll
c:\windows\system32\_004298_.tmp.dll
c:\windows\system32\_004299_.tmp.dll
c:\windows\system32\_004300_.tmp.dll
c:\windows\system32\_004301_.tmp.dll
c:\windows\system32\_004302_.tmp.dll
c:\windows\system32\_004303_.tmp.dll
c:\windows\system32\_004304_.tmp.dll
c:\windows\system32\_004305_.tmp.dll
c:\windows\system32\_004306_.tmp.dll
c:\windows\system32\_004307_.tmp.dll
c:\windows\system32\_004308_.tmp.dll
c:\windows\system32\_004309_.tmp.dll
c:\windows\system32\_004310_.tmp.dll
c:\windows\system32\_004311_.tmp.dll
c:\windows\system32\_004312_.tmp.dll
c:\windows\system32\_004313_.tmp.dll
c:\windows\system32\_004314_.tmp.dll
c:\windows\system32\_004315_.tmp.dll
c:\windows\system32\_004316_.tmp.dll
c:\windows\system32\_004317_.tmp.dll
c:\windows\system32\_004318_.tmp.dll
c:\windows\system32\_004319_.tmp.dll
c:\windows\system32\_004320_.tmp.dll
c:\windows\system32\_004321_.tmp.dll
c:\windows\system32\_004322_.tmp.dll
c:\windows\system32\_004323_.tmp.dll
c:\windows\system32\_004324_.tmp.dll
c:\windows\system32\_004325_.tmp.dll
c:\windows\system32\_004326_.tmp.dll
c:\windows\system32\_004327_.tmp.dll
c:\windows\system32\_004328_.tmp.dll
c:\windows\system32\_004329_.tmp.dll
c:\windows\system32\_004330_.tmp.dll
c:\windows\system32\_004331_.tmp.dll
c:\windows\system32\_004332_.tmp.dll
c:\windows\system32\_004333_.tmp.dll
c:\windows\system32\_004334_.tmp.dll
c:\windows\system32\_004335_.tmp.dll
c:\windows\system32\_004336_.tmp.dll
c:\windows\system32\_004337_.tmp.dll
c:\windows\system32\_004338_.tmp.dll
c:\windows\system32\_004340_.tmp.dll
c:\windows\system32\_004341_.tmp.dll
c:\windows\system32\_004342_.tmp.dll
c:\windows\system32\_004343_.tmp.dll
c:\windows\system32\_004344_.tmp.dll
c:\windows\system32\_004345_.tmp.dll
c:\windows\system32\_004346_.tmp.dll
c:\windows\system32\_004347_.tmp.dll
c:\windows\system32\_004349_.tmp.dll
c:\windows\system32\_004350_.tmp.dll
c:\windows\system32\_004351_.tmp.dll
c:\windows\system32\_004352_.tmp.dll
c:\windows\system32\_004353_.tmp.dll
c:\windows\system32\_004354_.tmp.dll
c:\windows\system32\_004355_.tmp.dll
c:\windows\system32\_004357_.tmp.dll
c:\windows\system32\_004358_.tmp.dll
c:\windows\system32\_004359_.tmp.dll
c:\windows\system32\_004360_.tmp.dll
c:\windows\system32\_004361_.tmp.dll
c:\windows\system32\_004364_.tmp.dll
c:\windows\system32\_004365_.tmp.dll
c:\windows\system32\_004366_.tmp.dll
c:\windows\system32\_004367_.tmp.dll
c:\windows\system32\_004368_.tmp.dll
c:\windows\system32\_004369_.tmp.dll
c:\windows\system32\_004370_.tmp.dll
c:\windows\system32\_004372_.tmp.dll
c:\windows\system32\_004373_.tmp.dll
c:\windows\system32\_004374_.tmp.dll
c:\windows\system32\_004375_.tmp.dll
c:\windows\system32\_004376_.tmp.dll
c:\windows\system32\_004377_.tmp.dll
c:\windows\system32\_004378_.tmp.dll
c:\windows\system32\_004379_.tmp.dll
c:\windows\system32\_004380_.tmp.dll
c:\windows\system32\_004381_.tmp.dll
c:\windows\system32\_004382_.tmp.dll
c:\windows\system32\_004383_.tmp.dll
c:\windows\system32\_004384_.tmp.dll
c:\windows\system32\_004385_.tmp.dll
c:\windows\system32\_004386_.tmp.dll
c:\windows\system32\_004387_.tmp.dll
c:\windows\system32\_004388_.tmp.dll
c:\windows\system32\_004390_.tmp.dll
c:\windows\system32\_004391_.tmp.dll
c:\windows\system32\_004392_.tmp.dll
c:\windows\system32\_004393_.tmp.dll
c:\windows\system32\_004394_.tmp.dll
c:\windows\system32\_004397_.tmp.dll
c:\windows\system32\_004398_.tmp.dll
c:\windows\system32\_004399_.tmp.dll
c:\windows\system32\_004400_.tmp.dll
c:\windows\system32\_004401_.tmp.dll
c:\windows\system32\_004402_.tmp.dll
c:\windows\system32\_004403_.tmp.dll
c:\windows\system32\_004405_.tmp.dll
c:\windows\system32\_004406_.tmp.dll
c:\windows\system32\_004407_.tmp.dll
c:\windows\system32\_004408_.tmp.dll
c:\windows\system32\_004409_.tmp.dll
c:\windows\system32\_004410_.tmp.dll
c:\windows\system32\_004411_.tmp.dll
c:\windows\system32\_004412_.tmp.dll
c:\windows\system32\_004414_.tmp.dll
c:\windows\system32\_004415_.tmp.dll
c:\windows\system32\_004416_.tmp.dll
c:\windows\system32\_004418_.tmp.dll
c:\windows\system32\_004419_.tmp.dll
c:\windows\system32\_004420_.tmp.dll
c:\windows\system32\_004424_.tmp.dll
c:\windows\system32\_004425_.tmp.dll
c:\windows\system32\_004427_.tmp.dll
c:\windows\system32\_004430_.tmp.dll
c:\windows\system32\_004432_.tmp.dll
c:\windows\system32\_004433_.tmp.dll
c:\windows\system32\_004434_.tmp.dll
c:\windows\system32\_004435_.tmp.dll
c:\windows\system32\_004438_.tmp.dll
c:\windows\system32\_004439_.tmp.dll
c:\windows\system32\_004440_.tmp.dll
c:\windows\system32\_004441_.tmp.dll
c:\windows\system32\_004442_.tmp.dll
c:\windows\system32\_004447_.tmp.dll
c:\windows\system32\_004449_.tmp.dll
c:\windows\system32\_004614_.tmp.dll
c:\windows\system32\_004615_.tmp.dll
c:\windows\system32\_004616_.tmp.dll
c:\windows\system32\_004617_.tmp.dll
c:\windows\system32\_004624_.tmp.dll
c:\windows\system32\_004625_.tmp.dll
c:\windows\system32\_004626_.tmp.dll
c:\windows\system32\_004628_.tmp.dll
c:\windows\system32\_004629_.tmp.dll
c:\windows\system32\_004632_.tmp.dll
c:\windows\system32\_004633_.tmp.dll
c:\windows\system32\_004635_.tmp.dll
c:\windows\system32\_004636_.tmp.dll
c:\windows\system32\_004637_.tmp.dll
c:\windows\system32\_004639_.tmp.dll
c:\windows\system32\_004642_.tmp.dll
c:\windows\system32\_004643_.tmp.dll
c:\windows\system32\_004645_.tmp.dll
c:\windows\system32\_004647_.tmp.dll
c:\windows\system32\_004648_.tmp.dll
c:\windows\system32\_004650_.tmp.dll
c:\windows\system32\_004653_.tmp.dll
c:\windows\system32\_004655_.tmp.dll
c:\windows\system32\_004656_.tmp.dll
c:\windows\system32\_004657_.tmp.dll
c:\windows\system32\_004658_.tmp.dll
c:\windows\system32\_004661_.tmp.dll
c:\windows\system32\_004662_.tmp.dll
c:\windows\system32\_004663_.tmp.dll
c:\windows\system32\_004664_.tmp.dll
c:\windows\system32\_004665_.tmp.dll
c:\windows\system32\_004670_.tmp.dll
c:\windows\system32\_004672_.tmp.dll
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-02-04 do 2009-03-04 )))))))))))))))))))))))))))))))
.
2009-03-04 16:59 . 2008-04-14 08:51 539,136 --a------ c:\windows\system32\SET17BA.tmp
2009-03-04 16:59 . 2008-04-14 08:48 177,152 --a------ c:\windows\system32\SET17BC.tmp
2009-03-04 16:58 . 2008-04-14 00:06 2,927,616 --a------ c:\windows\system32\SET1794.tmp
2009-03-04 16:58 . 2008-04-14 08:52 354,304 --a------ c:\windows\system32\SET1786.tmp
2009-03-04 16:58 . 2008-04-14 00:05 188,928 --a------ c:\windows\system32\SET1795.tmp
2009-03-04 16:58 . 2008-04-14 08:52 80,896 --a------ c:\windows\system32\SET1781.tmp
2009-03-04 16:58 . 2008-04-14 08:52 6,656 --a------ c:\windows\system32\SET177C.tmp
2009-03-04 16:50 . 2008-04-14 08:51 1,179,648 --a------ c:\windows\system32\SETB58.tmp
2009-03-04 16:49 . 2008-04-14 08:51 2,843,136 --a------ c:\windows\system32\SETA56.tmp
2009-03-04 16:48 . 2008-04-14 08:51 8,465,408 --a------ c:\windows\system32\SET961.tmp
2009-03-04 16:47 . 2008-04-14 08:52 729,600 --a------ c:\windows\system32\SET8EC.tmp
2009-03-04 16:44 . 2006-12-29 00:31 19,569 --a------ c:\windows\
002827_.tmp
2009-03-04 16:40 . 2007-04-18 17:15 2,854,400 --a------ c:\windows\system32\dllcache\msi.dll
2009-03-04 16:39 . 2008-07-03 14:03 8,464,896 --a------ c:\windows\system32\dllcache\shell32.dll
2009-03-04 16:19 . 2009-03-04 19:59 <DIR> d-------- c:\windows\system32\CatRoot2
2009-03-01 21:53 . 2009-03-01 22:27 1,355 --a------ c:\windows\imsins.BAK
2009-03-01 21:46 . 2006-03-02 13:00 71,040 --------- c:\windows\system32\drivers\_004252_.tmp.dll
2009-03-01 21:30 . 2008-04-14 04:21 512,000 --a------ c:\windows\system32\SET8A2.tmp
2009-03-01 21:29 . 2008-04-14 04:21 2,843,136 --a------ c:\windows\system32\SET850.tmp
2009-03-01 21:28 . 2008-04-14 04:21 8,465,408 --a------ c:\windows\system32\SET704.tmp
2009-03-01 21:27 . 2008-04-14 04:22 729,600 --a------ c:\windows\system32\SET63E.tmp
2009-03-01 01:43 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2009-03-01 01:38 . 2009-03-01 01:38 <DIR> d-------- c:\program files\Microsoft Works
2009-03-01 01:37 . 2009-03-01 01:37 <DIR> d-------- c:\program files\MSBuild
2009-03-01 01:34 . 2009-03-01 01:34 <DIR> d-------- c:\program files\Microsoft.NET
2009-03-01 01:29 . 2009-03-01 01:29 <DIR> d-------- c:\program files\Microsoft Visual Studio 8
2009-03-01 01:27 . 2009-03-01 02:41 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Microsoft Help
2009-03-01 01:25 . 2009-03-01 01:25 <DIR> dr-h----- C:\MSOCache
2009-03-01 01:09 . 2009-03-01 01:18 <DIR> d-------- c:\documents and settings\doma\Data aplikací\DAEMON Tools Pro
2009-03-01 01:09 . 2009-03-01 01:09 <DIR> d-------- c:\documents and settings\doma\Data aplikací\DAEMON Tools
2009-03-01 01:07 . 2009-03-01 01:07 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2009-03-01 01:07 . 2009-03-01 01:07 <DIR> d-------- c:\program files\DAEMON Tools Lite
2009-03-01 01:07 . 2009-03-01 01:07 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\DAEMON Tools Lite
2009-03-01 01:04 . 2009-03-01 01:09 <DIR> d-------- c:\documents and settings\doma\Data aplikací\DAEMON Tools Lite
2009-02-28 21:52 . 2009-02-28 22:06 <DIR> d-------- c:\documents and settings\doma\Data aplikací\Mp3tag
2009-02-22 17:26 . 2009-03-04 20:04 25,540 --a------ c:\windows\system32\oodbs.lor
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 19:06 --------- d-----w c:\documents and settings\doma\Data aplikací\uTorrent
2009-03-04 19:03 349,283 ---h--w c:\documents and settings\doma\Data aplikací\TurboLaunch_IconCache.dat
2009-03-01 20:06 --------- d---a-w c:\documents and settings\All Users\Data aplikací\TEMP
2009-03-01 10:57 --------- d-----w c:\documents and settings\All Users\Data aplikací\DVD Shrink
2009-03-01 10:40 --------- d-----w c:\documents and settings\doma\Data aplikací\Vso
2009-03-01 00:04 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-02-23 19:00 --------- d-----w c:\documents and settings\doma\Data aplikací\Skype
2009-02-23 15:49 --------- d-----w c:\documents and settings\doma\Data aplikací\skypePM
2009-02-21 20:51 81,920 ----a-w c:\documents and settings\doma\Data aplikací\ezpinst.exe
2009-02-21 20:51 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-02-21 20:51 47,360 ----a-w c:\documents and settings\doma\Data aplikací\pcouffin.sys
2009-01-31 00:02 --------- d-----w c:\program files\HDD Regenerator
2009-01-10 19:05 --------- d-----w c:\documents and settings\doma\Data aplikací\VitySoft
2009-01-04 14:42 --------- d-----w c:\documents and settings\doma\Data aplikací\Hamachi
2008-12-19 20:57 193,560 ----a-w c:\documents and settings\doma\Data aplikací\GDIPFONTCACHEV1.DAT
2008-03-25 18:56 241 ----a-w c:\documents and settings\doma\SR.vbs
2007-11-21 10:09 32 ----a-w c:\documents and settings\All Users\Data aplikací\ezsid.dat
2007-10-30 18:53 13,560 --sha-w c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 11:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2006-03-02 13:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 12:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 18:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\tcpip.sys
2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\ab04a73630759d84a46114bfca20f64c\tcpip.sys
2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 11:45 360320 3c966f647bab332093cb0f92692b5cb8 c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"QIP2005"="d:\programy\QIP\qip.exe" [2008-12-09 3259392]
"uTorrent"="d:\programy\uTorrent\uTorrent.exe" [2009-02-27 270128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 c:\windows\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\doma\Nabˇdka Start\Programy\Po spuçtŘnˇ\
TurboLaunch.lnk - d:\programy\TurboLaunch\TurboLaunch.exe [2007-02-08 2105856]
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 101784]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"GreyMSIAds"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= d:\programy\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\programy\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"d:\\programy\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"d:\\programy\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"d:\\programy\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"d:\\Hry\\Valve\\hlds.exe"=
"d:\\Hry\\Valve\\hl.exe"=
"d:\\programy\\Hamachi\\hamachi.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\programy\\Opera\\Opera.exe"=
"d:\\programy\\Strong DC\\StrongDC.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\programy\\QIP\\qip.exe"=
"d:\\Hry\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"d:\\programy\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2009-03-04 69120]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2006-03-02 3584]
S3 CrystalSysInfo;CrystalSysInfo;d:\programy\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 Droppix Service;Droppix Service;c:\program files\Common Files\Droppix\DxService.exe [2007-12-31 135168]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-12-07 10976]
S3 SE30bus;Sony Ericsson Device 048 Driver driver (WDM);c:\windows\system32\drivers\SE30bus.sys [2007-03-11 61600]
S3 SE30mdfl;Sony Ericsson Device 048 USB WMC Modem Filter;c:\windows\system32\drivers\SE30mdfl.sys [2007-03-11 9360]
S3 SE30mdm;Sony Ericsson Device 048 USB WMC Modem Driver;c:\windows\system32\drivers\SE30mdm.sys [2007-03-11 97184]
S3 SE30mgmt;Sony Ericsson Device 048 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\SE30mgmt.sys [2007-03-11 88688]
S3 se30nd5;Sony Ericsson Device 048 USB Ethernet Emulation SEMC48 (NDIS);c:\windows\system32\drivers\se30nd5.sys [2007-03-11 18704]
S3 SE30obex;Sony Ericsson Device 048 USB WMC OBEX Interface;c:\windows\system32\drivers\SE30obex.sys [2007-03-11 86560]
S3 se30unic;Sony Ericsson Device 048 USB Ethernet Emulation SEMC48 (WDM);c:\windows\system32\drivers\se30unic.sys [2007-03-11 90800]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Obsah adresáře 'Naplánované úlohy'
2009-02-20 c:\windows\Tasks\1-Click Maintenance.job
- d:\programy\TuneUp Utilities 2008\OneClick.exe [2008-01-20 14:02]
2008-09-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Notify-dimsntfy - (no file)
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.neobux.com/uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
TCP: {A80B43A5-542A-4B3A-8F6E-D5D7AC5EF881} = 62.129.50.20,85.135.32.100
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-04 20:05:48
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,03,e8,44,15,48,
99,a5,06,c8,28,51,af,b0,29,a3,98,eb,76,cf,f4,79,3c,f1,af,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b1,73,c5,c9,e6,
a9,0c,b4,71,3b,04,66,8b,46,0d,96,17,b5,7f,d4,26,41,4c,57,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,34,b3,00,04,de,
17,c6,27,25,da,ec,7e,55,20,c9,26,ac,ab,17,98,c2,ac,c1,a2,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,31,ca,77,80,c7,
8e,26,a3,3e,1e,9e,e0,57,5a,93,61,e3,f5,05,b7,f0,d4,6d,b0,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,e4,ed,fb,b2,05,
a4,48,e0,cd,44,cd,b9,a6,33,6c,cd,33,c9,6d,1d,62,bd,2d,87,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,e0,80,3d,37,1e,
0c,5d,8a,b0,18,ed,a7,3f,8d,37,a4,18,be,59,d6,01,67,28,f4,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,a6,c4,d8,bc,41,
de,06,bc,31,77,e1,ba,b1,f8,68,02,9b,6c,fb,be,ff,10,34,4a,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,de,98,58,c7,c3,
a7,3c,c6,83,6c,56,8b,a0,85,96,ab,98,08,f2,c2,35,0e,7c,59,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,dc,de,5b,4a,92,
47,f0,0e,51,fa,6e,91,28,9e,14,cc,22,86,a7,0b,cf,6b,07,34,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,78,15,43,68,fe,
ef,d0,ca,b1,cd,45,5a,a8,c4,f8,b9,2e,ea,80,6f,9b,7d,76,07,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,18,06,b1,94,50,
7b,2a,1e,e3,0e,66,d5,eb,bc,2f,6b,dc,08,b0,1a,6b,1f,6a,77,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,8c,da,e4,1f,71,
94,7b,63,fa,ea,66,7f,d4,3b,6b,70,92,ea,e9,3f,ba,06,4c,f3,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="B30702C9C880636A978C237F59420940768169B22FD3FAE009F8573C39F0E0AF0232359FBA6BF4E8E77B7112AFF5A3C80469765248BD3113E3D8A6D36B5D735F63435BB14A90A1BA50E7747E8E4A2A98143801D88D899D14F5A4EBD18A08AB7C67AB432A933BAB3AE1BE8757E3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933FEBC9E127BECC74CA2D97226D213B555A6171C11EC38DE3DF0274460CE99A02701A4023788FBF5A988B10B525035957118A426EFABEA6450C81CDB617A8BFBC6AF8450E95423B16EAF37F9ADC538F36914A09EAACCC46EF27DFD27D035B4846C2127BC18B5F71A094E66B8B3E729288153676B4D8E3BAD5F23AEA3D8283DDFCB562597EACEAFB47F74B18F2FF864BF2F93E467626FF0D49A423263E32CB2049E45BDC9CEFBDEE0DAA43059ADED289BEC0529853AA2EE69B2D8338AA35485BC1FD952CB75C5004EA9559D04827019F13ACB6747650C23C7B457FB528A618CAB117068ABD3EEF1017DF2D69343DE3D4E197EF746BC49DB9E37A37F88524C014337DBAA0D236BF6D36B5BE0A04949010B90AAD62FDA28CEEFCF94518EF5BF004BDA616625DF64B5F10E61E0D4B37533DC2AD025C0202993131AF92B59B61C8BDFC7BB8E3ECCB4B75C814DA370635E08C876632451AD852732379369F2987387704E1837386D6F6C68E85916C680AF16A787CA3DC76C27E9CD4A158DF6E20F3EC146999C030C56A6BE6834CCBD73CBD828F2E2FCA006AAA036F92ABC97A26ADCE904551A26B5E31B5B2B02FDD1EA4930CB53FC916C6BE47293F26DBD9A27B3F5D6E7D5B3BA3B44E48FDED884925AEF5F68C8DBD0CFCDDA6BDF64F1005985CEFC4650198D71B1D68301B3435FA2F53D8D2875B7B181A5487E6B82BB14C01553CDCC2211738AF13257A6E0413139B863C6087F3CCE50AE1AFD5705C3ADD1728DA252C6A3D1DD1A1D29CE9E46C0A160C879D9120B6A1A6675249BA67626A1FD7C20122BAABBD30A94221AAB38793B700679445CB76754112E0B82A636FAD95BD2C99DBEF4E56CE7C94FFBC8F26A79ACE87FC08FC84D06B45034AA4A574D38F1F888567744A9B79D2025BEBC45C5E3A1F1A49C623BC8CD1E990487D8A3608D6F0BAB754CCE07DE5631F97ECFF162151D58E87990FEA8D9DA7CC3DE1DD51E3EC3D86386BBBD201A844807AC51AF3DBCAF05B1CDD8F8E1703F211ECBE7A114C52363C569C5AF3838DC676B8D12AAF19E30144363FC7F0CE7626025BD8BABF12F04644BD06E363B9BD84229396701C5113959CB57445F622C9EC84BF6600B8D1D25C6D1453E58B53B3542271EAB451F7F2959D89CF8D9C640921E6B8E43CEDE4405A99AA3C30F5A9F73822FFA3B8009E8A1CCDE78E9A1BAB523563F6E91F7046D"
"OODEFRAG11.00.00.01WORKSTATION"="A0420701B413B45DB48BB03D90202A32F4EC8E6BAEB65CCAC41AE62807F94E72E01030BB241F5341A7ADCD85DBD0F2943D5E887ACEA107956F5765B6C1923CCEF7DCBF953C9D54558422BFE7845E43FB9830972DDCC3951A36E391E31C50A7635AF1F867136FB0CF4B8BBFDFBBD49B0F34FD083EC570AA8F1174EE4D62F277186DBEB04F6FDC35E86E3117AAE7234B78AE853AACAC603EB3ED619053139AE8D90CD452ACCD8E035F547D26CBA19C79669BADA2BB67301A452DA8211861CB0B9903E85CA660150D73D800DF87B7F89FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808BA7FD869164D6794FEBC9E127BECC74C6DD4D582A83B871AB6787BB71B30E40E03BF4135480093B452F0F7A8CC6D16AC5A4B502A558FBB3B26943AABD24A47E4D1764CB8B58F98D94D273E083B74F9A9B46DF25DD116674DB9E2963701507C01121C43D06ABEDC6C868AC0F1D8923D1985BFCB125E37723D48F6F4C4044795D38D7183FB8550B6835A27761B22E720D7D73D0E537A0F24CC32D462547D67852213AA92516A3AE488297E7E4DDCC64995BDD30D3D6A6E2D10D67A0C77D3202208756F19F541A7063CD60698E412B8C1D5CAE5C40439D81FEF1E5546D7B19229F08B5CE02873F61FAF492628540B7877701948516DB309F0A9EF49082F8492399FB07FDB3831BA19CAED3B3920DBF43A904346F654E9E97DCC3A2D6B4D7DAB55A9C1DE9B89EDB83EC63318766054D1C036EB9D98A5329B01BE70CB2F95151AE478A2F1DA14DFEB41358D7FB1C49066A43637004365A47421B80564B6FD04D0B34B39A574E4028336F5F4AD5F0E6A3FE1B7CC9323A81FFBE047F3A80914C8F2F0327158671D946195C1E34C9810021ADBB5D9F18A9942ED2DCABAC2D075A55DAF1439DE576F9A1DBAA25A7E9A35BC6DD681102AED77F33CD3F8DACA5CD5201AE72A82818D245A7E66775C5845FA42DDFBBD22BD69935D0B865958D09F7C036DF50244FAF519DF083D7371E29FF17E4858624B233A54EAB15BC9BFD73144DCCB967EF9FD9F3DF9E8481C251CCF3FA13CDE3B46C3C1344DBD4E7A9CD64C1EFEDDEE5422ABBE15BB09724D0874249D9F7DE3E8537D0742FB70BC6F0239CE8BFE03878D3E1EAB39FB030EB5AB510E58B182215D38A2329F2DBC698383DDBC24394BC888566061D556244DD72A0A21D1D277B3E23E791283E0CC7AE13C17BB14497C0576F3F1002BAA71CA0B1E6D977FC33B1D1330BB9838567C7A0C4AAC981A9311ED5C2748CC0D9A1E80F826BCCC6A87E2C35E6097DC1A925BD856CED9BF89BBB59A16814AAD650E18D122E7AAC32F67B46F08A22F169DDFAE65E96ECC46C8AECB88CF1A542F2E307B015709E2200070ADCDA9CF"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\HDDSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
d:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\program files\Cyberlink\Shared Files\RichVideo.exe
d:\programy\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ICQ6\ICQ.exe
.
**************************************************************************
.
Celkový čas: 2009-03-04 20:14:14 - počítač byl restartován [doma]
ComboFix-quarantined-files.txt 2009-03-04 19:13:28
Před spuštěním: 4,892,139,520
Po spuštění: 5,059,710,976
Current=1 Default=1 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
538 --- E O F --- 2009-03-02 21:01:06