A tady je log z ComboFixu
ComboFix 09-06-05.02 - nosovi 05.06.2009 21:43.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.659 [GMT 2:00]
Spuštěný z: c:\documents and settings\nosovi\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\nosovi\x.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\_002311_.tmp.dll
c:\windows\system32\_002312_.tmp.dll
c:\windows\system32\_002313_.tmp.dll
c:\windows\system32\_002314_.tmp.dll
c:\windows\system32\_002321_.tmp.dll
c:\windows\system32\_002322_.tmp.dll
c:\windows\system32\_002323_.tmp.dll
c:\windows\system32\_002325_.tmp.dll
c:\windows\system32\_002326_.tmp.dll
c:\windows\system32\_002329_.tmp.dll
c:\windows\system32\_002330_.tmp.dll
c:\windows\system32\_002333_.tmp.dll
c:\windows\system32\_002334_.tmp.dll
c:\windows\system32\_002336_.tmp.dll
c:\windows\system32\_002339_.tmp.dll
c:\windows\system32\_002340_.tmp.dll
c:\windows\system32\_002345_.tmp.dll
c:\windows\system32\_002347_.tmp.dll
c:\windows\system32\_002350_.tmp.dll
c:\windows\system32\_002352_.tmp.dll
c:\windows\system32\_002353_.tmp.dll
c:\windows\system32\_002354_.tmp.dll
c:\windows\system32\_002355_.tmp.dll
c:\windows\system32\_002358_.tmp.dll
c:\windows\system32\_002359_.tmp.dll
c:\windows\system32\_002360_.tmp.dll
c:\windows\system32\_002361_.tmp.dll
c:\windows\system32\_002362_.tmp.dll
c:\windows\system32\_002367_.tmp.dll
c:\windows\system32\_002995_.tmp.dll
c:\windows\system32\_002996_.tmp.dll
c:\windows\system32\_002997_.tmp.dll
c:\windows\system32\_002998_.tmp.dll
c:\windows\system32\_003005_.tmp.dll
c:\windows\system32\_003006_.tmp.dll
c:\windows\system32\_003007_.tmp.dll
c:\windows\system32\_003008_.tmp.dll
c:\windows\system32\_003010_.tmp.dll
c:\windows\system32\_003011_.tmp.dll
c:\windows\system32\_003014_.tmp.dll
c:\windows\system32\_003015_.tmp.dll
c:\windows\system32\_003018_.tmp.dll
c:\windows\system32\_003019_.tmp.dll
c:\windows\system32\_003021_.tmp.dll
c:\windows\system32\_003024_.tmp.dll
c:\windows\system32\_003025_.tmp.dll
c:\windows\system32\_003030_.tmp.dll
c:\windows\system32\_003032_.tmp.dll
c:\windows\system32\_003035_.tmp.dll
c:\windows\system32\_003037_.tmp.dll
c:\windows\system32\_003038_.tmp.dll
c:\windows\system32\_003039_.tmp.dll
c:\windows\system32\_003040_.tmp.dll
c:\windows\system32\_003041_.tmp.dll
c:\windows\system32\_003044_.tmp.dll
c:\windows\system32\_003045_.tmp.dll
c:\windows\system32\_003046_.tmp.dll
c:\windows\system32\_003047_.tmp.dll
c:\windows\system32\_003048_.tmp.dll
c:\windows\system32\_003053_.tmp.dll
c:\windows\system32\_004320_.tmp.dll
c:\windows\system32\_004321_.tmp.dll
c:\windows\system32\_004322_.tmp.dll
c:\windows\system32\_004323_.tmp.dll
c:\windows\system32\_004326_.tmp.dll
c:\windows\system32\_004330_.tmp.dll
c:\windows\system32\_004331_.tmp.dll
c:\windows\system32\_004332_.tmp.dll
c:\windows\system32\_004334_.tmp.dll
c:\windows\system32\_004335_.tmp.dll
c:\windows\system32\_004337_.tmp.dll
c:\windows\system32\_004338_.tmp.dll
c:\windows\system32\_004339_.tmp.dll
c:\windows\system32\_004340_.tmp.dll
c:\windows\system32\_004341_.tmp.dll
c:\windows\system32\_004342_.tmp.dll
c:\windows\system32\_004343_.tmp.dll
c:\windows\system32\_004344_.tmp.dll
c:\windows\system32\_004345_.tmp.dll
c:\windows\system32\_004348_.tmp.dll
c:\windows\system32\_004349_.tmp.dll
c:\windows\system32\_004354_.tmp.dll
c:\windows\system32\_004355_.tmp.dll
c:\windows\system32\_004356_.tmp.dll
c:\windows\system32\_004357_.tmp.dll
c:\windows\system32\_004358_.tmp.dll
c:\windows\system32\_004359_.tmp.dll
c:\windows\system32\_004361_.tmp.dll
c:\windows\system32\_004362_.tmp.dll
c:\windows\system32\_004363_.tmp.dll
c:\windows\system32\_004364_.tmp.dll
c:\windows\system32\_004365_.tmp.dll
c:\windows\system32\_004366_.tmp.dll
c:\windows\system32\_004367_.tmp.dll
c:\windows\system32\_004368_.tmp.dll
c:\windows\system32\_004369_.tmp.dll
c:\windows\system32\_004370_.tmp.dll
c:\windows\system32\_004371_.tmp.dll
c:\windows\system32\_004374_.tmp.dll
c:\windows\system32\_004375_.tmp.dll
c:\windows\system32\_004376_.tmp.dll
c:\windows\system32\_004379_.tmp.dll
c:\windows\system32\_004380_.tmp.dll
c:\windows\system32\_004382_.tmp.dll
c:\windows\system32\_004383_.tmp.dll
c:\windows\system32\_004385_.tmp.dll
c:\windows\system32\_004386_.tmp.dll
c:\windows\system32\_004391_.tmp.dll
c:\windows\system32\_004393_.tmp.dll
c:\windows\system32\_004396_.tmp.dll
c:\windows\system32\_004398_.tmp.dll
c:\windows\system32\_004399_.tmp.dll
c:\windows\system32\_004400_.tmp.dll
c:\windows\system32\_004401_.tmp.dll
c:\windows\system32\_004404_.tmp.dll
c:\windows\system32\_004405_.tmp.dll
c:\windows\system32\_004406_.tmp.dll
c:\windows\system32\_004407_.tmp.dll
c:\windows\system32\_004408_.tmp.dll
c:\windows\system32\_004413_.tmp.dll
c:\windows\system32\_004918_.tmp.dll
c:\windows\system32\_004919_.tmp.dll
c:\windows\system32\_004920_.tmp.dll
c:\windows\system32\_004921_.tmp.dll
c:\windows\system32\_004928_.tmp.dll
c:\windows\system32\_004929_.tmp.dll
c:\windows\system32\_004930_.tmp.dll
c:\windows\system32\_004932_.tmp.dll
c:\windows\system32\_004933_.tmp.dll
c:\windows\system32\_004936_.tmp.dll
c:\windows\system32\_004937_.tmp.dll
c:\windows\system32\_004940_.tmp.dll
c:\windows\system32\_004941_.tmp.dll
c:\windows\system32\_004943_.tmp.dll
c:\windows\system32\_004946_.tmp.dll
c:\windows\system32\_004947_.tmp.dll
c:\windows\system32\_004952_.tmp.dll
c:\windows\system32\_004954_.tmp.dll
c:\windows\system32\_004957_.tmp.dll
c:\windows\system32\_004959_.tmp.dll
c:\windows\system32\_004960_.tmp.dll
c:\windows\system32\_004961_.tmp.dll
c:\windows\system32\_004962_.tmp.dll
c:\windows\system32\_004965_.tmp.dll
c:\windows\system32\_004966_.tmp.dll
c:\windows\system32\_004967_.tmp.dll
c:\windows\system32\_004968_.tmp.dll
c:\windows\system32\_004969_.tmp.dll
c:\windows\system32\_004974_.tmp.dll
c:\windows\system32\dbfb.dll
c:\windows\system32\Drivers\sptd.sys
c:\windows\system32\tmp58.tmp
c:\windows\system32\ysusxvsc.ini
D:\desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Soubory vytvořené od 2009-05-05 do 2009-06-05 )))))))))))))))))))))))))))))))
.
2009-06-05 18:52 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-05 18:52 . 2009-06-05 18:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-05 18:52 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-05 04:49 . 2009-06-05 04:49 -------- d-----w- c:\program files\Trend Micro
2009-06-01 14:45 . 2009-03-26 23:16 12672 ----a-w- c:\windows\system32\drivers\cpuz132_x32.sys
2009-06-01 14:45 . 2009-06-01 14:45 -------- d-----w- c:\program files\CPUID
2009-06-01 13:52 . 2009-06-01 13:52 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-06-01 13:52 . 2009-06-01 13:52 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-05-31 17:26 . 2009-05-31 17:26 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-05-31 17:26 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-05-31 17:26 . 2009-05-31 17:26 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-05-31 17:26 . 2009-05-31 17:26 -------- d-----w- c:\program files\TuneUp Utilities 2009
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 18:29 . 2008-12-11 18:44 -------- d-----w- c:\program files\VDOWNLOADER
2009-06-01 13:42 . 2008-03-07 22:40 -------- d-----w- c:\program files\UltraISO
2009-05-31 17:25 . 2006-12-04 19:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-23 11:08 . 2006-11-25 11:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-23 10:59 . 2008-05-13 04:33 -------- d-----w- c:\program files\Atari
2009-05-05 09:36 . 2009-05-05 09:36 -------- d-----w- c:\program files\Avira
2009-04-15 16:53 . 2001-10-25 14:00 76270 ----a-w- c:\windows\system32\perfc005.dat
2009-04-15 16:53 . 2001-10-25 14:00 407180 ----a-w- c:\windows\system32\perfh005.dat
2009-04-15 16:42 . 2006-11-25 10:47 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-15 16:42 . 2006-11-25 10:47 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-04-08 04:47 . 2009-03-20 21:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-04-07 18:04 . 2006-11-25 14:04 -------- d-----r- c:\program files\Skype
2009-04-07 18:04 . 2009-04-07 18:04 -------- d-----w- c:\program files\Common Files\Skype
2009-04-07 14:51 . 2006-11-25 14:12 -------- d-----w- c:\program files\Google
2009-03-30 08:33 . 2009-05-05 09:36 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-03-24 16:50 . 2006-12-06 14:33 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-03-24 14:08 . 2009-05-05 09:36 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-03-21 07:29 . 2006-11-25 15:20 16 ----a-w- c:\windows\popcinfo.dat
2009-03-08 10:08 . 2007-03-30 08:56 226 ----a-w- c:\windows\tpinrank.dat
2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
2007-08-23 05:13 . 2007-08-23 05:13 48 --sh--w- c:\windows\S2A4176DB.tmp
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Digital Imaging Monitor"="c:\program files\HP\Digital Imaging\bin\hpqtra08.exe" [2004-11-04 258048]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-17 44544]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STI Simulator"=2 (0x2)
"PnkBstrA"=2 (0x2)
"gusvc"=3 (0x3)
"AntiVirService"=2 (0x2)
"AntiVirScheduler"=2 (0x2)
"aawservice"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Microsoft Office Outlook"=c:\progra~1\MICROS~1\OFFICE11\OUTLOOK.EXE /recycle
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe"
"SoundMan"=SOUNDMAN.EXE
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TrackMania Nations ESWC Special Edition\\TmNationsESWC.exe"=
"c:\\Program Files\\Reallusion\\CrazyTalk for Skype\\CT4Skype.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\Program Files\\Metin2_TESTER\\metin2.bin"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [8.10.2007 14:49 2996]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5.5.2009 11:36 108289]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [31.5.2009 19:26 604416]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [11.6.2008 17:11 33792]
R3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [14.11.2003 4:46 8192]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [12.2.2008 20:02 16512]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [1.6.2009 16:45 12672]
S3 CrystalCpuInfo;CrystalCpuInfo;\??\c:\docume~1\nosovi\LOCALS~1\Temp\CpuInfo.sys --> c:\docume~1\nosovi\LOCALS~1\Temp\CpuInfo.sys [?]
S3 PAC207;VideoCAM GE111;c:\windows\system32\drivers\pfc027.sys [8.4.2005 11:46 162176]
S4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [9.7.2008 20:15 222456]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2009-06-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]
2009-06-05 c:\windows\Tasks\HPpromotions journeysoftware.job
- c:\program files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [2005-04-22 15:36]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
SafeBoot-procexp90.Sys
.
------- Doplňkový sken -------
.
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Compare Prices with &Dealio - c:\program files\Dealio\res\DealioSearch.html
FF - ProfilePath - c:\documents and settings\nosovi\Data aplikací\Mozilla\Firefox\Profiles\6hxk5trj.default\
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - prefs.js: keyword.URL -
hxxp://search.sweetim.com/search.asp?src=2&q=FF - component: c:\documents and settings\nosovi\Data aplikací\Mozilla\Firefox\Profiles\6hxk5trj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: c:\documents and settings\nosovi\Data aplikací\Mozilla\Firefox\Profiles\6hxk5trj.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: nglayout.initialpaint.delay - 600
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-05 21:50
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PAStiSvc.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Celkový čas: 2009-06-05 21:57 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-06-05 19:57
ComboFix2.txt 2008-09-13 17:40
Před spuštěním: Volných bajtů: 18 421 649 408
Po spuštění: Volných bajtů: 18 925 346 816
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=1 Default=1 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
334 --- E O F --- 2009-05-13 11:31