Ten strationremover nepomohl.
Tady posilam ten log.
"Martin" - 07-04-04 15:28:06 Service Pack 2
ComboFix 07-04-04.5 - Running from: "C:\Documents and Settings\Martin\Plocha"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\install.log
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\regedit.com
((((((((((((((((((((((((((((((( Files Created from 2007-03-04 to 2007-04-04 ))))))))))))))))))))))))))))))))))
2007-04-04 15:26 <DIR> d-------- C:\avenger
2007-04-03 15:27 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-04-03 15:27 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-04-03 15:27 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-04-03 15:27 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-04-03 15:27 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-04-03 15:27 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-04-03 00:18 1,386,496 --a------ C:\WINDOWS\system\MSVBVM60.DLL
2007-04-03 00:10 1,392,671 --a------ C:\WINDOWS\msvbvm60.dll
2007-03-28 22:46 <DIR> d-------- C:\Program Files\GamePark
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-03 00:40 -------- d--h----- C:\Program Files\installshield installation information
2007-04-03 00:40 -------- d--h----- C:\Program Files\installshield installation information
2007-04-03 00:39 -------- d-------- C:\Program Files\kooperativa
2007-04-03 00:39 -------- d-------- C:\Program Files\kooperativa
2007-03-26 16:29 70540 --a------ C:\WINDOWS\system32\perfc005.dat
2007-03-26 16:29 392956 --a------ C:\WINDOWS\system32\perfh005.dat
2007-03-14 22:40 -------- d-------- C:\Program Files\icqlite
2007-03-14 22:40 -------- d-------- C:\Program Files\icqlite
2007-02-27 00:32 -------- d-------- C:\Program Files\Common Files\microworld
2007-02-25 22:32 -------- d-------- C:\Program Files\qip
2007-02-25 22:32 -------- d-------- C:\Program Files\qip
2007-02-22 23:21 18706 --a------ C:\WINDOWS\winsbak.reg
2007-02-22 23:21 129870 --a------ C:\WINDOWS\winsbak2.reg
2007-02-21 20:33 0 --------- C:\AUTOEXEC.BAT
2007-02-13 12:53 -------- d-------- C:\Program Files\graphiccalc
2007-02-13 12:53 -------- d-------- C:\Program Files\graphiccalc
2007-01-15 19:32 689280 --a------ C:\WINDOWS\system32\aswboot.exe
2007-01-15 19:23 90112 --a------ C:\WINDOWS\system32\avastss.scr
2007-01-08 21:22 73216 --a------ C:\WINDOWS\st6unst.exe
2007-01-08 21:22 249856 --------- C:\WINDOWS\setup1.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"H/PC Connection Agent"="\"C:\\Programy\\MICROS~2\\wcescomm.exe\""
"DrvMon.exe"="C:\\WINDOWS\\system32\\DrvMon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"avast!"="\"C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe\""
"SoundMan"="SOUNDMAN.EXE"
"AudioDeck"="C:\\Program Files\\VIAudioi\\SBADeck\\ADeck.exe 1 "
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Akcelerátor spuštění AutoCADu.lnk]
"path"="C:\\Documents and Settings\\All Users\\Nabídka Start\\Programy\\Po spuštění\\Akcelerátor spuštění AutoCADu.lnk"
"backup"="C:\\WINDOWS\\pss\\Akcelerátor spuštění AutoCADu.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\AUTODE~1\\ACSTAR~1.EXE "
"item"="Akcelerátor spuštění AutoCADu"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Martin^Nabídka Start^Programy^Po spuštění^Miranda IM.lnk]
"path"="C:\\Documents and Settings\\Martin\\Nabídka Start\\Programy\\Po spuštění\\Miranda IM.lnk"
"backup"="C:\\WINDOWS\\pss\\Miranda IM.lnkStartup"
"location"="Startup"
"command"="C:\\Programy\\Miranda IM\\miranda32.exe "
"item"="Miranda IM"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvMon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DrvMon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\DrvMon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="C:\\Programy\\CyberLink\\PowerDVD\\PDVDServ.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=dword:00000002
"wscsvc"=dword:00000002
"RCSERVER"=dword:00000002
"Autodesk Licensing Service"=dword:00000003
"matlabserver"=dword:00000002
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"=dword:00000000
"SynchronousUserGroupPolicy"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-04 15:38:00
C:\ComboFix-quarantined-files.txt ... 07-04-04 15:38