To jsem nevěděl, omlouvám se.
Zkoušel jsem už všechno možné, ale výsledek vždy stejný...
ComboFix 11-07-25.02 - Administrator 25.07.2011 21:59:33.2.1 - FAT32x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.502.257 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Eset NOD32 antivirus system 2.51 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\dna69\Local Settings\temp\RtkBtMnt.exe
.
---- Předchozí spuštění -------
.
c:\program files\FunWebProducts\PopSwatr\History\notallow
c:\program files\FunWebProducts\ScreenSaver\Images\00ABD0BD.urr
c:\program files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\Internet Explorer\msimg32.dll
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3BRovly.dll
c:\program files\MyWebSearch\bar\1.bin\F3CJpeg.dll
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUtlcn.dll
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\00ABA1DD
c:\program files\MyWebSearch\bar\Cache\00ABAA4A
c:\program files\MyWebSearch\bar\Cache\00ABACBB.bin
c:\program files\MyWebSearch\bar\Cache\00ABAE51.bin
c:\program files\MyWebSearch\bar\Cache\00ABAFE7.bin
c:\program files\MyWebSearch\bar\Cache\00ABB17D.bin
c:\program files\MyWebSearch\bar\Cache\00B6BFA1.bin
c:\program files\MyWebSearch\bar\Cache\00B6C2ED.bin
c:\program files\MyWebSearch\bar\Cache\00B6C4F0.bin
c:\program files\MyWebSearch\bar\Cache\00B6D173.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search2
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSrcas.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\driVERs\jjwgo.sys
c:\windows\system32\f3PSSavr.scr
H:\autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_jjwgo
-------\Service_jjwgo
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-25 do 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 17:30 . 2011-07-25 17:30 -------- d-----w- C:\FOUND.014
2011-07-25 15:26 . 2011-07-25 15:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-25 11:42 . 2011-07-25 11:42 -------- d-----w- c:\documents and settings\All Users\Data aplikací\mD02300CkNbF02300
2011-07-24 10:57 . 2011-07-24 10:57 100352 ----a-w- c:\windows\system32\drivers\zgscwqlu.sys
2011-07-23 17:32 . 2011-07-23 17:32 1409 ----a-w- c:\windows\QTFont.for
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-03 16:42 . 2011-05-27 06:51 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-06 11:35 . 2007-04-04 16:35 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-02 15:32 . 2004-08-18 18:00 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-18 18:00 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-18 18:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 16248320]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2006-05-15 45056]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-18 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-18 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2006-08-09 151552]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 352256]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-22 3080704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 397312]
"CloneCDTray"="c:\program files\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-06-26 921600]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"UpdateReminder"="c:\program files\Eset\UpdateReminder.exe" [2011-07-19 462848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
.
c:\documents and settings\dna69\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Opera.lnk - c:\program files\Opera\Opera.exe [2007-10-15 79360]
UltimateZip Quick Start.lnk - c:\program files\UltimateZip\uzqkst.exe [2005-2-26 303616]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"d:\\Condition Zero\\czero.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\QIP Infium\\INFIUM.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\BIN\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
.
S0 snbtgj;snbtgj; [x]
S2 Application Updater;Application Updater;"c:\program files\Application Updater\ApplicationUpdater.exe" --> c:\program files\Application Updater\ApplicationUpdater.exe [?]
S2 zgscwqlu;zgscwqlu;c:\windows\system32\drivers\zgscwqlu.sys [24.7.2011 12:57 100352]
S3 0499c25276c15976;0499c25276c15976;\??\c:\windows\TEMP\10560bc4b0c5c --> c:\windows\TEMP\10560bc4b0c5c [?]
S3 0637ebeca377c932;0637ebeca377c932;\??\c:\windows\TEMP\1052099ccf70c --> c:\windows\TEMP\1052099ccf70c [?]
S3 0bafa66e91ece68f;0bafa66e91ece68f;\??\c:\windows\TEMP\105201663e8a4 --> c:\windows\TEMP\105201663e8a4 [?]
S3 24b1e08353f28cc2;24b1e08353f28cc2;\??\c:\windows\TEMP\10520e3a0b9c0 --> c:\windows\TEMP\10520e3a0b9c0 [?]
S3 26d24817e9b3875b;26d24817e9b3875b;\??\c:\windows\TEMP\10520a068d31c --> c:\windows\TEMP\10520a068d31c [?]
S3 2cbe92f3705e1ce4;2cbe92f3705e1ce4;\??\c:\windows\TEMP\1052043814a74 --> c:\windows\TEMP\1052043814a74 [?]
S3 300987ea9be03b25;300987ea9be03b25;\??\c:\windows\TEMP\1052050a5ae98 --> c:\windows\TEMP\1052050a5ae98 [?]
S3 44bfa5b4146114d5;44bfa5b4146114d5;\??\c:\windows\TEMP\10560c118198 --> c:\windows\TEMP\10560c118198 [?]
S3 59a106159134adb7;59a106159134adb7;\??\c:\windows\TEMP\10520874bf754 --> c:\windows\TEMP\10520874bf754 [?]
S3 7c8a9b297eaf5d92;7c8a9b297eaf5d92;\??\c:\windows\TEMP\10520db6613ac --> c:\windows\TEMP\10520db6613ac [?]
S3 7f3436be5ade665c;7f3436be5ade665c;\??\c:\windows\TEMP\10521d5344328 --> c:\windows\TEMP\10521d5344328 [?]
S3 810c1d9fd27e521b;810c1d9fd27e521b;\??\c:\windows\TEMP\105207acb7704 --> c:\windows\TEMP\105207acb7704 [?]
S3 8d6c76050ce3e2c3;8d6c76050ce3e2c3;\??\c:\windows\TEMP\105205e4313f4 --> c:\windows\TEMP\105205e4313f4 [?]
S3 a74bd38007fd0bde;a74bd38007fd0bde;\??\c:\windows\TEMP\10520733d43a8 --> c:\windows\TEMP\10520733d43a8 [?]
S3 b29ce8df6069a09d;b29ce8df6069a09d;\??\c:\windows\TEMP\105205d05c430 --> c:\windows\TEMP\105205d05c430 [?]
S3 b2e4a3091d6e03de;b2e4a3091d6e03de;\??\c:\windows\TEMP\105206efbcb2c --> c:\windows\TEMP\105206efbcb2c [?]
S3 b996d33d88343e90;b996d33d88343e90;\??\c:\windows\TEMP\10520fb5920b0 --> c:\windows\TEMP\10520fb5920b0 [?]
S3 d3dc9f3307e084c6;d3dc9f3307e084c6;\??\c:\windows\TEMP\105206956e408 --> c:\windows\TEMP\105206956e408 [?]
S3 d9558d29fb0714c6;d9558d29fb0714c6;\??\c:\windows\TEMP\10520cff3d5cc --> c:\windows\TEMP\10520cff3d5cc [?]
S3 da1eb02627c96a23;da1eb02627c96a23;\??\c:\windows\TEMP\1052084dd8fd4 --> c:\windows\TEMP\1052084dd8fd4 [?]
S3 e9e99b9bd8add747;e9e99b9bd8add747;\??\c:\windows\TEMP\10520bfa6d800 --> c:\windows\TEMP\10520bfa6d800 [?]
S3 f0cb6631aeb4f667;f0cb6631aeb4f667;\??\c:\windows\TEMP\10560459bbb6c --> c:\windows\TEMP\10560459bbb6c [?]
S3 f76f15cd6b3a6825;f76f15cd6b3a6825;\??\c:\windows\TEMP\105208770df2c --> c:\windows\TEMP\105208770df2c [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MDMXSDK
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://global.acer.com
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
LSP: c:\windows\system32\imon.dll
Trusted Zone: mojebanka.cz\*
TCP: DhcpNameServer = 10.107.52.1 10.107.4.100
TCP: Interfaces\{8617164D-C891-448E-9395-C136971A7643}: NameServer = 10.107.52.1,10.107.4.100
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-25 22:06
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\0499c25276c15976]
"ImagePath"="\??\c:\windows\TEMP\10560bc4b0c5c"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\0637ebeca377c932]
"ImagePath"="\??\c:\windows\TEMP\1052099ccf70c"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\0bafa66e91ece68f]
"ImagePath"="\??\c:\windows\TEMP\105201663e8a4"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\24b1e08353f28cc2]
"ImagePath"="\??\c:\windows\TEMP\10520e3a0b9c0"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\26d24817e9b3875b]
"ImagePath"="\??\c:\windows\TEMP\10520a068d31c"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\2cbe92f3705e1ce4]
"ImagePath"="\??\c:\windows\TEMP\1052043814a74"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\300987ea9be03b25]
"ImagePath"="\??\c:\windows\TEMP\1052050a5ae98"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\44bfa5b4146114d5]
"ImagePath"="\??\c:\windows\TEMP\10560c118198"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\59a106159134adb7]
"ImagePath"="\??\c:\windows\TEMP\10520874bf754"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\7c8a9b297eaf5d92]
"ImagePath"="\??\c:\windows\TEMP\10520db6613ac"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\7f3436be5ade665c]
"ImagePath"="\??\c:\windows\TEMP\10521d5344328"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\810c1d9fd27e521b]
"ImagePath"="\??\c:\windows\TEMP\105207acb7704"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\8d6c76050ce3e2c3]
"ImagePath"="\??\c:\windows\TEMP\105205e4313f4"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\a74bd38007fd0bde]
"ImagePath"="\??\c:\windows\TEMP\10520733d43a8"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\b29ce8df6069a09d]
"ImagePath"="\??\c:\windows\TEMP\105205d05c430"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\b2e4a3091d6e03de]
"ImagePath"="\??\c:\windows\TEMP\105206efbcb2c"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\b996d33d88343e90]
"ImagePath"="\??\c:\windows\TEMP\10520fb5920b0"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\d3dc9f3307e084c6]
"ImagePath"="\??\c:\windows\TEMP\105206956e408"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\d9558d29fb0714c6]
"ImagePath"="\??\c:\windows\TEMP\10520cff3d5cc"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\da1eb02627c96a23]
"ImagePath"="\??\c:\windows\TEMP\1052084dd8fd4"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\e9e99b9bd8add747]
"ImagePath"="\??\c:\windows\TEMP\10520bfa6d800"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\f0cb6631aeb4f667]
"ImagePath"="\??\c:\windows\TEMP\10560459bbb6c"
.
[HKEY_LOCAL_MACHINE\System\ControlSet010\Services\f76f15cd6b3a6825]
"ImagePath"="\??\c:\windows\TEMP\105208770df2c"
.
Celkový čas: 2011-07-25 22:08:22
ComboFix-quarantined-files.txt 2011-07-25 20:08
.
Před spuštěním: Volných bajtů: 18 864 340 992
Po spuštění: Volných bajtů: 18 817 548 288
.
- - End Of File - - 529285E0CD8A1CFB8B27315FCB0CC210