Problem byl ve stáří kombofixu, měl jsem ho uložený na počítači několik týdnů, ,takže stažením nového přímo od zdroje pomohlo. Sken projel, přeposílám log, link na uložené viry pošlu obratem
ComboFix 10-03-03.07 - Administrator 04.03.2010 12:50:17.2.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.503.291 [GMT 1:00]
Sputěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Pouité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
file zipped: c:\windows\Fonts\vgafixt.fon
file zipped: c:\windows\Fonts\vgasyst.fon
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Fonts\vgafixt.fon . . . . nemohl být smazán
c:\windows\Fonts\vgasyst.fon . . . . nemohl být smazán
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-04 do 2010-03-04 )))))))))))))))))))))))))))))))
.
2010-03-03 20:21 . 2010-03-03 22:10 -------- d-----w- C:\hmyz
2010-03-03 12:26 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-03 12:26 . 2010-03-03 12:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-03 12:26 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-03 12:24 . 2010-03-03 12:24 -------- d-----w- c:\program files\trend micro
2010-03-03 12:24 . 2010-03-03 12:24 -------- d-----w- C:\rsit
2010-02-28 14:33 . 2010-03-02 19:08 -------- d-----w- c:\program files\Ultimate Process Manager
2010-02-28 14:25 . 2001-10-24 10:54 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-02-28 14:19 . 2008-04-13 23:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-02-24 11:57 . 2010-02-24 11:57 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-02-24 04:06 . 2010-02-24 05:00 -------- d-----w- C:\9c742d4edf43896c2bd64d0542
2010-02-14 08:38 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-14 08:38 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-02-13 15:49 . 2010-03-04 10:19 -------- d-----w- c:\documents and settings\Computer\Tracing
2010-02-13 15:43 . 2010-02-13 15:43 -------- d-----w- c:\program files\Microsoft
2010-02-13 15:42 . 2010-02-13 15:42 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-02-13 15:42 . 2010-02-13 15:44 -------- d-----w- c:\program files\Windows Live
2010-02-13 15:35 . 2010-02-13 15:35 -------- d-----w- c:\program files\Common Files\Windows Live
2010-02-10 10:21 . 2010-02-10 10:22 -------- d-----w- c:\program files\ABBYY FineReader 6.0 Sprint
2010-02-10 10:13 . 2010-02-10 10:23 -------- d-----w- c:\program files\epson
2010-02-10 10:11 . 2004-09-10 20:12 49152 ----a-w- c:\windows\system32\E_DCINST.DLL
2010-02-10 10:11 . 2006-12-08 02:04 76800 ----a-w- c:\windows\system32\E_FLBCDE.DLL
2010-02-10 10:11 . 2006-04-19 02:00 62976 ----a-w- c:\windows\system32\E_FD4BCDE.DLL
2010-02-10 10:10 . 2008-04-13 23:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-02-10 10:10 . 2008-04-13 23:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-02-10 10:08 . 2007-03-26 23:00 67072 ----a-w- c:\windows\system32\escwiad.dll
2010-02-10 10:08 . 2008-04-13 23:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-02-10 10:08 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-10 10:05 . 2008-04-13 23:15 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-02-10 10:05 . 2008-04-13 23:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-02-07 21:12 . 2010-02-07 21:14 -------- d-----w- c:\program files\QuickTime
2010-02-07 21:11 . 2010-02-07 21:11 -------- d-----w- c:\program files\Common Files\Apple
2010-02-07 21:10 . 2010-02-07 21:11 -------- d-----w- c:\program files\Apple Software Update
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 18:46 . 2010-01-20 11:17 -------- d-----w- c:\program files\Spyware Terminator
2010-02-28 14:40 . 2010-01-20 17:57 -------- d-----w- c:\program files\CCleaner
2010-02-10 10:31 . 2010-01-12 13:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-10 10:29 . 2010-01-12 16:45 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-29 09:22 . 2010-01-29 09:22 -------- d-----w- c:\program files\OpenOffice.org 3
2010-01-22 20:57 . 2010-01-22 19:01 -------- d-----w- c:\program files\Common Files\Real
2010-01-22 20:42 . 2006-09-06 02:08 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-01-22 20:42 . 2006-09-06 02:08 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-01-22 19:04 . 2010-01-22 19:04 -------- d-----w- c:\program files\Common Files\xing shared
2010-01-22 19:01 . 2010-01-22 19:01 -------- d-----w- c:\program files\Real
2010-01-22 18:56 . 2010-01-12 19:21 -------- d-----w- c:\program files\Google
2010-01-22 17:33 . 2010-01-22 17:32 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-21 16:10 . 2001-10-25 12:00 77850 ----a-w- c:\windows\system32\perfc005.dat
2010-01-21 16:10 . 2001-10-25 12:00 428744 ----a-w- c:\windows\system32\perfh005.dat
2010-01-20 18:34 . 2010-01-20 18:33 -------- d-----w- c:\program files\SystemRequirementsLab
2010-01-20 15:17 . 2010-01-20 15:17 -------- d-----w- c:\program files\Intel
2010-01-20 14:43 . 2010-01-20 14:43 -------- d-----w- c:\program files\CPUID
2010-01-20 13:12 . 2010-01-14 17:08 -------- d-----w- c:\program files\Realtek AC97
2010-01-20 11:18 . 2010-01-20 11:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-20 11:10 . 2010-01-20 10:09 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-15 07:56 . 2010-01-12 10:57 -------- d-----w- c:\program files\Windows Media Connect 2
2010-01-13 15:49 . 2010-01-12 11:01 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-13 15:49 . 2010-01-12 11:00 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-01-13 15:49 . 2010-01-12 11:01 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-01-12 18:39 . 2010-01-12 17:16 -------- d-----w- c:\program files\Seznam.cz
2010-01-12 16:47 . 2010-01-12 16:47 -------- d-----w- c:\program files\Vimicro Corporation
2010-01-12 16:45 . 2010-01-12 16:45 -------- d-----w- c:\program files\Vimicro
2010-01-12 16:32 . 2010-01-12 16:32 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-12 16:27 . 2010-01-12 16:26 -------- d-----w- c:\program files\Yahoo!
2010-01-12 16:23 . 2010-01-12 16:23 -------- d-----r- c:\program files\Skype
2010-01-12 16:23 . 2010-01-12 16:23 -------- d-----w- c:\program files\Common Files\Skype
2010-01-12 13:23 . 2010-01-12 13:23 -------- d-----w- c:\program files\MSBuild
2010-01-12 13:23 . 2010-01-12 13:23 -------- d-----w- c:\program files\Reference Assemblies
2010-01-12 13:02 . 2010-01-12 13:02 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-12 13:02 . 2010-01-12 13:02 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-12 13:02 . 2010-01-12 13:02 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-12 13:02 . 2010-01-12 13:02 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-12 13:02 . 2010-01-12 13:02 -------- d-----w- c:\program files\AVG
2010-01-12 11:57 . 2010-01-12 11:57 0 ----a-w- c:\windows\nsreg.dat
2010-01-12 11:02 . 2010-01-12 11:02 -------- d-----w- c:\program files\microsoft frontpage
2010-01-12 10:58 . 2010-01-12 10:58 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-31 16:50 . 2008-04-13 22:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2008-08-08 15:43 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2010-01-12 10:56 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2008-04-14 06:51 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 10:11 . 2008-04-14 06:06 2147328 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:11 . 2008-04-14 08:06 2025984 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2008-04-13 22:47 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
------- Sigcheck -------
[-] 2008-08-08 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-03_23.22.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-12 11:49 . 2010-03-04 10:09 122136 c:\windows\system32\FNTCACHE.DAT
.
(((((((((((((((((((((((((((((((((( Spoutěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"VMSnap5"="c:\windows\VMSnap5.EXE" [2006-10-23 49152]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-01-20 2166784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-01-22 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\Computer\NabĄdka Start\Programy\Po spuçtŘnĄ\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-12 13:02 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Domino]
2006-10-23 11:17 49152 ----a-r- c:\windows\Domino.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12.1.2010 14:02 333192]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12.1.2010 14:02 360584]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [20.1.2010 12:18 142592]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12.1.2010 14:02 906520]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12.1.2010 14:02 285392]
S2 gupdate1ca9b94849eaedc;Sluba Google Update (gupdate1ca9b94849eaedc);c:\program files\Google\Update\GoogleUpdate.exe [22.1.2010 19:55 133104]
S3 ZSMC0305;VIMICRO USB PC Camera V;c:\windows\system32\drivers\usbVM305.sys [12.1.2010 17:40 391737]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-22 18:55]
2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-22 18:55]
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - c:\program files\Seznam.cz\listicka.dll
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\6b6wqqfi.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-04 15:35
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých poloek 'Po sputění' ...
skenování skrytých souborů ...
sken byl úspeně dokončen
skryté soubory: 0
**************************************************************************
.
------------------------ Jiné sputené procesy ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
.
**************************************************************************
.
Celkový čas: 2010-03-04 15:43:57 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-04 14:43
ComboFix2.txt 2010-03-03 23:29
Před sputěním: Volných bajtů: 149 673 263 104
Po sputění: Volných bajtů: 149 644 001 280
- - End Of File - - 8507B5FF65C9C6B6B446CCCBC226DDDB