save sem dával, ale když jsem ten log chtěl otevřít, tak tam nic nebylo..
zde je druhý log:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-10-04 13:22:51
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\PETRNO~1\LOCALS~1\Temp\awayyfog.sys
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x57 0x55 0x67 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3F 0x14 0xF7 0x2A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2D 0x9C 0xC1 0x0E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x57 0x55 0x67 0x54 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3F 0x14 0xF7 0x2A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2D 0x9C 0xC1 0x0E ...
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WFlags 2
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@ShowCmd 3
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1680x1050(1).left 360
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1680x1050(1).top 360
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1680x1050(1).right 1257
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1680x1050(1).bottom 764
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Petr Novak\Cookies\petr
novak@reklama.viry[2].txt 102 bytes
File C:\Documents and Settings\Petr Novak\Cookies\petr novak@viry[2].txt 341 bytes
File C:\System Volume Information\_restore{808A901B-B478-4790-A8D8-9A9988BBD41D}\RP299\A0486206.ini 12357 bytes
File C:\System Volume Information\_restore{808A901B-B478-4790-A8D8-9A9988BBD41D}\RP299\A0486207.ini 3317 bytes
---- EOF - GMER 1.0.15 ----