Posilam log, uz nemazu sve jmeno a vsiml jsem si, ze jsem asi blbe prepsal jmeno prijmeni pro cript pro CF
viz FILE
"c:\documents and settings\Jmeno Prijmenia\Local Settings\temp\_uninst_04303634.bat"
nyni posilam bez uprav, prosim tedy jeste jednou o zaslani noveho scryptu, nyni jiz se jmenem.
diky moc
a jeste jedna zprava
, udelal jsem ten script jeste jednou a dal znova pres CF a pak se to stalo 
Nevim, jestli to bylo po restartu CF ale asi ano, objevila se prihlasovaci obrazovka, ale heslo mi tam nefunguje, nevim jestli je to zkrat v hlave, ze jsem ho najednou zapomnel,
ale proste se nemuzu prihlasit (CAPSLOG jsem kontroloval)
*-*-*-*-*-*
ComboFix 11-10-10.01 - Petr Vácha 10.10.2011 12:18:41.8.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1440 [GMT 2:00]
Spuštěný z: c:\documents and settings\Petr Vácha\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Petr Vácha\Plocha\CFScript.txt
AV: AVG Anti-Virus Free *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
FILE ::
"c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk"
"c:\documents and settings\Jmeno Prijmenia\Local Settings\temp\_uninst_04303634.bat"
"c:\documents and settings\Petr Vácha\Local Settings\temp\_uninst_.bat"
"c:\documents and settings\Petr Vácha\Nabídka Start\Programy\Po spuštění\_uninst_.lnk"
"c:\documents and settings\Petr Vácha\Nabídka Start\Programy\Po spuštění\_uninst_04303634.lnk"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-10 do 2011-10-10 )))))))))))))))))))))))))))))))
.
.
2011-10-05 12:04 . 2011-10-05 12:04 -------- d-----w- c:\documents and settings\Petr Vácha\DoctorWeb
2011-10-05 07:59 . 2008-04-13 19:21 162816 -c--a-w- c:\windows\system32\dllcache\netbt.sys
2011-10-05 07:59 . 2008-04-13 19:21 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-10-04 13:34 . 2008-04-14 02:14 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-10-04 09:57 . 2011-10-04 09:57 -------- d-----w- C:\_OTM
2011-10-04 08:40 . 2011-10-05 08:41 -------- d-sh--w- c:\documents and settings\Petr Vácha\Local Settings\Data aplikací\cae38cb6
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 14:42 . 2006-03-02 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-09-09 09:12 . 2006-03-02 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-08 09:07 . 2011-05-26 06:55 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-30 12:00 . 2011-08-30 12:00 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-08-30 12:00 . 2011-08-30 12:00 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-30 11:42 . 2011-08-30 11:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2011-08-30 11:41 . 2011-08-30 11:41 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-08-30 11:41 . 2011-08-30 11:41 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-08-30 11:41 . 2011-08-30 11:41 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-08-22 5148672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"nwiz"="nwiz.exe" [2008-09-17 1657376]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2011-09-07 2048352]
"HP CP1020 System Tray"="c:\program files\HP\HP LaserJet Professional CP1020 Series\HPCP1020STRAY.EXE" [2010-05-12 2627384]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
c:\documents and settings\Petr Vácha\Nabídka Start\Programy\Po spuštění\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
_uninst_.lnk - c:\documents and settings\Petr Vácha\Local Settings\temp\_uninst_.bat [N/A]
_uninst_04303634.lnk - c:\documents and settings\Petr Vácha\Local Settings\temp\_uninst_04303634.bat [N/A]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-12 581693]
ColorVisionStartup.lnk - c:\program files\ColorVision\Utility\ColorVisionStartup.exe [2006-1-31 385024]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2011-08-30 11:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Java\\Java Update\\jucheck.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 7\\PCSuite.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\WinSCP\\WinSCP.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\Documents and Settings\\Petr Vácha\\Dokumenty\\Stažené soubory\\RSIT.exe"=
"c:\\Program Files\\STORMWARE\\POHODA\\StwUpdater.exe"=
"c:\\Program Files\\STORMWARE\\POHODA\\StwPh.exe"=
.
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 HP LaserJet Service;HP LaserJet Service;"c:\program files\HP\HPLaserJetService\HPLaserJetService.exe" --> c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15.8.2008 6:46 284016]
S3 FLASHSYS;FLASHSYS;c:\program files\MSI\Live Update 4\LU4\FlashSys.sys [1.12.2009 14:10 9216]
S3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [7.9.2011 9:58 20792]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [3.4.2010 20:56 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [3.4.2010 11:02 240608]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [3.4.2010 20:56 367456]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: Interfaces\{9F197DCB-A24E-4E1B-8E00-E01343FDCF9F}: NameServer = 10.0.0.138
FF - ProfilePath - c:\documents and settings\Petr Vácha\Data aplikací\Mozilla\Firefox\Profiles\oolt324t.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.dobrysluha.cz
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: 602XML Filler:
xmlfiller@software602.cz - c:\program files\Mozilla Firefox\extensions\
xmlfiller@software602.cz
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: PC Sync 2 Synchronisation Extension:
bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: Firebug:
firebug@software.joehewitt.com - %profile%\extensions\
firebug@software.joehewitt.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-10-10 12:25
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(116)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2011-10-10 12:28:37 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-10 10:28
ComboFix2.txt 2011-10-10 07:41
ComboFix3.txt 2011-10-05 08:14
ComboFix4.txt 2011-10-04 13:52
ComboFix5.txt 2011-10-10 10:17
.
Před spuštěním: Volných bajtů: 86 850 453 504
Po spuštění: Volných bajtů: 86 833 500 160
.
- - End Of File - - 90BC9ED7821420238A7252FAF6744C89