je to tu :
ComboFix 12-02-01.01 - Administrator . 02. 2012 20:12:09.2.1 - FAT32x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.502.293 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator.ACERTM2480\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator.ACERTM2480\Plocha\CFScript.txt.txt
.
FILE ::
"c:\documents and settings\palo talpas\Nabídka Start\Programy\Po spuštění\_uninst_08825654.lnk"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\FOUND.000
c:\found.000\FILE0000.CHK
c:\found.000\FILE0001.CHK
c:\found.000\FILE0002.CHK
c:\found.000\FILE0003.CHK
c:\found.000\FILE0004.CHK
c:\found.000\FILE0005.CHK
c:\found.000\FILE0006.CHK
c:\found.000\FILE0007.CHK
c:\found.000\FILE0008.CHK
c:\found.000\FILE0009.CHK
c:\found.000\FILE0010.CHK
c:\found.000\FILE0011.CHK
c:\found.000\FILE0012.CHK
c:\found.000\FILE0013.CHK
C:\FOUND.001
c:\found.001\FILE0000.CHK
c:\found.001\FILE0001.CHK
c:\found.001\FILE0002.CHK
c:\found.001\FILE0003.CHK
c:\found.001\FILE0004.CHK
c:\found.001\FILE0005.CHK
c:\found.001\FILE0006.CHK
c:\found.001\FILE0007.CHK
c:\found.001\FILE0008.CHK
c:\found.001\FILE0009.CHK
c:\found.001\FILE0010.CHK
c:\found.001\FILE0011.CHK
c:\found.001\FILE0012.CHK
c:\found.001\FILE0013.CHK
c:\found.001\FILE0014.CHK
c:\found.001\FILE0015.CHK
c:\found.001\FILE0016.CHK
c:\found.001\FILE0017.CHK
c:\found.001\FILE0018.CHK
c:\found.001\FILE0019.CHK
c:\found.001\FILE0020.CHK
c:\found.001\FILE0021.CHK
c:\found.001\FILE0022.CHK
c:\found.001\FILE0023.CHK
c:\found.001\FILE0024.CHK
c:\found.001\FILE0025.CHK
c:\found.001\FILE0026.CHK
c:\found.001\FILE0027.CHK
c:\found.001\FILE0028.CHK
c:\found.001\FILE0029.CHK
c:\found.001\FILE0030.CHK
c:\found.001\FILE0031.CHK
c:\found.001\FILE0032.CHK
c:\found.001\FILE0033.CHK
c:\found.001\FILE0034.CHK
c:\found.001\FILE0035.CHK
c:\found.001\FILE0036.CHK
c:\found.001\FILE0037.CHK
c:\found.001\FILE0038.CHK
c:\found.001\FILE0039.CHK
c:\found.001\FILE0040.CHK
c:\found.001\FILE0041.CHK
c:\found.001\FILE0042.CHK
c:\found.001\FILE0043.CHK
c:\found.001\FILE0044.CHK
c:\found.001\FILE0045.CHK
c:\found.001\FILE0046.CHK
c:\found.001\FILE0047.CHK
c:\found.001\FILE0048.CHK
c:\found.001\FILE0049.CHK
c:\found.001\FILE0050.CHK
c:\found.001\FILE0051.CHK
c:\found.001\FILE0052.CHK
c:\found.001\FILE0053.CHK
c:\found.001\FILE0054.CHK
c:\found.001\FILE0055.CHK
c:\found.001\FILE0056.CHK
c:\found.001\FILE0057.CHK
c:\found.001\FILE0058.CHK
c:\found.001\FILE0059.CHK
c:\found.001\FILE0060.CHK
c:\found.001\FILE0061.CHK
c:\found.001\FILE0062.CHK
c:\found.001\FILE0063.CHK
c:\found.001\FILE0064.CHK
c:\found.001\FILE0065.CHK
c:\windows\WindowsUpdate.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_08825654
-------\Legacy_GUPDATE
-------\Legacy_GUPDATEM
-------\Service_08825654
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-01 do 2012-02-01 )))))))))))))))))))))))))))))))
.
.
2012-02-01 14:26 . 2008-04-14 04:22 50176 ----a-w- c:\windows\system32\proquota.exe
2012-02-01 13:55 . 2012-02-01 13:55 -------- d-----w- C:\beruska.com
2012-02-01 09:58 . 2012-02-01 19:28 133208 ----a-w- c:\windows\system32\drivers\08825654.sys
2012-02-01 09:26 . 2012-02-01 09:49 117563736 ----a-w- C:\setup_11.0.0.1245.x01_2012_02_01_12_48.exe
2012-01-31 18:57 . 2012-01-31 18:57 -------- d-----w- c:\documents and settings\palo talpas\Data aplikací\Malwarebytes
2012-01-31 18:56 . 2012-01-31 18:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-01-31 18:56 . 2012-01-31 18:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-31 18:56 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-31 18:51 . 2012-01-31 18:55 9502424 ----a-w- C:\mbam--setup-1.60.1.1000.exe
2012-01-31 16:06 . 2012-01-31 16:06 -------- d-----w- c:\documents and settings\Administrator
2012-01-31 13:12 . 2012-01-31 13:12 2059056 ----a-w- C:\tdsskiller.exe
2012-01-31 08:47 . 2012-01-31 08:47 -------- d-----w- c:\program files\ESET
2012-01-31 08:47 . 2012-01-31 08:47 2322184 ----a-w- C:\esetsmartinstaller_sky.exe
2012-01-24 18:44 . 2012-01-24 18:44 -------- d-----w- C:\rsit
2012-01-13 16:10 . 2012-01-13 16:10 -------- d-----w- c:\program files\trend micro
2012-01-06 18:39 . 2012-01-06 18:39 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-06 18:39 . 2012-01-06 18:39 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-06 18:39 . 2012-01-06 18:39 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-06 18:39 . 2012-01-06 18:39 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-25 21:57 . 2004-08-18 19:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2004-08-18 19:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2004-08-18 19:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-18 09:39 . 2011-11-18 09:39 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-16 14:21 . 2004-08-18 19:00 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2004-08-18 19:00 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-04 19:13 . 2006-01-09 19:08 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2004-08-18 19:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:13 . 2004-08-18 19:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:24 . 2004-08-18 19:00 385024 ----a-w- c:\windows\system32\html.iec
2012-01-06 18:39 . 2011-09-30 12:13 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\system32 ----
.
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-13 88204]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-19 16248320]
"SkyTel"="SkyTel.EXE" [2006-07-19 2879488]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-29 766041]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2006-05-15 45056]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-18 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-18 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-03-17 345088]
"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-06-07 208896]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-13 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-13 118784]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-07-12 438272]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2006-07-14 471040]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
.
c:\documents and settings\palo talpas\Nabídka Start\Programy\Po spuštění\
_uninst_08825654.lnk - c:\documents and settings\palo talpas\Local Settings\Temp\_uninst_08825654.bat [N/A]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2006-6-29 45056]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-1-17 618557]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
Rychlý začátek s aplikací HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqdirec.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqthb08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Product Assistant\\BIN\\hprbui.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\HPQDocViewer.exe"=
"c:\\Program Files\\Common Files\\NewTech Infosystems\\LiveUpdate\\LiveUpdate.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Acer\\Empowering Technology\\Acer.Empowering.Framework.Launcher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
.
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [31. 1. 2012 19:56 652360]
S3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [19. 6. 2006 12:20 1097728]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [31. 1. 2012 19:56 20464]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-01 17:21]
.
2012-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-01 17:21]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Administrator.ACERTM2480\Data aplikací\Mozilla\Firefox\Profiles\3barn7ty.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-02-01 20:33
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2012-02-01 20:38:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-02-01 19:38
ComboFix2.txt 2012-02-01 14:57
.
Před spuštěním: Volných bajtů: 36 183 375 872
Po spuštění: Volných bajtů: 36 179 705 856
.
- - End Of File - - FDDCE8A36DBC45A15D5ED088BF4A5BE9