Dobrý den,
vše dle mého v počítači funguje a chodí tak jak by mělo.log:
ComboFix 10-03-24.02 - Martin 25.03.2010 10:32:53.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3071.2383 [GMT 1:00]
Spuštěný z: c:\documents and settings\Martin\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-25 do 2010-03-25 )))))))))))))))))))))))))))))))
.
2010-03-23 15:48 . 2010-03-23 15:49 -------- d-----w- c:\program files\trend micro
2010-03-23 15:48 . 2010-03-23 15:49 -------- d-----w- C:\rsit
2010-03-16 15:01 . 2008-04-13 23:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-03-16 15:01 . 2008-04-13 23:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-03-16 15:01 . 2008-04-13 23:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-03-16 15:01 . 2008-04-13 23:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-03-16 15:00 . 2008-04-13 23:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-03-13 15:22 . 2010-03-13 15:23 -------- d-----w- c:\program files\Mv2Player
2010-03-10 17:11 . 2010-03-10 17:11 -------- d-----w- c:\documents and settings\LocalService\Dokumenty
2010-03-10 17:10 . 2009-04-14 22:51 96768 ----a-w- c:\windows\system32\htimon.dll
2010-03-10 17:10 . 2010-03-10 17:10 -------- d-----w- c:\program files\Crongreen Software
2010-03-06 16:30 . 2010-03-06 16:30 -------- d-----w- c:\program files\Palm
2010-03-06 00:10 . 2010-03-06 00:12 -------- d-----w- c:\program files\The KMPlayer
2010-02-23 14:04 . 2008-03-09 05:25 236 ---ha-w- c:\program files\Common Files\dx.reg
2010-02-23 14:04 . 2006-11-02 10:46 39936 ----a-w- c:\windows\system32\dwmapi.dll
2010-02-23 14:04 . 2006-11-02 10:46 167936 ----a-w- c:\windows\system32\dxgi.dll
2010-02-23 14:04 . 2006-11-29 12:06 440080 ----a-w- c:\windows\system32\d3dx10.dll
2010-02-23 14:04 . 2006-11-02 10:46 187392 ----a-w- c:\windows\system32\d3d10core.dll
2010-02-23 14:04 . 2006-11-02 10:46 1029120 ----a-w- c:\windows\system32\d3d10.dll
2010-02-23 13:36 . 2010-03-12 17:03 -------- d-----w- c:\documents and settings\Martin\Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-24 13:10 . 2010-02-22 16:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-23 15:35 . 2009-10-29 15:05 -------- d-----w- c:\program files\Spyware Terminator
2010-03-16 19:35 . 2009-11-30 15:15 -------- d-----w- c:\program files\Vuze
2010-03-12 14:58 . 2009-10-29 15:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-09 11:24 . 2009-10-29 15:03 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-09 11:12 . 2009-10-29 15:03 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-09 11:12 . 2009-10-29 15:03 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-09 11:09 . 2009-10-29 15:03 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-09 11:08 . 2009-10-29 15:03 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-09 11:08 . 2009-10-29 15:03 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-09 11:08 . 2009-10-29 15:03 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-09 11:08 . 2009-10-29 15:03 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-23 17:18 . 2009-10-29 15:25 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-22 04:42 . 2010-02-21 21:41 138464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-22 04:41 . 2010-02-21 21:41 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-22 04:37 . 2010-02-21 21:41 682280 ----a-w- c:\windows\system32\pbsvc.exe
2010-02-21 21:41 . 2010-02-21 21:41 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-02-21 20:55 . 2010-02-21 20:27 52273 ----a-w- c:\windows\War3Unin.dat
2010-02-21 20:55 . 2010-02-21 20:27 2829 ----a-w- c:\windows\War3Unin.pif
2010-02-21 20:55 . 2010-02-21 20:27 139264 ----a-w- c:\windows\War3Unin.exe
2010-02-19 12:46 . 2009-11-27 16:31 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-16 19:47 . 2010-02-16 19:27 -------- d-----w- c:\program files\zFTPServer Administration
2010-02-16 19:27 . 2010-02-16 19:27 -------- d-----w- c:\program files\zFTPServer
2010-02-13 11:42 . 2010-02-13 11:42 -------- d-----w- c:\program files\Alwil Software
2010-02-11 18:53 . 2009-10-29 15:03 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-03 19:19 . 2010-02-03 19:19 -------- d-----w- c:\program files\Windows Media Connect 2
2010-02-01 20:27 . 2009-11-09 14:42 -------- d-----w- c:\program files\CDBurnerXP
2010-01-25 21:06 . 2009-10-29 15:24 -------- d-----w- c:\program files\Opera
2010-01-22 16:17 . 2006-03-02 12:00 484044 ----a-w- c:\windows\system32\perfh005.dat
2010-01-22 16:17 . 2006-03-02 12:00 100464 ----a-w- c:\windows\system32\perfc005.dat
2010-01-19 15:50 . 2010-01-19 15:44 73728 ----a-w- c:\windows\ST6UNST.EXE
2010-01-19 15:50 . 2010-01-19 15:44 253952 ------w- c:\windows\Setup1.exe
2010-01-07 15:07 . 2010-02-22 16:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2010-02-22 16:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 21:03 . 2010-01-02 21:03 1641107 ----a-w- c:\windows\WANEUninstaller.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-29 39408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Steam"="e:\steam\steam.exe" [2010-02-20 1217872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-02-17 33595392]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ASUS Update Checker"="c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe" [2008-12-11 114688]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-10-29 1809408]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"zFTPServer"="c:\program files\zFTPServer\zFTPServer.exe" [2008-05-03 3037696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Martin\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]
zFTPServer Administration.lnk - c:\program files\zFTPServer Administration\zFTPServerAdmin.exe [2010-2-16 4570112]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"e:\\Program Files\\X-Men Origins - Wolverine(TM)\\Binaries\\Wolverine.exe"=
"e:\\Program Files\\Damnation\\Binaries\\DamnGame.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"d:\\Program Files\\Modern Warfare 2\\iw4mp.exe"=
"e:\\Program Files\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"d:\\Image\\cs1,6\\hl.exe"=
"d:\\Image\\flatout\\FlatOut2.exe"=
"e:\\Program Files\\DiRT2\\dirt2_game.exe"=
"e:\\Program Files\\NBA 2K10\\nba2k10.exe"=
"d:\\Image\\CS-NS\\CS-NS\\Valve\\hl.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"e:\\steam\\Steam.exe"=
"e:\\Program FilesSTREETFIGHTERIV\\StreetFighterIV.exe"=
"e:\\Program Files@Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"e:\\steam\\steamapps\\mastertegy\\counter-strike\\hl.exe"=
"e:\\UT2004\\System\\UT2004.exe"=
"e:\\Program Files\\Warmonger\\Binaries\\WMGame.exe"=
"c:\\Program Files\\zFTPServer\\zFTPServer.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"e:\\Program Files\\Warcraft III\\War3.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"e:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"e:\\Program Files\\Age of Empires III\\age3y.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\Age of Empires III\\age3x.exe"=
"e:\\Program Files\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [29.10.2009 16:03 162640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [29.10.2009 16:05 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29.10.2009 16:03 19024]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.10.2009 17:33 222968]
R3 ip100xp;TP-LINK TF-3200 10/100 Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [19.2.2010 17:27 26752]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [29.10.2009 16:12 1057024]
S3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\DRIVERS\MOSUMAC.SYS --> c:\windows\system32\DRIVERS\MOSUMAC.SYS [?]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
TCP: {3EF81F71-7646-4F8E-A728-1A25AB063478} = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\wojkvvsj.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-25 10:36
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(180)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-25 10:37:08
ComboFix-quarantined-files.txt 2010-03-25 09:37
ComboFix2.txt 2010-03-24 11:09
ComboFix3.txt 2009-10-29 17:26
Před spuštěním: 2 695 434 240
Po spuštění: 2 659 913 728
- - End Of File - - C55B272451AEB4A342D1DE9EDDE090EF