log je zde, ještě jdu na ten virus total.
ComboFix 10-08-03.01 - Honza 14.08.2010 1:30.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2814.1623 [GMT 2:00]
Spuštěný z: c:\users\Honza\Videos\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Honza\Videos\Desktop\CFScript.txt.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
- REŽIM S OMEZENOU FUNKČNOSTÍ -
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\SweetIM
c:\program files\SweetIM\Messenger\default.xml
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\program files\SweetIM\Messenger\mgAIMAuto.dll
c:\program files\SweetIM\Messenger\mgAIMMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgArchive.dll
c:\program files\SweetIM\Messenger\mgcommon.dll
c:\program files\SweetIM\Messenger\mgcommunication.dll
c:\program files\SweetIM\Messenger\mgconfig.dll
c:\program files\SweetIM\Messenger\mgFlashPlayer.dll
c:\program files\SweetIM\Messenger\mghooking.dll
c:\program files\SweetIM\Messenger\mgICQAuto.dll
c:\program files\SweetIM\Messenger\mgICQMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgIEPlayer.dll
c:\program files\SweetIM\Messenger\mglogger.dll
c:\program files\SweetIM\Messenger\mgMediaPlayer.dll
c:\program files\SweetIM\Messenger\mgMsnAuto.dll
c:\program files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgsimcommon.dll
c:\program files\SweetIM\Messenger\mgSweetIM.dll
c:\program files\SweetIM\Messenger\mgUpdateSupport.dll
c:\program files\SweetIM\Messenger\mgxml_wrapper.dll
c:\program files\SweetIM\Messenger\mgYahooAuto.dll
c:\program files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
c:\program files\SweetIM\Messenger\msvcp71.dll
c:\program files\SweetIM\Messenger\msvcr71.dll
c:\program files\SweetIM\Messenger\resources\images\AudibleButton.png
c:\program files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
c:\program files\SweetIM\Messenger\resources\images\EmoticonButton.png
c:\program files\SweetIM\Messenger\resources\images\GamesButton.png
c:\program files\SweetIM\Messenger\resources\images\KeyboardButton.png
c:\program files\SweetIM\Messenger\resources\images\NudgeButton.png
c:\program files\SweetIM\Messenger\resources\images\SoundFxButton.png
c:\program files\SweetIM\Messenger\resources\images\WinksButton.png
c:\program files\SweetIM\Messenger\SweetIM.exe
c:\programdata\SweetIM
c:\programdata\SweetIM\Messenger\conf\adapter.xml
c:\programdata\SweetIM\Messenger\conf\autoupdate.xml
c:\programdata\SweetIM\Messenger\conf\logger.xml
c:\programdata\SweetIM\Messenger\conf\messages.xml
c:\programdata\SweetIM\Messenger\conf\sweetim.xml
c:\programdata\SweetIM\Messenger\conf\sweetimapp.xml
c:\programdata\SweetIM\Messenger\conf\users\611006066\content_update_notification.xml
c:\programdata\SweetIM\Messenger\conf\users\611006066\emoticons_shortcut.xml
c:\programdata\SweetIM\Messenger\conf\users\611006066\lastuse_Audibles.xml
c:\programdata\SweetIM\Messenger\conf\users\611006066\lastuse_Emoticons.xml
c:\programdata\SweetIM\Messenger\conf\users\611006066\lastuse_SpecialFX.xml
c:\programdata\SweetIM\Messenger\conf\users\611006066\user_config.xml
c:\programdata\SweetIM\Messenger\conf\users\main_user_config.xml
c:\programdata\SweetIM\Messenger\data\contentdb\00000002.dat
c:\programdata\SweetIM\Messenger\data\contentdb\00010896.dat
c:\programdata\SweetIM\Messenger\data\contentdb\00010952.dat
c:\programdata\SweetIM\Messenger\data\contentdb\0002032E.dat
c:\programdata\SweetIM\Messenger\data\contentdb\000203F6.dat
c:\programdata\SweetIM\Messenger\data\contentdb\00020466.dat
c:\programdata\SweetIM\Messenger\data\contentdb\0002053B.dat
c:\programdata\SweetIM\Messenger\data\contentdb\000300D9.dat
c:\programdata\SweetIM\Messenger\data\contentdb\00030102.dat
c:\programdata\SweetIM\Messenger\data\contentdb\00080063.dat
c:\programdata\SweetIM\Messenger\data\contentdb\000800EC.dat
c:\programdata\SweetIM\Messenger\data\contentdb\cache_indx.dat
c:\users\Honza\AppData\Local\Temp\7ABE.tmp
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-07-13 do 2010-08-13 )))))))))))))))))))))))))))))))
.
2010-08-13 23:33 . 2010-08-13 23:36 -------- d-----w- c:\users\Honza\AppData\Local\temp
2010-08-13 23:33 . 2010-08-13 23:33 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-13 23:33 . 2010-08-13 23:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-13 14:43 . 2010-08-13 14:43 2915944 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2010-08-13 14:43 . 2010-08-13 14:43 304528 ----a-w- c:\windows\system32\appdrvrem01.exe
2010-08-13 12:22 . 2010-08-13 12:30 -------- d-----w- c:\program files\Just Cause
2010-08-11 04:45 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-08-11 04:44 . 2010-06-08 17:35 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-11 04:44 . 2010-06-08 17:35 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-11 04:44 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-08-11 04:44 . 2010-06-18 15:04 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-11 04:44 . 2010-06-18 15:04 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-11 04:44 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-11 00:55 . 2010-08-11 00:55 -------- d-----w- c:\users\Honza\AppData\Roaming\Malwarebytes
2010-08-11 00:55 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-11 00:55 . 2010-08-11 00:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-11 00:55 . 2010-08-11 00:55 -------- d-----w- c:\programdata\Malwarebytes
2010-08-11 00:55 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-09 19:36 . 2010-08-09 19:36 -------- d--h--r- c:\users\Honza\AppData\Roaming\SecuROM
2010-08-09 19:34 . 2010-08-09 19:35 -------- d-----w- c:\programdata\Electronic Arts
2010-08-09 19:34 . 2010-08-09 19:34 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-09 19:33 . 2010-08-09 19:33 -------- d-----w- c:\users\Honza\AppData\Local\Adobe
2010-08-09 18:49 . 2010-08-09 18:49 -------- d-----w- c:\program files\Electronic Arts
2010-08-09 18:49 . 2010-08-09 18:49 2030 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2010-07-27 00:00 . 2010-07-27 00:01 -------- d-----w- c:\program files\trend micro
2010-07-27 00:00 . 2010-07-27 00:01 -------- d-----w- C:\rsit
2010-07-23 01:33 . 2010-07-23 01:33 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-23 01:07 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-07-23 01:07 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-07-22 01:46 . 2010-07-22 01:46 603904 ----a-w- c:\windows\system32\TUProgSt.exe
2010-07-22 01:46 . 2010-07-22 01:46 -------- d-----w- c:\users\Honza\AppData\Roaming\TuneUp Software
2010-07-22 01:45 . 2010-07-22 01:45 -------- d-----w- c:\programdata\TuneUp Software
2010-07-22 01:45 . 2010-07-22 01:45 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2010-07-22 01:36 . 2010-07-22 01:36 -------- d-----w- c:\program files\The KMPlayer
2010-07-21 01:53 . 2010-07-21 01:53 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-07-21 01:44 . 2010-07-21 01:44 -------- d-----w- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-13 23:38 . 2010-06-22 18:44 -------- d-----w- c:\users\Honza\AppData\Roaming\Skype
2010-08-13 23:37 . 2010-06-22 18:46 -------- d-----w- c:\users\Honza\AppData\Roaming\skypePM
2010-08-13 23:35 . 2009-02-14 20:56 48175 ----a-w- c:\programdata\nvModes.dat
2010-08-13 19:02 . 2008-01-21 06:46 598832 ----a-w- c:\windows\system32\perfh005.dat
2010-08-13 19:02 . 2008-01-21 06:46 114992 ----a-w- c:\windows\system32\perfc005.dat
2010-08-12 01:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-11 02:46 . 2009-01-31 14:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-11 02:44 . 2009-03-30 04:25 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-09 19:33 . 2010-08-09 19:34 53632 ----a-w- c:\users\Honza\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-08-09 19:33 . 2010-08-09 19:34 53632 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-08-09 18:48 . 2010-08-09 18:48 -------- d-----w- c:\users\Honza\AppData\Roaming\Leadertech
2010-07-23 01:07 . 2010-07-23 01:06 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-07-23 01:06 . 2010-07-22 02:03 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-07-22 01:38 . 2010-07-03 12:48 -------- d-----w- c:\users\Honza\AppData\Roaming\BSplayer
2010-07-22 01:38 . 2010-07-03 12:48 -------- d-----w- c:\program files\Webteh
2010-07-21 01:58 . 2010-06-22 18:43 -------- d-----r- c:\program files\Skype
2010-07-13 08:57 . 2009-04-30 18:04 -------- d-----w- c:\program files\Bethesda Softworks
2010-07-06 23:44 . 2009-01-31 13:30 1356 ----a-w- c:\users\Honza\AppData\Local\d3d9caps.dat
2010-07-03 12:48 . 2010-07-03 12:48 -------- d-----w- c:\users\Honza\AppData\Roaming\BSplayer Pro
2010-06-29 18:59 . 2010-06-29 18:59 -------- d-----w- c:\programdata\ICQ
2010-06-26 13:01 . 2010-06-26 13:01 -------- d-----w- c:\program files\Windows Portable Devices
2010-06-26 13:01 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-06-26 12:49 . 2010-06-26 12:49 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-06-26 12:48 . 2010-06-26 12:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-06-26 07:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-06-26 07:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-06-26 07:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-06-26 07:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-06-26 07:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-06-26 07:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-06-26 07:16 . 2009-02-14 20:56 -------- d-----w- c:\programdata\NVIDIA
2010-06-26 06:05 . 2010-08-11 04:46 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-11 04:46 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 06:02 . 2010-08-11 04:46 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 04:25 . 2010-08-11 04:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-23 14:55 . 2009-01-31 13:30 49168 ----a-w- c:\users\Honza\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-22 19:52 . 2010-06-22 19:52 2605008 ----a-w- c:\users\Honza\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-06-22 18:46 . 2010-06-22 18:46 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-06-22 18:44 . 2010-06-22 18:44 -------- d-----w- c:\program files\Google
2010-06-22 18:43 . 2010-06-22 18:43 -------- d-----w- c:\program files\Common Files\Skype
2010-06-22 18:43 . 2010-06-22 18:43 -------- d-----w- c:\programdata\Skype
2010-06-22 09:34 . 2010-06-22 09:34 -------- d-----w- c:\users\Honza\AppData\Roaming\Telefónica Móviles
2010-06-22 09:32 . 2010-06-22 09:32 -------- d-----w- c:\program files\O2
2010-06-21 13:37 . 2010-08-11 04:46 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-06-11 16:16 . 2010-08-11 04:46 274944 ----a-w- c:\windows\system32\schannel.dll
2010-06-01 17:37 . 2009-11-07 23:55 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-27 20:08 . 2010-08-11 04:46 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06 . 2010-06-22 09:52 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-22 09:52 289792 ----a-w- c:\windows\system32\atmfd.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"CollaborationHost"="c:\windows\system32\p2phost.exe" [2008-01-21 192000]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):9e,04,fd,eb,01,15,cb,01
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 101120]
R3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
R3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
R3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2010-08-13 2915944]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 23424]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-12-22 51232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-14 01:36
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-2291515259-1860780186-4230215190-1000\Software\SecuROM\License information*]
"datasecu"=hex:b8,ac,c1,24,bb,f0,c3,91,64,62,a1,0a,58,35,18,bd,c9,6d,5c,12,57,
26,fa,d9,54,87,f7,4e,d1,56,d2,c7,48,29,0d,e6,e9,2d,5d,a7,a6,12,0b,bc,40,c7,\
"rkeysecu"=hex:22,60,c7,9f,9d,02,e4,7b,b2,08,46,41,dd,4d,64,5a
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-08-14 01:43:13 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-08-13 23:43
ComboFix2.txt 2010-08-03 23:53
ComboFix3.txt 2010-07-22 23:08
Před spuštěním: Volných bajtů: 233 003 708 416
Po spuštění: Volných bajtů: 232 995 577 856
- - End Of File - - 6209D68AFD2F89794541495DDEDE273C