tak jsem to udělal a pořád je to tam a píše, že soubor nejde vymazat - nejdříve se ptá, jestli chci vymazat systémový soubor a pak - protože ho nelze nalézt
ComboFix 13-05-16.02 - jozka 17.05.2013 8:38.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2038.1377 [GMT 2:00]
Spuštěný z: c:\documents and settings\jozka\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\data
c:\documents and settings\jozka\WINDOWS
c:\program files\xp-AntiSpy
c:\program files\xp-AntiSpy\Uninstall.exe
c:\program files\xp-AntiSpy\xp-AntiSpy.exe
c:\program files\xp-AntiSpy\xp-AntiSpy.chm
c:\program files\xp-AntiSpy\xp-AntiSpy.url
c:\windows\msmqinst.log
c:\windows\system32\pthreadVC.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-04-17 do 2013-05-17 )))))))))))))))))))))))))))))))
.
.
2013-04-24 19:54 . 2013-04-24 19:54 -------- d-----w- c:\program files\Common Files\Skype
2013-04-24 19:47 . 2013-04-24 19:47 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\IObit
2013-04-24 19:16 . 2013-04-24 19:16 -------- d-----w- c:\documents and settings\jozka\Data aplikací\AidemMedia
2013-04-24 19:13 . 2013-04-24 19:13 -------- d-----w- c:\program files\AidemMedia
2013-04-24 18:44 . 2013-01-15 16:49 23360 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-04-24 18:21 . 2013-04-24 18:21 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\Application Updater
2013-04-24 18:20 . 2013-05-01 15:42 -------- d-----w- c:\program files\Common Files\Spigot
2013-04-24 18:19 . 2013-04-24 18:19 -------- d-----w- c:\documents and settings\jozka\AppData
2013-04-24 18:17 . 2013-04-24 18:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-04-24 18:17 . 2013-04-24 18:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\IObit
2013-04-24 18:17 . 2013-04-24 18:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{BDDB56DE-AE4E-48A2-B856-FB60C8498453}
2013-04-24 18:17 . 2013-05-01 15:19 -------- d-----w- c:\documents and settings\jozka\Data aplikací\IObit
2013-04-24 18:16 . 2013-04-24 18:16 -------- d-----w- c:\program files\IObit
2013-04-23 11:59 . 2013-04-23 11:59 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Foxit Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-02 15:28 . 2010-12-08 17:25 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-29 05:48 . 2012-03-30 08:15 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-29 05:48 . 2011-05-14 17:56 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2006-03-24 20:31 . 2011-10-23 07:22 5083136 ----a-w- c:\program files\mplayerc.exe
2013-04-25 17:55 . 2013-04-25 17:54 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2013-05-04 802136]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE" [2013-02-18 774168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2007-08-21 217088]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-09-24 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-24 8478720]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-05-16 19:50 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0auto_reactivate \\?\Volume{2989FBC3-02C0-11E0-BAEE-806D6172696F}\bootwiz\asrm.bin
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\realsched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect]
2009-09-18 16:48 2412032 ----a-w- c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UxTuneUp"=2 (0x2)
"afcdpsrv"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
"Google Update"="c:\documents and settings\jozka\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
"Zoner Photo Studio Autoupdate"=c:\program files\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Persistence"=c:\windows\system32\igfxpers.exe
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe"
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe"
"IFXSPMGT"=c:\windows\system32\ifxspmgt.exe /NotifyLogon
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe"
"ISBMgr.exe"=c:\program files\Sony\ISB Utility\ISBMgr.exe
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"SAOB Monitor"=c:\program files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
"Služba Acronis Scheduler2"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe"
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe"
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"g:\\program\\OperaPortable\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"g:\\program\\skypeport\\Portable Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2.1.2011 17:47 691696]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [18.12.2010 20:31 752128]
R1 MpKsl490c02f9;MpKsl490c02f9;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E99F9390-D7D0-4655-B781-A6B1B61F2AE7}\MpKsl490c02f9.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E99F9390-D7D0-4655-B781-A6B1B61F2AE7}\MpKsl490c02f9.sys [?]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [24.9.2007 18:07 38816]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [15.9.2009 11:51 19200]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
R2 afcdpsrv;Služba Acronis Nonstop Backup;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [18.12.2010 20:31 3246040]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [5.4.2012 20:41 348160]
R2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [5.4.2012 20:41 403456]
R2 GtFlashSwitch;GtFlashSwitch;c:\program files\Common Files\GtFlashSwitch\GtFlashSwitch.exe [9.2.2007 15:48 176128]
R2 Správce výběru OS;Aktivátor Správce výběru OS Acronis;c:\program files\Acronis\DiskDirector\OSS\reinstall_svc.exe [7.7.2010 17:17 2156952]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [18.9.2009 18:48 9216]
R3 5U870UVC;Sony Visual Communication Camera VGP-VCC7;c:\windows\system32\drivers\5U870UVCx86.sys [8.12.2010 13:43 70144]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [18.12.2010 20:31 167968]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8.12.2010 14:01 41216]
R3 SPI;Programovatelné zařízení Sony pro ovládání V/V ;c:\windows\system32\drivers\SonyPI.sys [8.12.2010 13:54 37040]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [8.12.2010 13:43 812544]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [28.2.2013 18:45 161384]
S3 AVerAF35;AVerMedia A867 USB DVB-T;c:\windows\system32\drivers\AVerAF35.sys [5.4.2012 20:21 768896]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [11.12.2010 11:34 112640]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [11.12.2010 11:34 24448]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [11.12.2010 11:34 100736]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [22.12.2011 13:28 100480]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [16.1.2013 20:45 27064]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL490C02F9
.
Obsah adresáře 'Naplánované úlohy'
.
2013-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 05:48]
.
2013-04-05 c:\windows\Tasks\Automatická údržba.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 12:49]
.
2013-05-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-861567501-1957994488-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-06-21 10:00]
.
2013-05-16 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-861567501-1957994488-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-06-21 10:00]
.
2013-05-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-10-02 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.cz/ig#home
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: LastPass - file://c:\documents and settings\jozka\Local Settings\Data aplikací\LastPass\context.html?cmd=lastpass
IE: LastPass vyplňování formulářů - file://c:\documents and settings\jozka\Local Settings\Data aplikací\LastPass\context.html?cmd=fillforms
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\documents and settings\jozka\Data aplikací\Mozilla\Firefox\Profiles\v085alzz.default-1367337267250\
FF - prefs.js: browser.startup.homepage - hxxp://
www.gastrocentrum-pisek.cz/produkt-6500 ... -pojizdna/
FF - ExtSQL: 2013-04-30 19:05; {3d7eb24f-2740-49df-8937-200b1cc08f8a}; c:\documents and settings\jozka\Data aplikacĂÂ\Mozilla\Firefox\Profiles\v085alzz.default-1367337267250\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF - ExtSQL: 2019-09-25 23:40; {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}; c:\documents and settings\jozka\Data aplikacĂÂ\Mozilla\Firefox\Profiles\v085alzz.default-1367337267250\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-xp-AntiSpy - c:\program files\xp-AntiSpy\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-05-17 08:42
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1032)
c:\windows\system32\VESWinlogon.dll
c:\windows\system32\igfxdev.dll
.
Celkový čas: 2013-05-17 08:43:54
ComboFix-quarantined-files.txt 2013-05-17 06:43
.
Před spuštěním: 8 495 058 944
Po spuštění: 8 557 051 904
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
;timeout=3
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - C617CD18E49ABE38484F241823B242EC