snad se v tom vyznáte....:
ComboFix 09-08-04.03 - Administrator 05.08.2009 21:13.1.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.305 [GMT 2:00]
Spuštěný z: c:\docs\Administrator\Plocha\ComboFix.exe
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-07-05 do 2009-08-05 )))))))))))))))))))))))))))))))
.
V tomto časovém úseku nebyly vytvořeny žádné nové soubory.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-05 16:22 . 2009-08-05 16:22 0 ----a-w- c:\windows\nsreg.dat
2009-08-05 15:47 . 2009-08-05 15:21 158010 ----a-w- c:\windows\hpoins14.dat
2009-08-05 15:43 . 2009-08-05 15:38 -------- d-----w- c:\progs\HP
2009-08-05 15:41 . 2009-08-05 15:41 -------- d-----w- c:\progs\Common Files\HP
2009-08-05 15:40 . 2009-08-05 15:40 -------- d-----w- c:\progs\Hewlett-Packard
2009-08-05 15:40 . 2009-08-05 15:40 -------- d-----w- c:\progs\Common Files\Hewlett-Packard
2009-08-05 15:33 . 2009-08-05 15:29 -------- d-----w- c:\progs\ICQ6.5
2009-08-05 15:30 . 2009-08-05 15:00 -------- d-----w- c:\progs\ICQ6
2009-08-05 15:20 . 2009-08-05 14:30 -------- d--h--w- c:\progs\InstallShield Installation Information
2009-08-05 15:20 . 2009-08-05 15:18 -------- d-----w- c:\progs\AVerMedia
2009-08-05 15:19 . 2009-08-05 15:18 -------- d-----w- c:\progs\Common Files\AVerMedia
2009-08-05 15:12 . 2009-08-05 14:57 -------- d-----w- c:\progs\totalcmd
2009-08-05 15:07 . 2009-08-05 15:07 -------- d-----w- c:\progs\D-Tools
2009-08-05 15:07 . 2009-08-05 15:07 -------- d-----w- c:\progs\Common Files\Adobe AIR
2009-08-05 15:06 . 2009-08-05 15:06 -------- d-----w- c:\progs\Common Files\Adobe
2009-08-05 15:05 . 2009-08-05 15:05 -------- d-----w- c:\progs\AMP WinOFF
2009-08-05 15:05 . 2009-08-05 15:04 -------- d-----w- c:\progs\Winamp
2009-08-05 15:04 . 2009-08-05 15:04 -------- d-----w- c:\progs\Skype
2009-08-05 15:04 . 2009-08-05 15:04 -------- d-----w- c:\progs\Common Files\Skype
2009-08-05 15:03 . 2009-08-05 15:03 -------- d-----w- c:\progs\Ahead
2009-08-05 15:03 . 2009-08-05 15:03 -------- d-----w- c:\progs\Common Files\Ahead
2009-08-05 14:59 . 2009-08-05 14:59 -------- d-----w- c:\progs\Lavasoft
2009-08-05 14:58 . 2009-08-05 14:58 -------- d-----w- c:\progs\Common Files\ACD Systems
2009-08-05 14:58 . 2009-08-05 14:58 -------- d-----w- c:\progs\ACD Systems
2009-08-05 14:58 . 2009-08-05 14:58 -------- d-----w- c:\progs\Micro DVD Player
2009-08-05 14:57 . 2009-08-05 14:57 -------- d-----w- c:\progs\Codec Pack - All In 1
2009-08-05 14:57 . 2009-08-05 14:57 737280 ----a-w- c:\windows\iun6002.exe
2009-08-05 14:57 . 2009-08-05 14:57 -------- d-----w- c:\progs\BSPlayer
2009-08-05 14:55 . 2009-08-05 14:55 -------- d-----w- c:\progs\ESET
2009-08-05 14:49 . 2009-08-05 14:34 -------- d-----w- c:\progs\ATI Technologies
2009-08-05 14:48 . 2001-10-25 13:00 67094 ----a-w- c:\windows\system32\perfc005.dat
2009-08-05 14:48 . 2001-10-25 13:00 386954 ----a-w- c:\windows\system32\perfh005.dat
2009-08-05 14:45 . 2009-08-05 14:33 -------- d-----w- c:\progs\ATI
2009-08-05 14:34 . 2009-08-05 14:30 -------- d-----w- c:\progs\Common Files\InstallShield
2009-08-05 14:30 . 2009-08-05 14:30 -------- d-----w- c:\progs\Realtek Sound Manager
2009-08-05 14:30 . 2009-08-05 14:30 -------- d-----w- c:\progs\AvRack
2009-08-05 14:30 . 2009-08-05 14:30 -------- d-----w- c:\progs\Realtek AC97
2009-08-05 14:30 . 2009-08-05 14:26 -------- d-----w- c:\progs\ovladac_zakl_deska
2009-08-05 14:29 . 2009-08-05 14:29 -------- d-----w- c:\progs\VIALAN
2009-08-05 14:21 . 2009-08-05 14:21 8738 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-08-05 14:21 . 2009-08-05 14:21 2112 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-08-05 14:21 . 2009-08-05 14:21 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-05 14:19 . 2009-08-05 14:19 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-14 13:49 . 2009-05-14 13:49 94360 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2009-05-14 13:47 . 2009-05-14 13:47 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-05-14 13:41 . 2009-05-14 13:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
.
------- Sigcheck -------
[-] 2006-02-23 08:34 359040 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\progs\Skype\Phone\Skype.exe" [2006-12-11 25343016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\progs\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"egui"="c:\progs\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"Ad-Watch"="c:\progs\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="c:\progs\Winamp\winampa.exe" [2006-06-21 35328]
"Adobe Reader Speed Launcher"="c:\progs\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"DAEMON Tools-1033"="c:\progs\D-Tools\daemon.exe" [2004-08-22 81920]
"HP Software Update"="c:\progs\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-06-21 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-17 44544]
c:\docs\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AVer HID Receiver.lnk - c:\progs\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2009-8-5 159744]
AVerQuick.lnk - c:\progs\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2009-8-5 663552]
HP Digital Imaging Monitor.lnk - c:\progs\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Microsoft Office.lnk - c:\progs\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoInternetIcon"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\progs\\ICQ6.5\\ICQ.exe"=
"c:\\progs\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5.8.2009 17:00 64160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 15:49 94360]
R2 AVerRemote;AVerRemote;c:\progs\Common Files\AVerMedia\Service\AVerRemote.exe [5.8.2009 17:18 352256]
R2 AVerScheduleService;AVerScheduleService;c:\progs\Common Files\AVerMedia\Service\AVerScheduleService.exe [5.8.2009 17:18 409600]
R2 ekrn;ESET Service;c:\progs\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 15:47 731840]
R3 AVerFx2hbtv;AVerMedia USB SW Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv.sys [5.8.2009 17:20 273152]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\progs\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 21:06 951632]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - AVERREMOTE
*NewlyCreated* - AVERSCHEDULESERVICE
*NewlyCreated* - HPQCXS08
*NewlyCreated* - HPQDDSVC
*NewlyCreated* - NET_DRIVER_HPZ12
*NewlyCreated* - PML_DRIVER_HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2009-08-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\progs\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-ICQ - c:\progs\ICQ6\ICQ.exe
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progs\MICROS~1\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\docs\Administrator\Data aplikací\Mozilla\Firefox\Profiles\jlrgdt94.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.centrum.cz/
---- NASTAVENÍ FIREFOXU ----
c:\progs\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\progs\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\progs\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\progs\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\progs\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\progs\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\progs\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-05 21:16
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(572)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2009-08-05 21:17
ComboFix-quarantined-files.txt 2009-08-05 19:17
Před spuštěním: Volných bajtů: 16 608 870 400
Po spuštění: Volných bajtů: 16 728 395 776
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff