vymazat to neslo ani cez jedno ani cez druhe, tu je log z combofix:
ComboFix 07-10-02.2 - peter 2007-10-02 22:00:26.1 - NTFSx86
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.139 [GMT 2:00]
Running from: C:\Documents and Settings\peter\Plocha\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\peter\Plocha\internet.lnk
C:\Program Files\outerinfo
C:\Program Files\outerinfo\outerinfo.ico
C:\WINDOWS\1.exe
C:\WINDOWS\2.exe
C:\WINDOWS\system32\Cfx32.lic
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\iexplorer.exe
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NPF
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-09-02 to 2007-10-02 )))))))))))))))))))))))))))))))
.
2007-10-02 21:59 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-02 18:59 <DIR> d-------- C:\Program Files\Advanced Registry Doctor
2007-10-02 17:45 36,352 --------- C:\WINDOWS\system32\xxywtuu.dll
2007-09-30 22:33 740,442 --a------ C:\WINDOWS\system32\divx.dll
2007-09-30 22:33 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-09-30 22:33 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-09-30 22:33 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-09-30 22:33 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-09-30 22:33 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-09-30 22:33 163,840 --a------ C:\WINDOWS\system32\unrar.dll
2007-09-30 22:33 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-09-30 22:32 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-09-30 20:01 <DIR> d-------- C:\!KillBox
2007-09-30 19:50 <DIR> d-------- C:\Program Files\Vstplugins
2007-09-30 19:50 <DIR> d-------- C:\Program Files\Sony
2007-09-30 19:48 <DIR> d-------- C:\Program Files\Sony Setup
2007-09-27 18:21 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-09-27 17:32 <DIR> d-------- C:\Program Files\Pointstone
2007-09-27 17:32 <DIR> d-------- C:\Program Files\Common Files\Pointstone
2007-09-25 17:43 441,760 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2007-09-25 17:43 44,384 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-09-25 17:42 368,736 --a------ C:\WINDOWS\system32\drivers\tdrpman.sys
2007-09-25 17:42 129,248 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2007-09-25 17:40 <DIR> d-------- C:\Program Files\Common Files\Acronis
2007-09-25 17:40 <DIR> d-------- C:\Program Files\Acronis
2007-09-23 18:52 <DIR> d-------- C:\Program Files\LimeWire
2007-09-23 14:43 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-19 21:35 <DIR> d-------- C:\Program Files\Common Files\Nero
2007-09-19 17:04 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-09-16 19:20 <DIR> d-------- C:\Program Files\QIP
2007-09-13 17:13 <DIR> d-------- C:\Program Files\CyberLink
2007-09-12 17:53 67,752 --a------ C:\WINDOWS\system32\drivers\avfwot.sys
2007-09-12 17:53 61,096 --a------ C:\WINDOWS\system32\drivers\avfwim.sys
2007-09-12 17:53 <DIR> d-------- C:\Program Files\Avira
2007-09-11 23:03 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2007-09-11 17:11 <DIR> d-------- C:\Program Files\CCleaner
2007-09-10 21:56 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-09 23:54 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-09-09 20:55 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2007-09-09 01:03 88 -r-hs---- C:\WINDOWS\system32\1C6BA2AAD8.sys
2007-09-09 00:56 <DIR> d-------- C:\Program Files\Common Files\Corel
2007-09-08 21:25 2,516 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-09-08 21:16 <DIR> d-------- C:\Program Files\Corel
2007-09-08 18:36 <DIR> d-------- C:\Documents and Settings\peter\Incomplete
2007-09-06 22:28 545 --a------ C:\WINDOWS\UC.PIF
2007-09-06 22:28 545 --a------ C:\WINDOWS\RAR.PIF
2007-09-06 22:28 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-09-06 22:28 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-09-06 22:28 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-09-06 22:28 545 --a------ C:\WINDOWS\LHA.PIF
2007-09-06 22:28 545 --a------ C:\WINDOWS\ARJ.PIF
2007-09-06 22:28 <DIR> d-------- C:\totalcmd
2007-09-05 16:07 <DIR> d-------- C:\Program Files\Microsoft Works
2007-09-05 16:05 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-09-04 21:18 <DIR> d-------- C:\Program Files\SlySoft
2007-09-04 21:16 86,528 ---h----- C:\WINDOWS\Optimiz.exe
2007-09-04 21:16 0 --a------ C:\WINDOWS\ElbyCDIO.sys
2007-09-04 21:09 505,392 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-09-04 21:09 32,768 --a------ C:\WINDOWS\system32\BCGPOleAcc.dll
2007-09-04 21:09 2,605,056 --a------ C:\WINDOWS\system32\BCGCBPRO800u.dll
2007-09-04 21:09 2,600,960 --a------ C:\WINDOWS\system32\BCGCBPRO800.dll
2007-09-04 21:09 1,712,128 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-09-04 21:09 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-09-04 21:09 1,047,552 --a------ C:\WINDOWS\system32\mfc71u.dll
2007-09-03 20:04 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-09-03 20:00 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-09-03 19:57 <DIR> dr-h----- C:\MSOCache
2007-09-03 19:03 <DIR> d-------- C:\Documents and Settings\peter\.borland
2007-09-03 19:00 <DIR> d-------- C:\Program Files\Borland
2007-09-03 17:07 4 --a------ C:\WINDOWS\windebug2561.dll
2007-09-02 18:27 <DIR> d-------- C:\Program Files\PowerISO
2007-09-02 01:15 <DIR> d-------- C:\WINDOWS\Web Download
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-29 14:47 --------- d-------- C:\Program Files\TuneUp Utilities 2007
2007-09-29 00:06 --------- d-------- C:\Program Files\Registry Genius
2007-09-27 18:45 --------- d-------- C:\Program Files\BitComet
2007-09-19 21:35 --------- d-------- C:\Program Files\Nero
2007-09-19 21:19 --------- d-------- C:\Program Files\Common Files\Ahead
2007-09-13 17:15 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-03 20:10 --------- d-------- C:\Program Files\MSBuild
2007-09-02 15:22 --------- d-------- C:\Program Files\AusLogics Registry Defrag
2007-09-02 14:41 --------- d-------- C:\Program Files\Disk Cleaner
2007-09-02 14:12 359808 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-09-01 17:59 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-01 17:55 --------- d-------- C:\Program Files\UltraISO
2007-09-01 17:55 --------- d-------- C:\Program Files\Common Files\EZB Systems
2007-09-01 17:36 --------- d-------- C:\Program Files\MSXML 6.0
2007-09-01 16:23 --------- d-------- C:\Program Files\Reference Assemblies
2007-09-01 14:19 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-09-01 10:23 --------- d-------- C:\Program Files\ICQ6
2007-08-31 18:25 --------- d-------- C:\Program Files\Realtek
2007-08-31 18:25 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-08-31 18:21 --------- d-------- C:\Program Files\Motorola
2007-08-31 18:18 --------- d-------- C:\Program Files\Common Files\ATI Technologies
2007-08-31 18:17 --------- d-------- C:\Program Files\ATI Technologies
2007-08-31 18:05 --------- d-------- C:\Program Files\microsoft frontpage
2007-08-31 14:04 222488 --a------ C:\WINDOWS\system32\snapapi.dll
2007-08-28 12:00 626688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-28 12:00 548864 --a------ C:\WINDOWS\system32\msvcp80.dll
2007-08-28 12:00 1101824 --a------ C:\WINDOWS\system32\mfc80.dll
2007-08-08 09:33 132904 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2007-08-08 09:33 11304 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2007-08-07 02:15 33052 --a------ C:\WINDOWS\system32\drivers\scdemu.sys
2007-08-04 10:40 972072 --a------ C:\WINDOWS\UNRecode.exe
2007-08-04 10:10 95600 --a------ C:\WINDOWS\system32\NeroCo.dll
2007-08-03 12:52 972072 --a------ C:\WINDOWS\UNNeroMediaHome.exe
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-20 00:57 267112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2007-07-20 00:54 18280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-19 18:14 444776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-07-19 18:14 3727720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-07-19 18:14 1358192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 09:34 C:\WINDOWS\RTHDCPL.exe]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [2007-08-31 12:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Application executable file"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-06-01 07:57]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 16:49]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"=1 (0x1)
"NoThumbnailCache"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E908A6A7-026C-4FBE-93A9-96020BEEAD53}"= C:\WINDOWS\system32\xxywtuu.dll [2007-10-02 17:45 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxywtuu]
xxywtuu.dll 2007-10-02 17:45 36352 C:\WINDOWS\system32\xxywtuu.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R1 avfwot;avfwot;C:\WINDOWS\system32\DRIVERS\avfwot.sys
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\C:\Program Files\CyberLink\PowerDVD\000.fcl
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;"C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe"
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;"C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe"
R2 AntiVirScheduler;Avira Premium Security Suite Scheduler;"C:\Program Files\Avira\Avira Premium Security Suite\sched.exe"
R2 antivirwebservice;Avira Premium Security Suite WebGuard;"C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE"
R2 AVEService;Avira Premium Security Suite MailGuard helper service;"C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe"
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe"
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
UxTuneUp
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-02 22:07:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\AntiVirScheduler]
"ImagePath"="\"C:\Program Files\Avira\Avira Premium Security Suite\sched.exe\""
.
Completion time: 2007-10-02 22:09:20 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-02 22:08
.
--- E O F ---