reset biosu nepomohol. ked ukaze tu obrazovku, ze system sa vypina, tak prestane reagovat, ale hdd dioda sem tam preblikne. tu je log z combofix:
ComboFix 08-06-01.6 - Palik 2008-06-02 21:23:16.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.1136 [GMT 2:00]
Running from: D:\Stiahnuté\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-02 to 2008-06-02 )))))))))))))))))))))))))))))))
.
2008-06-01 21:07 . 2008-06-01 21:08 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-05-30 22:38 . 2008-05-30 22:45 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-30 22:36 . 2008-05-30 22:43 <DIR> d-------- C:\Program Files\Google
2008-05-26 20:12 . 2008-05-26 20:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-05-20 20:58 . 2008-05-20 20:58 <DIR> d-------- C:\Program Files\Setup Files
2008-05-20 20:43 . 2008-05-20 20:43 <DIR> d-------- C:\Program Files\MSI
2008-05-15 17:18 . 2008-05-15 17:18 <DIR> d-------- C:\Documents and Settings\Palik\Application Data\dvdcss
2008-05-11 17:18 . 2008-05-11 17:18 20 --ah----- C:\sccfg.sys
2008-05-07 21:13 . 2008-05-07 21:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-07 19:55 . 2008-05-07 19:55 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-05-07 19:55 . 2008-05-07 19:55 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-05-04 15:25 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-04 15:25 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-04 15:25 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-04 13:10 . 2008-05-04 13:10 <DIR> d-------- C:\Program Files\Common Files\Autodesk
2008-05-04 13:08 . 2008-05-04 13:08 <DIR> d-------- C:\Program Files\Microsoft WSE
2008-05-04 13:08 . 2008-05-04 13:08 <DIR> d-------- C:\Program Files\DWG TrueView 2007
2008-05-04 13:04 . 2008-05-04 13:10 <DIR> d-------- C:\Program Files\Autodesk
2008-05-04 13:00 . 2008-05-10 18:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-05-04 12:58 . 2008-05-04 15:45 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-05-03 18:25 . 2008-05-03 18:25 <DIR> d-------- C:\Documents and Settings\Palik\Contacts
2008-05-03 18:24 . 2008-05-03 18:24 <DIR> d-------- C:\Program Files\Windows Live
2008-05-03 18:24 . 2008-05-03 18:24 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-03 18:24 . 2008-05-03 18:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-02 12:26 . 2006-12-08 17:01 547,840 --a------ C:\WINDOWS\mHotkey.exe
2008-05-02 12:26 . 2003-07-03 14:21 294,912 --a------ C:\WINDOWS\PIC.dll
2008-05-02 12:26 . 2005-02-25 16:54 233,472 --a------ C:\WINDOWS\InstIt.exe
2008-05-02 12:26 . 2005-02-25 16:54 24,576 --a------ C:\WINDOWS\HKNTDLL.dll
2008-05-02 12:26 . 2005-02-25 16:54 5,280 --a------ C:\WINDOWS\hotbtnv.vxd
2008-05-02 12:26 . 2007-01-15 17:37 4,308 --a------ C:\WINDOWS\NT4_98.reg
2008-05-02 12:26 . 2007-01-15 17:37 4,306 --a------ C:\WINDOWS\2K.reg
2008-05-02 12:26 . 2007-01-15 17:37 4,290 --a------ C:\WINDOWS\Other.reg
2008-05-02 12:26 . 2007-01-15 17:37 4,290 --a------ C:\WINDOWS\MeXP.reg
2008-05-02 12:26 . 2007-01-11 15:45 490 --a------ C:\WINDOWS\Instit.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 19:09 --------- d-----w C:\Documents and Settings\Palik\Application Data\Skype
2008-06-02 18:39 --------- d-----w C:\Documents and Settings\Palik\Application Data\skypePM
2008-05-30 20:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-28 19:05 --------- d-----w C:\Documents and Settings\Palik\Application Data\uTorrent
2008-05-26 18:12 --------- d-----w C:\Program Files\Multimedia
2008-05-26 17:48 --------- d-----w C:\Program Files\System
2008-05-19 18:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 16:21 --------- d-----w C:\Documents and Settings\Palik\Application Data\Autodesk
2008-05-07 19:13 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-04 13:41 --------- d-----w C:\Program Files\Internet
2008-05-04 13:41 --------- d-----w C:\Documents and Settings\Palik\Application Data\Lavasoft
2008-04-26 14:22 --------- d-----w C:\Documents and Settings\Palik\Application Data\TuneUp Software
2008-04-26 14:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-04-22 17:32 --------- d-----w C:\Program Files\Sierra On-Line
2008-04-22 17:22 --------- d-----w C:\Documents and Settings\Palik\Application Data\SolidWorks
2008-04-22 17:17 --------- d-----w C:\Program Files\Common Files\SolidWorks Shared
2008-04-22 17:16 --------- d-----w C:\Program Files\SolidWorks Installation Manager
2008-04-22 17:16 --------- d-----w C:\Program Files\Common Files\eDrawings2007
2008-04-22 16:50 --------- d-----w C:\Program Files\Ergo Series
2008-04-21 16:12 --------- d-----w C:\Program Files\Ovládače
2008-04-20 15:16 --------- d-----w C:\Documents and Settings\Palik\Application Data\sldIM
2008-04-20 14:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
2008-04-20 14:26 --------- d-----w C:\Program Files\Iné
2008-04-20 12:48 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-13 09:21 17,920 ----a-w C:\WINDOWS\system32\Ntaccess.sys
2008-04-08 19:08 6,656 ----a-w C:\WINDOWS\system32\haspvdd.dll
2008-04-08 19:07 132,608 ----a-w C:\WINDOWS\system32\drivers\Haspnt.sys
2008-04-08 19:07 106,496 ----a-w C:\WINDOWS\kokundo.exe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-10 17:20 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\Internet\Avast\ashDisp.exe" [2008-05-16 01:19 79224]
"nwiz"="nwiz.exe" [2006-08-11 22:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 05:01 77824 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 22:43 7630848]
"mouseElf"="C:\PROGRA~1\ERGOSE~1\MouseElf.EXE" [2005-03-17 01:58 184320]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
"Autodesk Licensing Service"=3 (0x3)
"lanmanworkstation"=2 (0x2)
"WZCSVC"=2 (0x2)
"W32Time"=2 (0x2)
"upnphost"=3 (0x3)
"UxTuneUp"=2 (0x2)
"LmHosts"=2 (0x2)
"lanmanserver"=2 (0x2)
"seclogon"=2 (0x2)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"Irmon"=2 (0x2)
"CiSvc"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=2 (0x2)
"TrkWks"=2 (0x2)
"Browser"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet\\ICQ\\ICQLite.exe"=
"D:\\Program Files\\Strong DC++\\StrongDC.exe"=
"C:\\Program Files\\Iné\\Total Commander\\TOTALCMD.EXE"=
"C:\\Program Files\\Internet\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Internet\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 genmcmnUSB;USB Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2004-04-19 07:01]
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 00:04]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
S3 genmcmn;Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gmfiltr.sys [2004-09-15 09:53]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2008-02-09 14:10]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2008-02-09 14:10]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys [2008-02-09 14:10]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2008-02-09 14:10]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2008-02-09 14:10]
S3 RushTopDevice;RushTopDevice;D:\Program Files\System\Core Center\RushTop.sys []
S4 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 01:56]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Setup.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-30 15:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\System\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-02 21:24:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\PROGRA~1\ERGOSE~1\WhoRU.dll
.
Completion time: 2008-06-02 21:25:03
ComboFix-quarantined-files.txt 2008-06-02 19:24:57
Pre-Run: 10,170,818,560 bytes free
Post-Run: 10,174,865,408 bytes free
163 --- E O F --- 2008-05-19 17:59:47