Pardon to me nenapadlo....

tady je.....
ComboFix 10-01-20.04 - Administrator 24.01.2010 10:50:58.7.1 - x86
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-24 do 2010-01-24 )))))))))))))))))))))))))))))))
.
2010-01-24 18:21 . 2009-08-07 03:24 53472 -c--a-w- c:\windows\system32\dllcache\wuauclt.exe
2010-01-24 18:21 . 2009-08-07 03:24 53472 ------w- c:\windows\system32\wuauclt.exe
2010-01-24 18:21 . 2008-04-14 06:52 71680 -c--a-w- c:\windows\system32\dllcache\ssdpsrv.dll
2010-01-24 18:21 . 2008-04-14 06:52 71680 ------w- c:\windows\system32\ssdpsrv.dll
2010-01-24 18:21 . 2008-04-14 06:52 295936 -c--a-w- c:\windows\system32\dllcache\termsrv.dll
2010-01-24 18:21 . 2008-04-14 06:52 295936 ------w- c:\windows\system32\termsrv.dll
2010-01-24 18:21 . 2008-04-14 06:51 59904 -c--a-w- c:\windows\system32\dllcache\regsvc.dll
2010-01-24 18:21 . 2008-04-14 06:51 59904 ------w- c:\windows\system32\regsvc.dll
2010-01-24 18:21 . 2008-04-14 06:51 192512 -c--a-w- c:\windows\system32\dllcache\schedsvc.dll
2010-01-24 18:21 . 2008-04-14 06:51 192512 ------w- c:\windows\system32\schedsvc.dll
2010-01-24 18:21 . 2008-04-14 06:51 77824 -c--a-w- c:\windows\system32\dllcache\browser.dll
2010-01-24 18:21 . 2008-04-14 06:51 77824 ------w- c:\windows\system32\browser.dll
2010-01-22 07:27 . 2010-01-23 01:35 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-01-22 07:20 . 2010-01-23 01:36 -------- d-----w- c:\program files\COMODO
2010-01-22 06:21 . 2010-01-22 06:21 3904728 ----a-w- c:\windows\REGBK00.ZIP
2010-01-22 05:34 . 2010-01-22 05:34 -------- d-----w- c:\program files\XnView
2010-01-22 04:56 . 2010-01-22 06:16 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-22 04:49 . 2010-01-24 18:17 -------- d-----w- C:\Antivir-Resistance
2010-01-22 04:23 . 2010-01-22 04:23 -------- d---a-w- c:\windows\rundll16.exe
2010-01-22 04:23 . 2010-01-22 04:23 -------- d---a-w- c:\windows\logo1_.exe
2010-01-22 00:49 . 2008-04-14 06:52 171008 ------w- c:\windows\system32\srsvc.dll
2010-01-21 18:24 . 2010-01-21 18:24 -------- d---a-w- c:\windows\VDLL.DLL
2010-01-21 18:24 . 2010-01-21 18:24 -------- d---a-w- c:\windows\system32\runouce.exe
2010-01-21 18:24 . 2010-01-21 18:24 -------- d---a-w- c:\windows\RUNDL132.EXE
2010-01-21 18:24 . 2010-01-21 18:24 -------- d---a-w- c:\windows\logo_1.exe
2010-01-21 18:22 . 2010-01-21 18:22 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-01-21 18:22 . 2010-01-21 18:22 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-01-21 18:22 . 2010-01-21 18:22 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-01-21 18:22 . 2008-04-14 06:52 137216 ----a-w- c:\windows\system32\T.COM
2010-01-21 18:22 . 2008-04-14 06:52 147968 ----a-w- c:\windows\R.COM
2010-01-21 18:22 . 2010-01-21 18:22 -------- d-----w- c:\program files\Common Files\MicroWorld
2010-01-21 02:05 . 2010-01-21 23:40 -------- d-----w- C:\XP_Losos
2010-01-21 01:56 . 2010-01-21 23:42 -------- d-----w- c:\program files\nLite
2010-01-20 21:23 . 2010-01-20 21:23 -------- d-----w- c:\program files\Combined Community Codec Pack
2010-01-20 19:06 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-20 19:06 . 2010-01-23 12:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-20 19:05 . 2010-01-20 19:05 -------- d-----w- c:\program files\MalwarebytesPortable
2010-01-20 17:06 . 2010-01-20 17:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-20 17:02 . 2010-01-20 17:02 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-01-20 17:02 . 2010-01-20 17:02 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-01-20 17:02 . 2010-01-20 17:02 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-01-20 17:02 . 2010-01-20 17:02 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-01-20 16:18 . 2010-01-21 04:39 -------- d-----w- c:\program files\PeerGuardian2
2010-01-20 13:07 . 2010-01-21 09:25 -------- d-----w- c:\program files\TC UP
2010-01-12 23:37 . 2010-01-12 23:37 58 ----a-w- c:\windows\system32\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2010-01-12 23:37 . 2010-01-16 05:39 -------- d-----w- c:\program files\ScreenshotCaptor
2010-01-09 00:34 . 2010-01-09 01:56 -------- d-----w- c:\program files\Commandos
2010-01-08 22:29 . 1996-01-09 18:38 283648 ----a-w- c:\windows\uninst.exe
2010-01-08 22:27 . 2010-01-08 22:27 -------- d-----w- c:\documents and settings\Administrator\WINDOWS
2010-01-08 09:46 . 2010-01-20 21:07 -------- d-----w- c:\program files\MediaInfo
2010-01-07 06:43 . 2010-01-07 06:44 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-07 05:25 . 1997-07-06 19:22 756736 ------w- c:\windows\system32\ir41_32.dll
2010-01-07 05:24 . 2010-01-07 05:24 -------- d-----w- c:\program files\Microsoft Games
2010-01-07 03:30 . 2010-01-07 03:30 -------- d-----w- c:\documents and settings\Administrator\Data aplikac?
2010-01-07 03:30 . 2010-01-07 03:30 4096 ----a-w- c:\windows\d3dx.dat
2010-01-07 03:26 . 2010-01-07 03:26 -------- d-----w- c:\program files\Echidna LLC
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 01:54 . 2009-11-13 09:53 -------- d-----w- c:\program files\JDownloader 0.8.821
2010-01-21 09:24 . 2008-04-14 06:52 219648 ----a-w- c:\windows\system32\uxtheme.dll
2010-01-21 05:38 . 2010-01-21 05:38 140288 ----a-w- c:\windows\system32\sfc_os.dll.tmp
2010-01-21 04:46 . 2001-10-25 14:00 78070 ----a-w- c:\windows\system32\perfc005.dat
2010-01-21 04:46 . 2001-10-25 14:00 428988 ----a-w- c:\windows\system32\perfh005.dat
2010-01-20 13:34 . 2009-11-13 05:49 -------- d-----w- c:\program files\CCleaner
2010-01-08 21:50 . 2009-11-13 03:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-08 00:07 . 2009-08-03 11:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 06:44 . 2009-11-13 03:22 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-01-07 06:43 . 2009-11-13 02:44 691696 ----a-w- c:\windows\system32\drivers\sptd.sys.12772220
2009-12-23 03:16 . 2009-12-23 03:16 -------- d-----w- c:\program files\Cinemax
2009-12-22 12:33 . 2009-12-22 12:33 -------- d-----w- c:\program files\AGEIA Technologies
2009-12-22 12:32 . 2009-12-22 12:32 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-14 23:00 . 2009-12-14 22:39 -------- d-----w- c:\program files\Tropico
2009-12-14 22:52 . 2009-12-14 22:52 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-12-10 07:44 . 2009-12-10 07:38 -------- d-----w- c:\program files\JDownloader
2009-12-09 07:16 . 2009-12-03 07:15 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-03 07:14 . 2009-12-03 07:14 -------- d-----w- c:\program files\Avira
2009-12-03 04:35 . 2009-12-03 04:35 -------- d-----w- c:\program files\MSBuild
2009-12-03 04:34 . 2009-12-03 04:34 -------- d-----w- c:\program files\Reference Assemblies
2009-12-03 02:15 . 2009-12-02 06:11 -------- d-----w- c:\program files\Common Files\BitDefender
2009-12-02 06:00 . 2009-12-02 05:59 -------- d-----w- c:\program files\AviSynth 2.5
2009-11-29 05:30 . 2009-11-29 05:30 -------- d-----w- c:\program files\Altar Games
2009-11-26 03:04 . 2009-11-13 02:42 -------- d-----r- c:\program files\Skype
2009-11-21 16:03 . 2008-04-14 06:51 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-13 10:33 . 2009-11-13 10:33 0 ----a-w- c:\windows\PowerReg.dat
2009-11-13 09:58 . 2009-11-13 09:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-13 06:42 . 2009-11-13 01:09 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-13 06:42 . 2009-11-13 01:09 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-11-13 06:41 . 2009-11-13 01:09 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-11-13 03:22 . 2009-11-13 03:22 0 ----a-w- c:\windows\nsreg.dat
2009-11-13 03:16 . 2009-11-13 03:16 315392 ----a-w- c:\windows\HideWin.exe
2009-11-13 01:06 . 2009-11-13 01:06 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-03 04:42 . 2009-11-13 03:23 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:43 . 2008-04-14 06:52 916480 ------w- c:\windows\system32\wininet.dll
.
Kód: Vybrat vše
<pre>
c:\program files\Commandos\Odinštalovať Commandos-sk .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-01-22_00.51.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-24 18:26 . 2010-01-24 18:26 16384 c:\windows\temp\Perflib_Perfdata_6bc.dat
+ 2008-04-14 06:52 . 2009-03-08 12:33 420352 c:\windows\system32\vbscript.dll
+ 2010-01-24 18:21 . 2008-04-14 06:51 192512 c:\windows\system32\schedsvc.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-29 16132608]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-12 53248]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-13 149280]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"TC UP"="c:\program files\TC UP\TC UP.exe" [2009-10-04 37376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-14 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"PeerGuardian"=c:\program files\PeerGuardian2\pg2.exe
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 VD_FileDisk;VD_FileDisk; [x]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
.
.
------- Doplňkový sken -------
.
mStart Page = about:blank
mSearch Bar = hxxp://
www.google.com/ie
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\6xqo9sa7.default\
FF - prefs.js: browser.startup.homepage - war-forum.net
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-24 10:54
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TlntSvr]
"ImagePath"=""
.
Celkový čas: 2010-01-24 10:55:12
ComboFix-quarantined-files.txt 2010-01-24 18:55
ComboFix2.txt 2010-01-24 18:31
ComboFix3.txt 2010-01-23 01:55
ComboFix4.txt 2010-01-23 01:44
ComboFix5.txt 2010-01-24 18:50
Před spuštěním: Volných bajtů: 61 257 859 072
Po spuštění: Volných bajtů: 61 248 663 552
- - End Of File - - 77FFD35C45034CB5F86D476EE6B209D3