Log z combofix:>
ComboFix 07-11-19.3 - Skynet 2007-11-22 23:58:30.1 - NTFSx86
Running from: c:\Documents and Settings\Skynet\Desktop\ANTIVIRUS\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\system32\dpvvo.dll
C:\WINDOWS\system32\drivers\wnrhdxqy.dat
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\W000t32w.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_PIIFLRUG
-------\piiflrug
((((((((((((((((((((((((( Files Created from 2007-10-22 to 2007-11-22 )))))))))))))))))))))))))))))))
.
2007-11-21 01:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-21 00:40 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-11-21 00:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2007-11-19 23:51 <DIR> d-------- C:\Hijack
2007-11-18 09:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-17 11:06 <DIR> d-------- C:\Program Files\Yahoo!
2007-11-17 11:06 <DIR> d-------- C:\Program Files\CCleaner
2007-11-16 23:59 27,136 --a------ C:\WINDOWS\system32\PCWizard.cpl
2007-11-16 23:58 <DIR> d-------- C:\Program Files\PC Wizard 2008
2007-11-16 23:08 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-16 23:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 20:59 <DIR> d-------- C:\Documents and Settings\Skynet\Application Data\AVG7
2007-11-16 20:58 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-16 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-16 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-22 10:16 --------- d-----w C:\Program Files\Warez P2P Client
2007-11-22 07:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-18 21:43 --------- d-----w C:\Program Files\Support Software
2007-11-17 08:24 --------- d-----w C:\Documents and Settings\Skynet\Application Data\Skype
2007-11-16 22:06 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 18:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-16 18:42 --------- d-----w C:\Program Files\InterVideo
2007-11-16 18:41 --------- d-----w C:\Program Files\Volo View Express
2007-11-16 18:41 --------- d-----w C:\Program Files\scbar
2007-11-16 18:40 --------- d-----w C:\Program Files\Mv2Player
2007-11-16 18:40 --------- d-----w C:\Program Files\IM Sniffer
2007-11-16 18:40 --------- d-----w C:\Program Files\ICQToolbar
2007-11-16 18:40 --------- d-----w C:\Program Files\ICQ
2007-11-16 18:40 --------- d-----w C:\Program Files\Cliprex DS DVD Player
2007-11-16 18:40 --------- d-----w C:\Program Files\AutoCAD 2002 Cz
2007-11-16 18:38 --------- d-----w C:\Program Files\AV Music Morpher Gold
2007-11-16 18:37 --------- d-----w C:\Program Files\Acala DVD Copy
2007-11-04 11:19 --------- d-----w C:\Documents and Settings\Skynet\Application Data\uTorrent
2007-10-21 08:58 --------- d-----w C:\Program Files\uTorrent
2007-10-21 08:05 --------- d-----w C:\Program Files\Paltalk Messenger
2007-10-02 14:11 --------- d-----w C:\Documents and Settings\Skynet\Application Data\Kodak
2007-02-20 17:18 17,920 ----a-w C:\Program Files\Common Files\stdole2.tlb
2007-02-20 17:18 151,552 ----a-w C:\Program Files\Common Files\scrrun.dll
2007-02-20 17:18 11,776 ----a-w C:\Program Files\Common Files\smartsubclass.dll
2007-02-20 17:18 1,227,264 ----a-w C:\Program Files\Common Files\dx8vb.dll
2006-07-30 14:53 83,736 ----a-w C:\Documents and Settings\Skynet\Application Data\GDIPFONTCACHEV1.DAT
2005-02-06 08:26 1,266 ----a-w C:\Program Files\INSTALL.LOG
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 13:00]
"FreeRAM XP"="C:\Program Files\framxpro\FreeRAM XP Pro 1.40.exe" [2003-08-19 17:22]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-02 20:22]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-07-18 22:51]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15]
"SiS Tray"="C:\WINDOWS\System32\sistray.EXE" [2003-06-26 11:35]
"SiS KHooker"="C:\WINDOWS\System32\khooker.exe" [2003-05-29 03:23]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-29 09:58 C:\WINDOWS\AGRSMMSG.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-16 20:58]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-09-27 12:54]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-16 20:58]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 12:01:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"NKtveUur"= {74EF26BD-DE45-8C17-6239-410A840D9630} - C:\WINDOWS\System32\gnfp.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
c:\program files\altnet\points manager\points manager.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
2004-02-16 14:04 147456 --a------ C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClickMe]
C:\apps\ClickMe\ClickMe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
C:\PROGRA~1\Save\Save.exe
R1 Asapi;Asapi;C:\WINDOWS\System32\drivers\Asapi.sys
R2 amdfix;amdfix;\??\C:\WINDOWS\System32\drivers\amdfix.sys
R2 MicroGuard;MicroGuard Copy Protection;\??\C:\WINDOWS\system32\drivers\mgnt.sys
R2 xinstall;xinstall;\??\C:\WINDOWS\System32\drivers\xinstall.sys
R3 AVBE;AlarIT Virtual Bus Enumerator Driver;C:\WINDOWS\System32\DRIVERS\avbe.sys
S1 prodrv03;Star Force copy protection driver v3;C:\WINDOWS\System32\drivers\prodrv03.sys
S3 akshasp;Aladdin HASP Key;C:\WINDOWS\System32\DRIVERS\akshasp.sys
S3 AVSD;Alarit Virtual Serial Ports Driver;C:\WINDOWS\System32\DRIVERS\avsd.sys
S3 ulusba;NEC 616 Command Port Driver;C:\WINDOWS\System32\DRIVERS\ulusba.sys
S3 ulusbc;NEC 616 CONTROL Driver;C:\WINDOWS\System32\DRIVERS\ulusbc.sys
S3 ulusbe;NEC 616 ENUMERATION Driver;C:\WINDOWS\System32\DRIVERS\ulusbe.sys
S3 ulusbm;NEC 616 Modem Driver;C:\WINDOWS\System32\DRIVERS\ulusbm.sys
S3 ulusbo;NEC 616 OBEX Port Driver;C:\WINDOWS\System32\DRIVERS\ulusbo.sys
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-23 00:11:41
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-23 0:16:02 - machine was rebooted
.
--- E O F ---
Takze problem vyrieseny (aspon dufam), Rbot dakujem za pomoc. Este otazka na zaver co to vlastne bolo a ako tomu predist ??? Nedokazali to chytit a odstranit nasledujuce programi> AVG, Avira, Adware, ApybotS&D, OTMoveIt, Avenger ..