takze uz to vyzera ze uz je to ok, dik vam za pomoc ale stala sa mi takato vec, na ikonach na ploche co su knim popisky s nazvom zrazu nemam priehladne
predtym som to mal priehladne a teraz je to modre, neviete co stym ???
tu je este ten log z combofixu
ComboFix 07-10-28.2 - pocitac 2007-10-28 21:14:46.1 - NTFSx86
Running from: C:\Documents and Settings\pocitac\Plocha\net\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\pocitac\Data aplikací\macromedia\Flash Player\#SharedObjects\G2PJR5NE\www.broadcaster.com
C:\Documents and Settings\pocitac\Data aplikací\macromedia\Flash Player\#SharedObjects\G2PJR5NE\www.broadcaster.com\played_list.sol
C:\Documents and Settings\pocitac\Data aplikací\macromedia\Flash Player\#SharedObjects\G2PJR5NE\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\pocitac\Data aplikací\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\pocitac\Data aplikací\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\pocitac\Oblíbené položky\Error Cleaner.url
C:\Documents and Settings\pocitac\Oblíbené položky\Privacy Protector.url
C:\Documents and Settings\pocitac\Oblíbené položky\Spyware&Malware Protection.url
C:\Program Files\Sothink Glanda\Templates\Album\Calendar\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\cube\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\frame\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\Fresh\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\MAC_style\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\Mail\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\number\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\player\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\snow\_desktop.ini
C:\Program Files\Sothink Glanda\Templates\Album\xmasstar\_desktop.ini
C:\Program Files\VideoAccessCodec
C:\Program Files\VideoAccessCodec\install.ico
C:\Program Files\VideoAccessCodec\Uninstall.exe
C:\Program Files\VideoAccessCodec\VideoAccessCodec.ocx
C:\WINDOWS\dat.txt
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\nvrssk.dll
C:\WINDOWS\system32\nvrssl.dll
C:\WINDOWS\system32\sysdm.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-28 )))))))))))))))))))))))))))))))
.
2007-10-28 21:09 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-28 21:05 60,416 --a------ C:\WINDOWS\system32\drivers\jhnpbgjk.sys
2007-10-28 21:05 1,080 --a------ C:\muklxall.bat
2007-10-28 20:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-28 20:30 60,416 --a------ C:\WINDOWS\system32\drivers\rwmlkjkp.sys
2007-10-28 20:30 1,080 --a------ C:\tvmpakws.bat
2007-10-28 20:24 283 --a------ C:\rem.reg
2007-10-28 20:21 60,416 --a------ C:\WINDOWS\system32\drivers\ljpyhfxe.sys
2007-10-28 20:21 1,080 --a------ C:\rsalmrdb.bat
2007-10-28 12:09 <DIR> d-------- C:\Program Files\Kyodai Mahjongg
2007-10-28 12:07 <DIR> d-------- C:\Program Files\Real
2007-10-28 12:05 106,496 --a------ C:\WINDOWS\kthemup.exe
2007-10-28 12:01 <DIR> d-------- C:\Program Files\ReflexiveArcade
2007-10-19 13:19 <DIR> d-------- C:\naevius_temp_folder
2007-10-14 13:35 297,984 --a------ C:\WINDOWS\unin0405.exe
2007-10-14 13:34 <DIR> d-------- C:\LXKZ600
2007-10-12 13:51 52,352 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
2007-10-12 13:51 52,352 --a--c--- C:\WINDOWS\system32\dllcache\i8042prt.sys
2007-10-11 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2007-10-11 15:46 <DIR> d-------- C:\Program Files\Spyware Terminator
2007-10-03 16:57 <DIR> d-------- C:\Program Files\Elaborate Bytes
2007-09-30 22:30 <DIR> dr-h----- C:\Documents and Settings\pocitac\Data aplikací\SecuROM
2007-09-30 22:30 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-09-30 22:26 22,328 --a------ C:\Documents and Settings\pocitac\Data aplikací\PnkBstrK.sys
2007-09-28 14:18 <DIR> d-------- C:\Documents and Settings\pocitac\Data aplikací\Nero
2007-09-28 14:11 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-26 15:22 --------- d-----w C:\Program Files\totalcmd
2013-06-25 19:02 --------- d-----w C:\Program Files\Ubisoft
2013-06-24 17:36 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Blueberry
2013-06-23 18:04 2,944 ----a-w C:\WINDOWS\system32\drivers\bbcap.sys
2013-06-23 18:04 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Blueberry
2013-06-23 18:03 --------- d-----w C:\Program Files\Common Files\Blueberry Software
2013-06-23 18:03 --------- d-----w C:\Program Files\Blueberry Software
2013-06-23 18:03 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\{06CB4BE7-FE57-4F52-B26F-0DD54A008B74}
2013-06-23 17:50 --------- d-----w C:\Program Files\3ivx
2013-06-22 17:46 --------- d-----w C:\Program Files\Uniblue
2013-06-22 17:46 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Uniblue
2013-06-22 16:49 --------- d-----w C:\Program Files\ashampoo
2013-06-17 18:30 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-06-17 12:25 --------- d-----w C:\Program Files\PDFCreator
2013-06-15 12:00 --------- d-----w C:\Program Files\AgemSoft
2013-06-15 11:50 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\LANGMaster
2013-06-11 16:27 --------- d-----w C:\Program Files\Common Files\Macromedia
2013-06-11 16:24 --------- d-----w C:\Program Files\Macromedia
2013-06-10 09:38 --------- d-----w C:\Program Files\MSN Games
2013-06-10 09:37 --------- d-----w C:\Program Files\Luxor_at
2013-06-10 09:11 --------- d-----w C:\Program Files\bfgclient
2013-06-10 09:11 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\BigFishGamesCache
2013-06-08 15:59 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Hamachi
2013-06-08 15:36 17,480 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2013-06-08 15:36 --------- d-----w C:\Program Files\Hamachi
2013-06-01 16:17 --------- d-----w C:\Program Files\Rockstar Games
2013-06-01 15:12 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2013-05-29 19:12 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\AdobeUM
2013-05-29 17:12 --------- d-----w C:\Program Files\MachrSoft
2013-05-25 14:26 --------- d-----w C:\Program Files\Game_Maker6
2013-05-24 18:56 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2013-05-24 18:49 --------- d-----w C:\Program Files\Common Files\Adobe
2013-05-24 18:33 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2013-05-23 13:59 --------- d-----w C:\Program Files\Common Files\AVSMedia
2013-05-23 13:55 --------- d-----w C:\Program Files\AVSMedia
2013-05-20 16:35 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Lavasoft
2013-05-20 15:21 --------- d-----w C:\Program Files\Lavasoft
2013-05-20 15:21 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2013-05-18 15:02 --------- d-----w C:\Program Files\Common Files\Stardock
2013-05-18 14:59 --------- d-----w C:\Program Files\Stardock
2013-05-18 14:53 502,208 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2007-10-28 12:22 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\U3
2007-10-28 12:13 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Skype
2007-10-28 11:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-19 15:51 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-19 15:03 --------- d-----w C:\Program Files\Nero
2007-10-11 15:18 --------- d-----w C:\Program Files\DAEMON Tools
2007-10-08 19:45 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\BSplayer PRO
2007-09-30 21:26 674,600 ----a-w C:\WINDOWS\system32\pbsvc.exe
2007-09-30 21:26 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-09-30 21:26 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-09-30 21:26 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-09-27 14:42 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-09-22 14:04 --------- d-----w C:\Program Files\YouTube Downloader
2007-09-22 14:04 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\uTorrent
2007-09-22 13:39 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\for move dart
2007-09-16 15:58 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\view name beep for
2007-09-13 20:10 --------- d-----w C:\Program Files\for move dart
2007-09-10 12:09 --------- d-----w C:\Program Files\MOBILedit!
2007-09-06 14:36 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Hemera
2007-09-06 13:09 --------- d-----w C:\Documents and Settings\pocitac\Data aplikací\Ulead Systems
2007-09-06 13:06 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2007-09-06 13:04 --------- d-----w C:\Program Files\Ulead Systems
2007-09-06 13:04 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-09-06 13:03 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
2007-09-06 13:00 --------- d-----w C:\Program Files\Hemera
2007-09-06 12:58 --------- d-----w C:\Program Files\Windows Media Components
2007-09-05 23:22 289,144 ----a-w C:\WINDOWS\system32\VCCLSID.exe
2007-09-05 19:58 --------- d-----w C:\Program Files\Valve
2007-08-04 20:04 3,202,885 ---h--w C:\WINDOWS\youtube_converter.exe
2007-07-01 11:58:29 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007070120070702\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-03-03 21:41]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 14:49 C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43]
"nwiz"="nwiz.exe" [2006-08-11 21:43 C:\WINDOWS\system32\nwiz.exe]
"LPT LED Effect"="C:\Documents and Settings\pocitac\Plocha\net\llle\LLE.exe" [2005-10-02 00:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Virtual DAEMON Manager"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-12-10 15:57]
"LLE"="C:\Documents and Settings\pocitac\Plocha\net\llle\LLE.EXE" [2005-10-02 00:05]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49]
"OEXPRESS"="C:\WINDOWS\OETRN.EXE" [2013-06-07 19:32]
C:\Documents and Settings\pocitac\Nabídka Start\Programy\Po spuštění\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2013-05-18 16:02:58]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ball byte]
C:\DOCUME~1\pocitac\DATAAP~1\FORMOV~1\OnlineProxyPhone.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
R0 sojubus;sojubus;C:\WINDOWS\system32\DRIVERS\sojubus.sys
R0 sojuscsi;sojuscsi;C:\WINDOWS\system32\DRIVERS\sojuscsi.sys
R1 hwinterface;hwinterface;C:\WINDOWS\system32\Drivers\hwinterface.sys
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys
S3 Nvrcsew;Nvrcsew;C:\WINDOWS\system32\drivers\btcusb.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{606db9da-ece5-11db-80d5-00301b24a83b}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Open(0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6830b2ef-263c-11dc-818b-0011f6064dc7}]
AutoRun\command - M:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 16:16:59 C:\WINDOWS\Tasks\1-Click Maintenance.job"
"2013-06-22 17:09:48 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2013-06-22 17:09:47 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2013-06-22 17:54:10 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-28 21:22:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-28 21:23:45 - machine was rebooted
.
--- E O F ---