A tu je combofix:
ComboFix 08-05-25.5 - bbb 2008-06-03 1:00:03.4 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1544 [GMT 2:00]
Running from: C:\Documents and Settings\bbb\Plocha\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-02 to 2008-06-02 )))))))))))))))))))))))))))))))
.
2008-06-01 22:37 . 2001-10-24 12:25 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2008-06-01 22:37 . 2001-10-24 12:25 138,752 --a--c--- C:\WINDOWS\system32\dllcache\sndvol32.exe
2008-06-01 22:05 . 2008-06-01 22:14 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-06-01 22:02 . 2008-06-01 22:02 <DIR> d-------- C:\Program Files\Softwin
2008-06-01 22:02 . 2008-06-01 22:14 <DIR> d-------- C:\Program Files\Common Files\Softwin
2008-06-01 22:02 . 2008-06-01 22:03 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\BitDefender
2008-06-01 21:47 . 2008-06-01 22:15 <DIR> d-------- C:\Documents and Settings\bbb\Data aplikací\SUPERAntiSpyware.com
2008-06-01 21:47 . 2008-06-01 21:47 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2008-06-01 21:19 . 2008-06-01 21:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-30 17:53 . 2008-05-30 17:53 19,344 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-05-30 17:40 . 2008-05-30 17:40 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-05-25 22:37 . 2008-05-25 22:37 1,917 --a------ C:\WINDOWS\imsins.BAK
2008-05-25 22:23 . 2001-10-24 11:58 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-05-25 22:22 . 2004-08-17 15:49 4,274,816 --a--c--- C:\WINDOWS\system32\dllcache\nv4_disp.dll
2008-05-25 22:21 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-05-25 22:20 . 2001-10-24 12:24 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-05-25 22:19 . 2001-08-17 21:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-05-25 22:18 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-05-25 22:17 . 2004-08-17 15:45 2,183,168 --a--c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-05-22 23:07 . 2008-05-22 23:12 <DIR> d-------- C:\Program Files\RegCleaner
2008-05-18 16:06 . 2008-05-25 17:16 151 --a------ C:\WINDOWS\PhotoSnapViewer.INI
2008-05-16 21:17 . 2008-05-16 21:17 <DIR> d-------- C:\OpenSSL
2008-05-16 21:17 . 2008-05-16 21:17 155,648 --a------ C:\WINDOWS\system32\libssl32.dll
2008-05-15 19:34 . 2008-05-15 19:34 <DIR> d-------- C:\Program Files\Nero
2008-05-14 22:07 . 2008-05-14 22:07 <DIR> d-------- C:\Documents and Settings\bbb\Data aplikací\vlc
2008-05-12 22:56 . 2008-05-12 22:56 <DIR> d-------- C:\Program Files\Invisible Browsing
2008-05-12 22:56 . 2008-05-12 23:10 54 --a------ C:\WINDOWS\MyProg.ini
2008-05-10 01:46 . 2008-05-10 01:46 <DIR> d-------- C:\Documents and Settings\bbb\Data aplikací\WNR
2008-05-08 23:18 . 2008-05-12 22:37 32 --a------ C:\WINDOWS\go
2008-05-08 23:15 . 2008-05-08 23:15 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-05 23:00 . 2008-05-05 23:00 <DIR> d-------- C:\Program Files\CCleaner
2008-05-04 00:51 . 2008-05-04 00:51 <DIR> d-------- C:\Documents and Settings\bbb\Data aplikací\JLC's Software
2008-05-03 01:50 . 2008-05-03 01:50 <DIR> d-------- C:\Documents and Settings\bbb\Data aplikací\Steganos Internet Anonym Pro 7
2008-05-02 01:37 . 2008-05-02 01:40 <DIR> d-------- C:\Program Files\Microsoft Bootvis
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 22:58 --------- d-----w C:\Documents and Settings\bbb\Data aplikací\Skype
2008-06-02 22:38 --------- d-----w C:\Documents and Settings\bbb\Data aplikací\Vso
2008-06-02 22:06 --------- d-----w C:\Documents and Settings\bbb\Data aplikací\skypePM
2008-05-25 15:14 --------- d-----w C:\Documents and Settings\bbb\Data aplikací\uTorrent
2008-05-15 17:37 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-15 17:26 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Nero
2008-05-14 20:07 --------- d-----w C:\Program Files\VideoLAN
2008-05-03 12:26 --------- d-----w C:\Program Files\ESET
2008-04-30 16:06 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Symantec
2008-04-30 15:52 --------- d-----w C:\Documents and Settings\bbb\Data aplikací\Symantec
2008-04-30 10:26 491,520 ----a-w C:\WINDOWS\WebIE.dll
2008-04-30 10:26 294,912 ----a-w C:\WINDOWS\TrnWord.dll
2008-04-30 10:25 516,096 ----a-w C:\WINDOWS\UN32.EXE
2008-04-12 20:05 --------- d-----w C:\Program Files\Opera
2008-04-12 11:22 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-12 11:22 47,360 ----a-w C:\Documents and Settings\bbb\Data aplikací\pcouffin.sys
2008-04-12 11:21 --------- d-----w C:\Program Files\vso
2008-04-12 09:46 --------- d-----w C:\Documents and Settings\bbb\Data aplikací\Any Video Converter
2008-04-12 08:38 81,920 ----a-w C:\Documents and Settings\bbb\Data aplikací\ezpinst.exe
2008-03-03 21:00 7,780 ----a-w C:\Documents and Settings\bbb\FMCodec.dat
2008-02-12 17:12 20,888 ----a-w C:\Documents and Settings\bbb\Data aplikací\GDIPFONTCACHEV1.DAT
2008-02-03 13:18 32 ----a-w C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-26_23.18.57,70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-26 19:30:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-02 18:56:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2002-04-17 13:05:32 45,056 ------w C:\WINDOWS\system32\CleanUp.exe
+ 2002-04-17 12:05:32 45,056 ------w C:\WINDOWS\system32\CleanUp.exe
- 2004-08-03 22:08:00 60,288 -c--a-w C:\WINDOWS\system32\dllcache\drmk.sys
+ 2004-08-03 21:08:00 60,288 -c--a-w C:\WINDOWS\system32\dllcache\drmk.sys
- 2004-08-03 22:15:22 140,928 -c--a-w C:\WINDOWS\system32\dllcache\ks.sys
+ 2004-08-03 21:15:22 140,928 -c--a-w C:\WINDOWS\system32\dllcache\ks.sys
- 2004-08-03 22:15:50 145,792 -c--a-w C:\WINDOWS\system32\dllcache\portcls.sys
+ 2004-08-03 21:15:50 145,792 -c--a-w C:\WINDOWS\system32\dllcache\portcls.sys
- 2004-08-03 22:08:04 48,640 -c--a-w C:\WINDOWS\system32\dllcache\stream.sys
+ 2004-08-03 21:08:04 48,640 -c--a-w C:\WINDOWS\system32\dllcache\stream.sys
- 2004-08-03 22:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
+ 2004-08-03 21:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
- 2004-08-03 22:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
+ 2004-08-03 21:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
- 2004-08-03 22:15:50 145,792 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
+ 2004-08-03 21:15:50 145,792 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
- 2004-08-03 22:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
+ 2004-08-03 21:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
- 2006-07-10 13:42:46 49,152 ------w C:\WINDOWS\system32\DSndUp.exe
+ 2006-07-10 12:42:46 49,152 ------w C:\WINDOWS\system32\DSndUp.exe
- 2001-09-11 13:20:50 1,285,632 ------w C:\WINDOWS\system32\SMMedia.dll
+ 2001-09-11 12:20:50 1,285,632 ------w C:\WINDOWS\system32\SMMedia.dll
- 2005-05-04 07:20:00 53,248 ------w C:\WINDOWS\system32\wdmioctl.dll
+ 2005-05-04 06:20:00 53,248 ------w C:\WINDOWS\system32\wdmioctl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 16:08 21686568]
"WEBTRAN"="" []
"OEXPRESS"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"Rapget"="C:\Documents and Settings\bbb\Plocha\RapGet 1.40\rapget.exe" [2007-10-07 19:51 171008]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 15:34 868352]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 03:48:00 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 02:01:00 734872]
ASUS WiFi-AP Solo.lnk - C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe [2008-01-28 11:03:01 987136]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2002-12-12 22:53:54 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"D:\\eMule\\emule.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"D:\\sdc212\\StrongDC.exe"=
"C:\\Strong DC++\\StrongDC.exe"=
"C:\\Program Files\\Invisible Browsing\\InvisibleBrowsing.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24496:TCP"= 24496:TCP:24496 TCP
"15456:UDP"= 15456:UDP:15456 UDP
R1 wfcxacap;WinFast TV PCI Audio Capture Driver;C:\WINDOWS\system32\DRIVERS\wfcxacap.sys [2007-09-19 12:09]
R2 wfcxatun;WinFast TV Analog Tuner Driver;C:\WINDOWS\system32\drivers\wfcxatun.sys [2007-09-19 14:37]
R2 WFCXVCAP;WinFast TV Video Capture Driver;C:\WINDOWS\system32\drivers\wfcxvcap.sys [2007-09-19 12:10]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 09:30]
R3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2006-03-31 05:39]
R3 wfcxdtun;WinFast DTV BDA Tuner/Demod Driver;C:\WINDOWS\system32\drivers\wfcxdtun.sys [2007-09-19 12:12]
R3 wfcxtcap;WinFast DTV BDA Transport Stream Capture Driver;C:\WINDOWS\system32\drivers\wfcxtcap.sys [2007-09-19 12:09]
R3 wfcxxbar;WinFast TV Crossbar Driver;C:\WINDOWS\system32\drivers\wfcxxbar.sys [2007-09-19 12:09]
S3 tap0901_2gm;VPN Anonymizer Adapter;C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 17:21]
S3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS [2005-01-06 17:55]
*Newly Created Service* - SJYPKT
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-03 01:01:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time: 2008-06-03 1:01:30
ComboFix-quarantined-files.txt 2008-06-02 23:01:26
ComboFix2.txt 2008-06-02 20:51:22
ComboFix3.txt 2008-06-02 20:45:35
ComboFix4.txt 2008-05-26 21:19:11
Adresářů: 12, Volných bajtů: 11,152,375,808
Adresářů: 15, Volných bajtů: 11,247,972,352
168 --- E O F --- 2008-02-02 09:45:20