Tu je log zo CF:
Jedna poznámka: ESS bol zapnutý a našiel 1 test. súbor EICAR, uložil do karantény.
ComboFix 08-08-01.05 - Intel Core 2 Duo 2008-08-02 20:23:32.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1349 [GMT 2:00]
Running from: C:\Documents and Settings\Intel Core 2 Duo\Dokumenty\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-07-24 10:40 . 2008-07-24 10:43 <DIR> d-------- C:\Program Files\BitComet
2008-07-19 10:41 . 2008-07-19 10:41 <DIR> d-------- C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\QIP
2008-07-19 10:40 . 2008-07-19 10:44 <DIR> d-------- C:\Program Files\QIP Infium
2008-07-19 10:30 . 2008-07-19 10:30 <DIR> d-------- C:\Program Files\IrfanView
2008-07-14 19:31 . 2008-07-14 19:31 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-14 19:31 . 2008-07-14 19:31 <DIR> d-------- C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\SUPERAntiSpyware.com
2008-07-14 19:31 . 2008-07-14 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2008-07-12 20:23 . 2008-07-12 20:23 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Symantec
2008-07-10 19:40 . 2008-07-10 19:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-05 11:43 . 2008-07-05 11:43 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-05 11:42 . 2008-07-05 11:43 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-05 11:18 . 2006-01-10 16:50 24,576 --a------ C:\WINDOWS\system32\AsIO.dll
2008-07-05 11:18 . 2007-12-17 17:14 12,400 --a------ C:\WINDOWS\system32\drivers\AsIO.sys
2008-07-05 11:09 . 2008-07-05 11:09 <DIR> d-------- C:\Program Files\AoA Audio Extractor
2008-07-05 11:09 . 2008-07-05 11:20 <DIR> d-a------ C:\Documents and Settings\All Users\Data aplikací\TEMP
2008-07-05 10:19 . 2005-03-10 23:57 356,352 --a------ C:\WINDOWS\eSellerateEngine.dll
2008-07-05 10:19 . 2001-06-21 21:13 81,332 --a------ C:\WINDOWS\system32\BASS.DLL
2008-07-05 10:19 . 2005-06-18 19:21 7,436 --a------ C:\WINDOWS\system32\PulseSoundTouchForVB.tlb
2008-07-05 10:19 . 2008-07-05 10:19 56 --a------ C:\WINDOWS\system\Djsec63691.dll
2008-07-05 10:19 . 2008-07-05 10:19 55 --a------ C:\WINDOWS\system\Djsec61721.dll
2008-07-03 22:48 . 2008-07-03 22:48 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-07-03 16:37 . 2008-07-03 16:37 <DIR> d-------- C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 18:09 --------- d-----w C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\Skype
2008-08-02 17:05 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-08-02 16:54 --------- d-----w C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\LimeWire
2008-08-02 16:36 --------- d-----w C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\skypePM
2008-08-02 09:41 --------- d-----w C:\Program Files\SpeedFan
2008-07-27 06:24 --------- d-----w C:\Program Files\Java
2008-07-18 13:00 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2008-07-14 17:30 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-07 16:15 --------- d-----w C:\Program Files\Opera
2008-07-05 09:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-05 09:18 --------- d-----w C:\Program Files\ASUS
2008-07-01 14:47 --------- d-----w C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\ESET
2008-07-01 14:46 --------- d-----w C:\Program Files\ESET
2008-06-28 14:08 --------- d-----w C:\Program Files\Common Files\Java
2008-06-28 09:51 --------- d-----w C:\Program Files\Online TV Player 4
2008-06-27 18:51 --------- d-----w C:\Program Files\TrojanHunter 5.0
2008-06-27 18:07 --------- d-----w C:\Program Files\Skype
2008-06-27 18:07 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-27 18:07 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Skype
2008-06-25 16:14 --------- d-----w C:\Program Files\HD Tune
2008-06-22 16:07 --------- d-----w C:\Program Files\XP Codec Pack
2008-06-22 07:51 --------- d-----w C:\Program Files\The KMPlayer
2008-06-22 07:41 --------- d-----w C:\Program Files\Google
2008-06-21 18:35 --------- d-----w C:\Program Files\ViStart
2008-06-21 15:07 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-21 14:48 --------- d-----w C:\Program Files\Lavalys
2008-06-21 11:00 --------- d-----w C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\ViStart
2008-06-21 10:22 203,264 ----a-w C:\WINDOWS\system32\miss_februar_07.scr
2008-06-20 17:42 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 17:43 --------- d-----w C:\Documents and Settings\Intel Core 2 Duo\Data aplikací\uTorrent
2008-06-19 16:16 --------- d-----w C:\Program Files\MP3 Cutter
2008-06-19 15:04 --------- d-----w C:\Program Files\mp3DirectCut
2008-06-15 13:29 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Grisoft
2008-06-14 18:00 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 16:56 71,688 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-06-10 16:56 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-06-10 16:56 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-06-10 16:48 53,256 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-06-10 16:47 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-05-20 16:03 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-05-20 16:03 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-05-20 16:03 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-05-07 05:16 1,290,240 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 16:14 147456]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-27 18:28 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 15:54 21718312]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 18:43 8466432]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 18:43 81920]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-07-12 10:03 380928]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 14:44 36864]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [2006-10-30 14:44 1953792]
"TVdiag"="C:\PROGRA~1\Zoltrix\GenieTV\TVdiag.exe" [2001-08-17 11:25 158720]
"TVWDMDrv"="C:\WINDOWS\system32\drivers\tvwdmdrv.exe" [2001-06-18 11:01 194048]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 02:08 2512392]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"TVRemote"="C:\PROGRA~1\Zoltrix\GenieTV\TVREMOTE.exe" [2001-12-17 10:34 299008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-06-10 18:52 1447168]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"nwiz"="nwiz.exe" [2007-06-28 18:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 11:21 16270848 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"VIDC.FFDS"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Infogrames\\Grand Prix 4\\GP4.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22173:TCP"= 22173:TCP:BitComet 22173 TCP
"22173:UDP"= 22173:UDP:BitComet 22173 UDP
R2 BT848;BtCap, WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2000-04-28 11:35]
R2 BTTUNER;BtTuner, WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2001-06-18 15:00]
R2 BTXBAR;BtXBar, WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [1999-07-21 17:28]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-17 15:49]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 10:03]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-07-12 10:03]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-29 01:35]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-07-11 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:17]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.google.sk/
O8 -: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 -: E&xportovať do programu Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 -: {12345678-1234-1234-1234-1234567890AB}
O17 -: HKLM\CCS\Interface\{29EE0AF0-D9D8-48F1-866E-776D3DBEAC7B}: NameServer = 10.30.0.1
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-02 20:24:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-02 20:24:40
ComboFix-quarantined-files.txt 2008-08-02 18:24:27
Pre-Run: Volných bajtů: 27,229,634,560
Post-Run: Volných bajtů: 27,259,441,152
180 --- E O F --- 2008-07-18 13:00:47