Ahoj ještě jednou,
moc díky.
Logy přikládám níže ze všech tří utilitek. Oba soubory jsem otestoval, winstart.bat je čistý a casino.exe asi ve čtyřech testovacích antivirech hodil podezření...předpokládám, že bych ho měl smazat, ale radši už nedělám nic, co nedostanu příkazem

.
Jinak symptomy (pomalý net) zmizely, ale...teď to projíždím Malwarebytes Antimalwarem znovu, a zase to něco našlo...:
Malwarebytes' Anti-Malware 1.31
Verze databáze: 1550
Windows 5.1.2600 Service Pack 2
27.12.2008 21:23:04
mbam-log-2008-12-27 (21-23-00).txt
Typ skenu: Úplný sken (C:\|)
Objektu skenováno: 94497
Uplynulý cas: 13 minute(s), 10 second(s)
Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 11
Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)
Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)
Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované složky:
(Žádné zákerné položky nebyly zjišteny)
Infikované soubory:
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138468.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138469.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138471.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138472.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138473.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138476.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138477.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP606\A0138478.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP611\A0139250.sys (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP611\A0139251.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{8C39F97A-8A53-4399-9350-3C2A806ED9D3}\RP611\A0139252.sys (Trojan.TDSS) -> No action taken.
Musel jsem vyzkoušet několik způsobů, jak ten adresář zpřístupnit, Microsoftí KB samozřejmě nefungovalo (nakonec přes cacls) :-/, tak jsem je zrušil.
Jinak disky jsou mechanika, druhý HDD, flash, daemontoolsy, foťák...nic víc si nevzpomínám

Logy zde:
______________________________________________________________________
Avenger:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.comPlatform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\WINDOWS\system32\drivers\TDSSmhlt.sys" deleted successfully.
File "C:\WINDOWS\system32\drivers\TDSSmqlt.sys" deleted successfully.
File "C:\WINDOWS\system32\drivers\glaide32.sys" deleted successfully.
File "C:\WINDOWS\system32\syssetub.dll" deleted successfully.
File "C:\Program Files\Common Files\Microsoft Shared\MSInfo\System36.jup" deleted successfully.
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSmhlt" not found!
Deletion of driver "TDSSmhlt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSmqlt" not found!
Deletion of driver "TDSSmqlt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Driver "glaide32" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
_________________________________________________________________
HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 20:55:36, on 27.12.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Util\CooL Wallpaper Changer\coolwpc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Util\SpeedFan\speedfan.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Util\CZ\CZDCPlusPlus.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\DVBViewer\Scheduler.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\DVBViewer\DVBViewer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BSplayer\bsplayer.exe
C:\Util\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKCU\..\Run: [TClockEx] C:\Util\TClockEx\TCLOCKEX.EXE
O4 - HKCU\..\Run: [CooLWPC3] C:\Util\CooL Wallpaper Changer\coolwpc.exe /boot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Startup: SpeedFan.lnk = C:\Util\SpeedFan\speedfan.exe
O4 - Startup: Total Commander.lnk = C:\Program Files\totalcmd\TOTALCMD.EXE
O4 - Startup: Zástupce - CZDCPlusPlus.lnk = C:\Util\CZ\CZDCPlusPlus.exe
O4 - Startup: Zástupce - daemon.lnk = C:\Program Files\DAEMON Tools\daemon.exe
O4 - Startup: Zástupce - Scheduler.lnk = C:\Program Files\DVBViewer\Scheduler.exe
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.srtest.com/srl_bin/sysreqlab_srl.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemrequirementslab.com/sysreqlab2.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su2/CTL_V02002/ocx/15033/CTPID.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logmein.com/activex/ractrl.cab?lmi=100O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Ad-Aware\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: cisvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: ups - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
______________________________________________________________________--
No a ComboFix:
ComboFix 08-12-26.03 - ML 2008-12-27 20:58:10.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.3582.2944 [GMT 1:00]
Spuštěný z: c:\documents and settings\ML\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!.
((((((((((((((((((((((((( Soubory vytvořené od 2008-11-27 do 2008-12-27 )))))))))))))))))))))))))))))))
.
2008-12-27 19:14 . 2008-12-27 19:14 <DIR> d-------- c:\documents and settings\ML\Data aplikací\Malwarebytes
2008-12-27 19:14 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-27 19:13 . 2008-12-27 19:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-27 19:13 . 2008-12-27 19:13 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2008-12-27 19:13 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-27 18:25 . 2008-12-27 18:25 90 --a------ c:\windows\system32\Partizan.RRI
2008-12-27 17:34 . 2008-12-27 18:07 <DIR> d-------- c:\windows\RestoreSafeDeleted
2008-12-27 17:19 . 2008-12-27 17:20 <DIR> d-------- C:\RootkitNO
2008-12-27 17:17 . 2008-12-27 18:27 <DIR> d-------- c:\program files\UnHackMe
2008-12-27 17:17 . 2008-12-27 17:17 (2) -rahs-ot- c:\windows\winstart.bat
2008-12-27 17:16 . 2008-12-27 20:58 4,144 --a------ c:\windows\system32\PerfStringBackup.TMP
2008-12-27 16:02 . 2008-12-27 16:02 <DIR> d-------- c:\program files\Network Traffic Monitor
2008-12-27 16:02 . 2004-05-20 13:19 193,768 --a------ c:\windows\system32\csdnsapi.dll
2008-12-27 16:02 . 2004-05-20 13:19 165,088 --a------ c:\windows\system32\cswhoapi.dll
2008-12-27 16:02 . 2008-01-08 08:47 45,056 --a------ c:\windows\system32\SETHOOK.DLL
2008-12-27 14:35 . 2008-12-27 14:35 <DIR> d-------- c:\windows\system32\oobe
2008-12-27 14:35 . 2008-12-27 14:35 <DIR> d-------- c:\windows\srchasst
2008-12-27 14:28 . 2008-12-27 14:28 <DIR> d-------- c:\documents and settings\ML\Data aplikací\TuneUp Software
2008-12-27 14:28 . 2008-12-27 14:28 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\TuneUp Software
2008-12-27 14:27 . 2008-12-27 14:27 <DIR> d--hs---- c:\documents and settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
2008-12-27 10:23 . 2008-12-27 10:23 <DIR> d-------- c:\windows\system32\config\systemprofile\Data aplikací\AVGTOOLBAR
2008-12-27 10:23 . 2008-12-27 10:23 <DIR> d-------- c:\windows\system32\config\systemprofile\Data aplikací\AVGTOOLBAR
2008-12-27 10:23 . 2008-12-27 10:23 39,936 --a------ c:\windows\system32\config\systemprofile\Data aplikací\casino.exe
2008-12-27 10:23 . 2008-12-27 10:23 39,936 --a------ c:\windows\system32\config\systemprofile\Data aplikací\casino.exe
2008-12-26 21:27 . 2008-12-26 21:27 68,352 --a------ c:\windows\system32\CBEVTSVC.del
2008-12-26 21:27 . 2008-12-26 21:27 33,280 --a------ c:\windows\system32\CRYPTS.DLL.del
2008-12-26 11:37 . 2008-12-26 11:38 <DIR> d-------- c:\program files\Security Task Manager
2008-12-26 11:37 . 2008-12-26 11:38 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\SecTaskMan
2008-12-25 22:39 . 2008-12-26 10:28 <DIR> d-------- c:\program files\Ad-Aware
2008-12-25 22:38 . 2008-12-25 22:38 <DIR> d-------- c:\program files\Lavasoft
2008-12-11 16:33 . 2008-12-11 16:33 <DIR> d-------- c:\windows\Samsung
2008-12-11 16:33 . 2008-02-24 04:56 479,232 --a------ c:\windows\ssndii.exe
2008-12-11 16:33 . 2007-02-13 10:30 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-11 16:33 . 2007-02-13 10:29 21,776 --a------ c:\windows\system32\msxml2a.dll
2008-12-11 16:33 . 2007-03-05 09:09 11,502 --------- c:\windows\Dr. Printer Icon.ico
2008-12-11 16:28 . 2008-12-11 16:28 <DIR> d-------- c:\windows\system32\drivers\Samsung
2008-12-11 16:28 . 2008-12-11 16:28 <DIR> d-------- c:\program files\Samsung
2008-12-11 16:28 . 2007-02-09 02:21 151,552 --a------ c:\windows\system32\ml163sci.exe
2008-12-11 16:28 . 2007-02-09 02:21 65,536 --a------ c:\windows\system32\ml163sci.dll
2008-12-11 16:28 . 2007-03-05 09:11 41,984 --------- c:\windows\system32\drivers\DGIVECP.SYS
2008-12-11 16:28 . 2007-02-09 02:22 22,723 --a------ c:\windows\system32\ml163sl3.dll
2008-12-11 16:28 . 2007-02-09 02:22 520 --a------ c:\windows\system32\ml163sl3.smt
2008-12-11 16:17 . 2008-12-11 16:17 <DIR> d--h----- c:\documents and settings\All Users\Data aplikací\CanonIJScan
2008-12-11 16:16 . 2008-12-11 16:16 <DIR> d--h----- c:\windows\system32\CanonIJ Uninstaller Information
2008-12-11 16:15 . 2008-12-11 16:15 <DIR> d--h----- c:\program files\CanonBJ
2008-12-11 16:15 . 2008-04-07 15:58 1,339,392 --a------ c:\windows\system32\CNQ2413C.DLL
2008-12-11 16:15 . 2008-05-02 10:13 585,728 --a------ c:\windows\system32\CNQ2413L.DLL
2008-12-11 16:15 . 2007-03-15 15:12 188,416 --a------ c:\windows\system32\CNQ2413O.DLL
2008-12-11 16:15 . 2008-04-07 15:58 98,304 --a------ c:\windows\system32\CNQ2413I.DLL
2008-12-08 17:59 . 2008-12-08 17:59 <DIR> d-------- c:\documents and settings\ML\WINDOWS
2008-12-08 17:59 . 1996-11-05 16:13 299,008 --a------ c:\windows\uninst.exe
2008-12-05 18:17 . 2008-12-27 20:54 <DIR> d--h----- C:\$AVG8.VAULT$
2008-11-28 17:34 . 2008-11-28 17:34 <DIR> d-------- c:\program files\DreamCatcher
2008-11-28 17:33 . 2003-03-15 23:15 90,112 --a------ c:\windows\unvise32.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 18:12 --------- d-----w c:\documents and settings\ML\Data aplikací\uTorrent
2008-12-27 09:21 --------- d-----w c:\program files\LogMeIn
2008-12-26 10:45 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-25 21:40 15,648 ----a-w c:\windows\system32\drivers\NSDriver.sys
2008-12-25 21:40 15,648 ----a-w c:\windows\system32\drivers\AWRTRD.sys
2008-12-25 21:40 12,960 ----a-w c:\windows\system32\drivers\AWRTPD.sys
2008-12-25 21:39 --------- d-----w c:\documents and settings\All Users\Data aplikací\Lavasoft
2008-12-20 13:19 --------- d-----w c:\documents and settings\All Users\Data aplikací\Codemasters
2008-12-18 19:00 --------- d-----w c:\documents and settings\ML\Data aplikací\Creative
2008-12-15 16:15 --------- d-----w c:\program files\Hewlett-Packard
2008-11-15 21:46 --------- d-----w c:\documents and settings\ML\Data aplikací\Skype
2008-11-15 15:58 --------- d-----w c:\documents and settings\ML\Data aplikací\skypePM
2008-11-15 15:32 --------- d-----w c:\documents and settings\All Users\Data aplikací\Microsoft Help
2008-11-12 12:45 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
2008-11-01 13:34 --------- d-----w c:\program files\MSBuild
2008-11-01 13:32 --------- d-----w c:\program files\Reference Assemblies
2008-10-29 19:00 319,488 ----a-w c:\windows\HideWin.exe
2008-10-29 19:00 --------- d-----w c:\program files\Realtek
2008-10-29 18:12 98,304 ----a-w c:\windows\DUMP9ff9.tmp
2008-10-28 10:42 --------- d-----w c:\program files\SystemRequirementsLab
2008-10-27 18:50 --------- d-----w c:\documents and settings\ML\Data aplikací\U3
2008-10-27 09:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-25 17:12 98,304 ----a-w c:\windows\DUMP9b46.tmp
2008-10-17 19:03 87,352 ----a-w c:\windows\system32\LMIinit.dll
2008-10-17 19:03 83,288 ----a-w c:\windows\system32\LMIRfsClientNP.dll
2008-10-17 19:03 28,984 ----a-w c:\windows\system32\LMIport.dll
2008-10-17 19:03 23,736 ----a-w c:\windows\system32\lmimirr.dll
2008-10-17 19:03 10,040 ----a-w c:\windows\system32\lmimirr2.dll
2008-10-17 06:08 98,304 ----a-w c:\windows\DUMP9f8b.tmp
2008-10-13 08:56 70,936 ----a-w c:\windows\system32\PhysXLoader.dll
2008-10-10 03:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
2008-10-09 17:42 505,128 ----a-w c:\windows\system32\msvcp71.dll
2008-10-09 17:42 353,576 ----a-w c:\windows\system32\msvcr71.dll
2008-10-09 17:17 29,480 ----a-w c:\windows\system32\msxml3a.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelTraditionalChinese.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelSwedish.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelSpanish.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelSimplifiedChinese.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelPortugese.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelKorean.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelJapanese.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelGerman.dll
2008-10-07 08:13 58,648 ----a-w c:\windows\system32\AgCPanelFrench.dll
2008-10-07 08:13 288,024 ----a-w c:\windows\system32\PhysXCplUI.exe
2008-10-07 08:13 288,024 ----a-w c:\windows\system32\PhysXCompatCplUI.exe
2008-10-07 08:13 23,320 ----a-w c:\windows\system32\PhysXDevice.dll
2008-06-27 19:00 21 ----a-w c:\documents and settings\All Users\Data aplikací\emopts.dat
2008-06-27 19:00 133 ---ha-w c:\documents and settings\All Users\Data aplikací\ML-acu.dat
2008-06-27 18:59 73 ---h--w c:\documents and settings\All Users\Data aplikací\acopts.dat
2008-06-27 18:59 142 ---h--w c:\documents and settings\All Users\Data aplikací\ML-acopts.dat
2008-05-11 10:51 22,328 ----a-w c:\documents and settings\ML\Data aplikací\PnkBstrK.sys
2008-01-04 17:58 32 ----a-w c:\documents and settings\All Users\Data aplikací\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-12-27_18.18.16.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-27 19:53:50 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_768.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TClockEx"="c:\util\TClockEx\TCLOCKEX.EXE" [2000-03-09 89088]
"CooLWPC3"="c:\util\CooL Wallpaper Changer\coolwpc.exe" [2003-04-06 1008128]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"Norton Ghost 9.0"="c:\program files\Norton Ghost\Agent\GhostTray.exe" [2004-07-29 1122304]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2008-02-23 536576]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 c:\windows\system32\bthprops.cpl]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 c:\windows\RTHDCPL.exe]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 c:\windows\SoundMan.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\ML\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-12-23 692224]
SpeedFan.lnk - c:\util\SpeedFan\speedfan.exe [2008-04-22 3287552]
Total Commander.lnk - c:\program files\totalcmd\TOTALCMD.EXE [2007-12-01 1074896]
Z stupce - CZDCPlusPlus.lnk - c:\util\CZ\CZDCPlusPlus.exe [2008-01-03 2416640]
Z stupce - daemon.lnk - c:\program files\DAEMON Tools\daemon.exe [2007-12-19 486856]
Z stupce - Scheduler.lnk - c:\program files\DVBViewer\Scheduler.exe [2007-12-03 229888]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02 546288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 20:03 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
"vidc.divx32"= divxc32.dll
"vidc.divx32f"= divxc32f.dll
"msacm.l3radius"= l3codecp.acm
"msacm.divxa"= divxa32.acm
"msacm.PLCMg722"= PLCMg722.acm
"msacm.PLCMg728"= PLCMg728.acm
"msacm.PLCMg729A"= PLCMg729A.acm
"msacm.PLCMsiren"= PLCMsiren.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools\daemon.exe"
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"ICQ"="c:\program files\ICQ6\ICQ.exe" silent
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AlcWzrd"=ALCWZRD.EXE
"BDRegion"=c:\program files\Cyberlink\Shared Files\brs.exe
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe"
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe"
"ReminderApp"=c:\program files\Scrapbook Factory Deluxe 4.0\ReminderApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-07-29 138780]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-05-16 97928]
R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\Cinemsup.sys [2002-07-19 6656]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-07-29 46779]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};\??\c:\program files\CyberLink\PowerDVD\
000.fcl [2007-11-03 00:12:32 41456]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\
000.fcl [2008-08-08 09:15:56 41456]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-16 231704]
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\LMIRfsDriver.sys [2008-06-26 47640]
R3 FStarForce;FStarForce;c:\windows\system32\DRIVERS\FStarForce.sys [2008-11-01 9216]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\DRIVERS\psched.sys [2004-08-03 69120]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\DRIVERS\SkyNET.SYS [2007-12-01 343040]
R3 V0260VID;Live! Cam Vista IM;c:\windows\system32\DRIVERS\V0260Vid.sys [2007-12-25 178913]
S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2007-12-01 75925]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys []
S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;c:\windows\system32\drivers\wf2ktunr.sys [2007-12-01 36423]
S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;c:\windows\system32\drivers\wf2kxbar.sys [2007-12-01 10005]
S3 FlyPCI;FlyPCI;\??\c:\windows\system32\drivers\FlyPCI.sys [2007-12-02 4134]
S4 LMIRfsClientNP;LMIRfsClientNP; []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de22e28b-7fdc-11dd-99b8-0013d37d1cd8}]
\shell\autorun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system.exe
\shell\explore\command - K:\system.exe
\shell\open\command - K:\system.exe
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.cz/mStart Page = about:blank
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\sysreqlab3.dll - c:\windows\Downloaded Program Files\sysreqlab_srl.dll
O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cabc:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-27 20:59:22
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\tlntsvr]
"ImagePath"=""
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\
000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1980)
c:\windows\system32\avgrsstx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'lsass.exe'(260)
c:\windows\system32\avgrsstx.dll
.
Celkový čas: 2008-12-27 20:59:55
ComboFix-quarantined-files.txt 2008-12-27 19:59:44
ComboFix2.txt 2008-12-27 17:18:39
Před spuštěním: Volných bajtů: 13 735 854 080
Po spuštění: Volných bajtů: 13,719,437,312
258