Proszę.
# ComboFix 08-08-08.08 - domownicy 2008-08-09 16:54:16.2 - NTFSx86
# Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.538 [GMT 2:00]
# Running from: E:\ComboFix.exe
# * Created a new restore point
# * Resident AV is active
#
#
#
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!# .
#
# ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
# .
#
# C:\WINDOWS\system32\actskn43.ocx
# C:\WINDOWS\system32\dcadfdac3_z.dll
#
# .
# ((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
# .
#
# 2008-08-09 15:11 . 2008-08-09 15:11<DIR>d--------C:\Program Files\ToniArts
# 2008-08-09 15:02 . 2008-08-09 15:0223--a------C:\WINDOWS\system32\acdcda7_z.ocx
# 2008-08-09 13:23 . 2008-08-09 14:03<DIR>d--------C:\Program Files\Yahoo!
# 2008-08-09 13:23 . 2008-08-09 13:24<DIR>d--------C:\Program Files\CCleaner
# 2008-08-07 18:04 . 2008-08-07 18:04<DIR>d--------C:\Program Files\Trojan Remover
# 2008-08-07 18:04 . 2008-08-07 18:04<DIR>d--------C:\Documents and Settings\domownicy\Dane aplikacji\Simply Super Software
# 2008-08-07 18:04 . 2008-08-07 18:04<DIR>d--------C:\Documents and Settings\All Users\Dane aplikacji\Simply Super Software
# 2008-08-07 18:04 . 2006-05-25 15:52162,304--a------C:\WINDOWS\system32\ztvunrar36.dll
# 2008-08-07 18:04 . 2003-02-02 20:06153,088--a------C:\WINDOWS\system32\UNRAR3.dll
# 2008-08-07 18:04 . 2005-08-26 01:5077,312--a------C:\WINDOWS\system32\ztvunace26.dll
# 2008-08-07 18:04 . 2006-06-19 13:0169,632--a------C:\WINDOWS\system32\ztvcabinet.dll
# 2008-08-04 18:53 . 2008-08-04 18:53280--a------C:\WINDOWS\game.ini
# 2008-08-04 14:19 . 2008-08-04 14:20<DIR>d--------C:\Program Files\SnadBoy's Revelation v2
# 2008-08-03 17:20 . 2008-08-03 17:20<DIR>d--------C:\Program Files\RubyMicro Software
# 2008-08-03 16:44 . 2008-08-03 16:44<DIR>d--------C:\Program Files\SymplisIT
# 2008-08-03 14:41 . 2006-08-01 15:0249,152--a------C:\WINDOWS\system32\ChCfg.exe
# 2008-08-03 14:40 . 2008-08-03 14:40<DIR>d--------C:\Program Files\Realtek AC97
# 2008-08-03 13:36 . 2008-08-03 13:36<DIR>d--------C:\Program Files\Lavalys
# 2008-08-02 16:23 . 2008-08-09 13:57<DIR>d--------C:\Program Files\Proste Faktury
# 2008-08-02 10:53 . 2008-08-02 10:53<DIR>d--------C:\Expert Lotto
# 2008-08-02 10:53 . 2000-01-24 05:012,023,424--a------C:\WINDOWS\system32\VCL50.BPL
# 2008-08-02 10:53 . 1999-03-23 09:12299,520--a------C:\WINDOWS\uninst.exe
# 2008-08-01 17:32 . 2008-08-01 17:32<DIR>d--------C:\Program Files\SAGEM
# 2008-07-28 15:15 . 2008-07-28 15:16<DIR>d--------C:\Program Files\PractiCount and Invoice (Standard)
# 2008-07-28 15:15 . 2005-11-14 21:00383,488--a------C:\WINDOWS\system32\midas.dll
# 2008-07-28 15:15 . 2008-04-26 23:06214,528--a------C:\WINDOWS\system32\PCountStCME.dll
# 2008-07-28 15:05 . 2008-07-28 15:14<DIR>d--------C:\Program Files\ExpertLotto
# 2008-07-20 14:48 . 2008-07-20 14:480--a------C:\WINDOWS\ativpsrm.bin
# 2008-07-20 14:45 . 2008-07-20 14:45<DIR>d--------C:\ATI
# 2008-07-19 14:49 . 2008-08-05 17:00<DIR>d--------C:\!mw
# 2008-07-19 14:14 . 2008-08-09 16:54<DIR>d--h-----C:\$AVG8.VAULT$
# 2008-07-19 13:56 . 2008-08-08 16:52<DIR>d--------C:\WINDOWS\system32\drivers\Avg
# 2008-07-19 13:56 . 2008-07-19 13:56<DIR>d--------C:\Program Files\AVG
# 2008-07-19 13:56 . 2008-07-19 13:56<DIR>d--------C:\Documents and Settings\All Users\Dane aplikacji\avg8
# 2008-07-19 13:56 . 2008-07-19 15:2296,520--a------C:\WINDOWS\system32\drivers\avgldx86.sys
# 2008-07-19 13:56 . 2008-07-19 15:2276,040--a------C:\WINDOWS\system32\drivers\avgtdix.sys
# 2008-07-19 13:56 . 2008-07-19 15:2210,520--a------C:\WINDOWS\system32\avgrsstx.dll
# 2008-07-19 13:50 . 2008-07-20 14:45<DIR>d--------C:\Instale
# 2008-07-15 18:10 . 2008-07-15 18:15<DIR>d--------C:\Program Files\Anti Trojan Elite
# 2008-07-14 16:11 . 2008-08-08 16:52<DIR>d-a------C:\Documents and Settings\All Users\Dane aplikacji\TEMP
# 2008-07-14 16:10 . 2002-03-06 01:0075,264--a------C:\WINDOWS\system32\unacev2.dll
# 2008-07-13 16:33 . 2008-07-13 16:33<DIR>d--------C:\Program Files\Trend Micro
#
# .
# (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
# .
# 2008-08-09 13:54---------d-----wC:\Program Files\FlashGet
# 2008-08-09 13:11---------d--h--wC:\Program Files\InstallShield Installation Information
# 2008-08-09 12:10---------d-----wC:\Program Files\EA GAMES
# 2008-08-09 12:06---------d-----wC:\Program Files\UselessCreations
# 2008-08-09 12:06---------d-----wC:\Program Files\Mad Tracks
# 2008-08-09 12:05---------d-----wC:\Program Files\Activision
# 2008-08-09 12:04---------d-----wC:\Program Files\Best Friends Free Trial
# 2008-08-09 12:03---------d-----wC:\Program Files\Wolfenstein - Enemy Territory
# 2008-08-09 12:03---------d-----wC:\Program Files\1-abc
# 2008-08-09 12:01---------d-----wC:\Program Files\Skoki narciarskie 2004
# 2008-08-09 11:59---------d-----wC:\Program Files\Skype
# 2008-08-09 11:57---------d-----wC:\Program Files\PacMan Adventures 3D
# 2008-08-09 11:57---------d-----wC:\Program Files\Gadu-Gadu
# 2008-08-09 11:46---------d-----wC:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
# 2008-08-05 12:31---------d-----wC:\Documents and Settings\domownicy\Dane aplikacji\OpenOffice.org2
# 2008-07-19 11:59---------d-----wC:\Program Files\Java
# 2008-07-19 11:57---------d-----wC:\Program Files\Common Files\Adobe
# 2008-07-19 11:53---------d-----wC:\Program Files\Spybot - Search & Destroy
# 2008-07-07 13:16---------d-----wC:\Documents and Settings\Gość\Dane aplikacji\GHISLER
# 2008-06-27 20:18---------d-----wC:\Program Files\long range shooting
# 2008-06-20 17:42246,784----a-wC:\WINDOWS\system32\mswsock.dll
# 2008-06-20 10:45360,320----a-wC:\WINDOWS\system32\drivers\tcpip.sys
# 2008-06-20 10:44138,368----a-wC:\WINDOWS\system32\drivers\afd.sys
# 2008-06-20 09:52225,920----a-wC:\WINDOWS\system32\drivers\tcpip6.sys
# 2008-06-16 18:46---------d-----wC:\Program Files\Qtracker
# 2008-06-16 16:36---------d-----wC:\Program Files\Reference Assemblies
# 2008-06-16 16:36---------d-----wC:\Program Files\MSBuild
# 2008-06-16 16:26---------d-----wC:\Program Files\MSXML 6.0
# 2008-06-16 15:07---------d-----wC:\Documents and Settings\Damian\Dane aplikacji\OpenOffice.org2
# 2008-06-16 13:51---------d-----wC:\Documents and Settings\domownicy\Dane aplikacji\Uniblue
# 2008-06-14 18:01273,024------wC:\WINDOWS\system32\drivers\bthport.sys
# 2008-06-13 14:08---------d-----wC:\Program Files\ElcomSoft
# 2008-06-11 01:03---------d-----wC:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
# 2008-06-03 03:4610,276,864----a-wC:\WINDOWS\system32\atioglx2.dll
# 2008-06-03 03:22413,696----a-wC:\WINDOWS\system32\ATIDEMGX.dll
# 2008-06-03 03:21306,688----a-wC:\WINDOWS\system32\ati2dvag.dll
# 2008-06-03 03:1143,520----a-wC:\WINDOWS\system32\ati2edxx.dll
# 2008-06-03 03:1126,112----a-wC:\WINDOWS\system32\Ati2mdxx.exe
# 2008-06-03 03:11180,224----a-wC:\WINDOWS\system32\atipdlxx.dll
# 2008-06-03 03:11139,264----a-wC:\WINDOWS\system32\Oemdspif.dll
# 2008-06-03 03:11139,264----a-wC:\WINDOWS\system32\ati2evxx.dll
# 2008-06-03 03:09552,960----a-wC:\WINDOWS\system32\ati2evxx.exe
# 2008-06-03 03:0853,248----a-wC:\WINDOWS\system32\ATIDDC.DLL
# 2008-06-03 03:04245,760----a-wC:\WINDOWS\system32\atiok3x2.dll
# 2008-06-03 03:02307,200----a-wC:\WINDOWS\system32\atiiiexx.dll
# 2008-06-03 02:593,500,352----a-wC:\WINDOWS\system32\ati3duag.dll
# 2008-06-03 02:482,120,832----a-wC:\WINDOWS\system32\ativvaxx.dll
# 2008-06-03 02:3348,128----a-wC:\WINDOWS\system32\amdpcom32.dll
# 2008-06-03 02:29348,160----a-wC:\WINDOWS\system32\atikvmag.dll
# 2008-06-03 02:2823,040----a-wC:\WINDOWS\system32\atiadlxx.dll
# 2008-06-03 02:2817,408----a-wC:\WINDOWS\system32\atitvo32.dll
# 2008-06-03 02:225,439,488----a-wC:\WINDOWS\system32\atioglxx.dll
# 2008-06-03 02:21557,056----a-wC:\WINDOWS\system32\ati2cqag.dll
# 2008-06-02 19:05593,920------wC:\WINDOWS\system32\ati2sgag.exe
# 2006-12-13 20:3334----a-wC:\Documents and Settings\All Users\Dane aplikacji\amlistx.dat
# 2006-12-13 20:330----a-wC:\Documents and Settings\domownicy\Dane aplikacji\amopn.dat
# 2006-11-12 13:15368,678----a-wC:\Program Files\Nowe miasto.sc3
# 2005-12-02 21:282,678,784----a-wC:\Program Files\Foxit Reader.exe
# .
#
# ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
# .
# .
# *Note* empty entries & legit default entries are not shown
# REGEDIT4
#
# [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
# "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
# "ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-07-29 15:41 1213680]
#
# [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
# "PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 16:24 86016]
# "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-19 15:22 1232152]
# "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-13 21:20 98304]
# "SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe]
#
# [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
# "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
#
# C:\Documents and Settings\Damian\Menu Start\Programy\Autostart\
# OpenOffice.org 2.0.2.lnk - C:\Program Files\OpenOffice.org 2.0.2\program\quickstart.exe [2006-03-12 01:12:44 393216]
#
# [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
# "AppInit_DLLs"=avgrsstx.dll
#
# [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
# path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
# backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
#
# [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
# path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
# backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
#
# [HKLM\~\startupfolder\^.antileechdir]
# path=\.antileechdir
# backup=C:\WINDOWS\pss\.antileechdirCommon Startup
#
# [HKLM\~\startupfolder\^NTUSER.DAT]
# path=\NTUSER.DAT
# backup=C:\WINDOWS\pss\NTUSER.DATCommon Startup
#
# [HKLM\~\startupfolder\^ntuser.dat.LOG]
# path=\ntuser.dat.LOG
# backup=C:\WINDOWS\pss\ntuser.dat.LOGCommon Startup
#
# [HKLM\~\startupfolder\^ntuser.ini]
# path=\ntuser.ini
# backup=C:\WINDOWS\pss\ntuser.iniCommon Startup
#
# [HKLM\~\startupfolder\^regupdate.ini]
# path=\regupdate.ini
# backup=C:\WINDOWS\pss\regupdate.iniCommon Startup
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
# ??? [?]
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
# ??? [?]
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\system_tray]
# shutdown -r -f -t 0 [X]
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
# --a------ 2007-05-04 02:32 961024 C:\Program Files\Ares\Ares.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
# --a------ 2004-08-04 00:44 15360 C:\WINDOWS\system32\ctfmon.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
# --a------ 2008-03-20 12:04 2127296 C:\Program Files\Gadu-Gadu\Gadu-Gadu\gg.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
# --a------ 2005-05-12 00:12 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImagePath]
# --a------ 2008-07-04 16:47 64 C:\WINDOWS\system_32.bat
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
# --a------ 2007-07-13 21:20 98304 C:\Program Files\QuickTime\qttask.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
# --a------ 2005-03-04 03:36 36975 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
# --a------ 2005-06-06 21:04 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
# --a------ 2008-06-03 20:33 878672 C:\Program Files\Trojan Remover\Trjscan.exe
#
# [HKEY_LOCAL_MACHINE\software\microsoft\security center]
# "AntiVirusOverride"=dword:00000001
#
# [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
# "%windir%\\system32\\sessmgr.exe"=
# "C:\\Program Files\\Ares\\Ares.exe"=
# "C:\\Program Files\\Shareaza\\Shareaza.exe"=
# "C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
# "C:\\Program Files\\Gadu-Gadu\\Gadu-Gadu\\gg.exe"=
# "C:\\Program Files\\Gadu-Gadu\\gg.exe"=
# "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
# "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
# "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
# "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
#
# R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-19 15:22]
# R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-19 15:22]
# R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 15:22]
# R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-19 15:22]
# S3 ATE_PROCMON;ATE_PROCMON;C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
#
# *Newly Created Service* - PROCEXP90
# .
# .
# ------- Supplementary Scan -------
# .
# FireFox -: Profile - C:\Documents and Settings\domownicy\Dane aplikacji\Mozilla\Firefox\Profiles\w5xvsf6e.default\
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPJava11.dll
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPJava12.dll
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPJava13.dll
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPJava14.dll
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPJava32.dll
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
# FF -: plugin - C:\Program Files\Java\jre1.5.0_02\bin\NPOJI610.dll
# FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
# FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
#
#
# **************************************************************************
#
# catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
# Rootkit scan 2008-08-09 16:55:48
# Windows 5.1.2600 Dodatek Service Pack 2 NTFS
#
# scanning hidden processes ...
#
# scanning hidden autostart entries ...
#
# scanning hidden files ...
#
# scan completed successfully
# hidden files: 0
#
# **************************************************************************
#
# [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AudioSrv]
# "ImagePath"="net user %username% 9314 "
# .
# Completion time: 2008-08-09 16:58:13
# ComboFix-quarantined-files.txt 2008-08-09 14:58:06
# ComboFix2.txt 2008-07-13 15:05:29
#
# Pre-Run: 32,167,997,440 bajtów wolnych
# Post-Run: 32,171,122,688 bajtów wolnych
#
# 233--- E O F ---2008-07-18 00:43:18
P.S dawno tu nie byłem, a wtedy były inne zasady
