
Dlatego proszę o pomoc w zlokalizowaniu niepotrzebnych plików.
Log z ComboFix:
- Kod: Zaznacz wszystko
ComboFix 08-07-10.1 - Misiu 2008-07-11 16:08:47.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.163 [GMT 2:00]
Running from: C:\Documents and Settings\Misiu\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-06-11 to 2008-07-11 )))))))))))))))))))))))))))))))
.
2008-07-11 16:02 . 2008-07-11 16:03 <DIR> d-------- C:\327882R2FWJFW
2008-07-11 11:06 . 2008-07-11 11:11 <DIR> d-------- C:\Program Files\Opera
2008-07-10 18:15 . 2008-07-10 18:30 <DIR> d-------- C:\Program Files\ScanSpyware v3.8.0.4
2008-07-10 18:06 . 2008-07-10 18:07 <DIR> d-------- C:\Documents and Settings\Misiu\DoctorWeb
2008-07-08 17:45 . 2008-07-11 15:59 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
2008-07-08 17:44 . 2008-07-08 17:44 <DIR> d-------- C:\Documents and Settings\Misiu\Dane aplikacji\PC Tools
2008-07-08 17:44 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-07-08 17:44 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-07-08 17:44 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-07-08 17:44 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-18 12:00 . 2008-06-18 12:00 206 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-18 11:50 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-18 11:50 . 2008-06-14 20:01 273,024 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 13:53 . 2008-06-13 13:53 <DIR> d-------- C:\Documents and Settings\Misiu\Dane aplikacji\AdobeUM
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-11 13:48 --------- d-----w C:\Documents and Settings\Misiu\Dane aplikacji\DMCache
2008-07-11 09:02 --------- d-----w C:\Documents and Settings\Misiu\Dane aplikacji\uTorrent
2008-07-08 17:31 --------- d-----w C:\Program Files\uTorrent
2008-07-08 17:31 --------- d-----w C:\Documents and Settings\Misiu\Dane aplikacji\BitTorrent
2008-06-24 22:22 --------- d-----w C:\Documents and Settings\Misiu\Dane aplikacji\U3
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-05 13:58 121,300 --sh--r C:\lgrncie.bat
2008-05-15 18:56 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 07:20 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2006-11-06 11:09 32,768 ----a-w C:\Documents and Settings\Wlasciciel\setup9X.exe
2006-03-22 13:14 36 ----a-w C:\Documents and Settings\Wlasciciel\klextlock.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"Gadu-Gadu"="C:\Programy\Gadu-Gadu\gg.exe" [2006-11-14 11:12 1849032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-08 18:11 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"ISTray"="C:\Programy\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]
"SiSPower"="SiSPower.dll" [2005-03-04 02:50 49152 C:\WINDOWS\system32\SiSPower.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2004-02-12 01:18]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2004-01-27 23:00]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3091769c-7dd0-11dc-8eda-00030d33d53c}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f184038c-025e-11dd-bbd7-00030d33d53c}]
\Shell\AutoRun\command - G:\lgrncie.bat
\Shell\explore\Command - G:\lgrncie.bat
\Shell\open\Command - G:\lgrncie.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f63f2026-7800-11dc-8ec9-00030d33d53c}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
*Newly Created Service* - CATCHME
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Twoje TVN24 - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-11 16:14:31
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-11 16:16:24
ComboFix-quarantined-files.txt 2008-07-11 14:16:17
Pre-Run: 5,625,905,152 bajtów wolnych
Post-Run: 5,620,183,040 bajtów wolnych
96 --- E O F --- 2008-07-09 12:40:57