
proszę o sprawdzenie loga z ComboFix , poces bezczynności ok 60% przy Intelu Q9450 , problem z csrss.exe i MOM.exe dotychczsowe próby naprawy SDfix oraz OTMovelt nie skutkują, proszę o pomoc jak dla laika. DZIĘKI
- Kod: Zaznacz wszystko
ComboFix 09-01-21.04 - Piotr 2009-01-25 23:11:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.3326.2706 [GMT 1:00]
Uruchomiony z: f:\pobrane z sieci\NAPRAWA\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2008-12-25 do 2009-01-25 )))))))))))))))))))))))))))))))
.
2009-01-25 22:31 . 2009-01-25 22:31 <DIR> d-------- C:\ERDNT
2009-01-25 22:31 . 2009-01-25 22:32 <DIR> d-------- C:\!FixIEDef
2009-01-23 21:52 . 2005-05-03 11:43 69,632 -r------- c:\windows\Alcmtr.exe
2009-01-23 13:50 . 2009-01-23 20:35 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-01-23 13:49 . 2008-06-14 19:01 273,024 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-01-23 13:47 . 2008-08-14 14:40 2,187,264 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-01-23 13:47 . 2008-08-14 14:40 2,144,256 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-01-23 13:47 . 2008-08-14 14:40 2,064,256 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-01-23 13:47 . 2008-08-14 14:40 2,022,400 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-01-23 13:45 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-01-22 21:52 . 2004-08-04 11:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2009-01-22 21:51 . 2004-05-13 00:39 876,653 --a--c--- c:\windows\system32\dllcache\fp4awel.dll
2009-01-22 21:50 . 2009-01-22 21:50 749 -rah----- c:\windows\WindowsShell.Manifest
2009-01-22 21:50 . 2009-01-22 21:50 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2009-01-22 21:50 . 2009-01-22 21:50 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2009-01-22 21:50 . 2009-01-22 21:50 749 -rah----- c:\windows\system32\nwc.cpl.manifest
2009-01-22 21:50 . 2009-01-22 21:50 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2009-01-22 21:50 . 2009-01-22 21:50 488 -rah----- c:\windows\system32\logonui.exe.manifest
2009-01-22 21:48 . 2004-08-04 11:00 65,954 --a------ c:\windows\Pod mikroskopem.bmp
2009-01-22 21:48 . 2004-08-04 11:00 65,832 --a------ c:\windows\Stiuk z Santa Fe.bmp
2009-01-22 21:48 . 2004-08-04 11:00 26,582 --a------ c:\windows\Nefryt.bmp
2009-01-22 21:48 . 2004-08-04 11:00 17,362 --a------ c:\windows\Rododendron.bmp
2009-01-22 21:48 . 2004-08-04 11:00 17,336 --a------ c:\windows\Na rybkach.bmp
2009-01-22 21:48 . 2004-08-04 11:00 9,522 --a------ c:\windows\Indiański pled.bmp
2009-01-22 21:48 . 2004-08-04 11:00 1,272 --a------ c:\windows\Niebieska koronka 16.bmp
2009-01-22 21:12 . 2009-01-22 21:12 <DIR> d-------- C:\$WIN_NT$.~BT
2009-01-19 21:19 . 2009-01-19 21:19 <DIR> d-------- c:\documents and settings\Piotr\Dane aplikacji\PC Tools
2009-01-19 21:19 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-01-19 21:19 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-01-19 21:19 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-01-19 21:19 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-01-19 19:54 . 2009-01-25 22:31 <DIR> d-------- c:\windows\ERUNT
2009-01-19 17:49 . 2009-01-19 18:25 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-01-19 17:48 . 2009-01-22 20:12 6,150 --a------ c:\windows\setupapi.old
2009-01-08 22:43 . 2009-01-08 22:43 1,494 --a------ c:\windows\SDNT.MIF
2009-01-08 21:07 . 2000-09-02 04:46 159,830 --a------ c:\windows\nsuninst.exe
2009-01-08 21:06 . 2009-01-08 21:06 <DIR> d-------- c:\program files\Common Files\Novell Shared
2009-01-08 21:05 . 2009-01-08 21:05 <DIR> d-------- c:\documents and settings\Piotr\Dane aplikacji\Symantec
2009-01-08 21:05 . 1999-06-10 14:50 437,528 --a------ c:\windows\system32\401COMUPD.EXE
2009-01-08 21:05 . 1999-03-24 22:28 182,784 --a------ c:\windows\system32\ddao35.dll
2009-01-08 21:05 . 2000-08-28 22:54 90,112 --a------ c:\windows\system32\qdcsinet.dll
2009-01-08 21:05 . 2000-08-28 23:07 86,016 --a------ c:\windows\system32\apitrap.dll
2009-01-08 21:05 . 2000-08-28 23:14 13,760 --a------ c:\windows\system32\drivers\qdfsdrv.sys
2009-01-08 21:04 . 2009-01-08 21:04 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Symantec
2009-01-08 21:04 . 1999-04-13 00:00 1,046,288 --a------ c:\windows\system32\msjet35.dll
2009-01-08 21:04 . 1998-04-24 20:08 368,912 --a------ c:\windows\system32\vbar332.dll
2009-01-08 21:04 . 1998-04-24 19:40 252,176 --a------ c:\windows\system32\msrd2x35.dll
2009-01-08 21:04 . 1998-04-24 19:40 123,664 --a------ c:\windows\system32\Msjint35.dll
2009-01-08 21:04 . 1998-04-24 19:40 24,848 --a------ c:\windows\system32\msjter35.dll
2009-01-08 21:03 . 2009-01-08 21:11 <DIR> d-------- c:\program files\Symantec
2009-01-08 21:03 . 2009-01-08 22:43 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-01-08 21:03 . 2009-01-08 21:03 <DIR> d-------- c:\documents and settings\Piotr\WINDOWS
2009-01-08 21:03 . 2006-08-25 16:51 617,472 --a------ c:\windows\system32\COMCTL32.NU5
2009-01-08 21:03 . 2000-09-02 05:07 120,379 --a------ c:\windows\system32\SYMEVNT.386
2009-01-08 21:03 . 2000-09-02 05:07 63,616 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-08 21:03 . 2000-09-02 05:07 36,864 --a------ c:\windows\system32\S32EVNT1.DLL
2009-01-08 21:03 . 2000-09-02 05:07 4,032 --a------ c:\windows\system32\SYMEVNT1.DLL
2009-01-08 21:03 . 2009-01-08 21:05 450 --a------ c:\windows\_delis43.ini
2009-01-08 21:03 . 2008-08-30 20:25 0 --a------ C:\CONFIG.NS0
2009-01-08 21:03 . 2008-08-30 20:25 0 --a------ C:\AUTOEXEC.NS0
2009-01-08 20:59 . 1998-10-29 16:45 306,688 --a------ c:\windows\IsUninst.exe
2009-01-08 20:59 . 1998-06-26 00:00 89,600 --a------ c:\windows\system32\MSCAL.OCX
2009-01-08 18:51 . 2009-01-08 20:28 <DIR> d-------- C:\RECYCLER(2)
2008-12-27 01:35 . 2008-12-27 01:54 10 --ah----- C:\lqlurj.gqe
2008-12-26 13:26 . 2008-12-26 13:26 487,936 --a------ c:\windows\system32\madFlac.ax
2008-12-26 13:25 . 2008-12-26 13:25 892,928 --a------ c:\windows\system32\iconv.dll
2008-12-26 13:25 . 2008-12-26 13:25 688,128 --a------ c:\windows\system32\mmamr.ax
2008-12-26 13:25 . 2008-12-26 13:25 675,840 --a------ c:\windows\system32\ac3filter.ax
2008-12-26 13:25 . 2008-12-26 13:25 348,160 --a------ c:\windows\system32\CoreVorbis.ax
2008-12-26 13:25 . 2008-12-26 13:25 258,048 --a------ c:\windows\system32\libFLAC.dll
2008-12-26 13:24 . 2008-12-26 13:24 536,576 --a------ c:\windows\system32\splitter.ax
2008-12-26 13:24 . 2008-12-26 13:24 319,488 --a------ c:\windows\system32\CoreAAC.ax
2008-12-26 13:24 . 2008-12-26 13:24 177,152 --a------ c:\windows\system32\MonkeySource.ax
2008-12-26 13:24 . 2008-12-26 13:24 141,312 --a------ c:\windows\system32\mp4.dll
2008-12-26 13:24 . 2008-12-26 13:24 108,032 --a------ c:\windows\system32\avi.dll
2008-12-26 13:24 . 2008-12-26 13:24 75,264 --a------ c:\windows\system32\MACDec.dll
2008-12-26 13:23 . 2008-12-26 13:23 2,625,536 --a------ c:\windows\system32\ffdshow.ax
2008-12-26 13:23 . 2008-12-26 13:23 520,192 --a------ c:\windows\system32\MP4Splitter.ax
2008-12-26 13:23 . 2008-12-26 13:23 163,840 --a------ c:\windows\system32\ts.dll
2008-12-26 13:23 . 2008-12-26 13:23 159,744 --a------ c:\windows\system32\mmfinfo.dll
2008-12-26 13:23 . 2008-12-26 13:23 148,992 --a------ c:\windows\system32\mkx.dll
2008-12-26 13:23 . 2008-12-26 13:23 120,832 --a------ c:\windows\system32\ogm.dll
2008-12-26 13:23 . 2008-12-26 13:23 79,360 --a------ c:\windows\system32\mkzlib.dll
2008-12-26 13:23 . 2008-12-26 13:23 23,552 --a------ c:\windows\system32\mkunicode.dll
2008-12-26 13:22 . 2008-12-26 13:22 560,802 --a------ c:\windows\system32\libmplayer.dll
2008-12-26 13:22 . 2008-12-26 13:22 547 --a------ c:\windows\system32\ffdshow.ax.manifest
2008-12-26 13:21 . 2008-12-26 13:21 4,302,881 --a------ c:\windows\system32\libavcodec.dll
2008-12-26 13:21 . 2008-12-26 13:21 145,609 --a------ c:\windows\system32\libmpeg2_ff.dll
2008-12-26 13:18 . 2008-12-26 13:18 113,152 --a------ c:\windows\system32\ff_unrar.dll
2008-12-26 13:18 . 2008-12-26 13:18 93,184 --a------ c:\windows\system32\ff_wmv9.dll
2008-12-26 13:17 . 2008-12-26 13:17 485,888 --a------ c:\windows\system32\ff_libfaad2.dll
2008-12-26 13:17 . 2008-12-26 13:17 183,296 --a------ c:\windows\system32\ff_samplerate.dll
2008-12-26 13:17 . 2008-12-26 13:17 178,688 --a------ c:\windows\system32\ff_libmad.dll
2008-12-26 13:16 . 2008-12-26 13:16 921,600 --a------ c:\windows\system32\vorbisenc.dll
2008-12-26 13:16 . 2008-12-26 13:16 257,024 --a------ c:\windows\system32\ff_libdts.dll
2008-12-26 13:16 . 2008-12-26 13:16 237,568 --a------ c:\windows\system32\OggDS.dll
2008-12-26 13:16 . 2008-12-26 13:16 142,848 --a------ c:\windows\system32\ff_liba52.dll
2008-12-26 13:15 . 2008-12-26 13:15 1,415,680 --a------ c:\windows\system32\WMV9VCM.dll
2008-12-26 13:15 . 2008-12-26 13:15 188,416 --a------ c:\windows\system32\vorbis.dll
2008-12-26 13:15 . 2008-12-26 13:15 45,056 --a------ c:\windows\system32\ogg.dll
2008-12-26 13:14 . 2008-12-26 13:14 873,888 --a------ c:\windows\system32\CLVSD.ax
2008-12-26 13:14 . 2008-12-26 13:14 245,760 --a------ c:\windows\system32\mplvpx.dll
2008-12-26 13:14 . 2008-12-26 13:14 106,496 --a------ c:\windows\system32\lmpgspl.ax
2008-12-26 13:14 . 2008-12-26 13:14 94,208 --a------ c:\windows\system32\lmpgvd.ax
2008-12-26 13:14 . 2008-12-26 13:14 9,216 --a------ c:\windows\system32\cpuinf32.dll
2008-12-26 13:13 . 2008-12-26 13:13 729,088 --a------ c:\windows\system32\divxdec.ax
2008-12-26 13:13 . 2008-12-26 13:13 524,288 --a------ c:\windows\system32\DivXsm.exe
2008-12-26 13:13 . 2008-12-26 13:13 417,792 --a------ c:\windows\system32\FLVSplitter.ax
2008-12-26 13:12 . 2008-12-26 22:41 <DIR> d-------- c:\program files\Real Alternative
2008-12-26 13:12 . 2008-12-26 13:12 795,648 --a------ c:\windows\system32\xvidcore.dll
2008-12-26 13:12 . 2008-12-26 13:12 77,824 --a------ c:\windows\system32\xvid.ax
2008-12-26 13:12 . 2008-12-26 13:12 69,632 --a------ c:\windows\system32\divxconfig.exe
2008-12-26 13:12 . 2008-12-26 13:12 4,816 --a------ c:\windows\system32\divxsm.tlb
2008-12-25 04:47 . 2008-05-08 02:03 453,632 --a------ c:\windows\system32\SetACL.ocx
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-25 22:16 16,608 ----a-w c:\windows\gdrv.sys
2009-01-25 22:15 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-01-25 22:13 81,644 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-25 22:13 696,352 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-25 22:13 5,392,160 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-25 22:13 35,228 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-25 22:07 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2009-01-17 16:12 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\XnView
2009-01-08 19:59 --------- d-----w c:\program files\NAPI-PROJEKT
2008-12-28 19:54 --------- d-----w c:\documents and settings\Anna\Dane aplikacji\PC Suite
2008-12-26 18:32 278,984 ----a-w c:\windows\system32\drivers\atksgt.sys
2008-12-26 18:32 25,416 ----a-w c:\windows\system32\drivers\lirsgt.sys
2008-12-26 18:22 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-23 19:48 --------- d-----w c:\documents and settings\Zuzanna\Dane aplikacji\PC Suite
2008-12-20 11:25 --------- d-----w c:\program files\Opera
2008-12-16 17:12 --------- d-----w c:\documents and settings\Anna\Dane aplikacji\Nokia
2008-12-14 20:26 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\DAEMON Tools Pro
2008-12-14 20:26 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\DAEMON Tools Lite
2008-12-14 20:26 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\DAEMON Tools
2008-12-14 20:26 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 17:18 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\PC Suite
2008-12-10 17:06 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\PC Suite
2008-12-10 17:02 --------- d-----w c:\program files\PC Connectivity Solution
2008-12-10 17:02 --------- d-----w c:\program files\DIFX
2008-12-10 17:02 --------- d-----w c:\program files\Common Files\PCSuite
2008-12-10 17:02 --------- d-----w c:\program files\Common Files\Nokia
2008-12-10 17:00 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Installations
2008-12-10 16:26 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-12-09 21:42 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Bluetooth
2008-11-28 18:51 --------- d-----w c:\documents and settings\Anna\Dane aplikacji\Media Player Classic
2008-11-28 18:51 --------- d-----w c:\documents and settings\Anna\Dane aplikacji\DivX
2008-11-27 20:11 --------- d-----w c:\program files\Borland
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61DB16C5-B733-43F4-872E-B20DC9E72740}]
2008-10-10 23:57 444416 --a------ f:\programy\ALLPlayer\ALLPlayer\YouTubeToALLPlayer.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D023EBF-70B8-45A6-9ED5-556515FA0FE4}]
2008-07-07 10:27 398776 --a------ c:\program files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Odkurzacz-MCD"="f:\programy\Odkurzacz\odk_mcd.exe" [2008-08-16 264704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="c:\program files\GIGABYTE\GEST\RUN.exe" [2007-12-14 236040]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Reader Speed Launcher"="f:\adobe reader 9\Reader\Reader_sl.exe" [2008-06-12 34672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-19 136600]
"SymTray - Norton SystemWorks"="c:\program files\Common Files\Symantec Shared\SymTray.exe" [2000-09-02 73808]
"ISTray"="f:\spyware doctor\pctsTray.exe" [2008-08-25 1168264]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2000-02-14 c:\windows\system32\WFXSNT40.EXE]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-09-22 91440]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-09-22 805392]
Przyspieszenie uruchomienia programu AutoCAD.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 11000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SDFix"=f:\pobran~1\SDFix\SDFix\RunThis.bat /second
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"Kernel and Hardware Abstraction Layer"=KHALMNPR.EXE
"JMB36X IDE Setup"=c:\windows\RaidTool\xInsIDE.exe
"CloneCDTray"="f:\programy\CLONE CD\CloneCD\CloneCDTray.exe" /s
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"f:\\PROGRAMY\\BitTorrent6.0\\BitTorrent\\bittorrent.exe"=
"d:\\programy\\BearShare.exe"=
"d:\\Gadu-Gadu\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"f:\\PROGRAMY\\Bluesoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-08-30 93696]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [2008-08-30 47624]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592]
R4 sdAuxService;PC Tools Auxiliary Service;f:\spyware doctor\pctsAuxs.exe [2009-01-19 356920]
--- Inne Usługi/Sterowniki w Pamięci ---
*Deregistered* - mchInjDrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\Autorun.exe
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.idg.pl
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {60B2731D-435A-48D3-9FAD-D18C1AABB27C} = 192.168.0.1,83.168.104.66
TCP: {6265522D-A1BC-4664-B0C1-9365196506CE} = 192.168.0.1,83.168.104.66
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-25 23:15:20
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
f:\spyware doctor\pctsSvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
.
**************************************************************************
.
Czas ukończenia: 2009-01-25 23:18:03 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-01-25 22:17:59
Przed: 36 914 851 840 bajtów wolnych
Po: 36,845,961,216 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect