Niestety CFScript.txt wkleiłem ale nic to nie dało nadal edycja rejestru zablokowana. Komp coraz bardziej muli.
Chyba się powoli poddaje, usuwam w hj ten wpis co blokuje rejestr właczam kompoa w trybie normalnym i ten wpis tam znowu jest

Kilka razy tak robiłem i zawsze wpis wraca. Przez to sie zawiesza combofix.
Ostatnie co wygenerował to jakaś masakra:
- Kod: Zaznacz wszystko
ComboFix 08-08-08.05 - Matteo 2008-08-09 10:59:16.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1250.1.1045.18.223 [GMT 2:00]
Running from: C:\Documents and Settings\Matteo\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Matteo\Pulpit\CFScript.txt
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\Microsoft\backup.ftp
C:\WINDOWS\system32\Microsoft\backup.tftp
.
---- Previous Run -------
.
C:\WINDOWS\system32\Microsoft\backup.ftp
C:\WINDOWS\system32\Microsoft\backup.tftp
.
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.
2008-08-09 00:50 . 2008-08-09 00:50 97,792 -r-hs---- C:\WINDOWS\system32\soundman.exe
2008-08-09 00:13 . 2008-08-09 00:57 326 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-08-08 23:45 . 2008-08-08 23:45 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-08-08 13:00 . 2008-08-08 13:00 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-08 12:59 . 2008-08-09 11:13 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-08-08 12:59 . 2008-07-08 18:51 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-08-08 12:59 . 2008-07-08 17:58 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-08-08 12:59 . 2008-08-09 11:14 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-08-08 12:59 . 2008-07-08 18:51 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-08-08 12:59 . 2008-07-08 18:51 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-08-08 12:59 . 2008-07-08 18:51 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-08-08 12:59 . 2008-08-08 12:59 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-08 12:55 . 2008-08-09 01:05 <DIR> d-------- C:\SDFix
2008-08-05 14:31 . 2002-08-29 01:32 21,760 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-15 20:58 . 2008-07-15 20:58 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-07-13 15:37 . 2008-07-13 15:37 <DIR> d---s---- C:\Documents and Settings\Matteo\UserData
2008-07-12 14:31 . 2008-07-12 14:31 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-12 14:31 . 2008-07-12 14:31 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2008-07-10 15:19 . 2008-07-10 15:19 <DIR> d-------- C:\Program Files\WMV9_VCM
2008-07-10 14:46 . 2008-07-10 14:46 <DIR> d-------- C:\Documents and Settings\Matteo\Dane aplikacji\XCPCSync.OEM
2008-07-10 14:42 . 2003-08-25 18:06 182,880 --a------ C:\WINDOWS\system32\iuengine.dll
2008-07-10 14:42 . 2003-08-25 18:06 182,880 --a--c--- C:\WINDOWS\system32\dllcache\iuengine.dll
2008-07-10 14:30 . 1998-06-18 01:00 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2008-07-10 14:30 . 1998-05-05 22:00 57,344 --------- C:\WINDOWS\system32\VBAME.DLL
2008-07-10 14:29 . 2008-07-10 14:29 <DIR> d-------- C:\Program Files\Common Files\XCPCSync.OEM
2008-07-10 14:00 . 2008-07-10 14:00 <DIR> d-------- C:\Documents and Settings\Matteo\Dane aplikacji\AdobeUM
2008-07-10 13:55 . 2008-07-10 13:55 <DIR> d-------- C:\Documents and Settings\Mateo\Moje dokumenty
2008-07-10 13:55 . 2008-07-10 13:55 <DIR> d-------- C:\Documents and Settings\Mateo
2008-07-10 13:33 . 2008-07-10 13:33 1,103 --a------ C:\WINDOWS\bestplayer.ini
2008-07-10 13:33 . 2008-07-10 13:33 0 --a------ C:\WINDOWS\bestplayer.bpp
2008-07-10 13:33 . 2008-07-10 13:33 0 --a------ C:\WINDOWS\bestplayer.bbt
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-09 09:17 4,155,680 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-09 09:14 176,416 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-09 08:50 42,496 ----a-w C:\WINDOWS\system32\ftp.exe
2008-08-09 08:50 16,896 ----a-w C:\WINDOWS\system32\tftp.exe
2008-08-09 08:50 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-08-08 23:23 63,680 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-08 23:23 21,620 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-08 09:34 133,632 ----a-w C:\WINDOWS\system32\sfc_os.dll
2008-08-06 17:07 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-24 11:09 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-12 12:32 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-10 22:00 --------- d-----w C:\Program Files\Gadu-Gadu
2008-07-10 12:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-10 12:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-08 18:03 --------- d-----w C:\Documents and Settings\Matteo\Dane aplikacji\Gadu-Gadu
2008-07-08 18:00 --------- d-----w C:\Program Files\Tlen.pl
2008-07-08 17:31 --------- d-----w C:\Documents and Settings\Matteo\Dane aplikacji\Tlen.pl
2008-07-08 16:50 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-08 16:38 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-08 16:37 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-07-08 16:21 --------- d-----w C:\Program Files\Realtek
2008-07-08 16:11 --------- d-----w C:\Program Files\Intel
2008-07-08 16:02 558,142 ----a-w C:\WINDOWS\java\Packages\5NXRHJLN.ZIP
2008-07-08 16:02 155,995 ----a-w C:\WINDOWS\java\Packages\I9R3R5F7.ZIP
2008-07-08 16:02 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-08 16:01 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
C:\Documents and Settings\Matteo\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe %WINDIR%\\system32\\soundman.exe"
"SFCDisable"=dword:ffffff9d
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
R1 fwdrv;Firewall Driver;C:\WINDOWS\System32\drivers\fwdrv.sys [2006-05-09 16:08]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\System32\drivers\khips.sys [2006-05-09 16:08]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\System32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 siusbmod;siusbmod;C:\WINDOWS\System32\DRIVERS\siusbmod.sys [2005-11-30 17:12]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 11:15:16
Windows 5.1.2600 Dodatek Service Pack. 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\abp480n5]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ACPI]
"ImagePath"="System32\DRIVERS\ACPI.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ACPIEC]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\actser]
"ImagePath"="system32\drivers\actser.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Adobe LM Service]
"ImagePath"="\"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe\""
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\adpu160m]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aec]
"ImagePath"="system32\drivers\aec.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aha154x]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aic78u2]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aic78xx]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AliIde]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\amsint]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\asc]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\asc3350p]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\asc3550]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\atapi]
"ImagePath"="System32\DRIVERS\atapi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Atdisk]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Atmarpc]
"ImagePath"="System32\DRIVERS\atmarpc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\audstub]
"ImagePath"="System32\DRIVERS\audstub.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AVP]
"ImagePath"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe -r"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Beep]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\catchme]
"ImagePath"="\??\C:\DOCUME~1\Matteo\USTAWI~1\Temp\catchme.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\cd20xrnt]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Cdfs]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Cdrom]
"ImagePath"="System32\DRIVERS\cdrom.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Changer]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\CiSvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\CmdIde]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\COMSysApp]
"ImagePath"="C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Cpqarray]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dac2w2k]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dac960nt]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Disk]
"ImagePath"="System32\DRIVERS\disk.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dmio]
"ImagePath"="System32\drivers\dmio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dmload]
"ImagePath"="System32\drivers\dmload.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\dpti2o]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EventSystem]
"ServiceDll"="C:\WINDOWS\System32\es.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Fastfat]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Fdc]
"ImagePath"="System32\DRIVERS\fdc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Fips]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Flpydisk]
"ImagePath"="System32\DRIVERS\flpydisk.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ftdisk]
"ImagePath"="System32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\fwdrv]
"ImagePath"="\SystemRoot\system32\drivers\fwdrv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Gpc]
"ImagePath"="System32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HdAudAddService]
"ImagePath"="system32\drivers\HdAudio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HDAudBus]
"ImagePath"="System32\DRIVERS\HDAudBus.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\hpn]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\i2omp]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\i8042prt]
"ImagePath"="System32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Imapi]
"ImagePath"="System32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\inetaccs]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ini910u]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Inport]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IntcAzAudAddService]
"ImagePath"="system32\drivers\RtkHDAud.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IntelIde]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IpFilterDriver]
"ImagePath"="System32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IpInIp]
"ImagePath"="System32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IpNat]
"ImagePath"="System32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IPSec]
"ImagePath"="System32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\IRENUM]
"ImagePath"="System32\DRIVERS\irenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\isapnp]
"ImagePath"="System32\DRIVERS\isapnp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Kbdclass]
"ImagePath"="System32\DRIVERS\kbdclass.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\khips]
"ImagePath"="\SystemRoot\system32\drivers\khips.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\kl1]
"ImagePath"="System32\drivers\kl1.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\klif]
"ImagePath"="\??\C:\WINDOWS\System32\drivers\klif.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\klim5]
"ImagePath"="System32\DRIVERS\klim5.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\KPF4]
"ImagePath"="C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\KSecDD]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ldap]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\LicenseService]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mnmdd]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mnmsrvc]
"ImagePath"="C:\WINDOWS\System32\mnmsrvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Modem]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Mouclass]
"ImagePath"="System32\DRIVERS\mouclass.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MountMgr]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mraid35x]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MRxDAV]
"ImagePath"="System32\DRIVERS\mrxdav.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MRxSmb]
"ImagePath"="System32\DRIVERS\mrxsmb.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSDTC]
"ImagePath"="C:\WINDOWS\System32\msdtc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Msfs]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSIServer]
"ImagePath"="%systemroot%\system32\msiexec.exe /V"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Mup]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NDIS]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NdisTapi]
"ImagePath"="System32\DRIVERS\ndistapi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ndisuio]
"ImagePath"="System32\DRIVERS\ndisuio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NdisWan]
"ImagePath"="System32\DRIVERS\ndiswan.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NDProxy]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NetBIOS]
"ImagePath"="System32\DRIVERS\netbios.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NetBT]
"ImagePath"="System32\DRIVERS\netbt.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Npfs]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ntfs]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\System32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Null]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\nv]
"ImagePath"="System32\DRIVERS\nv4_mini.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NVSvc]
"ImagePath"="%SystemRoot%\System32\nvsvc32.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NwlnkFlt]
"ImagePath"="System32\DRIVERS\nwlnkflt.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NwlnkFwd]
"ImagePath"="System32\DRIVERS\nwlnkfwd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Parport]
"ImagePath"="System32\DRIVERS\parport.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PartMgr]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ParVdm]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCI]
"ImagePath"="System32\DRIVERS\pci.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCIDump]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCIIde]
"ImagePath"="System32\DRIVERS\pciide.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Pcmcia]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PDCOMP]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PDFRAME]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PDRELI]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PDRFRAME]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\perc2]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\perc2hib]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PerfDisk]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PerfNet]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PerfOS]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PerfProc]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PlugPlay]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PolicyAgent]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PptpMiniport]
"ImagePath"="System32\DRIVERS\raspptp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Processor]
"ImagePath"="System32\DRIVERS\processr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PSched]
"ImagePath"="System32\DRIVERS\psched.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ptilink]
"ImagePath"="System32\DRIVERS\ptilink.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ql1080]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ql10wnt]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ql12160]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ql1240]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ql1280]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Rasl2tp]
"ImagePath"="System32\DRIVERS\rasl2tp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RasPppoe]
"ImagePath"="System32\DRIVERS\raspppoe.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Raspti]
"ImagePath"="System32\DRIVERS\raspti.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Rdbss]
"ImagePath"="System32\DRIVERS\rdbss.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RDPDD]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\rdpdr]
"ImagePath"="System32\DRIVERS\rdpdr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RDPNP]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RDPWD]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RDSessMgr]
"ImagePath"="C:\WINDOWS\system32\sessmgr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\redbook]
"ImagePath"="System32\DRIVERS\redbook.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RemoteAccess]
"ServiceDll"="%SystemRoot%\System32\mprdim.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\System32\locator.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\System32\rpcss.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RSVP]
"ImagePath"="%SystemRoot%\System32\rsvp.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SCardDrv]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SCardSvr]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Schedule]
"ServiceDll"="%SystemRoot%\system32\schedsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Secdrv]
"ImagePath"="System32\DRIVERS\secdrv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\seclogon]
"ServiceDll"="%SystemRoot%\System32\seclogon.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\serenum]
"ImagePath"="System32\DRIVERS\serenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Serial]
"ImagePath"="System32\DRIVERS\serial.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Sfloppy]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Simbad]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\siusbmod]
"ImagePath"="System32\DRIVERS\siusbmod.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Sparrow]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\splitter]
"ImagePath"="system32\drivers\splitter.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\system32\spoolsv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\sr]
"ImagePath"="system32\DRIVERS\sr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\srservice]
"ServiceDll"="C:\WINDOWS\System32\srsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Srv]
"ImagePath"="System32\DRIVERS\srv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\system32\wiaservc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\swenum]
"ImagePath"="System32\DRIVERS\swenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\swmidi]
"ImagePath"="system32\drivers\swmidi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SwPrv]
"ImagePath"="C:\WINDOWS\System32\dllhost.exe /Processid:{CB47A5D7-0A1B-43A3-8780-A7129A7966EC}"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\symc810]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\symc8xx]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\sym_hi]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\sym_u3]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\sysaudio]
"ImagePath"="system32\drivers\sysaudio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SysmonLog]
"ImagePath"="%SystemRoot%\system32\smlogsvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Tcpip]
"ImagePath"="System32\DRIVERS\tcpip.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDPIPE]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDTCP]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TermDD]
"ImagePath"="System32\DRIVERS\termdd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Themes]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TlntSvr]
"ImagePath"="C:\WINDOWS\System32\tlntsvr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TosIde]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TrkWks]
"ServiceDll"="%SystemRoot%\system32\trkwks.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TSDDD]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Udfs]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ultra]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Update]
"ImagePath"="System32\DRIVERS\update.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\uploadmgr]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\UPS]
"ImagePath"="%SystemRoot%\System32\ups.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\USBCM]
"ImagePath"="System32\DRIVERS\Sacm2A.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\usbehci]
"ImagePath"="System32\DRIVERS\usbehci.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\usbhub]
"ImagePath"="System32\DRIVERS\usbhub.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\USBSTOR]
"ImagePath"="System32\DRIVERS\USBSTOR.SYS"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\usbuhci]
"ImagePath"="System32\DRIVERS\usbuhci.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ViaIde]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\VolSnap]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsbus]
"ImagePath"="System32\DRIVERS\vsb.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vserial]
"ImagePath"="System32\DRIVERS\vserial.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\VSS]
"ImagePath"="%SystemRoot%\System32\vssvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\W32Time]
"ServiceDll"="%systemroot%\system32\w32time.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\W3SVC]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Wanarp]
"ImagePath"="System32\DRIVERS\wanarp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WDICA]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\wdmaud]
"ImagePath"="system32\drivers\wdmaud.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Winsock]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WinSock2]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WinTrust]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WmdmPmSp]
"ServiceDll"="C:\WINDOWS\System32\mspmspsv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Wmi]
"ServiceDll"="%SystemRoot%\System32\advapi32.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WmiApRpl]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WmiApSrv]
"ImagePath"="C:\WINDOWS\System32\wbem\wmiapsrv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\wscsvc]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\wuauserv]
"ServiceDll"="C:\WINDOWS\System32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WZCSVC]
"ServiceDll"="%SystemRoot%\System32\wzcsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{AE5F1177-53AE-4937-ADE2-979C0D1438FF}]
.
Completion time: 2008-08-09 11:20:21
ComboFix-quarantined-files.txt 2008-08-09 09:20:10
ComboFix2.txt 2008-08-08 12:14:40
Pre-Run: 12,633,059,328 bajtów wolnych
Post-Run: 12,632,489,984 bajtów wolnych
565
Czekam jeszcze na jakis genialny pomysł ale powoli szykuję płytkę z windowsem.
Moze ktoś chociaz poleci jakiegos dobrego antywira żeby nie było potem jak teraz, chociaz cały czas miałem kaspersky internet security 7.0.1.325 i te syfy i tak weszły.
Czekam jeszcze troche na pomysły jakieś a potem format jak nic nie pomoże

Edytowano - podpis niezgodny z regulaminem.