
- Kod: Zaznacz wszystko
- ComboFix 08-08-14.05 - Maria 2008-08-15 17:51:02.2 - NTFSx86
 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.426 [GMT 2:00]
 Running from: C:\Documents and Settings\Maria\Pulpit\ComboFix.exe
 * Resident AV is active
 [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
 .
 ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 ---- Previous Run -------
 .
 C:\WINDOWS\hosts
 .
 ((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))
 .
 2008-08-14 14:38 . 2008-08-14 14:38 <DIR> d-------- C:\Program Files\Photo!
 2008-08-05 15:27 . 2008-08-05 15:27 <DIR> d-------- C:\Documents and Settings\Maria\Dane aplikacji\Nowe Gadu-Gadu
 2008-07-21 23:39 . 2008-07-21 23:39 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\FLEXnet
 2008-07-21 23:32 . 2008-07-21 23:32 <DIR> d-------- C:\Program Files\Bonjour
 2008-07-21 23:25 . 2008-07-21 23:25 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
 2008-07-18 08:00 . 2008-07-18 08:00 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.Vsys
 2008-07-18 08:00 . 2008-07-18 08:00 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.Vsys
 2008-07-16 16:47 . 2008-07-16 16:47 <DIR> d-------- C:\Documents and Settings\Maria\Dane aplikacji\Inkscape
 2008-07-16 16:42 . 2008-07-16 16:44 <DIR> d-------- C:\Program Files\Inkscape
 2008-07-16 11:21 . 2008-07-16 11:21 <DIR> d-------- C:\Program Files\Zinio
 2008-07-16 11:21 . 2008-07-16 11:21 <DIR> d-------- C:\Program Files\Common Files\Zinio
 2008-07-16 11:21 . 2008-07-31 21:31 <DIR> d-------- C:\Documents and Settings\Maria\Dane aplikacji\ContentGuard
 .
 (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2008-08-15 15:53 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\Skype
 2008-08-15 15:52 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\skypePM
 2008-08-14 13:21 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\OpenOffice.ux.pl2
 2008-08-13 11:17 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\POP Peeper
 2008-08-11 08:28 --------- d-----w C:\Program Files\ESET
 2008-08-06 15:41 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\GanymedeNet
 2008-08-06 15:17 --------- d-----w C:\Program Files\Ganymede
 2008-08-06 08:37 --------- d-----w C:\Program Files\POP Peeper
 2008-08-05 08:13 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
 2008-07-21 21:33 --------- d-----w C:\Program Files\Common Files\Adobe
 2008-07-21 18:31 --------- d-----w C:\Program Files\DivX
 2008-07-21 18:29 --------- d-----w C:\Program Files\Adibu
 2008-07-19 18:33 --------- d-----w C:\Program Files\Winamp
 2008-07-13 18:33 --------- d-----w C:\Program Files\Yahoo!
 2008-07-13 18:30 --------- d-----w C:\Program Files\Java
 2008-06-20 17:31 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
 2008-06-20 17:31 --------- d-----r C:\Program Files\Skype
 2008-06-20 17:30 --------- d-----w C:\Program Files\Common Files\Skype
 2007-11-16 19:43 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
 2007-06-07 11:21 774,144 ----a-w C:\Program Files\RngInterstitial.dll
 .
 ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Note* empty entries & legit default entries are not shown
 REGEDIT4
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
 "Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-03-29 08:13 258048]
 "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 21:03 68856]
 "POP Peeper"="C:\Program Files\POP Peeper\POPPeeper.exe" [2008-07-18 09:40 1437696]
 "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 17:46 1460560]
 "Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-03-03 15:44 266240]
 "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:44 15360]
 "Zinio DLM"="C:\Program Files\Zinio\ZinioDeliveryManager.exe" [2006-12-13 19:47 1003590]
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-10-31 18:58 921600]
 "QuickTime Task"="C:\Program Files\QuickTime Alternative\qttask.exe" [2007-04-27 09:41 282624]
 "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25 257088]
 "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
 "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
 "PD0620 STISvc"="P0620Pin.dll" [2005-05-10 19:03 36864 C:\WINDOWS\system32\P0620Pin.dll]
 "SoundMan"="SOUNDMAN.EXE" [2004-01-09 03:54 65536 C:\WINDOWS\SOUNDMAN.EXE]
 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:44 15360]
 C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
 Mawi_BDE_monitor.exe [2004-01-20 16:59:10 540160]
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
 "msacm.l3acm"= E:\WINDOWS\system32\l3codeca.acm
 "aux"= ctwdm32.dll
 "msacm.iac2"= E:\WINDOWS\system32\iac25_32.ax
 "aux1"= ctwdm32.dll
 "msacm.l3codec"= l3codecp.acm
 [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Mawi_BDE_monitor.exe]
 path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Mawi_BDE_monitor.exe
 backup=C:\WINDOWS\pss\Mawi_BDE_monitor.exeCommon Startup
 [HKLM\~\startupfolder\C:^Documents and Settings^Maria^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.0.3.lnk]
 path=C:\Documents and Settings\Maria\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.0.3.lnk
 backup=C:\WINDOWS\pss\OpenOffice.ux.pl 2.0.3.lnkStartup
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
 --a------ 2007-02-18 23:30 969728 C:\Program Files\Ares\Ares.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
 --a------ 2007-07-09 09:39 2119104 C:\Program Files\Gadu-Gadu\gg.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
 --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
 --a------ 2007-10-23 23:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
 --a------ 2006-12-28 17:09 4579328 C:\Program Files\VIA\RAID\raid_tool.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
 -ra------ 2008-07-01 20:46 25504040 C:\Program Files\Skype\Phone\Skype.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
 --a------ 2008-04-01 20:49 36352 C:\Program Files\Winamp\winampa.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
 --a------ 2006-12-13 19:47 1003590 C:\Program Files\Zinio\ZinioDeliveryManager.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\security center]
 "AntiVirusOverride"=dword:00000001
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
 "%windir%\\system32\\sessmgr.exe"=
 "C:\\Program Files\\Ares\\Ares.exe"=
 "C:\\Program Files\\Gadu-Gadu\\gg.exe"=
 "C:\\WINDOWS\\system32\\dpvsetup.exe"=
 "C:\\Program Files\\INTERIAPL\\Stefan\\Stefan.exe"=
 "C:\\Program Files\\iTunes\\iTunes.exe"=
 "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
 "C:\\Program Files\\MSN Messenger\\livecall.exe"=
 "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
 "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
 "C:\\Program Files\\ESET\\nod32.exe"=
 "C:\\Program Files\\ESET\\nod32kui.exe"=
 "C:\\Program Files\\POP Peeper\\POPPeeper.exe"=
 "C:\\Program Files\\123 Free Solitaire\\123FreeSolitaire.exe"=
 "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
 "42141:TCP"= 42141:TCP:AresChatServer
 "443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
 "37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
 "37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
 "37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
 R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 21:22]
 .
 Contents of the 'Scheduled Tasks' folder
 2008-08-14 C:\WINDOWS\Tasks\rpc.job
 - C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
 .
 - - - - ORPHANS REMOVED - - - -
 HKLM-Run-Cmaudio - cmicnfg.cpl
 HKU-Default-Run-PcSync - C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
 MSConfigStartUp-PCSuiteTrayApplication - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 .
 ------- Supplementary Scan -------
 .
 FireFox -: Profile - C:\Documents and Settings\Maria\Dane aplikacji\Mozilla\Firefox\Profiles\eldbvw43.default\
 FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.onet.pl/
 **************************************************************************
 catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
 Rootkit scan 2008-08-15 17:53:45
 Windows 5.1.2600 Dodatek Service Pack 2 NTFS
 scanning hidden processes ...
 scanning hidden autostart entries ...
 scanning hidden files ...
 scan completed successfully
 hidden files: 0
 **************************************************************************
 .
 Completion time: 2008-08-15 17:54:51
 ComboFix-quarantined-files.txt 2008-08-15 15:54:35
 Pre-Run: 66,044,850,176 bajtów wolnych
 Post-Run: 66,036,441,088 bajtów wolnych
 159 --- E O F --- 2007-06-30 05:51:26
Edit by Mike013
Następnym razem wstawiaj logi zgodnie z reguleminem
 przeczytaj-zanim-wstawisz-logi-na-forum-vt93842.html
  przeczytaj-zanim-wstawisz-logi-na-forum-vt93842.html    
				
 
	

 
 

 
	 , nie mam cd z win. Jeszcze raz dzieki i pozdrawiam
 , nie mam cd z win. Jeszcze raz dzieki i pozdrawiam