
ostatnio odkryłem, że mój komputer wolno chodzi. Wolno się włącza, na starcie systemu wolno reaguje na moje polecenia. Przy instalowaniu jakiejś aplikacji lub gry, mogę coś robić ale wszystko jest jakieś zamulone

Log z ComoFixa:
- Kod: Zaznacz wszystko
ComboFix 09-04-16.02 - PC 2009-04-16 16:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.3327.2775 [GMT 2:00]
Uruchomiony z: c:\documents and settings\PC\Pulpit\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090416-0] *On-access scanning disabled* (Updated)
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ISODRIVE
-------\Legacy_PROTECTOR
-------\Service_ISODrive
-------\Service_protector
((((((((((((((((((((((((( Pliki utworzone od 2009-03-16 do 2009-04-16 )))))))))))))))))))))))))))))))
.
2009-04-15 11:17 . 2008-10-16 12:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-15 11:17 . 2008-10-16 12:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-15 11:17 . 2008-10-16 12:06 27496 ----a-w c:\windows\system32\mucltui.dll.mui
2009-04-14 19:33 . 2009-04-14 19:33 -------- d-sh--w c:\documents and settings\PC\IECompatCache
2009-04-14 19:33 . 2009-04-14 19:33 -------- d-sh--w c:\documents and settings\PC\PrivacIE
2009-04-14 19:32 . 2009-04-14 19:32 -------- d-sh--w c:\documents and settings\PC\IETldCache
2009-04-14 19:30 . 2009-04-14 19:30 -------- d-----w c:\windows\ie8updates
2009-04-14 19:28 . 2009-04-14 19:29 -------- dc-h--w c:\windows\ie8
2009-04-14 19:22 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-14 15:00 . 2008-02-15 07:33 36224 ----a-w c:\windows\system32\drivers\protector.sys
2009-04-14 13:02 . 2009-04-14 13:02 -------- d-----w c:\documents and settings\PC\Dane aplikacji\Desktopicon
2009-04-14 02:19 . 2009-04-14 02:19 41808 ----a-w c:\windows\system32\xfcodec.dll
2009-04-08 18:10 . 2009-04-08 18:12 4273 ----a-w C:\test.spr
2009-04-08 18:05 . 1998-10-07 10:54 327168 ----a-w c:\windows\IsUn0415.exe
2009-04-04 17:51 . 2009-04-04 17:51 -------- d-----w c:\documents and settings\PC\Dane aplikacji\teamspeak2
2009-04-04 17:50 . 2009-04-04 17:50 34064 ----a-w c:\windows\system32\lhacm.acm
2009-04-01 18:00 . 2009-04-01 18:00 -------- d-----w c:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Sony Ericsson
2009-04-01 17:59 . 2009-04-01 17:59 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\BVRP Software
2009-04-01 17:59 . 2007-12-10 13:22 110120 ----a-w c:\windows\system32\drivers\s3017unic.sys
2009-04-01 17:59 . 2007-12-10 13:22 100648 ----a-w c:\windows\system32\drivers\s3017obex.sys
2009-04-01 17:59 . 2007-12-10 13:22 104616 ----a-w c:\windows\system32\drivers\s3017mgmt.sys
2009-04-01 17:59 . 2007-12-10 13:22 10792 ----a-w c:\windows\system32\drivers\s3017cr.sys
2009-04-01 17:58 . 2007-12-10 13:22 12200 ----a-w c:\windows\system32\drivers\s3017whnt.sys
2009-04-01 17:58 . 2007-12-10 13:22 12200 ----a-w c:\windows\system32\drivers\s3017wh.sys
2009-04-01 17:58 . 2007-12-10 13:22 25512 ----a-w c:\windows\system32\drivers\s3017nd5.sys
2009-04-01 17:58 . 2007-12-10 13:22 15016 ----a-w c:\windows\system32\drivers\s3017mdfl.sys
2009-04-01 17:58 . 2007-12-10 13:22 110632 ----a-w c:\windows\system32\drivers\s3017mdm.sys
2009-04-01 17:58 . 2007-12-10 13:22 12200 ----a-w c:\windows\system32\drivers\s3017cmnt.sys
2009-04-01 17:58 . 2007-12-10 13:22 12200 ----a-w c:\windows\system32\drivers\s3017cm.sys
2009-04-01 17:58 . 2007-12-10 13:22 83880 ----a-w c:\windows\system32\drivers\s3017bus.sys
2009-04-01 17:58 . 2009-04-01 17:58 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Sony Ericsson
2009-04-01 17:58 . 2009-04-01 17:58 -------- d-----w c:\documents and settings\PC\Dane aplikacji\InstallShield
2009-04-01 15:43 . 2009-03-09 13:27 453456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-04-01 15:43 . 2009-03-09 13:27 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-04-01 15:43 . 2009-03-16 12:18 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-04-01 15:43 . 2009-03-16 12:18 517448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-04-01 15:43 . 2009-03-16 12:18 235352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-04-01 15:43 . 2009-03-09 13:27 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-04-01 15:43 . 2009-03-16 12:18 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-21 22:04 . 2009-03-21 22:04 4194322 ----a-w C:\memory_map.tga
2009-03-20 19:07 . 2009-03-20 19:07 -------- d-----w c:\documents and settings\NetworkService\Dane aplikacji\Xfire
2009-03-20 19:06 . 2009-04-14 10:13 -------- d-----w c:\documents and settings\PC\Dane aplikacji\Xfire
2009-03-17 21:08 . 2009-03-17 21:08 -------- d-----w c:\documents and settings\PC\Dane aplikacji\The Creative Assembly
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 10:26 . 2008-12-19 15:39 138920 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-16 10:26 . 2008-12-19 15:39 189072 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-16 10:14 . 2008-04-15 12:00 83988 ----a-w c:\windows\system32\perfc015.dat
2009-04-16 10:14 . 2008-04-15 12:00 490808 ----a-w c:\windows\system32\perfh015.dat
2009-04-14 20:53 . 2009-04-14 14:55 -------- d-----w c:\program files\PlayAll
2009-04-14 19:31 . 2009-01-13 14:03 2119240 ----a-w c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
2009-04-14 17:45 . 2009-02-08 13:52 -------- d-----w c:\program files\Km TPR
2009-04-14 14:29 . 2009-03-20 19:06 -------- d-----w c:\program files\Xfire
2009-04-14 13:02 . 2009-04-14 13:02 -------- d-----w c:\program files\Unlocker
2009-04-14 11:32 . 2009-04-14 11:32 -------- d-----w c:\program files\Klawiatura
2009-04-12 18:15 . 2008-12-19 15:39 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-04-11 10:50 . 2008-12-19 16:57 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-11 10:13 . 2009-01-10 18:17 -------- d-----w c:\program files\Activision
2009-04-11 10:10 . 2008-12-19 17:00 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-08 18:29 . 2009-02-06 14:06 -------- d-----w c:\program files\AGEIA Technologies
2009-04-08 18:14 . 2009-02-06 14:05 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-08 18:05 . 2009-04-08 18:05 -------- d-----w c:\program files\Software2000
2009-04-04 17:51 . 2009-04-04 17:50 -------- d-----w c:\program files\Teamspeak2_RC2
2009-04-02 11:17 . 2009-03-03 17:52 -------- d-----w c:\program files\PermissionResearch
2009-04-01 18:08 . 2009-04-01 17:59 -------- d-----w c:\program files\Avanquest update
2009-04-01 17:58 . 2009-04-01 17:58 -------- d-----w c:\program files\Sony Ericsson
2009-04-01 15:44 . 2009-03-02 18:55 -------- d-----w c:\program files\Landwirtschafts-Simulator 2008
2009-04-01 15:13 . 2009-03-02 14:34 -------- d-----w c:\program files\Java
2009-03-24 20:27 . 2008-12-19 17:21 -------- d-----w c:\program files\7-Zip
2009-03-16 16:47 . 2008-12-20 19:41 -------- d-----w c:\program files\Cheat Engine
2009-03-11 16:31 . 2009-02-09 13:47 -------- d-----w c:\program files\Ahead
2009-03-09 03:19 . 2008-12-28 12:04 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 14:20 . 2009-03-04 13:38 -------- d-----w c:\program files\Wiedźmin
2009-03-08 13:44 . 2009-02-12 19:46 -------- d-----w c:\program files\Kohan
2009-03-08 02:34 . 2008-04-15 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2008-04-15 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2008-04-15 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2008-04-15 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2008-04-15 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2008-04-15 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2008-04-15 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2008-04-15 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2008-04-15 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2008-04-15 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-04 14:35 . 2009-03-04 14:35 278984 ----a-w c:\windows\system32\drivers\atksgt.sys
2009-03-04 14:35 . 2009-03-04 14:35 25416 ----a-w c:\windows\system32\drivers\lirsgt.sys
2009-03-04 14:35 . 2009-03-04 14:20 -------- d-----w c:\program files\AllSubmitter
2009-03-02 16:07 . 2009-03-02 16:07 -------- d-----w c:\documents and settings\PC\Dane aplikacji\Thinstall
2009-03-01 19:20 . 2009-03-01 17:57 -------- d-----w c:\documents and settings\PC\Dane aplikacji\FarmingSimulator2008
2009-02-25 20:35 . 2009-02-25 20:35 -------- d-----w c:\program files\SopCast
2009-02-23 20:22 . 2009-02-23 20:22 -------- d-----w c:\program files\UltraISO
2009-02-23 20:22 . 2009-02-23 20:22 -------- d-----w c:\program files\Common Files\EZB Systems
2009-02-23 18:53 . 2009-02-23 18:53 -------- d-----w c:\program files\Common Files\Futuremark Shared
2009-02-19 20:05 . 2008-12-19 17:21 -------- d-----w c:\program files\NAPI-PROJEKT
2009-02-19 20:05 . 2008-12-19 17:21 -------- d-----w c:\program files\ALLPlayer
2009-02-12 15:14 . 2008-12-19 15:39 22328 ----a-w c:\documents and settings\PC\Dane aplikacji\PnkBstrK.sys
2009-01-27 15:23 . 2008-12-19 17:14 27488 ----a-w c:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-01-18 17:07 . 2009-01-18 17:07 1700352 ----a-w c:\windows\system32\gdiplus.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2009-02-06 9302632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-03 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-13 16871936]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
c:\documents and settings\PC\Menu Start\Programy\Autostart\
Tworzenie wycink˘w ekranu i uruchamianie programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALLUpdate]
2008-11-24 19:44 869888 ----a-w c:\program files\ALLPlayer\ALLUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40 687560 ----a-w c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2009-01-13 16:45 306088 ----a-w e:\rockstar games social club\RGSCLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
2008-06-25 13:13 5625344 ----a-w c:\program files\ASUS\EPU-4 Engine\FourEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2008-08-03 23:02 36352 ----a-w c:\program files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"e:\\GRY\\Activision\\Call of Duty 4 Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\program files\\permissionresearch\\prmrsr.exe"=
R3 cpuz130;cpuz130; [x]
R3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\DRIVERS\s3017bus.sys [2007-12-10 83880]
R3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s3017mdfl.sys [2007-12-10 15016]
R3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s3017mdm.sys [2007-12-10 110632]
R3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s3017mgmt.sys [2007-12-10 104616]
R3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\DRIVERS\s3017nd5.sys [2007-12-10 25512]
R3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s3017obex.sys [2007-12-10 100648]
R3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\DRIVERS\s3017unic.sys [2007-12-10 110120]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-05-20 93696]
S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\l1e51x86.sys [2008-06-25 36864]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22bfe8a6-d64c-11dd-a7b3-002215ed77a0}]
\Shell\AutoRun\command - \Firefox\FirefoxPortable.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da487f5a-d32d-11dd-a7ab-002215ed77a0}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Zawartość folderu 'Zaplanowane zadania'
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-Prec - c:\program files\Prec\PrecStarter.exe
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.com/
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {7A692276-F39C-465B-94F8-52B15B5C6334} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\93pl7xph.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (pl)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
FF - component: c:\program files\PermissionResearch\components\prxg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOggX.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 16:24
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-1123561945-1644491937-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:48,27,3f,ec,ff,b5,28,0b,cd,50,42,ee,36,ef,39,db,ff,cc,c7,cb,ff,e7,81,
2d,bb,4a,25,6d,e1,db,5c,43,61,7e,a5,20,6a,a1,dc,34,75,b7,1d,07,b2,f9,f7,fc,\
"??"=hex:2f,b6,6f,45,ee,e2,ec,0a,29,d5,69,d3,55,fd,2c,18
[HKEY_USERS\S-1-5-21-1123561945-1644491937-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:46,59,1c,aa,67,b3,f9,1c,b5,fc,14,a1,c2,55,56,08,9f,ec,00,23,e8,
3c,73,9a,14,58,69,6d,01,a3,19,6f,ad,c9,a9,0b,f0,73,04,59,b9,99,a3,0b,a7,1c,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(496)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Czas ukończenia: 2009-04-16 16:25 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-04-16 14:25
Przed: 44 836 278 272 bajtów wolnych
Po: 47 674 146 816 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
260 --- E O F --- 2008-12-20 20:22
Log z Hijack This:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:26:38, on 2009-04-16
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A692276-F39C-465B-94F8-52B15B5C6334}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5517 bytes