Chodzi o to, że internet mi strasznie muli. Strony włączają sie 4 razy wolniej niz powinny.
Jeżeli możecie to rzuccie na to okiem.
log z ComboFix
ComboFix 08-04-27.3 - user 2008-04-29 23:38:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.1517 [GMT 2:00]
Running from: C:\Documents and Settings\user\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\deposit.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-29 )))))))))))))))))))))))))))))))
.
2008-04-27 19:56 . 2008-04-27 19:56 <DIR> d-------- C:\Program Files\Rockstar Games
2008-04-27 19:56 . 2008-04-27 19:56 <DIR> d-------- C:\Program Files\directx
2008-04-27 17:33 . 2008-04-27 17:33 <DIR> d-------- C:\Pulpit
2008-04-27 12:02 . 2008-04-27 12:02 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Media Player Classic
2008-04-27 12:00 . 2008-04-27 12:00 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-04-27 12:00 . 2008-03-21 22:30 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-04-27 12:00 . 2008-01-10 14:15 755,027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-04-27 12:00 . 2008-03-31 23:25 682,496 --a------ C:\WINDOWS\system32\divx.dll
2008-04-27 12:00 . 2006-09-24 17:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2008-04-27 12:00 . 2004-01-25 18:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-04-27 12:00 . 2007-09-04 18:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-04-27 12:00 . 2008-01-10 14:16 159,839 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-04-27 12:00 . 2007-09-21 02:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-04-27 12:00 . 2008-03-21 22:28 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-04-27 12:00 . 2007-10-03 17:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-04-26 23:52 . 2008-04-27 11:52 <DIR> d-------- C:\Program Files\XVid;-)
2008-04-26 23:47 . 2008-04-26 23:47 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-04-26 23:47 . 2008-04-26 23:47 <DIR> d-------- C:\Program Files\streamtofile.com
2008-04-26 23:33 . 2008-04-26 23:33 <DIR> d-------- C:\Program Files\FDRLab
2008-04-26 23:33 . 2008-04-26 23:33 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\FDRLab
2008-04-26 23:26 . 2008-04-26 23:26 <DIR> d-------- C:\q3test-1.08
2008-04-26 22:59 . 2008-04-26 22:59 <DIR> d-------- C:\Program Files\Codemasters
2008-04-26 22:59 . 1999-04-23 22:22 151,552 --a------ C:\WINDOWS\system32\MSOSS.DLL
2008-04-26 21:44 . 2008-04-26 21:44 <DIR> d-------- C:\Program Files\Ares
2008-04-26 21:27 . 2008-04-26 21:27 <DIR> d-------- C:\Program Files\Shareaza Pro
2008-04-26 21:27 . 2008-04-26 21:27 <DIR> d-------- C:\Program Files\P2P_Energy
2008-04-26 21:27 . 2008-04-26 21:27 <DIR> d-------- C:\Program Files\Conduit
2008-04-26 21:27 . 2008-04-26 21:27 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Shareaza
2008-04-26 21:01 . 2008-04-26 21:01 <DIR> d-------- C:\Downloads
2008-04-26 19:39 . 2007-11-22 17:00 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2008-04-26 19:31 . 2008-04-26 19:31 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Kazaa Lite
2008-04-26 19:01 . 2008-04-26 19:01 <DIR> d-------- C:\Program Files\Deluxe Ski Jump 3
2008-04-26 16:28 . 2008-04-26 16:28 <DIR> d-------- C:\Program Files\Avira
2008-04-26 15:52 . 2008-04-26 17:31 <DIR> d-------- C:\Program Files\mks_vir_2007
2008-04-26 13:00 . 2008-04-26 16:28 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-04-25 23:23 . 2008-04-25 23:23 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-04-25 23:19 . 2008-04-25 23:19 163,328 --a------ C:\WINDOWS\UNINEPSC.EXE
2008-04-25 22:46 . 2006-03-02 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-25 21:32 . 2008-04-25 21:32 <DIR> d-------- C:\WINDOWS\Sun
2008-04-25 21:31 . 2008-04-25 21:31 <DIR> d-------- C:\Program Files\Sun
2008-04-25 21:31 . 2008-04-25 21:31 <DIR> d-------- C:\Program Files\Java
2008-04-25 21:31 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-25 21:25 . 2008-04-25 21:25 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-25 21:18 . 2008-04-25 21:18 <DIR> d--hs---- C:\Documents and Settings\user\UserData
2008-04-25 21:03 . 2008-04-25 21:03 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Gadu-Gadu
2008-04-25 20:58 . 2008-04-25 20:58 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-04-25 20:58 . 2008-04-27 13:04 <DIR> d-------- C:\Documents and Settings\user\Gadu-Gadu
2008-04-25 20:48 . 2008-04-25 20:48 <DIR> d-------- C:\Program Files\EA SPORTS
2008-04-25 19:53 . 2008-04-25 19:53 <DIR> d-------- C:\Program Files\Google
2008-04-25 19:43 . 2003-10-16 19:07 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
2008-04-25 19:42 . 2008-04-25 19:42 <DIR> d-------- C:\Program Files\Thomson
2008-04-25 19:42 . 2003-12-08 11:53 70,688 --a------ C:\WINDOWS\system32\drivers\alcaudsl.sys
2008-04-25 19:42 . 2003-12-08 11:53 53,600 --a------ C:\WINDOWS\system32\drivers\alcan5wn.sys
2008-04-25 19:42 . 2003-12-08 11:53 5,606 --a------ C:\WINDOWS\system32\stci.dll
2008-04-25 19:42 . 2003-12-08 11:53 5,280 --a------ C:\WINDOWS\system32\drivers\alcawh.sys
2008-04-25 19:42 . 2003-12-08 11:53 3,968 --a------ C:\WINDOWS\system32\drivers\alcacr.sys
2008-04-25 19:41 . 2008-04-29 22:57 <DIR> d-------- C:\Program Files\Neostrada TP
2008-04-25 19:41 . 2008-04-25 19:41 1,409 --a------ C:\WINDOWS\system32\tmp610BD.FOT
2008-04-25 19:29 . 2001-03-08 18:30 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2008-04-25 19:28 . 2008-04-25 19:28 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2008-04-25 19:25 . 2008-04-25 19:26 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\CyberLink
2008-04-25 19:25 . 2007-03-22 21:28 1,066,544 --------- C:\WINDOWS\system32\MFC71.dll
2008-04-25 19:25 . 2007-03-22 21:28 1,053,232 --------- C:\WINDOWS\system32\MFC71u.dll
2008-04-25 19:25 . 2007-03-22 21:27 505,392 --------- C:\WINDOWS\system32\msvcp71.dll
2008-04-25 19:25 . 2007-03-22 21:28 353,840 --------- C:\WINDOWS\system32\msvcr71.dll
2008-04-25 19:22 . 2008-04-25 19:29 <DIR> d-------- C:\Program Files\CyberLink
2008-04-25 19:22 . 2008-04-25 19:22 <DIR> d-------- C:\MyWorks
2008-04-25 18:59 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-04-23 21:32 . 2008-04-23 21:32 262,144 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-04-23 21:32 . 2008-04-23 21:32 86,016 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-04-23 21:31 . 2008-04-23 21:31 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2008-04-23 21:31 . 2004-10-25 20:02 21,664 --a------ C:\WINDOWS\system32\drivers\Entech.sys
2008-04-23 21:31 . 1999-11-02 10:01 6,173 --a------ C:\WINDOWS\system32\drivers\Entech.vxd
2008-04-23 21:31 . 2004-06-22 15:44 5,632 --a------ C:\WINDOWS\system32\drivers\Entech64.sys
2008-04-23 21:31 . 2001-11-19 19:05 3,972 --a------ C:\WINDOWS\system32\drivers\PciBus.sys
2008-04-23 21:29 . 2008-04-23 21:29 <DIR> d-------- C:\Program Files\Futuremark
2008-04-23 21:26 . 2008-04-23 21:26 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\ATI
2008-04-23 21:26 . 2008-04-23 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ATI
2008-04-23 21:25 . 2008-04-23 21:25 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-04-23 21:15 . 2008-04-23 21:15 <DIR> d-------- C:\Program Files\Common Files\ATI Technologies
2008-04-23 21:12 . 2007-12-21 04:35 3,107,788 -ra------ C:\WINDOWS\system32\ativvaxx.dat
2008-04-23 21:12 . 2007-12-21 04:35 3,107,788 -ra------ C:\WINDOWS\system32\ativva5x.dat
2008-04-23 21:12 . 2007-12-21 04:35 887,724 -ra------ C:\WINDOWS\system32\ativva6x.dat
2008-04-23 21:12 . 2007-12-20 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-04-23 21:12 . 2007-12-21 05:09 368,640 -ra------ C:\WINDOWS\system32\ATIDEMGX.dll
2008-04-23 21:12 . 2007-12-21 05:02 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2008-04-23 21:12 . 2007-11-27 21:34 160,289 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-04-23 21:12 . 2006-12-28 18:44 84,992 -ra------ C:\WINDOWS\system32\drivers\AtiHdAud.sys
2008-04-23 21:12 . 2007-11-20 10:23 11,874 -ra------ C:\WINDOWS\atiogl.xml
2008-04-23 21:12 . 2007-08-31 16:20 7,167 -ra------ C:\WINDOWS\system32\atifglpf.xml
2008-04-23 21:11 . 2008-04-23 21:16 <DIR> d-------- C:\Program Files\ATI Technologies
2008-04-23 21:09 . 2008-04-23 21:09 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-04-23 21:09 . 2006-06-14 11:00 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-23 21:09 . 2006-06-14 11:00 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-04-23 21:08 . 2004-08-03 23:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-23 21:08 . 2004-08-03 22:58 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-04-23 21:08 . 2004-08-03 22:58 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-04-23 21:08 . 2004-08-03 22:58 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-04-23 21:07 . 2007-05-31 09:19 96,896 -ra------ C:\WINDOWS\system32\drivers\Rtenicxp.sys
2008-04-23 21:06 . 2008-04-23 21:06 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-04-23 21:06 . 2008-04-23 21:06 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\InstallShield
2008-04-23 21:05 . 2006-08-01 09:02 49,152 -r------- C:\WINDOWS\system32\ChCfg.exe
2008-04-23 21:04 . 2008-04-23 21:04 <DIR> d-------- C:\Program Files\Realtek
2008-04-23 21:04 . 2008-04-27 19:56 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-23 21:03 . 2008-04-23 21:11 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-23 21:03 . 2007-07-26 11:09 520,192 -r------- C:\WINDOWS\RtlExUpd.dll
2008-04-23 21:03 . 2008-04-23 21:03 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-04-23 20:49 . 2008-04-23 20:49 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-23 20:49 . 2008-04-23 20:49 <DIR> d-------- C:\Program Files\Intel
2008-04-23 20:49 . 2008-04-23 20:49 <DIR> d-------- C:\Intel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 16:29 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-16 16:28 --------- d-----w C:\Program Files\Usługi online
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2008-03-30 12:38 1522200 --a------ C:\Program Files\P2P_Energy\tbP2P_.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D023EBF-70B8-45A6-9ED5-556515FA0FE4}]
C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "C:\Program Files\P2P_Energy\tbP2P_.dll" [2008-03-30 12:38 1522200]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"Power2GoExpress"="C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" [2007-08-17 11:06 2503976]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-25 19:53 171448]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]
"areslite"="C:\Program Files\Ares Lite Edition\AresLite.exe" [ ]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-04 02:32 961024]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 09:21 16384000 C:\WINDOWS\RTHDCPL.exe]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 15:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55 54832]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 19:07 24576]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 19:07 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 19:07 53248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24316:TCP"= 24316:TCP:BitComet 24316 TCP
"24316:UDP"= 24316:UDP:BitComet 24316 UDP
S3 FXDrv32;FXDrv32;E:\FXDrv32.sys []
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-29 23:39:32
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-29 23:39:49
ComboFix-quarantined-files.txt 2008-04-29 21:39:48
Pre-Run: 5,637,644,288 bajtów wolnych
Post-Run: 5,676,896,256 bajtów wolnych
198 --- E O F --- 2008-04-26 14:22:02


