odczyta mi to ktos??
od razu powiem ze nei moge otwierac worda i plikow word bo wyskakuje mi komunikat ze za malo pamieci lub m9ejsca na dysku a mam ponad 80 gb i nie moge tez otwierac plikow rmvb mimo ze wczesniej dzialalo, wszystko sie powalilo po scanie kasperskym i usunieciu 4 trojanow
ComboFix 09-03-03.01 - super machina 2009-03-04 16:26:18.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.1023.600 [GMT 1:00]
Uruchomiony z: c:\documents and settings\super machina\Pulpit\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-04 do 2009-03-04 )))))))))))))))))))))))))))))))
.
2009-03-03 18:28 . 2009-03-03 18:28 <DIR> d-------- c:\program files\MSBuild
2009-03-03 18:28 . 2009-03-03 18:28 <DIR> d-------- c:\program files\Microsoft Works
2009-03-03 18:27 . 2009-03-03 18:27 <DIR> d-------- c:\program files\Microsoft.NET
2009-03-03 18:25 . 2009-03-03 18:25 <DIR> d-------- c:\program files\Microsoft Visual Studio 8
2009-03-03 18:24 . 2009-03-03 18:28 <DIR> d-------- c:\windows\SHELLNEW
2009-03-03 18:22 . 2009-03-03 18:22 <DIR> dr-h----- C:\MSOCache
2009-03-02 15:04 . 2009-03-02 15:13 101,287 --a------ c:\windows\system32\drivers\klin.dat
2009-03-02 15:04 . 2009-03-02 15:13 89,601 --a------ c:\windows\system32\drivers\klick.dat
2009-03-02 15:03 . 2009-03-04 16:28 4,390,432 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-03-02 15:03 . 2009-03-04 16:31 532,512 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-03-02 15:03 . 2009-03-04 16:28 37,476 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-03-02 15:03 . 2009-03-04 16:31 3,976 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-02-27 23:55 . 2009-02-27 23:55 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\CyberLink
2009-02-27 23:54 . 2009-02-27 23:54 <DIR> d-------- c:\program files\Common Files\CyberLink
2009-02-27 23:54 . 2009-02-27 23:54 <DIR> d-------- c:\documents and settings\super machina\Dane aplikacji\CyberLink
2009-02-27 23:53 . 2009-02-27 23:54 <DIR> d-------- c:\program files\CyberLink
2009-02-27 23:53 . 2009-02-27 23:53 29,480 --a------ c:\windows\system32\msxml3a.dll
2009-02-18 16:30 . 2006-10-22 15:06 208,896 --a------ c:\windows\system32\NVUNINST.EXE
2009-02-18 16:19 . 2009-02-18 16:19 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\nView_Profiles
2009-02-18 16:14 . 2005-04-05 20:22 261,888 -ra------ c:\windows\system32\drivers\nvnrm.sys
2009-02-18 16:14 . 2006-10-22 15:06 208,896 --a------ c:\windows\system32\nvunrm.exe
2009-02-18 16:14 . 2005-04-05 20:22 208,256 -ra------ c:\windows\system32\drivers\nvsnpu.sys
2009-02-18 16:14 . 2005-04-05 20:19 201,728 -ra------ c:\windows\system32\fdco1.dll
2009-02-18 16:14 . 2005-04-05 20:22 33,536 -ra------ c:\windows\system32\drivers\NVENETFD.sys
2009-02-18 16:14 . 2005-04-04 12:00 32,256 -ra------ c:\windows\system32\nvconrm.dll
2009-02-18 16:14 . 2005-04-05 20:22 12,928 -ra------ c:\windows\system32\drivers\nvnetbus.sys
2009-02-18 16:14 . 2005-04-05 20:19 9,728 -ra------ c:\windows\system32\bdco1.dll
2009-02-18 16:14 . 2005-02-08 07:26 3,596 --a------ c:\windows\system32\nvnrm.nvu
2009-02-18 16:10 . 2009-03-04 16:30 88,108 --a------ c:\windows\system32\nvapps.xml
2009-02-18 16:09 . 2009-02-18 16:33 <DIR> d-------- c:\windows\nview
2009-02-18 16:09 . 2006-10-22 15:06 208,896 --a------ c:\windows\system32\nvudisp.exe
2009-02-18 16:09 . 2006-10-22 12:22 17,056 --a------ c:\windows\system32\nvdisp.nvu
2009-02-16 16:18 . 2009-02-16 17:36 <DIR> d-------- c:\documents and settings\super machina\Dane aplikacji\Nowe Gadu-Gadu
2009-02-16 16:17 . 2009-02-16 16:17 <DIR> d-------- c:\program files\Nowe Gadu-Gadu
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 15:31 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2009-03-04 15:30 --------- d-----w c:\program files\neostrada tp
2009-03-03 17:31 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-03-03 12:52 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-03-02 14:13 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-03-02 14:08 --------- d-----w c:\program files\Eset
2009-03-02 14:01 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2009-02-27 22:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-27 22:53 505,128 ----a-w c:\windows\system32\msvcp71.dll
2009-02-27 22:53 353,576 ----a-w c:\windows\system32\msvcr71.dll
2009-02-27 21:52 --------- d-----w c:\program files\ALLPlayer
2009-02-18 20:30 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited
2009-02-17 17:14 --------- d-----w c:\program files\OpenOffice.org 2.4
2009-02-17 17:14 --------- d-----w c:\documents and settings\super machina\Dane aplikacji\OpenOffice.org2
2009-02-09 18:44 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-02-09 18:44 138,464 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-09 18:44 111,928 ----a-w c:\windows\system32\PnkBstrB.exe
2009-02-09 15:13 --------- d-----w c:\documents and settings\super machina\Dane aplikacji\Image Zone Express
2009-02-02 21:32 22,328 ----a-w c:\documents and settings\super machina\Dane aplikacji\PnkBstrK.sys
2009-02-01 16:34 682,280 ----a-w c:\windows\system32\pbsvc.exe
2009-01-30 16:54 --------- d-----w c:\program files\Winamp
2009-01-22 13:48 --------- d-----w c:\documents and settings\super machina\Dane aplikacji\Skype
2009-01-22 13:47 --------- d-----w c:\documents and settings\super machina\Dane aplikacji\skypePM
2009-01-15 12:48 --------- d-----w c:\program files\Lektury
2009-01-07 16:26 --------- d-----w c:\program files\Google
2009-01-04 16:59 --------- d--h--r c:\documents and settings\super machina\Dane aplikacji\SecuROM
2008-12-20 23:03 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-16 14:29 77,824 ----atw c:\windows\system32\DRWEBSP.DLL
2008-09-23 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012008092320080924\index.dat
.
------- Sigcheck -------
2008-04-14 18:21 977408 63a65ac59aa07472edffdca892b71c4c c:\windows\explorer.exe
2008-04-14 18:21 1226240 e96aec9214b5384f3bc8d4bda8f91e65 c:\windows\icon_TMP\explorer.exe
2008-04-14 18:21 977408 63a65ac59aa07472edffdca892b71c4c c:\windows\ServicePackFiles\i386\explorer.exe
2008-04-14 18:21 1035264 c791ed9eac5e76d9525e157b1d7a599a c:\windows\system_backup\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-05 68856]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2008-11-24 869888]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2009-02-27 9339496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-24 136600]
"Launch Ai Booster"="c:\program files\ASUS\Ai Booster\OverClk.exe" [2005-05-05 3632640]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]
"WOOWATCH"="c:\progra~1\NEOSTR~1\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\NEOSTR~1\GestMaj.exe" [2004-10-14 32768]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"AVP"="e:\kaspersky anti-virus 2009\avp.exe" [2009-03-02 206088]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\super machina\Menu Start\Programy\Autostart\
RocketDock.lnk - e:\vista inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.tscc"= e:\mpcstar\Codecs\tscc\tsccvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Polish\\setup.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"e:\\Valve\\hl.exe"=
"e:\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Counter-Strike 1.6\\hltv.exe"=
"e:\\Counter-Strike 1.6\\hlds.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13417:TCP"= 13417:TCP:BitComet 13417 TCP
"13417:UDP"= 13417:UDP:BitComet 13417 UDP
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
"17420:TCP"= 17420:TCP:BitComet 17420 TCP
"17420:UDP"= 17420:UDP:BitComet 17420 UDP
"10495:TCP"= 10495:TCP:BitComet 10495 TCP
"10495:UDP"= 10495:UDP:BitComet 10495 UDP
"11141:TCP"= 11141:TCP:BitComet 11141 TCP
"11141:UDP"= 11141:UDP:BitComet 11141 UDP
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2008-10-15 116992]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2008-10-15 64000]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a4b9a01-49c0-11dd-9c5f-806d6172696f}]
\Shell\AutoRun\command - F:\SETUP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://google.atcomet.com/b/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: { - c:\program files\Messenger\msmsgs.exe
FF - ProfilePath - c:\documents and settings\super machina\Dane aplikacji\Mozilla\Firefox\Profiles\fdj3ybyh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - hxxp://google.atcomet.com/b/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/sli ... pab&query=
FF - component: c:\documents and settings\super machina\Dane aplikacji\Mozilla\Firefox\Profiles\fdj3ybyh.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: e:\divx\DivX Content Uploader\npUpload.dll
FF - plugin: e:\divx\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: e:\divx\DivX Web Player\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 16:30:48
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-220523388-412668190-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:16,59,46,69,ce,50,97,2b,6a,d1,3c,b3,38,ad,97,20,71,23,f2,28,b9,1c,7d,
0a,b9,c4,66,a5,f9,87,33,40,08,15,ea,58,86,0c,6b,fa,31,48,42,15,af,a2,cc,fe,\
"??"=hex:59,e5,97,70,47,08,a5,1e,f6,13,83,cc,52,0d,a6,6c
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\FTRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\NEOSTR~1\TaskBarIcon.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
e:\vista inspirat 2\UberIcon\UberIcon Manager.exe
e:\vista inspirat 2\YzShadow\YzShadow.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Czas ukończenia: 2009-03-04 16:33:40 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-03-04 15:33:37
ComboFix2.txt 2009-02-01 15:49:59
ComboFix3.txt 2009-02-01 15:45:58
ComboFix4.txt 2009-01-29 12:25:52
Przed: 3 705 131 008 bajtów wolnych
Po: 4,075,192,320 bajtów wolnych
233 --- E O F --- 2009-02-25 19:06:09