ojojoj znalazłam kolejny plik który moze być osttanim logiem ;/ boje sie od nowa zorbić log bo mi ciągle kompa wyłacza
ComboFix 08-05-11.1 - Dorotka 2008-05-12 23:17:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.216 [GMT 2:00]
Running from: C:\Documents and Settings\Dorotka\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dorotka\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\TEMP\AD.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{DEF85C80-216A-43AB-AF70-1665EDBE2780}
-------\Service_{DEF85C80-216A-43ab-AF70-1665EDBE2780}
((((((((((((((((((((((((( Files Created from 2008-04-12 to 2008-05-12 )))))))))))))))))))))))))))))))
.
2008-05-12 21:41 . 2008-05-12 21:41 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-08 17:11 . 2008-05-08 17:11 <DIR> d-------- C:\Documents and Settings\Dorotka\Dane aplikacji\Thinstall
2008-05-04 21:29 . 2008-05-04 21:29 15 --a------ C:\WINDOWS\Robot Office Common.ini
2008-05-04 21:23 . 2008-05-04 21:23 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-04 21:23 . 2008-05-04 21:23 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 21:02 --------- d-----w C:\Documents and Settings\Dorotka\Dane aplikacji\Skype
2008-05-12 17:07 --------- d-----w C:\Documents and Settings\Dorotka\Dane aplikacji\skypePM
2008-05-11 22:54 --------- d-----w C:\Program Files\DC++
2008-04-16 15:01 --------- d-----w C:\Program Files\SkanerOnline
2008-04-09 21:36 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-31 22:35 63,488 ----a-w C:\WINDOWS\system32\HaspEmu.dll
2008-03-31 22:19 --------- d-----w C:\Program Files\Common Files\RbtProt
2008-03-31 22:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-31 22:15 --------- d-----w C:\Program Files\Robot Office
2008-03-30 21:06 --------- d-----w C:\Program Files\MathType
2008-03-30 21:06 --------- d-----w C:\Documents and Settings\Dorotka\Dane aplikacji\Design Science
2008-03-30 16:24 --------- d-----w C:\Program Files\Winamp
2008-03-30 11:32 --------- d-----w C:\Program Files\Common Files\HP
2008-03-26 10:01 --------- d-----w C:\Documents and Settings\Dorotka\Dane aplikacji\DivX
2008-03-26 09:59 --------- d-----w C:\Program Files\Codec
2008-03-19 18:35 --------- d-----w C:\Program Files\eMule
2008-03-16 09:50 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-03-15 21:21 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2008-03-13 21:19 --------- d-----w C:\Program Files\Java
2008-03-13 21:17 --------- d-----w C:\Program Files\Common Files\Java
2008-03-12 15:09 --------- d-----w C:\Program Files\Jasc Software Inc
2008-03-12 15:09 --------- d-----w C:\Documents and Settings\Dorotka\Dane aplikacji\Jasc Software Inc
2008-03-09 19:48 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-03-09 16:49 6,656 ----a-w C:\WINDOWS\system32\haspvdd.dll
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-05-12_21.45.04,24 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-12 19:00:47 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-12 21:21:34 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2008-05-12 21:22:17 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_190.dat
+ 2008-05-12 21:21:39 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_488.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-01-30 16:58 1716224]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 18:22 21898024]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-05 10:34 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 15:43 45056]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 09:57 143360]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 12:48 157592]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-09-26 16:49 35328]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 19:29 13312]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 08:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
R1 aswSP;avast! Self Protection;C:\WINDOWS\System32\drivers\aswSP.sys [2008-03-29 19:31]
R2 SG_Service;SoftGuard Service;C:\Program Files\Common Files\RbtProt\sgsrv.exe [2003-10-25 12:51]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-12 23:22:27
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2008-05-12 23:25:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-12 21:25:10
ComboFix2.txt 2008-05-12 19:45:17
Pre-Run: 1,095,745,536 bajtów wolnych
Post-Run: 1,039,724,544 bajt˘w wolnych
123
przepraszam za te niejasności i niecierpliwie czekam na odp i pomoc; )