Zrobiłem tak jak kazałeś, a to log z Combofixa
ComboFix 07-12-31.4 - Dom 2008-01-04 17:40:37.5 - NTFSx86
Running from: C:\Documents and Settings\Dom\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dom\Pulpit\CFScript.txt
FILE
C:\WINDOWS\system\322958199783.dat
C:\WINDOWS\system32\antivir32.exe
C:\WINDOWS\system32\cg.exe
C:\WINDOWS\system32\cxdsfs.exe
C:\WINDOWS\system32\driversfidbox.dat
C:\WINDOWS\system32\driversoreans32.sys
C:\WINDOWS\system32\dsfds.pif
C:\WINDOWS\system32\hqghumea.dll
C:\WINDOWS\system32\kfgbcg.exe
C:\WINDOWS\system32\mccaffe32.exe
C:\WINDOWS\system32\mysnlive.exe
C:\WINDOWS\system32\sysrest32.exe
C:\WINDOWS\system32\vinampd.exe
C:\WINDOWS\system32\zpacdh.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\a.bat
C:\WINDOWS\system32\cg.exe
C:\WINDOWS\system32\cxdsfs.exe
C:\WINDOWS\system32\dsfds.pif
C:\WINDOWS\system32\hqghumea.dll
C:\WINDOWS\system32\kfgbcg.exe
C:\WINDOWS\system32\mysnlive.exe
C:\WINDOWS\system32\sysrest32.exe
C:\WINDOWS\system32\vinampd.exe
C:\WINDOWS\system32\zpacdh.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.
2008-01-04 13:11 . 2008-01-04 13:12 548,864 --a------ C:\WINDOWS\system32\igfxsrvc32.exe
2008-01-03 21:51 . 2008-01-03 21:51 2,855 --a------ C:\WINDOWS\system32\win32.PIF
2008-01-03 21:50 . 2008-01-03 21:50 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-03 19:06 . 2008-01-03 19:06 393,216 -r-hsc--- C:\WINDOWS\system32\dllcache\msfav32.exe
2008-01-03 19:03 . 2008-01-03 19:03 0 --a------ C:\WINDOWS\system32\ftpupd.exe
2008-01-03 19:00 . 2008-01-03 19:00 1,204,224 ---hs---- C:\WINDOWS\system32\msygl32.exe
2008-01-03 19:00 . 2008-01-04 17:23 0 --a------ C:\adware.exe
2008-01-03 15:52 . 2008-01-03 21:26 73 --a------ C:\WINDOWS\system32\i
2008-01-03 15:48 . 2008-01-03 15:49 <DIR> d-------- C:\Program Files\Silent
2008-01-03 15:43 . 2008-01-03 15:43 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-03 15:42 . 2008-01-03 15:42 <DIR> dr------- C:\Documents and Settings\Administrator\Ulubione
2008-01-03 15:42 . 2008-01-03 15:44 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-01-03 15:42 . 2008-01-03 15:42 <DIR> d-------- C:\Documents and Settings\Administrator\Menu Start
2008-01-02 14:34 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-30 19:14 . 2007-12-30 19:14 <DIR> d-------- C:\Program Files\D-Tools
2007-12-30 19:14 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2007-12-30 19:14 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2007-12-30 19:11 . 2007-12-30 19:11 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-12-28 00:48 . 2007-12-28 10:52 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-12-28 00:32 . 2007-12-28 00:32 <DIR> d-------- C:\Program Files\GameSpy Arcade
2007-12-25 19:10 . 2007-12-25 19:10 <DIR> d-------- C:\WINDOWS\system32\Nowy folder
2007-12-24 14:09 . 2007-12-24 18:30 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-24 14:09 . 2007-12-24 18:30 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-24 14:08 . 2007-12-24 14:08 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-24 14:08 . 2008-01-04 17:23 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2007-12-24 14:08 . 2008-01-04 17:52 4,069,664 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-24 14:08 . 2008-01-04 17:52 80,928 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-24 14:08 . 2008-01-04 17:51 56,600 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-24 14:08 . 2008-01-04 17:51 9,680 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-24 14:04 . 2007-12-24 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2007-12-24 11:34 . 2007-12-24 11:39 20,101 --a------ C:\WINDOWS\system32\cx.exe
2007-12-24 08:32 . 2007-12-24 08:32 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2007-12-24 08:32 . 2007-12-24 08:33 <DIR> d-------- C:\Program Files\TuneUp Utilities 2007
2007-12-24 08:32 . 2007-12-24 08:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-24 08:32 . 2007-12-24 08:32 <DIR> d-------- C:\Documents and Settings\Dom\Dane aplikacji\TuneUp Software
2007-12-24 08:32 . 2007-12-24 08:32 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software
2007-12-24 08:32 . 2007-05-16 09:41 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-12-24 08:06 . 2007-12-24 08:14 20,102 --a------ C:\WINDOWS\system32\dfs.exe
2007-12-24 07:13 . 2007-12-29 21:47 <DIR> d-------- C:\Program Files\dfrerter
2007-12-24 07:10 . 2007-12-24 11:18 625,789 --a------ C:\WINDOWS\system32\dfsdfs.exe
2007-12-23 23:51 . 2007-12-24 08:43 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-23 23:51 . 2007-12-23 23:51 <DIR> d-------- C:\Documents and Settings\Dom\Dane aplikacji\PC Tools
2007-12-23 23:51 . 2007-10-18 00:16 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-23 23:51 . 2007-10-18 00:15 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-23 23:51 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-23 23:51 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-23 22:54 . 2007-12-23 22:54 20,117 --a------ C:\WINDOWS\system32\cgdfs.exe
2007-12-23 17:56 . 2008-01-03 15:56 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2007-12-23 17:56 . 2007-12-23 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\Szablony
2007-12-23 17:56 . 2007-12-23 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\Dane aplikacji
2007-12-23 10:41 . 2007-12-27 00:24 69 --a------ C:\WINDOWS\NeroDigital.ini
2007-12-22 16:48 . 2007-12-22 16:48 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-12-22 16:48 . 2007-12-22 16:48 <DIR> d-------- C:\Program Files\Ahead
2007-12-22 16:48 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-12-22 16:48 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-12-22 16:48 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-12-22 16:48 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-12-22 16:48 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-12-22 16:48 . 2006-01-12 16:40 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-12-22 16:48 . 2005-09-01 12:03 127,488 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2007-12-22 16:48 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-12-22 16:48 . 2005-09-01 12:03 5,888 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2007-12-21 15:26 . 2007-12-21 15:26 269,334 --a------ C:\WINDOWS\system32\epsbat.bmp
2007-12-21 15:19 . 2007-12-21 15:19 269,334 --a------ C:\WINDOWS\system32\ihkred.bmp
2007-12-21 13:29 . 2007-12-21 13:29 269,334 --a------ C:\WINDOWS\system32\ehcfml.bmp
2007-12-21 13:19 . 2007-12-21 13:19 33,952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
2007-12-21 13:14 . 2007-12-21 13:14 269,334 --a------ C:\WINDOWS\system32\cfqtgr.bmp
2007-12-21 12:55 . 2007-12-21 12:55 269,334 --a------ C:\WINDOWS\system32\lcnidojahsnih.bmp
2007-12-21 11:03 . 2007-12-21 11:03 269,334 --a------ C:\WINDOWS\system32\dgnmdkred.bmp
2007-12-21 10:11 . 2007-12-21 10:12 109 --ahs---- C:\WINDOWS\system32\2958199783.dat
2007-12-21 08:11 . 2007-12-21 08:11 269,334 --a------ C:\WINDOWS\system32\nelgbehkn.bmp
2007-12-21 08:09 . 2007-12-21 08:09 269,334 --a------ C:\WINDOWS\system32\apgrmhsrepor.bmp
2007-12-20 23:04 . 2007-12-20 23:04 269,334 --a------ C:\WINDOWS\system32\cbmlofqd.bmp
2007-12-16 17:16 . 2007-12-29 21:50 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-12-16 17:10 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-14 21:00 . 2008-01-03 19:46 <DIR> d-------- C:\Documents and Settings\Dom\Dane aplikacji\skypePM
2007-12-14 21:00 . 2007-12-14 21:00 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2007-12-14 20:58 . 2008-01-03 19:46 <DIR> d-------- C:\Documents and Settings\Dom\Dane aplikacji\Skype
2007-12-14 20:57 . 2007-12-14 20:57 <DIR> d-------- C:\Program Files\Skype
2007-12-14 20:57 . 2007-12-14 20:57 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-12-13 21:57 . 2003-08-25 18:06 182,880 --a------ C:\WINDOWS\system32\iuengine.dll
2007-12-13 21:57 . 2003-08-25 18:06 182,880 --a--c--- C:\WINDOWS\system32\dllcache\iuengine.dll
2007-12-13 20:13 . 2007-12-13 21:50 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-12-13 19:27 . 2007-12-14 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2007-12-13 18:37 . 2003-12-11 11:15 1,230,336 -ra------ C:\WINDOWS\system32\MSXML4.dll
2007-12-13 18:37 . 2003-12-11 11:15 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2007-12-13 18:37 . 2003-12-11 11:15 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2007-12-13 18:37 . 2003-12-11 11:15 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2007-12-13 18:37 . 2003-12-11 11:15 82,432 -ra------ C:\WINDOWS\system32\MSXML4r.dll
2007-12-13 18:37 . 2003-12-11 11:15 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2007-12-13 18:03 . 2007-12-13 20:13 <DIR> d-------- C:\Program Files\HP
2007-12-10 22:23 . 2007-12-13 20:09 553,479 --a------ C:\WINDOWS\hpdj3740.hi2
2007-12-10 22:23 . 2007-12-13 20:09 10,645 --a------ C:\WINDOWS\hpdj3740.bu2
2007-12-09 22:57 . 2007-12-13 21:51 767,078 --a------ C:\WINDOWS\hpdj3740.hi1
2007-12-09 22:57 . 2007-12-13 21:51 10,901 --a------ C:\WINDOWS\hpdj3740.bu1
2007-12-09 22:50 . 2007-12-13 21:57 8,455 --a------ C:\WINDOWS\hpdj3740.his
2007-12-09 22:50 . 2007-12-13 21:57 1,733 --a------ C:\WINDOWS\hpdj3740.ini
2007-12-09 15:24 . 2007-12-09 15:25 <DIR> d-------- C:\Program Files\BearShare Applications
2007-12-09 15:24 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2007-12-08 23:44 . 2007-12-26 23:15 <DIR> d-------- C:\Program Files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 14:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-02 16:51 --------- d-----w C:\Program Files\Trend Micro
2007-12-10 15:45 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-08 12:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-07 19:21 89,984 ----a-w C:\WINDOWS\system32\drivers\sptd3021.sys
2007-12-07 19:21 664,064 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-07 19:20 --------- d-----w C:\Program Files\SubEdit-Player
2007-12-07 19:17 --------- d-----w C:\Program Files\Winamp
2007-12-07 19:13 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-07 19:13 --------- d-----w C:\Program Files\Microsoft Works
2007-12-07 19:05 --------- d-----w C:\Program Files\ATI Technologies
2007-12-07 18:50 --------- d-----w C:\Program Files\ASUS
2007-12-07 18:48 --------- d-----w C:\Program Files\Analog Devices
2007-12-07 18:43 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-07 18:40 --------- d-----w C:\Program Files\Usługi online
2001-10-26 17:29 502,784 --sh--r C:\WINDOWS\system32\azwkpo.exe
.
((((((((((((((((((((((((((((( snapshot@2008-01-02_14.48.55.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 02:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 14:43:41 380,928 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-01-03 14:43:41 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-01-02 02:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 14:43:35 380,928 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-01-03 14:43:35 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
- 2007-12-31 09:43:58 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-03 20:44:15 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-01-02 13:35:41 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
+ 2008-01-04 16:36:19 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
- 2007-12-31 09:43:58 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2008-01-03 20:44:15 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2008-01-03 20:44:15 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-25 14:46:28 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-04 16:27:41 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-12-25 14:46:28 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2008-01-04 16:27:42 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2007-12-25 14:46:28 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-04 16:27:42 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-12-25 14:46:28 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-01-04 16:27:42 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 11:54 2131392]
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 21:00 315392]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51 218376]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"WinDLL (msygl32.exe)"="C:\WINDOWS\System32\msygl32.exe" [2008-01-03 19:00 1204224]
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 18:29 13312]
"Microsoft Windows Updeta"="kfgbcg.exe" []
"HOT FIX"="Gothic.exe" []
"Microsoft Winedows rpdate"="zpacdh.exe" []
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"MicroSoft Visual SP2"="igfxsrvc32.exe" [2008-01-04 13:12 548864 C:\WINDOWS\system32\igfxsrvc32.exe]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Bfj36.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Fjm72.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntiVirusPro]
C:\Program Files\AntiVirusPro\AntiVirusPro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2001-10-26 18:29 13312 --a------ C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmona]
C:\WINDOWS\System32\ctfmona.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
C:\Program Files\Gadu-Gadu\gg.exe /tray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 08:38 241664 --a------ C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2004-02-18 18:55 49152 --a------ C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2004-03-04 16:46 172032 --a------ C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Firewall Layer]
tsqla.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MicroSoft Legal Syst3m32]
Syst3m32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Windows Updeta]
kfgbcg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NETIANET]
C:\Program Files\Netia\Net\netianet.exe -auto
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe /icon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysrest32.exe]
C:\WINDOWS\System32\sysrest32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDLL (mysnlive.exe)]
rundll32.exe C:\WINDOWS\System32\mysnlive.exe,start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDLL (vinampd.exe)]
rundll32.exe C:\WINDOWS\System32\vinampd.exe,start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Logon Application]
C:\WINDOWS\System32\winIogon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WintelUpdate]
C:\otfd.exe
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2007-12-21 13:19]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2001-10-26 18:30]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\System32\DRIVERS\klim5.sys [2007-04-04 14:58]
R4 update.microsoft.com;MicroSoft Visual SP2;"C:\WINDOWS\System32\igfxsrvc32.exe" [2008-01-04 13:12]
S0 Bfj36;Bfj36;C:\WINDOWS\System32\Drivers\Bfj36.sys []
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2001-08-17 22:03]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-01-04 16:17:58 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-04 17:52:45
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-04 17:53:47 - machine was rebooted [Dom]
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-04 16:53:38
C:\qoobox\ComboFix2.txt 2008-01-03 14:56:42
C:\qoobox\ComboFix3.txt 2008-01-02 13:49:22