dzieki za pomoc juz to zrobiłem a to log z ComboFix
ComboFix 08-06-12.2 - Andrzej Lis 2008-06-15 16:21:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1635 [GMT 2:00]
Running from: C:\Program Files\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\1.bin\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\Cache\
00FA51F8
C:\Program Files\myglobalsearch\bar\Cache\
00FA542A
C:\Program Files\myglobalsearch\bar\Cache\
00FA5563.bin
C:\Program Files\myglobalsearch\bar\Cache\
00FA5747.bin
C:\Program Files\myglobalsearch\bar\Cache\
00FA5880.bin
C:\Program Files\myglobalsearch\bar\Cache\files.ini
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm
.
((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))
.
2008-06-15 16:18 . 2008-06-15 16:18 1,979,425 --a------ C:\Program Files\ComboFix.exe
2008-06-15 14:38 . 2008-06-15 14:38 401,720 --a------ C:\Documents and Settings\HiJackThis.exe
2008-06-15 00:34 . 2008-06-15 00:58 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-06-11 12:17 . 2008-04-14 17:53 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 12:17 . 2008-04-14 17:53 273,024 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 21:45 . 2008-06-10 21:45 <DIR> d-------- C:\Program Files\Edgard
2008-06-10 21:24 . 2008-06-10 23:27 48 --a------ C:\WINDOWS\EL0103.dat
2008-06-10 21:01 . 2008-06-10 21:24 <DIR> d-------- C:\Program Files\EasyLanguage
2008-06-10 16:39 . 2008-06-10 16:39 <DIR> d-------- C:\Program Files\MyPlayCity.com
2008-06-10 16:39 . 2008-06-10 16:39 <DIR> d-------- C:\Program Files\MyPlayCity
2008-06-10 16:39 . 2008-06-10 16:39 <DIR> d-------- C:\Program Files\Conduit
2008-06-09 16:42 . 2008-06-09 16:42 65,790 --a------ C:\iranf wiew polski.zip
2008-06-09 14:54 . 2008-06-09 14:55 <DIR> d-------- C:\Program Files\Opera
2008-06-09 14:53 . 2008-06-09 14:53 6,666,408 --a------ C:\Program Files\Opera_9.27_International_Setup.exe
2008-06-06 18:51 . 2008-06-13 22:20 264 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-06-06 14:58 . 2008-06-06 14:58 <DIR> d-------- C:\Documents and Settings\Andrzej Lis\Dane aplikacji\AdobeAUM
2008-06-05 22:59 . 2008-06-05 22:59 <DIR> d-------- C:\TEMP
2008-06-05 22:12 . 2008-06-09 18:08 <DIR> d-------- C:\Program Files\IrfanView
2008-06-05 19:27 . 2008-05-14 00:05 3,663,208 --a------ C:\BSPL_5.2.5_[www.POBIERALNIA.org].exe
2008-06-03 23:21 . 2008-06-03 23:21 <DIR> d-------- C:\Program Files\Avira
2008-06-03 23:21 . 2008-06-03 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-06-03 23:05 . 2008-06-03 23:05 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-06-01 16:48 . 2008-06-01 16:48 <DIR> d-------- C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Media Player Classic
2008-06-01 16:47 . 2008-06-01 16:47 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-01 16:47 . 2007-11-29 23:30 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-05-30 19:55 . 2008-05-30 19:56 <DIR> d-------- C:\Program Files\Winamp
2008-05-30 19:55 . 2008-05-30 19:58 <DIR> d-------- C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Winamp
2008-05-18 22:13 . 2008-05-18 22:13 <DIR> d-------- C:\Program Files\MarBit
2008-05-18 15:53 . 2001-10-26 17:29 99,328 --a------ C:\WINDOWS\system32\srusd.dll
2008-05-18 15:53 . 2001-10-26 17:29 99,328 --a--c--- C:\WINDOWS\system32\dllcache\srusd.dll
2008-05-18 15:53 . 2001-10-26 17:29 71,680 --a------ C:\WINDOWS\system32\fnfilter.dll
2008-05-18 15:53 . 2001-10-26 17:29 71,680 --a--c--- C:\WINDOWS\system32\dllcache\fnfilter.dll
2008-05-18 15:53 . 2001-10-26 17:05 6,912 --a------ C:\WINDOWS\system32\drivers\serscan.sys
2008-05-18 15:53 . 2001-10-26 17:05 6,912 --a--c--- C:\WINDOWS\system32\dllcache\serscan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 14:19 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-06-15 14:13 --------- d-----w C:\Program Files\BearShare
2008-06-09 12:44 --------- d-----w C:\Program Files\Google
2008-06-03 17:49 --------- d-----w C:\Documents and Settings\Monika Lis\Dane aplikacji\Winamp
2008-05-28 14:10 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\AdobeUM
2008-05-24 20:39 --------- d-----w C:\Program Files\eMule
2008-05-18 13:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-18 13:23 --------- d-----w C:\Program Files\COMPANY_NAME
2008-05-16 16:01 --------- d-----w C:\Program Files\Spyware Doctor
2008-05-13 20:50 --------- d-----w C:\Program Files\Gadu-Gadu
2008-05-13 20:35 --------- d-----w C:\Documents and Settings\Monika Lis\Dane aplikacji\ACD Systems
2008-05-11 08:39 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-05-11 08:39 --------- d-----w C:\Program Files\ACD Systems
2008-05-11 08:39 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\ACD Systems
2008-05-11 08:39 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems
2008-05-10 13:27 --------- d-----w C:\Documents and Settings\Monika Lis\Dane aplikacji\Gadu-Gadu
2008-05-09 12:54 --------- d-----w C:\Documents and Settings\Monika Lis\Dane aplikacji\Leadertech
2008-05-09 12:22 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Leadertech
2008-05-09 06:15 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-05-09 06:15 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-05-09 06:13 --------- d-----w C:\Program Files\Futuremark
2008-05-09 06:10 --------- d-----w C:\Program Files\ASUS
2008-05-09 05:15 --------- d-----w C:\Program Files\InterVideo
2008-05-09 05:14 65 ----a-w C:\Program Files\Common Files\appop.log
2008-05-09 05:08 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-09 04:32 --------- d-----w C:\Program Files\Kaspersky Lab
2008-05-09 04:32 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Anti-Virus Personal
2008-05-08 17:11 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Winamp
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 11:27 --------- d-----w C:\Program Files\EIZO
2008-05-08 06:04 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-07 22:48 --------- d-----w C:\Documents and Settings\Monika Lis\Dane aplikacji\Teleca
2008-05-07 19:05 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\PC Tools
2008-05-07 17:14 --------- d-----w C:\Program Files\Java
2008-05-07 17:14 --------- d-----w C:\Program Files\Common Files\Java
2008-05-07 14:59 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Gadu-Gadu
2008-05-07 11:57 --------- d-----w C:\Program Files\Analog Devices
2008-05-07 11:53 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-05-07 11:51 --------- d-----w C:\Program Files\DIFX
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-06 20:55 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-06 20:52 --------- d-----w C:\Program Files\Sony Ericsson
2008-05-06 20:52 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-05-06 20:52 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Teleca
2008-05-06 20:52 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Teleca
2008-05-06 20:52 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2008-05-06 20:51 6,144 ----a-w C:\WINDOWS\system32\drivers\k750cm.sys
2008-05-06 20:51 5,744 ----a-w C:\WINDOWS\system32\drivers\k750wh.sys
2008-05-06 20:18 --------- d-----w C:\Program Files\Philips
2008-05-06 20:17 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\InstallShield
2008-05-06 20:06 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-06 20:05 --------- d-----w C:\Program Files\Usługi online
2008-04-21 07:03 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-25 04:52 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:52 178,976 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
2008-03-04 13:44 1470488 --a------ C:\Program Files\MyPlayCity\tbMyPl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}"= "C:\Program Files\MyPlayCity\tbMyPl.dll" [2008-03-04 13:44 1470488]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}"= C:\Program Files\MyPlayCity\tbMyPl.dll [2008-03-04 13:44 1470488]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-10-29 14:00 15360]
"Gadu-Gadu"="D:\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-06 11:30 8523776]
"nwiz"="nwiz.exe" [2007-11-06 11:30 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-06 11:30 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ScreenManager Pro for LCD"="C:\Program Files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe" [2006-06-08 10:33 8953856]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]
"KAVPersonal50"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" [2006-03-27 17:55 94350]
"DIRECTCD"="C:\Program Files\COMPANY_NAME\Disc Master 2.5\DirectCD.exe" [2005-10-25 00:49 299008]
"WINCINEMAMGR"="C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe" [2005-01-21 02:47 270336]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 14:25 868352]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.16\AsRunHelp.exe" [2006-11-14 08:25 363008]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-10-29 14:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
COMPANY_NAME WinCinema Manager.lnk - C:\Program Files\COMPANY_NAME\Common\Bin\WinCinemaMgr.exe [2008-05-09 07:11:28 229376]
InterVideo WinCinema Manager.lnk - C:\Program Files\COMPANY_NAME\Common\Bin\WinCinemaMgr.exe [2008-05-09 07:11:28 229376]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\mohpa.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
R0 ivicd;Ivi CDVD Filter Driver;C:\WINDOWS\system32\drivers\ivicd.sys [2005-01-12 06:29]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2006-03-20 19:22]
S2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};C:\WINDOWS\TEMP\E2.tmp []
S3 iviudf;iviudf;C:\WINDOWS\system32\drivers\IviUdf.sys [2005-06-23 02:09]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11712b1d-9965-11db-af56-806d6172696f}]
\Shell\AutoRun\command - E:\.\Bin\ASSETUP.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-15 16:25:36
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\C:\WINDOWS\TEMP\E2.tmp"
.
Completion time: 2008-06-15 16:26:59
ComboFix-quarantined-files.txt 2008-06-15 14:26:54
Pre-Run: 232,864,346,112 bajtów wolnych
Post-Run: 232,981,544,960 bajtów wolnych
196 --- E O F --- 2008-06-11 17:54:35