po restarcie pokazal mi sie taki log:
ComboFix 08-04-29.5 - mario 2008-05-03 13:53:22.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1298 [GMT 2:00]
Running from: C:\Documents and Settings\mario\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\mario\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\h0s2.bat
C:\Program Files\DaemonTools_WhenUSave_Installer
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\h0s2.bat
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))
.
2008-05-01 16:24 . 2008-05-01 22:58 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-05-01 15:54 . 2008-05-01 22:53 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-05-01 15:54 . 2008-05-01 15:54 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\PC Tools
2008-05-01 15:54 . 2008-05-01 16:02 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-05-01 15:54 . 2008-05-01 16:02 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-05-01 15:54 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-05-01 15:54 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-05-01 15:53 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-05-01 15:25 . 2008-05-03 13:56 45,056 --a------ C:\WINDOWS\system32\acovcnt.exe
2008-04-24 14:24 . 2008-04-24 14:24 <DIR> d-------- C:\Program Files\Szkoa Haker˘w - Odtwarzacz film˘w instruktaľowych
2008-04-24 14:24 . 2008-04-24 14:24 1,849 --a------ C:\WINDOWS\system32\odtwarzacz.csh
2008-04-21 21:36 . 2008-04-21 21:36 38 --a------ C:\WINDOWS\avisplitter.INI
2008-04-20 22:10 . 2008-04-20 22:10 <DIR> d-------- C:\Program Files\danny_kay1710
2008-04-19 09:26 . 2008-04-19 09:26 <DIR> d-------- C:\Program Files\VirtualDJ
2008-04-19 06:53 . 2008-04-19 06:53 <DIR> d-------- C:\WINDOWS\Sun
2008-04-18 22:23 . 2008-04-18 22:23 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Ashampoo
2008-04-18 22:22 . 2008-04-18 22:22 <DIR> d-------- C:\Program Files\Ashampoo
2008-04-18 22:22 . 2008-04-18 22:22 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
2008-04-18 22:01 . 2008-04-18 22:01 0 --a------ C:\WINDOWS\Irremote.ini
2008-04-18 19:18 . 2008-04-18 19:19 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\InternetCalls
2008-04-18 19:16 . 2008-04-18 19:16 <DIR> d-------- C:\Program Files\InternetCalls.com
2008-04-15 15:29 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-15 15:28 . 2008-04-15 15:29 <DIR> d-------- C:\Program Files\Java
2008-04-15 15:26 . 2008-04-15 15:26 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-12 15:59 . 2008-04-12 15:59 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Media Player Classic
2008-04-10 19:03 . 2008-04-10 19:03 <DIR> d-------- C:\Program Files\MathSoft
2008-04-10 19:03 . 2008-04-10 19:03 <DIR> d-------- C:\Documents and Settings\mario\WINDOWS
2008-04-10 19:03 . 1997-04-23 09:13 299,008 --a------ C:\WINDOWS\uninst.exe
2008-04-09 20:59 . 2008-04-09 20:59 <DIR> d-------- C:\Program Files\Infogrames
2008-04-09 20:59 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-08 21:55 . 2008-04-08 21:55 1,024 --ah----- C:\Documents and Settings\Default User\NtUser.dat.LOG
2008-04-08 21:54 . 2008-04-08 21:54 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Nero
2008-04-08 21:52 . 2008-04-08 21:52 <DIR> d-------- C:\Program Files\Nero
2008-04-08 21:52 . 2008-04-18 22:02 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-04-08 21:52 . 2008-04-18 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-04-07 21:22 . 2008-04-07 21:22 97 --a------ C:\WINDOWS\WirelessFTP.INI
2008-04-07 21:17 . 2008-04-07 21:30 17,608 --a------ C:\Documents and Settings\mario\Dane aplikacji\GDIPFONTCACHEV1.DAT
2008-04-07 17:01 . 2008-04-07 17:01 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\BESTplayer
2008-04-07 16:04 . 2008-05-02 23:41 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-04-07 15:54 . 2008-04-07 15:54 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Thunderbird
2008-04-06 21:56 . 2008-04-06 21:56 <DIR> d-------- C:\Program Files\Tlen.pl
2008-04-06 21:56 . 2008-04-23 23:25 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Tlen.pl
2008-04-06 21:54 . 2008-04-06 21:54 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Dane aplikacji\Infineon
2008-04-06 21:51 . 2008-04-06 21:51 <DIR> d-------- C:\Program Files\Wireless Console 2
2008-04-06 21:51 . 2005-10-17 17:09 987,136 --a------ C:\WINDOWS\system32\wcourier.exe
2008-04-06 21:51 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-06 21:51 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-06 21:51 . 2004-08-04 00:44 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-04-06 21:51 . 2004-08-04 00:44 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-04-06 21:51 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-04-06 21:51 . 2001-08-17 22:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-04-06 21:50 . 2008-04-06 21:50 0 --a------ C:\WINDOWS\tosOBEX.INI
2008-04-06 21:49 . 2005-07-06 15:43 155,648 --a------ C:\WINDOWS\system32\ACEngSvr.exe
2008-04-06 21:48 . 2008-04-06 21:48 <DIR> d-------- C:\Program Files\Infineon
2008-04-06 21:48 . 2008-04-06 21:48 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Infineon
2008-04-06 21:48 . 2008-04-06 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Infineon
2008-04-06 21:48 . 2005-10-21 05:19 36,352 -ra------ C:\WINDOWS\system32\drivers\ifxtpm.sys
2008-04-06 21:48 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-04-06 21:48 . 2004-08-03 22:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-04-06 21:46 . 2008-04-06 21:46 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-06 21:46 . 2008-04-06 21:46 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Dane aplikacji\Intel
2008-04-06 21:46 . 2008-04-06 21:46 <DIR> d-------- C:\Documents and Settings\NetworkService\Dane aplikacji\Intel
2008-04-06 21:46 . 2008-04-06 21:46 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\Intel
2008-04-06 21:46 . 2008-04-06 21:46 <DIR> d-------- C:\Documents and Settings\LocalService\Dane aplikacji\Intel
2008-04-06 21:46 . 2008-04-06 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Intel
2008-04-06 21:46 . 2006-07-28 02:46 2,732,032 --a------ C:\WINDOWS\system32\NETw3r32.dll
2008-04-06 21:46 . 2006-09-27 02:36 1,709,696 --a------ C:\WINDOWS\system32\drivers\NETw3x32.sys
2008-04-06 21:46 . 2006-07-28 02:45 561,152 --a------ C:\WINDOWS\system32\NETw3c32.dll
2008-04-06 21:46 . 2008-04-06 21:46 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-04-06 21:44 . 2006-02-07 02:40 143,360 -ra------ C:\WINDOWS\system32\igfxres.dll
2008-04-06 21:19 . 2001-10-26 16:57 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-04-06 21:19 . 2001-10-26 16:57 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-04-06 21:14 . 2008-04-06 21:14 <DIR> d-------- C:\Program Files\Toshiba
2008-04-06 21:13 . 2008-04-06 21:13 <DIR> d-------- C:\Program Files\Synaptics
2008-04-06 21:13 . 2008-04-06 21:13 <DIR> d-------- C:\Program Files\Motorola
2008-04-06 21:13 . 2008-04-06 21:50 <DIR> d-------- C:\Program Files\Asus
2008-04-06 21:12 . 2008-04-06 21:12 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-04-06 21:12 . 2008-04-06 22:43 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-06 21:12 . 2008-04-06 21:48 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-06 21:11 . 2008-04-06 21:11 <DIR> d-------- C:\Program Files\Sigmatel
2008-04-06 21:11 . 2006-04-27 12:37 1,164,600 --a------ C:\WINDOWS\system32\drivers\sthda.sys
2008-04-06 21:11 . 2006-04-20 08:12 1,069,056 --a------ C:\WINDOWS\system32\STLANG.DLL
2008-04-06 21:11 . 2006-05-04 10:50 208,896 --a------ C:\WINDOWS\system32\stacapi.dll
2008-04-06 21:11 . 2004-08-04 00:44 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-04-06 21:11 . 2004-08-04 00:44 130,048 --a--c--- C:\WINDOWS\system32\dllcache\ksproxy.ax
2008-04-06 21:11 . 2006-05-04 10:51 112,128 --a------ C:\WINDOWS\system32\staco.dll
2008-04-06 21:11 . 2004-08-03 23:08 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-04-06 21:11 . 2004-08-03 23:08 60,288 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys
2008-04-06 21:11 . 2004-08-04 00:44 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-04-06 21:11 . 2004-08-04 00:44 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll
2008-04-06 21:10 . 2006-10-08 21:51 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-06 21:08 . 2008-04-06 21:46 <DIR> d-------- C:\Program Files\Intel
2008-04-06 21:06 . 2000-03-03 05:16 7,424 -ra------ C:\WINDOWS\system32\drivers\MMIOPORT.SYS
2008-04-06 21:04 . 2008-04-07 15:41 <DIR> d-------- C:\Program Files\DaemonTools_WhenUSave_Installer
2008-04-06 21:03 . 2008-04-06 21:03 <DIR> d-------- C:\Documents and Settings\mario\Dane aplikacji\DAEMON Tools Pro
2008-04-06 21:01 . 2008-04-06 21:01 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Pro
2008-04-06 21:00 . 2008-04-06 21:05 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-03 09:57 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 5
2008-04-24 12:24 --------- d-----w C:\Program Files\Szkoła Hakerów - Odtwarzacz filmów instruktażowych
2008-04-20 10:43 --------- d-----w C:\Program Files\Winamp Remote
2008-04-20 10:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks
2008-04-08 12:08 --------- d-----w C:\Documents and Settings\mario\Dane aplikacji\Winamp
2008-04-07 19:46 --------- d-----w C:\Program Files\Yahoo!
2008-04-07 19:46 --------- d-----w C:\Program Files\Common Files\Scanner
2008-04-07 19:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-06 20:40 --------- d-----w C:\Program Files\Samsung
2008-04-06 20:14 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Office Genuine Advantage
2008-04-06 20:13 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-06 20:13 --------- d-----w C:\Documents and Settings\mario\Dane aplikacji\Yahoo!
2008-04-06 20:09 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\LogiShrd
2008-04-06 20:08 --------- d-----w C:\Documents and Settings\mario\Dane aplikacji\Logitech
2008-04-06 20:07 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-06 20:07 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-04-06 20:06 --------- d-----w C:\Program Files\Logitech
2008-04-06 20:06 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-04-06 20:06 --------- d-----w C:\Documents and Settings\mario\Dane aplikacji\InstallShield
2008-04-06 20:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Logitech
2008-04-06 20:04 --------- d-----w C:\Program Files\Winamp Toolbar
2008-04-06 20:04 --------- d-----w C:\Program Files\Winamp
2008-04-06 20:04 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar
2008-04-06 20:02 --------- d-----w C:\Program Files\Alwil Software
2008-04-06 18:59 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-06 18:52 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-06 18:50 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2008-03-20 00:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-20 00:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-20 00:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-06-22 14:45 133576]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" [2007-10-16 12:53 6234112]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 16:22 110592]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-02-07 02:39 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-02-07 02:36 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-02-07 02:40 118784]
"SigmatelSysTrayApp"="stsystra.exe" []
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-08-07 07:11 573440]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 14:02 786521]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 00:38 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 00:32 696320]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 10:28 811008]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-14 17:46 90112]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 07:28 36352]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 02:17 55824 C:\WINDOWS\KHALMNPR.Exe]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [2006-02-14 11:32 507904]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2006-05-24 14:16:14 49152]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-04-06 22:06:48 789008]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
IfxWlxEN.dll 2006-03-10 09:20 434176 C:\WINDOWS\system32\IfxWlxEN.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2008-01-09 12:30 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"VIDC.CSCD"= camcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Tlen.pl\\tlen.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Infogrames\\Tactical Ops\\System\\TacticalOps.exe"=
"C:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetCalls.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 PersonalSecureDrive;PersonalSecureDrive;C:\WINDOWS\system32\drivers\psd.sys [2005-11-29 12:50]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-10-21 05:19]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-08-09 08:15]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-08-09 08:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57b64c5b-0413-11dd-a101-001bfc134dc1}]
\Shell\AutoRun\command - G:\h0s2.bat
\Shell\explore\Command - G:\h0s2.bat
\Shell\open\Command - G:\h0s2.bat
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-03 13:56:12
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Infineon\Security Platform Software\PSDsrvc.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTNA.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\acovcnt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
C:\Program Files\Winamp\winamp.exe
.
**************************************************************************
.
Completion time: 2008-05-03 13:58:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-03 11:58:03
Pre-Run: 22,813,831,168 bajtów wolnych
Post-Run: 22,911,414,272 bajt˘w wolnych
272