Służę:
ComboFix 08-06-01.6 - Adak 2008-06-04 18:41:38.1 - NTFSx86
Running from: C:\Documents and Settings\Adak\Pulpit\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-03 17:03 . 2001-10-26 19:30 12,800 --a------ C:\WINDOWS\system32\svchost.exe
2008-06-03 13:29 . 2001-08-17 20:19 136,960 --a------ C:\WINDOWS\system32\drivers\essm2e.sys
2008-06-03 13:29 . 2001-08-18 06:24 135,040 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-06-03 13:29 . 2001-08-18 06:24 134,144 --a------ C:\WINDOWS\system32\drivers\ks.sys
2008-06-03 13:29 . 2001-10-26 17:30 117,248 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-06-03 13:29 . 2001-08-17 22:01 57,344 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-06-03 13:29 . 2001-08-17 22:01 42,752 --a------ C:\WINDOWS\system32\drivers\stream.sys
2008-06-03 13:29 . 2001-10-26 17:30 22,016 --a------ C:\WINDOWS\system32\wdmaud.drv
2008-06-03 13:29 . 2001-08-17 21:48 5,120 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-06-03 13:29 . 2001-10-26 17:27 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-06-02 19:58 . 2008-06-02 19:59 <DIR> d-------- C:\Program Files\Luxor
2008-06-02 19:57 . 2008-06-02 19:57 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-29 21:34 . 2008-05-29 21:38 <DIR> d-------- C:\Documents and Settings\Adak\Dane aplikacji\ICQ
2008-05-29 21:32 . 2008-05-29 21:42 <DIR> d-------- C:\Program Files\ICQLite
2008-05-29 21:32 . 2008-05-29 21:42 <DIR> d-------- C:\Documents and Settings\Adak\Dane aplikacji\ICQLite
2008-05-29 10:59 . 2008-05-29 10:59 <DIR> d-------- C:\Program Files\Tlen.pl
2008-05-29 10:15 . 2008-05-29 10:15 <DIR> d-------- C:\Documents and Settings\Adak\Dane aplikacji\Tlen.pl
2008-05-07 11:25 . 2008-05-07 11:25 0 --a------ C:\WINDOWS\system32\swunilog.ini
2008-05-07 11:11 . 2008-05-07 11:11 <DIR> d-------- C:\Program Files\802.11 Wireless LAN
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2003-05-01 08:36 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV7ActiveXControl.dll
.
------- Sigcheck -------
2001-10-26 19:30 12800 b3c95bfeef6781a82a1c429f466a3a11 C:\WINDOWS\system32\svchost.exe
2004-06-17 19:58 530432 160a69cf24a426b2bd22b2b8cb7950c8 C:\WINDOWS\system32\user32.dll
2004-06-17 19:58 530432 160a69cf24a426b2bd22b2b8cb7950c8 C:\WINDOWS\system32\dllcache\user32.dll
2001-10-26 19:29 75264 9b7d1c56cc12d806314b853bf52ecb4c C:\WINDOWS\system32\ws2_32.dll
2001-10-26 19:29 75264 9b7d1c56cc12d806314b853bf52ecb4c C:\WINDOWS\system32\dllcache\ws2_32.dll
2004-08-23 19:18 587776 33e3501fbe09d90c57ca9831f38a3e09 C:\WINDOWS\system32\WININET.DLL
2004-08-23 19:18 587776 33e3501fbe09d90c57ca9831f38a3e09 C:\WINDOWS\system32\dllcache\WININET.DLL
2001-08-18 08:24 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\system32\dllcache\tcpip.sys
2001-08-18 08:24 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\system32\drivers\tcpip.sys
2004-06-17 02:21 433152 3b7db268f4962c1f6061c77fddcedd26 C:\WINDOWS\system32\winlogon.exe
2004-06-17 02:21 433152 3b7db268f4962c1f6061c77fddcedd26 C:\WINDOWS\system32\dllcache\winlogon.exe
2001-08-18 08:24 161536 3efd4f59ba0a340de0a3ab984001dbf7 C:\WINDOWS\system32\dllcache\ndis.sys
2001-08-18 08:24 161536 3efd4f59ba0a340de0a3ab984001dbf7 C:\WINDOWS\system32\drivers\ndis.sys
2004-06-17 19:53 1905152 95e107cc318d3197f00d0bdddf99f952 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2004-06-17 19:53 1905152 95e107cc318d3197f00d0bdddf99f952 C:\WINDOWS\system32\ntkrnlpa.exe
2004-06-17 19:54 1883136 cb6c56d0f5b0de01ab74158427d42d2b C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2004-06-17 19:54 1883136 cb6c56d0f5b0de01ab74158427d42d2b C:\WINDOWS\system32\ntoskrnl.exe
2001-10-26 19:29 1002496 0b6cb4abb3166e1717bda7895f2029d8 C:\WINDOWS\explorer.exe
2001-10-26 19:29 1002496 0b6cb4abb3166e1717bda7895f2029d8 C:\WINDOWS\system32\dllcache\explorer.exe
2001-10-26 19:30 101888 bf4cbefdce42a699389791647cb95ca2 C:\WINDOWS\system32\services.exe
2001-10-26 19:30 101888 bf4cbefdce42a699389791647cb95ca2 C:\WINDOWS\system32\dllcache\services.exe
2001-10-26 19:29 11776 5cc79cfe660dd720739fb9adb03f2275 C:\WINDOWS\system32\lsass.exe
2001-10-26 19:29 11776 5cc79cfe660dd720739fb9adb03f2275 C:\WINDOWS\system32\dllcache\lsass.exe
2001-10-26 19:29 13312 106e93e7eead4f0797fc1a30bd53fa3d C:\WINDOWS\system32\ctfmon.exe
2001-10-26 19:29 13312 106e93e7eead4f0797fc1a30bd53fa3d C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedswitchXP"="C:\SpeedswitchXP\SpeedswitchXP.exe" [2004-05-14 03:30 491520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 19:29 13312]
[HKLM\~\startupfolder\C:^Documents and Settings^Adak^Menu Start^Programy^Autostart^H3 The Shadow of Death(TM).lnk]
path=C:\Documents and Settings\Adak\Menu Start\Programy\Autostart\H3 The Shadow of Death(TM).lnk
backup=C:\WINDOWS\pss\H3 The Shadow of Death(TM).lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^NkvMon.exe.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\NkvMon.exe.lnk
backup=C:\WINDOWS\pss\NkvMon.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Auto CD-ROM Startup]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2003-10-26 23:53 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2001-10-26 19:29 13312 C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
--a------ 2006-07-11 12:06 3144800 C:\Program Files\ICQLite\ICQLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunUtility]
--a------ 2006-01-20 19:29 17895424 C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-03-14 03:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\DP.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-04 18:51:45
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-04 18:53:27
ComboFix-quarantined-files.txt 2008-06-04 16:53:20
Pre-Run: 464,842,752 bajtów wolnych
Post-Run: 1,445,974,016 bajtów wolnych
107