hello !
cos sie dzieje dziwnego:
- komputer bardzo wolno rusza i "myśli" przy otwieraniu okien i programów
- zwolniły programy
- samoczynnie sie wyłącza ( np w przy przeglądaniu kilku stron www w mozilii na raz )
przeskanowany kasperskim - czysty
wklejam log z combofx-a:
ComboFix 07-08-17.2 - "p" 2007-08-20 8:16:08.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.668 [GMT 2:00]
Files Created from 2007-07-20 to 2007-08-20
2007-08-20 07:35 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-19 15:33 <DIR> d-------- C:\Program Files\Prime95
2007-08-17 16:36 <DIR> d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\vlc
2007-08-17 16:35 <DIR> d-------- C:\Program Files\VideoLAN
2007-08-17 08:19 <DIR> d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\EssentialPIM Pro
2007-08-17 08:18 <DIR> d-------- C:\Program Files\EssentialPIM Pro
2007-08-16 22:03 0 --a------ C:\WINDOWS\nsreg.dat
2007-08-16 22:03 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2007-08-16 22:03 <DIR> d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\Thunderbird
2007-08-16 22:03 <DIR> d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\Talkback
2007-08-15 23:10 <DIR> d-------- C:\WINDOWS\system32\oodag
2007-08-15 18:54 <DIR> d-------- C:\Program Files\OO Software
2007-08-15 18:21 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-08-15 18:07 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-08-13 21:40 <DIR> d-------- C:\Program Files\sqldbatips
2007-08-13 16:13 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2007-08-13 16:13 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2007-08-09 20:45 <DIR> d-------- C:\Program Files\The Privacy Guard
2007-08-08 11:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\DAEMON Tools Pro
2007-08-08 11:28 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2007-08-08 11:28 <DIR> d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\DAEMON Tools Pro
2007-08-08 11:20 <DIR> d-------- C:\Program Files\MoorHunt
2007-08-08 10:39 <DIR> d-------- C:\Program Files\UberIcon
2007-08-08 00:46 64,801 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-08-08 00:39 6,120 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-08-08 00:38 <DIR> d-------- C:\WINDOWS\BricoPacks
2007-08-06 21:56 <DIR> d-------- C:\Program Files\Groove Games
2007-08-04 17:05 <DIR> d-------- C:\Program Files\DVD Decrypter
2007-08-01 11:18 <DIR> d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\Ulead Systems
2007-08-01 11:14 <DIR> d-------- C:\Program Files\SmartSound Software
2007-08-01 11:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\SmartSound Software Inc
2007-08-01 11:13 <DIR> d-------- C:\Program Files\QuickTime
2007-08-01 11:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Apple Computer
2007-08-01 11:12 26,136 --a------ C:\WINDOWS\system32\IVIresize.dll
2007-08-01 11:12 210,456 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2007-08-01 11:12 206,360 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2007-08-01 11:12 198,168 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2007-08-01 11:12 198,168 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2007-08-01 11:12 194,072 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2007-08-01 11:12 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2007-08-01 11:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\InterVideo
2007-08-01 11:11 <DIR> d-------- C:\Program Files\Windows Media Components
2007-08-01 11:10 <DIR> d-------- C:\Program Files\Ulead Systems
2007-08-01 11:10 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2007-08-01 11:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Ulead Systems
2007-08-01 09:53 <DIR> d-------- C:\Program Files\MagicISO
2007-08-01 07:16 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-08-01 07:10 <DIR> d-------- C:\Program Files\Microsoft Works
2007-08-01 07:07 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-08-01 07:04 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-08-01 07:03 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-08-01 07:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Microsoft Help
2007-08-01 07:02 <DIR> dr-h----- C:\MSOCache
2007-07-31 23:10 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-31 22:19 90,112 --------- C:\WINDOWS\Updreg.EXE
2007-07-31 22:19 84,992 --------- C:\WINDOWS\system32\SFCVRT32.DLL
2007-07-31 22:19 82,432 --------- C:\WINDOWS\system32\CTWFLT32.DLL
2007-07-31 22:19 53,552 --------- C:\WINDOWS\CTCCW.DLL
2007-07-31 22:19 26,768 --------- C:\WINDOWS\system32\CTL3D.DLL
2007-07-31 22:19 24,976 --------- C:\WINDOWS\CTRES.DLL
2007-07-31 22:19 1,048,576 --------- C:\WINDOWS\system32\SFMAN.DAT
2007-07-31 20:49 998,004 --a------ C:\WINDOWS\system32\drivers\ha10kx2k.sys
2007-07-31 20:49 837,548 --a------ C:\WINDOWS\system32\drivers\ctaud2k.sys
2007-07-31 20:49 44,055 --a------ C:\WINDOWS\system32\ctdaught.dat
2007-07-31 20:49 213,860 --a------ C:\WINDOWS\system32\drivers\ctsfm2k.sys
2007-07-31 20:49 20,480 --a------ C:\WINDOWS\INRES.DLL
2007-07-31 20:49 195,432 --a------ C:\WINDOWS\system32\drivers\ctoss2k.sys
2007-07-31 20:49 179,669 --a------ C:\WINDOWS\system32\ctstatic.dat
2007-07-31 20:49 164,044 --a------ C:\WINDOWS\system32\ctdlang.dat
2007-07-31 20:49 156,604 --a------ C:\WINDOWS\system32\drivers\emupia2k.sys
2007-07-31 20:49 127,948 --a------ C:\WINDOWS\system32\drivers\ctac32k.sys
2007-07-31 20:49 113,373 --a------ C:\WINDOWS\system32\CTBASICW.DAT
2007-07-31 20:49 113,273 --a------ C:\WINDOWS\system32\ctbas2w.dat
2007-07-31 20:49 11,068 --a------ C:\WINDOWS\system32\drivers\ctprxy2k.sys
2007-07-31 20:48 94,208 --a------ C:\WINDOWS\DEVREG.DLL
2007-07-31 20:48 77,824 --a------ C:\WINDOWS\system32\EAXAC3.DLL
2007-07-31 20:48 65,536 --a------ C:\WINDOWS\system32\a3d.dll
2007-07-31 20:48 643,072 --a------ C:\WINDOWS\system32\ctsblfx.dll
2007-07-31 20:48 61,440 --a------ C:\WINDOWS\MIDIDEF.EXE
2007-07-31 20:48 57,344 --a------ C:\WINDOWS\system32\CTAGENT.DLL
2007-07-31 20:48 53,248 --a------ C:\WINDOWS\system32\AC3API.DLL
2007-07-31 20:48 49,152 --a------ C:\WINDOWS\system32\KILLAPPS.EXE
2007-07-31 20:48 49,152 --a------ C:\WINDOWS\CTDCRES.DLL
2007-07-31 20:48 36,864 --a------ C:\WINDOWS\system32\sfman32.dll
2007-07-31 20:48 36,864 --a------ C:\WINDOWS\system32\REGPLIB.EXE
2007-07-31 20:48 36,864 --a------ C:\WINDOWS\system32\ctemupia.dll
2007-07-31 20:48 319,488 --a------ C:\WINDOWS\system32\CTDEVCON.DLL
2007-07-31 20:48 28,672 --a------ C:\WINDOWS\system32\CTSPKHLP.DLL
2007-07-31 20:48 270,336 --a------ C:\WINDOWS\system32\sfms32.dll
2007-07-31 20:48 24,576 --a------ C:\WINDOWS\system32\CTHELPER.EXE
2007-07-31 20:48 184,320 --a------ C:\WINDOWS\PSCONV.EXE
2007-07-31 20:48 176,128 --a------ C:\WINDOWS\READREG.EXE
2007-07-31 20:48 155,648 --a------ C:\WINDOWS\system32\CTOSUSER.DLL
2007-07-31 20:48 135,168 --a------ C:\WINDOWS\system32\OPENAL32.DLL
2007-07-31 20:48 110,592 --a------ C:\WINDOWS\system32\piaproxy.dll
2007-07-31 20:48 110,592 --a------ C:\WINDOWS\system32\commonfx.dll
2007-07-31 20:48 106,496 --a------ C:\WINDOWS\system32\ctdproxy.dll
2007-07-31 20:48 106,496 --a------ C:\WINDOWS\system32\CTASIO.DLL
2007-07-31 20:36 73,728 --------- C:\WINDOWS\system32\CTDrmRes.dll
2007-07-31 20:36 62,976 --------- C:\WINDOWS\system32\CTDetres.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-20 08:14 --------- d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\Skype
2007-08-20 08:09 20812320 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-20 07:48 1213984 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-08-19 16:34 283868 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-19 16:34 121688 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-17 16:32 --------- d-------- C:\Program Files\FlashGet
2007-08-16 23:08 --------- d-------- C:\Program Files\The Bat!
2007-08-16 22:28 --------- d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\The Bat!
2007-08-16 22:18 --------- d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\The Bat! Pwd
2007-08-13 23:23 --------- d-------- C:\Program Files\Microsoft SQL Server
2007-08-13 21:42 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-08 08:25 --------- d-------- C:\Program Files\Movie Maker
2007-08-08 00:45 219648 --a------ C:\WINDOWS\system32\uxtheme.dll
2007-08-08 00:15 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-08-01 12:15 --------- d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\OpenOffice.org2
2007-08-01 07:10 --------- d-------- C:\Program Files\MSBuild
2007-07-31 20:37 --------- d-------- C:\Program Files\Creative
2007-07-30 10:43 --------- d-------- C:\Program Files\Absolute Uninstaller
2007-07-30 10:39 --------- d-------- C:\Program Files\Ashampoo
2007-07-16 11:55 --------- d-------- C:\DOCUME~1\PRACOW~1\DANEAP~1\Google
2007-07-08 16:07 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 15:23 1034752 --a------ C:\WINDOWS\explorer.exe
2006-02-19 03:28 12288 --a------ C:\WINDOWS\Fonts.\RandFont.dll
2006-03-02 12:00:00 60,928 --sha-w C:\WINDOWS\BricoPacks\SysFiles\80_msimn.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 20:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-03-02 14:00 C:\WINDOWS\system32\bthprops.cpl]
"Ad Muncher"="C:\Program Files\Ad Muncher\AdMunch.exe" [2007-07-30 10:00]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 02:08]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-07 10:32]
"RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-19 00:05]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00]
"ThePrivacyGuard"="C:\Program Files\The Privacy Guard\ThePrivacyGuard.exe" [2007-04-25 11:30]
"EssentialPIM Pro"="C:\Program Files\EssentialPIM Pro\EssentialPIM.exe" [2007-07-07 23:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\pracownia\Menu Start\Programy\Autostart\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 00:05:02]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 21:41:18]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 09:43:08]
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-05-21 09:43:14]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 17:23:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifcabb]
R2 MSSQL$INFOTEL;MSSQL$INFOTEL;C:\Program Files\Microsoft SQL Server\MSSQL$INFOTEL\Binn\sqlservr.exe -sINFOTEL
S3 kxwdmdrv;kX WDM Driver Service;C:\WINDOWS\system32\drivers\kx.sys
S3 SQLAgent$INFOTEL;SQLAgent$INFOTEL;C:\Program Files\Microsoft SQL Server\MSSQL$INFOTEL\Binn\sqlagent.EXE -i INFOTEL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5831a0b-fd80-11db-a3cb-806d6172696f}]
AutoRun\command- F:\hp.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-20 08:19:21
Windows 5.1.2600 Dodatek Service Pack 2 NTFS