Dzięki za szybką reakcję!
Poniżej log
pozdr
ComboFix 08-04-15.5 - stas 2008-04-16 19:04:19.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.1479 [GMT 2:00]
Running from: C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
FILE ::
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Program Files\AskTBar\bar\Cache\032445DC
C:\Program Files\AskTBar\bar\Cache\03244B1B
C:\Program Files\AskTBar\bar\Cache\03244C25.bin
C:\Program Files\AskTBar\bar\Cache\03244D5E.bin
C:\Program Files\AskTBar\bar\Cache\03244EC5.bin
C:\Program Files\AskTBar\bar\Cache\files.ini
C:\Program Files\AskTBar\bar\History\search2
C:\Program Files\AskTBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskTBar\PopSwatr\History\allowed
C:\Program Files\AskTBar\PopSwatr\History\notallow
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
C:\WINDOWS\dat.txt
C:\WINDOWS\search_res.txt
C:\WINDOWS\system32\Dvbpws.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 )))))))))))))))))))))))))))))))
.
2008-04-15 21:28 . 2008-04-15 21:28
2008-04-15 20:07 . 2008-04-15 20:07 12,540 --a------ C:\WINDOWS\system32\wpa.bak
2008-04-10 20:05 . 2008-04-10 20:05
2008-04-08 18:08 . 2008-04-09 07:40
2008-04-06 10:12 . 2002-07-16 19:08 49,152 --a------ C:\WINDOWS\system32\FTPStubInstUtils.dll
2008-04-06 10:11 . 2008-04-06 19:26
2008-04-05 22:06 . 2008-04-05 22:06 279 --a–c— C:\Nowy (D).lnk
2008-04-05 21:57 . 2008-04-15 22:05
2008-04-05 21:56 . 2008-04-15 22:05
2008-04-05 21:56 . 2008-04-05 21:56 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-05 08:34 . 2008-04-05 08:34
2008-04-05 08:17 . 2006-03-02 14:00 49,536 --a------ C:\WINDOWS\system32\drivers\a5bwou1u.sys
2008-03-28 22:22 . 2001-09-30 20:10 246,784 --a------ C:\WINDOWS\system32\ActiveSkin.ocx
2008-03-28 22:22 . 2001-05-24 13:59 162,304 --a–c— C:\UNWISE.EXE
2008-03-28 22:22 . 2002-01-18 19:12 112 --a------ C:\WINDOWS\ActiveSkin.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 16:54 --------- d—a-w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
2008-04-16 16:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-16 16:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Symantec
2008-04-16 06:20 --------- d-----w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\uTorrent
2008-04-15 19:43 19,456 ----a-w C:\WINDOWS\system32\Partizan.exe
2008-04-15 18:13 --------- d-----w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\Orbit
2008-04-15 18:10 --------- d-----w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\Skype
2008-04-15 18:09 --------- d-----w C:\Program Files\Winamp Remote
2008-04-13 17:00 --------- d-----w C:\Program Files\Szkola podstawowa klasa 5 - Przyroda
2008-04-09 17:58 --------- d-----w C:\Program Files\uTorrent
2008-04-05 06:07 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-08 07:25 --------- d-----w C:\Program Files\Wiedźmin
2008-03-06 20:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-06 14:11 --------- d-----w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\Vso
2008-03-06 06:00 --------- d-----w C:\Program Files\EA Games
2008-03-05 15:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll
2008-03-05 15:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll
2008-03-05 15:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll
2008-03-05 14:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll
2008-03-05 14:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll
2008-03-04 16:33 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-03-02 07:49 --------- d-----w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\Nero
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-28 20:47 --------- d-----w C:\Program Files\Deutsch Translator 2
2008-02-25 06:16 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Microsoft Help
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-05 22:07 462,864 ----a-w C:\WINDOWS\system32\d3dx10_37.dll
2008-01-17 18:47 53,248 ----a-w C:\WINDOWS\system32\suppdll.dll
2008-01-17 18:47 35,363 ----a-w C:\WINDOWS\system32\windrvNT.sys
2007-12-29 10:17 47,360 ----a-w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\pcouffin.sys
2007-12-06 14:41 22,328 ----a-w C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\PnkBstrK.sys
2007-01-14 08:54 56 --sh–r C:\WINDOWS\system32\7CE28638E0.sys
2007-12-30 17:10 88 --sh–r C:\WINDOWS\system32\8CE88CD098.sys
2007-05-19 18:21 638,085 --sh–w C:\WINDOWS\system32\cccdd.bak1
2007-05-21 18:23 640,176 --sh–w C:\WINDOWS\system32\cccdd.bak2
2007-05-22 16:45 655,686 --sh–w C:\WINDOWS\system32\cccdd.ini2
2007-12-30 17:10 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 22:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
“{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}”= “C:\Program Files\Winamp Toolbar\winamptb.dll” [2007-10-04 22:06 1135968]
[HKEY_CLASSES_ROOT\clsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}”= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 22:06 1135968]
[HKEY_CLASSES_ROOT\clsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 18:24 1694208]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 14:00 15360]
“Uniblue RegistryBooster 2”=“C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe” [2007-08-14 16:52 1877272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
“SoundMan”=“SOUNDMAN.EXE” [2004-11-15 18:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
“OFFICEKB”=“C:\Program Files\Labtec\Desktop\V5.1\kbdap32a.exe” [2007-08-26 18:26 387584]
“nwiz”=“nwiz.exe” [2007-10-04 18:14 1626112 C:\WINDOWS\system32\nwiz.exe]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2007-10-04 18:14 81920]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2007-10-04 18:14 8491008]
“NBKeyScan”=“C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” [2007-09-20 09:51 1836328]
“ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2005-02-16 16:15 81920]
“ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\ISUSPM.exe” [2005-02-16 16:15 221184]
“HPDJ Taskbar Utility”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe” [2004-05-04 16:21 176128]
“FLMOFFICE4DMOUSE”=“C:\Program Files\Labtec\Desktop\V5.1\moffice.exe” [2007-08-26 18:26 958464]
“ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2007-01-09 22:59 115816]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“@”=“OSK.exe” [2006-03-02 14:00 216064 C:\WINDOWS\system32\osk.exe]
C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-26 20:41:50 692224]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“ForceClassicControlPanel”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrnt32]
winrnt32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Start^Programy^Autostart^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^stas.DOM-3AC09B3FAB2^Menu Start^Programy^Autostart^HDDlife.lnk]
backup=C:\WINDOWS\pss\HDDlife.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^stas.DOM-3AC09B3FAB2^Menu Start^Programy^Autostart^On-Screen Keyboard.lnk]
backup=C:\WINDOWS\pss\On-Screen Keyboard.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^stas.DOM-3AC09B3FAB2^Menu Start^Programy^Autostart^RollerCoaster Tycoon 3 Registration.lnk]
backup=C:\WINDOWS\pss\RollerCoaster Tycoon 3 Registration.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^stas.DOM-3AC09B3FAB2^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
backup=C:\WINDOWS\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^stas.DOM-3AC09B3FAB2^Menu Start^Programy^Autostart^Xfire.lnk]
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Automatyczny terminarz]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a------ 2006-10-27 01:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odkurzacz-MCD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
–a------ 2007-08-14 16:52 1877272 C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFast Schedule]
–a------ 2006-07-07 18:15 348160 C:\Program Files\WinFast\WFDTV\WFWIZ.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“NeroFilterCheck”=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
“MMTray”=“C:\Program Files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe”
“mmtraylsi”=“C:\Program Files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe”
“mmtray2k”=“C:\Program Files\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“C:\Program Files\uTorrent\uTorrent.exe”=
“F:\Stranglehold\Binaries\Retail-Stranglehold.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
“AllowInboundEchoRequest”= 1 (0x1)
R1 wfcxacap;WinFast TV PCI Audio Capture Driver;C:\WINDOWS\system32\DRIVERS\wfcxacap.sys [2006-03-24 10:20]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;“C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe” [2006-09-13 14:54]
R2 HDDlife HDD Access service;HDDlife HDD Access service;“C:\Program Files\BinarySense\HDDlife 3\hldasvc.exe” [2007-05-25 13:57]
R2 wfcxatun;WinFast TV Analog Tuner Driver;C:\WINDOWS\system32\drivers\wfcxatun.sys [2006-03-24 10:24]
R2 WFCXVCAP;WinFast TV Video Capture Driver;C:\WINDOWS\system32\drivers\wfcxvcap.sys [2006-03-24 10:25]
R3 wfcxdtun;WinFast DTV BDA Tuner/Demod Driver;C:\WINDOWS\system32\drivers\wfcxdtun.sys [2006-03-24 10:23]
R3 wfcxtcap;WinFast DTV BDA Transport Stream Capture Driver;C:\WINDOWS\system32\drivers\wfcxtcap.sys [2006-03-24 10:21]
R3 wfcxxbar;WinFast TV Crossbar Driver;C:\WINDOWS\system32\drivers\wfcxxbar.sys [2006-03-24 10:22]
S2 sbbotdi;sbbotdi;C:\PROGRA~1\SpeedBit Video Accelerator\sbbotdi.sys []
S3 AmdTools;AMD Special Tools Driver;C:\WINDOWS\system32\DRIVERS\AmdTools.sys []
S3 EraserUtilDrv10621;EraserUtilDrv10621;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10621.sys []
S3 nthwio;nthwio;C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Pulpit\kablwka\nthwio.sys []
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 15:54]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15:54]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 15:54]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 15:54]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 15:54]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 11:33]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s125mdfl.sys [2007-04-24 11:33]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s125mdm.sys [2007-04-24 11:33]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s125mgmt.sys [2007-04-24 11:33]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s125obex.sys [2007-04-24 11:33]
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS [2005-01-06 17:55]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{7a812dc1-f1cd-11db-9a16-001731ea2f1e}]
\Shell\AutoRun\command - J:\launcher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{f973354b-95ce-11db-9cbb-001731ea2f1e}]
\Shell\AutoRun\command - H:\SETUP.EXE /AUTORUN
\Shell\configure\command - H:\SETUP.EXE
\Shell\install\command - H:\SETUP.EXE
*Newly Created Service* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
“C:\Program Files\Common Files\LightScribe\LSRunOnce.exe”
.
Contents of the ‘Scheduled Tasks’ folder
“2008-04-04 15:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job”
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
“2008-04-16 17:07:00 C:\WINDOWS\Tasks\HP Usg Daily.job”
- C:\Program Files\Hewlett-Packard{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe
“2008-04-12 04:42:25 C:\WINDOWS\Tasks\Norton Internet Security - Uruchom pełne skanowanie systemu - stas.job”
- C:\PROGRA~1\Norton Internet Security\Norton AntiVirus\Navw32.exen/TASK:
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 19:06:43
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
disk error: C:\WINDOWS\system32\drivers\
disk error: C:\DOCUME~1\STAS~1.DOM\USTAWI~1\Temp\
disk error: C:\WINDOWS\TEMP\
disk error: C:\WINDOWS\
disk error: C:\WINDOWS\system32\wbem\
disk error: C:\Program Files\Common Files\
disk error: C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Dane aplikacji\
disk error: C:\
disk error: C:\WINDOWS\system32\
disk error: C:\Program Files\
disk error: C:\WINDOWS\Downloaded Program Files\
disk error: C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Ustawienia lokalne\Dane aplikacji\
disk error: C:\WINDOWS\Fonts\
disk error: C:\Documents and Settings\stas.DOM-3AC09B3FAB2\Menu Start\Programy\Autostart\
disk error: C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\
scan completed successfully
hidden files:
**************************************************************************
.
Completion time: 2008-04-16 19:07:16
ComboFix-quarantined-files.txt 2008-04-16 17:07:13
Pre-Run: 16,564,895,744 bajtów wolnych
Post-Run: 16,620,138,496 bajtów wolnych
.
2008-04-13 11:57:13 — E O F —