Najpierw z Fixwareout
Username "liczkowscy" - 2008-08-10 12:59:16 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdhml.exe"
Pomyślnie opróżniono pamięć podręczną programu rozpoznawania nazw DNS.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\Temp\kdhml.ren 62976 2007-06-13
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="atiptaxx.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jusched.exe\""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"C:\\WINDOWS\\system32\\kdhml.exe"="C:\\WINDOWS\\system32\\kdhml.exe"
"IMJPMIG8.2"="msime82.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"ATI Launchpad"=""
"MsServer"="msfun80.exe"
"DAEMON Tools Lite"="\"E:\\DAEMON Tools Lite\\daemon.exe\" -autorun"
"SpybotSD TeaTimer"="E:\\Spybot - Search & Destroy\\TeaTimer.exe"
"AlcoholAutomount"="\"C:\\Program Files\\Alcohol Soft\\Alcohol 120\\axcmd.exe\" /automount"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
A teraz ComboFix
ComboFix 08-08-09.06 - liczkowscy 2008-08-10 13:15:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.276 [GMT 2:00]
Running from: E:\Obrazki, instalki i inne\ComboFix.exe
Command switches used :: E:\Obrazki, instalki i inne\CFScript.txt
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]
FILE ::
C:\Program Files\Web Technologies\wcs.exe
C:\WINDOWS\msfun80.exe
C:\WINDOWS\system32\2lRS3447.exe
C:\WINDOWS\system32\3hp8jMQg.dll
C:\WINDOWS\system32\kdhml.exe
C:\WINDOWS\system32\L18E0mq0.exe
C:\WINDOWS\system32\msfun80.exe
C:\WINDOWS\system32\msime82.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At49.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At50.job
C:\WINDOWS\Tasks\At51.job
C:\WINDOWS\Tasks\At52.job
C:\WINDOWS\Tasks\At53.job
C:\WINDOWS\Tasks\At54.job
C:\WINDOWS\Tasks\At55.job
C:\WINDOWS\Tasks\At56.job
C:\WINDOWS\Tasks\At57.job
C:\WINDOWS\Tasks\At58.job
C:\WINDOWS\Tasks\At59.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At60.job
C:\WINDOWS\Tasks\At61.job
C:\WINDOWS\Tasks\At62.job
C:\WINDOWS\Tasks\At63.job
C:\WINDOWS\Tasks\At64.job
C:\WINDOWS\Tasks\At65.job
C:\WINDOWS\Tasks\At66.job
C:\WINDOWS\Tasks\At67.job
C:\WINDOWS\Tasks\At68.job
C:\WINDOWS\Tasks\At69.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At70.job
C:\WINDOWS\Tasks\At71.job
C:\WINDOWS\Tasks\At72.job
C:\WINDOWS\Tasks\At73.job
C:\WINDOWS\Tasks\At74.job
C:\WINDOWS\Tasks\At75.job
C:\WINDOWS\Tasks\At76.job
C:\WINDOWS\Tasks\At77.job
C:\WINDOWS\Tasks\At78.job
C:\WINDOWS\Tasks\At79.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At80.job
C:\WINDOWS\Tasks\At81.job
C:\WINDOWS\Tasks\At82.job
C:\WINDOWS\Tasks\At83.job
C:\WINDOWS\Tasks\At84.job
C:\WINDOWS\Tasks\At85.job
C:\WINDOWS\Tasks\At86.job
C:\WINDOWS\Tasks\At87.job
C:\WINDOWS\Tasks\At88.job
C:\WINDOWS\Tasks\At89.job
C:\WINDOWS\Tasks\At9.job
C:\WINDOWS\Tasks\At90.job
C:\WINDOWS\Tasks\At91.job
C:\WINDOWS\Tasks\At92.job
C:\WINDOWS\Tasks\At93.job
C:\WINDOWS\Tasks\At94.job
C:\WINDOWS\Tasks\At95.job
C:\WINDOWS\Tasks\At96.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\Program Files\Web Technologies
C:\Program Files\Web Technologies\wcs.exe
C:\Program Files\Web Technologies\wcu.exe
C:\WINDOWS\system32\2lRS3447.exe
C:\WINDOWS\system32\3hp8jMQg.dll
C:\WINDOWS\system32\L18E0mq0.exe
C:\WINDOWS\system32\msfun80.exe
C:\WINDOWS\system32\msime82.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At49.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At50.job
C:\WINDOWS\Tasks\At51.job
C:\WINDOWS\Tasks\At52.job
C:\WINDOWS\Tasks\At53.job
C:\WINDOWS\Tasks\At54.job
C:\WINDOWS\Tasks\At55.job
C:\WINDOWS\Tasks\At56.job
C:\WINDOWS\Tasks\At57.job
C:\WINDOWS\Tasks\At58.job
C:\WINDOWS\Tasks\At59.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At60.job
C:\WINDOWS\Tasks\At61.job
C:\WINDOWS\Tasks\At62.job
C:\WINDOWS\Tasks\At63.job
C:\WINDOWS\Tasks\At64.job
C:\WINDOWS\Tasks\At65.job
C:\WINDOWS\Tasks\At66.job
C:\WINDOWS\Tasks\At67.job
C:\WINDOWS\Tasks\At68.job
C:\WINDOWS\Tasks\At69.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At70.job
C:\WINDOWS\Tasks\At71.job
C:\WINDOWS\Tasks\At72.job
C:\WINDOWS\Tasks\At73.job
C:\WINDOWS\Tasks\At74.job
C:\WINDOWS\Tasks\At75.job
C:\WINDOWS\Tasks\At76.job
C:\WINDOWS\Tasks\At77.job
C:\WINDOWS\Tasks\At78.job
C:\WINDOWS\Tasks\At79.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At80.job
C:\WINDOWS\Tasks\At81.job
C:\WINDOWS\Tasks\At82.job
C:\WINDOWS\Tasks\At83.job
C:\WINDOWS\Tasks\At84.job
C:\WINDOWS\Tasks\At85.job
C:\WINDOWS\Tasks\At86.job
C:\WINDOWS\Tasks\At87.job
C:\WINDOWS\Tasks\At88.job
C:\WINDOWS\Tasks\At89.job
C:\WINDOWS\Tasks\At9.job
C:\WINDOWS\Tasks\At90.job
C:\WINDOWS\Tasks\At91.job
C:\WINDOWS\Tasks\At92.job
C:\WINDOWS\Tasks\At93.job
C:\WINDOWS\Tasks\At94.job
C:\WINDOWS\Tasks\At95.job
C:\WINDOWS\Tasks\At96.job
C:\WINDOWS\ufdata2000.log
E:\AUTORUN.INF
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.
2008-08-10 12:58 . 2008-08-10 13:05 <DIR> d-------- C:\fixwareout
2008-08-09 19:23 . 2008-08-09 19:23 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-08-09 19:23 . 2008-08-09 19:23 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-08-05 22:07 . 2008-08-05 22:33 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-08-05 18:50 . 2008-08-05 18:50 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-08-01 15:20 . 2008-08-01 15:20 96 --a------ C:\WINDOWS\cool.ini
2008-08-01 15:19 . 1996-11-25 09:06 140,288 --a------ C:\WINDOWS\system32\ra3214_4.dll
2008-08-01 15:19 . 1996-11-25 09:06 90,624 --a------ C:\WINDOWS\system32\pnc32301.dll
2008-08-01 15:19 . 1996-11-25 09:06 85,504 --a------ C:\WINDOWS\system32\encdnet.dll
2008-08-01 15:19 . 1996-11-25 09:06 82,398 --a------ C:\WINDOWS\c96unins.exe
2008-08-01 15:19 . 1996-11-25 09:06 72,704 --a------ C:\WINDOWS\system32\ra3228_8.dll
2008-08-01 15:19 . 1996-11-25 09:06 13,824 --a------ C:\WINDOWS\system32\ra32dnet.dll
2008-07-30 19:51 . 2008-07-30 19:51 <DIR> d-------- C:\Documents and Settings\liczkowscy\Dane aplikacji\DAEMON Tools
2008-07-24 20:54 . 2008-08-06 18:28 13,030 --a------ C:\PDOXUSRS.NET
2008-07-24 19:58 . 2008-07-24 19:58 <DIR> d-------- C:\Program Files\Common Files\grafa
2008-07-24 19:58 . 2008-07-24 19:58 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-07-24 19:55 . 2008-07-24 19:55 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-23 20:15 . 2008-07-23 20:15 <DIR> dr------- C:\Documents and Settings\LocalService\Ulubione
2008-07-23 14:12 . 2008-08-10 10:10 <DIR> d-------- C:\Metin2_PL
2008-07-23 12:36 . 2008-07-23 12:36 1,720,086 --a------ C:\WINDOWS\system32\TmpA10893140
2008-07-21 22:07 . 2008-07-21 22:07 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-07-21 22:07 . 2008-07-21 22:07 <DIR> d-------- C:\Documents and Settings\liczkowscy\SystemRequirementsLab
2008-07-20 20:59 . 2008-07-20 20:59 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-07-16 15:44 . 2008-07-16 15:44 0 --a------ C:\WINDOWS\system32\L18E0mq0.exe.a_a
2008-07-16 13:00 . 2008-07-16 13:00 <DIR> dr------- C:\Documents and Settings\NetworkService\Ulubione
2008-07-15 22:48 . 2008-07-15 22:48 0 --a------ C:\WINDOWS\system32\2lRS3447.exe.a_a
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 16:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-31 18:33 --------- d-----w C:\Documents and Settings\liczkowscy\Dane aplikacji\Hamachi
2008-07-31 10:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-30 17:51 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-23 10:40 --------- d-----w C:\Program Files\Image-Line
2008-07-17 21:00 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ATI MMC
2008-07-17 20:14 --------- d-----w C:\Program Files\NetPanel
2008-07-01 19:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-07-01 19:15 --------- d-----w C:\Program Files\Lavasoft
2008-07-01 19:14 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-24 18:07 49,152 --sh--w C:\fun.xls.exe
2008-06-22 20:53 --------- d-----w C:\Program Files\CyberLink
2008-06-22 16:20 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 12:05 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-05-25 12:59 234,418 ----a-w C:\WINDOWS\EasyGifAnimator_Toolbar_Uninstaller_7109.exe
2008-02-28 22:35 0 ----a-w C:\Documents and Settings\liczkowscy\tree.dat
2007-11-17 12:44 19,552 ----a-w C:\Documents and Settings\liczkowscy\Dane aplikacji\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"DAEMON Tools Lite"="E:\DAEMON Tools Lite\daemon.exe" [2008-07-24 17:02 490952]
"SpybotSD TeaTimer"="E:\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41 45056]
"ATIPTA"="atiptaxx.exe" [2006-02-22 02:05 344064 C:\WINDOWS\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 15:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= divxa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"E:\\Gadu-Gadu\\gg.exe"=
"F:\\Program Files\\Soulseek\\slsk.exe"=
"F:\\CS 1.6\\hl.exe"=
"E:\\Liero\\LieroX.exe"=
"C:\\Metin2_PL\\metin2.bin"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1454:UDP"= 1454:UDP:Windows Media Format SDK (firefox.exe)
"1455:UDP"= 1455:UDP:Windows Media Format SDK (firefox.exe)
"22049:TCP"= 22049:TCP:BitComet 22049 TCP
"22049:UDP"= 22049:UDP:BitComet 22049 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{268384ab-9128-11dc-b43c-00e04c041f0b}]
\Shell\Auto\command - G:\fun.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35428b1a-5e61-11dd-b636-001bbf597f60}]
\Shell\Auto\command - G:\fun.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f09ec8a-5728-11dd-b61f-001bbf597f60}]
\Shell\Auto\command - G:\fun.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74f77f1e-6520-11dd-b643-001bbf597f60}]
\Shell\Auto\command - G:\fun.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c51083e-2a82-11dd-b5b3-001bbf597f60}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e906c680-48ec-11dd-b601-001bbf597f60}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contents of the 'Scheduled Tasks' folder
2008-07-22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-08-09 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- E:\Spybot - Search & Destroy\SpybotSD.exe [2008-01-28 11:43]
.
- - - - ORPHANS REMOVED - - - -
BHO-{99C6D1BB-7555-474C-91DA-D8FB62A9CC75} - (no file)
HKCU-Run-AlcoholAutomount - C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe
HKLM-Run-C:\WINDOWS\system32\kdhml.exe - C:\WINDOWS\system32\kdhml.exe
HKLM-Run-IMJPMIG8.2 - msime82.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-10 13:23:51
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\SYZ_DAT
C:\WINDOWS\system32\drivers\MFX.sys 45824 bytes executable
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"C:\\WINDOWS\\system32\\kdhml.exe"="C:\\WINDOWS\\system32\\kdhml.exe"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-08-10 13:29:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-10 11:29:48
Pre-Run: 249,245,696 bajtów wolnych
Post-Run: 505,552,896 bajt˘w wolnych
382 --- E O F --- 2008-07-12 11:05:47
Dodam że już odczuwalnie komputer przyspieszył ^^ Dzięki wielkie ^^