to jest log z combofix... ktos sie na tym zna?
ComboFix 08-03-27.1 - ppp 2008-03-28 19:52:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1519 [GMT 1:00]
Running from: C:\Program Files\combofix\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED 
.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-28 )))))))))))))))))))))))))))))))
.
2008-03-28 19:48 . 2008-03-28 19:48 <DIR> d-------- C:\Program Files\combofix
2008-03-27 19:15 . 2008-03-27 19:15 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-03-27 19:04 . 2008-03-27 19:04 <DIR> d-------- C:\WINDOWS\Sun
2008-03-27 19:04 . 2008-03-27 19:04 <DIR> d-------- C:\Program Files\Java
2008-03-27 19:04 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-27 19:02 . 2008-03-27 19:02 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-27 19:01 . 2008-03-27 19:01 <DIR> d-------- C:\Program Files\xpiinstal
2008-03-20 21:15 . 2008-03-20 21:17 <DIR> d-------- C:\Program Files\SMAC
2008-03-20 21:15 . 2008-03-20 21:15 249,856 --------- C:\WINDOWS\Setup1.exe
2008-03-20 21:15 . 2008-03-20 21:15 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-03-16 20:13 . 2008-03-27 19:45 <DIR> d-------- C:\Program Files\HijackThis 2.0.2
2008-03-16 17:04 . 2008-03-16 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\FLEXnet
2008-03-16 16:59 . 2008-03-16 16:59 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-03-16 16:57 . 2008-03-16 16:57 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ALM
2008-03-16 16:46 . 2008-03-16 16:46 <DIR> d-------- C:\Program Files\QuickTime
2008-03-16 16:41 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-03-16 16:41 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-03-16 16:34 . 2008-03-16 16:34 <DIR> d-------- C:\Program Files\Bonjour
2008-03-16 16:30 . 2008-03-16 16:30 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-03-10 14:32 . 2008-03-10 14:32 <DIR> d-------- C:\Program Files\Grupa IMAGE
2008-03-02 19:43 . 2008-03-02 19:44 <DIR> d-------- C:\Documents and Settings\ppp\Dane aplikacji\BESTplayer
2008-03-01 19:12 . 2008-03-01 19:12 89 --a------ C:\WINDOWS\MyHeritage.INI
2008-03-01 19:11 . 2008-03-01 19:11 <DIR> d-------- C:\Documents and Settings\ppp\Dane aplikacji\The Complete Genealogy Reporter - FTB
2008-03-01 19:11 . 2000-05-22 15:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-03-01 19:11 . 2002-03-07 00:19 454,656 --a------ C:\WINDOWS\system32\PaintX.dll
2008-03-01 19:11 . 1998-06-23 23:00 137,000 --a------ C:\WINDOWS\system32\msmapi32.ocx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-28 18:53 14,579,744 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-28 18:53 1,001,248 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-28 18:52 --------- d-----w C:\Documents and Settings\ppp\Dane aplikacji\Skype
2008-03-28 18:03 99,800 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-28 18:03 201,956 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-28 17:27 --------- d-----w C:\Program Files\DC++
2008-03-28 10:33 --------- d-----w C:\Documents and Settings\ppp\Dane aplikacji\skypePM
2008-03-21 16:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-16 19:48 --------- d-----w C:\Program Files\CyberLink
2008-03-16 19:45 --------- d-----w C:\Program Files\Google
2008-03-16 19:42 --------- d-----w C:\Program Files\SubEdit-Player
2008-03-16 19:41 --------- d-----w C:\Program Files\Ulead VideoStudio 8.0
2008-03-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-03-16 19:41 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems
2008-03-16 15:59 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-09 13:12 --------- d-----w C:\Program Files\C-Media 6501 Sound
2008-02-09 12:36 --------- d-----w C:\Program Files\drivers
2008-01-31 21:38 --------- d-----w C:\Program Files\lightscribe
2008-01-31 13:21 --------- d-----w C:\Program Files\Real Player
2008-01-30 20:01 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Pinnacle
2008-01-30 17:04 --------- d-----w C:\Program Files\Pinnacle
2008-01-30 16:45 --------- d-----w C:\Program Files\Macromedia
2008-01-30 16:42 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-01-29 20:43 --------- d-----w C:\Documents and Settings\ppp\Dane aplikacji\Ulead Systems
2008-01-29 20:42 --------- d-----w C:\Program Files\SmartSound Software
2008-01-29 20:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-29 20:42 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\SmartSound Software Inc
2008-01-29 20:41 --------- d-----w C:\Program Files\Windows Media Components
2008-01-25 22:05 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-01-22 04:34 1,214,032 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\pswi_preloaded.exe
2007-05-21 09:56 995,328 ----a-w C:\WINDOWS\inf\UIU\A1\W20MLRES.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:21 1694208]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-12 15:23 21686568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 23:22 35328]
"aol"="C:\Program Files\AOL\Active Virus Shield\avp.exe" [2006-05-30 10:13 139367]
"C6501Sound"="c6501.cpl" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-06 10:30 8523776]
"nwiz"="nwiz.exe" [2007-11-06 10:30 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-06 10:30 81920]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 16:26 406016]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\adobe cs\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="regsvr32 /s /n /i:U shell32" []
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AOL\\Active Virus Shield\\avp.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2007-05-21 10:56]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;C:\WINDOWS\system32\drivers\c6501.sys [2007-07-10 02:42]
S3 cm102u32;C-Media CM6501 Like Sound Interface;C:\WINDOWS\system32\drivers\c6501.sys [2007-07-10 02:42]
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4931c5a6-f6b7-11dc-8fe3-001d608d7b93}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc45ad43-0785-11dc-b1aa-806d6172696f}]
\Shell\AutoRun\command - E:\UIU.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-28 19:53:24
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-28 19:53:47
ComboFix-quarantined-files.txt 2008-03-28 18:53:45
Pre-Run: 20,665,724,928 bajtów wolnych
Post-Run: 20,656,918,528 bajtów wolnych
i jak... podpowie ktos cos?
mozna liczyc na czyjas pomoc?