Konto usunięte: Przede wszystkim polecam Ci przeskanować komputer programem ComboFix z pewnoscia pomoże
Tylko, że ja nie wiem o co mu chodzi:

Konto usunięte: ComboFix 11-05-11.01 - Administrator 2011-05-15 1254.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.511.120 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Administrator\Pulpit\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\auth.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\burnlib.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\CddbLangPL.dll
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\dsp_sps.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\enc_aacplus.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\enc_flac.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\enc_lame.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\enc_vorbis.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\enc_wav.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\enc_wma.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_classicart.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_crasher.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_ff.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_find_on_disk.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_hotkeys.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_jumpex.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_ml.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_nopro.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_orgler.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_skinmanager.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_timerestore.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_tray.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\gen_undo.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_avi.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_cdda.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_dshow.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_flac.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_flv.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_linein.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_midi.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_mkv.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_mod.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_mp3.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_mp4.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_nsv.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_swf.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_vorbis.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_wav.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_wave.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_wm.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\in_wv.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_addons.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_autotag.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_bookmarks.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_devices.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_disc.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_downloads.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_enqplay.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_history.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_impex.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_local.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_nowplaying.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_online.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_orb.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_playlists.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_plg.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_pmp.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_rg.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_transcode.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ml_wire.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\ombrowser.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\out_disk.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\out_ds.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\out_wave.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\playlist.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_activesync.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_android.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_ipod.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_njb.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_p4s.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_usb.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\pmp_wifi.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\tagz.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\vis_avs.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\vis_milk2.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\vis_nsfs.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\winamp.lng
c:\docume~1\ADMINI~1\USTAWI~1\Temp\WLZ67FB.tmp\winampa.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\auth.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\burnlib.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\CddbLangPL.dll
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\dsp_sps.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\enc_aacplus.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\enc_flac.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\enc_lame.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\enc_vorbis.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\enc_wav.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\enc_wma.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_classicart.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_crasher.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_ff.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_find_on_disk.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_hotkeys.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_jumpex.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_ml.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_nopro.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_orgler.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_skinmanager.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_timerestore.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_tray.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\gen_undo.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_avi.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_cdda.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_dshow.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_flac.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_flv.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_linein.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_midi.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_mkv.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_mod.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_mp3.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_mp4.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_nsv.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_swf.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_vorbis.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_wav.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_wave.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_wm.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\in_wv.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_addons.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_autotag.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_bookmarks.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_devices.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_disc.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_downloads.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_enqplay.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_history.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_impex.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_local.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_nowplaying.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_online.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_orb.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_playlists.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_plg.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_pmp.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_rg.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_transcode.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ml_wire.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\ombrowser.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\out_disk.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\out_ds.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\out_wave.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\playlist.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_activesync.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_android.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_ipod.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_njb.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_p4s.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_usb.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\pmp_wifi.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\tagz.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\vis_avs.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\vis_milk2.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\vis_nsfs.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\winamp.lng
c:\documents and settings\Administrator\Ustawienia lokalne\Temp\WLZ67FB.tmp\winampa.lng
E:\Autorun.inf
.
.
((((((((((((((((((((((((( Pliki utworzone od 2011-04-15 do 2011-05-15 )))))))))))))))))))))))))))))))
.
.
2011-05-14 22:01 . 2011-05-14 22:01--------d-----w-c:\program files\ChomikBox
2011-05-14 21:30 . 2011-05-14 21:39--------dc----w-c:\documents and settings\Administrator\Dane aplikacji\foobar2000
2011-05-14 21:03 . 2011-05-14 21:22--------dc----w-c:\documents and settings\Administrator\Dane aplikacji\vlc
2011-05-14 21:00 . 2011-05-14 21:00--------d-----w-c:\program files\VideoLAN
2011-05-02 00:13 . 2011-04-14 16:59142296----a-w-c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-02 00:13 . 2011-04-14 16:59781272----a-w-c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-02 00:13 . 2011-04-14 16:591874904----a-w-c:\program files\Mozilla Firefox\mozjs.dll
2011-05-02 00:13 . 2011-04-14 16:5915832----a-w-c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-02 00:13 . 2011-04-14 16:5989048----a-w-c:\program files\Mozilla Firefox\libEGL.dll
2011-05-02 00:13 . 2011-04-14 16:59465880----a-w-c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-02 00:13 . 2010-01-01 08:001974616----a-w-c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-02 00:13 . 2010-01-01 08:001892184----a-w-c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-29 00:19 . 2011-05-02 00:06--------dc----w-c:\documents and settings\Administrator\Dane aplikacji\Winamp
2011-04-27 20:10 . 2001-10-26 15:295632----a-w-c:\windows\system32\ptpusb.dll
2011-04-27 20:10 . 2004-08-03 22:44159232----a-w-c:\windows\system32\ptpusd.dll
2011-04-23 10:51 . 2011-05-15 10:30--------d-----w-c:\windows\SxsCaPendDel
2011-04-21 15:42 . 2011-04-21 15:43--------d-----w-c:\program files\Common Files\Adobe
2011-04-20 15:42 . 2011-04-20 15:42--------d-----w-c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Identities
2011-04-18 18:16 . 2011-05-14 22:24--------d-----w-c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\ChomikBox
2011-04-18 18:15 . 2011-05-14 13:10--------d-----w-c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Temp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 19:44 . 2011-04-15 00:0959888------w-c:\windows\system32\pxwma.dll
2011-03-04 19:44 . 2011-02-28 13:5145648------w-c:\windows\system32\drivers\PxHelp20.sys
2011-03-04 19:44 . 2011-02-28 13:51133616------w-c:\windows\system32\pxafs.dll
2011-03-04 19:44 . 2011-04-15 00:09126448------w-c:\windows\system32\pxinsi64.exe
2011-03-04 19:44 . 2011-04-15 00:09123888------w-c:\windows\system32\pxcpyi64.exe
2011-02-22 18:32 . 2011-02-22 18:3273728----a-w-c:\windows\system32\javacpl.cpl
2011-02-22 18:32 . 2011-02-22 18:32472808----a-w-c:\windows\system32\deployJava1.dll
2011-04-14 16:59 . 2011-05-02 00:13142296----a-w-c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 16945032]
"Gadu-Gadu 10"="c:\program files\Gadu-Gadu 10\gg.exe" [2010-12-16 12984928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 90112]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"ORAHSSSessionManager"="c:\program files\Livebox\SessionManager\SessionManager.exe" [2008-06-10 107248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
c:\documents and settings\Administrator\Menu Start\Programy\Autostart\
Tworzenie wycink˘w ekranu i uruchamianie programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Livebox\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Gadu-Gadu 10\\gg.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-02-21 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-02-21 19024]
R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\drivers\WlanBZXP.sys [2011-02-28 402432]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\Drivers\VMUVC.sys --> c:\windows\system32\Drivers\VMUVC.sys [?]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys --> c:\windows\system32\drivers\vvftUVC.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
.
Zawartość folderu 'Zaplanowane zadania'
.
2011-05-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-03-04 21:18]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.wp.pl/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\ziv2uil1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
HKCU-Run-PKTray - c:\program files\Przyspiesz Komputer\PKTray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-15 12:32
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
.
skanowanie ukrytych procesów ...
.
skanowanie ukrytych wpisów autostartu ...
.
skanowanie ukrytych plików ...
.
skanowanie pomyślnie ukończone
ukryte pliki: 0
.
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
.
- - - - - - - > 'winlogon.exe'(824)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3328)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\browselc.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL
c:\windows\system32\shdoclc.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\SOUNDMAN.EXE
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WISPTIS.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Czas ukończenia: 2011-05-15 12

02 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2011-05-15 10:34
.
Przed: 6 767 431 680 bajtów wolnych
Po: 7 456 600 064 bajtów wolnych
.
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 793F6F2E7E71BAF7470C19DAA699D85C