i nie ma badziewia
ComboFix 08-07-24.3 - Maciej 2008-07-25 16:05:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1516 [GMT 2:00]
Running from: C:\Documents and Settings\Maciej\Pulpit\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED 
.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.
2008-07-25 12:43 . 2008-07-25 12:43 <DIR> d-------- C:\Program Files\Thomson
2008-07-07 23:03 . 2008-07-07 23:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-07 22:47 . 2008-07-07 22:47 <DIR> d-------- C:\Program Files\CableRouting
2008-07-07 21:54 . 2008-07-07 22:22 <DIR> d-------- C:\Program Files\RegSupreme Pro
2008-07-07 21:05 . 2008-07-07 21:05 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ADSL Software Ltd
2008-07-01 23:04 . 2008-07-01 23:04 <DIR> d-------- C:\Program Files\SAGEM
2008-07-01 23:04 . 2005-11-04 16:55 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll
2008-06-30 13:32 . 2008-06-30 13:32 <DIR> d-------- C:\ArmyBuilderEX
2008-06-30 13:30 . 2008-06-30 13:30 <DIR> d-------- C:\Documents and Settings\SamboR\Menu Start
2008-06-30 13:30 . 2008-06-30 13:30 <DIR> d-------- C:\Documents and Settings\SamboR
2008-06-27 18:31 . 2008-06-27 18:32 <DIR> d-------- C:\Program Files\GameSpy Arcade
2008-06-25 10:43 . 2008-06-25 10:43 <DIR> d-------- C:\Program Files\MP3 2 Ogg Lab 2004
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-25 14:10 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-07-25 14:10 --------- d-----w C:\Program Files\neostrada tp
2008-07-25 14:10 --------- d-----w C:\Program Files\lg_fwupdate
2008-07-25 13:12 --------- d-----w C:\Program Files\Spyware Doctor
2008-07-25 10:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-07 20:22 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\Xfire
2008-06-28 20:49 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\AdobeUM
2008-06-20 17:31 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
2008-06-15 20:25 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\PC Tools
2008-06-15 09:16 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\Wizards of the Coast
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-01 20:32 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-06-01 15:44 --------- d-----w C:\Program Files\free-downloads.net
2008-06-01 15:16 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-06-01 15:16 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\DAEMON Tools
2008-05-28 21:07 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 14:00 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-03-07 22:07 22,328 ----a-w C:\Documents and Settings\Maciej\Dane aplikacji\PnkBstrK.sys
2008-03-07 17:07 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2007-12-04 13:53 1502232]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2007-12-04 13:53 1502232 --a------ C:\Program Files\free-downloads.net\tbfree.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2007-12-04 13:53 1502232]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "C:\Program Files\free-downloads.net\tbfree.dll" [2007-12-04 13:53 1502232]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:44 15360]
"Steam"="c:\program files\valve\steam\steam.exe" [2008-03-28 20:29 1271032]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2006-02-10 20:40 2048000]
"BitComet"="C:\Program FilesBitComet\BitComet.exe" [2008-02-01 09:20 2194744]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
"AlcoholAutomount"="C:\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-07-02 12:27 219520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-07-12 11:58 356352]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 14:49 20480]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-11-02 08:55 1397760]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"LGODDFU"="C:\Program Files\lg_fwupdate\fwupdate.exe" [2005-04-12 10:11 229376]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]
"WinampAgent"="C:\Winamp\winampa.exe" [2005-10-20 20:32 33792]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-07-25 13:42 1107848]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 16:55 32768]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 10:56 16261632 C:\WINDOWS\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:44 15360]
C:\Documents and Settings\Maciej\Menu Start\Programy\Autostart\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-11-15 02:59:50 2836304]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 22:26:24 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 22:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\the_monaster\\condition zero\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\the_monaster\\counter-strike\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\the_monaster\\day of defeat\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\the_monaster\\deathmatch classic\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program FilesBitComet\\BitComet.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\the_monaster\\condition zero deleted scenes\\hl.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"F:\\Heroes of Might and Magic III\\Heroes3.exe"=
"F:\\soulstrom\\Soulstorm.exe"=
"F:\\commandos\\commandos3.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"E:\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"E:\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"E:\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"F:\\orginalwar\\OwarFull.dll"=
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11704:TCP"= 11704:TCP:BitComet 11704 TCP
"11704:UDP"= 11704:UDP:BitComet 11704 UDP
S3 bDMusicb;bDMusicb;C:\DOCUME~1\Maciej\USTAWI~1\Temp\bDMusicb.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40c1ccc0-d715-11dc-9682-000e50d680bb}]
\Shell\AutoRun\command - I:\xo8wr9.exe
\Shell\explore\Command - I:\xo8wr9.exe
\Shell\open\Command - I:\xo8wr9.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40c1ccc1-d715-11dc-9682-000e50d680bb}]
\Shell\AutoRun\command - K:\xo8wr9.exe
\Shell\explore\Command - K:\xo8wr9.exe
\Shell\open\Command - K:\xo8wr9.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e130e1c-c9de-11dc-9656-000e50d680bb}]
\Shell\AutoRun\command - I:\xo8wr9.exe
\Shell\explore\Command - I:\xo8wr9.exe
\Shell\open\Command - I:\xo8wr9.exe
.
.
------- Supplementary Scan -------
.
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
O8 -: &D&ownload &with BitComet - C:\Program FilesBitComet\BitComet.exe/AddLink.htm
O8 -: &D&ownload all video with BitComet - C:\Program FilesBitComet\BitComet.exe/AddVideo.htm
O8 -: &D&ownload all with BitComet - C:\Program FilesBitComet\BitComet.exe/AddAllLink.htm
O8 -: E&ksportuj do programu Microsoft Excel
O9 -: { - C:\Program Files\Messenger\msmsgs.exe
O9 -: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program FilesBitComet\tools\BitCometBHO_1.2.1.2.dll/206