wylaczenie procesow noda nie pomaga
ComboFix 08-02-25.3 - MnMs 2008-02-27 21:06:07.1 - 
FAT32x86
Microsoft Windows XP Professional  5.1.2600.0.1250.1.1045.18.260 [GMT 1:00]
Running from: C:\Documents and Settings\MnMs\Pulpit\ComboFix.exe
 * Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
(((((((((((((((((((((((((   Files Created from 2008-01-27 to 2008-02-27  )))))))))))))))))))))))))))))))
.
2008-02-27 19:06 . 2008-02-27 19:06	<DIR>	d--hs----	C:\FOUND.007
2008-02-26 21:48 . 2008-02-26 21:48	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-02-26 21:31 . 2008-02-26 21:31	<DIR>	d--hs----	C:\FOUND.006
2008-02-26 20:25 . 2008-02-26 20:25	<DIR>	d--hs----	C:\FOUND.005
2008-02-26 19:48 . 2008-02-26 19:48	<DIR>	d--hs----	C:\FOUND.004
2008-02-25 21:44 . 2008-02-25 21:44	<DIR>	d--hs----	C:\FOUND.003
2008-02-25 21:40 . 2008-02-25 21:40	0	--a------	C:\WINDOWS\ativpsrm.bin
2008-02-25 20:01 . 2008-02-25 20:01	<DIR>	d--hs----	C:\FOUND.002
2008-02-25 17:34 . 2008-02-25 17:34	<DIR>	d--hs----	C:\FOUND.001
2008-02-25 13:33 . 2001-08-17 22:03	21,760	--a------	C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-23 15:43 . 2008-02-23 15:43	<DIR>	d--------	C:\Documents and Settings\MnMs\WinWAP Temporary Files
2008-02-23 15:41 . 2008-02-23 15:41	<DIR>	d--------	C:\Program Files\Winwap Technologies
2008-02-23 15:35 . 1998-02-06 22:37	299,520	--a------	C:\WINDOWS\uninst.exe
2008-02-23 15:34 . 2008-02-23 15:34	<DIR>	d--------	C:\Downloads
2008-02-23 15:34 . 2008-02-23 15:35	<DIR>	d--------	C:\Documents and Settings\MnMs\WINDOWS
2008-02-23 15:34 . 2008-02-23 15:34	<DIR>	d--------	C:\Documents and Settings\MnMs\Dane aplikacji\GetRightToGo
2008-02-22 14:39 . 2008-02-22 14:39	<DIR>	d--------	C:\Documents and Settings\MnMs\Dane aplikacji\Gadu-Gadu
2008-02-21 18:19 . 2003-07-21 04:17	5,174	--a------	C:\WINDOWS\system32\nppt9x.vxd
2008-02-21 18:19 . 2005-01-04 19:43	4,682	--a------	C:\WINDOWS\system32\npptNT2.sys
2008-02-21 18:16 . 2008-02-21 18:16	<DIR>	d--------	C:\WINDOWS\system32\Adobe
2008-02-21 18:16 . 2008-02-21 18:16	<DIR>	d--------	C:\WINDOWS\Profiles
2008-02-21 18:16 . 2008-02-21 18:16	<DIR>	d--------	C:\Program Files\Common Files\Adobe
2008-02-21 18:16 . 2008-02-21 18:16	<DIR>	d--------	C:\Documents and Settings\MnMs\Dane aplikacji\InterTrust
2008-02-21 18:16 . 1998-10-29 16:45	306,688	--a------	C:\WINDOWS\IsUninst.exe
2008-02-21 18:12 . 2008-02-21 18:12	<DIR>	d--hs----	C:\FOUND.000
2008-02-21 16:14 . 2008-02-21 16:14	<DIR>	d--------	C:\WINDOWS\system32\LogFiles
2008-02-21 16:14 . 2008-02-27 20:36	107,832	--a------	C:\WINDOWS\system32\PnkBstrB.exe
2008-02-21 16:14 . 2008-02-21 16:14	66,872	--a------	C:\WINDOWS\system32\PnkBstrA.exe
2008-02-21 16:14 . 2008-02-27 20:37	22,328	--a------	C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-21 15:39 . 2008-02-21 15:39	427	--a------	C:\WINDOWS\ODBC.INI
2008-02-21 15:36 . 2008-02-21 15:36	<DIR>	d--------	C:\WINDOWS\ShellNew
2008-02-21 15:32 . 2008-02-21 15:32	<DIR>	d--------	C:\Documents and Settings\MnMs\Dane aplikacji\Microsoft Web Folders
2008-02-21 15:26 . 2008-02-21 15:26	<DIR>	d--hs----	C:\Recycled
2008-02-21 15:16 . 2008-02-21 15:16	0	--a------	C:\WINDOWS\nsreg.dat
2008-02-21 14:06 . 2008-02-21 14:06	<DIR>	d--------	C:\Program Files\Sunbelt Software
2008-02-21 14:05 . 2008-02-21 14:05	<DIR>	d--------	C:\Program Files\ESET
2008-02-21 14:05 . 2008-02-21 14:05	<DIR>	d--------	C:\Program Files\Ares
2008-02-21 14:05 . 2008-02-21 14:05	512,096	--a------	C:\WINDOWS\system32\drivers\amon.sys
2008-02-21 14:05 . 2008-02-21 14:05	298,104	--a------	C:\WINDOWS\system32\imon.dll
2008-02-21 14:05 . 2008-02-21 14:05	15,424	--a------	C:\WINDOWS\system32\drivers\nod32drv.sys
2008-02-21 13:55 . 2007-09-28 21:05	593,920	---------	C:\WINDOWS\system32\ati2sgag.exe
2008-02-21 13:54 . 2008-02-21 13:54	<DIR>	d--------	C:\Program Files\ATI Technologies
2008-02-21 13:53 . 2008-02-21 13:53	<DIR>	d--------	C:\ATI
2008-02-21 13:51 . 2008-02-27 17:46	536,141,824	--a------	C:\WINDOWS\MEMORY.DMP
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-21 14:14	520,248	----a-w	C:\WINDOWS\UNNERO.exe
2008-02-21 14:14	325,632	----a-w	C:\WINDOWS\system32\netsetup.exe
2008-02-21 14:14	266,240	----a-w	C:\WINDOWS\CMIUninstall.exe
2008-02-21 14:14	225,280	----a-w	C:\WINDOWS\CmiRmRedundDir.exe
2004-09-03 09:32	3,488	----a-w	C:\WINDOWS\inf\OTHER\CMIAINFO.SYS
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 18:07 24576]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07 53248]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2005-11-15 21:31 33792]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-10-05 17:38 147456]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-02-21 14:05 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 17:29 13312]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 18:05:56 65588]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-25 21:10:32 113664]
R1 fwdrv;Firewall Driver;C:\WINDOWS\System32\drivers\fwdrv.sys [2005-12-15 18:13]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\System32\drivers\khips.sys [2005-12-15 18:01]
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\System32\drivers\NeroCd2k.sys [2006-10-05 17:38]
S3 

va095;XDva095;C:\WINDOWS\System32\XDva095.sys []
S3 

va098;XDva098;C:\WINDOWS\System32\XDva098.sys []
*Newly Created Service* - PNKBSTRK
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, 
http://www.gmer.netRootkit scan 2008-02-27 21:09:17
Windows 5.1.2600  FAT NTAPI
scanning hidden processes ... 
scanning hidden autostart entries ...
scanning hidden files ... 
scan completed successfully 
hidden files: 0 
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2600.0000]
-> D:\ggg\6.1 gg\Gadu-Gadu\ggwhook.dll
.
Completion time: 2008-02-27 21:10:50
log z combofixa