1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253.
254. | ComboFix 10-03-09.06 - Admin 2010-03-10 8:42.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.3319.2696 [GMT 1:00]
Uruchomiony z: c:\\documents and settings\\Admin\\Pulpit\\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Zapora osobista *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezydentny antywirus jest aktywny
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\\documents and settings\\Admin\\Dane aplikacji\\EurekaLog
c:\\documents and settings\\Admin\\Dane aplikacji\\EurekaLog\\EurekaLog.ini
.
((((((((((((((((((((((((( Pliki utworzone od 2010-02-10 do 2010-03-10 )))))))))))))))))))))))))))))))
.
2010-03-06 10:27 . 2010-02-12 10:03 293376 ------w- c:\\windows\\system32\\browserchoice.exe
2010-03-02 08:41 . 2010-03-02 08:41 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\OpenFM
2010-03-02 07:58 . 2010-03-02 08:07 -------- d-----w- c:\\documents and settings\\Admin\\Dane aplikacji\\ipla
2010-03-02 07:58 . 2010-03-02 07:58 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\ipla
2010-03-02 07:58 . 2010-03-02 07:58 -------- d-----w- c:\\program files\\ipla
2010-03-02 07:57 . 2010-03-02 07:57 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\Gadu-Gadu 10
2010-03-02 07:56 . 2010-03-02 07:57 -------- d-----w- c:\\documents and settings\\Admin\\Dane aplikacji\\Gadu-Gadu 10
2010-03-02 07:56 . 2010-03-02 07:57 -------- d-----w- c:\\program files\\Gadu-Gadu 10
2010-02-23 10:19 . 2010-03-06 12:27 -------- d-----w- c:\\program files\\Pity 2009
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-10 07:40 . 2009-09-08 07:44 12 ----a-w- c:\\windows\\system32\\haspaddr.dat
2010-03-10 07:27 . 2008-09-28 10:51 -------- d-----w- c:\\documents and settings\\Admin\\Dane aplikacji\\Skype
2010-03-02 08:41 . 2009-05-08 08:56 -------- d-----w- c:\\documents and settings\\Admin\\Dane aplikacji\\OpenFM
2010-03-02 07:56 . 2009-02-13 07:15 -------- d-----w- c:\\program files\\Nowe Gadu-Gadu
2010-02-19 14:20 . 2009-12-01 14:34 -------- d-----w- c:\\program files\\Full Tilt Poker
2010-02-12 09:42 . 2008-09-28 08:31 -------- d-----w- c:\\program files\\Trans
2010-02-03 15:06 . 2008-09-28 07:46 73352 ----a-w- c:\\documents and settings\\Admin\\Ustawienia lokalne\\Dane aplikacji\\GDIPFONTCACHEV1.DAT
2010-01-29 12:27 . 2010-01-29 12:27 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\Nokia
2010-01-29 12:27 . 2010-01-29 09:45 -------- d-----w- c:\\program files\\Common Files\\Nokia
2010-01-29 12:27 . 2010-01-29 09:44 -------- d-----w- c:\\program files\\Nokia
2010-01-29 12:26 . 2010-01-29 12:26 3351812 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\\Installer\\CommonCustomActions\\msxml6Exec.exe
2010-01-29 12:26 . 2010-01-29 12:26 36864 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\\Installer\\CommonCustomActions\\Sleep.exe
2010-01-29 12:26 . 2010-01-29 12:26 3203453 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\\Installer\\CommonCustomActions\\vcredistExec.exe
2010-01-29 12:26 . 2010-01-29 12:26 24566576 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\\NokiaSoftwareUpdaterSetup_pl[1].exe
2010-01-29 12:26 . 2010-01-29 09:42 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations
2010-01-29 09:56 . 2010-01-29 09:46 -------- d-----w- c:\\documents and settings\\Admin\\Dane aplikacji\\PC Suite
2010-01-29 09:47 . 2010-01-29 09:47 0 ---ha-w- c:\\windows\\system32\\drivers\\Msft_Kernel_ccdcmb_01007.Wdf
2010-01-29 09:47 . 2010-01-29 09:47 0 ---ha-w- c:\\windows\\system32\\drivers\\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-01-29 09:46 . 2010-01-29 09:46 -------- d-----w- c:\\documents and settings\\Admin\\Dane aplikacji\\Nokia
2010-01-29 09:46 . 2010-01-29 09:46 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\PC Suite
2010-01-29 09:45 . 2010-01-29 09:45 -------- d-----w- c:\\program files\\Common Files\\PCSuite
2010-01-29 09:45 . 2010-01-29 09:45 -------- d-----w- c:\\program files\\DIFX
2010-01-29 09:45 . 2010-01-29 09:45 -------- d-----w- c:\\program files\\PC Connectivity Solution
2010-01-29 09:43 . 2010-01-29 09:43 95232 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\\Installer\\CommonCustomActions\\pcswpcsi.exe
2010-01-29 09:43 . 2010-01-29 09:43 8192 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\\Installer\\CommonCustomActions\\UninstCCD.exe
2010-01-29 09:43 . 2010-01-29 09:43 61440 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\\Installer\\CommonCustomActions\\UninstPCSFEMsi.exe
2010-01-29 09:43 . 2010-01-29 09:43 10240 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\\Installer\\CommonCustomActions\\UninstPCS.exe
2010-01-29 09:42 . 2010-01-29 09:44 34760920 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Installations\\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\\Nokia_PC_Suite_pol_web[1].exe
2010-01-29 07:03 . 2010-01-29 07:03 -------- d-----w- c:\\program files\\Common Files\\Borland Shared
2010-01-29 07:02 . 2010-01-29 07:02 -------- d-----w- c:\\program files\\Common Files\\Business Objects
2010-01-29 07:02 . 2010-01-29 07:02 -------- d-----w- c:\\program files\\Business Objects
2010-01-29 07:02 . 2009-09-07 12:26 -------- d-----w- c:\\program files\\PC NET SERVICE
2010-01-20 12:05 . 2010-01-20 12:05 42088 ----a-w- c:\\documents and settings\\Admin\\Dane aplikacji\\Gadu-Gadu 10\\_userdata\\ggbho.2.dll
2010-01-19 10:06 . 2008-09-28 08:51 -------- d-----w- c:\\program files\\Common Files\\Adobe
2010-01-18 11:49 . 2009-10-06 12:02 -------- d-----w- c:\\program files\\Pro Surveillance System(EN)
2010-01-06 14:21 . 2006-03-02 12:00 567712 ----a-w- c:\\windows\\system32\\perfh015.dat
2010-01-06 14:21 . 2006-03-02 12:00 115166 ----a-w- c:\\windows\\system32\\perfc015.dat
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\\windows\\system32\\drivers\\srv.sys
2009-12-21 19:08 . 2006-03-02 12:00 916480 ----a-w- c:\\windows\\system32\\wininet.dll
2009-12-17 11:05 . 2009-12-17 11:05 1956528 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\NOS\\Adobe_Downloads\\install_flash_player_ax.exe
2009-12-17 07:42 . 2008-09-24 12:14 345088 ----a-w- c:\\windows\\system32\\mspaint.exe
2009-12-14 07:10 . 2006-03-02 12:00 33280 ----a-w- c:\\windows\\system32\\csrsrv.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
\"Skype\"=\"c:\\program files\\Skype\\Phone\\Skype.exe\" [2008-08-12 21741864]
\"SpybotSD TeaTimer\"=\"c:\\program files\\Spybot - Search & Destroy\\TeaTimer.exe\" [2009-03-05 2260480]
\"HuaWeiEVDO.exe\"=\"c:\\program files\\Huawei technologies\\Mobile Connect\\Mobile Connect.exe\" [2007-05-29 917504]
\"TSPNSUpdate\"=\"c:\\program files\\PC NET SERVICE\\UpdateManager\\update.exe\" [2009-11-03 9414144]
\"PC Suite Tray\"=\"c:\\program files\\Nokia\\Nokia PC Suite 7\\PCSuite.exe\" [2009-11-11 1451520]
\"Gadu-Gadu 10\"=\"c:\\program files\\Gadu-Gadu 10\\gg.exe\" [2010-01-20 12067432]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
\"RTHDCPL\"=\"RTHDCPL.EXE\" [2007-10-25 16855552]
\"IgfxTray\"=\"c:\\windows\\system32\\igfxtray.exe\" [2007-12-19 135168]
\"HotKeysCmds\"=\"c:\\windows\\system32\\hkcmd.exe\" [2007-12-19 159744]
\"Persistence\"=\"c:\\windows\\system32\\igfxpers.exe\" [2007-12-19 131072]
\"Trans\"=\"c:\\program files\\Trans\\trans.exe\" [2009-11-09 2870712]
\"egui\"=\"c:\\program files\\ESET\\ESET Smart Security\\egui.exe\" [2009-05-14 2029640]
\"EPSS\"=\"c:\\program files\\Software Tools\\Enterprise Pro Surveillance System(Basic)\\EPSS.exe\" [2008-09-04 1052672]
\"Kernel and Hardware Abstraction Layer\"=\"KHALMNPR.EXE\" [2009-06-17 55824]
\"QuickTime Task\"=\"c:\\program files\\QuickTime\\qttask.exe\" [2009-05-26 413696]
\"Adobe Reader Speed Launcher\"=\"c:\\program files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\" [2009-12-22 35760]
\"Adobe ARM\"=\"c:\\program files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\" [2009-12-11 948672]
[HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
\"CTFMON.EXE\"=\"c:\\windows\\system32\\CTFMON.EXE\" [2008-04-14 15360]
c:\\documents and settings\\Admin\\Menu Start\\Programy\\Autostart\\
Mobile Connect.lnk - c:\\program files\\Huawei technologies\\Mobile Connect\\Mobile Connect.exe [2008-9-28 917504]
Skr˘t do TrayIt!.exe.lnk - c:\\documents and settings\\Admin\\Moje dokumenty\\trayit_4_6_5_5\\TrayIt!.exe [2010-3-3 204800]
c:\\documents and settings\\All Users\\Menu Start\\Programy\\Autostart\\
Logitech SetPoint.lnk - c:\\program files\\Logitech\\SetPoint\\SetPoint.exe [2008-9-29 813584]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\windows nt\\currentversion\\winlogon\\notify\\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\\program files\\Common Files\\Logishrd\\Bluetooth\\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\aawservice]
@=\"Service\"
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\Wdf01000.sys]
@=\"Driver\"
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\WdfLoadGroup]
@=\"\"
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\\program files\\Adobe\\Reader 9.0\\Reader\\reader_sl.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\HP Software Update]
2007-05-08 15:24 54840 -c--a-w- c:\\program files\\HP\\HP Software Update\\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\HPWH myPrintMileage Agent]
2003-09-23 12:43 102400 ----a-w- c:\\program files\\Hewlett-Packard\\hp business inkjet 1100 series\\Toolbox\\mpm.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Panasonic Device Manager for Multi-Function Station software]
2007-05-21 10:46 126976 -c--a-w- c:\\program files\\Panasonic\\MFStation\\PCCMFSDM.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Panasonic Device Monitor Wakeup]
2006-11-02 12:54 303104 -c--a-w- c:\\program files\\Panasonic\\Device Monitor\\DMWakeup.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Panasonic PCFAX for Multi-Function Station software]
2007-08-10 10:05 757760 -c--a-w- c:\\program files\\Panasonic\\MFStation\\KmPcFax.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\\program files\\QuickTime\\QTTask.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\SunJavaUpdateSched]
2009-07-25 03:23 149280 -c--a-w- c:\\program files\\Java\\jre6\\bin\\jusched.exe
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\TRUCK & CARGO Online]
2009-07-01 07:47 1122816 ----a-w- c:\\tccargo\\tccargo.exe
[HKLM\\~\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile]
\"EnableFirewall\"= 0 (0x0)
[HKLM\\~\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile\\AuthorizedApplications\\List]
\"%windir%\\\\system32\\\\sessmgr.exe\"=
\"%windir%\\\\Network Diagnostic\\\\xpnetdiag.exe\"=
\"c:\\\\Program Files\\\\Panasonic\\\\TrapMonitor\\\\Trapmnnt.exe\"=
\"c:\\\\Program Files\\\\Hewlett-Packard\\\\hp business inkjet 1100 series\\\\Toolbox\\\\HPWHTBX.exe\"=
\"c:\\\\Program Files\\\\Gadu-Gadu\\\\gg.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpqtra08.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpqste08.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpofxm08.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hposfx08.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hposid01.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpqscnvw.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpqkygrp.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpqCopy.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpfccopy.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpzwiz01.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\Unload\\\\HpqPhUnl.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\Unload\\\\HpqDIA.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpoews01.exe\"=
\"c:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\bin\\\\hpqnrs08.exe\"=
\"c:\\\\WINDOWS\\\\system32\\\\PnkBstrA.exe\"=
\"c:\\\\WINDOWS\\\\system32\\\\PnkBstrB.exe\"=
\"c:\\\\Program Files\\\\Microsoft SQL Server\\\\80\\\\Tools\\\\Binn\\\\sqlmangr.exe\"=
\"c:\\\\Program Files\\\\Microsoft SQL Server\\\\90\\\\Shared\\\\SqlSAC.exe\"=
\"c:\\\\Program Files\\\\Microsoft SQL Server\\\\90\\\\Shared\\\\SqlWtsn.exe\"=
\"c:\\\\Program Files\\\\Microsoft SQL Server\\\\80\\\\Tools\\\\Binn\\\\SVRNETCN.exe\"=
\"c:\\\\Program Files\\\\uTorrent\\\\uTorrent.exe\"=
\"c:\\\\Program Files\\\\Skype\\\\Phone\\\\Skype.exe\"=
[HKLM\\~\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile\\GloballyOpenPorts\\List]
\"1947:TCP\"= 1947:TCP:HASP SRM
\"1947:UDP\"= 1947:UDP:HASP SRM
R1 ehdrv;ehdrv;c:\\windows\\system32\\drivers\\ehdrv.sys [2009-05-14 107256]
R2 ekrn;ESET Service;c:\\program files\\ESET\\ESET Smart Security\\ekrn.exe [2009-05-14 731840]
R2 HASP Loader;HASP Loader;c:\\windows\\system32\\nhsrvice.exe -service --> c:\\windows\\system32\\nhsrvice.exe -service [?]
R2 hasplms;HASP License Manager;c:\\windows\\system32\\hasplms.exe -run --> c:\\windows\\system32\\hasplms.exe -run [?]
R2 HASPSrv;HASPSrv;c:\\windows\\system32\\HASPSrv.exe [2009-08-21 696320]
R2 MSSQL$CDN_OPTIMA;SQL Server (CDN_OPTIMA);c:\\program files\\Microsoft SQL Server\\MSSQL.1\\MSSQL\\Binn\\sqlservr.exe [2007-02-10 29178224]
R2 MSSQL$PCNETSERVICE;MSSQL$PCNETSERVICE;c:\\program files\\Microsoft SQL Server\\MSSQL$PCNETSERVICE\\Binn\\sqlservr.exe -sPCNETSERVICE --> c:\\program files\\Microsoft SQL Server\\MSSQL$PCNETSERVICE\\Binn\\sqlservr.exe -sPCNETSERVICE [?]
R2 Panasonic Local Printer Service;Panasonic Local Printer Service;c:\\progra~1\\PANASO~1\\LocalCom\\lmsrvnt.exe [2008-09-29 36864]
R2 port_nt;port_nt;c:\\windows\\system32\\drivers\\port_nt.sys [2009-09-07 3912]
R2 SQLAgent$PCNETSERVICE;SQLAgent$PCNETSERVICE;c:\\program files\\Microsoft SQL Server\\MSSQL$PCNETSERVICE\\Binn\\sqlagent.EXE -i PCNETSERVICE --> c:\\program files\\Microsoft SQL Server\\MSSQL$PCNETSERVICE\\Binn\\sqlagent.EXE -i PCNETSERVICE [?]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\\windows\\system32\\drivers\\l151x86.sys [2008-09-24 36864]
R3 cxbu0wdm;CardMan 3x21;c:\\windows\\system32\\drivers\\cxbu0wdm.sys [2009-06-24 114304]
S0 sptd;sptd;c:\\windows\\system32\\drivers\\sptd.sys [2008-09-28 685816]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\\windows\\system32\\drivers\\nmwcdnsu.sys [2010-01-29 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\\windows\\system32\\drivers\\nmwcdnsuc.sys [2010-01-29 8320]
.
Zawartość folderu \'Zaplanowane zadania\'
2010-03-09 c:\\windows\\Tasks\\User_Feed_Synchronization-{FA8F49C0-C4D4-46B6-B643-F3D43C669D1C}.job
- c:\\windows\\system32\\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.onet.pl/
IE: E&ksport do programu Microsoft Excel - c:\\progra~1\\MICROS~2\\OFFICE11\\EXCEL.EXE/3000
Trusted Zone: era.pl\\faktury
DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} - hxxp://10.0.0.250/webrec.cab
DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A41} - hxxps://www.pekaobiznes24.pl/sme/static/components/SignActivXPEKAO.cab
DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} - hxxps://www.bph.pl/pi/components/bph/SignActivX.cab
.
- - - - USUNIĘTO PUSTE WPISY - - - -
AddRemove-KB923789 - c:\\windows\\system32\\MacroMed\\Flash\\genuinst.exe
**************************************************************************
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki:
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > \'winlogon.exe\'(1052)
c:\\program files\\common files\\logishrd\\bluetooth\\LBTWlgn.dll
c:\\program files\\common files\\logishrd\\bluetooth\\LBTServ.dll
.
Czas ukończenia: 2010-03-10 08:48:06
ComboFix-quarantined-files.txt 2010-03-10 07:48
Przed: 9 096 638 464 bajtów wolnych
Po: 9 281 359 872 bajtów wolnych
Current=10 Default=10 Failed=9 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
- - End Of File - - E890A16E73F2A1923952EB595BA27692
|