1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253.
254.
255.
256.
257.
258.
259.
260.
261.
262.
263.
264.
265.
266.
267.
268.
269.
270.
271.
272.
273.
274.
275.
276.
277.
278.
279.
280.
281.
282.
283.
284.
285.
286.
287.
288.
289.
290.
291.
292.
293.
294. | ComboFix 10-09-04.06 - Metal Up Your Ass 2010-09-05 23:45:31.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2047.1638 [GMT 2:00]
Uruchomiony z: c:\\documents and settings\\Metal Up Your Ass\\Moje dokumenty\\Downloads\\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Pliki utworzone od 2010-08-05 do 2010-09-05 )))))))))))))))))))))))))))))))
.
2010-09-02 21:51 . 2010-09-02 21:51 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\WinZip
2010-09-02 21:50 . 2010-09-02 21:57 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\WinZip
2010-09-02 13:14 . 2010-09-02 13:17 -------- d-----w- c:\\program files\\coolpro2
2010-09-02 12:45 . 2010-09-02 13:20 -------- d-----w- C:\\temp
2010-09-02 12:39 . 2007-01-22 06:49 344064 ----a-w- c:\\windows\\system32\\lxbkcoin.dll
2010-09-02 12:36 . 2006-11-30 11:34 413696 ----a-w- c:\\windows\\system32\\lxbkutil.dll
2010-09-02 12:35 . 2010-09-02 12:35 -------- d-----w- C:\\drivers
2010-09-02 11:06 . 2010-09-02 11:06 61440 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Sun\\Java\\Deployment\\SystemCache\\6.0\\42\\4488892a-7b46fe5b-n\\decora-sse.dll
2010-09-02 11:06 . 2010-09-02 11:06 503808 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Sun\\Java\\Deployment\\SystemCache\\6.0\\4\\7ec4bf04-57744457-n\\msvcp71.dll
2010-09-02 11:06 . 2010-09-02 11:06 499712 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Sun\\Java\\Deployment\\SystemCache\\6.0\\4\\7ec4bf04-57744457-n\\jmc.dll
2010-09-02 11:06 . 2010-09-02 11:06 12800 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Sun\\Java\\Deployment\\SystemCache\\6.0\\42\\4488892a-7b46fe5b-n\\decora-d3d.dll
2010-09-02 11:06 . 2010-09-02 11:06 348160 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Sun\\Java\\Deployment\\SystemCache\\6.0\\4\\7ec4bf04-57744457-n\\msvcr71.dll
2010-09-02 11:06 . 2010-09-02 11:06 -------- d-----w- c:\\program files\\Common Files\\Java
2010-09-02 11:06 . 2010-09-02 11:05 411368 ----a-w- c:\\windows\\system32\\deployJava1.dll
2010-09-02 11:05 . 2010-09-02 11:05 -------- d-----w- c:\\program files\\Java
2010-09-02 11:04 . 2010-09-03 19:46 -------- d-----w- c:\\program files\\JDownloader
2010-09-02 08:39 . 2010-09-02 08:39 499712 ----a-w- c:\\windows\\system32\\msvcp71.dll
2010-09-02 08:39 . 2010-09-02 08:39 348160 ----a-w- c:\\windows\\system32\\msvcr71.dll
2010-09-02 08:32 . 2010-09-02 08:32 0 ----a-w- c:\\windows\\nsreg.dat
2010-09-02 08:32 . 2010-09-02 08:32 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Mozilla
2010-09-01 11:17 . 2010-09-01 21:24 -------- d-----w- c:\\program files\\AudioRetoucher
2010-09-01 10:55 . 2010-09-01 10:55 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Easy CD-DA Extractor
2010-09-01 10:55 . 2010-09-01 10:55 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\TEMP
2010-09-01 10:55 . 2010-09-01 10:55 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\Easy CD-DA Extractor
2010-09-01 10:55 . 2010-09-01 10:56 -------- d-----w- c:\\program files\\Easy CD-DA Extractor 2010
2010-08-31 20:32 . 2010-08-31 20:32 26641904 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\rp\\RealPlayerSPGold.exe
2010-08-31 20:32 . 2010-08-31 20:32 220272 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\gtb\\GOOGLE_TOOLBAR\\GoogleToolbarInstaller.exe
2010-08-31 20:32 . 2010-08-31 20:32 149000 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\chr_helper\\LaunchHelper.exe
2010-08-31 20:31 . 2010-08-31 20:31 13407072 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\chr\\ChromeInstaller.exe
2010-08-31 20:31 . 2010-08-31 20:31 79368 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\RUP\\vista.exe
2010-08-31 20:31 . 2010-08-31 20:31 73344 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\RUP\\inst_config\\gtapi_v6.dll
2010-08-31 20:31 . 2010-08-31 20:31 64000 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\RUP\\inst_config\\gcapi_dll.dll
2010-08-31 20:31 . 2010-08-31 20:31 52288 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\RUP\\inst_config\\gtapi.dll
2010-08-31 20:31 . 2010-08-31 20:31 122880 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\RUP\\inst_config\\compat.dll
2010-08-31 08:12 . 2010-09-02 08:30 452104 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Real\\Update\\setup3.12\\setup.exe
2010-08-31 08:06 . 2010-09-02 08:40 -------- d-----w- c:\\program files\\Common Files\\Real
2010-08-31 08:06 . 2010-09-02 08:40 -------- d-----w- c:\\program files\\Real
2010-08-30 12:57 . 2006-09-28 12:10 11648 ----a-w- c:\\windows\\system32\\drivers\\ggsemc.sys
2010-08-30 12:56 . 2010-08-30 12:56 -------- d-----w- C:\\USBFlashDriver
2010-08-30 12:54 . 2010-08-30 12:54 -------- d-----w- c:\\program files\\Sony Ericsson
2010-08-30 07:08 . 2010-08-30 07:08 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Ahead
2010-08-30 06:56 . 2005-09-01 09:03 5888 ------w- c:\\windows\\system32\\drivers\\imagedrv.sys
2010-08-30 06:56 . 2005-09-01 09:03 127488 ------w- c:\\windows\\system32\\drivers\\imagesrv.sys
2010-08-30 06:55 . 2004-07-09 06:43 364544 ------w- c:\\windows\\system32\\TwnLib4.dll
2010-08-30 06:55 . 2000-06-26 08:45 106496 ----a-w- c:\\windows\\system32\\TwnLib20.dll
2010-08-30 06:55 . 2006-01-12 13:40 155648 ----a-w- c:\\windows\\system32\\NeroCheck.exe
2010-08-30 06:55 . 2004-07-26 14:16 476320 ------w- c:\\windows\\system32\\ImagXpr7.dll
2010-08-30 06:55 . 2004-07-26 14:16 471040 ------w- c:\\windows\\system32\\ImagXRA7.dll
2010-08-30 06:55 . 2004-07-26 14:16 262144 ------w- c:\\windows\\system32\\ImagXR7.dll
2010-08-30 06:55 . 2004-07-26 14:16 1568768 ------w- c:\\windows\\system32\\ImagX7.dll
2010-08-30 06:55 . 2010-08-30 06:55 -------- d-----w- c:\\program files\\Common Files\\Ahead
2010-08-26 10:49 . 2010-09-03 13:55 24 ----a-w- c:\\windows\\system32\\DVCStateBkp-{00000004-00000000-00000001-00001102-00000002-80641102}.dat
2010-08-26 10:49 . 2010-09-03 13:55 24 ----a-w- c:\\windows\\system32\\DVCState-{00000004-00000000-00000001-00001102-00000002-80641102}.dat
2010-08-26 10:36 . 2010-08-26 10:46 -------- d-----w- c:\\windows\\ie8updates
2010-08-26 10:29 . 2000-05-10 23:00 90112 ------w- c:\\windows\\Updreg.EXE
2010-08-26 10:29 . 1998-06-05 00:00 84992 ------w- c:\\windows\\system32\\SFCVRT32.DLL
2010-08-26 10:29 . 1996-05-23 00:24 24976 ------w- c:\\windows\\CTRES.DLL
2010-08-26 10:29 . 1994-12-05 01:11 53552 ------w- c:\\windows\\CTCCW.DLL
2010-08-26 10:29 . 2010-08-26 10:29 -------- d-----w- c:\\windows\\system32\\Defaults
2010-08-26 10:29 . 1998-10-20 14:05 54784 ------w- c:\\windows\\system32\\INETWH32.DLL
2010-08-26 10:29 . 1998-01-07 23:00 1048576 ------w- c:\\windows\\system32\\SFMAN.DAT
2010-08-26 10:29 . 1995-08-30 00:02 82432 ------w- c:\\windows\\system32\\CTWFLT32.DLL
2010-08-26 10:29 . 1995-07-13 00:01 26768 ------w- c:\\windows\\system32\\CTL3D.DLL
2010-08-26 10:29 . 1995-01-13 12:10 149504 ------w- c:\\windows\\system32\\MFCANS32.DLL
2010-08-26 10:29 . 1995-01-13 12:10 108032 ------w- c:\\windows\\system32\\MFCUIA32.DLL
2010-08-26 10:26 . 1999-12-16 23:00 6752 ------w- c:\\windows\\system32\\PFMODNT.SYS
2010-08-26 09:51 . 2010-08-26 09:51 -------- d-----w- c:\\program files\\ASIO4ALL v2
2010-08-26 06:30 . 2010-02-12 10:03 293376 ------w- c:\\windows\\system32\\browserchoice.exe
2010-08-26 06:30 . 2008-06-14 17:36 273024 -c----w- c:\\windows\\system32\\dllcache\\bthport.sys
2010-08-26 06:30 . 2008-06-14 17:36 273024 ------w- c:\\windows\\system32\\drivers\\bthport.sys
2010-08-26 06:29 . 2010-06-24 12:26 599040 -c----w- c:\\windows\\system32\\dllcache\\msfeeds.dll
2010-08-26 06:29 . 2010-06-24 12:26 55296 -c----w- c:\\windows\\system32\\dllcache\\msfeedsbs.dll
2010-08-26 06:29 . 2010-06-24 12:26 247808 -c----w- c:\\windows\\system32\\dllcache\\ieproxy.dll
2010-08-26 06:29 . 2010-06-24 12:26 1986560 -c----w- c:\\windows\\system32\\dllcache\\iertutil.dll
2010-08-26 06:29 . 2010-06-24 12:26 12800 -c----w- c:\\windows\\system32\\dllcache\\xpshims.dll
2010-08-26 06:29 . 2010-06-24 12:26 743424 -c----w- c:\\windows\\system32\\dllcache\\iedvtool.dll
2010-08-26 06:29 . 2010-04-28 18:15 2191232 -c----w- c:\\windows\\system32\\dllcache\\ntoskrnl.exe
2010-08-26 06:29 . 2010-04-28 05:45 2147840 -c----w- c:\\windows\\system32\\dllcache\\ntkrnlmp.exe
2010-08-26 06:29 . 2010-04-28 05:45 2068096 -c----w- c:\\windows\\system32\\dllcache\\ntkrnlpa.exe
2010-08-26 06:29 . 2010-04-28 05:45 2025984 -c----w- c:\\windows\\system32\\dllcache\\ntkrpamp.exe
2010-08-26 06:28 . 2010-02-24 13:11 455680 -c----w- c:\\windows\\system32\\dllcache\\mrxsmb.sys
2010-08-25 22:45 . 2010-08-26 20:24 -------- d--h--w- c:\\windows\\$hf_mig$
2010-08-25 05:21 . 2010-08-25 05:22 -------- d-----w- c:\\program files\\The KMPlayer
2010-08-24 19:58 . 2010-08-24 19:58 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\GHISLER
2010-08-24 19:56 . 2010-08-24 19:58 -------- d-----w- c:\\program files\\totalcmd
2010-08-24 19:56 . 2010-08-24 19:56 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\GHISLER
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\UC.PIF
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\RAR.PIF
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\PKZIP.PIF
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\PKUNZIP.PIF
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\NOCLOSE.PIF
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\LHA.PIF
2010-08-24 19:56 . 2010-07-07 05:55 545 ----a-w- c:\\windows\\ARJ.PIF
2010-08-24 11:07 . 2010-08-24 11:07 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Media Player Classic
2010-08-24 10:48 . 2010-08-24 10:48 -------- d-----w- c:\\program files\\IrfanView
2010-08-23 22:09 . 2010-08-24 12:50 -------- d-----w- c:\\program files\\Max Payne
2010-08-23 18:16 . 2010-08-23 18:16 -------- d-sh--w- c:\\documents and settings\\LocalService\\IETldCache
2010-08-23 14:15 . 2010-08-23 14:15 -------- d-----w- c:\\program files\\Common Files\\Adobe
2010-08-23 14:14 . 2010-08-23 14:17 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Adobe
2010-08-23 13:44 . 2007-07-03 15:00 9256 ----a-w- c:\\windows\\system32\\drivers\\sscdwhnt.sys
2010-08-23 13:44 . 2007-07-03 15:00 9256 ----a-w- c:\\windows\\system32\\drivers\\sscdwh.sys
2010-08-23 13:44 . 2007-07-03 14:58 106792 ----a-w- c:\\windows\\system32\\drivers\\sscdmdm.sys
2010-08-23 13:44 . 2007-07-03 14:57 11944 ----a-w- c:\\windows\\system32\\drivers\\sscdmdfl.sys
2010-08-23 13:44 . 2007-07-03 14:56 9256 ----a-w- c:\\windows\\system32\\drivers\\sscdcmnt.sys
2010-08-23 13:44 . 2007-07-03 14:56 9256 ----a-w- c:\\windows\\system32\\drivers\\sscdcm.sys
2010-08-23 13:44 . 2007-07-03 14:54 80552 ----a-w- c:\\windows\\system32\\drivers\\sscdbus.sys
2010-08-23 13:44 . 2010-08-23 13:44 -------- d-----w- c:\\windows\\system32\\Samsung_USB_Drivers
2010-08-23 13:44 . 2010-08-23 13:44 -------- d-----w- c:\\program files\\Samsung
2010-08-23 13:05 . 2008-04-13 22:15 26368 -c--a-w- c:\\windows\\system32\\dllcache\\usbstor.sys
2010-08-23 12:48 . 2006-10-26 17:56 33104 ----a-w- c:\\windows\\system32\\Spool\\prtprocs\\w32x86\\msonpppr.dll
2010-08-23 12:48 . 2006-10-26 17:56 32592 ----a-w- c:\\windows\\system32\\msonpmon.dll
2010-08-23 12:47 . 2010-08-23 12:47 -------- d-----w- c:\\program files\\Microsoft Works
2010-08-23 12:47 . 2010-08-23 12:47 -------- d-----w- c:\\program files\\MSBuild
2010-08-23 12:43 . 2010-08-23 12:46 -------- d-----w- c:\\windows\\SHELLNEW
2010-08-23 12:43 . 2010-08-23 12:43 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Microsoft Help
2010-08-23 12:41 . 2010-08-23 12:48 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\Microsoft Help
2010-08-23 12:40 . 2010-08-23 12:40 -------- d-----r- C:\\MSOCache
2010-08-23 10:41 . 2010-08-23 10:41 -------- d-----w- c:\\program files\\Guitar Pro 5
2010-08-23 10:04 . 2010-08-23 10:04 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\CyberLink
2010-08-23 10:03 . 2010-08-23 10:03 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\CyberLink
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-05 21:06 . 2010-08-23 08:28 664 ----a-w- c:\\windows\\system32\\d3d9caps.dat
2010-09-05 20:36 . 2010-08-23 09:00 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\uTorrent
2010-09-02 12:39 . 2010-09-02 12:36 -------- d-----w- c:\\program files\\Lexmark X1100 Series
2010-09-02 08:40 . 2010-09-02 08:40 49152 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\Firefox\\Ext\\Components\\nprpffbrowserrecordext.dll
2010-09-02 08:40 . 2010-09-02 08:40 45056 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\ThinShims\\rpnpshimwmp.dll
2010-09-02 08:40 . 2010-09-02 08:40 45056 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\ThinShims\\rpnpshimswf.dll
2010-09-02 08:40 . 2010-09-02 08:40 45056 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\ThinShims\\rpnpshimrp.dll
2010-09-02 08:40 . 2010-09-02 08:40 45056 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\ThinShims\\rpnpshimqt.dll
2010-09-02 08:40 . 2010-09-02 08:40 40960 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\Chrome\\Hook\\rpchromebrowserrecordhelper.dll
2010-09-02 08:40 . 2010-09-02 08:40 308808 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\Common\\rpmainbrowserrecordplugin.dll
2010-09-02 08:40 . 2010-09-02 08:40 14848 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\MozillaPlugins\\nprphtml5videoshim.dll
2010-09-02 08:40 . 2010-09-02 08:40 341600 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\IE\\rpbrowserrecordplugin.dll
2010-09-02 08:40 . 2010-09-02 08:40 -------- d-----w- c:\\program files\\Common Files\\xing shared
2010-08-30 20:32 . 2010-08-23 09:01 -------- d-----w- c:\\program files\\uTorrent
2010-08-30 06:55 . 2010-08-23 09:53 -------- d-----w- c:\\program files\\Ahead
2010-08-27 08:02 . 2008-04-15 12:00 49712 ----a-w- c:\\windows\\system32\\perfc015.dat
2010-08-27 08:02 . 2008-04-15 12:00 355830 ----a-w- c:\\windows\\system32\\perfh015.dat
2010-08-26 10:28 . 2010-08-23 08:22 -------- d--h--w- c:\\program files\\InstallShield Installation Information
2010-08-26 10:28 . 2010-08-26 10:26 -------- d-----w- c:\\program files\\Creative
2010-08-24 22:55 . 2010-08-23 09:31 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Gadu-Gadu 10
2010-08-24 11:23 . 2010-08-23 08:47 70040 ----a-w- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\GDIPFONTCACHEV1.DAT
2010-08-23 10:15 . 2010-08-23 09:09 -------- d-----w- c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Winamp
2010-08-23 09:59 . 2010-08-23 09:59 -------- d-----w- c:\\program files\\CyberLink
2010-08-23 09:59 . 2010-08-23 09:59 -------- d-----w- c:\\program files\\Common Files\\InstallShield
2010-08-23 09:29 . 2010-08-23 09:29 -------- d-----w- c:\\documents and settings\\All Users\\Dane aplikacji\\Gadu-Gadu 10
2010-08-23 09:29 . 2010-08-23 09:29 -------- d-----w- c:\\program files\\Gadu-Gadu 10
2010-08-23 09:13 . 2010-08-23 09:09 -------- d-----w- c:\\program files\\Winamp
2010-08-23 09:10 . 2010-08-23 09:10 -------- d-----w- c:\\program files\\Winamp Detect
2010-07-21 23:23 . 2010-07-21 23:23 397312 ----a-w- c:\\documents and settings\\All Users\\Dane aplikacji\\Gadu-Gadu 10\\_userdata\\ggbho.3.dll
2010-06-30 12:33 . 2008-04-15 12:00 149504 ----a-w- c:\\windows\\system32\\schannel.dll
2010-06-24 12:26 . 2008-04-15 12:00 916480 ----a-w- c:\\windows\\system32\\wininet.dll
2010-06-24 09:02 . 2008-04-15 12:00 1852160 ----a-w- c:\\windows\\system32\\win32k.sys
2010-06-21 15:27 . 2008-04-15 12:00 354304 ----a-w- c:\\windows\\system32\\drivers\\srv.sys
2010-06-17 14:03 . 2008-04-15 12:00 80384 ----a-w- c:\\windows\\system32\\iccvid.dll
2010-06-14 14:31 . 2010-08-23 07:52 744448 ----a-w- c:\\windows\\pchealth\\helpctr\\binaries\\helpsvc.exe
2010-06-14 07:43 . 2008-04-15 12:00 1172480 ----a-w- c:\\windows\\system32\\msxml3.dll
2010-06-08 16:10 . 2010-08-23 09:02 790528 ----a-w- c:\\windows\\system32\\xvidcore.dll
2010-06-08 16:10 . 2010-08-23 09:02 134144 ----a-w- c:\\windows\\system32\\xvidvfw.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\explorer\\shelliconoverlayidentifiers\\snxPluginsShell]
@=\"{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}\"
[HKEY_CLASSES_ROOT\\CLSID\\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-05-06 21:02 151648 ----a-w- c:\\program files\\Alwil Software\\Avast5\\snxPlugins.dll
[HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
\"Google Update\"=\"c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Google\\Update\\GoogleUpdate.exe\" [2010-08-23 136176]
\"uTorrent\"=\"c:\\program files\\uTorrent\\uTorrent.exe\" [2010-08-29 328568]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
\"NvCplDaemon\"=\"c:\\windows\\system32\\NvCpl.dll\" [2008-07-26 13570048]
\"nwiz\"=\"nwiz.exe\" [2008-07-26 1657376]
\"NvMediaCenter\"=\"c:\\windows\\system32\\NvMcTray.dll\" [2008-07-26 86016]
\"RemoteControl\"=\"c:\\program files\\CyberLink\\PowerDVD\\PDVDServ.exe\" [2004-11-02 32768]
\"GrooveMonitor\"=\"c:\\program files\\Microsoft Office\\Office12\\GrooveMonitor.exe\" [2006-10-26 31016]
\"Adobe Reader Speed Launcher\"=\"c:\\program files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\" [2010-06-20 35760]
\"Adobe ARM\"=\"c:\\program files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\" [2010-06-09 976832]
\"WINDVDPatch\"=\"CTHELPER.EXE\" [2002-02-07 40960]
\"UpdReg\"=\"c:\\windows\\UpdReg.EXE\" [2000-05-10 90112]
\"Jet Detection\"=\"c:\\program files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\" [2001-10-03 28672]
\"NeroFilterCheck\"=\"c:\\windows\\system32\\NeroCheck.exe\" [2006-01-12 155648]
\"TkBellExe\"=\"c:\\program files\\Common Files\\Real\\Update_OB\\realsched.exe\" [2010-09-02 202256]
\"SunJavaUpdateSched\"=\"c:\\program files\\Common Files\\Java\\Java Update\\jusched.exe\" [2010-02-18 248040]
[HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
\"CTFMON.EXE\"=\"c:\\windows\\system32\\CTFMON.EXE\" [2008-04-15 15360]
[HKLM\\~\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile\\AuthorizedApplications\\List]
\"%windir%\\\\Network Diagnostic\\\\xpnetdiag.exe\"=
\"%windir%\\\\system32\\\\sessmgr.exe\"=
\"d:\\\\eMule\\\\emule.exe\"=
\"c:\\\\Program Files\\\\uTorrent\\\\uTorrent.exe\"=
\"c:\\\\Program Files\\\\Gadu-Gadu 10\\\\gg.exe\"=
\"c:\\\\Program Files\\\\Microsoft Office\\\\Office12\\\\OUTLOOK.EXE\"=
\"c:\\\\Program Files\\\\Microsoft Office\\\\Office12\\\\GROOVE.EXE\"=
\"c:\\\\Program Files\\\\Microsoft Office\\\\Office12\\\\ONENOTE.EXE\"=
\"c:\\\\Program Files\\\\Java\\\\jre6\\\\bin\\\\javaw.exe\"=
\"c:\\\\WINDOWS\\\\system32\\\\lxbkcoms.exe\"=
S1 aswSnx;aswSnx;c:\\windows\\system32\\drivers\\aswSnx.sys [2010-08-23 307280]
S1 aswSP;aswSP;c:\\windows\\system32\\drivers\\aswSP.sys [2010-08-23 164048]
S2 aswFsBlk;aswFsBlk;c:\\windows\\system32\\drivers\\aswFsBlk.sys [2010-08-23 19024]
S2 lxbk_device;lxbk_device;c:\\windows\\system32\\lxbkcoms.exe -service --> c:\\windows\\system32\\lxbkcoms.exe -service [?]
.
Zawartość folderu \'Zaplanowane zadania\'
2010-09-03 c:\\windows\\Tasks\\GoogleUpdateTaskUserS-1-5-21-606747145-796845957-1801674531-1004Core.job
- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Google\\Update\\GoogleUpdate.exe [2010-08-23 08:57]
2010-09-03 c:\\windows\\Tasks\\GoogleUpdateTaskUserS-1-5-21-606747145-796845957-1801674531-1004UA.job
- c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Google\\Update\\GoogleUpdate.exe [2010-08-23 08:57]
2010-09-05 c:\\windows\\Tasks\\RealUpgradeLogonTaskS-1-5-21-606747145-796845957-1801674531-1004.job
- c:\\program files\\Real\\RealUpgrade\\realupgrade.exe [2010-06-03 01:02]
2010-09-03 c:\\windows\\Tasks\\RealUpgradeScheduledTaskS-1-5-21-606747145-796845957-1801674531-1004.job
- c:\\program files\\Real\\RealUpgrade\\realupgrade.exe [2010-06-03 01:02]
.
.
------- Skan uzupełniający -------
.
IE: E&ksportuj do programu Microsoft Excel - c:\\progra~1\\MICROS~2\\Office12\\EXCEL.EXE/3000
TCP: {B914960C-0FC8-4CBA-BD4C-669DA7313B35} = 217.144.192.2,217.144.192.33
FF - ProfilePath - c:\\documents and settings\\Metal Up Your Ass\\Dane aplikacji\\Mozilla\\Firefox\\Profiles\\ek9t5q89.default\\
FF - component: c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\Firefox\\Ext\\components\\nprpffbrowserrecordext.dll
FF - plugin: c:\\documents and settings\\All Users\\Dane aplikacji\\Real\\RealPlayer\\BrowserRecordPlugin\\MozillaPlugins\\nprphtml5videoshim.dll
FF - plugin: c:\\documents and settings\\Metal Up Your Ass\\Ustawienia lokalne\\Dane aplikacji\\Google\\Update\\1.2.183.29\\npGoogleOneClick8.dll
FF - plugin: c:\\program files\\Java\\jre6\\bin\\new_plugin\\npdeployJava1.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
c:\\program files\\Mozilla Firefox\\greprefs\\all.js - pref(\"network.IDN.whitelist.xn--mgbaam7a8h\", true);
c:\\program files\\Mozilla Firefox\\greprefs\\all.js - pref(\"network.IDN.whitelist.xn--mgberp4a5d4ar\", true);
c:\\program files\\Mozilla Firefox\\defaults\\pref\\firefox.js - pref(\"dom.ipc.plugins.enabled\", false);
.
**************************************************************************
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki:
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > \'explorer.exe\'(220)
c:\\windows\\system32\\WININET.dll
c:\\program files\\Common Files\\Adobe\\Acrobat\\ActiveX\\PDFShell.dll
c:\\program files\\Common Files\\Adobe\\Acrobat\\ActiveX\\PDFShell.POL
c:\\program files\\Microsoft Office\\Office12\\1045\\GrooveIntlResource.dll
c:\\windows\\system32\\nvcpl.dll
c:\\windows\\system32\\NVRSPL.DLL
c:\\windows\\system32\\nvshell.dll
.
Czas ukończenia: 2010-09-05 23:49:49
ComboFix-quarantined-files.txt 2010-09-05 21:49
Przed: 18 246 602 752 bajtów wolnych
Po: 18 297 454 592 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\\WINDOWS
[operating systems]
c:\\cmdcons\\BOOTSECT.DAT=\"Microsoft Windows Recovery Console\" /cmdcons
UnsupportedDebug=\"do not select this\" /debug
multi(0)disk(0)rdisk(0)partition(1)\\WINDOWS=\"Microsoft Windows XP Home Edition\" /noexecute=optin /fastdetect
- - End Of File - - B905360D6BF0E7F4E460CE59D1433E7F
|