ComboFix 09-02-11.02 - Isabell 2009-02-12 14:15:12.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.1023.602 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Isabell\Pulpit\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
FW: COMODO Firewall *enabled*
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA
.
((((((((((((((((((((((((( Pliki utworzone od 2009-01-12 do 2009-02-12 )))))))))))))))))))))))))))))))
.
2009-02-11 20:27 . 2009-02-11 20:27 <DIR> d-------- c:\documents and settings\Isabell\WINDOWS
2009-02-11 20:27 . 1999-03-23 09:12 299,520 --a------ c:\windows\uninst.exe
2009-02-09 12:54 . 2009-02-09 12:54 <DIR> d-------- c:\program files\mp3DirectCut
2009-02-07 19:28 . 2009-02-07 19:28 <DIR> d-------- c:\program files\Advanced Spyware Remover
2009-02-03 13:48 . 1999-12-17 10:13 86,016 --a------ c:\windows\unvise32.exe
2009-02-02 22:38 . 2009-02-02 22:38 <DIR> d-------- c:\documents and settings\Isabell\Dane aplikacji\InstallShield Installation Information
2009-01-29 22:41 . 2009-01-29 22:42 815 --a------ c:\windows\Informat.ini
2009-01-24 12:56 . 2009-01-24 12:56 <DIR> d-------- c:\program files\NCH Software
2009-01-24 12:55 . 2009-01-24 12:55 <DIR> d-------- c:\program files\NCH Swift Sound
2009-01-24 12:55 . 2009-01-24 12:55 <DIR> d-------- c:\documents and settings\Isabell\Dane aplikacji\NCH Swift Sound
2009-01-17 13:42 . 2009-01-22 10:23 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-01-17 13:39 . 2009-01-17 13:39 <DIR> d-------- c:\windows\system32\LogFiles
2009-01-17 13:39 . 2009-01-17 13:40 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-01-17 12:01 . 2004-09-10 19:15 86,094 --a------ c:\windows\system32\ImageDrive.cpl
2009-01-15 23:55 . 2009-02-06 15:36 69 --a------ c:\windows\NeroDigital.ini
2009-01-15 17:31 . 2009-01-15 17:31 0 --a------ c:\windows\cdplayer.ini
2009-01-15 16:25 . 2009-01-15 16:25 <DIR> d-------- c:\program files\Common Files\Ahead
2009-01-15 16:25 . 2009-01-15 16:25 <DIR> d-------- c:\program files\Ahead
2009-01-15 16:25 . 2004-07-26 17:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
2009-01-15 16:25 . 2004-07-26 17:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
2009-01-15 16:25 . 2004-07-26 17:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
2009-01-15 16:25 . 2004-07-26 17:16 262,144 --------- c:\windows\system32\ImagXR7.dll
2009-01-15 16:25 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
2009-01-15 16:25 . 2004-03-02 17:37 125,184 --------- c:\windows\system32\drivers\imagesrv.sys
2009-01-15 16:25 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2009-01-15 16:25 . 2004-03-02 17:37 5,504 --------- c:\windows\system32\drivers\imagedrv.sys
2009-01-15 01:10 . 2009-01-15 01:10 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\nView_Profiles
2009-01-15 01:09 . 2009-01-15 01:10 <DIR> d-------- c:\windows\system32\pl-pl
2009-01-15 01:02 . 2008-10-16 21:33 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-01-15 01:02 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-01-15 01:02 . 2007-03-08 06:11 1,036,288 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-15 01:02 . 2008-10-16 21:33 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-01-15 01:02 . 2008-10-16 21:33 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-01-15 01:02 . 2008-10-16 21:33 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-01-15 01:02 . 2008-10-16 21:33 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-01-15 01:02 . 2008-10-16 21:33 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-15 01:02 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-01-14 23:57 . 2009-01-14 23:57 <DIR> d-------- c:\windows\system32\oodag
2009-01-14 23:57 . 2009-01-14 23:57 0 --a------ c:\windows\oodcnt.INI
2009-01-12 22:30 . 2009-02-11 20:07 <DIR> d-------- c:\program files\Google
2009-01-12 21:22 . 2009-01-12 21:22 156 --a------ c:\windows\Twunk001.MTX
2009-01-12 21:22 . 2009-01-12 21:22 2 --a------ c:\windows\Twain001.Mtx
2009-01-12 21:22 . 2009-01-12 21:22 0 --a------ c:\windows\Twunk002.MTX
2009-01-12 19:20 . 2009-01-12 19:20 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Trymedia
2009-01-12 13:09 . 2009-01-12 13:09 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\SpeedBit
2009-01-12 13:08 . 2009-01-12 13:08 479,298 --------- c:\windows\system32\wbocx.ocx
2009-01-12 13:08 . 2009-01-12 13:08 172,032 --------- c:\windows\system32\AniGIF.ocx
2009-01-12 13:08 . 2009-01-12 13:08 50,688 --------- c:\windows\system32\wbhelp2.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 13:12 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\foobar2000
2009-02-12 13:10 507,936 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-02-12 13:10 4,912 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-02-12 12:22 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2009-02-11 23:07 4,386,848 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-11 23:07 38,496 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-11 22:47 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\uTorrent
2009-02-11 15:31 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\HPAppData
2009-02-08 20:09 --------- d-----w c:\documents and settings\LocalService\Dane aplikacji\SACore
2009-02-07 16:28 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-04 14:16 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-03 17:45 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 17:45 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-02 20:42 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2009-02-02 20:37 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-02 20:27 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\stamina
2009-02-01 13:44 20 ---h--w c:\documents and settings\All Users\Dane aplikacji\PKP_DLdu.DAT
2009-01-20 16:43 --------- d-----w c:\program files\uTorrent
2009-01-16 19:57 3 ----a-w c:\windows\Fonts\dxva_sig.txt
2009-01-15 11:14 --------- d-----w c:\program files\Easy CD-DA Extractor 12
2009-01-15 10:11 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Smart PC Solutions
2009-01-15 10:00 --------- d-----w c:\program files\CCleaner
2009-01-12 12:14 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-01-09 20:54 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Media Player Classic
2009-01-09 12:08 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\NCH Swift Sound
2009-01-09 12:06 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Easy CD-DA Extractor
2009-01-08 18:30 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\NVIDIA
2009-01-08 12:09 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Nikon
2009-01-08 10:14 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\HP
2009-01-08 10:14 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\HP
2009-01-07 22:35 --------- d-----w c:\program files\Lavalys
2009-01-07 21:25 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-01-07 21:24 --------- d-----w c:\program files\Microsoft Works
2009-01-07 20:41 --------- d-----w c:\program files\Common Files\Reallusion
2009-01-07 19:46 --------- d-----w c:\program files\PhotoScape
2009-01-07 18:12 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\ashampoo
2009-01-07 16:24 --------- d-----w c:\program files\VS Revo Group
2009-01-07 10:36 65,109 ----a-w c:\windows\BricoPackUninst.cmd
2009-01-07 10:36 6,118 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2009-01-07 10:36 219,648 ----a-w c:\windows\system32\uxtheme.dll
2009-01-07 08:51 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\DAEMON Tools Lite
2009-01-07 08:50 --------- d-----w c:\program files\DAEMON Tools Lite
2009-01-07 08:50 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\DAEMON Tools Pro
2009-01-07 08:50 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\DAEMON Tools
2009-01-07 08:50 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-01-06 23:29 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-01-06 18:23 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Notepad++
2009-01-06 00:01 --------- d-----w c:\program files\NAPI-PROJEKT
2009-01-05 14:10 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Last.fm
2009-01-05 14:09 --------- d-----w c:\program files\Last.fm
2009-01-05 14:07 --------- d-----w c:\program files\foobar2000
2009-01-05 13:58 --------- d-----w c:\program files\McAfee
2009-01-05 13:53 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Winamp
2009-01-05 11:24 --------- d-----w c:\program files\Foxit Software
2009-01-05 11:24 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Foxit
2009-01-05 11:23 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-05 11:22 --------- d-----w c:\program files\Java
2009-01-05 11:07 --------- d-----w c:\program files\Common Files\McAfee
2009-01-05 11:07 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\SiteAdvisor
2009-01-05 11:07 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\McAfee
2009-01-05 10:38 --------- d-----w c:\program files\WapSter
2009-01-05 01:38 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\FLEXnet
2009-01-05 01:36 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\BVRP Software
2009-01-05 01:31 --------- d-----w c:\program files\Motorola Phone Tools
2009-01-05 01:31 --------- d-----w c:\program files\Avanquest update
2009-01-05 01:30 24,192 ----a-w c:\documents and settings\Isabell\usbsermptxp.sys
2009-01-05 01:30 22,768 ----a-w c:\windows\system32\drivers\usbsermpt.sys
2009-01-05 01:30 22,768 ----a-w c:\documents and settings\Isabell\usbsermpt.sys
2009-01-05 01:27 --------- d-----w c:\program files\Common Files\Adobe
2009-01-05 01:27 --------- d-----w c:\program files\Bonjour
2009-01-05 01:19 --------- d-----w c:\program files\Common Files\Macrovision Shared
2009-01-05 01:12 --------- d-----w c:\program files\HP
2009-01-05 01:12 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\WEBREG
2009-01-05 01:11 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Hewlett-Packard
2009-01-05 01:08 --------- d-----w c:\program files\Hewlett-Packard
2009-01-05 01:08 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-01-05 01:08 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\HP Product Assistant
2009-01-05 01:07 --------- d-----w c:\program files\Common Files\HP
2009-01-05 00:55 --------- d-----w c:\program files\IZArc
2009-01-05 00:42 --------- d-----w c:\program files\Samsung
2009-01-05 00:40 --------- d-----w c:\program files\Nikon
2009-01-05 00:40 --------- d-----w c:\program files\Common Files\Nikon
2009-01-05 00:40 --------- d-----w c:\program files\Common Files\muvee Technologies
2009-01-05 00:40 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Nikon
2009-01-05 00:39 106,496 ----a-w c:\windows\system32\ATL71.DLL
2009-01-05 00:39 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Ultima_T15
2009-01-05 00:39 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\EnterNHelp
2009-01-05 00:38 --------- d-----w c:\program files\QuickTime
2009-01-05 00:38 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2009-01-05 00:30 31,504 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2009-01-05 00:30 147,192 ----a-w c:\windows\system32\guard32.dll
2009-01-05 00:30 101,776 ----a-w c:\windows\system32\drivers\cmdguard.sys
2009-01-05 00:26 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\comodo
2009-01-05 00:24 --------- d-----w c:\program files\COMODO
2009-01-05 00:24 --------- d-----w c:\documents and settings\Isabell\Dane aplikacji\Comodo
2009-01-05 00:22 --------- d-----w c:\program files\Winamp
2009-01-05 00:12 --------- d-----w c:\program files\Notepad++
2009-01-05 00:11 --------- d-----w c:\program files\ALLPlayer
2009-01-05 00:10 --------- d-----w c:\program files\K-Lite Codec Pack
2009-01-04 23:59 --------- d-----w c:\program files\Kaspersky Lab
2007-08-28 12:54 237,568 ----a-w c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-25 17:43 204,895 ----a-w c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 13:41 77,824 ----a-w c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-06-19 12:10 426,081 ----a-w c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 11:19 458,752 ----a-w c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 17:35 139,264 ----a-w c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 10:10 204,800 ----a-w c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 10:42 106,496 ----a-w c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 10:22 212,992 ----a-w c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 10:21 167,936 ----a-w c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-02 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-02 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-02 455168]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-01-05 1797880]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-01-05 1797880]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-05 136600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-04 206088]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\Isabell\Menu Start\Programy\Autostart\
Glassy Calendar by adni18.lnk - f:\for xp\Vista.Xp Gadgets\Glassy Calendar Gadget.exe [2009-01-04 588800]
Glassy-Time Gadget by adni18.lnk - f:\for xp\Vista.Xp Gadgets\Glassy-Time Gadget.exe [2009-01-04 652288]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-01-05 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-01-05 31504]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-01-05 206096]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
S2 gupdate1c98a3add011d06;Google Update Service (gupdate1c98a3add011d06);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Zawartość folderu 'Zaplanowane zadania'
2009-02-12 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe []
2009-02-04 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-02-03 12:04]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Isabell\Dane aplikacji\Mozilla\Firefox\Profiles\0pdo5ruy.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
FF - prefs.js: keyword.URL - about:neterror?e=query&u=
FF - component: c:\documents and settings\Isabell\Dane aplikacji\Mozilla\Firefox\Profiles\0pdo5ruy.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRLCT4Player.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-12 14:16:25
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-861567501-1390067357-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="9E8A191AE081891D5B8617969A8794FA40E99CD25F1B385D7D980994BF72A3BD11EA6DD23EB
8B65448135E58807D37791C148A64D3B2D29ED54A2B6A783A75C50EFC3FDFC5056C206E8B9A8D9542
DC27CC9D3A840D9F0655156DFD8EA61158E1801D184112B6569B1D1E6013E8C8CDC628A5F1093093D
60EB534146D208B2F86A72D749E50E35546FAFCBEE61E45087FD8CEE968F28702B90650EF17550111
0E989148C044E47E0000DDB0ABEBB33E5CDB3F4B4025B5732CAA7B0EC0C68E4BB4BAB1F91543D799F
EBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFE
BC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC7933A9C6AECB7A5D1407A2D97226D213B555D55
1B86D6BB85A822A3FCE7F2D8EF6F8E8072D1951262DDA4F715F5164E49F42802D175677B5301C8643
4830692AA2C1E45FC744436844793A6C063C206E34AFF4F6572927A0A61291E9C40699ABCC74F3187
803EBB23F00C210AF1E6E54F9BDDD47C51608F37168E09445A284622C8E34F4927FEAC9F08C2FA621
CFE7EC084ACD0F3943CC3B09D6ED774F1594B03848A7106CDA8103F4702CCD1F1D4825BAE2B610874
8C7192AC89518EBE4D58CAF8735D4DD2618CA2A30C678F346EE7EAE4873610C33F3C2545E9954A58B
FAFE92E927844668B71FB107756A6FFD618BC8733FEC27856C7FCAE99F5B8FF65A2926BF2C34859D1
21572610E3E63ED4576B00D39723D32733018F2B1313C0AEE3BF38DD6CC83B5F7D296604B6327B168
79CF756884B424EDC285B53B2CC51AD3FB490C1C0AA791DF150B5ACD999558B8E5D6BDB389F938E33
E26220FFAC7714D45B6A7D77EE08966A782D819760C674C9FB8ACE73D7B3F023BCA5A631AE3CDC085
1280480D20E7C9F1F3199365EE56D920AB3DB42EAEFD1AE70FB64FDFBEE1B6C073EB0F6FDCEC6C691
98D092323103CF1AA9CAFBD8A2DA104CC4352720052DE8A39F1B3B10ECA5698EF5A29429476753676
2FCFA30AF93067A43FCCCD54BA8A8E03CE1F36B32831A0BA5907A732DBA8A1918BF2EAAC8604787B1
D83436EA72F0B38F321304D204C33FE181B8CEB0A9DFB42FA587277667CB5790622F4001DE6D18005
EB2A62C29B178859BE803CBB402215FBA5EB71249EB0895334DAC40FEF4A49DA957E7C9134A964113
2639B2120035841E1DFA5BA140EDC972BC1F6E82C6DC28298DE2805525964E89AED89DD71A31EB2FA
A7A41DAA88E6935DC7D787A0C964BAD2517787D4A89EBF7CA6078B0C9C40E83F72813051EAE0C003E
2ACBD7882E4FA872D00F73DAFEEA5C5EC1DB4EB9AD733654354CA9E984649BA58BD52804D43E85CA0
DAAAB419F0E0C371545A32DC459404F0B8BCC986D60E0546D77DAC73BFE2DB2B28E3832589EA2CBBB
CEE20B72A439825CD46313C17A0C7"
.
Czas ukończenia: 2009-02-12 14:17:44
ComboFix-quarantined-files.txt 2009-02-12 13:17:42
ComboFix2.txt 2009-02-07 17:19:06
Przed: 3,189,678,080 bajtów wolnych
Po: 4,411,203,584 bajtów wolnych
279
Dziękuje z góry..



Temat jest zamknięty





