Oto raport:
ComboFix 10-05-22.01 - Kris 22.05.2010 21:52:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.48.1045.18.2046.1111 [GMT 2:00]
Uruchomiony z: c:\users\Kris\Downloads\ComboFix.exe
* Utworzono nowy punkt przywracania
* Rezydentny antywirus jest aktywny
.
((((((((((((((((((((((((((((((((((((((( Usuniêto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\Real\Update_OB\lang\rpsearch_it.dll
c:\program files\Real\RealPlayer\converter\rnuninst_it.dll
c:\program files\Real\RealPlayer\lang\cdplay_it.dll
c:\program files\Real\RealPlayer\lang\dbcomp_it.dll
c:\program files\Real\RealPlayer\lang\embed_it.dll
c:\program files\Real\RealPlayer\lang\gemctl_it.dll
c:\program files\Real\RealPlayer\lang\mydevices_it.dll
c:\program files\Real\RealPlayer\lang\pngui_it.dll
c:\program files\Real\RealPlayer\lang\rjctl_it.dll
c:\program files\Real\RealPlayer\lang\rjdlg_it.dll
c:\program files\Real\RealPlayer\lang\rjeq_it.dll
c:\program files\Real\RealPlayer\lang\rjfade_it.dll
c:\program files\Real\RealPlayer\lang\rjmisc_it.dll
c:\program files\Real\RealPlayer\lang\rjprog_it.dll
c:\program files\Real\RealPlayer\lang\rjres_it.dll
c:\program files\Real\RealPlayer\lang\rjskin_it.dll
c:\program files\Real\RealPlayer\lang\rjviz_it.dll
c:\program files\Real\RealPlayer\lang\rjwma_it.dll
c:\program files\Real\RealPlayer\lang\rnuninst_it.dll
c:\program files\Real\RealPlayer\lang\rpapp_it.dll
c:\program files\Real\RealPlayer\lang\rpbgr_it.dll
c:\program files\Real\RealPlayer\lang\rpbrp_it.dll
c:\program files\Real\RealPlayer\lang\rpclsvc_it.dll
c:\program files\Real\RealPlayer\lang\rpclutil_it.dll
c:\program files\Real\RealPlayer\lang\rpdemand_it.dll
c:\program files\Real\RealPlayer\lang\rpdsplyr_it.dll
c:\program files\Real\RealPlayer\lang\rpext_it.dll
c:\program files\Real\RealPlayer\lang\rpgutil_it.dll
c:\program files\Real\RealPlayer\lang\rpmnpane_it.dll
c:\program files\Real\RealPlayer\lang\rpplylst_it.dll
c:\program files\Real\RealPlayer\lang\rpsearch_it.dll
c:\program files\Real\RealPlayer\lang\rpwebctl_it.dll
c:\program files\Real\RealPlayer\lang\systray_it.dll
c:\program files\Real\RealPlayer\lang\tcdinfo_it.dll
c:\program files\Real\RealPlayer\lang\tclsvc_it.dll
c:\program files\Real\RealPlayer\lang\tdwnmgr_it.dll
c:\program files\Real\RealPlayer\lang\tearm_it.dll
c:\program files\Real\RealPlayer\lang\teasdk_it.dll
c:\program files\Real\RealPlayer\lang\tmdedit_it.dll
c:\program files\Real\RealPlayer\lang\tmp3_it.dll
c:\program files\Real\RealPlayer\lang\twave_it.dll
c:\program files\Real\RealPlayer\lang\upgrdhlp_it.dll
c:\program files\Real\RealPlayer\lang\upgrdlib_it.dll
C:\restore
c:\restore\k-1-3542-4232123213-7676767-8888886\Desktop.ini
c:\users\Kris\AppData\Local\xhyiarc.dat
c:\users\Kris\AppData\Local\xhyiarc.exe
c:\users\Kris\AppData\Local\xhyiarc_nav.dat
c:\users\Kris\AppData\Local\xhyiarc_navps.dat
c:\users\Kris\AppData\Roaming\Microsoft\AdjMmsVista.dll
c:\windows\system32\AbaleZip.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2010-04-22 do 2010-05-22 )))))))))))))))))))))))))))))))
.
2010-05-22 19:48 . 2010-05-22 19:49 -------- d-----w- C:\32788R22FWJFW
2010-05-21 13:45 . 2010-05-21 13:45 2443 ----a-w- c:\users\Kris\AppData\Local\dywtif.exe
2010-05-18 18:21 . 2010-05-18 18:21 -------- d-----w- c:\users\Kris\AppData\Roaming\ATI
2010-05-18 18:21 . 2010-05-18 18:21 -------- d-----w- c:\users\Kris\AppData\Local\ATI
2010-05-18 18:21 . 2010-05-18 18:21 -------- d-----w- c:\programdata\ATI
2010-05-18 18:19 . 2010-05-18 18:19 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-05-18 18:17 . 2010-05-18 18:19 -------- d-----w- c:\program files\ATI Technologies
2010-05-18 18:17 . 2010-05-18 18:19 -------- d-----w- c:\program files\ATI
2010-05-16 09:42 . 2010-05-16 09:42 -------- d-----w- C:\New folder (2)
2010-05-10 17:41 . 2010-05-10 17:41 -------- d-----w- c:\users\Kris\AppData\Local\ESET
2010-05-10 16:45 . 2010-05-10 16:45 -------- d-----w- c:\program files\ESET
2010-05-10 09:59 . 2010-05-10 11:58 -------- d-----w- c:\programdata\OpenFM
2010-05-10 09:59 . 2010-05-10 09:59 -------- d-----w- c:\users\Kris\AppData\Roaming\OpenFM
2010-05-09 12:03 . 2010-05-09 12:03 3288 ------w- C:\bootsqm.dat
2010-05-09 10:05 . 2010-05-09 10:05 -------- d-----w- c:\users\Kris\AppData\Roaming\Win7codecs
2010-05-09 10:05 . 2010-05-09 10:05 -------- d-----w- c:\program files\Win7codecs
2010-05-09 10:04 . 2010-05-09 12:07 -------- d-----w- c:\programdata\Win7codecs
2010-05-09 06:03 . 2010-05-09 17:29 -------- d-----w- c:\program files\GameSpy Arcade
2010-05-09 06:03 . 2010-05-09 06:03 0 ----a-w- c:\windows\PowerReg.dat
2010-05-09 06:01 . 2010-05-09 06:01 -------- d-----w- c:\program files\Infogrames Interactive
2010-05-05 12:22 . 2010-05-05 12:22 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-05-04 16:01 . 2010-05-04 16:01 -------- d-----w- c:\users\Kris\AppData\Roaming\Leadertech
2010-05-02 18:51 . 2010-05-02 18:51 -------- d-----w- c:\program files\SopCast
2010-04-30 15:25 . 2010-05-10 12:22 -------- d-----w- C:\BDS
2010-04-30 14:12 . 2010-04-30 14:12 -------- d-----w- c:\program files\Common Files\Skype
2010-04-27 15:06 . 2010-04-27 15:06 -------- d-----w- c:\users\Kris\AppData\Roaming\widestream
2010-04-27 15:06 . 2010-04-27 15:06 -------- d-----w- c:\program files\Widestream6
2010-04-26 19:20 . 2010-04-26 19:20 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-04-26 19:20 . 2010-04-26 19:20 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-04-26 19:20 . 2010-04-26 19:20 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-04-26 19:20 . 2010-04-26 19:20 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-04-26 19:20 . 2010-04-26 19:20 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-04-26 19:20 . 2010-04-26 19:20 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-04-26 19:20 . 2010-04-26 19:20 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-04-26 19:20 . 2010-04-26 19:20 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-04-26 19:20 . 2010-04-26 19:20 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-04-26 19:20 . 2010-04-26 19:20 -------- d-----w- c:\program files\Common Files\xing shared
2010-04-25 12:17 . 2010-05-22 19:45 89 ----a-w- c:\users\Kris\AppData\Local\spcimrd.bat
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-22 19:49 . 2010-01-31 10:39 0 ----a-w- c:\windows\system32\Access.dat
2010-05-22 11:36 . 2009-11-08 17:12 -------- d-----w- c:\users\Kris\AppData\Roaming\Skype
2010-05-22 11:35 . 2009-11-08 17:15 -------- d-----w- c:\users\Kris\AppData\Roaming\skypePM
2010-05-17 17:52 . 2010-01-30 20:09 -------- d-----w- c:\programdata\Tunngle
2010-05-17 17:52 . 2010-01-30 20:09 -------- d-----w- c:\users\Kris\AppData\Roaming\Tunngle
2010-05-16 18:11 . 2010-01-29 16:06 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-05-16 13:55 . 2010-03-27 17:23 -------- d-----w- c:\users\Kris\AppData\Roaming\OfferBox
2010-05-16 09:49 . 2009-11-09 15:38 -------- d–h--w- c:\program files\InstallShield Installation Information
2010-05-16 08:23 . 2009-11-14 21:38 -------- d-----w- c:\users\Kris\AppData\Roaming\uTorrent
2010-05-15 19:30 . 2009-11-14 21:40 -------- d-----w- c:\program files\uTorrent
2010-05-15 07:56 . 2010-04-16 17:46 -------- d-----w- c:\users\Kris\AppData\Roaming\Moje pliki Bitwy o ?ródziemie™ II
2010-05-15 07:17 . 2010-02-28 07:26 137256 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-05-15 07:17 . 2010-02-28 07:26 218808 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-10 17:26 . 2009-11-09 14:39 -------- d-----w- c:\program files\Alwil Software
2010-05-10 14:13 . 2010-02-16 18:20 -------- d-----w- c:\users\Kris\AppData\Roaming\Xfire
2010-05-10 14:07 . 2010-02-16 18:20 -------- d-----w- c:\programdata\Xfire
2010-05-09 06:19 . 2009-11-09 15:02 -------- d-----w- c:\program files\Your Uninstaller 2006
2010-05-09 06:01 . 2010-01-09 18:07 -------- d-----w- c:\program files\Common Files\InstallShield
2010-04-26 21:30 . 2010-02-19 10:28 1216176 ----a-w- c:\users\Kris\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
2010-04-26 19:20 . 2009-11-08 17:58 -------- d-----w- c:\program files\Common Files\Real
2010-04-26 19:20 . 2009-11-08 17:58 -------- d-----w- c:\program files\Real
2010-04-25 15:37 . 2009-12-22 17:25 -------- d-----w- c:\users\Kris\AppData\Roaming\Tropico 3
2010-04-25 11:45 . 2010-01-16 18:49 89 ----a-w- c:\users\Kris\AppData\Local\cqelhv.bat
2010-04-25 07:32 . 2010-02-16 18:20 -------- d-----w- c:\program files\Xfire
2010-04-24 19:23 . 2010-03-08 13:45 443912 ----a-w- c:\users\Kris\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-04-17 07:45 . 2010-04-17 07:45 -------- d-----w- c:\programdata\Z-Manufaktur
2010-04-16 20:26 . 2010-04-16 20:26 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-04-16 19:39 . 2010-04-16 19:39 -------- d-----w- c:\program files\Veetle
2010-04-16 17:52 . 2010-04-16 17:51 -------- d-----w- c:\program files\Z-Cron
2010-04-12 20:47 . 2010-04-12 20:47 -------- d-----w- c:\program files\KM Wakeup
2010-04-12 14:22 . 2010-04-12 14:22 -------- d-----w- c:\program files\Firefly Studios
2010-04-10 18:16 . 2010-04-10 18:16 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-07 19:09 . 2010-04-07 19:09 96896 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2010-04-07 19:08 . 2010-04-07 19:08 114984 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-04-07 19:05 . 2010-04-07 19:05 134024 ----a-w- c:\windows\system32\drivers\eamonm.sys
2010-04-07 02:43 . 2010-04-07 02:43 5430272 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2010-04-07 02:16 . 2010-04-07 02:16 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-04-07 02:16 . 2010-04-07 02:16 489472 ----a-w- c:\windows\system32\aticfx32.dll
2010-04-07 02:13 . 2010-04-07 02:13 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-04-07 02:12 . 2010-04-07 02:12 372736 ----a-w- c:\windows\system32\atieclxx.exe
2010-04-07 02:12 . 2010-04-07 02:12 14321664 ----a-w- c:\windows\system32\atioglxx.dll
2010-04-07 02:12 . 2010-04-07 02:12 172032 ----a-w- c:\windows\system32\atiesrxx.exe
2010-04-07 02:10 . 2010-04-07 02:10 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-04-07 02:10 . 2010-04-07 02:10 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-04-07 02:10 . 2010-04-07 02:10 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-04-07 02:10 . 2010-04-07 02:10 11776 ----a-w- c:\windows\system32\atimuixx.dll
2010-04-07 02:10 . 2010-04-07 02:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-04-07 02:06 . 2009-07-13 22:09 3164160 ----a-w- c:\windows\system32\atidxx32.dll
2010-04-07 01:46 . 2010-04-07 01:46 50176 ----a-w- c:\windows\system32\coinst.dll
2010-04-07 01:40 . 2009-06-10 21:19 3707904 ----a-w- c:\windows\system32\atiumdag.dll
2010-04-07 01:40 . 2010-04-07 01:40 53248 ----a-w- c:\windows\system32\aticalrt.dll
2010-04-07 01:40 . 2010-04-07 01:40 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-04-07 01:38 . 2010-04-07 01:38 4018176 ----a-w- c:\windows\system32\aticaldd.dll
2010-04-07 01:23 . 2010-04-07 01:23 237568 ----a-w- c:\windows\system32\atiadlxx.dll
2010-04-07 01:23 . 2010-04-07 01:23 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-04-07 01:23 . 2010-04-07 01:23 14848 ----a-w- c:\windows\system32\atigktxx.dll
2010-04-07 01:23 . 2010-04-07 01:23 157184 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2010-04-07 01:22 . 2010-04-07 01:22 28160 ----a-w- c:\windows\system32\atiuxpag.dll
2010-04-07 01:22 . 2010-04-07 01:22 20480 ----a-w- c:\windows\system32\atiu9pag.dll
2010-04-07 01:22 . 2010-04-07 01:22 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-04-07 01:21 . 2009-07-13 22:09 2983936 ----a-w- c:\windows\system32\atiumdva.dll
2010-04-07 01:08 . 2010-04-07 01:08 52224 ----a-w- c:\windows\system32\atimpc32.dll
2010-04-07 01:08 . 2010-04-07 01:08 52224 ----a-w- c:\windows\system32\amdpcom32.dll
2010-04-06 06:03 . 2010-02-07 18:50 -------- d-----w- c:\users\Kris\AppData\Roaming\Gadu-Gadu 10
2010-04-03 15:43 . 2010-01-16 18:06 -------- d-----w- c:\program files\Ubisoft
2010-04-02 16:09 . 2010-04-02 16:09 2023 ----a-w- c:\windows\system32\atipblag.dat
2010-03-27 17:30 . 2010-03-27 17:30 -------- d-----w- c:\users\Kris\AppData\Roaming\freeTVRadio
2010-03-27 17:23 . 2010-03-27 17:23 -------- d-----w- c:\program files\freeTVRadio
2010-03-27 17:23 . 2010-03-27 17:23 -------- d-----w- c:\program files\OfferBoxSearch
2010-03-27 17:23 . 2010-03-27 17:23 -------- d-----w- c:\program files\OfferBox
2010-03-27 17:18 . 2010-03-27 17:18 -------- d-----w- c:\programdata\TVU Networks
2010-03-23 08:49 . 2010-03-23 08:49 101008 ----a-w- c:\users\Kris\AppData\Roaming\OfferBox\offerboxffx@offerbox.com\components\DataXPCOM.dll
2010-03-17 15:06 . 2010-03-17 15:06 202234 ----a-w- c:\windows\system32\atiicdxx.dat
2010-03-16 15:59 . 2010-03-16 15:59 118784 ----a-w- c:\users\Kris\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-12 17:30 . 2010-02-28 07:26 138056 ----a-w- c:\users\Kris\AppData\Roaming\PnkBstrK.sys
2010-03-12 17:30 . 2010-02-28 07:26 138056 ----a-w- c:\users\Kris\AppData\Roaming\PnkBstrK.sys
2010-03-12 17:30 . 2010-02-28 07:26 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-03-12 17:30 . 2010-02-28 07:26 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-03-09 10:21 . 2010-03-09 10:21 107024 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2010-02-27 07:23 . 2009-11-08 16:04 111120 ----a-w- c:\users\Kris\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-26 06:06 . 2010-02-26 06:06 2626360 ----a-w- c:\users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\nrdx7k9w.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyœlne, prawid³owe wpisy nie s¹ pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe” [2009-07-26 3883856]
“RGSC”=“c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe” [2009-11-14 306088]
“Gadu-Gadu”=“c:\program files\Gadu-Gadu\gg.exe” [2007-04-17 2113536]
“DAEMON Tools Lite”=“c:\program files\DAEMON Tools Lite\DTLite.exe” [2009-10-30 369200]
“Gadu-Gadu 10”=“c:\program files\Gadu-Gadu 10\gg.exe” [2010-01-20 12067432]
“Gadwin PrintScreen Pro”=“c:\program files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe” [2009-02-28 516096]
“Gadwin PrintScreen”=“c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe” [2008-12-09 495616]
“OfferBox”=“c:\program files\OfferBox\OfferBox.exe” [2010-03-23 632464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“hpqSRMon”=“c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe” [2008-07-22 150528]
“GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-26 31016]
“HP Software Update”=“c:\program files\HP\HP Software Update\HPWuSchd2.exe” [2008-12-08 54576]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2010-04-04 36272]
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2010-03-24 952768]
“TkBellExe”=“c:\program files\Common Files\Real\Update_OB\realsched.exe” [2010-04-26 202256]
“egui”=“c:\program files\ESET\ESET NOD32 Antivirus\egui.exe” [2010-04-07 2145000]
“LogMeIn Hamachi Ui”=“c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe” [2010-03-30 1820040]
“StartCCC”=“c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” [2010-04-06 102400]
“ATICustomerCare”=“c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe” [2009-11-16 307200]
c:\users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
GameRanger.lnk - c:\users\Kris\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe [2010-2-19 1216176]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
Sitecom Wireless Utility.lnk - c:\program files\Sitecom\Common\RaUI.exe [2009-12-4 1773568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableUIADesktopToggle”= 0 (0x0)
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-09 691696]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;e:\dragon\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R3 GarenaPEngine;GarenaPEngine;c:\users\Kris\AppData\Local\Temp\CBZA96D.tmp [x]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys [2009-02-03 63096]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-04-07 172032]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 134024]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2010-03-23 704760]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-04-07 5430272]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-04-07 157184]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Zawartoœæ folderu ‘Zaplanowane zadania’
.
.
------- Skan uzupe³niaj¹cy -------
.
IE: E&sporta in Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\nrdx7k9w.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - plugin: c:\program files\Win7codecs\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\Win7codecs\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\users\Kris\AppData\Roaming\Gadu-Gadu 10_userdata\npgg.2.dll
---- FIREFOX - SPOSÓB POSTÊPOWANIA ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref(“ui.use_native_colors”, true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref(“network.auth.force-generic-ntlm”, false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref(“svg.smil.enabled”, false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref”, true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl.renego_unrestricted_hosts”, “”);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl.treat_unsafe_negotiation_as_broken”, false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl.require_safe_negotiation”, false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name”, “chrome://browser/locale/browser.properties”);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref(“extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description”, “chrome://browser/locale/browser.properties”);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref(“plugins.update.notifyUser”, false);
.
-
-
-
- USUNIÊTO PUSTE WPISY - - - -
HKCU-Run-PlayNC Launcher - (no file)
HKCU-Run-xhyiarc - c:\users\kris\appdata\local\xhyiarc.exe
AddRemove-{2C2F85C4-62C3-4F59-A5E1-AB60E5F76ADF}_is1 - d:\f\Faces of War\unins000.exe
AddRemove-Half-Life 2 - c:\program files\booddanet\Half-Life 2\Uninstal.exe
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\GarenaPEngine]
“ImagePath”="??\c:\users\Kris\AppData\Local\Temp\CBZA96D.tmp"
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-4053120410-1907708109-2321777132-1001\Software\SecuROM\License information*]
“datasecu”=hex:80,e5,41,d1,b4,37,f5,32,dd,3e,b2,97,c2,80,91,36,9b,d2,32,14,1c,
6e,cd,3c,73,f9,3e,69,72,f1,80,83,bb,e9,ee,7d,90,a4,66,b3,ef,b2,f5,8d,87,3d,\
“rkeysecu”=hex:c5,8d,de,dd,40,64,be,4e,f1,85,05,be,12,0c,ee,ca
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Czas ukoñczenia: 2010-05-22 22:00:08
ComboFix-quarantined-files.txt 2010-05-22 20:00
Przed: 1’285’259’264 bytes free
Po: 1’512’591’360 bytes free
-
- End Of File - - 2150EA968DC03438EE550A663F9EEDB7