((((((((((((((((((((((((( Pliki utworzone od 2011-08-12 do 2011-09-12 ))))))))))))))))))))))))))))))) . . 2011-09-12 13:54 . 2011-09-12 13:54 -------- d-----w- c:\users\Public\AppData\Local\temp 2011-09-12 13:54 . 2011-09-12 13:54 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-09-12 13:24 . 2011-09-12 13:54 -------- d-----w- c:\users\Gadom\AppData\Local\temp 2011-09-09 12:35 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates{201596C7-CA7D-4AD1-89E7-8C8FBA65C280}\mpengine.dll 2011-08-26 12:31 . 2011-08-26 12:31 -------- d-----w- c:\program files\MSN Toolbar 2011-08-26 12:31 . 2011-08-26 12:31 -------- d-----w- c:\program files\Bing Bar Installer 2011-08-26 12:31 . 2011-08-26 12:34 -------- d-----w- c:\programdata\HP Photo Creations 2011-08-26 12:31 . 2011-08-26 12:31 -------- d-----w- c:\program files\HP Photo Creations 2011-08-26 12:31 . 2011-09-08 13:31 -------- d-----w- c:\users\Gadom\AppData\Roaming\HpUpdate 2011-08-24 09:57 . 2011-07-09 04:29 2048 ----a-w- c:\windows\system32\tzres.dll . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-10 17:14 . 2011-05-24 18:15 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-16 04:27 . 2011-08-10 23:49 290816 ----a-w- c:\windows\system32\KernelBase.dll 2011-07-16 04:15 . 2011-08-10 23:49 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 4096 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2011-07-16 04:15 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2011-07-16 02:17 . 2011-08-10 23:49 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17 . 2011-08-10 23:49 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17 . 2011-08-10 23:49 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17 . 2011-08-10 23:49 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2011-07-09 02:30 . 2011-08-10 23:50 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-24 04:27 . 2011-08-10 23:49 169984 ----a-w- c:\windows\system32\winsrv.dll 2011-06-24 04:22 . 2011-08-10 23:49 271360 ----a-w- c:\windows\system32\conhost.exe 2011-06-23 04:33 . 2011-08-10 23:50 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-06-23 04:33 . 2011-08-10 23:50 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-06-21 05:34 . 2011-08-10 23:49 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-15 08:55 . 2011-08-10 23:49 86016 ----a-w- c:\windows\system32\odbccu32.dll 2011-06-15 08:55 . 2011-08-10 23:49 81920 ----a-w- c:\windows\system32\odbccr32.dll 2011-06-15 08:55 . 2011-08-10 23:49 319488 ----a-w- c:\windows\system32\odbcjt32.dll 2011-06-15 08:55 . 2011-08-10 23:49 163840 ----a-w- c:\windows\system32\odbctrac.dll 2011-06-15 08:55 . 2011-08-10 23:49 122880 ----a-w- c:\windows\system32\odbccp32.dll 2011-09-07 20:34 . 2011-03-25 21:14 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE~\Browser Helper Objects{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}] 2011-02-09 18:29 400384 ----a-w- c:\progra~1\ALLPLA~1\Iplex\IplexToALLPlayer.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ALLUpdate”=“c:\program files\ALLPlayer\ALLUpdate.exe” [2011-02-07 1362944] “OscarEditor”=“c:\program files\OSCAR Editor\OscarEditor.exe” [2009-11-24 2642432] “Steam”=“e:\gry\steam\steam.exe” [2011-08-02 1242448] “Sony Ericsson PC Companion”=“c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe” [2010-11-16 422912] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NeroFilterCheck”=“c:\program files\Common Files\Ahead\Lib\NeroCheck.exe” [2008-07-14 570664] “amd_dc_opt”=“c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe” [2008-07-22 77824] “GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-26 31016] “QuickTime Task”=“c:\program files\QuickTime\QTTask.exe” [2010-03-17 421888] “Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2011-06-08 37296] “Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2011-03-30 937920] “egui”=“c:\program files\ESET\ESET Smart Security\egui.exe” [2010-11-04 2219184] “SunJavaUpdateSched”=“c:\program files\Common Files\Java\Java Update\jusched.exe” [2011-04-08 254696] “HP Software Update”=“c:\program files\HP\HP Software Update\HPWuSchd2.exe” [2010-03-12 49208] “Bing Bar”=“c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe” [2010-04-27 243544] “Microsoft Default Manager”=“c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe” [2009-11-11 288088] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “ConsentPromptBehaviorAdmin”= 0 (0x0) “ConsentPromptBehaviorUser”= 3 (0x3) “EnableLUA”= 0 (0x0) “EnableUIADesktopToggle”= 0 (0x0) “PromptOnSecureDesktop”= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] “aux”=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 ESLvnic1;ESLvnic Virtual Network 32 Bit;c:\windows\system32\DRIVERS\ESLvnic.sys [2010-06-07 24504] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2011-01-08 13224] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2010-10-26 155344] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-30 691696] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008] S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-09-03 137144] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-11-04 810144] S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984] S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . . ------- Skan uzupełniający ------- . uStart Page = hxxp://vshare.toolbarhome.com/?hp=df IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 Trusted Zone: kuaiche.com\software TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces{6E8EEAA0-5ABC-4D1C-93A1-95CA91EA2EE7}: NameServer = 194.204.152.34 208.67.222.222 FF - ProfilePath - c:\users\Gadom\AppData\Roaming\Mozilla\Firefox\Profiles\rsyxlne7.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www3.iamwired.net/websearch.php?src=tops&search= FF - prefs.js: browser.startup.homepage - hxxp://pl.start3.mozilla.com/firefox?cl … l:official FF - prefs.js: keyword.URL - hxxp://startsear.ch/?q= . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\S-1-5-21-1235542836-933740508-3956609943-1001\Software\SecuROM\License information*] “datasecu”=hex:45,ee,5c,03,fe,70,70,2d,2d,ef,1c,c1,56,1b,ad,ad,21,f5,18,c4,d5, 2b,6a,f2,9d,2a,b8,ac,0e,4e,f9,4b,bb,ae,b1,8d,03,1d,7b,b7,df,a3,27,26,e0,ce,\ “rkeysecu”=hex:84,b1,87,e0,76,42,e4,e4,60,e3,21,05,af,1e,37,af . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2011-09-12 15:55:34 ComboFix-quarantined-files.txt 2011-09-12 13:55 . Przed: 22 740 955 136 bajtów wolnych Po: 22 691 581 952 bajtów wolnych . - - End Of File - - 212C78FBF48E1BCE628049664F848C34