przez Squosh 14 Lis 2008, 20:07
Chwilowo piszę ze swojego kompa.
Nie wiem ale dawno tak za mulonego kompa nie widziałem. Raz się włącza a raz nie mogę nic robić. Za 10 minut dam z combo tylko muszę się kawałek przejść.
Dodano 15.11.2008 16:01:34:Wklejam loga z Combo. Komputer chodzi jak po formacie. Combofix chyba wszystko wywalił. Pozdrawiam.
- Kod: Zaznacz wszystko
ComboFix 08-11-12.02 - Właściciel 2008-11-14 19:51:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.684 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Właściciel\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\[u]0[/u]8dgu.com
C:\[u]0[/u]u.cmd
C:\1nkbd8h.bat
C:\1rfw8hjr.com
C:\1t6yxlxx.cmd
C:\1u0o8bnq.cmd
C:\1yl2d.bat
C:\2.cmd
C:\22xo.exe
C:\33gmhso.bat
C:\6.bat
C:\68.exe
C:\83l3v.cmd
C:\8ti.exe
C:\9.cmd
C:\a9.com
C:\Autorun.inf
C:\b.exe
C:\b3b9u.com
C:\bo1dhu.bat
C:\bpu.exe
C:\bwpncb6.com
C:\c9hehpa.bat
C:\cqdis.cmd
C:\d.com
c:\docume~1\WACICI~1\USTAWI~1\Temp\ovlx.dll
c:\docume~1\WACICI~1\USTAWI~1\Temp\q8gqt.dll
c:\docume~1\WACICI~1\USTAWI~1\Temp\zb5ok.dll
C:\ev60a2.cmd
C:\f.bat
C:\f0.cmd
C:\fe.bat
C:\ffojc.com
C:\fi.cmd
C:\g.com
C:\hgu.bat
C:\itsduel.exe
C:\ivcvknr.bat
C:\j8q8d.cmd
C:\kdxdweli.cmd
C:\kk3.bat
C:\kn6jhgc.cmd
C:\krg62.cmd
C:\m.cmd
C:\mp.cmd
C:\n.com
C:\n6t1h.cmd
C:\njibyekk.com
C:\nq0cq.cmd
C:\oufddh.exe
C:\ov.cmd
C:\pnt.com
C:\ps.bat
C:\pv6mxu.bat
C:\qxbx9blb.com
C:\r1y1.bat
C:\r6r.exe
C:\r813.bat
C:\rqq2v.bat
C:\rs.cmd
C:\svdioajm.cmd
C:\t0k3c.cmd
C:\t1ypkh.exe
C:\taqhptr.bat
C:\tpfbusg.cmd
C:\tyktjfww.exe
C:\tym8a.exe
C:\u9dyi.exe
C:\v0s.cmd
C:\vva0hc0p.cmd
C:\vxl.exe
c:\windows\system32\amvo2.dll
c:\windows\system32\Bitkv0.dll
c:\windows\system32\Bitkv1.dll
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\ckvo1.dll
c:\windows\system32\ckvo2.dll
c:\windows\system32\ckvo3.dll
C:\x.com
C:\xih9.cmd
C:\xk2n.bat
C:\xmnm2.cmd
C:\yew.bat
C:\yssjnngm.cmd
E:\[u]0[/u]8dgu.com
E:\[u]0[/u]u.cmd
E:\1nkbd8h.bat
E:\1rfw8hjr.com
E:\1t6yxlxx.cmd
E:\1u0o8bnq.cmd
E:\1yl2d.bat
E:\2.cmd
E:\22xo.exe
E:\33gmhso.bat
E:\6.bat
E:\68.exe
E:\83l3v.cmd
E:\8ti.exe
E:\9.cmd
E:\a9.com
E:\Autorun.inf
E:\b.exe
E:\b3b9u.com
E:\bo1dhu.bat
E:\bpu.exe
E:\bwpncb6.com
E:\c9hehpa.bat
E:\cqdis.cmd
E:\d.com
E:\ev60a2.cmd
E:\f.bat
E:\f0.cmd
E:\fe.bat
E:\ffojc.com
E:\fi.cmd
E:\g.com
E:\hgu.bat
E:\itsduel.exe
E:\ivcvknr.bat
E:\j8q8d.cmd
E:\kdxdweli.cmd
E:\kk3.bat
E:\kn6jhgc.cmd
E:\krg62.cmd
E:\m.cmd
E:\mp.cmd
E:\n.com
E:\n6t1h.cmd
E:\njibyekk.com
E:\nq0cq.cmd
E:\oufddh.exe
E:\ov.cmd
E:\pnt.com
E:\ps.bat
E:\pv6mxu.bat
E:\qxbx9blb.com
E:\r1y1.bat
E:\r6r.exe
E:\r813.bat
E:\rqq2v.bat
E:\rs.cmd
E:\svdioajm.cmd
E:\t0k3c.cmd
E:\t1ypkh.exe
E:\taqhptr.bat
E:\tpfbusg.cmd
E:\tyktjfww.exe
E:\u9dyi.exe
E:\v0s.cmd
E:\vva0hc0p.cmd
E:\vxl.exe
E:\x.com
E:\xih9.cmd
E:\xk2n.bat
E:\xmnm2.cmd
E:\yew.bat
E:\yssjnngm.cmd
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-14 do 2008-11-14 )))))))))))))))))))))))))))))))
.
2008-11-14 18:44 . 2008-11-14 18:44 <DIR> d-------- c:\windows\ERUNT
2008-11-14 17:49 . 2008-11-14 17:49 <DIR> d-------- c:\program files\VID_0E8F&PID_0012
2008-11-12 22:16 . 2008-09-04 18:17 1,106,944 --a------ c:\windows\system32\SET2B.tmp
2008-11-12 22:16 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 22:16 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 16:41 . 2008-11-12 16:41 85,504 -r-hs---- c:\windows\system32\gasretyw2.dll
2008-11-12 10:29 . 2008-11-01 14:30 104,927 -r-hs---- C:\vfjc8mxm.exe
2008-11-12 10:22 . 2008-11-13 14:48 99,670 -r-hs---- C:\lky.exe
2008-11-10 14:04 . 2008-11-14 19:47 85,504 -r-hs---- c:\windows\system32\gasretyw1.dll
2008-11-09 22:23 . 2008-11-10 14:04 108,271 -r-hs---- C:\whi.com
2008-11-09 22:23 . 2008-11-14 19:47 105,062 -r-hs---- c:\windows\system32\kamsoft.exe
2008-11-09 22:23 . 2008-11-14 19:47 85,504 --------- c:\windows\system32\gasretyw0.dll
2008-11-07 16:42 . 2008-11-08 12:57 108,973 -r-hs---- C:\sq.com
2008-11-02 00:56 . 2008-05-08 02:03 453,632 --a------ c:\windows\system32\SetACL.ocx
2008-10-28 15:17 . 2008-10-28 15:17 <DIR> d-------- c:\documents and settings\Właściciel\Dane aplikacji\Sports Interactive
2008-10-28 15:12 . 2008-10-28 15:15 <DIR> d--h----- c:\program files\Zero G Registry
2008-10-28 15:11 . 2008-10-28 15:11 <DIR> d--h----- c:\documents and settings\Właściciel\InstallAnywhere
2008-10-28 15:11 . 2008-10-28 15:11 <DIR> d--h----- c:\documents and settings\Właściciel\InstallAnywhere
2008-10-24 16:03 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-22 07:25 . 2008-10-22 14:47 104,123 -r-hs---- C:\xlk9.com
2008-10-21 15:33 . 2008-10-22 10:44 103,829 -r-hs---- C:\je26200.com
2008-10-18 09:01 . 2008-10-21 17:07 103,973 -r-hs---- C:\2fiji.com
2008-10-15 17:36 . 2008-08-14 14:26 2,190,464 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 17:36 . 2008-08-14 14:26 2,146,816 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 17:36 . 2008-08-14 14:26 2,067,328 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 17:36 . 2008-08-14 14:26 2,025,472 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 17:33 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-15 17:31 . 2008-09-15 16:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 18:54 --------- d-----w c:\program files\AutoConnect
2008-11-14 18:47 105,062 --sh--r C:\[u]0[/u]w.com
2008-11-14 18:19 --------- d-----w c:\program files\MarBit
2008-11-14 18:19 --------- d-----w c:\program files\Google
2008-11-14 17:58 --------- d-----w c:\documents and settings\Właściciel\Dane aplikacji\OpenOffice.org2
2008-11-14 17:55 --------- d-----w c:\program files\mks_vir_2007
2008-11-14 17:54 --------- d-----w c:\documents and settings\Właściciel\Dane aplikacji\Lavasoft
2008-11-14 16:49 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-10 16:41 --------- d-----w c:\program files\eMule
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-02 10:12 101,266 --sh--r C:\tknapl.exe
2008-09-25 10:52 --------- d-----w c:\program files\EA GAMES
2008-09-24 19:45 --------- d-----w c:\program files\Business-in-a-Box
2008-09-10 13:02 96,047 --sh--r C:\39lpji.com
2008-09-08 11:03 93,108 --sh--r C:\jdhc2x2.com
2008-09-06 07:46 92,932 --sh--r C:\ktnquo.exe
2008-08-29 20:49 91,084 --sh--r C:\ph.com
2008-08-23 16:04 90,366 --sh--r C:\mnl6on3.com
2008-08-21 19:02 90,994 --sh--r C:\83fgj.com
2007-02-13 19:34 21,822,168 -c--a-w c:\program files\AdbeRdr80_en_US.exe
2007-02-13 18:01 7,050,552 -c--a-w c:\program files\psa30se_en_us.exe
2004-10-01 14:00 40,960 ----a-w c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"CTZDetec.exe"="c:\program files\Creative\Creative Media Lite\CTZDetec.exe" [2007-12-18 401408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"AutoConnect"="c:\program files\AutoConnect\AutoConnect.exe" [2004-08-28 295424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"nwiz"="nwiz.exe" [2006-06-01 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 c:\windows\system32\nvmctray.dll]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-19 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2008-03-20 118784]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-01-16 1205840]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Image Zone - szybkie uruchamianie.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\HP Image Zone - szybkie uruchamianie.lnk
backup=c:\windows\pss\HP Image Zone - szybkie uruchamianie.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Właściciel^Menu Start^Programy^Autostart^OpenOffice.org 2.1.lnk]
path=c:\documents and settings\Właściciel\Menu Start\Programy\Autostart\OpenOffice.org 2.1.lnk
backup=c:\windows\pss\OpenOffice.org 2.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-11 23:12 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kamsoft]
-r-hs---- 2008-11-14 19:47 105062 c:\windows\system32\kamsoft.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2004-11-02 20:24 32768 c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-01-15 23:54 37376 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"e:\\Gry\\Pro Evolution Soccer 2008\\PES2008.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Gry\\Counter Strike Source\\hl2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"e:\\Gry\\Football Manager 2008\\fm.exe"=
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;c:\windows\system32\DRIVERS\atl01_xp.sys [2006-07-27 34944]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\DRIVERS\e4usbaw.sys [2007-01-04 104344]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\Drivers\e4ldr.sys [2007-01-04 69656]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);c:\windows\system32\DRIVERS\w300bus.sys [2006-03-13 60800]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;c:\windows\system32\DRIVERS\w300mdfl.sys [2006-03-13 9264]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;c:\windows\system32\DRIVERS\w300mdm.sys [2006-03-13 96352]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\w300mgmt.sys [2006-03-13 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\w300obex.sys [2006-03-13 85696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\lky.exe
\Shell\explore\Command - C:\lky.exe
\Shell\open\Command - C:\lky.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\lky.exe
\Shell\explore\Command - E:\lky.exe
\Shell\open\Command - E:\lky.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{060d194f-badb-11db-bd56-4d6564696130}]
\Shell\AutoRun\command - G:\xn1i9x.com
\Shell\explore\Command - G:\xn1i9x.com
\Shell\open\Command - G:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1b332c46-6ae6-11dd-81df-0018f315851f}]
\Shell\AutoRun\command - H:\rqq2v.bat
\Shell\explore\Command - H:\rqq2v.bat
\Shell\open\Command - H:\rqq2v.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2aa07ffe-3cf1-11dc-bdb7-0018f315851f}]
\Shell\AutoRun\command - H:\e.cmd
\Shell\explore\Command - H:\e.cmd
\Shell\open\Command - H:\e.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c06adc6-6c5e-11dd-81e2-0018f315851f}]
\Shell\AutoRun\command - H:\1u0o8bnq.cmd
\Shell\explore\Command - H:\1u0o8bnq.cmd
\Shell\open\Command - H:\1u0o8bnq.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{512f895e-4ac8-11dd-8183-0018f315851f}]
\Shell\AutoRun\command - H:\[u]0[/u]0hoeav.com
\Shell\explore\Command - H:\[u]0[/u]0hoeav.com
\Shell\open\Command - H:\[u]0[/u]0hoeav.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d93bd3d0-758d-11dc-beb5-0018f315851f}]
\Shell\AutoRun\command - H:\t0k3c.cmd
\Shell\explore\Command - H:\t0k3c.cmd
\Shell\open\Command - H:\t0k3c.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ece08077-dc0d-11dc-8001-4d6564696130}]
\Shell\AutoRun\command - H:\xqf.com
\Shell\explore\Command - H:\xqf.com
\Shell\open\Command - H:\xqf.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eee709bc-ffe0-11db-bc92-0018f315851f}]
\Shell\AutoRun\command - H:\e.cmd
\Shell\explore\Command - H:\e.cmd
\Shell\open\Command - H:\e.cmd
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-PowerBar - (no file)
MSConfigStartUp-BIBLauncher - c:\program files\Business-in-a-BoxBIBLauncher.exe
.
------- Skan uzupełniający -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O17 -: HKLM\CCS\Interface\{B62BD9D6-1C36-46B4-8AC8-746C863A46E2}: NameServer = 83.238.255.76 213.241.79.37
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-14 19:54:42
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
c:\windows\TEMP\zgdua0lw.TMP
skanowanie pomyślnie ukończone
ukryte pliki: 1
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Teleca Shared\CapabilityManager.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Czas ukończenia: 2008-11-14 19:59:04 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-11-14 18:59:01
Przed: 50 178 306 048 bajtów wolnych
Po: 50,543,448,064 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
390 --- E O F --- 2008-11-13 15:19:43
Jestem jedną z tych osób, które potrafią manipulować twoim czasem.
Wiesz dlaczego??
Bo tracisz go czytając mój podpis który nie ma w ogóle sensu.