
Przeskanowalem go programem ComboFix i co dalej?
Dodano Dzisiaj, 00:14:
- Kod: Zaznacz wszystko
ComboFix 08-12-11.01 - KOMPUTEREK 2008-12-11 21:39:47.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.276 [GMT 4.5:30]
Uruchomiony z: c:\documents and settings\KOMPUTEREK.STARUSZEK\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\[u]0[/u]w.com
C:\3rl3lqbq.bat
C:\abk.bat
C:\autorun.inf
c:\documents and settings\Gość\Dane aplikacji\addon.dat
c:\documents and settings\KOMPUTEREK\Dane aplikacji\addon.dat
c:\documents and settings\Patryk.DDD-73CA4DA5468\Dane aplikacji\addon.dat
C:\e.cmd
C:\ij.bat
C:\nq0cq.cmd
C:\pnt.com
C:\rcukd.cmd
c:\windows\IE4 Error Log.txt
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\ckvo1.dll
c:\windows\system32\gasretyw0.dll
c:\windows\system32\gasretyw1.dll
c:\windows\system32\kamsoft.exe
c:\windows\system32\setup.ini
C:\xih9.cmd
D:\[u]0[/u]w.com
D:\3rl3lqbq.bat
D:\abk.bat
D:\Autorun.inf
D:\e.cmd
D:\ij.bat
D:\nq0cq.cmd
D:\pnt.com
D:\rcukd.cmd
D:\WinRAR.exe
D:\xih9.cmd
E:\[u]0[/u]w.com
E:\3rl3lqbq.bat
E:\abk.bat
E:\Autorun.inf
E:\e.cmd
E:\ij.bat
E:\nq0cq.cmd
E:\pnt.com
E:\rcukd.cmd
E:\xih9.cmd
F:\[u]0[/u]w.com
F:\3rl3lqbq.bat
F:\abk.bat
F:\Autorun.inf
F:\e.cmd
F:\ij.bat
F:\nq0cq.cmd
F:\pnt.com
F:\rcukd.cmd
F:\xih9.cmd
G:\[u]0[/u]w.com
G:\3rl3lqbq.bat
G:\abk.bat
G:\Autorun.inf
G:\e.cmd
G:\ij.bat
G:\nq0cq.cmd
G:\pnt.com
G:\rcukd.cmd
G:\xih9.cmd
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-11 do 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-11 21:12 . 2008-12-11 21:13 <DIR> d-------- C:\totalcmd
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\UC.PIF
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\RAR.PIF
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\PKZIP.PIF
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\PKUNZIP.PIF
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\NOCLOSE.PIF
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\LHA.PIF
2008-12-11 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\ARJ.PIF
2008-12-11 21:12 . 2008-12-11 21:20 480 --a------ c:\windows\wincmd.ini
2008-12-11 19:45 . 2008-12-11 19:45 <DIR> d--hs---- C:\FOUND.066
2008-12-11 19:40 . 2008-12-06 21:20 104,421 -r-hs---- C:\6fnlpetp.exe
2008-12-11 19:40 . 2008-12-06 21:20 104,421 -r-hs---- C:\2u.com
2008-12-11 19:36 . 2008-12-11 19:36 <DIR> d--hs---- C:\FOUND.065
2008-12-11 19:19 . 2008-12-11 19:19 <DIR> d-------- c:\program files\Common Files\PC Tools
2008-12-11 19:19 . 2008-12-11 19:19 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dane aplikacji\TEMP
2008-12-10 21:13 . 2008-12-10 21:13 <DIR> d--hs---- C:\FOUND.064
2008-12-09 19:31 . 2008-12-09 19:31 <DIR> d--hs---- C:\FOUND.063
2008-12-09 15:31 . 2008-12-10 19:14 85,504 -r-hs---- c:\windows\system32\vbsdfe1.dll
2008-12-09 14:00 . 2008-12-10 19:14 108,137 -r-hs---- c:\windows\system32\vamsoft.exe
2008-12-09 14:00 . 2008-12-11 19:46 85,504 -r-hs---- c:\windows\system32\vbsdfe0.dll
2008-12-07 14:41 . 2008-12-07 14:41 <DIR> d--hs---- C:\FOUND.062
2008-12-06 21:19 . 2008-12-06 21:19 <DIR> d--hs---- C:\FOUND.061
2008-12-05 23:33 . 2001-08-18 06:36 8,704 --a------ c:\windows\system32\kbdjpn.dll
2008-12-05 23:33 . 2001-08-18 06:36 8,704 --a------ c:\windows\system32\dllcache\kbdjpn.dll
2008-12-05 23:33 . 2001-08-18 06:36 8,192 --a------ c:\windows\system32\kbdkor.dll
2008-12-05 23:33 . 2001-08-18 06:36 8,192 --a------ c:\windows\system32\dllcache\kbdkor.dll
2008-12-05 23:33 . 2008-04-14 21:39 6,144 --a------ c:\windows\system32\kbd106.dll
2008-12-05 23:33 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101c.dll
2008-12-05 23:33 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101b.dll
2008-12-05 23:33 . 2008-04-14 21:39 6,144 --a------ c:\windows\system32\dllcache\kbd106.dll
2008-12-05 23:33 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\dllcache\kbd101c.dll
2008-12-05 23:33 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\dllcache\kbd101b.dll
2008-12-05 23:33 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\kbd103.dll
2008-12-05 23:33 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\dllcache\kbd103.dll
2008-12-05 07:45 . 2008-12-05 07:45 <DIR> d--hs---- C:\FOUND.060
2008-12-04 16:48 . 2008-12-04 16:48 <DIR> d--hs---- C:\FOUND.059
2008-12-03 17:08 . 2008-12-03 17:08 <DIR> d--hs---- C:\FOUND.058
2008-12-01 16:53 . 2008-12-01 16:53 <DIR> d--hs---- C:\FOUND.057
2008-12-01 16:44 . 2008-12-01 16:44 <DIR> d--hs---- C:\FOUND.056
2008-12-01 10:55 . 2008-12-01 10:55 <DIR> d-------- c:\documents and settings\KOMPUTEREK.STARUSZEK\Dane aplikacji\vlc
2008-12-01 10:54 . 2008-12-01 10:54 <DIR> d-------- c:\program files\VideoLAN
2008-11-30 22:42 . 2008-11-30 22:42 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dane aplikacji\HP Product Assistant
2008-11-29 16:46 . 2008-11-29 16:45 105,411 -r-hs---- C:\o1.com
2008-11-29 11:52 . 2008-11-29 11:52 <DIR> d--hs---- C:\FOUND.055
2008-11-25 20:47 . 2008-11-25 20:47 43,520 --a------ c:\windows\explorer.opt
2008-11-25 20:40 . 2008-11-25 20:40 <DIR> d--hs---- C:\FOUND.054
2008-11-24 17:00 . 2008-11-24 17:00 <DIR> d-------- c:\program files\TVAnts
2008-11-24 14:30 . 2008-11-24 14:32 4,325 --a------ C:\dziadostwo2.m
2008-11-24 14:16 . 2008-11-24 14:17 7,732 --a------ C:\dziadostwo.m
2008-11-20 16:09 . 2008-11-20 16:09 <DIR> d--hs---- C:\FOUND.053
2008-11-17 17:21 . 2008-11-17 17:21 <DIR> d-------- c:\program files\OpenOffice.org 2.4
2008-11-17 15:10 . 2008-11-17 15:10 <DIR> d--hs---- C:\FOUND.052
2008-11-12 12:21 . 2008-09-04 21:47 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 12:21 . 2008-10-24 15:51 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 15:54 . 2008-11-11 15:54 <DIR> d-------- c:\documents and settings\KOMPUTEREK.STARUSZEK\Dane aplikacji\U3
2008-11-11 15:49 . 2008-11-11 15:49 <DIR> d--hs---- C:\FOUND.051
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 17:17 81,984 ----a-w c:\windows\system32\bdod.bin
2008-12-10 15:44 921,632 ----a-w C:\PA7311.DAT
2008-11-10 08:37 110,031 --sh--r C:\whi.com
2008-11-09 11:56 --------- d-----w c:\documents and settings\KOMPUTEREK.STARUSZEK\Dane aplikacji\Mathsoft
2008-11-09 11:54 --------- d-----w c:\program files\Mathcad
2008-11-09 06:47 110,013 --sh--r C:\sq.com
2008-11-08 21:27 52,736 ----a-w c:\windows\system32\drivers\CDAC11BA.EXE
2008-11-08 21:27 20,992 ----a-w c:\windows\CDAC13BA.EXE
2008-11-08 21:27 11,376 ----a-w c:\windows\system32\drivers\CdaC15BA.SYS
2008-11-08 21:24 --------- d-----w c:\program files\Mathsoft
2008-11-08 20:27 --------- d-----w c:\program files\OrCAD_Demo
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 07:55 96,384 ----a-w c:\windows\system32\drivers\sptd7581.sys
2008-10-23 12:42 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:42 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-20 04:08 106,249 --sh--r C:\2fiji.com
2008-10-16 12:46 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 12:46 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-10-16 09:43 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 09:43 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 09:43 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 09:43 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 09:42 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 09:42 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 09:42 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 09:42 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 09:39 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 09:39 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 09:39 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 09:39 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 09:39 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 09:38 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 09:38 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:36 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 06:34 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 06:33 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 12:13 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:27 1,846,656 ------w c:\windows\system32\dllcache\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Octoshape Streaming Services"="c:\documents and settings\KOMPUTEREK.STARUSZEK\Ustawienia lokalne\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2008-05-22 156944]
"vamsoft"="c:\windows\system32\vamsoft.exe" [2008-12-10 108137]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-25 1397760]
"PAC7311_Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
"BDMCon"="c:\progra~1\Softwin\BITDEF~2\bdmcon.exe" [2007-04-02 290816]
"BDAgent"="c:\program files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 69632]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-09 128920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AdslTaskBar"="stmctrl.dll" [2006-06-02 c:\windows\system32\stmctrl.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-10-17 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users.WINDOWS\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Gadu-Gadu\\GG.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\KOMPUTEREK.STARUSZEK\\Ustawienia lokalne\\Dane aplikacji\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"d:\\SopCast\\adv\\SopAdver.exe"=
"d:\\SopCast\\SopCast.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a9fe9ae-7cf8-11dd-87e2-0016e6360b89}]
\Shell\AutoRun\command - I:\kk3.bat
\Shell\explore\Command - I:\kk3.bat
\Shell\open\Command - I:\kk3.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1898aa13-85a3-11dd-8817-0016e6360b89}]
\Shell\AutoRun\command - I:\kk3.bat
\Shell\explore\Command - I:\kk3.bat
\Shell\open\Command - I:\kk3.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{213b8ee6-b7c9-11dd-898e-0016e6360b89}]
\Shell\AutoRun\command - I:\m9ma.exe
\Shell\explore\Command - I:\m9ma.exe
\Shell\open\Command - I:\m9ma.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ec5aa-afe3-11dd-8954-0016e6360b89}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ec5ab-afe3-11dd-8954-0016e6360b89}]
\Shell\AutoRun\command - K:\whi.com
\Shell\explore\Command - K:\whi.com
\Shell\open\Command - K:\whi.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a0a284e-2a63-11dd-8594-0016e6360b89}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2972942-af58-11dd-894f-0016e6360b89}]
\Shell\AutoRun\command - I:\whi.com
\Shell\explore\Command - I:\whi.com
\Shell\open\Command - I:\whi.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b72a9a8e-4053-11dd-861e-0016e6360b89}]
\Shell\AutoRun\command - I:\kk3.bat
\Shell\explore\Command - I:\kk3.bat
\Shell\open\Command - I:\kk3.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb1b4f90-ab4d-11dd-892f-0016e6360b89}]
\Shell\AutoRun\command - I:\e.cmd
\Shell\explore\Command - I:\e.cmd
\Shell\open\Command - I:\e.cmd
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-GoD - c:\documents and settings\KOMPUTEREK.STARUSZEK\Pulpit\GoD\GoD.exe
.
------- Skan uzupełniający -------
.
uInternet Connection Wizard,ShellNext = iexplore
TCP: {B1AAC84E-A160-4600-B9A7-47D4B5FC16F9} = 217.116.100.65 217.116.100.66
FF - ProfilePath - c:\documents and settings\KOMPUTEREK.STARUSZEK\Dane aplikacji\Mozilla\Firefox\Profiles\e880pk64.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.onet.pl/
FF - plugin: c:\documents and settings\KOMPUTEREK.STARUSZEK\Dane aplikacji\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\documents and settings\KOMPUTEREK.STARUSZEK\Ustawienia lokalne\Dane aplikacji\Octoshape\Octoshape Streaming Services\octoprogram-L03-NMS0810164_SUA_900\npoctoshape.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-11 21:47:10
Windows 5.1.2600 Dodatek Service Pack 3 FAT NTAPI
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(772)
c:\windows\system32\Ati2evxx.dll
.
Czas ukończenia: 2008-12-11 21:51:56
ComboFix-quarantined-files.txt 2008-12-11 17:21:54
Przed: 1 735 049 216 bajtów wolnych
Po: 2,578,415,616 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
317 --- E O F --- 2008-12-11 10:11:31