
oto log
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:13:19, on 2009-03-28
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\afisicx.exe
E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
E:\Program Files\Intel\Wireless\Bin\EvtEng.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\StkCSrv.exe
E:\PROGRA~1\AVG\AVG8\avgrsx.exe
E:\PROGRA~1\AVG\AVG8\avgnsx.exe
E:\PROGRA~1\AVG\AVG8\avgemc.exe
E:\Program Files\AVG\AVG8\avgcsrvx.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\rundll32.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\WINDOWS\system32\rundll32.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 - REG:system.ini: UserInit=E:\WINDOWS\system32\userinit.exe,E:\WINDOWS\system32\idaw64.exe,E:\WINDOWS\system32\pdbcopy.exe,
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG8_TRAY] E:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [el] "E:\WINDOWS\system32\regsvr32.exe" /u /s "E:\WINDOWS\system32\el32.dll"
O17 - HKLM\System\CCS\Services\Tcpip\..\{17BDE057-B69F-4E96-B293-D30CB0E593B8}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{29DF8E0E-67A6-4640-BB84-F7D3E7962F53}: NameServer = 192.168.0.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - E:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: afisicx Service (afisicx) - Unknown owner - E:\WINDOWS\system32\afisicx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - E:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - E:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ODBC Administration Service (odbcasvc) - Unknown owner - E:\WINDOWS\SYSTEM32\odbcasvc.EXE (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - E:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - E:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: sopidkc Service (sopidkc) - Unknown owner - E:\WINDOWS\system32\sopidkc.exe (file missing)
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - E:\WINDOWS\System32\StkCSrv.exe
O23 - Service: tdctxte Service (tdctxte) - Unknown owner - E:\WINDOWS\system32\tdctxte.exe (file missing)
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - E:\WINDOWS\system32\wdfmgr.exe (file missing)
--
End of file - 4062 bytes
Pojawiaja sie coraz to nowe zainfekowane pliki nie kazde da sie wyleczyc komp sie zawiesza:( co robic
log comfofix
- Kod: Zaznacz wszystko
ComboFix 09-03-27.02 - m 2009-03-28 18:22:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.3071.2502 [GMT 1:00]
Uruchomiony z: e:\documents and settings\m\Pulpit\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\m\reader_s.exe
e:\windows\Install.txt
e:\windows\services.exe
e:\windows\system32\3.tmp
e:\windows\system32\5.tmp
e:\windows\system32\8.tmp
e:\windows\system32\9.tmp
e:\windows\system32\A.tmp
e:\windows\system32\afisicx.exe
e:\windows\system32\C.tmp
e:\windows\system32\comsa32.sys
e:\windows\system32\D.tmp
e:\windows\system32\dxonool32.sys
e:\windows\system32\E.tmp
e:\windows\system32\NCTAudioFile2.dll
e:\windows\system32\reader_s.exe
e:\windows\system32\skinboxer43.dll
e:\windows\system32\tpszxyd.sys
e:\windows\system32\w.exe
[COLOR=RED] . . . jest zainfekowany!![/COLOR]
[COLOR=RED] . . . jest zainfekowany!![/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFISICX
-------\Legacy_DEFAULTLIB
-------\Legacy_ODBCASVC
-------\Legacy_SOPIDKC
-------\Service_afisicx
-------\Service_defaultlib
-------\Service_odbcasvc
-------\Service_PCIDump
-------\Service_sopidkc
((((((((((((((((((((((((( Pliki utworzone od 2009-02-28 do 2009-03-28 )))))))))))))))))))))))))))))))
.
2009-03-28 18:56 . 2009-03-28 18:56 37,376 --a------ e:\windows\system32\config\systemprofile\reader_s.exe
2009-03-28 18:02 . 2009-03-28 18:02 28,672 --a------ e:\windows\system32\16.tmp
2009-03-28 18:00 . 2009-03-28 18:00 128 --a------ e:\windows\system32\11.tmp
2009-03-28 17:51 . 2009-03-28 17:51 <DIR> d-------- e:\program files\Trend Micro
2009-03-28 15:29 . 2009-03-28 15:29 31,744 --a------ e:\windows\system32\14.tmp
2009-03-28 15:27 . 2009-03-28 15:27 128 --a------ e:\windows\system32\F.tmp
2009-03-28 12:23 . 2009-03-28 12:23 31,744 --a------ e:\windows\system32\12.tmp
2009-03-28 12:20 . 2009-03-28 12:20 128 --a------ e:\windows\system32\B.tmp
2009-03-27 16:41 . 2009-03-27 16:42 124 --a------ e:\windows\system32\6.tmp
2009-03-27 12:15 . 2009-03-27 12:15 164 --a------ e:\windows\system32\4.tmp
2009-03-27 12:15 . 2009-03-27 12:15 1 --a------ e:\windows\system32\7.tmp
2009-03-26 17:16 . 2009-03-26 17:16 124 --a------ e:\windows\system32\2.tmp
2009-03-25 19:45 . 2009-03-25 19:45 <DIR> d---s---- e:\documents and settings\m\UserData
2009-03-25 19:16 . 2009-03-25 19:16 0 --a------ e:\windows\system32\10.tmp
2009-03-25 19:15 . 2009-03-25 15:35 8,467 --a------ e:\windows\system32\wf.exe
2009-03-22 21:20 . 2009-03-22 21:30 <DIR> d-------- e:\documents and settings\m\Dane aplikacji\gtk-2.0
2009-03-21 16:46 . 2009-03-21 16:46 <DIR> d-------- e:\documents and settings\m\Dane aplikacji\Inkscape
2009-03-21 16:38 . 2009-03-21 16:41 <DIR> d-------- e:\program files\Inkscape
2009-03-20 20:52 . 2009-03-21 00:20 <DIR> d-------- E:\underw
2009-03-20 20:37 . 2009-03-20 20:47 <DIR> d-------- E:\niewiem
2009-03-17 17:52 . 2009-03-17 17:52 <DIR> d-------- e:\documents and settings\m\Dane aplikacji\ACD Systems
2009-03-17 17:51 . 2009-03-17 17:51 <DIR> d-------- e:\program files\ACD Systems
2009-03-17 17:51 . 2000-09-06 10:20 317,952 --a------ e:\windows\system32\Roboex32.dll
2009-03-17 17:51 . 2000-09-06 10:20 126,976 --a------ e:\windows\system32\lwf214p.dll
2009-03-17 13:16 . 2009-03-17 13:16 <DIR> d-------- e:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
2009-03-17 13:15 . 2009-03-17 13:47 <DIR> d-------- e:\windows\NV5481588.TMP
2009-03-15 15:06 . 2009-03-15 15:06 23,600 --a------ e:\windows\system32\drivers\TVICHW32.SYS
2009-03-14 23:01 . 2009-03-14 23:01 <DIR> d-------- e:\program files\DirectShow Pack
2009-03-14 17:47 . 2009-03-17 14:14 <DIR> d-------- E:\xxx
2009-03-14 01:08 . 2009-03-14 01:08 <DIR> dr------- e:\program files\Skype
2009-03-14 01:08 . 2009-03-16 12:39 <DIR> d-------- e:\documents and settings\m\Dane aplikacji\Skype
2009-03-14 01:07 . 2009-03-14 01:08 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\Skype
2009-03-11 23:12 . 2009-03-28 17:37 <DIR> d--h----- E:\$AVG8.VAULT$
2009-03-10 20:51 . 2004-03-09 16:00 1,081,616 --a------ e:\windows\system32\MSCOMCTL.OCX
2009-03-10 20:51 . 2005-06-01 12:15 966,144 --a------ e:\windows\system32\NCTAudioInformation2.dll
2009-03-10 20:51 . 2002-04-07 22:14 724,992 --a------ e:\windows\system32\ebCrypt.dll
2009-03-10 20:51 . 2004-03-09 00:00 609,824 --a------ e:\windows\system32\COMCTL32.OCX
2009-03-10 20:51 . 2003-05-15 12:07 389,120 --a------ e:\windows\system32\actskn43.ocx
2009-03-10 20:51 . 2007-01-04 22:47 376,832 --a------ e:\windows\system32\cmd22.dll
2009-03-10 20:51 . 2000-01-28 13:58 102,400 --a------ e:\windows\system32\ccrpprg6.ocx
2009-03-10 20:42 . 2009-03-10 20:44 <DIR> d-a------ e:\documents and settings\All Users\Dane aplikacji\TEMP
2009-03-10 20:41 . 2003-03-19 14:20 1,060,864 --a------ e:\windows\system32\mfc71.dll
2009-03-08 16:56 . 2009-03-08 16:57 <DIR> d-------- e:\program files\Noiseware Professional Edition
2009-03-02 09:42 . 2009-03-02 09:42 <DIR> d-------- e:\program files\Real Alternative
2009-03-02 09:42 . 2003-03-19 04:14 499,712 --a------ e:\windows\system32\msvcp71.dll
2009-02-28 14:17 . 2009-03-21 20:56 <DIR> d-------- E:\filmy
2009-02-28 14:03 . 2009-02-28 20:20 <DIR> d-------- E:\celebrities
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 17:56 31,744 ----a-w e:\windows\services.exe
2009-03-28 16:56 --------- d-----w e:\documents and settings\All Users\Dane aplikacji\Soulseek
2009-03-23 23:23 --------- d-----w e:\program files\Lavalys
2009-03-23 22:53 --------- d-----w e:\program files\Gadu-Gadu
2009-03-18 13:57 --------- d-----w e:\program files\IrfanView
2009-03-17 13:01 --------- d-----w e:\documents and settings\All Users\Dane aplikacji\nView_Profiles
2009-03-17 12:16 --------- d-----w e:\program files\Common Files\Wise Installation Wizard
2009-03-01 16:30 --------- d-----w e:\program files\K-Lite Codec Pack
2009-02-26 16:51 --------- d-----w e:\program files\AGEIA Technologies
2009-02-24 11:35 --------- d-----w e:\program files\WinISO
2009-02-17 23:51 325,128 ----a-w e:\windows\system32\drivers\avgldx86.sys
2009-02-17 23:51 107,272 ----a-w e:\windows\system32\drivers\avgtdix.sys
2009-02-17 23:51 --------- d-----w e:\program files\AVG
2009-02-17 23:51 --------- d-----w e:\documents and settings\All Users\Dane aplikacji\avg8
2009-02-14 22:45 --------- d-----w e:\program files\DAEMON Tools Lite
2009-02-14 22:45 --------- d-----w e:\documents and settings\m\Dane aplikacji\DAEMON Tools Pro
2009-02-14 22:45 --------- d-----w e:\documents and settings\m\Dane aplikacji\DAEMON Tools
2009-02-14 22:45 --------- d-----w e:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-02-14 22:42 717,296 ----a-w e:\windows\system32\drivers\sptd.sys
2009-02-14 22:42 --------- d-----w e:\documents and settings\m\Dane aplikacji\DAEMON Tools Lite
2009-01-31 01:04 --------- d-----w e:\documents and settings\m\Dane aplikacji\BSplayer PRO
2006-06-23 06:48 53,248 ----a-r e:\windows\inf\UpdateUSB.exe
.
------- Sigcheck -------
2008-04-15 13:00 1053184 d2a5b75e00856161772f7ba77a7e601b e:\windows\explorer.exe
2008-04-15 13:00 33280 18e40f2b7c081d91b4cdd7dc38cf387b e:\windows\system32\ctfmon.exe
2008-04-15 13:00 44544 6984341cb15b137fb8ec1ed7ede6ee5f e:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2008-12-08 13594624]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2008-12-08 86016]
"nwiz"="nwiz.exe" [2008-12-08 e:\windows\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 e:\windows\system32\bthprops.cpl]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="e:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-18 00:51 10520 e:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Bluetooth Manager.lnk]
path=e:\documents and settings\All Users\Menu Start\Programy\Autostart\Bluetooth Manager.lnk
backup=e:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
--a------ 2008-08-14 07:58 611712 e:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2009-02-18 00:51 1601304 e:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControl]
--a------ 2006-10-14 10:37 131072 e:\windows\ATK0100\HControl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2007-02-21 11:17 991232 e:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2007-02-21 11:19 839680 e:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-12-08 17:42 13594624 e:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-12-08 17:42 86016 e:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2009-03-11 12:00 24095528 e:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2006-05-25 13:02 786521 e:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 90112 e:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-12-08 17:42 1657376 e:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2007-03-21 07:49 16146432 e:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvCplDaemon"=RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\SoulseekNS\\slsk.exe"=
"e:\\Program Files\\Gadu-Gadu\\gg.exe"=
"e:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"e:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 AvgLdx86;AVG Free AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [2009-02-18 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;e:\windows\system32\drivers\avgtdix.sys [2009-02-18 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;e:\progra~1\AVG\AVG8\avgemc.exe [2009-02-18 903960]
R2 avg8wd;AVG Free8 WatchDog;e:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-18 298264]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;e:\windows\system32\StkCSrv.exe [2008-12-20 45056]
R3 StkCMini;Syntek AVStream USB2.0 2M WebCam;e:\windows\system32\drivers\StkCMini.sys [2008-12-20 1245056]
S2 tdctxte;tdctxte Service;e:\windows\system32\tdctxte.exe --> e:\windows\system32\tdctxte.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{242a5ce6-0da2-11de-a05b-001e8c39b7ce}]
\Shell\AutoRun\command - WScript.exe .\`.vbs
\Shell\open\Command - WScript.exe .\`.vbs
.
Zawartość folderu 'Zaplanowane zadania'
2009-03-28 e:\windows\Tasks\el.job
- e:\windows\system32\regsvr32.exe [2008-04-15 13:00]
2009-03-28 e:\windows\Tasks\elu.job
- e:\windows\system32\cmd.exe [2008-04-15 13:00]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
MSConfigStartUp-el - e:\windows\system32\el32.dll
MSConfigStartUp-SMSERIAL - e:\program files\Motorola\SMSERIAL\sm56hlpr.exe
.
------- Skan uzupełniający -------
.
TCP: {17BDE057-B69F-4E96-B293-D30CB0E593B8} = 192.168.0.1
TCP: {29DF8E0E-67A6-4640-BB84-F7D3E7962F53} = 192.168.0.2
FF - ProfilePath - e:\documents and settings\m\Dane aplikacji\Mozilla\Firefox\Profiles\jasg560f.default\
FF - component: e:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 18:57:57
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
e:\program files\Intel\Wireless\Bin\S24EvMon.exe
e:\program files\Intel\Wireless\Bin\EvtEng.exe
e:\windows\system32\nvsvc32.exe
e:\program files\Intel\Wireless\Bin\RegSrvc.exe
e:\program files\AVG\AVG8\avgrsx.exe
e:\progra~1\AVG\AVG8\avgnsx.exe
e:\program files\AVG\AVG8\avgcsrvx.exe
e:\windows\system32\rundll32.exe
e:\windows\system32\rundll32.exe
e:\windows\system32\rundll32.exe
C:\A.tmp
.
**************************************************************************
.
Czas ukończenia: 2009-03-28 18:59:52 - komputer został uruchomiony ponownie [m]
ComboFix-quarantined-files.txt 2009-03-28 17:59:49
Przed: 3 131 125 760 bajtów wolnych
Po: 4,921,073,664 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
247 --- E O F --- 2008-12-24 17:13:48