Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 10-02-27.04 - m3dioN 2010-02-27 22:28:25.2.2 - x86
- Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.3327.2558 [GMT 1:00]
- Uruchomiony z: c:\documents and settings\m3dioN\Pulpit\cf.exe
- AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
- FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
- UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
- .
- ((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\windows\system32\twain_32.dll
- .
- ((((((((((((((((((((((((( Pliki utworzone od 2010-01-27 do 2010-02-27 )))))))))))))))))))))))))))))))
- .
- 2099-11-21 21:18 . 2099-11-21 21:18 -------- d-----w- c:\program files\FlashFXP
- 2010-02-27 20:24 . 2010-02-27 20:24 -------- d-----w- c:\program files\Trend Micro
- 2010-02-27 16:35 . 2010-02-27 16:35 -------- d-----w- c:\windows\LastGood
- 2010-02-25 22:24 . 2010-02-25 22:24 -------- d-----w- c:\documents and settings\m3dioN\Ustawienia lokalne\Dane aplikacji\DFX
- 2010-02-25 22:23 . 2010-02-25 22:23 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\DFX
- 2010-02-25 22:23 . 2010-02-25 22:27 -------- d-----w- c:\program files\DFX
- 2010-02-25 22:23 . 2010-02-25 22:23 -------- d-----w- c:\program files\Common Files\DFX
- 2010-02-25 22:07 . 2010-02-25 23:17 -------- d-----w- c:\temp\pages
- 2010-02-22 00:43 . 2010-02-22 00:51 15406728 ----a-w- c:\windows\system32\xlive.dll
- 2010-02-22 00:42 . 2010-02-22 00:51 15406728 ----a-w- c:\program files\xlive.dll
- 2010-02-21 18:12 . 2010-02-21 18:12 316736 ----a-w- c:\program files\Paul.dll
- 2010-02-21 18:12 . 2010-02-21 18:15 14523016 ----a-w- c:\program files\GTAIV.exe
- 2010-02-21 18:04 . 2010-02-21 18:05 5109704 ----a-w- c:\program files\lol.exe
- 2010-02-21 00:04 . 2010-02-21 00:04 -------- d-----w- c:\temp\backup-Feb-21-2010-1
- 2010-02-16 18:50 . 2010-02-16 18:50 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\Publish Providers
- 2010-02-16 18:48 . 2010-02-16 18:50 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\Sony
- 2010-02-16 18:48 . 2010-02-16 18:48 -------- d-----w- c:\documents and settings\m3dioN\Ustawienia lokalne\Dane aplikacji\Sony
- 2010-02-16 18:45 . 2010-02-16 18:45 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Sony
- 2010-02-16 18:45 . 2010-02-16 18:45 -------- d-----w- c:\program files\Sony
- 2010-02-14 20:27 . 2010-02-15 00:31 -------- d-----w- C:\Converted Music
- 2010-02-14 04:42 . 2009-11-13 13:00 1048576 ---h--r- C:\K50AB.BIN
- 2010-02-13 22:29 . 2009-04-06 08:08 4682 ----a-w- c:\windows\system32\npptNT2.sys
- 2010-02-13 22:05 . 2010-02-13 22:05 -------- d-----w- c:\program files\NCsoft
- 2010-02-11 03:16 . 2010-02-11 03:16 41872 ----a-w- c:\windows\system32\xfcodec.dll
- 2010-02-07 21:13 . 2010-02-07 21:14 -------- d-----w- c:\program files\Windows Media Connect 2
- 2010-02-05 22:45 . 2010-02-26 05:13 -------- d-----w- C:\Fraps
- 2010-02-04 00:55 . 2010-02-04 00:55 -------- d-----w- c:\program files\CCleaner
- 2010-02-03 20:36 . 2010-02-03 20:36 -------- d-----w- c:\program files\hc
- 2010-02-01 15:43 . 2009-02-07 06:43 24576 ----a-w- c:\documents and settings\m3dioN\Dane aplikacji\Mozilla\Firefox\Profiles\8jdis1iq.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
- .
- (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-02-27 21:21 . 2009-03-09 23:29 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
- 2010-02-27 17:50 . 2009-11-03 13:44 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\vlc
- 2010-02-27 16:42 . 2009-03-09 23:03 -------- d-----w- c:\program files\Steam
- 2010-02-27 16:30 . 2009-09-06 00:18 1851768 ----a-w- c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
- 2010-02-27 14:25 . 2009-03-09 22:23 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\FileZilla
- 2010-02-27 14:22 . 2009-03-09 21:15 82352 ----a-w- c:\documents and settings\m3dioN\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
- 2010-02-26 21:56 . 2009-03-09 23:07 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\Xfire
- 2010-02-25 23:04 . 2009-09-03 23:44 -------- d-----w- c:\program files\IrfanView
- 2010-02-25 18:47 . 2010-02-25 18:43 6229619 ----a-w- c:\program files\Front Flip_720p.wmv
- 2010-02-25 17:49 . 2009-03-09 22:23 -------- d-----w- c:\program files\FileZilla FTP Client
- 2010-02-25 02:15 . 2009-03-09 23:07 -------- d-----w- c:\program files\Xfire
- 2010-02-24 14:50 . 2010-02-24 14:50 382 ----a-w- c:\program files\Skrót do Program Files.lnk
- 2010-02-23 15:52 . 2009-12-29 14:02 1984 ----a-w- c:\windows\system32\d3d9caps.dat
- 2010-02-22 15:54 . 2009-09-04 13:43 -------- d-----w- c:\program files\Rockstar Games
- 2010-02-22 15:54 . 2009-03-09 21:07 -------- d--h--w- c:\program files\InstallShield Installation Information
- 2010-02-21 20:09 . 2010-02-21 20:09 954356 ----a-w- c:\program files\pliki_gtaiv_SNT.rar
- 2010-02-20 01:03 . 2009-09-11 20:30 -------- d---a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP
- 2010-02-14 04:40 . 2009-03-09 21:37 -------- d-----w- c:\program files\ASUS
- 2010-02-14 04:18 . 2009-09-13 17:13 -------- d-----w- c:\program files\uTorrent
- 2010-02-13 22:00 . 2010-01-21 17:39 -------- d-----w- c:\program files\Lineage II
- 2010-02-13 21:18 . 2009-09-13 17:11 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\uTorrent
- 2010-02-11 23:52 . 2010-01-10 23:49 -------- d-----w- c:\program files\German Truck Simulator
- 2010-02-04 00:15 . 2009-12-13 09:32 -------- d-----w- c:\program files\Codemasters
- 2010-02-03 23:58 . 2009-11-03 13:46 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\dvdcss
- 2010-01-30 14:34 . 2009-11-15 00:35 1738 ----a-w- c:\documents and settings\m3dioN\tasks.dat
- 2010-01-30 12:37 . 2009-11-15 00:33 185344 ----a-w- c:\documents and settings\m3dioN\XPTable.dll
- 2010-01-30 12:37 . 2009-11-15 00:33 750592 ----a-w- c:\documents and settings\m3dioN\YgoowCore.dll
- 2010-01-30 12:37 . 2009-11-15 00:33 1015808 ----a-w- c:\documents and settings\m3dioN\Ygoow.exe
- 2010-01-29 21:22 . 2009-10-07 16:41 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
- 2010-01-29 21:22 . 2009-10-07 16:41 171552 ----a-w- c:\windows\system32\guard32.dll
- 2010-01-29 21:22 . 2009-10-07 16:41 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
- 2010-01-29 21:22 . 2009-10-07 16:41 134344 ----a-w- c:\windows\system32\drivers\cmdguard.sys
- 2010-01-20 13:34 . 2009-09-10 14:56 -------- d-----w- c:\program files\Sony Ericsson
- 2010-01-18 00:14 . 2009-03-09 23:51 -------- d-----w- c:\program files\Euro Truck Simulator
- 2010-01-17 22:29 . 2010-01-17 22:29 -------- d-----w- c:\program files\Kopia Euro Truck Simulator
- 2010-01-16 19:56 . 2009-10-24 12:59 -------- d-----w- c:\program files\Atari
- 2010-01-16 17:12 . 2010-01-07 15:39 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\VMware
- 2010-01-15 00:19 . 2010-01-15 00:19 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\NeatImage SL
- 2010-01-15 00:19 . 2010-01-15 00:19 -------- d-----w- c:\program files\Neat Image
- 2010-01-14 20:52 . 2010-01-14 20:52 -------- d-----w- c:\program files\Intuwave
- 2010-01-14 20:52 . 2010-01-14 20:52 -------- d-----w- c:\program files\Symbian
- 2010-01-14 20:51 . 2010-01-14 20:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Sony Ericsson
- 2010-01-14 20:51 . 2009-10-02 22:37 -------- d-----w- c:\program files\Common Files\Teleca Shared
- 2010-01-14 20:51 . 2010-01-14 20:51 -------- d-----w- c:\program files\Common Files\Sony Ericsson Shared
- 2010-01-14 20:51 . 2010-01-14 20:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Teleca
- 2010-01-13 12:08 . 2010-01-13 12:08 -------- d-----w- c:\program files\Eidos
- 2010-01-12 23:05 . 2010-01-12 23:05 2855 ----a-w- c:\windows\PIF\setup.PIF
- 2010-01-10 21:17 . 2009-09-10 14:56 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\Teleca
- 2010-01-10 21:16 . 2010-01-10 21:16 146 ----a-w- c:\windows\DelMR.bat
- 2010-01-10 20:54 . 2010-01-10 20:54 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
- 2010-01-10 20:22 . 2010-01-10 20:22 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
- 2010-01-10 01:10 . 2010-01-10 01:10 -------- d-----w- c:\program files\MSXML 6.0
- 2010-01-07 15:41 . 2010-01-07 15:39 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\VMware
- 2010-01-07 15:35 . 2010-01-07 15:35 -------- d-----w- c:\program files\VMware
- 2010-01-05 21:55 . 2010-01-05 21:55 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
- 2010-01-05 21:55 . 2010-01-05 21:55 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
- 2010-01-05 21:55 . 2010-01-05 21:55 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
- 2010-01-05 00:31 . 2010-01-05 00:31 -------- d-----w- c:\program files\Common Files\Borland Shared
- 2010-01-04 23:45 . 2009-09-15 20:46 -------- d-----w- c:\program files\Common Files\Adobe
- 2010-01-02 18:18 . 2010-01-02 18:18 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\IrfanView
- 2010-01-02 00:56 . 2010-01-02 00:56 -------- d-----w- c:\program files\Ray Adams
- 2010-01-01 22:21 . 2010-01-01 22:21 -------- d-----w- c:\documents and settings\m3dioN\Dane aplikacji\IObit
- 2010-01-01 22:21 . 2010-01-01 22:21 -------- d-----w- c:\program files\IObit
- 2009-12-21 19:08 . 2008-04-15 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
- 2009-12-13 14:17 . 2009-12-13 14:17 10134 ----a-r- c:\documents and settings\m3dioN\Dane aplikacji\Microsoft\Installer\{20820A45-02A1-144C-21A3-A1812C5DDE23}\ARPPRODUCTICON.exe
- 2009-12-13 11:01 . 2008-04-15 12:00 85114 ----a-w- c:\windows\system32\perfc015.dat
- 2009-12-13 11:01 . 2008-04-15 12:00 493870 ----a-w- c:\windows\system32\perfh015.dat
- 2009-12-08 22:11 . 2009-12-08 22:11 0 ----a-w- c:\windows\nsreg.dat
- 2009-12-08 18:34 . 2009-11-27 21:52 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
- 2009-11-30 22:07 . 2009-11-27 21:53 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
- .
- ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
- REGEDIT4
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-04-21 534528]
- "HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-04-30 33619968]
- "MsgTranAgt"="c:\program files\ASUS\ATK Hotkey\MsgTranAgt.exe" [2008-08-18 117304]
- "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-08-18 98304]
- "ATKHOTKEY"="c:\program files\ASUS\ATK Hotkey\HControl.exe" [2009-03-20 174648]
- "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2009-04-07 159744]
- "ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
- "Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2007-07-05 1040384]
- "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-09 61440]
- "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
- "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-01-29 1800464]
- "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
- "AppInit_DLLs"=c:\windows\system32\guard32.dll
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
- @="Driver"
- [HKLM\~\startupfolder\C:^Documents and Settings^m3dioN^Menu Start^Programy^Autostart^smgr32.exe]
- backup=c:\windows\pss\smgr32.exeStartup
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
- 2009-06-16 18:56 540672 ----a-w- c:\program files\ASUS\Splendid\ACMON.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Internet Security]
- 2010-01-29 21:22 1800464 ----a-w- c:\program files\COMODO\COMODO Internet Security\cfp.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
- 2008-04-15 12:00 15360 ------w- c:\windows\system32\ctfmon.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
- 2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
- 2001-07-09 08:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 2]
- 2007-07-05 15:53 1040384 ----a-w- c:\program files\Wireless Console 2\wcourier.exe
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
- "EnableFirewall"= 0 (0x0)
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
- "c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
- "c:\\Program Files\\uTorrent\\uTorrent.exe"=
- "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
- "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
- "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
- "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
- "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
- "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
- "c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
- "c:\\Program Files\\Opera\\opera.exe"=
- "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
- "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
- R1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 18088]
- R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-10-07 134344]
- R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-10-07 25160]
- R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2009-03-09 89856]
- R3 evserial;Virtual Serial Ports Driver (Eltima Softwate);c:\windows\system32\drivers\evserial.sys [2009-09-11 53888]
- R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-03-09 22072]
- R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-03-09 1131264]
- R3 VSBC;Virtual Serial Bus Enumerator (Eltima Software);c:\windows\system32\drivers\evsbc.sys [2009-09-11 27904]
- S3 96EW;96EW Filter;c:\windows\system32\drivers\96EW.sys [2009-12-14 20480]
- S3 CRFILTER;USB Mass Storage Filter;c:\windows\system32\drivers\CRFILTER.sys [2008-04-07 6656]
- S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\m3dioN\USTAWI~1\Temp\MLZ2A36.tmp --> c:\docume~1\m3dioN\USTAWI~1\Temp\MLZ2A36.tmp [?]
- S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-01-05 13224]
- S3 gggen;Generic USB Flash Driver;c:\windows\system32\drivers\gggen.sys [2009-09-11 11648]
- S3 ntportio;ntportio;\??\c:\documents and settings\m3dioN\Pulpit\SEMCtool_v8.4\ntportio.sys --> c:\documents and settings\m3dioN\Pulpit\SEMCtool_v8.4\ntportio.sys [?]
- S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [2004-01-23 13952]
- S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [2004-01-23 28800]
- S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [2009-10-02 83208]
- S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [2009-10-02 15112]
- S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [2009-10-02 108680]
- S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [2009-10-02 100488]
- S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [2009-10-02 98568]
- .
- .
- ------- Skan uzupełniający -------
- .
- uStart Page = hxxp://www.google.com/
- uInternet Settings,ProxyOverride = *.local
- uSearchAssistant = hxxp://www.google.com/ie
- uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
- IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
- TCP: {21548931-1FD7-47A6-9EF6-0D12A1F158B3} = 208.67.220.220,208.67.222.222
- FF - ProfilePath - c:\documents and settings\m3dioN\Dane aplikacji\Mozilla\Firefox\Profiles\8jdis1iq.default\
- FF - prefs.js: browser.startup.homepage - google.pl
- FF - component: c:\documents and settings\m3dioN\Dane aplikacji\Mozilla\Firefox\Profiles\8jdis1iq.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
- FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
- ---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
- .
- **************************************************************************
- disk not found C:\
- please note that you need administrator rights to perform deep scan
- skanowanie ukrytych procesów ...
- skanowanie ukrytych wpisów autostartu ...
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run
- HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
- skanowanie ukrytych plików ...
- skanowanie pomyślnie ukończone
- ukryte pliki:
- **************************************************************************
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
- "ImagePath"="\??\c:\docume~1\m3dioN\USTAWI~1\Temp\MLZ2A36.tmp"
- .
- --------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
- [HKEY_USERS\S-1-5-21-2052111302-842925246-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
- "??"=hex:e8,20,b5,81,7e,c7,a1,7b,63,c5,cb,bb,df,6a,31,e0,ab,aa,e0,59,33,4d,95,
- 17,c3,ef,a5,56,1a,e1,16,31,ab,f3,c1,6c,ba,8e,32,2c,7e,9b,c9,76,38,17,ff,b7,\
- "??"=hex:be,c9,a6,3f,53,2e,4c,13,c9,34,3f,6b,6d,86,cd,6f
- [HKEY_USERS\S-1-5-21-2052111302-842925246-1801674531-1003\Software\SecuROM\License information*]
- "datasecu"=hex:ca,5f,07,6a,7e,f2,a1,62,a4,fc,9a,45,82,84,71,5b,55,a9,33,00,d3,
- 68,8b,fc,02,54,a0,db,d9,36,8a,2d,38,6d,69,d7,c4,7c,a9,0e,ee,7a,4c,d9,8d,56,\
- "rkeysecu"=hex:5d,7c,7f,06,b2,19,11,4f,13,7d,87,43,75,df,0e,ea
- .
- --------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - - > 'winlogon.exe'(724)
- c:\windows\system32\guard32.dll
- c:\windows\system32\Ati2evxx.dll
- - - - - - - - > 'lsass.exe'(780)
- c:\windows\system32\guard32.dll
- .
- Czas ukończenia: 2010-02-27 22:39:14
- ComboFix-quarantined-files.txt 2010-02-27 21:39
- Przed: 40 411 611 136 bajtów wolnych
- Po: 40 531 587 072 bajtów wolnych
- - - End Of File - - 841B8B4C825050E46BF0571040820632
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement