przez Maniol9 01 Lis 2008, 00:23
kaspersky mi wykryl 2 keyloggery... niewiem jak je usunac nie muszac sciagac instalki gry od nowa. zamieszczam logi z hijackthis i combofixa. Prosze o pomoc .
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:34:40, on 2008-11-01
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\cFosSpeed\spd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ManioL\Pulpit\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe
O4 - HKCU\..\Run: [HEXelon MAX] "C:\Program Files\HEXelon MAX 6\hexelon.exe" /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\cFosSpeed\spd.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 3706 bytes
- Kod: Zaznacz wszystko
ComboFix 08-10-30.13 - ManioL 2008-10-31 23:17:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.727 [GMT 1:00]
Uruchomiony z: C:\Documents and Settings\ManioL\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-28 do 2008-10-31 )))))))))))))))))))))))))))))))
.
2008-10-31 22:44 . 2008-10-31 22:47 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-31 22:44 . 2008-10-31 22:47 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-10-31 21:51 . 2008-10-31 21:51 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-31 21:51 . 2008-10-31 21:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-10-31 18:58 . 2008-10-31 18:58 <DIR> d-------- C:\WINDOWS\LastGood
2008-10-28 06:29 . 2008-07-03 18:04 732,376 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys
2008-10-28 06:28 . 2008-10-31 23:19 <DIR> d-------- C:\Program Files\cFosSpeed
2008-10-28 06:28 . 2008-07-03 18:04 290,008 --a------ C:\WINDOWS\system32\cfosspeed.dll
2008-10-27 15:19 . 2008-10-27 15:19 <DIR> d-------- C:\Program Files\Ventrilo
2008-10-27 15:19 . 2008-10-31 21:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-26 21:57 . 2008-10-27 15:04 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\Ventrilo
2008-10-24 05:57 . 2008-10-24 05:57 <DIR> d-------- C:\Program Files\DivX
2008-10-24 04:47 . 2008-10-24 04:47 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-10-24 04:42 . 2008-10-24 04:42 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-10-24 04:42 . 2008-10-24 04:42 <DIR> d-------- C:\Program Files\Ahead
2008-10-24 04:42 . 2004-07-26 16:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-10-24 04:42 . 2004-07-26 16:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-10-24 04:42 . 2004-07-26 16:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-10-24 04:42 . 2004-07-26 16:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-10-24 04:42 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-10-24 04:42 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-10-23 15:09 . 2008-10-31 18:53 <DIR> d-------- C:\Program Files\eMule
2008-10-23 07:02 . 2004-08-03 22:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-10-23 06:45 . 2008-10-23 06:45 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-10-23 06:43 . 2008-10-23 06:43 <DIR> d-------- C:\Documents and Settings\NetworkService\Menu Start
2008-10-23 06:41 . 2008-10-23 06:41 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-10-22 22:06 . 2008-10-24 04:43 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-10-22 22:03 . 2008-10-22 22:03 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-10-22 22:00 . 2004-07-17 10:40 19,528 --a------ C:\WINDOWS\[u]0[/u]02364_.tmp
2008-10-22 21:59 . 2004-08-03 21:43 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-10-22 21:57 . 2008-10-22 22:05 <DIR> d-------- C:\WINDOWS\EHome
2008-10-22 15:59 . 2005-11-11 06:47 7,311,360 --a------ C:\WINDOWS\system32\nvcpl.dll
2008-10-22 15:59 . 2005-11-11 06:47 5,394,432 --a------ C:\WINDOWS\system32\nvoglnt.dll
2008-10-22 15:59 . 2005-11-11 06:47 3,924,992 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-10-22 15:59 . 2005-11-11 06:47 3,532,928 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-10-22 15:59 . 2005-11-11 06:47 573,440 --a------ C:\WINDOWS\system32\nvhwvid.dll
2008-10-22 15:59 . 2005-11-11 06:47 286,720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2008-10-22 15:59 . 2005-11-11 06:47 229,376 --a------ C:\WINDOWS\system32\nvmccs.dll
2008-10-22 15:59 . 2005-11-11 06:47 131,139 --a------ C:\WINDOWS\system32\nvsvc32.exe
2008-10-22 15:59 . 2005-11-11 06:47 86,016 --a------ C:\WINDOWS\system32\nvmctray.dll
2008-10-22 15:59 . 2005-11-11 06:47 86,016 --a------ C:\WINDOWS\system32\nvapi.dll
2008-10-22 15:59 . 2005-11-11 06:47 81,920 --a------ C:\WINDOWS\system32\nvwddi.dll
2008-10-22 15:59 . 2005-11-11 06:47 35,328 --a------ C:\WINDOWS\system32\nvcod.dll
2008-10-22 05:41 . 2008-10-22 05:41 <DIR> d-------- C:\Program Files\CCleaner
2008-10-21 22:36 . 2008-10-21 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-10-21 07:49 . 2008-10-21 07:49 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-10-21 07:49 . 2008-10-21 07:49 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-10-21 07:49 . 2008-10-21 07:49 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-10-21 07:49 . 2008-10-31 21:50 60,416 --a------ C:\WINDOWS\ALCFDRTM.VER
2008-10-21 07:49 . 2008-10-21 07:49 60,416 --a------ C:\WINDOWS\ALCFDRTM.EXE
2008-10-21 07:27 . 2008-10-21 07:27 <DIR> d-------- C:\Program Files\EA Sports
2008-10-21 07:26 . 2005-05-26 14:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-10-21 07:23 . 2008-10-21 07:23 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-10-21 07:23 . 2008-10-21 07:23 <DIR> d-------- C:\Program Files\D-Tools
2008-10-21 07:23 . 2004-08-22 15:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-10-21 07:23 . 2004-08-22 15:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-10-20 17:26 . 2008-10-20 17:26 <DIR> d-------- C:\Program Files\HEXelon MAX 6
2008-10-20 17:26 . 2008-10-20 17:26 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\HEXelon
2008-10-20 12:05 . 2008-10-31 18:52 <DIR> d-------- C:\Program Files\DNA
2008-10-20 12:05 . 2008-10-20 12:05 <DIR> d-------- C:\Program Files\BitTorrent
2008-10-20 12:05 . 2008-10-31 23:13 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\DNA
2008-10-20 12:05 . 2008-10-30 22:21 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\BitTorrent
2008-10-19 22:24 . 2008-10-19 22:24 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-10-19 15:35 . 2008-10-19 15:35 <DIR> d-------- C:\WINDOWS\system32\msmq
2008-10-19 13:57 . 2008-10-19 13:57 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\Gadu-Gadu
2008-10-18 22:03 . 2008-10-23 06:59 <DIR> d-------- C:\Program Files\Odkurzacz
2008-10-18 21:55 . 2008-10-18 21:55 1,181 --a------ C:\WINDOWS\mozver.dat
2008-10-18 21:52 . 2008-10-18 21:52 <DIR> d-------- C:\Perfect World
2008-10-18 21:48 . 2005-04-05 20:22 261,888 -ra------ C:\WINDOWS\system32\drivers\nvnrm.sys
2008-10-18 21:48 . 2005-04-05 20:22 208,256 -ra------ C:\WINDOWS\system32\drivers\nvsnpu.sys
2008-10-18 21:48 . 2005-04-05 20:19 201,728 -ra------ C:\WINDOWS\system32\fdco1ins.dll
2008-10-18 21:48 . 2005-04-05 20:19 201,728 -ra------ C:\WINDOWS\system32\fdco1.dll
2008-10-18 21:48 . 2005-04-04 11:59 176,128 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-10-18 21:48 . 2005-04-05 20:22 33,536 -ra------ C:\WINDOWS\system32\drivers\NVENETFD.sys
2008-10-18 21:48 . 2005-04-04 12:00 32,256 -ra------ C:\WINDOWS\system32\nvconrm.dll
2008-10-18 21:48 . 2005-04-05 20:22 12,928 -ra------ C:\WINDOWS\system32\drivers\nvnetbus.sys
2008-10-18 21:48 . 2005-04-05 20:19 9,728 -ra------ C:\WINDOWS\system32\bdco1ins.dll
2008-10-18 21:48 . 2005-04-05 20:19 9,728 -ra------ C:\WINDOWS\system32\bdco1.dll
2008-10-18 21:48 . 2005-02-08 07:26 3,596 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-10-18 21:38 . 2008-10-18 21:38 <DIR> d-------- C:\NVIDIA
2008-10-18 21:20 . 2008-10-31 18:54 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\skypePM
2008-10-18 21:20 . 2008-06-30 08:35 258,352 -ra------ C:\WINDOWS\system32\unicows.dll
2008-10-18 21:20 . 2008-10-18 21:20 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-18 21:19 . 2008-10-18 21:19 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\nView_Profiles
2008-10-18 21:17 . 2008-10-18 21:17 <DIR> d-------- C:\Program Files\Skype
2008-10-18 21:17 . 2008-10-31 18:59 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\Skype
2008-10-18 21:16 . 2008-10-18 21:16 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-10-18 21:16 . 2008-10-18 21:16 <DIR> d-------- C:\Documents and Settings\ManioL\Dane aplikacji\Talkback
2008-10-18 21:16 . 2008-10-18 21:17 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-10-18 21:16 . 2008-10-18 21:16 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 16:43 98,304 ----a-w C:\WINDOWS\DUMP5091.tmp
2008-10-31 15:42 98,304 ----a-w C:\WINDOWS\DUMP4a57.tmp
2008-10-18 18:54 --------- d-----w C:\Program Files\Gadu-Gadu
2008-10-18 18:51 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-10-18 18:51 --------- d-----w C:\Program Files\Realtek AC97
2008-10-18 18:51 --------- d-----w C:\Program Files\AvRack
2008-10-18 18:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-18 18:50 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-18 18:07 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-18 18:04 --------- d-----w C:\Program Files\Usługi online
2008-09-19 21:55 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-06-03 21718312]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-08-16 264704]
"HEXelon MAX"="C:\Program Files\HEXelon MAX 6\hexelon.exe" [2007-06-28 2816512]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2008-08-01 5480448]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 81920]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 159744]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 C:\WINDOWS\soundman.exe]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-10-20 12:05 342336 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cFosSpeed]
-ra------ 2008-07-03 18:04 867544 C:\Program Files\cFosSpeed\cfosspeed.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-03 23:44 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-11-11 06:47 7311360 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2005-11-11 06:47 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsmqIntCert]
--a------ 2004-08-03 23:44 177152 C:\WINDOWS\system32\mqrt.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Polish\\setup.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R4 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [ ]
*Newly Created Service* - AAWSERVICE
*Newly Created Service* - PROCEXP90
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\ManioL\Dane aplikacji\Mozilla\Firefox\Profiles\pkcm7441.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 23:19:18
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
PROCES: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\klogon.dll
.
Czas ukończenia: 2008-10-31 23:20:29
ComboFix-quarantined-files.txt 2008-10-31 22:20:23
Przed: 76 912 984 064 bajtów wolnych
Po: 76,898,304,000 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
193
TO JEST CALY LOG Z HIJACK :|
Ostatnio edytowany przez
Maniol9 01 Lis 2008, 18:36, edytowano w sumie 2 razy