ComboFix 11-11-06.01 - Pavilion dv5 2011-11-06 12:23:54.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.48.1045.18.3038.1955 [GMT 1:00] Uruchomiony z: c:\users\Pavilion dv5\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Utworzono nowy punkt przywracania . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\IsUn0415.exe . . ((((((((((((((((((((((((( Pliki utworzone od 2011-10-06 do 2011-11-06 ))))))))))))))))))))))))))))))) . . 2011-11-06 11:31 . 2011-11-06 11:31 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{96174535-A1ED-466B-89F2-1E953DD74C21}\offreg.dll 2011-11-04 14:52 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{96174535-A1ED-466B-89F2-1E953DD74C21}\mpengine.dll 2011-10-30 10:26 . 2011-10-30 10:26 -------- d-----w- c:\program files\Common Files\PX Storage Engine 2011-10-30 10:25 . 2011-10-30 10:37 -------- d-----w- c:\program files\Winamp 2011-10-26 20:28 . 2011-10-26 20:28 -------- d-----w- c:\program files\Codemasters 2011-10-26 20:26 . 2003-02-27 14:12 696320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll 2011-10-26 20:26 . 2002-12-05 12:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll 2011-10-26 20:26 . 2002-12-02 13:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe 2011-10-26 20:26 . 2002-12-02 11:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll 2011-10-26 20:26 . 2002-12-02 11:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll 2011-10-26 20:26 . 2011-10-26 20:26 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll 2011-10-26 20:26 . 2011-10-26 20:26 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll 2011-10-25 22:00 . 2011-10-25 22:00 -------- d-----w- c:\users\Pavilion dv5\Cisco Packet Tracer 5.3.2 2011-10-24 22:04 . 2011-10-24 22:04 -------- d-----w- c:\users\Pavilion dv5\AppData\Roaming\Nokia Ovi Suite 2011-10-24 22:04 . 2011-10-24 22:04 -------- d-----w- c:\users\Pavilion dv5\AppData\Roaming\Nokia 2011-10-24 22:04 . 2011-10-24 22:04 -------- d-----w- c:\programdata\Nokia 2011-10-24 22:01 . 2009-07-14 17:48 567808 ----a-w- c:\windows\system32\WUDFx.dll 2011-10-24 22:01 . 2009-07-14 17:48 64512 ----a-w- c:\windows\system32\WUDFSvc.dll 2011-10-24 22:01 . 2009-07-14 17:48 39936 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2011-10-24 22:01 . 2009-07-14 17:48 162304 ----a-w- c:\windows\system32\WUDFPlatform.dll 2011-10-24 22:01 . 2009-07-14 17:45 92672 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2011-10-24 22:01 . 2009-07-14 17:45 195584 ----a-w- c:\windows\system32\WUDFHost.exe 2011-10-24 22:01 . 2009-07-14 17:45 132224 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2011-10-24 18:45 . 2011-10-24 22:01 -------- d-----w- c:\programdata\PC Suite 2011-10-24 18:45 . 2011-10-24 18:45 -------- d-----w- c:\users\Pavilion dv5\AppData\Local\Nokia 2011-10-24 18:44 . 2011-10-27 19:47 -------- d-----w- c:\users\Pavilion dv5\AppData\Roaming\PC Suite 2011-10-24 18:42 . 2011-10-24 18:43 -------- d-----w- c:\program files\Common Files\Nokia 2011-10-24 18:42 . 2011-10-24 18:42 -------- d-----w- c:\program files\DIFX 2011-10-24 18:42 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys 2011-10-24 18:42 . 2011-10-24 18:42 -------- d-----w- c:\program files\PC Connectivity Solution 2011-10-24 18:41 . 2011-05-18 08:13 75264 ----a-w- c:\windows\system32\nmwcdcls.dll 2011-10-24 18:41 . 2011-10-24 18:42 -------- d-----w- c:\program files\Nokia 2011-10-17 11:39 . 2011-10-17 11:39 -------- d-----w- c:\users\Pavilion dv5\AppData\Roaming\OpenOffice.org 2011-10-17 11:29 . 2011-10-17 11:29 -------- d-----w- c:\program files\OpenOffice.org 3 2011-10-13 18:20 . 2011-09-06 13:30 2043392 ----a-w- c:\windows\system32\win32k.sys 2011-10-13 18:20 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll 2011-10-13 18:20 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax 2011-10-13 18:20 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax 2011-10-13 18:20 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax 2011-10-13 18:20 . 2011-09-14 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-10-13 18:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll 2011-10-13 18:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll 2011-10-13 18:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll 2011-10-13 18:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll 2011-10-11 18:13 . 2011-10-11 18:13 -------- d-----w- c:\users\Pavilion dv5\AppData\Roaming\Nero 2011-10-11 18:03 . 2011-10-11 18:11 -------- d-----w- c:\programdata\Nero 2011-10-11 17:59 . 2011-07-13 11:39 12464 ----a-w- c:\windows\system32\drivers\NBVolUp.sys 2011-10-11 17:59 . 2011-07-13 11:39 56496 ----a-w- c:\windows\system32\drivers\NBVol.sys 2011-10-11 17:59 . 2011-10-24 18:42 -------- dc----w- c:\windows\system32\DRVSTORE 2011-10-11 17:59 . 2011-10-12 18:52 -------- d-----w- c:\program files\Nero 2011-10-11 17:53 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll 2011-10-11 17:53 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll 2011-10-11 17:53 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll 2011-10-11 17:53 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll 2011-10-11 17:53 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll 2011-10-08 20:33 . 2011-10-08 20:33 -------- d-----w- c:\users\Pavilion dv5\AppData\Roaming\HP 2011-10-08 20:33 . 2011-10-08 20:33 -------- d-----w- c:\programdata\HP . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-03 20:02 . 2011-07-07 23:56 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2011-02-04 2346496] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-12 699456] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-11-02 365336] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-21 458844] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\kloehk.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKLM\~\startupfolder\C:^Users^Pavilion dv5^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk] path=c:\users\Pavilion dv5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer] c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser] 2010-11-04 20:09 980368 ----a-w- c:\progra~1\Eraser\Eraser.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2] 2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService] 2008-04-23 21:51 468264 ----a-w- c:\program files\HP\QuickPlay\QPService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2011-06-15 13:02 15141768 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2011-04-08 10:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;f:\programy\BitComet\tools\BitCometService.exe [x] R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-02-07 193840] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-05-18 137600] R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2011-05-18 8576] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2009-10-09 98560] R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2009-10-09 14848] R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2009-10-09 123648] R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2009-10-09 100352] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [2011-07-13 56496] S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [2011-07-13 12464] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-23 218688] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104] S2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\QuickPlay\000.fcl [2008-04-23 39408] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe [2009-03-02 81920] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168] S2 KMService;KMService;c:\windows\system32\srvany.exe [2011-07-28 8192] S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-03-26 341328] S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-03-26 595248] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-24 52736] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-01 81296] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984] S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-23 43552] S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-03-26 40752] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.google.pl/ IE: &P&obierz &za pomocą BitComet - f:\programy\BitComet\BitComet.exe/AddLink.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Pobierz wszystko za pomocą BitComet - f:\programy\BitComet\BitComet.exe/AddAllLink.htm IE: Wyślij &do programu OneNote - f:\programy\MS Office\Office14\ONBttnIE.dll/105 Trusted Zone: dyndns.org\creature TCP: Interfaces\{ED5B8BE6-7560-45C5-8E90-85A98F4CBF22}: NameServer = 194.204.152.34,194.204.159.1 FF - ProfilePath - c:\users\Pavilion dv5\AppData\Roaming\Mozilla\Firefox\Profiles\db2sriwf.default\ FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - www.pustamiska.pl FF - prefs.js: network.proxy.ftp - 127.0.0.1 FF - prefs.js: network.proxy.ftp_port - 8080 FF - prefs.js: network.proxy.gopher - 5.6.7.8 FF - prefs.js: network.proxy.gopher_port - 8080 FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.socks - 127.0.0.1 FF - prefs.js: network.proxy.socks_port - 8080 FF - prefs.js: network.proxy.ssl - 127.0.0.1 FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 0 . . ------- Skojarzenia plików ------- . . - - - - USUNIĘTO PUSTE WPISY - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) SafeBoot-WudfPf SafeBoot-WudfRd MSConfigStartUp-DAEMON Tools Lite - f:\programy\DAEMON Tools Lite\DTLite.exe AddRemove-Audacity_is1 - f:\programy\Audacity\unins000.exe AddRemove-BitComet - f:\programy\BitComet\uninst.exe AddRemove-Cisco Packet Tracer 5.3.2_is1 - f:\programy\Packet tarcer\Cisco Packet Tracer 5.3.2\unins000.exe AddRemove-DAEMON Tools Lite - f:\programy\DAEMON Tools Lite\uninst.exe AddRemove-Dev-C++ - f:\programowanie\Dev-Cpp\uninstall.exe AddRemove-encyklopedia pwn.pl - c:\windows\IsUn0415.exe AddRemove-FL Studio 9 - f:\programy\FLS.XXL.9(1)\uninstall.exe AddRemove-Nvu_is1 - f:\programy\nvu 1.0\Nvu\unins000.exe AddRemove-Picasa 3 - f:\programy\Picasa3\Uninstall.exe AddRemove-reFX Nexus 1.0.9_is1 - f:\programy\FLS.XXL.9(1)\Plugins\VST\FLS.XXL.9(1)\unins000.exe AddRemove-Synthesia - f:\programy\Synthesia\uninstall.exe AddRemove-Virtual DJ - Atomix Productions - f:\programy\ATOMIX~1.0\ATOMIX~1.0\VIRTUA~1\UNWISE.EXE AddRemove-WinGimp-2.0_is1 - f:\programy\GIMP-2.0\setup\unins000.exe AddRemove-WinRAR archiver - f:\programy\WinRar\uninstall.exe AddRemove-{84D04D4F-2201-4AED-BE9A-FFA62069CA19}_is1 - f:\programy\FLS.XXL.9(1)\Plugins\VST\FLS.XXL.9(1)\Nexus\Uninstall\unins000.exe AddRemove-BankBrowser - f:\!@#$%^&\bankbrowser_3_6.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-11-06 12:34 Windows 6.0.6002 Service Pack 2 NTFS . skanowanie ukrytych procesów ... . skanowanie ukrytych wpisów autostartu ... . skanowanie ukrytych plików ... . . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}] "ImagePath"="\??\c:\program files\HP\QuickPlay\000.fcl" . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\nvvsvc.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\STacSV.exe c:\program files\DigitalPersona\Bin\DpHostW.exe c:\windows\system32\nvvsvc.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\windows\KMService.exe c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\windows\servicing\TrustedInstaller.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe . ************************************************************************** . Czas ukończenia: 2011-11-06 12:41:02 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2011-11-06 11:40 . Przed: 248 650 633 216 bajtów wolnych Po: 251 587 100 672 bajtów wolnych . - - End Of File - - 521D940084B076B1A3982D9E5E8BEA48