ComboFix 12-03-06.01 - Olga 2012-03-06 22:05:56.1.4 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1250.48.1045.18.2988.1779 [GMT 1:00] Uruchomiony z: c:\users\Olga\Downloads\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Utworzono nowy punkt przywracania . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\users\Olga\AppData\Roaming\chrtmp . . ((((((((((((((((((((((((( Pliki utworzone od 2012-02-06 do 2012-03-06 ))))))))))))))))))))))))))))))) . . 2012-03-06 21:10 . 2012-03-06 21:10 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-03-06 15:38 . 2012-02-08 06:03 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2179162D-280D-4685-B155-512DFD373BF1}\mpengine.dll 2012-03-05 16:08 . 2010-07-01 20:34 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll 2012-03-05 16:08 . 2010-07-01 20:35 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll 2012-02-17 16:54 . 2011-02-19 06:30 805376 ----a-w- c:\windows\system32\FntCache.dll 2012-02-17 16:54 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\system32\DWrite.dll 2012-02-17 16:54 . 2011-02-19 06:30 739840 ----a-w- c:\windows\system32\d2d1.dll 2012-02-16 17:40 . 2011-12-30 05:27 478720 ----a-w- c:\windows\system32\timedate.cpl 2012-02-16 17:22 . 2011-12-16 07:52 690688 ----a-w- c:\windows\system32\msvcrt.dll 2012-02-16 17:22 . 2012-01-04 08:58 442880 ----a-w- c:\windows\system32\ntshrui.dll 2012-02-16 17:22 . 2012-01-14 03:35 2343424 ----a-w- c:\windows\system32\win32k.sys 2012-02-10 17:02 . 2012-02-10 17:02 -------- d-----w- c:\users\Olga\AppData\Roaming\Media Player Classic . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-23 08:18 . 2011-12-25 18:14 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-01-03 21:04 . 2012-01-03 21:04 86528 ----a-w- c:\windows\system32\iesysprep.dll 2012-01-03 21:04 . 2012-01-03 21:04 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-01-03 21:04 . 2012-01-03 21:04 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-01-03 21:04 . 2012-01-03 21:04 74752 ----a-w- c:\windows\system32\iesetup.dll 2012-01-03 21:04 . 2012-01-03 21:04 63488 ----a-w- c:\windows\system32\tdc.ocx 2012-01-03 21:04 . 2012-01-03 21:04 48640 ----a-w- c:\windows\system32\mshtmler.dll 2012-01-03 21:04 . 2012-01-03 21:04 420864 ----a-w- c:\windows\system32\vbscript.dll 2012-01-03 21:04 . 2012-01-03 21:04 367104 ----a-w- c:\windows\system32\html.iec 2012-01-03 21:04 . 2012-01-03 21:04 35840 ----a-w- c:\windows\system32\imgutil.dll 2012-01-03 21:04 . 2012-01-03 21:04 23552 ----a-w- c:\windows\system32\licmgr10.dll 2012-01-03 21:04 . 2012-01-03 21:04 161792 ----a-w- c:\windows\system32\msls31.dll 2012-01-03 21:04 . 2012-01-03 21:04 152064 ----a-w- c:\windows\system32\wextract.exe 2012-01-03 21:04 . 2012-01-03 21:04 150528 ----a-w- c:\windows\system32\iexpress.exe 2012-01-03 21:04 . 2012-01-03 21:04 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2012-01-03 21:04 . 2012-01-03 21:04 11776 ----a-w- c:\windows\system32\mshta.exe 2012-01-03 21:04 . 2012-01-03 21:04 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2012-01-03 21:04 . 2012-01-03 21:04 101888 ----a-w- c:\windows\system32\admparse.dll 2011-12-25 20:12 . 2011-12-25 20:12 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-04 18:10 . 2011-12-25 17:57 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2011-08-16 1379840] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-10-21 142616] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-10-21 177432] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-10-21 176408] "NUSB3MON"="c:\program files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI.exe" [2011-02-18 5446248] "IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-12 283160] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 501624] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-11-02 1210640] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2012-01-03 352976] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-07-24 101248] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-02 227600] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-01 197224] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 25600] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-31 1343400] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [2009-11-17 87968] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-12 13336] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] S3 BrYNSvc;BrYNSvc;c:\program files\Browny02\BrYNSvc.exe [2010-01-25 245760] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984] S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECI.sys [2010-10-19 41088] S3 NETwNs32;___ Sterownik karty Intel(R) Wireless WiFi Link 5000 Series dla systemu Windows 7 32 Bit;c:\windows\system32\DRIVERS\NETwNs32.sys [2010-11-09 7430144] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 63872] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 141952] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] . . --- Inne Usługi/Sterowniki w Pamięci --- . *Deregistered* - KL1 *Deregistered* - kl2 . . ------- Skan uzupełniający ------- . IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\c1zvwxsj.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.onet.pl/ FF - prefs.js: network.proxy.type - 0 . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2012-03-06 22:12:34 ComboFix-quarantined-files.txt 2012-03-06 21:12 . Przed: 81 884 430 336 bajtów wolnych Po: 81 872 351 232 bajtów wolnych . - - End Of File - - B015D8115007B90AE6D19E8DA65B58E0