ComboFix 12-12-29.02 - user 2012-12-29 15:42:54.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1250.48.1045.18.3692.1975 [GMT 1:00] Uruchomiony z: c:\users\user\Desktop\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\BrowserCompanion c:\program files (x86)\BrowserCompanion\BCHelper.exe c:\program files (x86)\BrowserCompanion\blabbers-ch.crx c:\program files (x86)\BrowserCompanion\logo.ico c:\program files (x86)\BrowserCompanion\updatebhoWin32.dll_1 c:\program files (x86)\BrowserCompanion\updatebhoWin32.dll_2 c:\program files (x86)\facemoods.com c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\BATORY STATKU JEDYNY - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\MS Batory the polish ship MS Batory polska vyletna lod - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\MS Batory w czasie operacji Pochodnia 1942.11.08 - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\MS Batory w kolorze 1964 - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\Powrót statku - MS Batory - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\Przedstawiciele Czerwonego Krzyża przybywają na MS Batory do New Yorku 1939 - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\Wodowanie Ms Batory - 1935 - YouTube.URL c:\users\user\AppData\Roaming\Microsoft\Windows\Recent\Wyjście ms Batory ze stoczni w Monfalcone 1936 - YouTube.URL c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\@ c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\L\00000004.@ c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\L\201d3dde c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\L\76603ac3 c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\U\00000004.@ c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\U\00000008.@ c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\U\000000cb.@ c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\U\80000000.@ c:\windows\Installer\{b4b72bb3-4995-578a-0932-d3483ee3d184}\U\trz22D2.tmp c:\windows\SysWow64\System32\MASetupCleaner.exe c:\windows\SysWow64\System32\muzapp.exe . Zainfekowana kopia c:\windows\system32\services.exe została znaleziona. Problem naprawiono Plik odzyskano z - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe . . ((((((((((((((((((((((((( Pliki utworzone od 2012-11-28 do 2012-12-29 ))))))))))))))))))))))))))))))) . . 2012-12-29 14:59 . 2012-12-29 14:59 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-12-29 14:44 . 2012-12-29 14:44 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB4A5AB9-B3C0-47B1-B878-4B0B6C39828A}\offreg.dll 2012-12-27 08:40 . 2012-12-27 08:40 -------- d-----w- c:\program files (x86)\ESET 2012-12-17 17:31 . 2012-12-17 17:31 347016 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys 2012-12-17 17:31 . 2012-12-17 17:31 258424 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2012-12-17 17:31 . 2012-12-17 17:31 1096176 ----a-w- c:\windows\system32\drivers\pctEFA64.sys 2012-12-17 17:31 . 2012-12-17 17:31 453896 ----a-w- c:\windows\system32\drivers\pctDS64.sys 2012-12-17 17:31 . 2012-12-17 17:31 413448 ----a-w- c:\windows\system32\drivers\PCTCore64.sys 2012-12-17 17:29 . 2012-10-23 16:40 77144 ----a-w- c:\windows\system32\drivers\PCTBD64.sys 2012-12-17 17:29 . 2012-10-23 16:40 769144 ----a-w- c:\windows\BDTSupport.dll 2012-12-17 17:29 . 2012-10-23 16:40 150648 ----a-w- c:\windows\SGDetectionTool.dll 2012-12-17 17:29 . 2012-10-23 16:40 2280568 ----a-w- c:\windows\PCTBDCore.dll 2012-12-17 17:29 . 2012-10-23 16:40 1690744 ----a-w- c:\windows\PCTBDRes.dll 2012-12-17 17:26 . 2012-12-17 17:26 -------- d-----w- c:\program files (x86)\PC Tools 2012-12-17 17:24 . 2012-11-01 14:35 253256 ----a-w- c:\windows\system32\drivers\PCTSD64.sys 2012-12-17 17:24 . 2012-12-17 18:56 -------- d-----w- c:\program files (x86)\Common Files\PC Tools 2012-12-17 17:24 . 2012-12-17 18:03 -------- d-----w- c:\programdata\PC Tools 2012-12-17 17:24 . 2012-12-17 17:24 -------- d-----w- c:\users\user\AppData\Roaming\TestApp 2012-12-17 16:07 . 2012-12-17 16:07 -------- d-----w- c:\program files\Enigma Software Group 2012-12-17 16:06 . 2012-12-17 18:56 -------- d-----w- c:\windows\83B952C7F8F34CA3B4C533C85B24E478.TMP 2012-12-17 16:06 . 2012-12-17 18:56 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2012-12-16 09:44 . 2012-12-19 08:29 -------- d-----w- c:\users\user\AppData\Roaming\Free Download Manager 2012-12-16 09:44 . 2012-12-16 09:49 -------- d-----w- c:\program files (x86)\Free Download Manager 2012-12-16 09:32 . 2012-12-16 09:32 -------- d-----w- c:\users\user\AppData\Roaming\TeamViewer 2012-12-16 09:22 . 2012-12-16 09:22 -------- d-----w- c:\users\user\AppData\Roaming\PDFReaderPackages 2012-12-16 09:16 . 2012-12-16 09:16 -------- d-----w- c:\users\user\AppData\Roaming\SumatraPDF 2012-12-16 09:16 . 2012-12-16 09:16 -------- d-----w- c:\program files (x86)\PDFReader 2012-12-13 22:56 . 2012-12-13 22:56 -------- d-sh--w- c:\windows\SysWow64\%APPDATA% 2012-12-08 10:20 . 2012-12-08 10:20 -------- d-----w- c:\programdata\Ad-Aware Antivirus 2012-12-08 10:18 . 2012-12-08 10:18 -------- d-----w- c:\programdata\Lavasoft 2012-12-08 10:18 . 2012-12-18 08:10 -------- d-----w- c:\program files (x86)\Ad-Aware Antivirus 2012-12-08 10:17 . 2012-12-08 10:17 -------- d-----w- c:\users\user\AppData\Local\Downloaded Installations 2012-12-08 10:17 . 2012-12-08 10:17 14456 ----a-w- c:\windows\system32\drivers\gfibto.sys 2012-12-08 10:17 . 2012-12-20 08:27 -------- d-----w- c:\programdata\Search Protection 2012-12-08 10:16 . 2012-12-08 10:16 -------- d-----w- c:\users\user\AppData\Roaming\LavasoftStatistics 2012-12-08 10:16 . 2012-12-08 11:17 -------- d-----w- c:\users\user\AppData\Roaming\Ad-Aware Antivirus 2012-12-07 17:55 . 2012-12-07 17:55 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2012-12-07 10:31 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB4A5AB9-B3C0-47B1-B878-4B0B6C39828A}\mpengine.dll 2012-12-03 15:32 . 2009-10-21 06:28 913408 ----a-w- c:\windows\system32\drivers\dvb7700all.sys 2012-12-03 15:28 . 2012-12-07 19:02 -------- d-----w- c:\program files\WinRAR . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-12 15:06 . 2012-06-26 18:28 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 15:06 . 2012-01-31 12:41 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-30 22:51 . 2012-01-11 15:43 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-30 22:51 . 2012-08-28 05:54 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys 2012-10-30 22:51 . 2012-01-11 15:43 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-30 22:51 . 2012-01-11 15:43 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-30 22:51 . 2012-01-11 15:43 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-30 22:51 . 2012-01-11 15:43 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-30 22:51 . 2012-01-11 15:43 41224 ----a-w- c:\windows\avastSS.scr 2012-10-30 22:50 . 2012-01-11 15:43 227648 ------w- c:\windows\SysWow64\aswBoot.exe 2012-10-30 22:50 . 2012-01-11 15:43 285328 ----a-w- c:\windows\system32\aswBoot.exe 2012-10-29 20:04 . 2012-01-12 09:14 66395536 ----a-w- c:\windows\system32\MRT.exe 2012-10-23 15:30 . 2012-12-17 17:29 3488 ----a-w- c:\windows\UDB.zip 2012-10-23 15:30 . 2012-12-17 17:29 131 ----a-w- c:\windows\IDB.zip 2012-10-18 18:25 . 2012-11-15 14:58 3149824 ----a-w- c:\windows\system32\win32k.sys 2012-10-16 08:38 . 2012-11-28 07:12 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 07:12 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 07:12 561664 ----a-w- c:\windows\apppatch\AcLayers.dll 2012-10-15 16:59 . 2012-02-26 16:12 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-10-09 18:17 . 2012-11-15 14:58 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-15 14:58 226816 ----a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-15 14:58 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-15 14:58 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll 2012-10-08 12:19 . 2012-11-15 22:10 17811968 ----a-w- c:\windows\system32\mshtml.dll 2012-10-08 11:42 . 2012-11-15 22:10 10925568 ----a-w- c:\windows\system32\ieframe.dll 2012-10-08 11:31 . 2012-11-15 22:11 2312704 ----a-w- c:\windows\system32\jscript9.dll 2012-10-08 11:24 . 2012-11-15 22:11 1346048 ----a-w- c:\windows\system32\urlmon.dll 2012-10-08 11:23 . 2012-11-15 22:10 1392128 ----a-w- c:\windows\system32\wininet.dll 2012-10-08 11:22 . 2012-11-15 22:11 1494528 ----a-w- c:\windows\system32\inetcpl.cpl 2012-10-08 11:22 . 2012-11-15 22:11 237056 ----a-w- c:\windows\system32\url.dll 2012-10-08 11:20 . 2012-11-15 22:10 85504 ----a-w- c:\windows\system32\jsproxy.dll 2012-10-08 11:18 . 2012-11-15 22:11 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2012-10-08 11:17 . 2012-11-15 22:10 599040 ----a-w- c:\windows\system32\vbscript.dll 2012-10-08 11:17 . 2012-11-15 22:10 816640 ----a-w- c:\windows\system32\jscript.dll 2012-10-08 11:15 . 2012-11-15 22:11 729088 ----a-w- c:\windows\system32\msfeeds.dll 2012-10-08 11:15 . 2012-11-15 22:10 2144768 ----a-w- c:\windows\system32\iertutil.dll 2012-10-08 11:13 . 2012-11-15 22:11 96768 ----a-w- c:\windows\system32\mshtmled.dll 2012-10-08 11:13 . 2012-11-15 22:11 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2012-10-08 11:09 . 2012-11-15 22:11 248320 ----a-w- c:\windows\system32\ieui.dll 2012-10-08 07:56 . 2012-11-15 22:10 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll 2012-10-08 07:48 . 2012-11-15 22:11 1129472 ----a-w- c:\windows\SysWow64\wininet.dll 2012-10-08 07:47 . 2012-11-15 22:11 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2012-10-08 07:44 . 2012-11-15 22:11 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2012-10-08 07:43 . 2012-11-15 22:11 420864 ----a-w- c:\windows\SysWow64\vbscript.dll 2012-10-08 07:40 . 2012-11-15 22:11 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2012-10-03 17:56 . 2012-11-15 14:58 1914248 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-10-03 17:44 . 2012-11-15 14:58 303104 ----a-w- c:\windows\system32\nlasvc.dll 2012-10-03 17:44 . 2012-11-15 14:58 70656 ----a-w- c:\windows\system32\nlaapi.dll 2012-10-03 17:44 . 2012-11-15 14:58 246272 ----a-w- c:\windows\system32\netcorehc.dll 2012-10-03 17:44 . 2012-11-15 14:58 18944 ----a-w- c:\windows\system32\netevent.dll 2012-10-03 17:44 . 2012-11-15 14:58 216576 ----a-w- c:\windows\system32\ncsi.dll 2012-10-03 17:42 . 2012-11-15 14:58 569344 ----a-w- c:\windows\system32\iphlpsvc.dll 2012-10-03 16:42 . 2012-11-15 14:58 175104 ----a-w- c:\windows\SysWow64\netcorehc.dll 2012-10-03 16:42 . 2012-11-15 14:58 18944 ----a-w- c:\windows\SysWow64\netevent.dll 2012-10-03 16:42 . 2012-11-15 14:58 156672 ----a-w- c:\windows\SysWow64\ncsi.dll 2012-10-03 16:07 . 2012-11-15 14:58 45568 ----a-w- c:\windows\system32\drivers\tcpipreg.sys . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942] "Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2010-11-10 4144448] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] "AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-29 885760] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-12-14 25072] R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-10-23 77144] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-10-30 250984] R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 127488] R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 18944] R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 161280] R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-13 1255736] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2011-06-16 79488] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2011-06-16 40064] S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2012-12-08 14456] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [2012-12-17 347016] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-07-12 204288] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-12 365568] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-10-23 580728] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-03-30 114704] S3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2011-08-18 349736] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-08-18 39464] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-05-17 533096] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672] . . --- Inne Usługi/Sterowniki w Pamięci --- . *NewlyCreated* - WS2IFSL . Zawartość folderu 'Zaplanowane zadania' . 2012-12-29 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-26 15:06] . 2012-12-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-818110064-4033437693-2602076331-1001Core.job - c:\users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-14 13:13] . 2012-12-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-818110064-4033437693-2602076331-1001UA.job - c:\users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-14 13:13] . 2012-12-19 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-12-14 04:09] . 2012-12-29 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-12-14 04:09] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-03-29 608112] "Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-06-28 2022976] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-04-29 2055016] . ------- Skan uzupełniający ------- . uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://www.bing.com/search?q={searchTerms} IE: E&ksport do programu Microsoft Excel - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000 IE: Pobierz plik wideo w FDM - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Pobierz w FDM - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: Pobierz wszystkie pliki w FDM - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Pobierz zaznaczone pliki w FDM - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 62.179.1.63 62.179.1.62 FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\udbmnf47.default\ FF - prefs.js: browser.search.defaulturl - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=FE3FDE70D718FC6E063F6050C313904C FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ig?hl=pl FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - ExtSQL: 2012-10-31 07:39; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - ExtSQL: 2012-11-19 07:46; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF - ExtSQL: 2012-12-07 09:00; AX1FMU@w19hh.com; c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\udbmnf47.default\extensions\AX1FMU@w19hh.com FF - ExtSQL: 2012-12-08 11:17; jid1-yZwVFzbsyfMrqQ@jetpack; c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\udbmnf47.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack FF - ExtSQL: 2012-12-16 10:44; fdm_ffext@freedownloadmanager.org; c:\program files (x86)\Free Download Manager\Firefox\Extension FF - ExtSQL: 2012-12-16 11:37; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\udbmnf47.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2012-12-17 18:29; {cb84136f-9c44-433a-9048-c5cd9df1dc16}; c:\program files (x86)\PC Tools\PC Tools Security\BDT\Firefox FF - ExtSQL: !HIDDEN! 2012-10-27 23:27; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files (x86)\Search Results Toolbar\Datamngr\FirefoxExtension FF - user.js: extensions.BabylonToolbar_i.id - 7642964d0000000000009439e5d62b9b FF - user.js: extensions.BabylonToolbar_i.hardId - 7642964d0000000000009439e5d62b9b FF - user.js: extensions.BabylonToolbar_i.instlDay - 15525 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.instlRef - sst FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings FF - user.js: extensions.Softonic.autoRvrt - false FF - user.js: extensions.Softonic_i.hmpg - true FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MON00084/tb_v1?SearchSource=13&cc= FF - user.js: extensions.Softonic.hpOld - hxxp://www.google.pl/ig?hl=pl FF - user.js: extensions.Softonic.hpNew - hxxp://search.softonic.com/MON00084/tb_v1?SearchSource=13&cc= FF - user.js: extensions.Softonic.dfltSrch - true FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic) FF - user.js: extensions.Softonic.keyWordUrl - hxxp://search.softonic.com/MON00084/tb_v1?SearchSource=2&cc=&q= FF - user.js: extensions.Softonic.dspOld - SweetIM Search FF - user.js: extensions.Softonic.dspNew - Search the web (Softonic) FF - user.js: extensions.Softonic_i.dnsErr - true FF - user.js: extensions.Softonic_i.newTab - true FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MON00084/tb_v1?SearchSource=15&cc= FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MON00084/tb_v1?SearchSource=1&cc=&q= FF - user.js: extensions.Softonic.id - 7642964d0000000000009439e5d62b9b FF - user.js: extensions.Softonic.instlDay - 15560 FF - user.js: extensions.Softonic.vrsn - 1.6.7.4 FF - user.js: extensions.Softonic.vrsni - 1.6.7.4 FF - user.js: extensions.Softonic_i.vrsnTs - 1.6.7.49:54 FF - user.js: extensions.Softonic.prtnrId - softonic FF - user.js: extensions.Softonic.prdct - Softonic FF - user.js: extensions.Softonic.aflt - SD FF - user.js: extensions.Softonic_i.smplGrp - none FF - user.js: extensions.Softonic.tlbrId - base FF - user.js: extensions.Softonic.instlRef - MON00084 FF - user.js: extensions.Softonic.dfltLng - pl FF - user.js: extensions.Softonic.excTlbr - false FF - user.js: extensions.Softonic.admin - false FF - user.js: extensions.searchya.hmpg - true FF - user.js: extensions.searchya.hmpgUrl - hxxp://www.searchya.com/?s=0&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzuzyyEtAzy0EyD0DyCtB0Bzy0CzyyCyE0DtN0D0Tzu0CtBtAtDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1374281765 FF - user.js: extensions.searchya.dfltSrch - true FF - user.js: extensions.searchya.srchPrvdr - Search FF - user.js: extensions.searchya.dnsErr - true FF - user.js: extensions.searchya_i.newTab - true FF - user.js: extensions.searchya.newTabUrl - hxxp://www.searchya.com/?s=2&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzuzyyEtAzy0EyD0DyCtB0Bzy0CzyyCyE0DtN0D0Tzu0CtBtAtDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1374281765 FF - user.js: extensions.searchya.tlbrSrchUrl - hxxp://www.searchya.com/?s=3&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzuzyyEtAzy0EyD0DyCtB0Bzy0CzyyCyE0DtN0D0Tzu0CtBtAtDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1374281765&q= FF - user.js: extensions.searchya.id - 9439E5D62B9C964D FF - user.js: extensions.searchya.instlDay - 15569 FF - user.js: extensions.searchya.vrsn - 1.5.25.0 FF - user.js: extensions.searchya.vrsni - 1.5.25.0 FF - user.js: extensions.searchya_i.vrsnTs - 1.5.25.016:15 FF - user.js: extensions.searchya.prtnrId - searchya FF - user.js: extensions.searchya.prdct - searchya FF - user.js: extensions.searchya.aflt - foxtab FF - user.js: extensions.searchya_i.smplGrp - none FF - user.js: extensions.searchya.tlbrId - base FF - user.js: extensions.searchya.instlRef - ft-100 FF - user.js: extensions.searchya.dfltLng - FF - user.js: extensions.searchya.excTlbr - false FF - user.js: extensions.searchya.autoRvrt - false FF - user.js: extensions.searchya.envrmnt - production FF - user.js: extensions.searchya.isdcmntcmplt - true FF - user.js: extensions.searchya.mntrvrsn - 1.3.0 FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=7642964d0000000000009439e5d62b9b&q= FF - user.js: extensions.BabylonToolbar.id - 7642964d0000000000009439e5d62b9b FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB} FF - user.js: extensions.BabylonToolbar.instlDay - 15690 FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.4.9 FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.4.9 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.4.910:43 FF - user.js: extensions.BabylonToolbar.prtnrId - babylon FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar.tlbrId - base FF - user.js: extensions.BabylonToolbar.instlRef - sst FF - user.js: extensions.BabylonToolbar.dfltLng - en FF - user.js: extensions.BabylonToolbar_i.excTlbr - false FF - user.js: extensions.BabylonToolbar.excTlbr - false FF - user.js: extensions.BabylonToolbar.admin - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110824&tt=5012_2 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar.autoRvrt - false FF - user.js: extensions.BabylonToolbar.rvrt - false FF - user.js: extensions.BabylonToolbar_i.newTab - false . - - - - USUNIĘTO PUSTE WPISY - - - - . Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms" . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000001 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2012-12-29 16:07:27 ComboFix-quarantined-files.txt 2012-12-29 15:07 . Przed: 28 294 017 024 bajtów wolnych Po: 29 408 034 816 bajtów wolnych . - - End Of File - - 41018A42AA9702366D2F85C3BE4F8819