ComboFix 13-01-17.04 - damian 2013-01-19 23:41:52.2.2 - x64 Microsoft Windows 7 Home Basic 6.1.7600.0.1250.48.1045.18.2013.682 [GMT 1:00] Uruchomiony z: c:\users\damian\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Pliki utworzone od 2012-12-20 do 2013-01-20 ))))))))))))))))))))))))))))))) . . 2013-01-20 00:02 . 2013-01-20 00:02 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-01-19 07:22 . 2011-03-25 03:23 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2013-01-19 00:14 . 2013-01-19 00:14 -------- d-----w- C:\31e8a89ee6bd90ebdce7 2013-01-18 23:44 . 2012-12-16 16:31 67599240 ----a-w- c:\windows\system32\MRT.exe 2013-01-18 23:44 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll 2013-01-18 21:19 . 2013-01-18 21:19 -------- d-----w- c:\program files (x86)\Ask.com 2013-01-18 21:19 . 2013-01-18 21:19 -------- d-----w- C:\Firefox 2013-01-18 21:08 . 2013-01-18 21:08 -------- d-----w- c:\programdata\Ask 2013-01-18 21:08 . 2013-01-18 21:08 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-01-18 21:08 . 2013-01-18 21:07 780192 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-18 21:08 . 2013-01-18 21:07 859552 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-01-18 21:08 . 2013-01-18 21:08 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-18 21:07 . 2013-01-18 21:07 -------- d-----w- c:\program files (x86)\Java 2013-01-18 18:43 . 2013-01-18 18:44 -------- d-----w- C:\dc58c5205b6561cffe222f6f05 2013-01-18 17:11 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll 2013-01-18 17:11 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll 2013-01-18 14:17 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll 2013-01-18 14:17 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll 2013-01-18 13:32 . 2012-07-26 05:05 2560 ----a-w- c:\windows\system32\drivers\pl-PL\wdf01000.sys.mui 2013-01-18 13:32 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2013-01-18 13:32 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2013-01-18 13:32 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll 2013-01-18 01:02 . 2009-11-25 11:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2013-01-18 01:02 . 2009-11-25 11:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll 2013-01-18 01:02 . 2009-11-25 11:47 48960 ----a-w- c:\windows\system32\netfxperf.dll 2013-01-18 01:02 . 2009-11-25 11:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll 2013-01-18 01:02 . 2009-11-25 11:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe 2013-01-18 01:02 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll 2013-01-18 01:02 . 2009-11-25 11:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2013-01-18 01:02 . 2009-11-25 11:47 444752 ----a-w- c:\windows\system32\mscoree.dll 2013-01-18 01:02 . 2009-11-25 11:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe 2013-01-18 01:02 . 2009-11-25 11:47 1942856 ----a-w- c:\windows\system32\dfshim.dll 2013-01-18 00:54 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2013-01-17 23:50 . 2012-12-16 16:52 46080 ----a-w- c:\windows\system32\atmlib.dll 2013-01-17 23:50 . 2012-12-16 14:25 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2013-01-17 23:50 . 2009-10-19 14:46 100864 ----a-w- c:\windows\system32\fontsub.dll 2013-01-17 23:50 . 2009-10-19 14:10 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2013-01-17 23:50 . 2012-12-16 14:40 367616 ----a-w- c:\windows\system32\atmfd.dll 2013-01-17 23:50 . 2012-12-16 14:25 295424 ----a-w- c:\windows\SysWow64\atmfd.dll 2013-01-17 23:44 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2013-01-17 23:44 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2013-01-17 23:44 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2013-01-17 23:44 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2013-01-17 23:44 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2013-01-17 23:44 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2013-01-17 23:44 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2013-01-17 23:29 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2013-01-17 23:29 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll 2013-01-17 23:29 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll 2013-01-17 23:29 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll 2013-01-17 23:29 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2013-01-17 23:23 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys 2013-01-17 13:28 . 2013-01-17 13:28 -------- d-----w- c:\program files (x86)\MSECache 2013-01-17 11:08 . 2013-01-17 11:08 -------- d-----w- c:\program files (x86)\Microsoft 2013-01-17 11:07 . 2013-01-17 11:07 -------- d-----w- c:\program files (x86)\MSN Toolbar 2013-01-17 11:06 . 2013-01-17 11:06 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2013-01-17 11:02 . 2013-01-17 11:11 -------- d-----w- c:\program files (x86)\Bing Bar Installer 2013-01-17 11:01 . 2013-01-17 13:13 -------- d-----w- c:\programdata\HP Photo Creations 2013-01-17 11:01 . 2013-01-17 11:01 -------- d-----w- c:\program files (x86)\HP Photo Creations 2013-01-17 11:00 . 2013-01-17 11:00 -------- d-----w- c:\programdata\HP 2013-01-17 10:58 . 2013-01-17 11:01 -------- d-----w- c:\program files (x86)\HP 2013-01-17 10:57 . 2013-01-17 10:57 -------- d-----w- c:\program files\HP 2013-01-17 10:25 . 2013-01-17 10:36 -------- d-----w- c:\windows\SHELLNEW 2013-01-17 10:24 . 2013-01-17 10:24 -------- d-----w- c:\windows\PCHEALTH 2013-01-17 10:17 . 2012-05-28 14:45 206336 ----a-w- c:\windows\system32\unrar64.dll 2013-01-17 10:17 . 2013-01-17 10:19 -------- d-----w- c:\program files\MPC-HC 2013-01-17 07:40 . 2011-06-15 09:04 163840 ----a-w- c:\windows\SysWow64\odbctrac.dll 2013-01-17 07:39 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2013-01-17 07:39 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe 2013-01-17 07:39 . 2013-01-04 18:51 9376256 ----a-w- c:\windows\system32\mshtml.dll 2013-01-17 07:39 . 2010-11-04 04:35 1638912 ----a-w- c:\windows\system32\mshtml.tlb 2013-01-17 07:39 . 2010-11-04 04:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-01-17 07:39 . 2011-02-26 06:23 2870272 ----a-w- c:\windows\explorer.exe 2013-01-17 07:39 . 2011-02-26 05:33 2614784 ----a-w- c:\windows\SysWow64\explorer.exe 2013-01-17 07:39 . 2012-11-09 04:49 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2013-01-17 07:39 . 2012-11-09 05:34 2048 ----a-w- c:\windows\system32\tzres.dll 2013-01-17 07:38 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll 2013-01-17 07:38 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll 2013-01-17 07:38 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll 2013-01-17 07:38 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax 2013-01-17 07:38 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll 2013-01-17 07:38 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax 2013-01-17 07:38 . 2010-08-26 05:27 148992 ----a-w- c:\windows\system32\t2embed.dll 2013-01-17 07:38 . 2010-08-26 04:39 109056 ----a-w- c:\windows\SysWow64\t2embed.dll 2013-01-17 07:36 . 2011-05-04 05:28 2228224 ----a-w- c:\windows\system32\mssrch.dll 2013-01-17 07:35 . 2010-01-18 23:28 277504 ----a-w- c:\windows\SysWow64\RMActivate_ssp_isv.exe 2013-01-17 07:35 . 2010-01-18 23:28 280064 ----a-w- c:\windows\SysWow64\RMActivate_ssp.exe 2013-01-17 07:35 . 2010-03-04 07:57 2080256 ----a-w- c:\program files\Windows Mail\msoe.dll 2013-01-17 07:35 . 2010-03-04 07:33 1619968 ----a-w- c:\program files (x86)\Windows Mail\msoe.dll 2013-01-17 07:35 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll 2013-01-17 07:35 . 2012-01-03 06:24 515584 ----a-w- c:\windows\system32\timedate.cpl 2013-01-17 07:35 . 2012-01-03 05:44 478208 ----a-w- c:\windows\SysWow64\timedate.cpl 2013-01-17 07:35 . 2011-02-24 06:30 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-01-17 07:35 . 2011-02-24 05:32 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-01-17 07:33 . 2012-10-27 05:35 12404736 ----a-w- c:\windows\system32\ieframe.dll 2013-01-17 07:31 . 2012-08-30 18:11 5505904 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-01-17 07:29 . 2012-11-02 05:30 2001408 ----a-w- c:\windows\system32\msxml6.dll 2013-01-17 07:29 . 2012-11-02 05:30 1880064 ----a-w- c:\windows\system32\msxml3.dll 2013-01-17 07:29 . 2012-11-02 04:50 1388544 ----a-w- c:\windows\SysWow64\msxml6.dll 2013-01-17 07:29 . 2012-11-02 04:50 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll 2013-01-17 07:29 . 2011-04-22 20:18 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2013-01-17 07:29 . 2010-07-29 06:30 82944 ----a-w- c:\windows\SysWow64\iccvid.dll 2013-01-17 07:29 . 2009-09-26 06:20 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys 2013-01-17 07:29 . 2012-05-02 05:32 208896 ----a-w- c:\windows\system32\profsvc.dll 2013-01-17 07:29 . 2011-03-03 06:17 182272 ----a-w- c:\windows\system32\dnsrslvr.dll 2013-01-17 07:29 . 2011-03-03 06:17 356352 ----a-w- c:\windows\system32\dnsapi.dll 2013-01-17 07:29 . 2011-03-03 06:14 30208 ----a-w- c:\windows\system32\dnscacheugc.exe 2013-01-17 07:29 . 2011-03-03 05:27 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe 2013-01-17 07:28 . 2012-11-02 05:27 478208 ----a-w- c:\windows\system32\dpnet.dll 2013-01-17 07:28 . 2012-11-02 04:48 376832 ----a-w- c:\windows\SysWow64\dpnet.dll 2013-01-17 07:28 . 2012-11-20 05:55 307200 ----a-w- c:\windows\system32\ncrypt.dll 2013-01-17 07:28 . 2012-11-20 05:10 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll 2013-01-17 07:28 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll 2013-01-17 07:26 . 2012-12-07 03:45 43520 ----a-w- c:\windows\system32\csrr.rs 2013-01-17 07:25 . 2011-08-17 05:32 613888 ----a-w- c:\windows\system32\psisdecd.dll 2013-01-17 07:24 . 2012-11-30 05:43 424960 ----a-w- c:\windows\system32\KernelBase.dll 2013-01-17 07:23 . 2012-06-16 05:25 609792 ----a-w- c:\windows\system32\vbscript.dll 2013-01-17 07:22 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll 2013-01-17 07:21 . 2011-10-15 06:25 723456 ----a-w- c:\windows\system32\EncDec.dll 2013-01-17 07:20 . 2012-06-02 05:25 1462784 ----a-w- c:\windows\system32\crypt32.dll 2013-01-17 07:20 . 2012-06-02 05:25 182272 ----a-w- c:\windows\system32\cryptsvc.dll 2013-01-17 07:20 . 2012-06-02 05:25 140288 ----a-w- c:\windows\system32\cryptnet.dll 2013-01-17 07:20 . 2012-06-02 04:45 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-01-17 07:20 . 2012-06-02 04:45 1157632 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-01-17 07:20 . 2012-06-02 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-18 18:29 . 2009-07-14 04:45 356568 ----a-w- c:\windows\system32\FNTCACHE.DAT 2012-11-30 04:56 . 2013-01-17 07:24 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-11-15 22:33 . 2012-11-15 22:33 111968 ----a-w- c:\windows\system32\drivers\avgmfx64.sys 2012-10-22 12:02 . 2012-10-22 12:02 154464 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-12-10 1520840] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-12-10 18:32 1520840 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-12-10 1520840] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Super-Charger"="c:\program files (x86)\MSI\Super-Charger\StartSuperCharger.exe" [2011-01-25 303104] "AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-12-11 3147384] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208] "Bing Bar"="c:\program files (x86)\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2012-12-10 1573576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-10-15 63328] S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120] S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-11-15 111968] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-01-16 22:10 1606760 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe . Zawartość folderu 'Zaplanowane zadania' . 2013-01-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-16 11:36] . 2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-16 22:08] . 2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-16 22:08] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-28 162328] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-28 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-28 415256] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-28 11905128] . ------- Skan uzupełniający ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&ksport do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.121.6.20 10.121.6.21 10.121.2.13 . - - - - USUNIĘTO PUSTE WPISY - - - - . Wow6432Node-HKLM-Run- - (no file) . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2013-01-20 01:19:40 ComboFix-quarantined-files.txt 2013-01-20 00:19 . Przed: 72 852 070 400 bajtów wolnych Po: 74 349 625 344 bajtów wolnych . - - End Of File - - 895D1FBDC8079899F3846181F57792C2