ComboFix 13-02-18.02 - d.bartosik 2013-02-19 8:52.2.2 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1250.48.1045.18.3548.2132 [GMT 1:00] Uruchomiony z: c:\users\d.bartosik\Downloads\ComboFix.exe AV: Kaspersky Endpoint Security 8 for Windows *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} FW: Kaspersky Endpoint Security 8 for Windows *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} SP: Kaspersky Endpoint Security 8 for Windows *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\TEMP\kladminkit\946c050d-146b-498e-ac54-76a728af7d2b.dll . ---- Poprzednie uruchomienie ------- . c:\users\d.bartosik\Documents\~WRL4086.tmp c:\users\d.bartosik\Documents\explorer\id_091020115745044_091020115745952.upf c:\windows\system32\SET1924.tmp c:\windows\system32\SET36BB.tmp c:\windows\system32\SET50C6.tmp c:\windows\system32\SET693B.tmp c:\windows\system32\SET6C54.tmp c:\windows\system32\SET7921.tmp c:\windows\system32\SETB097.tmp c:\windows\system32\SETB621.tmp c:\windows\system32\SETC835.tmp c:\windows\system32\SETD50A.tmp c:\windows\system32\SETDA8.tmp c:\windows\system32\SETE876.tmp c:\windows\TEMP\kladminkit\a7d33281-83e0-4c2a-90d4-2e53752aca9f.dll D:\setup.exe . . ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF . . ((((((((((((((((((((((((( Pliki utworzone od 2013-01-19 do 2013-02-19 ))))))))))))))))))))))))))))))) . . 2013-02-19 07:59 . 2013-02-19 07:59 -------- d-----w- c:\users\KL-AK-CADC9F2AC108F7\AppData\Local\temp 2013-02-19 07:59 . 2013-02-19 07:59 -------- d-----w- c:\users\Gość\AppData\Local\temp 2013-02-19 07:59 . 2013-02-19 07:59 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-02-19 07:59 . 2013-02-19 07:59 -------- d-----w- c:\users\DD7C4~1~BAR\AppData\Local\temp 2013-02-19 07:19 . 2013-02-19 07:19 -------- d-----w- c:\program files\Common Files\Java 2013-02-19 07:19 . 2013-02-19 07:18 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-02-19 07:04 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A31A4965-32FF-4D9D-9B25-1677873B1926}\mpengine.dll 2013-02-11 14:09 . 2013-02-11 14:16 -------- d-----w- c:\users\d.bartosik\AppData\Roaming\TeamViewer 2013-02-11 11:53 . 2013-02-11 11:54 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2013-02-11 11:53 . 2013-02-11 11:53 -------- d-----w- c:\users\d.bartosik\AppData\Roaming\Malwarebytes 2013-02-11 11:53 . 2013-02-11 11:53 -------- d-----w- c:\programdata\Malwarebytes 2013-02-11 11:53 . 2013-02-11 11:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-02-11 11:53 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-02-11 11:53 . 2013-02-11 11:53 -------- d-----w- c:\users\d.bartosik\AppData\Local\Programs . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-02-19 07:18 . 2012-09-18 05:44 861088 ----a-w- c:\windows\system32\npdeployJava1.dll 2013-02-19 07:18 . 2011-02-23 06:40 782240 ----a-w- c:\windows\system32\deployJava1.dll 2013-02-19 06:59 . 2011-03-14 10:14 0 ----a-w- c:\users\d.bartosik\AppData\Local\WavXMapDrive.bat 2013-02-15 13:03 . 2012-04-13 05:49 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-02-15 13:03 . 2011-05-20 05:38 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-01-17 00:28 . 2011-03-14 10:31 232336 ------w- c:\windows\system32\MpSigStub.exe 2012-12-16 14:13 . 2012-12-21 10:26 295424 ----a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 10:26 34304 ----a-w- c:\windows\system32\atmlib.dll 2012-12-07 12:26 . 2013-01-10 06:40 308736 ----a-w- c:\windows\system32\Wpc.dll 2012-12-07 12:20 . 2013-01-10 06:40 2576384 ----a-w- c:\windows\system32\gameux.dll 2012-12-07 10:46 . 2013-01-10 06:40 43520 ----a-w- c:\windows\system32\csrr.rs 2012-12-07 10:46 . 2013-01-10 06:40 30720 ----a-w- c:\windows\system32\usk.rs 2012-12-07 10:46 . 2013-01-10 06:40 45568 ----a-w- c:\windows\system32\oflc-nz.rs 2012-12-07 10:46 . 2013-01-10 06:40 44544 ----a-w- c:\windows\system32\pegibbfc.rs 2012-12-07 10:46 . 2013-01-10 06:40 20480 ----a-w- c:\windows\system32\pegi-pt.rs 2012-12-07 10:46 . 2013-01-10 06:40 23552 ----a-w- c:\windows\system32\oflc.rs 2012-12-07 10:46 . 2013-01-10 06:40 20480 ----a-w- c:\windows\system32\pegi-fi.rs 2012-12-07 10:46 . 2013-01-10 06:40 46592 ----a-w- c:\windows\system32\fpb.rs 2012-12-07 10:46 . 2013-01-10 06:40 20480 ----a-w- c:\windows\system32\pegi.rs 2012-12-07 10:46 . 2013-01-10 06:40 21504 ----a-w- c:\windows\system32\grb.rs 2012-12-07 10:46 . 2013-01-10 06:40 40960 ----a-w- c:\windows\system32\cob-au.rs 2012-12-07 10:46 . 2013-01-10 06:40 15360 ----a-w- c:\windows\system32\djctq.rs 2012-12-07 10:46 . 2013-01-10 06:40 51712 ----a-w- c:\windows\system32\esrb.rs 2012-12-07 10:46 . 2013-01-10 06:40 55296 ----a-w- c:\windows\system32\cero.rs 2012-11-30 04:47 . 2013-01-10 06:40 293376 ----a-w- c:\windows\system32\KernelBase.dll 2012-11-30 04:45 . 2013-01-10 06:40 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2012-11-30 04:45 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2012-11-30 02:55 . 2013-01-10 06:40 271360 ----a-w- c:\windows\system32\conhost.exe 2012-11-30 02:38 . 2013-01-10 06:40 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 02:38 . 2013-01-10 06:40 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 02:38 . 2013-01-10 06:40 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 02:38 . 2013-01-10 06:40 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-28 07:53 . 2012-11-28 07:53 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll 2012-11-23 02:48 . 2013-01-10 06:40 49152 ----a-w- c:\windows\system32\taskhost.exe 2012-11-22 04:45 . 2013-01-10 06:40 626688 ----a-w- c:\windows\system32\usp10.dll 2013-02-06 07:47 . 2013-02-06 07:47 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay] @="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}" [HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}] 2010-03-29 11:45 62832 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay] @="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}" [HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}] 2010-03-29 11:45 62832 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "AQQ"="c:\progra~1\WapSter\WAPSTE~1\AQQ.exe" [2012-12-31 8866816] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1314816] "IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696] "WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2010-07-21 147840] "USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2010-06-22 34232] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-24 140520] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Desktop Disc Tool"="c:\program files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] "AutoRegisterCerts"="c:\program files\Unizeto\proCertum CardManager\cryptoCertumScanner.exe" [2011-02-24 115976] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe" [2013-02-07 515888] "Bonus.SSR.FR10"="c:\program files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" [2010-10-15 941320] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\users\d.bartosik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2013-1-18 1199104] PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2013-1-9 484976] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ TdmNotify.lnk - c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe [2010-3-29 132456] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 wvauth . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x] S1 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x] S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 klnagent;Kaspersky Lab Network Agent;c:\program files\Kaspersky Lab\NetworkAgent\klnagent.exe [x] S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [x] S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usbxp.sys [x] S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k6232.sys [x] S3 GKUPRO2D;GKUPRO2D;c:\windows\system32\Drivers\GKUPRO2D.sys [x] S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . Zawartość folderu 'Zaplanowane zadania' . 2013-02-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 13:03] . 2013-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2749548007-2735581790-259122591-1000Core.job - c:\users\d.bartosik\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-07 08:30] . 2013-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2749548007-2735581790-259122591-1000UA.job - c:\users\d.bartosik\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-07 08:30] . . ------- Skan uzupełniający ------- . uStart Page = https://hansk.netbip.pl/admin/ IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000 IE: Wyślij &do programu OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105 Trusted Zone: dell.com TCP: DhcpNameServer = 194.204.152.34 194.204.159.1 DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} FF - ProfilePath - c:\users\d.bartosik\AppData\Roaming\Mozilla\Firefox\Profiles\k0fc46i1.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ig?hl=pl&source=iglk . . ------- Skojarzenia plików ------- . .txt=Notepad++_file . - - - - USUNIĘTO PUSTE WPISY - - - - . Toolbar-Locked - (no file) . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\S-1-5-21-2749548007-2735581790-259122591-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{12D54198-17EB-CD07-9D54-C6FA6365433E}*] "iaifnlgbgfcapifhhe"=hex:63,61,68,6c,6d,6f,00,00 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > 'lsass.exe'(664) c:\windows\system32\wvauth.DLL c:\windows\system32\crypto3CSP.dll . - - - - - - - > 'Explorer.exe'(6088) c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll c:\program files\Roxio\OEM\Roxio Burn\RBVirtualFolder.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\SYSTEM32\WISPTIS.EXE c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\RealVNC\VNC4\WinVNC4.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\system32\taskhost.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\program files\Common Files\microsoft shared\ink\TabTip.exe c:\windows\system32\WTablet\Wacom_TabletUser.exe c:\windows\system32\conhost.exe c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Czas ukończenia: 2013-02-19 09:17:06 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2013-02-19 08:17 . Przed: 60 339 437 568 bajtów wolnych Po: 59 976 159 232 bajtów wolnych . - - End Of File - - 0402661E2BD87E8E1423B2B2EDB6B3BD