ComboFix 13-05-01.03 - Henry 2013-05-04 13:10:52.5.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1250.48.1045.18.4095.2681 [GMT 2:00] Uruchomiony z: c:\users\Henry\Desktop\ComboFix.exe AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} FW: ZoneAlarm Free Firewall Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B} SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Pliki utworzone od 2013-04-04 do 2013-05-04 ))))))))))))))))))))))))))))))) . . 2013-05-04 11:15 . 2013-05-04 11:15 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-05-04 11:15 . 2013-05-04 11:15 -------- d-----w- c:\users\Public\AppData\Local\temp 2013-05-04 11:15 . 2013-05-04 11:15 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-05-03 18:31 . 2013-05-03 18:31 -------- d-----w- c:\program files (x86)\Color Style Studio 2013-04-24 14:37 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-23 04:10 . 2013-04-23 04:10 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-04-23 04:09 . 2013-04-04 03:35 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-16 18:55 . 2013-04-16 18:55 -------- d-----w- c:\users\Henry\AppData\Roaming\Check Point Software Technologies LTD 2013-04-10 14:07 . 2013-03-01 03:36 3153408 ----a-w- c:\windows\system32\win32k.sys 2013-04-10 14:07 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys 2013-04-10 14:07 . 2013-03-19 06:04 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-04-10 14:07 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-04-10 14:07 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-04-10 14:07 . 2013-03-19 05:46 43520 ----a-w- c:\windows\system32\csrsrv.dll 2013-04-10 14:07 . 2013-03-19 04:47 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll 2013-04-10 14:07 . 2013-03-19 03:06 112640 ----a-w- c:\windows\system32\smss.exe . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-03 19:29 . 2012-02-15 16:30 22368 ----a-w- c:\windows\system32\drivers\AFD.SYS 2013-05-03 19:29 . 2009-07-14 00:10 22368 ----a-w- c:\windows\system32\drivers\WS2IFSL.SYS 2013-04-30 17:46 . 2012-04-05 04:58 691592 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-30 17:46 . 2011-05-16 10:40 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-10 20:16 . 2011-01-19 17:41 72702784 ----a-w- c:\windows\system32\MRT.exe 2013-03-13 21:46 . 2013-03-13 21:46 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-03-13 21:46 . 2013-03-13 21:46 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-03-13 21:46 . 2013-03-13 21:46 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-03-13 21:45 . 2013-03-13 21:45 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-03-13 21:45 . 2013-03-13 21:45 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-03-13 21:45 . 2013-03-13 21:45 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-03-13 21:45 . 2013-03-13 21:45 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-03-13 21:45 . 2013-03-13 21:45 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-03-13 21:45 . 2013-03-13 21:45 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-03-13 21:45 . 2013-03-13 21:45 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-03-13 21:45 . 2013-03-13 21:45 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-03-13 21:45 . 2013-03-13 21:45 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-03-13 21:45 . 2013-03-13 21:45 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-03-13 21:45 . 2013-03-13 21:45 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-03-13 21:45 . 2013-03-13 21:45 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-03-13 21:45 . 2013-03-13 21:45 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-03-13 21:45 . 2013-03-13 21:45 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-03-13 21:45 . 2013-03-13 21:45 197120 ----a-w- c:\windows\system32\msrating.dll 2013-03-13 21:45 . 2013-03-13 21:45 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-03-13 21:45 . 2013-03-13 21:45 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-03-13 21:45 . 2013-03-13 21:45 441856 ----a-w- c:\windows\system32\html.iec 2013-03-13 21:45 . 2013-03-13 21:45 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-03-13 21:45 . 2013-03-13 21:45 216064 ----a-w- c:\windows\system32\msls31.dll 2013-03-13 21:45 . 2013-03-13 21:45 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-03-13 21:45 . 2013-03-13 21:45 81408 ----a-w- c:\windows\system32\icardie.dll 2013-03-13 21:45 . 2013-03-13 21:45 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-03-13 21:45 . 2013-03-13 21:45 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-03-13 21:45 . 2013-03-13 21:45 235008 ----a-w- c:\windows\system32\url.dll 2013-03-13 21:45 . 2013-03-13 21:45 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-03-13 21:45 . 2013-03-13 21:45 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-03-13 21:45 . 2013-03-13 21:45 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-03-13 21:45 . 2013-03-13 21:45 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-03-13 21:45 . 2013-03-13 21:45 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-03-13 21:45 . 2013-03-13 21:45 144896 ----a-w- c:\windows\system32\wextract.exe 2013-03-13 21:45 . 2013-03-13 21:45 102912 ----a-w- c:\windows\system32\inseng.dll 2013-03-13 21:45 . 2013-03-13 21:45 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-03-13 21:45 . 2013-03-13 21:45 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-03-13 21:45 . 2013-03-13 21:45 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-03-13 21:45 . 2013-03-13 21:45 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-03-13 21:45 . 2013-03-13 21:45 149504 ----a-w- c:\windows\system32\occache.dll 2013-03-13 21:45 . 2013-03-13 21:45 13824 ----a-w- c:\windows\system32\mshta.exe 2013-03-13 21:45 . 2013-03-13 21:45 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-03-13 21:45 . 2013-03-13 21:45 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-03-13 21:45 . 2013-03-13 21:45 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-03-13 21:45 . 2013-03-13 21:45 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-03-13 21:45 . 2013-03-13 21:45 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-03-13 21:45 . 2013-03-13 21:45 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-03-13 21:45 . 2013-03-13 21:45 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-03-13 21:45 . 2013-03-13 21:45 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-03-05 19:01 . 2012-06-18 08:41 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-03-05 19:01 . 2011-01-19 17:14 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-02-25 23:32 . 2013-02-25 23:32 25256224 ----a-w- c:\windows\system32\nvcompiler.dll 2013-02-25 23:32 . 2013-02-25 23:32 2505144 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-02-25 23:32 . 2013-02-25 23:32 15129960 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-02-25 23:32 . 2013-02-25 23:32 6262608 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-02-25 23:32 . 2011-01-19 16:49 2826040 ----a-w- c:\windows\system32\nvapi64.dll 2013-02-25 23:32 . 2013-02-25 23:32 18055184 ----a-w- c:\windows\system32\nvd3dumx.dll 2013-02-25 23:32 . 2011-09-05 07:35 1814304 ----a-w- c:\windows\system32\nvdispco64.dll 2013-02-25 23:32 . 2013-02-25 23:32 2720544 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2013-02-25 23:32 . 2013-02-25 23:32 26929440 ----a-w- c:\windows\system32\nvoglv64.dll 2013-02-25 23:32 . 2013-02-25 23:32 7932256 ----a-w- c:\windows\SysWow64\nvcuda.dll 2013-02-25 23:32 . 2013-02-25 23:32 2346784 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-02-25 23:32 . 2013-02-25 23:32 11036448 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-02-25 23:32 . 2012-10-10 20:23 1510176 ----a-w- c:\windows\system32\nvdispgenco64.dll 2013-02-25 23:32 . 2013-02-25 23:32 2904352 ----a-w- c:\windows\system32\nvcuvid.dll 2013-02-25 23:32 . 2013-02-25 23:32 20449056 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2013-02-25 23:32 . 2009-07-13 21:59 15053264 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-02-25 23:32 . 2013-02-25 23:32 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2013-02-25 23:32 . 2013-02-25 23:32 7564040 ----a-w- c:\windows\system32\nvopencl.dll 2013-02-25 23:32 . 2013-02-25 23:32 1985824 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-02-25 23:32 . 2013-02-25 23:32 12641992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-02-25 23:32 . 2013-02-25 23:32 9390760 ----a-w- c:\windows\system32\nvcuda.dll 2013-02-12 05:45 . 2013-03-13 15:38 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-13 15:38 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-13 15:38 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-13 15:38 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-13 15:38 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-13 15:38 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-02-12 04:12 . 2013-03-13 21:34 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2013-01-29 73832] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2012-11-13 450560] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2012-11-30 1263512] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-12-11 3147384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-19 1255736] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-10-15 63328] S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120] S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-11-15 111968] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-10-24 503352] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664] S2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2012-11-22 33712] S2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2012-11-22 828072] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-10 14:49 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Zawartość folderu 'Zaplanowane zadania' . 2013-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-17 19:24] . 2013-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-17 19:24] . 2013-01-24 c:\windows\Tasks\ROC_REG_JAN_DELETE.job - c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-23 21:16] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-09-04 767312] "ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2012-11-22 1127592] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Skan uzupełniający ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.gazeta.pl/0,0.html?p=128 mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&ksportuj do programu Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Wyślij &do programu OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 Trusted Zone: mks.com.pl\www FF - ProfilePath - c:\users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\ogd2kv4s.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Search By ZoneAlarm FF - prefs.js: browser.startup.homepage - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=7fad1d0ba5f84f6bbef7b994b19facf3&tu=10GX0007b2B000v&sku=&tstsId=&ver=& FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&q= FF - ExtSQL: 2013-04-16 20:57; ffxtlbr@zonealarm.com; c:\users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\ogd2kv4s.default\extensions\ffxtlbr@zonealarm.com FF - ExtSQL: 2013-04-16 20:57; {FFB96CC1-7EB3-449D-B827-DB661701C6BB}; c:\program files\CheckPoint\ZAForceField\WOW64\TrustChecker FF - user.js: extensions.zonealarm.hpOld0 - hxxp://www.google.pl/ FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=base2013&Lan={dfltLng}&gu=7fad1d0ba5f84f6bbef7b994b19facf3&tu=10GX0007b2B000v&sku=&tstsId=&ver=&&q= FF - user.js: extensions.zonealarm.id - f4c202a1000000000000002215a2afdb FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84} FF - user.js: extensions.zonealarm.instlDay - 15811 FF - user.js: extensions.zonealarm.vrsn - 1.8.11.6 FF - user.js: extensions.zonealarm.vrsni - 1.8.11.6 FF - user.js: extensions.zonealarm.vrsnTs - 1.8.11.620:55 FF - user.js: extensions.zonealarm.prtnrId - checkpoint FF - user.js: extensions.zonealarm.prdct - zonealarm FF - user.js: extensions.zonealarm.aflt - 1025 FF - user.js: extensions.zonealarm.smplGrp - none FF - user.js: extensions.zonealarm.tlbrId - base2013 FF - user.js: extensions.zonealarm.instlRef - ZLN24592994636691-1025 FF - user.js: extensions.zonealarm.dfltLng - en FF - user.js: extensions.zonealarm.excTlbr - false FF - user.js: extensions.zonealarm.ffxUnstlRst - false FF - user.js: extensions.zonealarm.admin - false FF - user.js: extensions.zonealarm.autoRvrt - false FF - user.js: extensions.zonealarm.rvrt - false FF - user.js: extensions.zonealarm.hmpg - true FF - user.js: extensions.zonealarm.hmpgUrl - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=7fad1d0ba5f84f6bbef7b994b19facf3&tu=10GX0007b2B000v&sku=&tstsId=&ver=& FF - user.js: extensions.zonealarm.dfltSrch - true FF - user.js: extensions.zonealarm.srchPrvdr - Search By ZoneAlarm FF - user.js: extensions.zonealarm.kw_url - hxxp://search.zonealarm.com/search?src=sp&tbid=base2013&Lan=en&gu=7fad1d0ba5f84f6bbef7b994b19facf3&tu=10GX0007b2B000v&sku=&tstsId=&ver=&&q= FF - user.js: extensions.zonealarm.dnsErr - true FF - user.js: extensions.zonealarm.newTab - true FF - user.js: extensions.zonealarm.newTabUrl - hxxp://search.zonealarm.com/?src=nt&tbid=base2013&Lan=en&gu=7fad1d0ba5f84f6bbef7b994b19facf3&tu=10GX0007b2B000v&sku=&tstsId=&ver=& . - - - - USUNIĘTO PUSTE WPISY - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\S-1-5-21-3178316281-1305049942-2870513097-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3178316281-1305049942-2870513097-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2013-05-04 13:16:54 ComboFix-quarantined-files.txt 2013-05-04 11:16 ComboFix2.txt 2012-07-10 20:37 . Przed: 22 666 973 184 bajtów wolnych Po: 21 961 469 952 bajtów wolnych . - - End Of File - - 90758D79E0DB2FE2B92840B3E88BCECE