ComboFix 14-02-01.01 - Damian 2014-02-01 18:30:06.2.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1250.48.1045.18.3059.2086 [GMT 1:00] Uruchomiony z: E:\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Utworzono nowy punkt przywracania . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\StartSearch plugin c:\program files\StartSearch plugin\IEhelperActiveX.dll c:\program files\StartSearch plugin\ssBarLcher.dll c:\program files\StartSearch plugin\StartBar.dll c:\program files\StartSearch plugin\uninst.exe c:\program files\StartSearch plugin\vshareplg.crx c:\users\Damian\svchost.exe c:\windows\IsUn0415.exe c:\windows\system32\frapsvid.dll c:\windows\system32\SET1BAE.tmp c:\windows\system32\SET21E2.tmp . . ((((((((((((((((((((((((( Pliki utworzone od 2014-01-01 do 2014-02-01 ))))))))))))))))))))))))))))))) . . 2014-02-01 17:39 . 2014-02-01 17:39 -------- d-----w- c:\users\Damian\AppData\Local\temp 2014-02-01 17:39 . 2014-02-01 17:39 -------- d-----w- c:\users\Public\AppData\Local\temp 2014-02-01 17:39 . 2014-02-01 17:39 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-01 17:39 . 2014-02-01 17:39 -------- d-----w- c:\users\CURRENT_USER\AppData\Local\temp 2014-01-26 19:00 . 2013-12-10 19:44 30520 ----a-w- c:\windows\system32\uxtuneup.dll 2014-01-26 18:58 . 2013-12-10 19:44 32568 ----a-w- c:\windows\system32\TURegOpt.exe 2014-01-26 18:58 . 2013-12-10 19:44 22328 ----a-w- c:\windows\system32\authuitu.dll 2014-01-26 18:57 . 2014-01-26 19:02 -------- dc----w- c:\program files\TuneUp Utilities 2013 2014-01-26 18:57 . 2014-01-26 19:56 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2014-01-26 18:57 . 2014-01-26 18:57 -------- d--h--w- c:\programdata\Common Files 2014-01-23 10:18 . 2013-12-18 20:10 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2014-01-23 10:06 . 2004-02-11 13:37 203976 ----a-w- c:\windows\system32\RICHTX32.OCX 2014-01-23 10:03 . 2002-02-14 09:26 647872 ----a-w- c:\windows\system32\mscomct2.ocx 2014-01-23 09:53 . 2014-01-23 09:56 -------- dc----w- c:\program files\MATLAB71 2014-01-15 13:37 . 2013-11-26 10:10 2349056 ----a-w- c:\windows\system32\win32k.sys 2014-01-15 13:37 . 2013-11-27 01:14 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2014-01-15 13:37 . 2013-11-27 01:13 284672 ----a-w- c:\windows\system32\drivers\usbport.sys 2014-01-15 13:37 . 2013-11-27 01:13 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2014-01-15 13:37 . 2013-11-27 01:13 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys 2014-01-15 13:37 . 2013-11-27 01:13 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys 2014-01-15 13:37 . 2013-11-27 01:13 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2014-01-15 13:37 . 2013-11-27 01:13 6016 ----a-w- c:\windows\system32\drivers\usbd.sys 2014-01-15 13:37 . 2013-11-26 11:11 240576 ----a-w- c:\windows\system32\drivers\netio.sys . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-17 13:15 . 2013-08-06 13:01 69240 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-12-17 13:15 . 2013-08-06 13:00 135648 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-12-17 13:15 . 2013-08-06 13:00 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-12-11 19:52 . 2012-05-25 19:18 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-12-11 19:52 . 2011-11-02 19:57 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-11-26 09:23 . 2013-12-11 21:46 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 09:22 . 2013-12-11 21:46 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 08:53 . 2013-12-11 21:46 61952 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 08:52 . 2013-12-11 21:46 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 08:29 . 2013-12-11 21:46 112128 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 08:29 . 2013-12-11 21:46 108032 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 08:28 . 2013-12-11 21:46 553472 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:16 . 2013-12-11 21:46 4243968 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 07:32 . 2013-12-11 21:46 1928192 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 06:33 . 2013-12-11 21:46 1820160 ----a-w- c:\windows\system32\wininet.dll 2013-11-23 18:26 . 2013-12-11 21:14 417792 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-19 21:35 . 2013-11-19 21:35 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-19 21:35 . 2013-11-19 21:35 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-19 21:35 . 2013-11-19 21:35 645120 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-19 21:35 . 2013-11-19 21:35 194048 ----a-w- c:\windows\system32\elshyph.dll 2013-11-19 21:35 . 2013-11-19 21:35 182272 ----a-w- c:\windows\system32\msls31.dll 2013-11-19 21:35 . 2013-11-19 21:35 86016 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-19 21:35 . 2013-11-19 21:35 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-19 21:35 . 2013-11-19 21:35 62464 ----a-w- c:\windows\system32\tdc.ocx 2013-11-19 21:35 . 2013-11-19 21:35 61952 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-11-19 21:35 . 2013-11-19 21:35 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-19 21:35 . 2013-11-19 21:35 454656 ----a-w- c:\windows\system32\vbscript.dll 2013-11-19 21:35 . 2013-11-19 21:35 36352 ----a-w- c:\windows\system32\imgutil.dll 2013-11-19 21:35 . 2013-11-19 21:35 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-19 21:35 . 2013-11-19 21:35 337408 ----a-w- c:\windows\system32\html.iec 2013-11-19 21:35 . 2013-11-19 21:35 24576 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-19 21:35 . 2013-11-19 21:35 151552 ----a-w- c:\windows\system32\iexpress.exe 2013-11-19 21:35 . 2013-11-19 21:35 139264 ----a-w- c:\windows\system32\wextract.exe 2013-11-19 21:35 . 2013-11-19 21:35 13312 ----a-w- c:\windows\system32\mshta.exe 2013-11-19 21:35 . 2013-11-19 21:35 111616 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-19 21:35 . 2013-11-19 21:35 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-12 02:07 . 2013-12-11 21:14 2048 ----a-w- c:\windows\system32\tzres.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "minerd"="c:\users\Damian\AppData\Roaming\minerd\nircmd.exe" [2013-08-11 44032] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-07 186904] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-30 1545512] "EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2009-06-16 4077384] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-20 7625248] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-11-07 6756048] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-12-17 684600] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2009-7-1 795936] TrueColorFinder.lnk - c:\program files\LG Electronics\TrueColorFinder Software\bin\TrueColorFinder.exe -startup [2013-10-18 4423680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer5"=wdmaud.drv . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Damian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^uTorrent Turbo Booster.lnk] path=c:\users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk backup=c:\windows\pss\uTorrent Turbo Booster.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2013-04-04 21:06 958576 -c--a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2012-12-19 14:39 41208 ----a-w- e:\programy\Adobr Reader\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu 10] 2011-06-19 09:42 11850344 ----a-w- e:\programy\Gadu-Gadu 10\gg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon] 2008-07-22 17:33 150528 ----a-w- e:\programy\HP\Digital Imaging\bin\HpqSRmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2012-02-28 14:02 28672 ----a-w- c:\windows\System32\qttask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2013-10-30 19:25 1820584 ----a-w- e:\gry\steam\Steam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2013-07-02 08:16 254336 -c--a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "DAEMON Tools Lite"="e:\programy\DAEMON Tools Lite\DTLite.exe" -autorun "OscarEditor"="c:\program files\OSCAR Editor X7\OscarEditor.exe" Minimum "ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Energy Management"=c:\program files\Lenovo\Energy Management\Energy Management.exe "Adobe Reader Speed Launcher"="e:\programy\Adobr Reader\Reader\Reader_sl.exe" "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "hpqSRMon"=e:\programy\HP\Digital Imaging\bin\hpqSRMon.exe "Windows Mobile Device Center"=%windir%\WindowsMobile\wmdc.exe "OnekeyDM"=c:\program files\Lenovo\OnekeyDM\OnekeyDM.exe "StereoLinksInstall"="c:\program files\NVIDIA Corporation\3D Vision\nvstlink.exe" /install1 "ISUSScheduler"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start . R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-02-28 161384] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 30312] R3 bpenum;Intel(R) WiMAX Link Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2009-07-30 56320] R3 DFX11_1;DFX Audio Enhancer 11.1;c:\windows\system32\drivers\dfx11_1.sys [2012-08-29 24424] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2013-02-06 83864] R3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\DRIVERS\emusba10.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032] R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-06-06 273448] R3 LGDDCDevice;LGDDCDevice;c:\windows\system32\LGI2CDriver.sys [2012-09-26 16384] R3 LGII2CDevice;LGII2CDevice;c:\windows\system32\LGPII2CDriver.sys [2012-12-27 10752] R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-06-06 4231680] R3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys [2002-01-12 3567] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-07-30 171520] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 121064] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 12776] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 136808] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 114280] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-26 1343400] R3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-07-30 691696] S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2012-05-16 3332784] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-10-01 37352] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2012-11-07 494416] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2012-11-07 36072] S1 funfrm;funfrm; [x] S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-12-17 440376] S2 AntiVirWebService;Avira Web Protection;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-12-17 1011768] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2013-12-10 1729336] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 59904] S3 enecirhid;ENE CIR HID Receiver;c:\windows\system32\DRIVERS\enecirhid.sys [2009-05-19 11776] S3 enecirhidma;ENE CIR HIDmini Filter;c:\windows\system32\DRIVERS\enecirhidma.sys [2008-04-24 5632] S3 NETw5s32;Sterownik karty Intel(R) Wireless WiFi Link dla systemu Windows 7 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-09-19 10088] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-01-29 06:57 1211672 -c--a-w- c:\program files\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe . Zawartość folderu 'Zaplanowane zadania' . 2014-02-01 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-25 19:52] . 2014-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-06-15 11:22] . 2014-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-06-15 11:22] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://pl.yahoo.com?fr=fp-comodo IE: E&ksportuj do programu Microsoft Excel - e:\programy\Office\Office14\EXCEL.EXE/3000 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Wyślij &do programu OneNote - e:\programy\Office\Office14\ONBttnIE.dll/105 IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 5.45.75.36 5.45.75.11 FF - ProfilePath - c:\users\Damian\AppData\Roaming\Mozilla\Firefox\Profiles\zq7o3gyl.default\ FF - prefs.js: browser.search.selectedEngine - Search the web FF - prefs.js: browser.startup.homepage - www.google.pl FF - prefs.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q= FF - user.js: browser.search.selectedEngine - Search the web FF - user.js: browser.search.order.1 - Search the web FF - user.js: browser.search.defaultenginename - Search the web FF - user.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q= FF - user.js: privacy.item.cookies - false FF - user.js: privacy.sanitize.promptOnSanitize - false FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - 4eaf71cd000000000000000000000007 FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15920 FF - user.js: extensions.delta.vrsn - 1.8.22.0 FF - user.js: extensions.delta.vrsni - 1.8.22.0 FF - user.js: extensions.delta.vrsnTs - 1.8.22.010:56 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - babsst FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - en FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.ffxUnstlRst - true FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta_i.babTrack - affID=121564&tsp=4963 FF - user.js: extensions.delta_i.babExt - FF - user.js: extensions.delta_i.srcExt - ss FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false . - - - - USUNIĘTO PUSTE WPISY - - - - . MSConfigStartUp-HP Software Update - e:\programy\HP\HP Software Update\HPWuSchd2.exe MSConfigStartUp-NokiaSuite - c:\program files\Nokia\Nokia Suite\NokiaSuite.exe MSConfigStartUp-PC Suite Tray - e:\programy\Nokia\Nokia PC Suite 7\PCSuite.exe AddRemove-LiveVDO plugin - c:\program files\StartSearch plugin\uninst.exe AddRemove-{0C9221F6-1EA9-4D92-892D-A5FEB3084A75} - c:\programdata\{2A082487-0FFF-4FD5-BE3C-DE59C1ECC4E0}\NFSU2_PL.exe . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > 'winlogon.exe'(696) c:\windows\system32\guard32.dll . - - - - - - - > 'lsass.exe'(608) c:\windows\system32\guard32.dll . Czas ukończenia: 2014-02-01 18:41:56 ComboFix-quarantined-files.txt 2014-02-01 17:41 . Przed: 9 904 128 000 bajtów wolnych Po: 9 934 934 016 bajtów wolnych . - - End Of File - - 57C0D686A2D3447C5A1F32F642E8E17D A36C5E4F47E84449FF07ED3517B43A31