ComboFix 16-04-29.01 - Ewelina Jarosz 2016-05-01 19:21:16.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1250.48.1045.18.4040.1210 [GMT 2:00] Uruchomiony z: c:\users\Ewelina Jarosz\Desktop\ComboFix.exe AV: AVG AntiVirus Free Edition *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413} SP: AVG AntiVirus Free Edition *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\ntuser.pol c:\windows\s.bat c:\windows\wininit.ini . . ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_AdobeUpdateService . . ((((((((((((((((((((((((( Pliki utworzone od 2016-04-01 do 2016-05-01 ))))))))))))))))))))))))))))))) . . 2016-05-01 18:00 . 2016-05-01 18:00 -------- d-----w- c:\users\Default\AppData\Local\temp 2016-04-22 09:03 . 2016-04-22 09:03 -------- d-----w- c:\users\Ewelina Jarosz\AppData\Roaming\anyburn 2016-04-22 09:03 . 2016-04-22 09:03 -------- d-----w- c:\program files (x86)\AnyBurn 2016-04-19 09:41 . 2016-04-19 14:14 -------- d-----w- c:\users\Ewelina Jarosz\AppData\Local\Quark 2016-04-19 09:41 . 2016-04-19 09:41 -------- d-----w- c:\users\Ewelina Jarosz\AppData\Roaming\Quark 2016-04-19 09:35 . 2016-04-23 05:26 -------- d-----w- c:\programdata\Quark 2016-04-19 09:35 . 2016-05-01 16:44 -------- d-----w- c:\program files\Quark 2016-04-13 15:53 . 2016-03-16 18:50 156672 ----a-w- c:\windows\system32\mtxoci.dll 2016-04-13 15:53 . 2016-03-16 18:28 111616 ----a-w- c:\windows\SysWow64\mtxoci.dll 2016-04-13 15:53 . 2016-03-16 18:28 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll 2016-04-13 15:53 . 2016-03-16 18:27 286720 ----a-w- c:\program files (x86)\Common Files\System\Ole DB\msdaora.dll 2016-04-13 15:51 . 2016-02-05 20:16 8192 ----a-w- c:\windows\system32\drivers\pl-PL\tpm.sys.mui 2016-04-13 15:22 . 2016-04-13 15:22 -------- d-----w- C:\found.002 2016-04-12 08:40 . 2016-04-13 15:24 -------- d-----w- c:\program files\Mozilla Firefox 2016-04-08 12:49 . 2016-04-08 12:49 5934784 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2016-04-15 07:21 . 2014-06-13 06:44 135176864 ----a-w- c:\windows\system32\MRT.exe 2016-04-08 12:50 . 2015-01-04 20:25 797376 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2016-04-08 12:50 . 2015-01-04 20:25 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2016-03-17 22:24 . 2016-04-13 15:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2016-03-08 15:12 . 2016-03-08 15:12 71456 ----a-w- c:\windows\system32\drivers\avguniva.sys 2016-03-08 15:12 . 2016-03-08 15:12 306976 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys 2016-03-07 12:39 . 2016-03-07 12:39 246560 ----a-w- c:\windows\system32\drivers\avgmfx64.sys 2016-02-20 15:35 . 2016-02-20 15:35 0 ----a-w- c:\windows\SysWow64\sho2B62.tmp 2016-02-17 03:11 . 2016-02-17 03:11 0 ----a-w- c:\windows\SysWow64\sho402F.tmp 2016-02-16 14:07 . 2016-02-16 14:07 162592 ----a-w- c:\windows\system32\drivers\avgdiska.sys 2016-02-16 14:05 . 2016-02-16 14:05 360736 ----a-w- c:\windows\system32\drivers\avgloga.sys 2016-02-12 18:52 . 2016-03-29 17:44 98816 ----a-w- c:\windows\system32\wudriver.dll 2016-02-12 18:52 . 2016-03-29 17:44 3169792 ----a-w- c:\windows\system32\wucltux.dll 2016-02-12 18:52 . 2016-03-29 17:44 192512 ----a-w- c:\windows\system32\wuwebv.dll 2016-02-12 18:44 . 2016-03-29 17:44 91136 ----a-w- c:\windows\system32\WinSetupUI.dll 2016-02-12 18:39 . 2016-03-29 17:44 174080 ----a-w- c:\windows\SysWow64\wuwebv.dll 2016-02-12 18:22 . 2016-03-29 17:44 2610688 ----a-w- c:\windows\system32\wuaueng.dll 2016-02-12 18:19 . 2016-03-29 17:44 709120 ----a-w- c:\windows\system32\wuapi.dll 2016-02-12 18:18 . 2016-03-29 17:44 37888 ----a-w- c:\windows\system32\wuapp.exe 2016-02-12 18:18 . 2016-03-29 17:44 140288 ----a-w- c:\windows\system32\wuauclt.exe 2016-02-12 18:18 . 2016-03-29 17:44 36864 ----a-w- c:\windows\system32\wups.dll 2016-02-12 18:18 . 2016-03-29 17:44 37888 ----a-w- c:\windows\system32\wups2.dll 2016-02-12 18:18 . 2016-03-29 17:44 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll 2016-02-12 18:06 . 2016-03-29 17:44 573440 ----a-w- c:\windows\SysWow64\wuapi.dll 2016-02-12 18:05 . 2016-03-29 17:44 93696 ----a-w- c:\windows\SysWow64\wudriver.dll 2016-02-12 18:05 . 2016-03-29 17:44 30208 ----a-w- c:\windows\SysWow64\wups.dll 2016-02-12 18:05 . 2016-03-29 17:44 35328 ----a-w- c:\windows\SysWow64\wuapp.exe 2016-02-09 09:57 . 2016-03-29 17:42 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2016-02-09 09:57 . 2016-03-29 17:42 14634496 ----a-w- c:\windows\system32\wmp.dll 2016-02-09 09:56 . 2016-03-29 17:42 5120 ----a-w- c:\windows\system32\msdxm.ocx 2016-02-09 09:56 . 2016-03-29 17:42 5120 ----a-w- c:\windows\system32\dxmasf.dll 2016-02-09 09:55 . 2016-03-29 17:42 30720 ----a-w- c:\windows\system32\seclogon.dll 2016-02-09 09:54 . 2016-03-29 17:42 9728 ----a-w- c:\windows\system32\spwmp.dll 2016-02-09 09:51 . 2016-03-29 17:42 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2016-02-09 09:13 . 2016-03-29 17:42 4096 ----a-w- c:\windows\SysWow64\msdxm.ocx 2016-02-09 09:13 . 2016-03-29 17:42 4096 ----a-w- c:\windows\SysWow64\dxmasf.dll 2016-02-09 09:13 . 2016-03-29 17:42 8192 ----a-w- c:\windows\SysWow64\spwmp.dll 2016-02-06 19:59 . 2015-06-07 19:58 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2016-02-05 18:54 . 2016-03-29 17:42 41472 ----a-w- c:\windows\system32\lpk.dll 2016-02-05 18:54 . 2016-03-29 17:42 100864 ----a-w- c:\windows\system32\fontsub.dll 2016-02-05 18:53 . 2016-03-29 17:42 14336 ----a-w- c:\windows\system32\dciman32.dll 2016-02-05 18:53 . 2016-03-29 17:42 46080 ----a-w- c:\windows\system32\atmlib.dll 2016-02-05 18:50 . 2016-03-29 17:42 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2016-02-05 18:44 . 2016-03-29 17:42 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2016-02-05 18:42 . 2016-03-29 17:42 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2016-02-05 17:48 . 2016-03-29 17:42 372736 ----a-w- c:\windows\system32\atmfd.dll 2016-02-05 17:43 . 2016-03-29 17:42 299520 ----a-w- c:\windows\SysWow64\atmfd.dll 2016-02-05 17:43 . 2016-03-29 17:42 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2016-02-05 01:19 . 2016-03-29 17:42 381440 ----a-w- c:\windows\system32\mfds.dll 2016-02-04 18:41 . 2016-03-29 17:42 296448 ----a-w- c:\windows\SysWow64\mfds.dll 2016-02-03 18:58 . 2016-03-29 17:44 862208 ----a-w- c:\windows\system32\oleaut32.dll 2016-02-03 18:52 . 2016-03-29 17:44 84992 ----a-w- c:\windows\system32\asycfilt.dll 2016-02-03 18:49 . 2016-03-29 17:44 572416 ----a-w- c:\windows\SysWow64\oleaut32.dll 2016-02-03 18:43 . 2016-03-29 17:44 67584 ----a-w- c:\windows\SysWow64\asycfilt.dll 2016-02-03 18:07 . 2016-03-29 17:44 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-03-13 7451928] "uTorrent"="c:\users\Ewelina Jarosz\AppData\Roaming\uTorrent\uTorrent.exe" [2016-04-07 1959424] "Akamai NetSession Interface"="c:\users\Ewelina Jarosz\AppData\Local\Akamai\netsession_win.exe" [2015-09-10 4691384] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-02-18 283160] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-28 336384] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2015-09-17 2292912] "AVG_UI"="c:\program files (x86)\AVG\Av\avuirunnerx.exe" [2016-04-06 32528] "AvgUi"="c:\program files (x86)\AVG\Framework\Common\avguirnx.exe" [2016-04-14 186640] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-01-29 594992] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AvgAMPS;AvgAMPS;c:\program files (x86)\AVG\Av\avgamps.exe;c:\program files (x86)\AVG\Av\avgamps.exe [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x] R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ew_usbenumfilter.sys [x] R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x] R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juextctrl.sys [x] R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x] S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x] S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x] S0 Avguniva;AVG Universal Driver;c:\windows\system32\DRIVERS\avguniva.sys;c:\windows\SYSNATIVE\DRIVERS\avguniva.sys [x] S0 fbfmon;fbfmon;c:\windows\system32\drivers\fbfmon.sys;c:\windows\SYSNATIVE\drivers\fbfmon.sys [x] S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x] S1 BPntDrv;BPntDrv;c:\windows\system32\drivers\BPntDrv.sys;c:\windows\SYSNATIVE\drivers\BPntDrv.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\Av\avgidsagent.exe;c:\program files (x86)\AVG\Av\avgidsagent.exe [x] S2 avgsvc;AVG Service;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe [x] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\Av\avgwdsvcx.exe;c:\program files (x86)\AVG\Av\avgwdsvcx.exe [x] S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x] S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 wordpressApache;wordpressApache;c:\bitnami\WORDPR~1.3-0\apache2\bin\httpd.exe;c:\bitnami\WORDPR~1.3-0\apache2\bin\httpd.exe [x] S2 wordpressMySQL;wordpressMySQL;c:\bitnami\wordpress-4.2.3-0\mysql\bin\mysqld.exe;c:\bitnami\wordpress-4.2.3-0\mysql\bin\mysqld.exe [x] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys;c:\windows\SYSNATIVE\DRIVERS\AcpiVpc.sys [x] S3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 IntcDAud;Intel(R) Audio dla ekranów;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 vm2uvcflt;Vimicro USB Camera Filter 2;c:\windows\system32\Drivers\vm2uvcflt.sys;c:\windows\SYSNATIVE\Drivers\vm2uvcflt.sys [x] S3 vm332avs;Lenovo Camera2;c:\windows\system32\Drivers\vm332avs.sys;c:\windows\SYSNATIVE\Drivers\vm332avs.sys [x] . . --- Inne Usługi/Sterowniki w Pamięci --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2016-04-11 19:46 1106072 ----a-w- c:\program files (x86)\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe . Zawartość folderu 'Zaplanowane zadania' . 2016-05-01 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-04 12:50] . 2016-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-18 18:03] . 2016-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-18 18:03] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2015-09-11 17:02 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2015-09-11 17:02 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2015-09-11 17:02 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc] @="{771C7324-DA80-49D3-8017-753B0AF60951}" [HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}] 2011-10-16 19:23 1508192 ----a-w- c:\windows\System32\IcnOvrly.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-25 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-25 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-25 418840] "Lenovo EE Boot Optimizer"="c:\program files (x86)\Lenovo\Boot Optimizer\PopWnd.exe" [2011-10-16 114688] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2011-10-16 9753024] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2011-10-16 5908928] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-09-04 508104] . ------- Skan uzupełniający ------- . uStart Page = hxxp://do-search.com/?type=hppp&ts=1427486579&from=cor&uid=WDCXWD7500BPVT-24HXZT3_WD-WX41E81JKP50JKP50 uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://do-search.com/web/?type=dspp&ts=1427486579&from=cor&uid=WDCXWD7500BPVT-24HXZT3_WD-WX41E81JKP50JKP50&q={searchTerms} mDefault_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1427486496&from=cor&uid=WDCXWD7500BPVT-24HXZT3_WD-WX41E81JKP50JKP50&q={searchTerms} mDefault_Page_URL = hxxp://do-search.com/?type=hppp&ts=1427486579&from=cor&uid=WDCXWD7500BPVT-24HXZT3_WD-WX41E81JKP50JKP50 mStart Page = hxxp://do-search.com/?type=hppp&ts=1427486579&from=cor&uid=WDCXWD7500BPVT-24HXZT3_WD-WX41E81JKP50JKP50 mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://do-search.com/web/?type=ds&ts=1427486496&from=cor&uid=WDCXWD7500BPVT-24HXZT3_WD-WX41E81JKP50JKP50&q={searchTerms} uInternet Settings,ProxyOverride = IE: E&ksportuj do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.0.1 192.168.0.2 FF - ProfilePath - c:\users\Ewelina Jarosz\AppData\Roaming\Mozilla\Firefox\Profiles\ksizquol.default-1432147414094\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ . - - - - USUNIĘTO PUSTE WPISY - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) Toolbar-10 - (no file) ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\program files (x86)\Lenovo\YouCam\YCMMirage.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Czas ukończenia: 2016-05-01 20:11:20 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2016-05-01 18:11 . Przed: 30 917 292 032 bajtów wolnych Po: 31 281 545 216 bajtów wolnych . - - End Of File - - 6347D9E90690F1D1B00AE66273F47170