ComboFix 12-07-26.03 - hp 2012-07-25 18:14:04.1.2 - x86 MINIMAL Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.48.1045.18.3069.2591 [GMT 2:00] Uruchomiony z: H:\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Utworzono nowy punkt przywracania . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\data C:\install.exe c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe c:\programdata\wxDfast c:\programdata\wxDfast\background.html c:\programdata\wxDfast\bccldkoinakjmmgebambiaggjobhikfg.crx c:\programdata\wxDfast\bhoclass.dll c:\programdata\wxDfast\content.js c:\programdata\wxDfast\data\content.js c:\programdata\wxDfast\data\jsondb.js c:\programdata\wxDfast\settings.ini c:\programdata\wxDfast\uninstall.exe c:\users\hp\AppData\Roaming\PriceGong c:\users\hp\AppData\Roaming\PriceGong\Data\mru.xml c:\windows\IsUn0415.exe . . ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_usnjsvc . . ((((((((((((((((((((((((( Pliki utworzone od 2012-06-25 do 2012-07-25 ))))))))))))))))))))))))))))))) . . 2012-07-25 16:25 . 2012-07-25 16:32 -------- d-----w- c:\users\hp\AppData\Local\temp 2012-07-25 16:25 . 2012-07-25 16:25 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-07-25 16:25 . 2012-07-25 16:25 -------- d-----w- c:\users\ADMINI~1\AppData\Local\temp 2012-07-25 15:36 . 2012-07-25 15:36 -------- d-----w- C:\BOS 2012-07-20 16:59 . 2012-07-20 16:59 -------- d-----w- c:\users\hp\AppData\Roaming\Moje pliki Bitwy o Śródziemie™ II 2012-07-20 16:46 . 2012-07-20 16:46 -------- d-----w- c:\program files\Electronic Arts 2012-07-06 17:41 . 2012-07-06 17:41 476936 ----a-w- c:\windows\system32\npdeployJava1.dll 2012-07-05 15:21 . 2012-07-05 15:21 -------- d-----w- c:\programdata\Babylon 2012-07-05 15:21 . 2012-07-05 15:21 -------- d-----w- c:\users\hp\AppData\Roaming\Babylon 2012-07-04 22:20 . 2012-07-04 22:20 -------- d-----w- c:\program files\EA SPORTS 2012-06-27 18:30 . 2012-06-27 18:31 4317184 ----a-w- c:\windows\system32\Launcher.atm . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-13 13:37 . 2011-08-06 16:58 444952 ----a-w- c:\windows\system32\wrap_oal.dll 2012-07-13 13:37 . 2011-08-06 16:58 109080 ----a-w- c:\windows\system32\OpenAL32.dll 2012-07-06 17:41 . 2011-04-24 10:59 472840 ----a-w- c:\windows\system32\deployJava1.dll 2012-06-29 08:44 . 2012-07-23 20:08 6891424 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64B926F6-2181-4971-8B49-42E4CC0C2F31}\mpengine.dll 2012-05-31 10:25 . 2011-02-08 17:33 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-05-03 02:54 . 2012-05-03 02:54 42392 ----a-w- c:\windows\system32\xfcodec.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}"= "c:\program files\InnoGames_Polska\prxtbInn1.dll" [2011-05-09 176936] "{87d5d709-40f2-48a7-8f47-7bb821af70ab}"= "c:\program files\Softonic-Polska2\prxtbSof2.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}] . [HKEY_CLASSES_ROOT\clsid\{87d5d709-40f2-48a7-8f47-7bb821af70ab}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}] 2011-05-09 09:49 176936 ----a-w- c:\program files\InnoGames_Polska\prxtbInn1.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87d5d709-40f2-48a7-8f47-7bb821af70ab}] 2011-05-09 09:49 176936 ----a-w- c:\program files\Softonic-Polska2\prxtbSof2.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}"= "c:\program files\InnoGames_Polska\prxtbInn1.dll" [2011-05-09 176936] "{87d5d709-40f2-48a7-8f47-7bb821af70ab}"= "c:\program files\Softonic-Polska2\prxtbSof2.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}] . [HKEY_CLASSES_ROOT\clsid\{87d5d709-40f2-48a7-8f47-7bb821af70ab}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{14F6A182-4C6F-45AE-9F5A-AA3CCBB1CFA3}"= "c:\program files\InnoGames_Polska\prxtbInn1.dll" [2011-05-09 176936] "{87D5D709-40F2-48A7-8F47-7BB821AF70AB}"= "c:\program files\Softonic-Polska2\prxtbSof2.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}] . [HKEY_CLASSES_ROOT\clsid\{87d5d709-40f2-48a7-8f47-7bb821af70ab}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392] "AQQ"="c:\users\hp\NOWYFO~1\WAPSTE~1\AQQ.exe" [2012-07-16 10354176] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Gadu-Gadu 10"="c:\users\hp\Programy\GG\Gadu-Gadu 10\gg.exe" [2010-07-21 12477024] "DAEMON Tools Lite"="c:\users\hp\Programy\Nowy folder\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912] "Steam"="c:\users\hp\Programy\Steam\Steam.exe" [2012-01-06 1242448] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "PCSpeedUp"="c:\program files\Przyspiesz Komputer\PCSpeedUp.lnk" [2011-08-19 2059] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-09-11 446556] "DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-09-26 1148200] "TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-09-25 1152296] "CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-09-25 189736] "TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2008-09-24 206120] "DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-07-14 814144] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-09-05 206128] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-09-23 912688] "BabylonToolbar"="c:\program files\BabylonToolbar\BabylonToolbar\1.4.23.10\BabylonToolbarsrv.exe" [2010-11-07 286720] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "4StoryPrePatch"="c:\users\hp\Gry\4Story\PrePatch.exe" [2012-02-12 327680] "TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2012-06-13 296056] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ DesktopVideoPlayer.lnk - c:\users\hp\AppData\Local\vghd\bin\vghd.exe [2012-5-3 914432] fliptoast.lnk - c:\program files\fliptoast\fliptoast.exe [N/A] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer4"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli DPPWDFLT . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe [x] . . --- Inne Usługi/Sterowniki w Pamięci --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Zawartość folderu 'Zaplanowane zadania' . 2012-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3537887629-1165293101-3988030321-1000Core.job - c:\users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-08 16:35] . 2012-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3537887629-1165293101-3988030321-1000UA.job - c:\users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-08 16:35] . 2012-04-27 c:\windows\Tasks\Norton Security Scan for hp.job - c:\progra~1\NORTON~2\Engine\353~1.1\Nss.exe [2012-03-19 05:53] . 2012-07-25 c:\windows\Tasks\User_Feed_Synchronization-{2C8942AB-35D1-451B-96FE-D7CFF6092F10}.job - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://search.babylon.com/?affID=112059&tt=010712_3&babsrc=HP_ss&mntrId=1065357000000000000000242b181b31 mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=91&bd=Pavilion&pf=cnnb IE: &Wyszukiwarka na pasku narzędzi AOL - c:\programdata\AOL\ieToolbar\resources\pl-PL\local\search.html IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.1.254 . - - - - USUNIĘTO PUSTE WPISY - - - - . URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) BHO-{F651FB60-08F7-47E5-B77C-26AEACF94ED2} - c:\programdata\wxDfast\bhoclass.dll Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKLM-Run-UCam_Menu - c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdateLBPShortCut - c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdatePSTShortCut - c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdateP2GoShortCut - c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdatePDIRShortCut - c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe AddRemove-Heroes III The Shadow of Death - c:\windows\IsUn0415.exe AddRemove-{4F4C5E11-0612-48D2-8055-987992AAC432} - c:\programdata\wxDfast\uninstall.exe AddRemove-1076177224.www.pcspeedup.com - c:\program files\Microsoft Silverlight\4.0.60310.0\Silverlight.Configuration.exe . . . ************************************************************************** skanowanie ukrytych procesów ... . skanowanie ukrytych wpisów autostartu ... . skanowanie ukrytych plików ... . skanowanie pomyślnie ukończone ukryte pliki: . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}] "ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl" . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > 'lsass.exe'(708) c:\windows\system32\DPPWDFLT.dll . - - - - - - - > 'Explorer.exe'(5756) c:\program files\DigitalPersona\Bin\DpoFeedb.dll c:\windows\system32\btmmhook.dll c:\program files\DigitalPersona\Bin\DpoSet.dll c:\windows\system32\btncopy.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe c:\windows\system32\Hpservice.exe c:\windows\system32\vfsFPService.exe c:\windows\system32\WLANExt.exe c:\program files\DigitalPersona\Bin\DpHostW.exe c:\windows\System32\lpksetup.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Przyspiesz Komputer\PCSUService.exe c:\windows\system32\PnkBstrA.exe c:\program files\SMINST\BLService.exe c:\program files\CyberLink\Shared files\RichVideo.exe c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe c:\windows\system32\WUDFHost.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\system32\conime.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\ehome\ehmsas.exe c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE c:\program files\Hewlett-Packard\Shared\HpqToaster.exe c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe c:\users\hp\AppData\Local\vghd\bin\VirtuaGirl_Downloader.exe c:\program files\Synaptics\SynTP\SynTPHelper.exe . ************************************************************************** . Czas ukończenia: 2012-07-25 18:40:29 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2012-07-25 16:40 . Przed: 24 103 112 704 bajtów wolnych Po: 24 569 958 400 bajtów wolnych . - - End Of File - - 6F7DD52603593744E235047B9E212024