ComboFix 12-09-24.03 - Helena 2012-09-27 10:00:13.2.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1250.48.1045.18.1644.830 [GMT 2:00] Uruchomiony z: c:\users\Helena\Desktop\ComboFix.exe AV: COMODO Antivirus *Disabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0} FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB} SP: COMODO Defense+ *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Pliki utworzone od 2012-08-27 do 2012-09-27 ))))))))))))))))))))))))))))))) . . 2012-09-27 08:57 . 2012-09-27 08:57 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-09-27 07:26 . 2012-09-27 07:26 -------- d-----w- c:\program files\Common Files\Java 2012-09-27 07:25 . 2012-09-27 07:25 -------- d-----w- c:\program files\Oracle 2012-09-27 07:24 . 2012-05-04 17:29 772504 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-09-26 11:42 . 2012-09-26 11:42 -------- d-----w- c:\users\Helena\.eclipse 2012-09-26 11:20 . 2012-09-26 11:20 -------- d-----w- C:\projects_svn 2012-09-26 11:04 . 2012-09-26 11:04 -------- d-----w- c:\users\Helena\AppData\Roaming\TortoiseSVN 2012-09-26 10:46 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{09D41D22-9F1F-4D5E-BCBD-97A9FC02C070}\mpengine.dll 2012-09-25 11:31 . 2012-09-26 11:40 -------- d-----w- c:\program files\eclipse 2012-09-24 08:05 . 2012-09-24 08:05 -------- d-----w- c:\program files\Common Files\Adobe 2012-09-24 07:48 . 2012-08-24 06:53 678912 ----a-w- c:\program files\Internet Explorer\iedvtool.dll 2012-09-24 07:48 . 2012-08-24 06:51 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2012-09-17 13:38 . 2012-09-24 09:26 -------- d-----w- c:\users\Helena\AppData\Local\TSVNCache 2012-09-17 11:30 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys 2012-09-17 11:30 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-17 11:30 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-17 11:30 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys 2012-09-17 11:30 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-17 11:30 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll 2012-09-15 13:35 . 2012-09-15 13:35 -------- d-----w- c:\users\Helena\AppData\Roaming\Subversion 2012-09-15 13:32 . 2012-09-15 13:32 -------- d-----w- c:\program files\Common Files\TortoiseOverlays 2012-09-15 13:32 . 2012-09-15 13:32 -------- d-----w- c:\program files\TortoiseSVN 2012-09-14 08:50 . 2012-09-14 09:04 -------- d-----w- c:\program files\WinMerge 2012-09-14 08:50 . 2012-09-14 08:50 -------- d-----w- c:\users\Helena\AppData\Local\GHISLER 2012-09-14 07:13 . 2008-12-21 21:22 499712 ----a-w- c:\windows\system32\msvcp71.dll 2012-09-14 07:13 . 2008-12-21 21:22 1047552 ----a-w- c:\windows\system32\mfc71u.dll 2012-09-03 13:26 . 2012-09-03 13:26 -------- d-----w- c:\users\Helena\AppData\Roaming\TuneUp Software 2012-09-03 13:26 . 2012-09-03 13:26 -------- d-----w- c:\program files\WinPcap 2012-09-03 13:23 . 2012-09-03 13:34 -------- d-----w- c:\programdata\TuneUp Software 2012-09-03 13:22 . 2012-09-03 13:26 -------- d-----w- c:\programdata\Freemake 2012-09-03 13:22 . 2012-09-03 13:22 -------- d-sh--w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2012-09-03 13:21 . 2012-09-03 13:21 -------- d--h--w- c:\programdata\Common Files 2012-09-03 13:20 . 2012-09-03 13:20 -------- d-----w- c:\users\Helena\AppData\Roaming\OpenCandy 2012-09-03 13:19 . 2012-09-03 13:22 -------- d-----w- c:\program files\Freemake 2012-08-29 20:03 . 2012-09-14 06:50 -------- d-----w- c:\program files\McAfee Security Scan . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-23 11:26 . 2012-08-20 22:14 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-23 11:26 . 2012-08-20 22:14 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-20 19:48 . 2010-06-24 10:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-08-20 17:00 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2012-08-09 07:44 . 2012-08-09 07:44 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-08-09 07:44 . 2012-08-09 07:44 161792 ----a-w- c:\windows\system32\msls31.dll 2012-08-09 07:44 . 2012-08-09 07:44 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2012-08-09 07:44 . 2012-08-09 07:44 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-08-09 07:44 . 2012-08-09 07:44 48640 ----a-w- c:\windows\system32\mshtmler.dll 2012-08-09 07:44 . 2012-08-09 07:44 86528 ----a-w- c:\windows\system32\iesysprep.dll 2012-08-09 07:43 . 2012-08-09 07:43 63488 ----a-w- c:\windows\system32\tdc.ocx 2012-08-09 07:43 . 2012-08-09 07:43 367104 ----a-w- c:\windows\system32\html.iec 2012-08-09 07:43 . 2012-08-09 07:43 74752 ----a-w- c:\windows\system32\iesetup.dll 2012-08-09 07:43 . 2012-08-09 07:43 23552 ----a-w- c:\windows\system32\licmgr10.dll 2012-08-09 07:43 . 2012-08-09 07:43 152064 ----a-w- c:\windows\system32\wextract.exe 2012-08-09 07:43 . 2012-08-09 07:43 150528 ----a-w- c:\windows\system32\iexpress.exe 2012-08-09 07:43 . 2012-08-09 07:43 11776 ----a-w- c:\windows\system32\mshta.exe 2012-08-09 07:43 . 2012-08-09 07:43 101888 ----a-w- c:\windows\system32\admparse.dll 2012-08-09 07:43 . 2012-08-09 07:43 35840 ----a-w- c:\windows\system32\imgutil.dll 2012-08-05 21:23 . 2012-08-05 21:23 163048 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10141.bin 2012-08-03 06:01 . 2012-08-20 13:42 545 ----a-w- c:\windows\UC.PIF 2012-08-03 06:01 . 2012-08-20 13:42 545 ----a-w- c:\windows\RAR.PIF 2012-08-03 06:01 . 2012-08-20 13:42 545 ----a-w- c:\windows\PKZIP.PIF 2012-08-03 06:01 . 2012-08-20 13:42 545 ----a-w- c:\windows\PKUNZIP.PIF 2012-08-03 06:01 . 2012-08-20 13:42 545 ----a-w- c:\windows\LHA.PIF 2012-08-03 06:01 . 2012-08-20 13:42 545 ----a-w- c:\windows\ARJ.PIF 2012-08-02 22:07 . 2012-08-02 22:07 348160 ----a-w- c:\windows\system32\msvcr71.dll 2012-08-02 22:07 . 2012-08-02 22:07 1700352 ----a-w- c:\windows\system32\gdiplus.dll 2012-08-02 22:07 . 2012-08-02 22:07 1060864 ----a-w- c:\windows\system32\mfc71.dll 2012-07-18 17:47 . 2012-08-16 22:13 2345984 ----a-w- c:\windows\system32\win32k.sys 2012-07-04 21:14 . 2012-08-16 22:12 41984 ----a-w- c:\windows\system32\browcli.dll 2012-07-04 21:14 . 2012-08-16 22:12 102912 ----a-w- c:\windows\system32\browser.dll 2012-07-14 00:15 . 2012-08-04 10:48 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2010-07-07 14:12 . 2012-08-20 13:52 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 08:20 64792 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TosNC"="c:\program files\Toshiba\BulletinBoard\TosNcCore.exe" [2010-11-16 468392] "TosReelTimeMonitor"="c:\program files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [2010-07-09 31648] "NBAgent"="c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-02 1234216] "Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2010-05-11 1050072] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-10 336384] "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 425984] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2010-09-14 35440] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2010-09-28 521640] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-08-13 521528] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2010-10-28 742776] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-16 9874024] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2010-11-11 1522280] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-03-10 1697064] "ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336] "TSleepSrv"="c:\program files\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe" [2010-06-04 252792] "Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2010-07-28 1349032] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 611672] "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-07-01 1295224] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-11-02 2475384] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 22840] "Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="c:\program files\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "tvncontrol"="c:\program files\Common Files\Comodo\tvnserver.exe" -controlservice -slave . R2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\McSACore.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;c:\windows\system32\DRIVERS\btfilter.sys [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R4 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x] S2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\Freemake\CaptureLib\CaptureLibService.exe [x] S2 IconMan_R;IconMan_R;c:\program files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [x] S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . Zawartość folderu 'Zaplanowane zadania' . 2012-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-20 11:26] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://toshiba.msn.com IE: Dodaj do programu TOSHIBA Bulletin Board - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000 IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 IE: {{97F922BD-8563-4184-87EE-8C4ACA438823} - {5D29E593-73A5-400A-B3BD-6B7A1AF05A31} - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll TCP: DhcpNameServer = 10.0.0.99 FF - ProfilePath - c:\users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\12koajks.default\ . - - - - USUNIĘTO PUSTE WPISY - - - - . Toolbar-Locked - (no file) . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > 'winlogon.exe'(592) c:\windows\system32\guard32.dll . - - - - - - - > 'lsass.exe'(640) c:\windows\system32\guard32.dll . - - - - - - - > 'Explorer.exe'(5676) c:\windows\system32\guard32.dll . Czas ukończenia: 2012-09-27 11:02:38 ComboFix-quarantined-files.txt 2012-09-27 09:02 . Przed: 40 217 268 224 bajtów wolnych Po: 39 890 583 552 bajtów wolnych . - - End Of File - - 079BDCB59B248208DF8F45E9732C6811