ComboFix 12-10-23.01 - Soob 2012-10-23 23:48:58.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1250.48.1045.18.4027.2429 [GMT 2:00] Uruchomiony z: c:\users\Soob\Desktop\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\IsUn0415.exe . . ((((((((((((((((((((((((( Pliki utworzone od 2012-09-23 do 2012-10-23 ))))))))))))))))))))))))))))))) . . 2012-10-23 21:53 . 2012-10-23 21:53 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-10-23 13:20 . 2012-01-20 12:14 18816 ----a-w- c:\windows\system32\roboot64.exe 2012-10-23 13:20 . 2012-10-23 13:39 -------- d-----w- c:\users\Soob\AppData\Roaming\systweak 2012-10-23 08:04 . 2012-10-12 07:19 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5513B64A-6316-42BD-B51B-7AB22AC694DD}\mpengine.dll 2012-10-22 15:36 . 2012-10-22 15:52 -------- d-----w- c:\users\Soob\AppData\Roaming\Subtitle Edit 2012-10-22 15:36 . 2012-10-22 15:36 -------- d-----w- c:\program files (x86)\Subtitle Edit 2012-10-22 15:35 . 2012-10-22 15:35 -------- d-----w- c:\windows\pl 2012-10-19 17:56 . 2012-10-19 17:56 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2012-10-15 11:31 . 2012-10-15 11:31 -------- d-----w- c:\users\Soob\AppData\Local\Google 2012-10-15 08:58 . 2012-10-15 09:09 -------- d-----w- c:\programdata\NCH Software 2012-10-15 08:58 . 2012-10-15 11:25 -------- d-----w- c:\program files (x86)\NCH Software 2012-10-15 08:58 . 2012-10-15 11:25 -------- d-----w- c:\users\Soob\AppData\Roaming\NCH Software 2012-10-13 19:08 . 2012-10-13 19:08 -------- d-----w- c:\program files (x86)\PANDORA.TV 2012-10-13 19:08 . 2012-10-23 15:30 -------- d-----w- c:\program files (x86)\The KMPlayer 2012-10-10 20:29 . 2012-10-10 20:29 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2012-10-10 03:29 . 2012-10-10 03:29 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services 2012-10-10 03:27 . 2012-10-10 03:27 -------- d-----w- c:\program files\Microsoft Office 2012-10-10 03:27 . 2012-10-10 03:27 -------- d-----w- c:\users\Soob\AppData\Local\Microsoft Help 2012-10-10 03:27 . 2012-10-13 05:50 -------- d-----w- c:\programdata\Microsoft Help 2012-10-10 03:27 . 2012-10-10 03:27 -------- d-----r- C:\MSOCache 2012-10-10 02:51 . 2012-10-10 02:51 -------- d-----w- c:\program files (x86)\MSECache 2012-10-08 09:18 . 2012-10-08 09:18 -------- d-----w- c:\programdata\SuperMemo World 2012-10-08 09:13 . 2012-10-08 09:14 -------- d-----w- c:\program files (x86)\MagicDisc 2012-10-08 09:13 . 2009-02-24 16:35 255552 ----a-w- c:\windows\SysWow64\drivers\mcdbus.sys 2012-10-08 09:13 . 2009-02-24 16:35 255552 ----a-w- c:\windows\system32\drivers\mcdbus.sys 2012-10-08 08:00 . 2012-10-08 08:00 -------- d-----w- c:\users\Soob\AppData\Roaming\SuperMemo World 2012-10-08 08:00 . 2012-10-08 09:17 -------- d-----w- c:\program files (x86)\SuperMemo UX 2012-10-08 01:33 . 2012-10-08 01:33 -------- d-----w- c:\users\Soob\AppData\Roaming\Malwarebytes 2012-10-08 01:33 . 2012-10-08 01:33 -------- d-----w- c:\programdata\Malwarebytes 2012-10-06 21:21 . 2012-10-06 21:21 -------- d-----w- C:\found.000 2012-10-04 02:40 . 2012-10-04 02:40 -------- d-----w- c:\users\Soob\AppData\Roaming\SendSpace 2012-10-04 02:40 . 2012-10-15 11:27 -------- d-----w- c:\programdata\Premium 2012-10-04 02:39 . 2012-10-15 11:27 -------- d-----w- c:\programdata\InstallMate 2012-10-03 22:38 . 2012-10-03 22:38 -------- d-----w- c:\program files (x86)\MagicISO 2012-10-03 22:33 . 2012-10-03 22:33 -------- d-----w- c:\users\Soob\AppData\Roaming\ImgBurn 2012-10-03 22:23 . 2012-10-03 22:23 -------- d-----w- c:\program files (x86)\ImgBurn 2012-10-03 07:19 . 2012-10-03 07:19 -------- d-----w- c:\program files (x86)\Common Files\Java 2012-10-03 07:18 . 2012-10-03 07:18 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-10-03 07:18 . 2012-10-03 07:18 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll 2012-10-03 07:18 . 2012-10-03 07:18 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-10-03 07:18 . 2012-10-03 07:18 -------- d-----w- c:\program files (x86)\Java 2012-09-29 13:18 . 2012-09-29 13:18 -------- d-----w- c:\program files\Microsoft Silverlight 2012-09-29 13:18 . 2012-09-29 13:18 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2012-09-29 12:48 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll 2012-09-29 12:48 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll 2012-09-27 10:54 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-27 10:54 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys 2012-09-27 10:54 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-27 10:54 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys 2012-09-27 10:54 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-27 10:54 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe 2012-09-26 20:59 . 2012-09-26 20:59 -------- d-----w- c:\windows\system32\SPReview 2012-09-26 20:58 . 2012-09-26 20:58 -------- d-----w- c:\windows\system32\EventProviders 2012-09-26 20:57 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll 2012-09-26 20:57 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll 2012-09-26 20:57 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll 2012-09-26 16:40 . 2010-11-20 13:26 317952 ----a-w- c:\windows\system32\dhcpcore.dll 2012-09-26 16:39 . 2010-11-20 13:27 594432 ----a-w- c:\windows\system32\wvc.dll 2012-09-26 16:38 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll 2012-09-26 16:38 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll 2012-09-26 16:38 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll 2012-09-25 18:17 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2012-09-25 18:17 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2012-09-25 18:17 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys 2012-09-25 18:17 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2012-09-25 18:17 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2012-09-25 18:17 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2012-09-25 18:17 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys 2012-09-25 18:16 . 2011-03-11 06:33 2565632 ----a-w- c:\windows\system32\esent.dll 2012-09-25 18:16 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\SysWow64\esent.dll 2012-09-25 18:16 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys 2012-09-25 18:16 . 2011-03-11 06:41 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys 2012-09-25 18:16 . 2011-03-11 06:41 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys 2012-09-25 18:16 . 2011-03-11 06:41 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys 2012-09-25 18:16 . 2011-03-11 06:41 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys 2012-09-25 18:16 . 2011-03-11 06:41 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys 2012-09-25 18:16 . 2011-03-11 06:30 96768 ----a-w- c:\windows\system32\fsutil.exe 2012-09-25 18:16 . 2011-03-11 05:31 74240 ----a-w- c:\windows\SysWow64\fsutil.exe 2012-09-25 18:16 . 2011-03-11 04:37 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS 2012-09-24 19:48 . 2012-09-24 19:48 -------- d-----w- c:\windows\SysWow64\Wat 2012-09-24 19:48 . 2012-09-24 19:48 -------- d-----w- c:\windows\system32\Wat 2012-09-24 18:53 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2012-09-24 18:35 . 2012-10-10 20:31 65309168 ----a-w- c:\windows\system32\MRT.exe 2012-09-24 18:27 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2012-09-24 18:27 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll 2012-09-24 18:27 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2012-09-24 18:27 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2012-09-24 18:27 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2012-09-24 18:14 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll 2012-09-24 18:14 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll 2012-09-24 18:14 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll 2012-09-24 18:14 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll 2012-09-24 18:14 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe 2012-09-24 18:14 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll 2012-09-24 18:14 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll 2012-09-24 18:12 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll 2012-09-24 18:12 . 2011-03-11 06:34 1395712 ----a-w- c:\windows\system32\mfc42.dll 2012-09-24 18:12 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll 2012-09-24 18:12 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll 2012-09-24 18:11 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll 2012-09-24 18:11 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll 2012-09-24 18:11 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll 2012-09-24 18:11 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax 2012-09-24 18:11 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll 2012-09-24 18:11 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax 2012-09-24 18:11 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl 2012-09-24 18:11 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl 2012-09-24 18:11 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll 2012-09-24 18:11 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll 2012-09-24 18:11 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2012-09-24 18:11 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe 2012-09-24 18:09 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll 2012-09-24 18:05 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll 2012-09-24 18:05 . 2011-03-03 06:24 357888 ----a-w- c:\windows\system32\dnsapi.dll 2012-09-24 18:05 . 2011-03-03 06:21 30208 ----a-w- c:\windows\system32\dnscacheugc.exe 2012-09-24 18:05 . 2011-03-03 05:36 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe 2012-09-24 18:04 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys 2012-09-24 18:04 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys 2012-09-24 18:04 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys 2012-09-24 18:02 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe 2012-09-24 18:02 . 2010-11-20 13:25 974336 ----a-w- c:\windows\system32\WFS.exe 2012-09-24 18:00 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-09-24 17:58 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll 2012-09-24 17:57 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll 2012-09-24 17:57 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-08 21:34 . 2012-09-13 06:40 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-10-08 21:34 . 2012-09-13 06:40 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-26 21:04 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2012-09-26 21:04 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll 2012-09-13 08:40 . 2012-09-13 08:40 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll 2012-09-13 08:40 . 2012-09-13 08:40 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll 2012-09-13 08:40 . 2012-09-13 08:40 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll 2012-09-12 13:57 . 2012-09-12 13:57 322048 ----a-w- c:\windows\WLXPGSS.SCR 2012-08-21 11:01 . 2012-09-14 05:09 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-08-21 11:01 . 2012-08-21 11:01 125872 ----a-w- c:\windows\system32\GEARAspi64.dll 2012-08-21 11:01 . 2012-08-21 11:01 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll 2012-08-21 09:13 . 2012-09-13 07:17 359464 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-08-21 09:13 . 2012-09-13 07:17 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-08-21 09:13 . 2012-09-13 07:17 969200 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-08-21 09:13 . 2012-09-13 07:17 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-08-21 09:13 . 2012-09-13 07:17 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-08-21 09:13 . 2012-09-13 07:17 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-08-21 09:12 . 2012-09-13 07:17 41224 ----a-w- c:\windows\avastSS.scr 2012-08-21 09:12 . 2012-09-13 07:17 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe 2012-08-21 09:12 . 2012-09-13 07:17 285328 ----a-w- c:\windows\system32\aswBoot.exe 2012-08-20 17:38 . 2012-10-10 18:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-07-28 03:43 . 2012-07-28 03:43 70144 ----a-w- c:\windows\system32\coinst_8.982.dll 2012-07-28 02:15 . 2012-07-28 02:15 163840 ----a-w- c:\windows\system32\atiapfxx.exe 2012-07-28 02:15 . 2012-07-28 02:15 931328 ----a-w- c:\windows\SysWow64\aticfx32.dll 2012-07-28 02:13 . 2012-07-28 02:13 1100288 ----a-w- c:\windows\system32\aticfx64.dll 2012-07-28 01:15 . 2012-07-28 01:15 17920 ----a-w- c:\windows\system32\atig6pxx.dll 2012-07-28 01:15 . 2012-07-28 01:15 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll 2012-07-28 01:15 . 2012-07-28 01:15 14848 ----a-w- c:\windows\system32\atiglpxx.dll 2012-07-28 01:15 . 2012-07-28 01:15 41984 ----a-w- c:\windows\system32\atig6txx.dll 2012-07-28 01:14 . 2012-07-28 01:14 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll 2012-07-28 01:14 . 2012-07-28 01:14 368640 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2012-07-28 01:13 . 2012-07-28 01:13 129536 ----a-w- c:\windows\system32\atiuxp64.dll 2012-07-28 01:13 . 2012-07-28 01:13 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll 2012-07-28 01:13 . 2012-07-28 01:13 103936 ----a-w- c:\windows\system32\atiu9p64.dll 2012-07-28 01:13 . 2012-07-28 01:13 83456 ----a-w- c:\windows\SysWow64\atiu9pag.dll 2012-07-26 17:08 . 2012-07-26 17:08 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll 2012-07-26 17:08 . 2012-07-26 17:08 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll 2012-07-26 17:08 . 2012-07-26 17:08 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll 2012-07-26 17:08 . 2012-07-26 17:08 153536 ----a-w- c:\windows\SysWow64\atl110.dll 2012-07-26 17:08 . 2012-07-26 17:08 115656 ----a-w- c:\windows\SysWow64\vcomp110.dll 2012-07-26 13:22 . 2012-07-26 13:22 828872 ----a-w- c:\windows\system32\msvcr110.dll 2012-07-26 13:22 . 2012-07-26 13:22 661448 ----a-w- c:\windows\system32\msvcp110.dll 2012-07-26 13:22 . 2012-07-26 13:22 354264 ----a-w- c:\windows\system32\vccorlib110.dll 2012-07-26 13:22 . 2012-07-26 13:22 177096 ----a-w- c:\windows\system32\atl110.dll 2012-07-26 13:22 . 2012-07-26 13:22 124360 ----a-w- c:\windows\system32\vcomp110.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2012-06-28 74752] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-04 98304] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808] R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2009-11-04 6088192] R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-07-28 368640] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-13 115168] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-24 1255736] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2010-03-01 20520] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-04 202752] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-08-21 71600] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-11-27 295424] . . Zawartość folderu 'Zaplanowane zadania' . 2012-10-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 21:34] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-08-21 09:11 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-01-19 9996320] . ------- Skan uzupełniający ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mDefault_Page_URL = hxxp://www.v9.com/?utm_source=b&utm_medium=prs&from=prs&uid=W2AEFLWG_ST500DM002-1BD142&ts=1347599554 mStart Page = hxxp://www.v9.com/?utm_source=b&utm_medium=prs&from=prs&uid=W2AEFLWG_ST500DM002-1BD142&ts=1347599554 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Soob\AppData\Roaming\Mozilla\Firefox\Profiles\d0l8463r.default\ FF - prefs.js: browser.search.selectedEngine - Wyszukiwarka filmĂłw w YouTube FF - prefs.js: browser.startup.homepage - hxxps://www.google.pl/ FF - ExtSQL: 2012-09-13 09:10; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Soob\AppData\Roaming\Mozilla\Firefox\Profiles\d0l8463r.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2012-09-13 09:17; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF FF - ExtSQL: 2012-09-13 11:31; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; c:\users\Soob\AppData\Roaming\Mozilla\Firefox\Profiles\d0l8463r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} . - - - - USUNIĘTO PUSTE WPISY - - - - . AddRemove-SuperMemo UX - Angielski. No problem!+ 2 - c:\windows\IsUn0415.exe . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2012-10-23 23:55:22 ComboFix-quarantined-files.txt 2012-10-23 21:55 . Przed: 19 666 190 336 bajtów wolnych Po: 20 571 500 544 bajtów wolnych . - - End Of File - - 73EDECA7DC59C725640264CCA8ADD53B