http://www.dobreprogramy.pl napisał(a):Pracę z narzędziem zaleca się jedynie zaawansowanym użytkownikom.
ComboFix 13-07-24.02 - TheHardStyl3r_PL 2013-07-24 11:26:06.1.2 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.48.1045.18.2046.1127 [GMT 2:00]
Uruchomiony z: c:\users\TheHardStyl3r_PL\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Utworzono nowy punkt przywracania
.
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\capsys184523.log
c:\windows\PFRO.log
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((((( Pliki utworzone od 2013-06-24 do 2013-07-24 )))))))))))))))))))))))))))))))
.
.
2013-07-24 09:34 . 2013-07-24 09:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-22 15:53 . 2013-07-24 08:02 -------- d-----w- c:\program files\OblyTile
2013-07-22 12:27 . 2012-07-11 15:09 64856 ----a-w- c:\windows\system32\klfphc.dll
2013-07-22 12:25 . 2013-07-22 12:25 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2013-07-22 12:25 . 2013-07-22 12:52 619616 ----a-w- c:\windows\system32\drivers\klif.sys
2013-07-22 12:25 . 2013-07-22 12:52 90208 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-07-22 10:10 . 2013-07-22 10:18 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2013-07-22 10:10 . 2013-07-22 10:10 -------- d-----w- c:\windows\SysWow64\xlive
2013-07-22 09:53 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C6976088-BDB1-46DF-8ED4-611166D8510C}\mpengine.dll
2013-07-22 09:35 . 2013-07-22 09:35 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2013-07-22 08:44 . 2013-07-22 08:46 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-07-20 15:36 . 2013-07-20 15:36 679936 ----a-w- c:\windows\system32\Fliqlo.scr
2013-07-20 15:36 . 2013-07-20 15:36 679936 ------w- c:\windows\SysWow64\Fliqlo.scr
2013-07-20 15:36 . 2013-07-20 15:36 -------- d-----w- c:\programdata\Screentime
2013-07-20 13:17 . 2013-07-20 13:17 -------- d-----w- c:\windows\pl
2013-07-20 13:17 . 2013-07-20 13:17 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-07-20 13:16 . 2013-07-20 13:16 -------- d-----w- c:\program files (x86)\Windows Live
2013-07-20 13:02 . 2013-07-20 13:02 -------- d-----r- C:\Windows Activation Technologies
2013-07-20 12:25 . 2013-07-20 12:25 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2013-07-20 12:08 . 2013-07-20 12:11 -------- d-----w- c:\windows\system32\MRT
2013-07-20 11:58 . 2012-08-31 00:52 17888 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-07-20 11:58 . 2012-08-31 00:53 17888 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2013-07-20 11:52 . 2013-04-09 04:51 3552768 ----a-w- c:\windows\system32\tquery.dll
2013-07-20 11:51 . 2013-04-09 04:49 281088 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-07-20 11:49 . 2012-10-11 05:45 3236864 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2013-07-20 11:48 . 2012-10-11 05:43 757760 ----a-w- c:\windows\system32\FirewallAPI.dll
2013-07-20 11:47 . 2013-03-02 02:45 1161728 ----a-w- c:\windows\system32\sppobjs.dll
2013-07-20 11:38 . 2013-01-09 23:23 2094592 ----a-w- c:\windows\system32\mmc.exe
2013-07-20 11:37 . 2013-06-01 09:20 2219520 ----a-w- c:\windows\system32\dwmcore.dll
2013-07-20 11:32 . 2013-07-20 11:32 -------- d-----w- c:\programdata\LogiShrd
2013-07-20 11:29 . 2013-07-20 11:30 -------- d-----w- c:\program files\Logitech Gaming Software
2013-07-20 11:20 . 2012-10-24 04:54 396008 ----a-w- c:\windows\system32\hal.dll
2013-07-20 11:18 . 2013-05-04 06:59 3241472 ----a-w- c:\windows\system32\wuaueng.dll
2013-07-20 11:18 . 2013-05-04 06:59 13644288 ----a-w- c:\windows\system32\Windows.UI.Xaml.dll
2013-07-20 11:18 . 2013-05-04 06:58 10116096 ----a-w- c:\windows\system32\twinui.dll
2013-07-20 11:13 . 2012-11-27 04:19 3245568 ----a-w- c:\windows\system32\rdpcorets.dll
2013-07-20 11:10 . 2012-10-12 06:14 115712 ----a-w- c:\windows\system32\wbem\PolicMan.dll
2013-07-20 11:09 . 2012-10-17 04:32 1172992 ----a-w- c:\windows\system32\mfnetsrc.dll
2013-07-20 11:09 . 2012-10-17 04:32 677888 ----a-w- c:\windows\system32\mfnetcore.dll
2013-07-20 11:09 . 2012-10-17 03:57 929792 ----a-w- c:\windows\SysWow64\mfnetsrc.dll
2013-07-20 11:09 . 2012-10-17 03:57 568832 ----a-w- c:\windows\SysWow64\mfnetcore.dll
2013-07-20 11:09 . 2012-10-17 04:32 673280 ----a-w- c:\windows\system32\mfmpeg2srcsnk.dll
2013-07-20 11:09 . 2012-10-17 03:57 513024 ----a-w- c:\windows\SysWow64\mfmpeg2srcsnk.dll
2013-07-20 11:07 . 2013-06-16 22:41 997632 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-07-20 11:06 . 2012-11-20 05:17 1184256 ----a-w- c:\windows\system32\Display.dll
2013-07-20 11:06 . 2012-11-20 05:24 1164800 ----a-w- c:\windows\SysWow64\Display.dll
2013-07-20 11:06 . 2012-11-20 04:59 7168 ----a-w- c:\windows\system32\KBDKURD.DLL
2013-07-20 11:06 . 2012-11-20 05:02 6656 ----a-w- c:\windows\SysWow64\KBDKURD.DLL
2013-07-20 11:06 . 2012-11-08 04:25 523776 ----a-w- c:\windows\SysWow64\WSShared.dll
2013-07-20 11:06 . 2012-11-08 04:25 143872 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-07-20 11:06 . 2012-11-08 04:25 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-07-20 11:06 . 2012-11-08 04:22 641536 ----a-w- c:\windows\system32\WSShared.dll
2013-07-20 11:06 . 2012-11-08 04:22 198656 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.dll
2013-07-20 11:06 . 2012-11-08 04:22 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-07-20 11:06 . 2012-12-04 04:21 368640 ----a-w- c:\windows\system32\sppwinob.dll
2013-07-19 08:30 . 2013-07-19 08:30 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2013-07-19 07:51 . 2013-07-19 07:51 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2013-07-19 07:51 . 2010-06-02 02:55 239960 ----a-w- c:\windows\SysWow64\xactengine3_7.dll
2013-07-19 07:51 . 2010-06-02 02:55 176984 ----a-w- c:\windows\system32\xactengine3_7.dll
2013-07-19 07:51 . 2010-05-26 09:41 1907552 ----a-w- c:\windows\system32\d3dcsx_43.dll
2013-07-19 07:51 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\SysWow64\d3dcsx_43.dll
2013-07-19 07:51 . 2010-05-26 09:41 511328 ----a-w- c:\windows\system32\d3dx10_43.dll
2013-07-19 07:51 . 2010-05-26 09:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2013-07-19 07:51 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2013-07-19 07:51 . 2010-05-26 09:41 2401112 ----a-w- c:\windows\system32\D3DX9_43.dll
2013-07-18 14:52 . 2013-07-19 07:15 -------- d-----w- c:\program files (x86)\Origin Games
2013-07-18 14:52 . 2013-07-19 06:29 -------- d-----w- c:\programdata\Origin
2013-07-18 14:51 . 2013-07-19 08:31 -------- d-----w- c:\program files (x86)\Origin
2013-07-18 13:37 . 2013-05-15 02:25 888320 ----a-w- c:\windows\system32\autochk.exe
2013-07-18 13:37 . 2013-05-15 02:25 542208 ----a-w- c:\windows\system32\untfs.dll
2013-07-18 13:37 . 2013-05-15 02:24 793088 ----a-w- c:\windows\SysWow64\autochk.exe
2013-07-18 13:37 . 2013-05-15 02:24 482816 ----a-w- c:\windows\SysWow64\untfs.dll
2013-07-18 13:37 . 2013-05-30 23:24 1257472 ----a-w- c:\windows\system32\kernel32.dll
2013-07-18 13:37 . 2013-05-23 23:01 1300992 ----a-w- c:\windows\system32\gdi32.dll
2013-07-18 13:37 . 2013-05-23 22:27 1022464 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-07-17 18:32 . 2013-07-24 08:49 281312 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-07-17 17:20 . 2010-09-16 07:13 2601752 ----a-w- c:\windows\SysWow64\pbsvc_moh.exe
2013-07-17 17:19 . 2013-07-17 17:19 -------- d-----w- c:\programdata\Electronic Arts
2013-07-17 17:19 . 2013-07-17 17:19 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2013-07-17 16:32 . 2013-07-17 16:32 -------- d-----w- c:\windows\SysWow64\AGEIA
2013-07-17 16:32 . 2013-07-17 16:32 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-07-17 16:30 . 2013-07-17 16:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-07-17 14:46 . 2006-03-31 10:41 3927248 ----a-w- c:\windows\system32\d3dx9_30.dll
2013-07-17 14:45 . 2013-07-24 08:57 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-07-17 14:45 . 2013-07-24 08:57 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-07-17 14:45 . 2013-07-20 19:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-07-17 14:41 . 2013-07-17 14:41 -------- d-----w- c:\program files (x86)\Activision
2013-07-14 20:05 . 2012-09-27 06:35 74240 ----a-w- c:\windows\SysWow64\newdev.exe
2013-07-14 20:05 . 2012-09-27 06:35 73728 ----a-w- c:\windows\SysWow64\ndadmin.exe
2013-07-14 20:05 . 2012-09-27 06:34 275968 ----a-w- c:\windows\SysWow64\newdev.dll
2013-07-14 20:05 . 2012-09-27 07:17 76288 ----a-w- c:\windows\system32\newdev.exe
2013-07-14 20:05 . 2012-09-27 07:17 75264 ----a-w- c:\windows\system32\ndadmin.exe
2013-07-14 20:05 . 2012-09-27 07:15 301568 ----a-w- c:\windows\system32\newdev.dll
2013-07-14 09:56 . 2013-07-14 09:56 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-07-14 09:56 . 2013-07-14 09:56 -------- d-----r- c:\program files (x86)\Skype
2013-07-14 09:56 . 2013-07-23 13:13 -------- d-----w- c:\programdata\Skype
2013-07-13 19:10 . 2013-07-13 19:11 -------- d-----w- c:\program files (x86)\DVDVideoSoft
2013-07-13 17:58 . 2013-07-13 17:58 -------- d-----w- c:\programdata\Mirillis
2013-07-13 17:58 . 2013-07-13 17:58 -------- d-----w- C:\Action!
2013-07-13 17:57 . 2013-07-13 17:57 -------- d-----w- c:\program files (x86)\Mirillis
2013-07-13 17:45 . 2012-05-17 11:01 33872 ----a-w- c:\windows\system32\drivers\anvsnddrv.sys
2013-07-13 15:25 . 2013-07-13 15:25 -------- d-----w- c:\programdata\Sony
2013-07-13 15:25 . 2013-07-13 15:25 -------- d-----w- c:\program files\Sony
2013-07-13 15:25 . 2013-07-13 15:25 -------- d-----w- c:\program files (x86)\Sony
2013-07-13 15:09 . 2012-09-20 05:55 51200 ----a-w- c:\windows\SysWow64\ndptsp.tsp
2013-07-13 15:08 . 2012-09-20 06:33 344064 ----a-w- c:\windows\system32\wlidcredprov.dll
2013-07-13 15:08 . 2012-10-11 07:02 1636672 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2013-07-13 15:08 . 2012-09-20 06:07 210304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-07-13 15:08 . 2012-09-20 07:55 3265256 ----a-w- c:\windows\system32\drivers\evbda.sys
2013-07-13 15:08 . 2012-09-20 07:55 533224 ----a-w- c:\windows\system32\drivers\bxvbda.sys
2013-07-13 15:08 . 2012-09-20 06:33 1314816 ----a-w- c:\program files\Windows Media Player\wmpnetwk.exe
2013-07-13 15:08 . 2012-09-20 06:33 573952 ----a-w- c:\program files\Windows Media Player\wmpnssci.dll
2013-07-13 15:08 . 2012-09-20 06:33 332800 ----a-w- c:\windows\system32\wintrust.dll
2013-07-13 15:08 . 2012-09-20 06:33 194048 ----a-w- c:\windows\system32\winsrv.dll
2013-07-13 15:08 . 2012-09-20 06:33 420352 ----a-w- c:\windows\system32\WWAHost.exe
2013-07-13 15:08 . 2012-09-20 06:33 588800 ----a-w- c:\windows\system32\webio.dll
2013-07-13 15:08 . 2012-09-20 06:33 3964416 ----a-w- c:\windows\system32\WinSAT.exe
2013-07-13 15:08 . 2012-09-20 06:09 22528 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys
2013-07-13 15:06 . 2012-09-20 06:33 142848 ----a-w- c:\windows\system32\fhmanagew.exe
2013-07-13 15:05 . 2013-05-15 22:37 44032 ----a-w- c:\windows\SysWow64\UXInit.dll
2013-07-13 15:04 . 2013-06-11 23:26 1084928 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-07-13 07:46 . 2010-02-04 08:01 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_4.dll
2013-07-13 07:46 . 2010-02-04 08:01 528216 ----a-w- c:\windows\SysWow64\XAudio2_6.dll
2013-07-13 07:46 . 2010-02-04 08:01 238936 ----a-w- c:\windows\SysWow64\xactengine3_6.dll
2013-07-13 07:46 . 2010-02-04 08:01 22360 ----a-w- c:\windows\SysWow64\X3DAudio1_7.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-22 12:52 . 2012-08-13 14:49 178448 ----a-w- c:\windows\system32\drivers\kneps.sys
2013-07-22 12:52 . 2012-08-03 13:55 50448 ----a-w- c:\windows\system32\drivers\klwfp.sys
2013-07-22 12:52 . 2012-07-25 12:53 29528 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2013-07-22 12:52 . 2012-05-25 17:38 29016 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2013-06-30 14:41 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-06-27 22:04 . 2012-07-26 08:14 78200 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04 . 2012-07-26 08:14 693112 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-28 20:23 . 2013-05-28 20:23 652288 ----a-w- c:\windows\system32\ficvdec_x64.dll
2013-05-28 20:22 . 2013-05-28 20:22 641024 ----a-w- c:\windows\SysWow64\ficvdec_x86.dll
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-07-10 15:43 277512 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-07-19 1807272]
"uTorrent"="c:\users\TheHardStyl3r_PL\AppData\Roaming\uTorrent\uTorrent.exe" [2013-07-10 884056]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19873896]
"RGSC"="c:\program files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2013-06-26 80480]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe" [2013-07-22 24504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19873896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 klelam;klelam;c:\windows\system32\DRIVERS\klelam.sys;c:\windows\SYSNATIVE\DRIVERS\klelam.sys [x]
R2 PLAY ONLINE. RunOuc;PLAY ONLINE. OUC;c:\program files (x86)\PLAY ONLINE\UpdateDog\ouc.exe;c:\program files (x86)\PLAY ONLINE\UpdateDog\ouc.exe [x]
R3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys;c:\windows\SYSNATIVE\drivers\anvsnddrv.sys [x]
R3 athur;Qualcomm Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athuw8x.sys;c:\windows\SYSNATIVE\DRIVERS\athuw8x.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\System32\drivers\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\drivers\ew_usbenumfilter.sys [x]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x]
R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\System32\drivers\ew_juextctrl.sys;c:\windows\SYSNATIVE\drivers\ew_juextctrl.sys [x]
R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klwfp;klwfp;c:\windows\system32\DRIVERS\klwfp.sys;c:\windows\SYSNATIVE\DRIVERS\klwfp.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [x]
S2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
S3 amdkmafd;AMD Audio Bus Lower Filter;c:\windows\System32\drivers\amdkmafd.sys;c:\windows\SYSNATIVE\drivers\amdkmafd.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW86.sys;c:\windows\SYSNATIVE\drivers\AtihdW86.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;@oem7.inf,%DeviceName% (WDM);Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\System32\drivers\ew_jubusenum.sys;c:\windows\SYSNATIVE\drivers\ew_jubusenum.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 RTL8168;Sterownik Realtek 8168 NT;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
apphost REG_MULTI_SZ apphostsvc
iissvcs REG_MULTI_SZ w3svc was
.
Zawartość folderu 'Zaplanowane zadania'
.
2013-07-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-30 06:13]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-07-10 15:43 336904 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-04-24 7477016]
.
------- Skan uzupełniający -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Wyślij &do programu OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
TCP: Interfaces\{517B10C8-DB2A-4509-B763-1F89393EF946}: NameServer = 89.108.195.20 89.108.202.20
TCP: Interfaces\{EF467450-0749-4D03-8BB2-50BA0A37D1A7}: NameServer = 89.108.195.20 89.108.202.20
TCP: Interfaces\{F654C57E-8D66-4CF8-AA26-CD74F450D401}: NameServer = 89.108.195.20 89.108.202.20
FF - ProfilePath - c:\users\TheHardStyl3r_PL\AppData\Roaming\Mozilla\Firefox\Profiles\f4i2dpu4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl
FF - ExtSQL: 2013-06-30 12:05; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\program files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF - ExtSQL: 2013-07-22 14:53; anti_banner@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF - ExtSQL: 2013-07-22 14:53; content_blocker@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF - ExtSQL: 2013-07-22 14:53; online_banking@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF - ExtSQL: 2013-07-22 14:53; url_advisor@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF - ExtSQL: 2013-07-22 14:53; virtual_keyboard@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF - ExtSQL: 2013-07-23 15:11; battlefieldheroespatcher@ea.com; c:\users\TheHardStyl3r_PL\AppData\Roaming\Mozilla\Firefox\Profiles\f4i2dpu4.default\extensions\battlefieldheroespatcher@ea.com
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
HKLM-Run-CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805} - c:\users\THEHAR~1\AppData\Local\Temp\cis5A5F.exe
HKLM-Run-CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} - c:\users\THEHAR~1\AppData\Local\Temp\cis5A5F.exe
AddRemove-Minecraft1.6.2 - c:\users\TheHardStyl3r_PL\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe
.
.
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Czas ukończenia: 2013-07-24 11:38:29
ComboFix-quarantined-files.txt 2013-07-24 09:38
.
Przed: 36 507 377 664 bytes free
Po: 36 635 770 880 bytes free
.
- - End Of File - - 279EC987611D0B6D540B89B35169BD27
A36C5E4F47E84449FF07ED3517B43A31
HardStyl3r_PL napisał(a):Mam mało miejsca na DyskuJeśli nie masz, to wyłącz przywracanie systemu na "C" i powinno ci miejsca przybyć.