Skocz do zawartości
logimen

Prosba o analize log'a

Rekomendowane odpowiedzi

Prosil bym ogarnieta osobe o analize LOG'a z combofix'a. Nagle po wlaczeniu kompa ikony pulpitu sa ZAWSZE wielkosci "medium" i zadne triki w rejestrze nie robia na nich wrazenia. Zmieniam poprzez PPM na pulpicie, a po restarcie znowu to samo. Przez ostatni tydzien nic nowego nie instalowalem, takze bezposrednio przed wystapieniem problemu. Irytujace to jest.

 

ComboFix 12-05-12.01 - logimen 2012-05-12  10:28:10.1.4 - x64Uruchomiony z: c:\users\logimen\Desktop\ComboFix.exe * Utworzono nowy punkt przywracania..(((((((((((((((((((((((((   Pliki utworzone od 2012-04-12 do 2012-05-12  )))))))))))))))))))))))))))))))..2012-05-09 21:37 . 2012-05-09 21:49	--------	d-----w-	c:\users\logimen\.android2012-05-09 21:37 . 2012-05-09 21:49	--------	d-----w-	C:\android-sdk2012-05-09 16:47 . 2012-05-09 16:47	--------	d-----w-	c:\users\logimen\AppData\Roaming\PDAppFlex2012-05-07 08:23 . 2012-05-07 08:23	--------	d-----w-	c:\users\Kisiel\AppData\Roaming\aWARemote2012-04-22 19:55 . 2012-04-22 19:55	--------	d-----w-	c:\users\logimen\AppData\Roaming\ImTOO2012-04-22 19:09 . 2012-04-22 19:09	--------	d-----w-	c:\users\logimen\AppData\Roaming\Xilisoft2012-04-20 23:33 . 2012-04-20 23:33	--------	d-----w-	c:\programdata\Blizzard Entertainment2012-04-20 08:59 . 2012-04-23 09:07	--------	d-----w-	c:\program files (x86)\Common Files\Blizzard Entertainment2012-04-20 08:51 . 2012-04-20 08:52	--------	d-----w-	c:\programdata\Battle.net2012-04-17 21:50 . 2012-04-17 21:50	--------	d-----w-	c:\users\logimen\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.12012-04-14 21:35 . 2012-04-14 21:35	--------	d-----w-	c:\windows\Sun2012-04-14 17:59 . 2012-03-01 06:46	23408	----a-w-	c:\windows\system32\drivers\fs_rec.sys2012-04-14 17:59 . 2012-03-01 06:38	220672	----a-w-	c:\windows\system32\wintrust.dll2012-04-14 17:59 . 2012-03-01 06:33	81408	----a-w-	c:\windows\system32\imagehlp.dll2012-04-14 17:59 . 2012-03-01 06:28	5120	----a-w-	c:\windows\system32\wmi.dll2012-04-14 17:59 . 2012-03-01 05:37	172544	----a-w-	c:\windows\SysWow64\wintrust.dll2012-04-14 17:59 . 2012-03-01 05:33	159232	----a-w-	c:\windows\SysWow64\imagehlp.dll2012-04-14 17:59 . 2012-03-01 05:29	5120	----a-w-	c:\windows\SysWow64\wmi.dll2012-04-14 17:40 . 2012-04-14 17:40	--------	d-----w-	c:\windows\system32\wbem\miconfig2012-04-13 20:33 . 2012-04-22 15:54	--------	d-----w-	c:\program files\Core Temp2012-04-13 19:54 . 2010-10-04 11:02	53248	----a-w-	c:\windows\SysWow64\CSVer.dll2012-04-13 19:47 . 2012-03-01 20:58	60800	----a-w-	c:\windows\system32\drivers\EtronHub3.sys2012-04-13 11:05 . 2012-04-13 11:05	--------	d-----w-	c:\windows\pl2012-04-13 11:04 . 2012-04-13 11:04	--------	d-----w-	c:\windows\en2012-04-13 11:03 . 2012-04-13 11:03	--------	d-----w-	c:\program files\Windows Live2012-04-13 11:02 . 2012-04-13 11:02	89944	----a-w-	c:\program files (x86)\Common Files\Windows Live\.cache\e8659ff21cd196401\DSETUP.dll2012-04-13 11:02 . 2012-04-13 11:02	537432	----a-w-	c:\program files (x86)\Common Files\Windows Live\.cache\e8659ff21cd196401\DXSETUP.exe2012-04-13 11:02 . 2012-04-13 11:02	1801048	----a-w-	c:\program files (x86)\Common Files\Windows Live\.cache\e8659ff21cd196401\dsetup32.dll...((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   )))))))))))))))))))))))))))))))))))))))))))))))))))).2012-05-07 07:25 . 2012-03-18 03:55	70304	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-05-07 07:25 . 2012-03-18 03:55	419488	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe2012-03-31 19:09 . 2012-03-31 19:09	456192	----a-w-	c:\windows\SetACL.exe2012-03-31 18:56 . 2012-03-31 18:56	178800	----a-w-	c:\windows\SysWow64\CmdLineExt_x64.dll2012-03-27 23:24 . 2009-07-13 23:41	705536	----a-w-	c:\windows\SysWow64\imagesp1.dll2012-03-27 23:24 . 2009-07-13 23:42	20268032	----a-w-	c:\windows\SysWow64\imageres.dll2012-03-27 23:23 . 2012-01-02 12:12	1498624	----a-w-	c:\windows\SysWow64\ExplorerFrame.dll2012-03-27 23:19 . 2009-07-13 23:57	705536	----a-w-	c:\windows\system32\imagesp1.dll2012-03-27 23:19 . 2009-07-13 23:57	20268032	----a-w-	c:\windows\system32\imageres.dll2012-03-27 23:18 . 2012-01-02 12:12	1867264	----a-w-	c:\windows\system32\ExplorerFrame.dll2012-03-27 12:36 . 2012-03-27 12:36	98304	----a-r-	c:\users\logimen\AppData\Roaming\Microsoft\Installer\{3577E42B-3347-4EB8-BFDA-D36E8ED3C519}\icons.exe2012-03-24 18:21 . 2012-03-24 18:20	18377015	----a-w-	C:\AirLive_WL1600USB_W7_20100309.zip2012-03-24 18:03 . 2012-03-24 18:03	21712	----a-w-	c:\windows\SysWow64\drivers\DrvAgent64.SYS2012-03-19 22:56 . 2012-03-19 09:53	76888	----a-w-	c:\windows\SysWow64\PnkBstrA.exe2012-03-19 22:56 . 2012-03-19 22:56	282864	----a-w-	c:\windows\SysWow64\PnkBstrB.xtr2012-03-19 22:56 . 2012-03-19 09:54	282864	----a-w-	c:\windows\SysWow64\PnkBstrB.exe2012-03-19 09:54 . 2012-03-19 09:54	189248	----a-w-	c:\windows\SysWow64\PnkBstrB.ex02012-03-18 22:13 . 2012-03-18 22:13	285280	----a-w-	c:\windows\system32\drivers\afcdp.sys2012-03-18 22:13 . 2012-03-18 22:13	1263200	----a-w-	c:\windows\system32\drivers\tdrpm273.sys2012-03-18 22:13 . 2012-03-18 22:13	970336	----a-w-	c:\windows\system32\drivers\timntr.sys2012-03-18 22:13 . 2012-03-18 22:13	277088	----a-w-	c:\windows\system32\drivers\snapman.sys2012-03-18 17:23 . 2012-03-18 17:23	72	----a-w-	c:\windows\Vue 7.5 xStream.reg2012-03-18 17:23 . 2012-03-18 17:23	70	----a-w-	c:\windows\Vue 7 xStream.reg2012-03-18 17:23 . 2012-03-18 17:23	70	----a-w-	c:\windows\Vue 6 xStream.reg2012-03-18 03:53 . 2012-03-18 03:53	750488	----a-w-	c:\windows\system32\npdeployJava1.dll2012-03-18 03:53 . 2012-03-18 03:53	660368	----a-w-	c:\windows\system32\deployJava1.dll2012-03-18 03:53 . 2012-03-18 03:53	637848	----a-w-	c:\windows\SysWow64\npdeployJava1.dll2012-03-18 03:53 . 2012-03-18 03:53	567184	----a-w-	c:\windows\SysWow64\deployJava1.dll2012-03-18 03:44 . 2012-03-18 03:44	98816	----a-w-	c:\windows\system32\wudriver.dll2012-03-18 03:44 . 2012-03-18 03:44	700408	----a-w-	c:\windows\system32\wuapi.dll2012-03-18 03:44 . 2012-03-18 03:44	37880	----a-w-	c:\windows\system32\wups.dll2012-03-18 03:44 . 2012-03-18 03:44	36864	----a-w-	c:\windows\system32\wuapp.exe2012-03-18 03:44 . 2012-03-18 03:44	185216	----a-w-	c:\windows\system32\wuwebv.dll2012-03-18 03:44 . 2012-03-18 03:44	57336	----a-w-	c:\windows\system32\wuauclt.exe2012-03-18 03:44 . 2012-03-18 03:44	43512	----a-w-	c:\windows\system32\wups2.dll2012-03-18 03:44 . 2012-03-18 03:44	2621440	----a-w-	c:\windows\system32\wucltux.dll2012-03-18 03:44 . 2012-03-18 03:44	2425848	----a-w-	c:\windows\system32\wuaueng.dll2012-03-17 22:57 . 2011-03-28 17:36	18328	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll2012-03-17 15:28 . 2012-03-17 15:28	283200	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys2012-03-12 18:56 . 2012-03-12 18:56	947472	----a-w-	c:\windows\SysWow64\msjava.dll2012-03-08 16:37 . 2012-03-08 16:37	302448	----a-w-	c:\windows\WLXPGSS.SCR2012-03-01 20:58 . 2011-02-08 05:30	85632	----a-w-	c:\windows\system32\drivers\EtronXHCI.sys2012-03-01 00:02 . 2012-03-18 04:08	9717568	----a-w-	c:\windows\system32\nvwgf2umx.dll2012-03-01 00:02 . 2012-03-18 04:08	962368	----a-w-	c:\windows\system32\nvumdshimx.dll2012-03-01 00:02 . 2012-03-18 04:08	812352	----a-w-	c:\windows\SysWow64\nvumdshim.dll2012-03-01 00:02 . 2012-03-18 04:08	8008000	----a-w-	c:\windows\system32\nvcuda.dll2012-03-01 00:02 . 2012-03-18 04:08	7713088	----a-w-	c:\windows\SysWow64\nvwgf2um.dll2012-03-01 00:02 . 2012-03-18 04:08	68928	----a-w-	c:\windows\system32\OpenCL.dll2012-03-01 00:02 . 2012-03-18 04:08	61248	----a-w-	c:\windows\SysWow64\OpenCL.dll2012-03-01 00:02 . 2012-03-18 04:08	5892928	----a-w-	c:\windows\SysWow64\nvcuda.dll2012-03-01 00:02 . 2012-03-18 04:08	364352	----a-w-	c:\windows\system32\nvdecodemft.dll2012-03-01 00:02 . 2012-03-18 04:08	301376	----a-w-	c:\windows\SysWow64\nvdecodemft.dll2012-03-01 00:02 . 2012-03-18 04:08	2872640	----a-w-	c:\windows\system32\nvcuvenc.dll2012-03-01 00:02 . 2012-03-18 04:08	2672448	----a-w-	c:\windows\system32\nvcuvid.dll2012-03-01 00:02 . 2012-03-18 04:08	2660160	----a-w-	c:\windows\system32\nvapi64.dll2012-03-01 00:02 . 2012-03-18 04:08	260416	----a-w-	c:\windows\system32\nvinitx.dll2012-03-01 00:02 . 2012-03-18 04:08	25543488	----a-w-	c:\windows\system32\nvoglv64.dll2012-03-01 00:02 . 2012-03-18 04:08	25222976	----a-w-	c:\windows\system32\nvcompiler.dll2012-03-01 00:02 . 2012-03-18 04:08	2517312	----a-w-	c:\windows\SysWow64\nvcuvid.dll2012-03-01 00:02 . 2012-03-18 04:08	2437440	----a-w-	c:\windows\SysWow64\nvcuvenc.dll2012-03-01 00:02 . 2012-03-18 04:08	2301248	----a-w-	c:\windows\SysWow64\nvapi.dll2012-03-01 00:02 . 2012-03-18 04:08	215360	----a-w-	c:\windows\SysWow64\nvinit.dll2012-03-01 00:02 . 2012-03-18 04:08	19444544	----a-w-	c:\windows\SysWow64\nvoglv32.dll2012-03-01 00:02 . 2012-03-18 04:08	17642816	----a-w-	c:\windows\system32\nvd3dumx.dll2012-03-01 00:02 . 2012-03-18 04:08	17543488	----a-w-	c:\windows\SysWow64\nvcompiler.dll2012-03-01 00:02 . 2012-03-18 04:08	1737536	----a-w-	c:\windows\system32\nvdispco64.dll2012-03-01 00:02 . 2012-03-18 04:08	15009600	----a-w-	c:\windows\SysWow64\nvd3dum.dll2012-03-01 00:02 . 2012-03-18 04:08	1466176	----a-w-	c:\windows\system32\nvgenco64.dll2012-03-01 00:02 . 2012-03-18 04:08	13626688	----a-w-	c:\windows\system32\drivers\nvlddmkm.sys2012-02-29 21:00 . 2012-03-18 04:09	3089728	----a-w-	c:\windows\system32\nvsvc64.dll2012-02-29 21:00 . 2012-03-18 04:09	6074176	----a-w-	c:\windows\system32\nvcpl.dll2012-02-29 20:59 . 2012-03-18 04:09	889664	----a-w-	c:\windows\system32\nvvsvc.exe2012-02-29 20:59 . 2012-03-18 04:09	63296	----a-w-	c:\windows\system32\nvshext.dll2012-02-29 20:59 . 2012-03-18 04:09	2561856	----a-w-	c:\windows\system32\nvsvcr.dll2012-02-29 20:59 . 2012-03-18 04:09	118080	----a-w-	c:\windows\system32\nvmctray.dll2012-02-29 20:59 . 2012-03-18 04:09	2515790	----a-w-	c:\windows\system32\nvcoproc.bin2012-02-17 06:38 . 2012-03-19 01:06	1112064	----a-w-	c:\windows\system32\rdpcorets.dll2012-02-17 06:38 . 2012-03-19 01:06	1031680	----a-w-	c:\windows\system32\rdpcore.dll2012-02-17 05:34 . 2012-03-19 01:06	826880	----a-w-	c:\windows\SysWow64\rdpcore.dll2012-02-17 04:58 . 2012-03-19 01:06	210944	----a-w-	c:\windows\system32\drivers\rdpwd.sys2012-02-17 04:57 . 2012-03-19 01:06	23552	----a-w-	c:\windows\system32\drivers\tdtcp.sys..(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))..*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane  REGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016]"ChomikBox"="c:\program files (x86)\ChomikBox\chomikbox.exe" [2012-02-22 5951488].[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]"aWARemote"="c:\program files (x86)\aWARemote Pro Server\aWARemote Pro Server.exe" [2012-04-03 2096640].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 5 (0x5)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"SynchronousMachineGroupPolicy"= 0 (0x0)"SynchronousUserGroupPolicy"= 0 (0x0)"EnableLinkedConnections"= 1 (0x1).[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]"MemCheckboxinRunDlg"= 1 (0x1)"NoResolveTrack"= 1 (0x1)"NoTaskGrouping"= 1 (0x1).[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"NoResolveTrack"= 1 (0x1)"AlwaysShowClassicMenu"= 1 (0x1)"NoTaskGrouping"= 1 (0x1).[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]"mixer4"=wdmaud.drv.[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]BootExecute	REG_MULTI_SZ   	.[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Security Packages	REG_MULTI_SZ   	kerberos msv1_0 schannel wdigest tspkg pku2u livessp.[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]"TrueImageMonitor.exe"="h:\programy\Acronis\True Image Home 2011\TrueImageMonitor.exe""Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe""AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin.R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2011-06-27 130384]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2011-06-27 138576]R2 gupdate;Usługa Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-19 136176]R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-07 257696]R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]R3 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-03-18 3246040]R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-03-18 1431888]R3 gupdatem;Usługa Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-19 136176]R3 OS Selector;Acronis OS Selector activator;h:\programy\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-05-25 2139536]R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]R3 RTL8187;AirLive WL1600USB;c:\windows\system32\DRIVERS\rtl8187.sys [x]R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys [x]R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]S0 AsrRamDisk;AsrRamDisk;c:\windows\system32\DRIVERS\AsrRamDisk.sys [x]S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [x]S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]S2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;h:\programy\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [2011-02-22 86016]S3 ALSysIO;ALSysIO;c:\users\LOGIMEN\APPDATA\LOCAL\TEMP\ALSysIO64.sys [x]S3 cmudaxp;ASUS Xonar DX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [x]S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x]S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x]S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]S3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys [2010-05-27 14648]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]..--- Inne Usługi/Sterowniki w Pamięci ---.*NewlyCreated* - IPNAT*NewlyCreated* - WS2IFSL.Zawartość folderu 'Zaplanowane zadania'.2012-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-18 07:25].2012-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-19 16:47].2012-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-19 16:47]..--------- x86-64 -----------..[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2011-05-12 8769536]"Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]"Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 4035152].[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"LoadAppInit_DLLs"=0x0.------- Skan uzupełniający -------.uStart Page = hxxp://google.pl/IE: E&ksportuj do programu Microsoft Excel - c:\program files (x86)\MIF5BA~1\Office12\EXCEL.EXE/3000TCP: DhcpNameServer = 192.168.1.1 192.168.1.1..--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------.[HKEY_USERS\S-1-5-21-685053964-3640630684-2288971780-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]@Denied: (2) (LocalSystem)"Progid"="WindowsLiveMail.VCard.1".[HKEY_USERS\S-1-5-21-685053964-3640630684-2288971780-1000\Software\SecuROM\License information*]"datasecu"=hex:9d,ae,5d,cb,6f,f3,f5,60,c5,79,90,92,7a,e4,41,2d,f2,46,28,eb,5a,   94,89,da,28,23,ab,09,fd,5e,f0,35,c1,c5,9a,69,90,25,ae,1f,37,76,d4,57,62,aa,\"rkeysecu"=hex:05,ed,79,7e,27,f4,60,13,c7,2f,97,ef,e8,ea,4e,58.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.11".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]@Denied: (A 2) (Everyone)@="IFlashBroker4".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).------------------------ Pozostałe uruchomione procesy ------------------------.c:\windows\SysWOW64\PnkBstrA.exec:\program files (x86)\MSI Afterburner\MSIAfterburner.exec:\program files\ASUS Xonar DX Audio\Customapp\ASUSAUDIOCENTER.EXEc:\program files (x86)\DAEMON Tools Lite\DTShellHlp.exec:\program files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe.**************************************************************************.Czas ukończenia: 2012-05-12  10:39:44 - komputer został uruchomiony ponownieComboFix-quarantined-files.txt  2012-05-12 08:39.Przed: 26 196 037 632 bytes freePo: 26 076 286 976 bytes free.- - End Of File - - 98FA774CFD6E5FC11E84D871BC814B56

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Dołącz do dyskusji

Możesz dodać zawartość już teraz a zarejestrować się później. Jeśli posiadasz już konto, zaloguj się aby dodać zawartość za jego pomocą.

Gość
Dodaj odpowiedź do tematu...

×   Wklejono zawartość z formatowaniem.   Przywróć formatowanie

  Dozwolonych jest tylko 75 emoji.

×   Odnośnik został automatycznie osadzony.   Przywróć wyświetlanie jako odnośnik

×   Przywrócono poprzednią zawartość.   Wyczyść edytor

×   Nie możesz bezpośrednio wkleić grafiki. Dodaj lub załącz grafiki z adresu URL.

Ładowanie


×
×
  • Dodaj nową pozycję...