Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 14-11-24.02 - Ania 2014-11-24 21:23:07.1.4 - x64
- Microsoft Windows 7 Professional 6.1.7601.1.1250.48.1045.18.8075.5596 [GMT 1:00]
- Uruchomiony z: c:\users\Ania\Downloads\ComboFix.exe
- AV: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
- SP: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\windows\msdownld.tmp
- .
- .
- ((((((((((((((((((((((((( Pliki utworzone od 2014-10-24 do 2014-11-24 )))))))))))))))))))))))))))))))
- .
- .
- 2014-11-24 20:33 . 2014-11-24 20:33 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
- 2014-11-24 20:33 . 2014-11-24 20:33 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2014-11-24 19:05 . 2014-11-24 19:05 -------- d-----w- c:\users\Ania\AppData\Local\ESET
- 2014-11-24 18:44 . 2014-11-24 18:44 -------- d-----w- c:\program files\ESET
- 2014-11-24 17:33 . 2014-11-24 17:33 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B72FD100-AB85-445F-9098-9426ECAF9546}\offreg.dll
- 2014-11-21 23:37 . 2014-11-02 04:20 11632448 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B72FD100-AB85-445F-9098-9426ECAF9546}\mpengine.dll
- 2014-11-19 09:40 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
- 2014-11-19 09:40 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
- 2014-11-19 09:40 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
- 2014-11-19 09:40 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
- 2014-11-14 19:44 . 2014-11-14 20:04 -------- d-----w- c:\users\Ania\AppData\Local\gtk-2.0
- 2014-11-14 19:44 . 2014-11-14 19:44 -------- d-----w- c:\users\Ania\.thumbnails
- 2014-11-14 19:39 . 2014-11-14 19:39 -------- d-----w- c:\users\Ania\AppData\Local\fontconfig
- 2014-11-14 19:39 . 2014-11-14 20:16 -------- d-----w- c:\users\Ania\.gimp-2.8
- 2014-11-14 19:39 . 2014-11-14 19:39 -------- d-----w- c:\users\Ania\AppData\Local\gegl-0.2
- 2014-11-14 19:38 . 2014-11-14 19:38 -------- d-----w- c:\program files\GIMP 2
- 2014-11-12 16:44 . 2014-11-05 17:56 304640 ----a-w- c:\windows\system32\generaltel.dll
- 2014-11-12 16:44 . 2014-11-05 17:56 228864 ----a-w- c:\windows\system32\aepdu.dll
- 2014-11-12 16:44 . 2014-11-05 17:52 424448 ----a-w- c:\windows\system32\aeinv.dll
- 2014-11-12 16:44 . 2014-10-14 02:16 155064 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
- 2014-11-12 16:44 . 2014-10-14 02:13 683520 ----a-w- c:\windows\system32\termsrv.dll
- 2014-11-12 16:44 . 2014-10-14 02:12 1460736 ----a-w- c:\windows\system32\lsasrv.dll
- 2014-11-12 16:44 . 2014-10-14 02:09 146432 ----a-w- c:\windows\system32\msaudite.dll
- 2014-11-12 16:44 . 2014-10-14 02:07 681984 ----a-w- c:\windows\system32\adtschema.dll
- 2014-11-12 16:44 . 2014-10-14 01:50 22016 ----a-w- c:\windows\SysWow64\secur32.dll
- 2014-11-12 16:44 . 2014-10-14 01:49 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
- 2014-11-12 16:44 . 2014-10-14 01:47 146432 ----a-w- c:\windows\SysWow64\msaudite.dll
- 2014-11-12 16:44 . 2014-10-14 01:46 681984 ----a-w- c:\windows\SysWow64\adtschema.dll
- 2014-11-03 20:16 . 2014-11-03 20:16 -------- d-----w- c:\users\Ania\AppData\Roaming\SolidDocuments
- 2014-10-26 12:25 . 2014-10-26 12:26 -------- d-----w- c:\programdata\FLEXnet
- 2014-10-26 12:20 . 2014-10-26 12:20 520584 ----a-r- c:\users\Ania\AppData\Roaming\Microsoft\Installer\{9D589081-AFC2-4932-9071-AC585AC1EA83}\UninstallTool.D01EB5D5_0EC4_4BDF_A131_1989F9F14A91.exe
- 2014-10-26 12:19 . 2014-11-03 20:50 -------- d-----w- c:\users\Ania\AppData\Local\Autodesk
- 2014-10-26 12:18 . 2014-10-26 12:18 -------- d-----w- c:\program files\Common Files\Macrovision Shared
- 2014-10-26 12:16 . 2014-10-26 12:20 -------- d-----w- c:\program files\Common Files\Autodesk Shared
- 2014-10-26 12:16 . 2014-10-26 12:16 -------- d-----w- c:\program files\Autodesk
- 2014-10-26 12:15 . 2014-10-26 12:15 -------- d-----w- c:\program files (x86)\Autodesk
- 2014-10-26 12:13 . 2014-10-26 12:20 -------- d-----w- c:\programdata\Package Cache
- 2014-10-26 12:11 . 2014-10-26 12:32 -------- d-----w- c:\users\Ania\AppData\Roaming\Autodesk
- 2014-10-26 12:11 . 2014-10-26 12:32 -------- d-----w- c:\programdata\Autodesk
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2014-11-12 22:26 . 2014-01-15 18:16 103374192 ----a-w- c:\windows\system32\MRT.exe
- 2014-11-04 13:30 . 2010-11-21 03:27 275080 ------w- c:\windows\system32\MpSigStub.exe
- 2014-10-10 07:59 . 2014-10-10 07:59 243440 ----a-w- c:\windows\system32\drivers\eamonm.sys
- 2014-10-10 07:59 . 2014-10-10 07:59 241368 ----a-w- c:\windows\system32\drivers\edevmon.sys
- 2014-10-10 07:59 . 2014-10-10 07:59 169280 ----a-w- c:\windows\system32\drivers\ehdrv.sys
- 2014-10-10 07:59 . 2014-10-10 07:59 158968 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
- 2014-10-03 19:48 . 2014-10-03 18:52 16152 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
- 2014-10-03 18:46 . 2013-04-22 08:13 92864 ----a-w- c:\windows\system32\DptfPolicyLpmService.exe
- 2014-10-03 18:46 . 2013-04-22 08:13 84568 ----a-w- c:\windows\system32\DptfPolicyCriticalService.exe
- 2014-10-03 18:46 . 2013-04-22 08:13 79376 ----a-w- c:\windows\system32\DptfPolicyLpmServiceHelper.exe
- 2014-10-03 18:46 . 2013-04-22 08:13 83032 ----a-w- c:\windows\system32\DptfParticipantProcessorService.exe
- 2014-10-03 18:46 . 2013-04-22 08:13 100032 ----a-w- c:\windows\system32\DptfPolicyConfigTDPService.exe
- 2014-10-03 18:46 . 2013-04-22 08:13 57216 ----a-w- c:\windows\system32\drivers\DptfDevPch.sys
- 2014-10-03 18:46 . 2013-04-22 08:13 200808 ----a-w- c:\windows\system32\drivers\DptfManager.sys
- 2014-10-03 18:46 . 2013-04-22 08:13 120256 ----a-w- c:\windows\system32\drivers\DptfDevProc.sys
- 2014-10-03 18:46 . 2013-04-22 08:13 78384 ----a-w- c:\windows\system32\DptfPolicyLpmDll.dll
- 2014-10-03 18:46 . 2013-04-22 08:13 77872 ----a-w- c:\windows\system32\DptfPolicyConfigTDPDll.dll
- 2014-10-03 18:46 . 2013-04-22 08:13 20536 ----a-w- c:\windows\system32\DptfCoInstaller.dll
- 2014-10-03 18:46 . 2013-04-22 08:13 186328 ----a-w- c:\windows\SysWow64\DptfInvalidPolicyRemover.exe
- 2014-10-03 18:46 . 2013-04-22 08:13 11128 ----a-w- c:\windows\system32\DptfEventLogMessage.dll
- 2014-10-03 18:35 . 2013-05-03 07:54 677360 ----a-w- c:\windows\system32\drivers\iaStorA.sys
- 2014-10-03 18:35 . 2013-05-03 07:54 28656 ----a-w- c:\windows\system32\drivers\iaStorF.sys
- 2014-10-03 18:35 . 2014-10-03 18:35 11866696 ----a-w- c:\windows\SysWow64\RtsPerIcon.dll
- 2014-10-03 18:35 . 2014-10-03 18:35 460872 ----a-w- c:\windows\system32\drivers\RtsPer.sys
- 2014-10-03 18:28 . 2013-06-14 14:21 824536 ----a-w- c:\windows\system32\drivers\Rt630x64.sys
- 2014-10-03 18:24 . 2014-10-03 18:25 15900936 ----a-w- c:\windows\system32\nvwgf2umx.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 13627696 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 6329552 ----a-w- c:\windows\SysWow64\nvopencl.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 30496 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
- 2014-10-03 18:24 . 2014-10-03 18:25 1412832 ----a-w- c:\windows\system32\nvumdshimx.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 1222824 ----a-w- c:\windows\SysWow64\nvumdshim.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 7648000 ----a-w- c:\windows\system32\nvopencl.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 29337376 ----a-w- c:\windows\system32\nvoglv64.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 317472 ----a-w- c:\windows\system32\nvoglshim64.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 266984 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 22101792 ----a-w- c:\windows\SysWow64\nvoglv32.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 11273504 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
- 2014-10-03 18:24 . 2014-10-03 18:25 681760 ----a-w- c:\windows\system32\NvFBC64.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 603424 ----a-w- c:\windows\system32\NvIFR64.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 586016 ----a-w- c:\windows\SysWow64\NvFBC.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 515360 ----a-w- c:\windows\SysWow64\NvIFR.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 458528 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 388384 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 168616 ----a-w- c:\windows\system32\nvinitx.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 1511712 ----a-w- c:\windows\system32\nvdispgenco6432683.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 141336 ----a-w- c:\windows\SysWow64\nvinit.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 1884448 ----a-w- c:\windows\system32\nvdispco6432683.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 15703176 ----a-w- c:\windows\system32\nvd3dumx.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 2970400 ----a-w- c:\windows\system32\nvcuvid.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 2789152 ----a-w- c:\windows\SysWow64\nvcuvid.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 2007328 ----a-w- c:\windows\system32\nvcuvenc.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 12946848 ----a-w- c:\windows\SysWow64\nvd3dum.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 7720576 ----a-w- c:\windows\SysWow64\nvcuda.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 2007328 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 9281032 ----a-w- c:\windows\system32\nvcuda.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 25256224 ----a-w- c:\windows\system32\nvcompiler.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 2986672 ----a-w- c:\windows\system32\nvapi64.dll
- 2014-10-03 18:24 . 2014-10-03 18:25 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 4067328 ----a-w- c:\windows\system32\MetroIntelGenericUIFramework.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 304640 ----a-w- c:\windows\system32\IntelOpenCL64.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 253440 ----a-w- c:\windows\SysWow64\IntelOpenCL32.dll
- 2014-10-03 18:22 . 2014-10-03 18:23 64000 ----a-w- c:\windows\system32\OpenCL.DLL
- 2014-10-03 18:22 . 2014-10-03 18:23 60416 ----a-w- c:\windows\SysWow64\OpenCL.DLL
- 2014-10-03 18:22 . 2013-08-28 13:34 64000 ----a-w- c:\windows\system32\Intel_OpenCL_ICD64.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 60416 ----a-w- c:\windows\SysWow64\Intel_OpenCL_ICD32.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 279000 ----a-w- c:\windows\SysWow64\IntelCpHeciSvc.exe
- 2014-10-03 18:22 . 2013-08-28 13:34 214528 ----a-w- c:\windows\system32\iglhcp64.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 180224 ----a-w- c:\windows\system32\igfxCoIn_v3277.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 1127424 ----a-w- c:\windows\system32\iglhsip64.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 1123328 ----a-w- c:\windows\SysWow64\iglhsip32.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 843224 ----a-w- c:\windows\system32\igfxsrvc.exe
- 2014-10-03 18:22 . 2013-08-28 13:34 66048 ----a-w- c:\windows\system32\igfxsrvc.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 524288 ----a-w- c:\windows\system32\igfxrtrk.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 391128 ----a-w- c:\windows\system32\igfxtray.exe
- 2014-10-03 18:22 . 2013-08-28 13:34 345600 ----a-w- c:\windows\system32\igfxTMM.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 179712 ----a-w- c:\windows\SysWow64\iglhcp32.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 526336 ----a-w- c:\windows\system32\igfxrrus.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 525824 ----a-w- c:\windows\system32\igfxrsky.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 524800 ----a-w- c:\windows\system32\igfxrsve.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 524800 ----a-w- c:\windows\system32\igfxrslv.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 523776 ----a-w- c:\windows\system32\igfxrtha.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 526848 ----a-w- c:\windows\system32\igfxrplk.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 525824 ----a-w- c:\windows\system32\igfxrrom.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 525312 ----a-w- c:\windows\system32\igfxrptg.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 524288 ----a-w- c:\windows\system32\igfxrptb.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 526336 ----a-w- c:\windows\system32\igfxrnld.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 525824 ----a-w- c:\windows\system32\igfxrita.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 525312 ----a-w- c:\windows\system32\igfxrhun.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 523776 ----a-w- c:\windows\system32\igfxrnor.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 517120 ----a-w- c:\windows\system32\igfxrjpn.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 516096 ----a-w- c:\windows\system32\igfxrkor.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 9081856 ----a-w- c:\windows\system32\igfxress.dll
- 2014-10-03 18:22 . 2013-08-28 13:34 526848 ----a-w- c:\windows\system32\igfxrfra.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 525312 ----a-w- c:\windows\system32\igfxrhrv.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 524800 ----a-w- c:\windows\system32\igfxrfin.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 522240 ----a-w- c:\windows\system32\igfxrheb.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 527360 ----a-w- c:\windows\system32\igfxrell.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 526848 ----a-w- c:\windows\system32\igfxresn.lrc
- 2014-10-03 18:22 . 2013-08-28 13:34 371200 ----a-w- c:\windows\system32\igfxrenu.lrc
- .
- .
- ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "BtTray"="c:\program files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe" [2013-01-10 379904]
- "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2013-05-21 406328]
- "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2013-05-30 205624]
- "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
- "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2014-06-27 292848]
- "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
- "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe" [2013-12-21 3478392]
- "ADSKAppManager"="c:\program files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" [2013-12-22 477064]
- .
- c:\users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- apm off.lnk - c:\program files (x86)\hdparm\apm off.cmd [2014-10-3 24]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableLUA"= 0 (0x0)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
- "LoadAppInit_DLLs"=1 (0x1)
- "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
- .
- R0 edevmon;edevmon;c:\windows\system32\DRIVERS\edevmon.sys;c:\windows\SYSNATIVE\DRIVERS\edevmon.sys [x]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
- R3 BthL2caScoIfSrv;Bluetooth Profile Interface Driver Service;c:\windows\system32\Drivers\BtL2caScoIf.sys;c:\windows\SYSNATIVE\Drivers\BtL2caScoIf.sys [x]
- R3 btUrbFilterDrv;IVT URB Bluetooth Filter Driver Service;c:\windows\system32\Drivers\IvtUrbBtFlt.sys;c:\windows\SYSNATIVE\Drivers\IvtUrbBtFlt.sys [x]
- R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
- R3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [x]
- R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
- R3 IntcDAud;Audio dla wyświetlaczy Intel(R);c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
- R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
- R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
- R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
- R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
- R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
- R3 USTOR2K;USB Mass Storage Windows Driver;c:\windows\system32\DRIVERS\ustor2k.sys;c:\windows\SYSNATIVE\DRIVERS\ustor2k.sys [x]
- R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
- S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
- S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
- S0 iusb3hcs;Sterownik przełącznika kontrolera hosta Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
- S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
- S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
- S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
- S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
- S2 AdAppMgrSvc;Autodesk Application Manager Service;c:\program files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe ;c:\program files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [x]
- S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
- S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
- S2 DptfParticipantProcessorService;Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service Application;c:\windows\system32\DptfParticipantProcessorService.exe;c:\windows\SYSNATIVE\DptfParticipantProcessorService.exe [x]
- S2 DptfPolicyConfigTDPService;Intel(R) Dynamic Platform and Thermal Framework Config TDP Service Application;c:\windows\system32\DptfPolicyConfigTDPService.exe;c:\windows\SYSNATIVE\DptfPolicyConfigTDPService.exe [x]
- S2 DptfPolicyCriticalService;Intel(R) Dynamic Platform and Thermal Framework Critical Service Application;c:\windows\system32\DptfPolicyCriticalService.exe;c:\windows\SYSNATIVE\DptfPolicyCriticalService.exe [x]
- S2 DptfPolicyLpmService;Intel(R) Dynamic Platform and Thermal Framework Low Power Mode Service Application;c:\windows\system32\DptfPolicyLpmService.exe;c:\windows\SYSNATIVE\DptfPolicyLpmService.exe [x]
- S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
- S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
- S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
- S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
- S3 BtAudioBusSrv;Ralink Bluetooth Audio Bus Service;c:\windows\system32\Drivers\BtAudioBus.sys;c:\windows\SYSNATIVE\Drivers\BtAudioBus.sys [x]
- S3 DptfDevPch;DptfDevPch;c:\windows\system32\DRIVERS\DptfDevPch.sys;c:\windows\SYSNATIVE\DRIVERS\DptfDevPch.sys [x]
- S3 DptfDevProc;DptfDevProc;c:\windows\system32\DRIVERS\DptfDevProc.sys;c:\windows\SYSNATIVE\DRIVERS\DptfDevProc.sys [x]
- S3 DptfManager;DptfManager;c:\windows\system32\DRIVERS\DptfManager.sys;c:\windows\SYSNATIVE\DRIVERS\DptfManager.sys [x]
- S3 iusb3hub;Sterownik koncentratora Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
- S3 iusb3xhc;Sterownik kontrolera hosta Intel(R) USB 3.0 eXtensible;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
- S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
- S3 rtbth;RTBTH Bluetooth Device Driver;c:\windows\system32\DRIVERS\rtbth.sys;c:\windows\SYSNATIVE\DRIVERS\rtbth.sys [x]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
- S3 RTSPER;Realtek PCIE Card Reader - PER;c:\windows\system32\DRIVERS\RtsPer.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPer.sys [x]
- .
- .
- --- Inne Usługi/Sterowniki w Pamięci ---
- .
- *NewlyCreated* - EAMONM
- *NewlyCreated* - EHDRV
- *NewlyCreated* - EPFWWFPR
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
- 2014-11-20 15:56 1087304 ----a-w- c:\program files (x86)\Google\Chrome\Application\39.0.2171.65\Installer\chrmstp.exe
- .
- Zawartość folderu 'Zaplanowane zadania'
- .
- 2014-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-10-03 18:40]
- .
- 2014-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-10-03 18:40]
- .
- .
- --------- X64 Entries -----------
- .
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-10-03 771032]
- "Persistence"="c:\windows\system32\igfxpers.exe" [2014-10-03 769496]
- "DptfPolicyLpmServiceHelper"="c:\windows\system32\DptfPolicyLpmServiceHelper.exe" [2014-10-03 79376]
- "UMonit"="c:\windows\SysWOW64\UMonit.exe" [2000-01-01 40960]
- "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
- "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2014-10-01 5595336]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
- .
- ------- Skan uzupełniający -------
- .
- uStart Page = hxxp://google.pl/
- uLocal Page = c:\windows\system32\blank.htm
- mLocal Page = c:\windows\SysWOW64\blank.htm
- IE: E&ksportuj do programu Microsoft Excel - c:\program files (x86)\MICROS~1\Office14\EXCEL.EXE/3000
- IE: Wyślij &do programu OneNote - c:\program files (x86)\MICROS~1\Office14\ONBttnIE.dll/105
- TCP: DhcpNameServer = 192.168.1.1
- .
- - - - - USUNIĘTO PUSTE WPISY - - - -
- .
- Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
- Wow6432Node-HKLM-Run-<NO NAME> - (no file)
- HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
- .
- .
- .
- --------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
- @Denied: (A) (Everyone)
- "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
- @Denied: (A) (Everyone)
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
- "Key"="ActionsPane3"
- "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- Czas ukończenia: 2014-11-24 21:51:25
- ComboFix-quarantined-files.txt 2014-11-24 20:51
- .
- Przed: 162 838 114 304 bajtów wolnych
- Po: 163 246 362 624 bajtów wolnych
- .
- - - End Of File - - 175798D7F72E370D65164DECB7CE08E6
- A36C5E4F47E84449FF07ED3517B43A31
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement