Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 12-03-03.02 - Apock 2012-03-04 14:11:49.1.4 - x64
- Microsoft Windows 7 Enterprise 6.1.7601.1.1250.48.1033.18.4095.1660 [GMT 1:00]
- Uruchomiony z: c:\users\Apock\Desktop\ComboFix.exe
- AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
- SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\programdata\ntuser.dat
- c:\windows\logboot_14.02.2012.tureg.log
- c:\windows\logboot_18.02.2012.tureg.log
- c:\windows\SysWow64\Temp
- c:\windows\SysWow64\Temp\KSKD87SFXS
- .
- Zainfekowana kopia c:\windows\System32\winver.exe została znaleziona. Problem naprawiono
- Plik odzyskano z - c:\windows\winsxs\amd64_microsoft-windows-winver_31bf3856ad364e35_6.1.7600.16385_none_12466fe3b629e036\winver.exe
- .
- .
- ((((((((((((((((((((((((( Pliki utworzone od 2012-02-04 do 2012-03-04 )))))))))))))))))))))))))))))))
- .
- .
- 2012-03-04 13:15 . 2012-03-04 13:15 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2012-03-03 14:12 . 2012-03-03 14:12 -------- d-----w- c:\users\Apock\AppData\Roaming\Avira
- 2012-03-03 14:12 . 2012-03-04 19:19 -------- d-----w- c:\programdata\Avira
- 2012-03-03 14:12 . 2012-03-03 14:12 -------- d-----w- c:\program files (x86)\Avira
- 2012-03-03 14:12 . 2011-09-18 07:39 130760 ----a-w- c:\windows\system32\drivers\avipbb.sys
- 2012-03-03 14:12 . 2011-09-15 22:55 97312 ----a-w- c:\windows\system32\drivers\avgntflt.sys
- 2012-03-03 14:12 . 2011-09-15 22:55 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
- 2012-02-29 15:43 . 2012-02-29 15:43 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
- 2012-02-28 07:52 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DA202D88-3660-4B7B-A942-5A8CE88B087A}\mpengine.dll
- 2012-02-27 11:47 . 2012-03-04 10:57 -------- d-----w- c:\users\UpdatusUser
- 2012-02-25 23:57 . 2012-02-25 23:57 -------- d-----w- c:\users\Apock\AppData\Local\PassMark
- 2012-02-25 23:55 . 2012-02-25 23:55 -------- d-----w- c:\programdata\PassMark
- 2012-02-25 23:55 . 2012-02-25 23:55 -------- d-----w- c:\program files (x86)\BurnInTest
- 2012-02-25 23:44 . 2012-02-25 23:44 -------- d-----w- c:\program files (x86)\HD Tune
- 2012-02-25 17:00 . 2012-02-25 19:10 -------- d-----w- c:\program files (x86)\Google
- 2012-02-21 11:48 . 2012-02-21 11:48 -------- d-----w- c:\users\Apock\AppData\Roaming\Canneverbe Limited
- 2012-02-21 11:48 . 2012-02-21 11:48 -------- d-----w- c:\programdata\Canneverbe Limited
- 2012-02-21 11:47 . 2012-02-21 11:48 -------- d-----w- c:\program files (x86)\CDBurnerXP
- 2012-02-20 15:09 . 2012-02-20 15:09 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
- 2012-02-20 15:09 . 2012-02-20 15:09 -------- d-----w- c:\users\Apock\AppData\Roaming\SystemRequirementsLab
- 2012-02-17 13:10 . 2012-02-17 13:10 -------- d-----w- c:\program files\CPUID
- 2012-02-17 13:10 . 2011-09-21 09:25 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys
- 2012-02-17 12:50 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
- 2012-02-17 12:01 . 2012-02-17 12:45 -------- d-----w- c:\users\Apock\AppData\Roaming\Download Manager
- 2012-02-12 12:41 . 2012-02-12 12:41 -------- d-----w- c:\users\Apock\AppData\Local\Western Digital
- 2012-02-12 10:07 . 2012-02-12 10:07 -------- d-----w- c:\windows\SysWow64\xlive
- 2012-02-12 10:07 . 2012-02-12 10:07 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
- 2012-02-12 09:59 . 2011-11-16 13:35 54400 ----a-w- c:\windows\system32\drivers\usbfilter.sys
- 2012-02-12 09:58 . 2012-02-12 09:58 -------- d-----w- C:\AMD
- 2012-02-12 09:57 . 2011-12-21 16:35 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
- 2012-02-12 09:57 . 2011-11-23 22:02 648808 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
- 2012-02-12 09:57 . 2011-11-23 22:02 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
- 2012-02-12 09:20 . 2012-02-12 09:20 -------- d-----w- c:\users\Apock\AppData\Local\PackageAware
- 2012-02-11 13:48 . 2012-02-11 13:48 -------- d-----w- c:\program files (x86)\7-Zip
- 2012-02-11 12:50 . 2009-03-18 15:35 33856 ---ha-w- c:\windows\system32\hamachi.sys
- 2012-02-09 19:28 . 2012-03-01 20:11 -------- d-----w- c:\users\Apock\AppData\Roaming\Skype
- 2012-02-09 19:28 . 2012-02-09 19:28 -------- d-----w- c:\program files (x86)\Common Files\Skype
- 2012-02-09 19:28 . 2012-02-09 19:28 -------- d-----r- c:\program files (x86)\Skype
- 2012-02-09 19:27 . 2012-02-09 19:27 -------- d-----w- c:\programdata\Skype
- 2012-02-09 19:11 . 2012-02-22 22:40 -------- d-----w- c:\program files (x86)\Steam
- 2012-02-09 16:23 . 2012-02-15 00:24 -------- d-----w- c:\program files (x86)\Common Files\Steam
- 2012-02-09 13:45 . 2012-02-09 13:45 -------- d-----w- c:\users\Apock\AppData\Local\Adobe
- 2012-02-09 13:45 . 2012-02-09 13:45 -------- d-----w- c:\program files (x86)\Common Files\Adobe
- 2012-02-08 22:52 . 2012-03-04 13:15 -------- d-----w- c:\users\Apock\AppData\Local\LogMeIn Hamachi
- 2012-02-05 11:49 . 2012-02-05 11:49 -------- d-----w- c:\users\Apock\AppData\Local\Diagnostics
- 2012-02-04 18:30 . 2012-02-04 18:30 -------- d-----w- c:\programdata\RELOADED
- 2012-02-04 18:17 . 2012-02-04 18:17 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
- 2012-02-04 18:16 . 2012-02-04 18:17 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
- 2012-02-04 18:16 . 2012-02-04 18:19 -------- d-----w- c:\users\Apock\AppData\Roaming\DAEMON Tools Lite
- 2012-02-04 18:16 . 2012-02-04 18:16 -------- d-----w- c:\programdata\DAEMON Tools Lite
- 2012-02-03 13:19 . 2012-02-03 13:19 -------- d-----w- c:\users\Apock\AppData\Roaming\Media Player Classic
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2012-02-23 16:23 . 2012-01-30 10:29 258520 ----a-w- c:\windows\system32\aswBoot.exe
- 2012-02-10 04:13 . 2012-01-30 11:29 7713088 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
- 2012-02-10 04:13 . 2012-01-30 11:29 2660160 ----a-w- c:\windows\system32\nvapi64.dll
- 2012-02-10 04:13 . 2012-01-30 11:29 2301248 ----a-w- c:\windows\SysWow64\nvapi.dll
- 2012-02-10 04:13 . 2012-01-30 11:29 1737536 ----a-w- c:\windows\system32\nvdispco64.dll
- 2012-02-10 04:13 . 2012-01-30 11:29 1466176 ----a-w- c:\windows\system32\nvgenco64.dll
- 2012-02-10 04:13 . 2009-07-13 21:59 9717568 ----a-w- c:\windows\system32\nvwgf2umx.dll
- 2012-02-10 04:13 . 2009-06-10 20:37 15009600 ----a-w- c:\windows\SysWow64\nvd3dum.dll
- 2012-02-10 03:14 . 2012-01-30 11:30 6074176 ----a-w- c:\windows\system32\nvcpl.dll
- 2012-02-10 03:14 . 2012-01-30 11:30 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
- 2012-02-10 03:07 . 2012-01-30 11:30 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
- 2012-02-10 03:07 . 2012-01-30 11:30 889664 ----a-w- c:\windows\system32\nvvsvc.exe
- 2012-02-10 03:07 . 2012-01-30 11:30 63296 ----a-w- c:\windows\system32\nvshext.dll
- 2012-02-10 03:07 . 2012-01-30 11:30 118080 ----a-w- c:\windows\system32\nvmctray.dll
- 2012-01-30 12:24 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
- 2012-01-30 12:24 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
- 2012-01-30 10:07 . 2012-01-30 10:07 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2012-01-30 10:05 . 2012-01-30 10:05 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
- 2012-01-29 04:10 . 2010-10-11 17:47 279656 ------w- c:\windows\system32\MpSigStub.exe
- 2012-01-25 18:00 . 2012-01-30 16:03 79360 ----a-w- c:\windows\SysWow64\ff_vfw.dll
- 2011-12-21 18:14 . 2012-01-30 16:03 151552 ----a-w- c:\windows\SysWow64\ac3acm.acm
- 2011-12-13 17:27 . 2012-01-30 11:37 4718952 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
- 2011-12-13 15:58 . 2012-01-30 11:37 1560168 ----a-w- c:\windows\system32\RTSnMg64.cpl
- 2011-12-13 10:01 . 2012-01-30 09:45 1698408 ----a-w- c:\windows\RtlExUpd.dll
- 2011-12-12 16:20 . 2012-01-30 11:37 100456 ----a-w- c:\windows\system32\RCoInstII64.dll
- 2011-12-09 15:42 . 2012-01-30 11:37 2684416 ----a-w- c:\windows\system32\RCoRes64.dat
- 2011-12-08 16:28 . 2012-01-30 11:37 1969768 ----a-w- c:\windows\system32\RtkApi64.dll
- 2011-12-08 15:27 . 2012-01-30 11:37 3744872 ----a-w- c:\windows\system32\RtkAPO64.dll
- .
- .
- ------- Sigcheck -------
- Note: Unsigned files aren't necessarily malware.
- .
- [7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
- [7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
- [-] 2010-11-20 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
- .
- [7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
- [7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
- [-] 2002-01-01 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
- .
- ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
- REGEDIT4
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "F.lux"="c:\users\Apock\Local Settings\Apps\F.lux\flux.exe" [2009-08-29 966656]
- "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-19 3477312]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
- "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
- Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
- "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
- .
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R3 BS_DEF;BS_DEF;c:\windows\system32\drivers\BS_DEF.sys [x]
- R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
- R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
- R3 tsusbhub;tsusbhub; [x]
- R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-01-31 158856]
- S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
- S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-09-23 86224]
- S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
- S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
- S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
- .
- .
- --- Inne Usługi/Sterowniki w Pamięci ---
- .
- *NewlyCreated* - WS2IFSL
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-12-12 7560296]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Skan uzupełniający -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://www.ask.com/?l=dis&o=102866&gct=hp
- mLocal Page = c:\windows\SysWOW64\blank.htm
- IE: E&ksportuj do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
- FF - ProfilePath - c:\users\Apock\AppData\Roaming\Mozilla\Firefox\Profiles\tm6u7lv3.default\
- FF - prefs.js: browser.startup.homepage - www.onet.pl
- FF - user.js: network.http.max-persistent-connections-per-server - 4
- FF - user.js: nglayout.initialpaint.delay - 600
- FF - user.js: content.notify.interval - 600000
- FF - user.js: content.max.tokenizing.time - 1800000
- FF - user.js: content.switch.threshold - 600000
- .
- .
- --------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ChromeHTML"
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ChromeHTML"
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ChromeHTML"
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ChromeHTML"
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ChromeHTML"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.10"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker4"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Pozostałe uruchomione procesy ------------------------
- .
- c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
- c:\program files\ASUS\GPU Boost Driver\GpuBoostServer.exe
- .
- **************************************************************************
- .
- Czas ukończenia: 2012-03-04 14:20:20 - komputer został uruchomiony ponownie
- ComboFix-quarantined-files.txt 2012-03-04 13:20
- .
- Przed: 115 694 243 840 bajtów wolnych
- Po: 119 142 547 456 bajtów wolnych
- .
- - - End Of File - - 558C67ABC332922481EF217C95385E2F
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement