Advertisement
Guest User

Untitled

a guest
Jul 17th, 2019
78
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 25.81 KB | None | 0 0
  1. ComboFix 18-08-08.01 - zabik 2019-07-17 15:01:40.1.2 - x64
  2. Microsoft Windows 7 Enterprise 6.1.7601.1.1250.48.1045.18.8136.6541 [GMT 2:00]
  3. Uruchomiony z: c:\users\zabik\Downloads\ComboFix.exe
  4. AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
  5. SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
  6. SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
  7. * Utworzono nowy punkt przywracania
  8. .
  9. .
  10. ((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
  11. .
  12. .
  13. C:\END
  14. c:\programdata\1419666011
  15. c:\programdata\ntuser.pol
  16. c:\users\zabik\AppData\Roaming\Microsoft\Windows\Recent\+-HELP-RECOVER-+mdpqw-+.html
  17. c:\users\zabik\AppData\Roaming\Microsoft\Windows\Recent\+-HELP-RECOVER-+mdpqw-+.png
  18. c:\users\zabik\AppData\Roaming\regsvr32.exe_log.txt
  19. c:\windows\SysWow64\sppcomapi.dll.epbzj
  20. c:\windows\SysWow64\systemcpl.dll.epbzj
  21. .
  22. .
  23. ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
  24. .
  25. .
  26. -------\Service_WiseBootAssistant
  27. .
  28. .
  29. ((((((((((((((((((((((((( Pliki utworzone od 2019-06-17 do 2019-07-17 )))))))))))))))))))))))))))))))
  30. .
  31. .
  32. 2019-07-15 15:14 . 2019-07-15 15:14 363400 ----a-w- c:\windows\system32\aswBoot.exe
  33. 2019-07-15 15:14 . 2019-07-15 15:14 225816 ----a-w- c:\windows\system32\drivers\aswStm.sys
  34. 2019-07-15 15:14 . 2019-07-15 15:14 169112 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
  35. 2019-07-09 07:59 . 2019-07-09 08:04 -------- d-----w- c:\users\zabik\AppData\Local\DeadByDaylight
  36. 2019-07-09 07:59 . 2019-07-09 07:59 -------- d-----w- c:\users\zabik\AppData\Roaming\EasyAntiCheat
  37. 2019-06-20 01:28 . 2019-06-20 01:28 -------- d-----w- c:\program files (x86)\Origin
  38. .
  39. .
  40. .
  41. (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
  42. .
  43. 2019-07-15 15:14 . 2018-03-31 17:44 387392 ----a-w- c:\windows\system32\drivers\aswVmm.sys
  44. 2019-07-15 15:14 . 2019-02-14 13:49 279336 ----a-w- c:\windows\system32\drivers\aswHdsKe.sys
  45. 2019-07-15 15:14 . 2018-10-19 19:08 42504 ----a-w- c:\windows\system32\drivers\aswKbd.sys
  46. 2019-07-15 15:14 . 2018-03-31 17:44 88160 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
  47. 2019-07-15 15:14 . 2018-03-31 17:44 477288 ----a-w- c:\windows\system32\drivers\aswSP.sys
  48. 2019-07-15 15:14 . 2018-03-31 17:44 112520 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
  49. 2019-07-15 15:14 . 2019-01-04 09:59 37320 ----a-w- c:\windows\system32\drivers\aswArDisk.sys
  50. 2019-07-15 15:14 . 2018-03-31 17:44 209256 ----a-w- c:\windows\system32\drivers\aswArPot.sys
  51. 2019-07-15 15:14 . 2018-03-31 17:44 1030992 ----a-w- c:\windows\system32\drivers\aswSnx.sys
  52. 2019-07-15 15:14 . 2019-01-14 15:24 263224 ----a-w- c:\windows\system32\drivers\aswbidsdriver.sys
  53. 2019-07-15 15:14 . 2019-01-04 09:59 61688 ----a-w- c:\windows\system32\drivers\aswbuniv.sys
  54. 2019-07-15 15:14 . 2019-01-04 09:59 206056 ----a-w- c:\windows\system32\drivers\aswbidsh.sys
  55. .
  56. .
  57. ------- Sigcheck -------
  58. Note: Unsigned files aren't necessarily malware.
  59. .
  60. [7] 2016-11-10 . 34BA256FBF83457F9D5E51A56DB54542 . 1009152 . . [6.1.7601.23594] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_2b915fa59d5abee0\user32.dll
  61. [7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
  62. [-] 2016-11-10 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
  63. .
  64. [-] 2018-02-19 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
  65. [7] 2016-11-10 . 3CB074875AC88A7C1010A2A7F9881A8C . 833024 . . [6.1.7601.23594] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_35e609f7d1bb80db\user32.dll
  66. [7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
  67. .
  68. ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
  69. .
  70. .
  71. *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
  72. REGEDIT4
  73. .
  74. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  75. "Steam"="f:\gry\Steam\steam.exe" [2019-07-16 3210016]
  76. "Discord"="c:\users\zabik\AppData\Local\Discord\app-0.0.305\Discord.exe" [2019-03-07 81780056]
  77. "WiseReminder"="c:\program files (x86)\Wise\Wise Reminder\WiseReminder.exe" [2018-12-17 3641512]
  78. .
  79. [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
  80. "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2017-06-07 456328]
  81. "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2018-10-06 601424]
  82. .
  83. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
  84. "ConsentPromptBehaviorAdmin"= 0 (0x0)
  85. "ConsentPromptBehaviorUser"= 3 (0x3)
  86. "EnableLUA"= 0 (0x0)
  87. "EnableUIADesktopToggle"= 0 (0x0)
  88. "PromptOnSecureDesktop"= 0 (0x0)
  89. "SoftwareSASGeneration"= 1 (0x1)
  90. "EnableLinkedConnections"= 1 (0x1)
  91. .
  92. [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
  93. "NoSimpleNetIDList"= 1 (0x1)
  94. .
  95. R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
  96. R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
  97. R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
  98. R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
  99. R3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [x]
  100. R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
  101. R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;f:\gry\1 Programy do gier\Deamon tools\DAEMON Tools Lite\DiscSoftBusServiceLite.exe;f:\gry\1 Programy do gier\Deamon tools\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [x]
  102. R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
  103. R3 EasyAntiCheat;EasyAntiCheat;c:\program files (x86)\EasyAntiCheat\EasyAntiCheat.exe;c:\program files (x86)\EasyAntiCheat\EasyAntiCheat.exe [x]
  104. R3 GoogleChromeElevationService;Google Chrome Elevation Service;c:\program files (x86)\Google\Chrome\Application\75.0.3770.142\elevation_service.exe;c:\program files (x86)\Google\Chrome\Application\75.0.3770.142\elevation_service.exe [x]
  105. R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
  106. R3 INETMON;INETMON;c:\windows\System32\Drivers\INETMON.sys;c:\windows\SYSNATIVE\Drivers\INETMON.sys [x]
  107. R3 IntcDAud;Audio dla wyświetlaczy Intel(R);c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
  108. R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
  109. R3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD.sys [x]
  110. R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys;c:\windows\SYSNATIVE\Drivers\IT9135BDA.sys [x]
  111. R3 mracdrv;MRAC Driver;c:\windows\System32\drivers\mracdrv.sys;c:\windows\SYSNATIVE\drivers\mracdrv.sys [x]
  112. R3 mracsvc;MRAC Service;c:\windows\System32\mracsvc.exe;c:\windows\SYSNATIVE\mracsvc.exe [x]
  113. R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
  114. R3 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
  115. R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
  116. R3 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x]
  117. R3 NvStreamKms;NVIDIA KMS;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
  118. R3 NvTelemetryContainer;NVIDIA Telemetry Container;c:\program files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe;c:\program files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [x]
  119. R3 Origin Client Service;Origin Client Service;f:\gry\Apex\Origin\OriginClientService.exe;f:\gry\Apex\Origin\OriginClientService.exe [x]
  120. R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
  121. R3 Ph3xIB64;Philips 713x Inbox PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB64.sys;c:\windows\SYSNATIVE\DRIVERS\Ph3xIB64.sys [x]
  122. R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
  123. R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
  124. R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
  125. R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
  126. R3 RTL2832U_IRHID;HID Infrared Remote Receiver;c:\windows\system32\DRIVERS\RTL2832U_IRHID.sys;c:\windows\SYSNATIVE\DRIVERS\RTL2832U_IRHID.sys [x]
  127. R3 RTL2832UBDA;REALTEK 2832U BDA Driver;c:\windows\system32\drivers\RTL2832UBDA.sys;c:\windows\SYSNATIVE\drivers\RTL2832UBDA.sys [x]
  128. R3 RTL2832UUSB;REALTEK 2832U USB Driver;c:\windows\system32\Drivers\RTL2832UUSB.sys;c:\windows\SYSNATIVE\Drivers\RTL2832UUSB.sys [x]
  129. R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys;c:\windows\SYSNATIVE\DRIVERS\sis163u.sys [x]
  130. R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
  131. R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
  132. R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
  133. R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
  134. R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
  135. R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
  136. R3 VOICEMOD_Driver;Voicemod Virtual Audio Device (WDM);c:\windows\system32\drivers\vmdrv.sys;c:\windows\SYSNATIVE\drivers\vmdrv.sys [x]
  137. R3 WiseHDInfo;WiseHDInfo;c:\windows\WiseHDInfo64.dll;c:\windows\WiseHDInfo64.dll [x]
  138. R3 WiseUnlock;WiseUnlock;c:\windows\WiseUnlock64.sys;c:\windows\WiseUnlock64.sys [x]
  139. R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x]
  140. R4 BRSptStub;BitRaider Mini-Support Service Stub Loader;c:\programdata\BitRaider\BRSptStub.exe;c:\programdata\BitRaider\BRSptStub.exe [x]
  141. R4 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
  142. R4 iumsvc;Intel(R) Update Manager;c:\program files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe;c:\program files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [x]
  143. R4 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
  144. S0 aswArDisk;aswArDisk;c:\windows\system32\drivers\aswArDisk.sys;c:\windows\SYSNATIVE\drivers\aswArDisk.sys [x]
  145. S0 aswbidsh;aswbidsh;c:\windows\system32\drivers\aswbidsh.sys;c:\windows\SYSNATIVE\drivers\aswbidsh.sys [x]
  146. S0 aswbuniv;aswbuniv;c:\windows\system32\drivers\aswbuniv.sys;c:\windows\SYSNATIVE\drivers\aswbuniv.sys [x]
  147. S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys;c:\windows\SYSNATIVE\drivers\aswRvrt.sys [x]
  148. S0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys;c:\windows\SYSNATIVE\drivers\aswVmm.sys [x]
  149. S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
  150. S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
  151. S0 iusb3hcs;Sterownik przełącznika kontrolera hosta Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
  152. S1 aswArPot;aswArPot;c:\windows\system32\drivers\aswArPot.sys;c:\windows\SYSNATIVE\drivers\aswArPot.sys [x]
  153. S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdriver.sys;c:\windows\SYSNATIVE\drivers\aswbidsdriver.sys [x]
  154. S1 aswHdsKe;aswHdsKe;c:\windows\system32\drivers\aswHdsKe.sys;c:\windows\SYSNATIVE\drivers\aswHdsKe.sys [x]
  155. S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
  156. S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
  157. S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
  158. S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
  159. S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO64A.SYS;c:\windows\SYSNATIVE\drivers\HWiNFO64A.SYS [x]
  160. S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
  161. S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
  162. S2 Origin Web Helper Service;Origin Web Helper Service;f:\gry\Apex\Origin\OriginWebHelperService.exe;f:\gry\Apex\Origin\OriginWebHelperService.exe [x]
  163. S2 WinI2C-DDC;WinI2C-DDC Kernel Mode Driver;c:\windows\system32\drivers\DDCDrv.sys;c:\windows\SYSNATIVE\drivers\DDCDrv.sys [x]
  164. S3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\aswidsagent.exe;c:\program files\AVAST Software\Avast\aswidsagent.exe [x]
  165. S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
  166. S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus;c:\windows\system32\DRIVERS\dtliteusbbus.sys;c:\windows\SYSNATIVE\DRIVERS\dtliteusbbus.sys [x]
  167. S3 iusb3hub;Sterownik koncentratora Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
  168. S3 iusb3xhc;Sterownik kontrolera hosta Intel(R) USB 3.0 eXtensible;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
  169. S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
  170. S3 nvvhci;NVVHCI Enumerator Service;c:\windows\system32\DRIVERS\nvvhci.sys;c:\windows\SYSNATIVE\DRIVERS\nvvhci.sys [x]
  171. S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
  172. S3 XtuAcpiDriver;Intel(R) Extreme Tuning Utility Device Service;c:\windows\system32\DRIVERS\XtuAcpiDriver.sys;c:\windows\SYSNATIVE\DRIVERS\XtuAcpiDriver.sys [x]
  173. .
  174. .
  175. --- Inne Usługi/Sterowniki w Pamięci ---
  176. .
  177. *NewlyCreated* - WS2IFSL
  178. .
  179. Zawartość folderu 'Zaplanowane zadania'
  180. .
  181. 2016-03-23 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX1000_exe.job
  182. - c:\windows\vVX1000.exe [2010-05-20 13:26]
  183. .
  184. 2019-05-16 c:\windows\Tasks\Wise Care 365.job
  185. - c:\program files (x86)\Wise\Wise Care 365\WiseTray.exe [2019-03-10 13:06]
  186. .
  187. 2019-03-21 c:\windows\Tasks\Wise Turbo Checker.job
  188. - c:\program files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2019-03-10 15:52]
  189. .
  190. .
  191. --------- X64 Entries -----------
  192. .
  193. .
  194. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
  195. @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
  196. [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
  197. 2012-10-01 18:47 2322576 ----a-w- c:\progra~1\Microsoft Office\Office15\GROOVEEX.DLL
  198. .
  199. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
  200. @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
  201. [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
  202. 2012-10-01 18:47 2322576 ----a-w- c:\progra~1\Microsoft Office\Office15\GROOVEEX.DLL
  203. .
  204. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
  205. @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
  206. [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
  207. 2012-10-01 18:47 2322576 ----a-w- c:\progra~1\Microsoft Office\Office15\GROOVEEX.DLL
  208. .
  209. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
  210. @="{472083B0-C522-11CF-8763-00608CC02F24}"
  211. .
  212. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
  213. @="{472083B0-C522-11CF-8763-00608CC02F24}"
  214. [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
  215. 2019-07-15 15:14 1769864 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
  216. .
  217. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
  218. @="{472083B0-C522-11CF-8763-00608CC02F24}"
  219. .
  220. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
  221. @="{472083B0-C522-11CF-8763-00608CC02F24}"
  222. [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
  223. 2019-07-15 15:14 1769864 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
  224. .
  225. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  226. "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2017-07-19 1903040]
  227. "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2019-07-15 269192]
  228. .
  229. ------- Skan uzupełniający -------
  230. .
  231. uLocal Page = c:\windows\system32\blank.htm
  232. uStart Page = https://search.yahoo.com/?fr=vmn&type=auslog_ya_hp
  233. mLocal Page = c:\windows\SysWOW64\blank.htm
  234. IE: E&ksportuj do programu Microsoft Excel - f:\gry\PowerPoint\Office15\EXCEL.EXE/3000
  235. IE: Wyślij &do programu OneNote - f:\gry\PowerPoint\Office15\ONBttnIE.dll/105
  236. Trusted Zone: dell.com
  237. TCP: DhcpNameServer = 130.140.1.2
  238. DPF: {444785F1-DE89-4295-863A-D46C3A781394} - hxxp://webplayer.unity3d.com/download_webplayer/UnityWebPlayer.cab
  239. .
  240. - - - - USUNIĘTO PUSTE WPISY - - - -
  241. .
  242. ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
  243. ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
  244. ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
  245. HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe
  246. ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
  247. ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
  248. ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
  249. AddRemove-ZLOrigin_is1 - f:\gry\Sims 4\Nowy folder\ZLOrigin\unins000.exe
  250. .
  251. .
  252. .
  253. [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
  254. "ImagePath"="c:\windows\system32\GameMon.des -service"
  255. .
  256. --------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
  257. .
  258. [HKEY_USERS\S-1-5-21-4291168581-1618026530-1807886344-1000\Software\SecuROM\License information*]
  259. "datasecu"=hex:cf,d0,02,b9,23,a2,3b,03,9d,14,0c,ef,12,0e,da,0b,9f,6f,26,33,cd,
  260. 25,93,cd,3f,e5,5a,5a,8f,09,59,9f,1d,60,8a,b3,9f,74,13,c9,f2,06,c7,8a,bb,fe,\
  261. "rkeysecu"=hex:83,f3,98,7e,3f,d0,0c,3e,e4,70,bf,a8,5c,25,8f,b1
  262. .
  263. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
  264. @Denied: (A 2) (Everyone)
  265. @="FlashBroker"
  266. "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_101_ActiveX.exe,-101"
  267. .
  268. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
  269. "Enabled"=dword:00000001
  270. .
  271. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
  272. @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_32_0_0_101_ActiveX.exe"
  273. .
  274. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
  275. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  276. .
  277. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
  278. @Denied: (A 2) (Everyone)
  279. @="IFlashBroker6"
  280. .
  281. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
  282. @="{00020424-0000-0000-C000-000000000046}"
  283. .
  284. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
  285. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  286. "Version"="1.0"
  287. .
  288. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
  289. @Denied: (A 2) (Everyone)
  290. @="FlashBroker"
  291. "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_101_ActiveX.exe,-101"
  292. .
  293. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
  294. "Enabled"=dword:00000001
  295. .
  296. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
  297. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_32_0_0_101_ActiveX.exe"
  298. .
  299. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
  300. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  301. .
  302. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
  303. @Denied: (A 2) (Everyone)
  304. @="Shockwave Flash Object"
  305. .
  306. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
  307. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_101.ocx"
  308. "ThreadingModel"="Apartment"
  309. .
  310. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
  311. @="0"
  312. .
  313. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
  314. @="ShockwaveFlash.ShockwaveFlash.32"
  315. .
  316. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
  317. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_101.ocx, 1"
  318. .
  319. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
  320. @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
  321. .
  322. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
  323. @="1.0"
  324. .
  325. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
  326. @="ShockwaveFlash.ShockwaveFlash"
  327. .
  328. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
  329. @Denied: (A 2) (Everyone)
  330. @="Macromedia Flash Factory Object"
  331. .
  332. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
  333. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_101.ocx"
  334. "ThreadingModel"="Apartment"
  335. .
  336. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
  337. @="FlashFactory.FlashFactory.1"
  338. .
  339. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
  340. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_32_0_0_101.ocx, 1"
  341. .
  342. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
  343. @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
  344. .
  345. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
  346. @="1.0"
  347. .
  348. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
  349. @="FlashFactory.FlashFactory"
  350. .
  351. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
  352. @Denied: (A 2) (Everyone)
  353. @="IFlashBroker6"
  354. .
  355. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
  356. @="{00020424-0000-0000-C000-000000000046}"
  357. .
  358. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
  359. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  360. "Version"="1.0"
  361. .
  362. [HKEY_LOCAL_MACHINE\software\Wow6432Node\AVAST Software]
  363. "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  364. 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
  365. .
  366. [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
  367. @Denied: (A) (Everyone)
  368. "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
  369. .
  370. [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
  371. @Denied: (A) (Everyone)
  372. .
  373. [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
  374. "Key"="ActionsPane3"
  375. "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
  376. .
  377. [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
  378. @Denied: (Full) (Everyone)
  379. .
  380. Czas ukończenia: 2019-07-17 15:12:09 - komputer został uruchomiony ponownie
  381. ComboFix-quarantined-files.txt 2019-07-17 13:12
  382. .
  383. Przed: 29 902 020 608 bajtów wolnych
  384. Po: 30 370 570 240 bajtów wolnych
  385. .
  386. - - End Of File - - 431A46FB1A997262095DCEEEF7D8E65E
  387. 32052574BF9F325AE309ABC7BFD04460
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement