Hello i recently have this popup problem with google chrome. I have nod32 antyvirus installed and working non stop, i've scanned with Malwarebytes' Anti-Malware in didn't show anything. I've deleted the cookies and still nothing changes. I'm pasting logs from asMBR and combofix below. Pls help.
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-28 13:14:54
-----------------------------
13:14:54.747 OS Version: Windows x64 6.1.7600
13:14:54.747 Number of processors: 4 586 0x403
13:14:54.748 ComputerName: IZDEB-PC UserName: Izdeb
13:14:57.331 Initialize success
13:15:17.873 AVAST engine defs: 12022801
13:15:23.959 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
13:15:23.961 Disk 0 Vendor: ST31000528AS CC38 Size: 953868MB BusType: 3
13:15:23.969 Disk 0 MBR read successfully
13:15:23.971 Disk 0 MBR scan
13:15:23.975 Disk 0 Windows 7 default MBR code
13:15:23.984 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
13:15:23.997 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 99899 MB offset 206848
13:15:24.016 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 400000 MB offset 204800000
13:15:24.039 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 453867 MB offset 1024000000
13:15:24.072 Disk 0 scanning C:\Windows\system32\drivers
13:15:36.281 Service scanning
13:15:55.735 Modules scanning
13:15:55.753 Disk 0 trace - called modules:
13:15:55.778 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80046f32c0]<<spmp.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
13:15:55.789 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a70060]
13:15:55.800 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa800494c9b0]
13:15:55.811 5 ACPI.sys[fffff880011b3781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004a5c060]
13:15:55.816 \Driver\atapi[0xfffffa8004788e70] -> IRP_MJ_CREATE -> 0xfffffa80046f32c0
13:15:56.645 AVAST engine scan C:\Windows
13:15:59.108 AVAST engine scan C:\Windows\system32
13:20:03.638 AVAST engine scan C:\Windows\system32\drivers
13:20:33.021 AVAST engine scan C:\Users\Izdeb
13:22:39.598 AVAST engine scan C:\ProgramData
13:24:37.522 Scan finished successfully
13:27:48.616 Disk 0 MBR has been saved successfully to "C:\Users\Izdeb\Desktop\MBR.dat"
13:27:48.621 The log file has been saved successfully to "C:\Users\Izdeb\Desktop\aswMBR.txt"
ComboFix 12-02-27.02 - Izdeb 2012-02-28 13:39:27.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.48.1033.18.4095.2720 [GMT 1:00]
Uruchomiony z: c:\users\Izdeb\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Utworzono nowy punkt przywracania
.
.
((((((((((((((((((((((((( Pliki utworzone od 2012-01-28 do 2012-02-28 )))))))))))))))))))))))))))))))
.
.
2012-02-28 12:42 . 2012-02-28 12:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-28 08:24 . 2012-02-28 08:24 -------- d-----w- c:\users\Izdeb\AppData\Roaming\Malwarebytes
2012-02-25 18:52 . 2012-02-25 18:52 -------- d-----w- c:\windows\Sun
2012-02-22 19:40 . 2012-02-22 19:40 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-02-15 20:13 . 2012-02-15 20:13 -------- d-----w- c:\users\Izdeb\AppData\Roaming\U3
2012-02-15 15:14 . 2012-02-19 18:47 -------- d-----w- c:\programdata\EA Logs
2012-02-15 15:08 . 2012-02-15 15:08 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-02-15 15:08 . 2012-02-15 15:08 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-02-04 16:09 . 2012-02-04 16:09 -------- d-----w- c:\users\Izdeb\AppData\Roaming\BigHugeEngine
2012-02-03 15:25 . 2012-02-03 15:25 -------- d-----w- c:\windows\system32\appmgmt
2012-02-02 18:32 . 2012-02-02 18:32 -------- d-----w- c:\users\Izdeb\AppData\Local\ESET
2012-02-01 16:59 . 2012-02-01 16:59 -------- d-----w- c:\programdata\LightScribe
2012-02-01 16:59 . 2012-02-01 17:09 -------- d-----w- c:\users\Izdeb\AppData\Roaming\Nero
2012-02-01 16:58 . 2012-02-01 16:58 -------- d-----w- c:\program files (x86)\Common Files\Nero
2012-02-01 16:58 . 2012-02-01 16:58 -------- d-----w- c:\program files (x86)\Nero
2012-02-01 16:58 . 2012-02-01 16:58 -------- d-----w- c:\programdata\Nero
2012-01-31 18:51 . 2012-01-31 18:51 -------- d-----w- c:\users\Izdeb\AppData\Roaming\LolClient
2012-01-31 18:37 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-31 18:37 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-31 18:37 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-31 16:55 . 2012-01-31 16:55 -------- d-----w- c:\program files\7-Zip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-27 19:24 . 2011-12-28 19:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-02-27 19:24 . 2011-12-28 18:57 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-02-27 19:23 . 2011-12-28 18:57 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-02-19 16:49 . 2011-12-28 18:57 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-01-05 15:24 . 2011-12-29 15:59 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-29 16:04 . 2011-12-29 16:04 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-12-13 20:02 . 2011-12-14 15:37 115216 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2011-12-13 20:02 . 2011-12-14 15:37 58880 ----a-w- c:\windows\system32\coinst.dll
2011-12-13 20:02 . 2011-12-14 15:37 40448 ----a-w- c:\windows\system32\atiuxp64.dll
2011-12-13 20:02 . 2011-12-14 15:37 3631104 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-12-13 20:02 . 2011-12-14 15:37 31232 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2011-12-13 20:02 . 2011-12-14 15:37 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-12-13 20:02 . 2011-12-14 15:37 1912832 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2011-12-13 20:02 . 2011-12-14 15:37 4246016 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-12-13 20:02 . 2011-12-14 15:37 3420672 ----a-w- c:\windows\system32\atiumd6a.dll
2011-12-13 20:02 . 2011-12-14 15:37 1208320 ----a-w- c:\windows\system32\atiumd6v.dll
2011-12-13 20:02 . 2011-12-14 15:37 5395968 ----a-w- c:\windows\system32\atiumd64.dll
2011-12-13 20:02 . 2011-12-14 15:37 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-12-13 20:02 . 2011-12-14 15:37 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-12-13 20:02 . 2011-12-14 15:37 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-12-13 20:02 . 2011-12-14 15:37 17469952 ----a-w- c:\windows\SysWow64\atioglxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 120320 ----a-w- c:\windows\system32\atitmm64.dll
2011-12-13 20:02 . 2011-12-14 15:37 332800 ----a-w- c:\windows\system32\ATIODE.exe
2011-12-13 20:02 . 2011-12-14 15:37 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
2011-12-13 20:02 . 2011-12-14 15:37 22623232 ----a-w- c:\windows\system32\atio6axx.dll
2011-12-13 20:02 . 2011-12-14 15:37 53760 ----a-w- c:\windows\system32\atimpc64.dll
2011-12-13 20:02 . 2011-12-14 15:37 53760 ----a-w- c:\windows\system32\amdpcom64.dll
2011-12-13 20:02 . 2011-12-14 15:37 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
2011-12-13 20:02 . 2011-12-14 15:37 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2011-12-13 20:02 . 2011-12-14 15:37 303616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2011-12-13 20:02 . 2011-12-14 15:37 16384 ----a-w- c:\windows\system32\atimuixx.dll
2011-12-13 20:02 . 2011-12-14 15:37 9319424 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-12-13 20:02 . 2011-12-14 15:37 59392 ----a-w- c:\windows\system32\atiedu64.dll
2011-12-13 20:02 . 2011-12-14 15:37 5080576 ----a-w- c:\windows\system32\atidxx64.dll
2011-12-13 20:02 . 2011-12-14 15:37 480256 ----a-w- c:\windows\system32\atieclxx.exe
2011-12-13 20:02 . 2011-12-14 15:37 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-12-13 20:02 . 2011-12-14 15:37 32768 ----a-w- c:\windows\SysWow64\atigktxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 203776 ----a-w- c:\windows\system32\atiesrxx.exe
2011-12-13 20:02 . 2011-12-14 15:37 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 788480 ----a-w- c:\windows\system32\aticfx64.dll
2011-12-13 20:02 . 2011-12-14 15:37 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-12-13 20:02 . 2011-12-14 15:37 4304896 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-12-13 20:02 . 2011-12-14 15:37 7467008 ----a-w- c:\windows\system32\aticaldd64.dll
2011-12-13 20:02 . 2011-12-14 15:37 671744 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-12-13 20:02 . 2011-12-14 15:37 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2011-12-13 20:02 . 2011-12-14 15:37 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-12-13 20:02 . 2011-12-14 15:37 6098432 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-12-13 20:02 . 2011-12-14 15:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-12-13 20:02 . 2011-12-14 15:37 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2011-12-13 20:02 . 2011-12-14 15:37 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-12-13 20:02 . 2011-12-14 15:37 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 361984 ----a-w- c:\windows\system32\atiadlxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 258048 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-12-13 20:02 . 2011-12-14 15:37 147456 ----a-w- c:\windows\system32\atiapfxx.exe
2011-12-13 20:02 . 2011-12-14 15:37 118784 ----a-w- c:\windows\system32\atibtmon.exe
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-02-22 740216]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-04-27 336384]
"DeathAdder"="c:\program files (x86)\Razer\DeathAdder\razerhid.exe" [2011-03-21 248320]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Spik"="c:\program files (x86)\Spik\Spik.exe" [2011-06-07 109424]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-04-27 365568]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]
.
.
--- Inne Usługi/Sterowniki w Pamięci ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-12-28 2918656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Skan uzupełniający -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.1.1.1 153.13.250.100
Handler: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - c:\program files (x86)\Spik\url_wpmsg.dll
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
.
.
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:00000000
"ProductBase"=dword:00000000
"ProductCode"="{50E9E32F-063A-412A-9627-553D5DA57C17}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.71.2"
"UniqueId"="0003BE6E4EFB470D"
"ScannerBuild"=dword:00001dd3
"ScannerVersionId"=dword:000015fe
"ScannerVersion"="ready"
"ei2"=hex(b):33,fd,47,8e,0f,39,39,ed
"ei1"=hex(b):20,cf,30,f5,53,cc,00,00
"ei3"=hex(b):da,48,fb,4e,00,00,00,00
"ei4"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\ASUS\GPU Boost Driver\GpuBoostServer.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Razer\DeathAdder\razertra.exe
c:\program files (x86)\Razer\DeathAdder\razerofa.exe
c:\program files (x86)\Razer\DeathAdder\vdDaemon.exe
.
**************************************************************************
.
Czas ukończenia: 2012-02-28 13:47:25 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2012-02-28 12:47
.
Przed: 48*501*235*712 bajtów wolnych
Po: 57*781*932*032 bajtów wolnych
.
- - End Of File - - 3DCD4AFE05009654E40AB506AFF3BFC6
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-28 13:14:54
-----------------------------
13:14:54.747 OS Version: Windows x64 6.1.7600
13:14:54.747 Number of processors: 4 586 0x403
13:14:54.748 ComputerName: IZDEB-PC UserName: Izdeb
13:14:57.331 Initialize success
13:15:17.873 AVAST engine defs: 12022801
13:15:23.959 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
13:15:23.961 Disk 0 Vendor: ST31000528AS CC38 Size: 953868MB BusType: 3
13:15:23.969 Disk 0 MBR read successfully
13:15:23.971 Disk 0 MBR scan
13:15:23.975 Disk 0 Windows 7 default MBR code
13:15:23.984 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
13:15:23.997 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 99899 MB offset 206848
13:15:24.016 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 400000 MB offset 204800000
13:15:24.039 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 453867 MB offset 1024000000
13:15:24.072 Disk 0 scanning C:\Windows\system32\drivers
13:15:36.281 Service scanning
13:15:55.735 Modules scanning
13:15:55.753 Disk 0 trace - called modules:
13:15:55.778 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80046f32c0]<<spmp.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
13:15:55.789 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a70060]
13:15:55.800 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa800494c9b0]
13:15:55.811 5 ACPI.sys[fffff880011b3781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004a5c060]
13:15:55.816 \Driver\atapi[0xfffffa8004788e70] -> IRP_MJ_CREATE -> 0xfffffa80046f32c0
13:15:56.645 AVAST engine scan C:\Windows
13:15:59.108 AVAST engine scan C:\Windows\system32
13:20:03.638 AVAST engine scan C:\Windows\system32\drivers
13:20:33.021 AVAST engine scan C:\Users\Izdeb
13:22:39.598 AVAST engine scan C:\ProgramData
13:24:37.522 Scan finished successfully
13:27:48.616 Disk 0 MBR has been saved successfully to "C:\Users\Izdeb\Desktop\MBR.dat"
13:27:48.621 The log file has been saved successfully to "C:\Users\Izdeb\Desktop\aswMBR.txt"
ComboFix 12-02-27.02 - Izdeb 2012-02-28 13:39:27.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.48.1033.18.4095.2720 [GMT 1:00]
Uruchomiony z: c:\users\Izdeb\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Utworzono nowy punkt przywracania
.
.
((((((((((((((((((((((((( Pliki utworzone od 2012-01-28 do 2012-02-28 )))))))))))))))))))))))))))))))
.
.
2012-02-28 12:42 . 2012-02-28 12:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-28 08:24 . 2012-02-28 08:24 -------- d-----w- c:\users\Izdeb\AppData\Roaming\Malwarebytes
2012-02-25 18:52 . 2012-02-25 18:52 -------- d-----w- c:\windows\Sun
2012-02-22 19:40 . 2012-02-22 19:40 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-02-15 20:13 . 2012-02-15 20:13 -------- d-----w- c:\users\Izdeb\AppData\Roaming\U3
2012-02-15 15:14 . 2012-02-19 18:47 -------- d-----w- c:\programdata\EA Logs
2012-02-15 15:08 . 2012-02-15 15:08 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-02-15 15:08 . 2012-02-15 15:08 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-02-04 16:09 . 2012-02-04 16:09 -------- d-----w- c:\users\Izdeb\AppData\Roaming\BigHugeEngine
2012-02-03 15:25 . 2012-02-03 15:25 -------- d-----w- c:\windows\system32\appmgmt
2012-02-02 18:32 . 2012-02-02 18:32 -------- d-----w- c:\users\Izdeb\AppData\Local\ESET
2012-02-01 16:59 . 2012-02-01 16:59 -------- d-----w- c:\programdata\LightScribe
2012-02-01 16:59 . 2012-02-01 17:09 -------- d-----w- c:\users\Izdeb\AppData\Roaming\Nero
2012-02-01 16:58 . 2012-02-01 16:58 -------- d-----w- c:\program files (x86)\Common Files\Nero
2012-02-01 16:58 . 2012-02-01 16:58 -------- d-----w- c:\program files (x86)\Nero
2012-02-01 16:58 . 2012-02-01 16:58 -------- d-----w- c:\programdata\Nero
2012-01-31 18:51 . 2012-01-31 18:51 -------- d-----w- c:\users\Izdeb\AppData\Roaming\LolClient
2012-01-31 18:37 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-31 18:37 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-31 18:37 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-31 16:55 . 2012-01-31 16:55 -------- d-----w- c:\program files\7-Zip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-27 19:24 . 2011-12-28 19:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-02-27 19:24 . 2011-12-28 18:57 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-02-27 19:23 . 2011-12-28 18:57 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-02-19 16:49 . 2011-12-28 18:57 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-01-05 15:24 . 2011-12-29 15:59 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-29 16:04 . 2011-12-29 16:04 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-12-13 20:02 . 2011-12-14 15:37 115216 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2011-12-13 20:02 . 2011-12-14 15:37 58880 ----a-w- c:\windows\system32\coinst.dll
2011-12-13 20:02 . 2011-12-14 15:37 40448 ----a-w- c:\windows\system32\atiuxp64.dll
2011-12-13 20:02 . 2011-12-14 15:37 3631104 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-12-13 20:02 . 2011-12-14 15:37 31232 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2011-12-13 20:02 . 2011-12-14 15:37 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-12-13 20:02 . 2011-12-14 15:37 1912832 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2011-12-13 20:02 . 2011-12-14 15:37 4246016 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-12-13 20:02 . 2011-12-14 15:37 3420672 ----a-w- c:\windows\system32\atiumd6a.dll
2011-12-13 20:02 . 2011-12-14 15:37 1208320 ----a-w- c:\windows\system32\atiumd6v.dll
2011-12-13 20:02 . 2011-12-14 15:37 5395968 ----a-w- c:\windows\system32\atiumd64.dll
2011-12-13 20:02 . 2011-12-14 15:37 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-12-13 20:02 . 2011-12-14 15:37 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-12-13 20:02 . 2011-12-14 15:37 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-12-13 20:02 . 2011-12-14 15:37 17469952 ----a-w- c:\windows\SysWow64\atioglxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 120320 ----a-w- c:\windows\system32\atitmm64.dll
2011-12-13 20:02 . 2011-12-14 15:37 332800 ----a-w- c:\windows\system32\ATIODE.exe
2011-12-13 20:02 . 2011-12-14 15:37 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
2011-12-13 20:02 . 2011-12-14 15:37 22623232 ----a-w- c:\windows\system32\atio6axx.dll
2011-12-13 20:02 . 2011-12-14 15:37 53760 ----a-w- c:\windows\system32\atimpc64.dll
2011-12-13 20:02 . 2011-12-14 15:37 53760 ----a-w- c:\windows\system32\amdpcom64.dll
2011-12-13 20:02 . 2011-12-14 15:37 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
2011-12-13 20:02 . 2011-12-14 15:37 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2011-12-13 20:02 . 2011-12-14 15:37 303616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2011-12-13 20:02 . 2011-12-14 15:37 16384 ----a-w- c:\windows\system32\atimuixx.dll
2011-12-13 20:02 . 2011-12-14 15:37 9319424 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-12-13 20:02 . 2011-12-14 15:37 59392 ----a-w- c:\windows\system32\atiedu64.dll
2011-12-13 20:02 . 2011-12-14 15:37 5080576 ----a-w- c:\windows\system32\atidxx64.dll
2011-12-13 20:02 . 2011-12-14 15:37 480256 ----a-w- c:\windows\system32\atieclxx.exe
2011-12-13 20:02 . 2011-12-14 15:37 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-12-13 20:02 . 2011-12-14 15:37 32768 ----a-w- c:\windows\SysWow64\atigktxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 203776 ----a-w- c:\windows\system32\atiesrxx.exe
2011-12-13 20:02 . 2011-12-14 15:37 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 788480 ----a-w- c:\windows\system32\aticfx64.dll
2011-12-13 20:02 . 2011-12-14 15:37 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-12-13 20:02 . 2011-12-14 15:37 4304896 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-12-13 20:02 . 2011-12-14 15:37 7467008 ----a-w- c:\windows\system32\aticaldd64.dll
2011-12-13 20:02 . 2011-12-14 15:37 671744 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-12-13 20:02 . 2011-12-14 15:37 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2011-12-13 20:02 . 2011-12-14 15:37 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-12-13 20:02 . 2011-12-14 15:37 6098432 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-12-13 20:02 . 2011-12-14 15:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-12-13 20:02 . 2011-12-14 15:37 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2011-12-13 20:02 . 2011-12-14 15:37 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-12-13 20:02 . 2011-12-14 15:37 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 361984 ----a-w- c:\windows\system32\atiadlxx.dll
2011-12-13 20:02 . 2011-12-14 15:37 258048 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-12-13 20:02 . 2011-12-14 15:37 147456 ----a-w- c:\windows\system32\atiapfxx.exe
2011-12-13 20:02 . 2011-12-14 15:37 118784 ----a-w- c:\windows\system32\atibtmon.exe
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-02-22 740216]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-04-27 336384]
"DeathAdder"="c:\program files (x86)\Razer\DeathAdder\razerhid.exe" [2011-03-21 248320]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Spik"="c:\program files (x86)\Spik\Spik.exe" [2011-06-07 109424]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-04-27 365568]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]
.
.
--- Inne Usługi/Sterowniki w Pamięci ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-12-28 2918656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Skan uzupełniający -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.1.1.1 153.13.250.100
Handler: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - c:\program files (x86)\Spik\url_wpmsg.dll
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
.
.
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:00000000
"ProductBase"=dword:00000000
"ProductCode"="{50E9E32F-063A-412A-9627-553D5DA57C17}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.71.2"
"UniqueId"="0003BE6E4EFB470D"
"ScannerBuild"=dword:00001dd3
"ScannerVersionId"=dword:000015fe
"ScannerVersion"="ready"
"ei2"=hex(b):33,fd,47,8e,0f,39,39,ed
"ei1"=hex(b):20,cf,30,f5,53,cc,00,00
"ei3"=hex(b):da,48,fb,4e,00,00,00,00
"ei4"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\ASUS\GPU Boost Driver\GpuBoostServer.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Razer\DeathAdder\razertra.exe
c:\program files (x86)\Razer\DeathAdder\razerofa.exe
c:\program files (x86)\Razer\DeathAdder\vdDaemon.exe
.
**************************************************************************
.
Czas ukończenia: 2012-02-28 13:47:25 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2012-02-28 12:47
.
Przed: 48*501*235*712 bajtów wolnych
Po: 57*781*932*032 bajtów wolnych
.
- - End Of File - - 3DCD4AFE05009654E40AB506AFF3BFC6