HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKU\S-1-5-21-1726508243-1813789817-3071424114-1000\...\Run: [Olmlics] => regsvr32.exe C:\Users\WhiteFrost\AppData\Local\Olmlics\WEBAPPDBG.DLL <===== UWAGA
C:\Users\WhiteFrost\AppData\Local\Olmlics
HKU\S-1-5-21-1726508243-1813789817-3071424114-1000\...\Run: [Ijvqsoft] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\WhiteFrost\AppData\Local\Ebrtion\nTrust.dll
C:\Users\WhiteFrost\AppData\Local\Ebrtion
ShellIconOverlayIdentifiers: [1SecureIconsProvider]
{FC9D8189-520A-4417-AED7-9EAC810C6FBA} => Brak pliku
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-1726508243-1813789817-3071424114-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aqovd.com?oem=sunadplv3&uid=6VETRJ84_ST9500325AS&tm=1443690727
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.aqovd.com?oem=sunadplv3&uid=6VETRJ84_ST9500325AS&tm=1443690727
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aqovd.com?oem=sunadplv3&uid=6VETRJ84_ST9500325AS&tm=1443690727
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aqovd.com?oem=sunadplv3&uid=6VETRJ84_ST9500325AS&tm=1443690727
HKU\S-1-5-21-1726508243-1813789817-3071424114-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aqovd.com?oem=sunadplv3&uid=6VETRJ84_ST9500325AS&tm=1443690727
HKU\S-1-5-21-1726508243-1813789817-3071424114-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aqovd.com?oem=sunadplv3&uid=6VETRJ84_ST9500325AS&tm=1443690727
SearchScopes: HKU\S-1-5-21-1726508243-1813789817-3071424114-1000
{E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
S3 andnetadb; System32\Drivers\lgandnetadb.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
Task: {42E16E3F-B7E8-423C-AA0C-5BD5A26FA7C7} - System32\Tasks\WhiteFrostForceSurceasingV2 => Rundll32.exe GiantessMagi.dll,main 7 1 <==== UWAGA
Task: {5F71137D-14CC-4210-A9E4-5EBD8DBBE537} - System32\Tasks\PriceFountainUpdateVer => C:\Users\WhiteFrost\AppData\Roaming\PriceFountainUpdateVer\UpdateProc\UpdateTask.exe [2016-03-04] () <==== UWAGA
C:\Users\WhiteFrost\AppData\Roaming\PriceFountainUpdateVer
Task: {7A7392E3-7A76-4273-9BBD-A84D37D5B9E7} - System32\Tasks\ZAI47n3QC0gjFX4Cq => C:\Users\WhiteFrost\AppData\Roaming\ZAI47n3QC0gjFX4Cq.exe <==== UWAGA
C:\Users\WhiteFrost\AppData\Roaming\ZAI47n3QC0gjFX4Cq.exe
Task: C:\Windows\Tasks\cWugx8GC0MIRKu1qs.job => C:\Users\WhiteFrost\AppData\Roaming\cWugx8GC0MIRKu1qs.exe <==== UWAGA
C:\Users\WhiteFrost\AppData\Roaming\cWugx8GC0MIRKu1qs.exe
Task: C:\Windows\Tasks\PriceFountainUpdateVer.job => C:\Users\WHITEF~1\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
Task: C:\Windows\Tasks\ZAI47n3QC0gjFX4Cq.job => C:\Users\WhiteFrost\AppData\Roaming\ZAI47n3QC0gjFX4Cq.exe <==== UWAGA
EmptyTemp: