UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Task: {40341B38-7B85-46DC-AF43-212E443F1BB2} - System32\Tasks\x7dePYZWymH67r8llJzHgWoY => C:\Users\Dariusz\AppData\Roaming\x7dePYZWymH67r8llJzHgWoY.exe <==== UWAGA
C:\Users\Dariusz\AppData\Roaming\x7dePYZWymH67r8llJzHgWoY.exe
Task: {9DB9FC6C-52A2-491B-8CC0-6C976E6E0209} - System32\Tasks\xv9hsWRuWgo5zMTdG => C:\Users\Dariusz\AppData\Roaming\xv9hsWRuWgo5zMTdG.exe <==== UWAGA
C:\Users\Dariusz\AppData\Roaming\xv9hsWRuWgo5zMTdG.exe
Task: {F467F6DA-B380-47BF-B780-CCADCC58260F} - System32\Tasks\oAh4TdYn6CXjXqMTlxyAjfxYF => C:\Users\Dariusz\AppData\Roaming\oAh4TdYn6CXjXqMTlxyAjfxYF.exe <==== UWAGA
C:\Users\Dariusz\AppData\Roaming\oAh4TdYn6CXjXqMTlxyAjfxYF.exe
Task: C:\Windows\Tasks\oAh4TdYn6CXjXqMTlxyAjfxYF.job => C:\Users\Dariusz\AppData\Roaming\oAh4TdYn6CXjXqMTlxyAjfxYF.exe <==== UWAGA
Task: C:\Windows\Tasks\x7dePYZWymH67r8llJzHgWoY.job => C:\Users\Dariusz\AppData\Roaming\x7dePYZWymH67r8llJzHgWoY.exe <==== UWAGA
Task: C:\Windows\Tasks\xv9hsWRuWgo5zMTdG.job => C:\Users\Dariusz\AppData\Roaming\xv9hsWRuWgo5zMTdG.exe <==== UWAGA
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Dariusz\AppData\Roaming\oAh4TdYn6CXjXqMTlxyAjfxYF
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Dariusz\AppData\Roaming\x7dePYZWymH67r8llJzHgWoY
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Dariusz\AppData\Roaming\xv9hsWRuWgo5zMTdG
HKU\S-1-5-21-641250380-1982369224-719823222-1001\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2765256 2015-04-27] (ALLPlayer Group Ltd.)
HKU\S-1-5-21-641250380-1982369224-719823222-1001\...\Run: [Napisy24Update] => C:\Program Files (x86)\Napisy24\Napisy24Update.exe [2790344 2015-03-12] (Napisy24.pl)
HKU\S-1-5-21-641250380-1982369224-719823222-1001\...\Run: [ALLPlayer WiFi Remote] => C:\Program Files (x86)\ALLPlayer Remote\ALLPlayerRemoteControl.exe [5182896 2014-07-23] (ALLPlayer Group Ltd.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
mateo8898 napisał(a):Wklej do notatnika:DeleteQuarantine:
Plik zapisujesz pod nazwą fixlist.txt i umieszczasz obok FRST. Uruchom FRST i kliknij w nim Napraw
Przeczyść dysk oraz rejestr CCleaner (zakładka Cleaner i Rejestr)
mateo8898 napisał(a):Zainstalujhttp://www.instalki.pl/programy/downloa ... hecky.html
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
Zarejestrowani użytkownicy: Bing [Bot]