UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3374051690-2922766382-867853538-1000\...\Policies\Explorer: [Run] "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\IEUpdate\taskeng.exe"
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\IEUpdate
HKU\S-1-5-21-3374051690-2922766382-867853538-1002\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)
ShellIconOverlayIdentifiers: [00avast] {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [1SecureIconsProvider] {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll ()
C:\ProgramData\Microsoft\Secure
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3374051690-2922766382-867853538-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-3374051690-2922766382-867853538-1000 {10BA48B7-8C24-4815-B121-4C707FBB5D52} URL = http://www.ant.com/search?s=browser&q={searchTerms}
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U3 uwldipob; \??\C:\Users\Admin\AppData\Local\Temp\uwldipob.sys [X]
Task: {07401519-E6E3-4FD0-83F5-B1F3C6513CA3} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe
Task: {0F6BB639-E835-4169-8130-93DB2F673742} - System32\Tasks\{D69EFB11-D346-4673-B225-9E6EA5845F05} => C:\Users\Admin\Desktop\lide20lide30n670un676un1240uvst7031a_xpen\SetupSG.exe
Task: {11346971-2E0F-4A87-A4E2-80A746BCB7DF} - System32\Tasks\AVG_SYS_TASK_1114av => C:\ProgramData\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe [2014-10-08] ()
Task: {1CFFB346-2E12-491B-A958-7F66DAD85299} - System32\Tasks\{B1574091-AF12-403F-97B4-997EF5927CDB} => C:\Users\Admin\Desktop\lide20lide30n670un676un1240uvst7031a_xpen\SetupSG.exe
Task: {23061F58-6776-4490-AA02-6B2EC9A87628} - System32\Tasks\{59875859-C3FD-4749-B7E5-4896EFC62208} => C:\Users\Admin\Desktop\lide20lide30n670un676un1240uvst7031a_xpen\SetupSG.exe
Task: {258E26FB-3D74-4D3A-8E63-708D14C3761D} - System32\Tasks\Update Service YourFileDownloader => C:\Program Files (x86)\YourFileDownloaderUpdater\YourFileDownloaderUpdater.exe <==== ATTENTION
C:\Program Files (x86)\YourFileDownloaderUpdater
Task: {7FC21BC7-B7D1-4FAB-A4C8-3CBAFD15B9DB} - System32\Tasks\{5C133666-0944-4B7C-B620-668889998D54} => C:\Users\Admin\Desktop\lide20lide30n670un676un1240uvst7031a_xpen\SetupSG.exe
Task: {82BEEDEA-206D-4477-BC1D-7FCEBB8128E5} - System32\Tasks\{18796BB0-E202-4B5C-ACDD-C51BA35641F2} => C:\Users\Admin\Desktop\lide20lide30n670un676un1240uvst7031a_xpen\SetupSG.exe
Task: {8D5EB117-563C-41FD-ACEF-E196CAF30F97} - System32\Tasks\AVG_SYS_TASK_1114av_DELETE => C:\ProgramData\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe [2014-10-08] ()
Task: {E75B0E15-5791-48E0-8A39-360C28F6A974} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION
Task: {EDC97562-8714-4075-81A6-E0A58D2438F7} - System32\Tasks\{480F100B-FCDB-4135-8BBA-3ED0C1820365} => C:\Users\Admin\Desktop\lide20lide30n670un676un1240uvst7031a_xpen\SetupSG.exe
Task: C:\Windows\Tasks\AVG_SYS_TASK_1114av.job => C:\ProgramData\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe
Task: C:\Windows\Tasks\AVG_SYS_TASK_1114av_DELETE.job => C:\ProgramData\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe
C:\ProgramData\Avg_Update_1114av
C:\Users\Admin\AppData\Roaming\newnext.me
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36
Zarejestrowani użytkownicy: Bing [Bot]