18 Paź 2014, 16:26
18 Paź 2014, 19:03
18 Paź 2014, 21:55
19 Paź 2014, 12:46
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-3427100945-3658676166-1123956353-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-3427100945-3658676166-1123956353-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
C:\Program Files\Settings Manager
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [18789920 2009-12-15] (Realtek Semiconductor Corp.)
HKU\S-1-5-21-3427100945-3658676166-1123956353-1005\...\Policies\Explorer: [NoRecentDocsHistory] 1
HKLM\...\AppCertDlls: [x64] c:\program files\settings manager\smdmf\x64\sysapcrt.dll [665104 2014-08-14] ()
HKLM\...\AppCertDlls: [x86] c:\program files\settings manager\smdmf\sysapcrt.dll [489488 2014-08-14] ()
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.default-search.net?sid=476&aid=130&itype=a&ver=13765&tm=291&src=hmp
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=130&itype=a&ver=13765&tm=291&src=ds&p={searchTerms}
SearchScopes: HKCU - DefaultScope Software\Microsoft\Internet Explorer\SearchScopes URL = http://start.iminent.com/?appId=F053DB23-1135-467A-8315-49EB916C3D91&ref=toolbox&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=130&itype=a&ver=13765&tm=291&src=ds&p={searchTerms}
DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab
FF SearchEngineOrder.1: Search the web
FF Extension: IB Updater - C:\Program Files\IB Updater\Firefox [2012-11-30]
C:\Program Files\WebCake
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [2012-11-30]
CHR HKLM\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files\WebCake\WebCakeLayers.crx [2012-11-30]
C:\Program Files\facemoods.com
CHR HKLM\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Program Files\facemoods.com\facemoods\1.4.8.1\facemoods.crx [2014-07-04]
CHR HKLM\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\DOCUME~1\Dagmara\USTAWI~1\Temp\ccex.crx [2012-05-21]
U3 asi6xz1v; C:\WINDOWS\system32\Drivers\asi6xz1v.sys [0 ] (M-Systems)
S3 catchme; \??\C:\DOCUME~1\Dagmara\USTAWI~1\Temp\catchme.sys [X]
S4 IntelIde; No ImagePath
U3 TlntSvr; No ImagePath
2014-10-15 07:05 - 2014-10-15 07:34 - 00000000 ____D () C:\AdwCleaner
2014-09-22 22:46 - 2009-06-18 09:15 - 00214024 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfehidk.sys
2014-09-22 22:46 - 2009-06-18 09:15 - 00079816 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeavfk.sys
2014-09-22 22:46 - 2009-06-18 09:15 - 00040552 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfesmfk.sys
2014-09-22 22:46 - 2009-06-18 09:15 - 00035272 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfebopk.sys
2014-09-22 22:46 - 2009-06-18 09:14 - 00034248 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mferkdk.sys
2014-09-22 22:46 - 2009-04-09 13:23 - 00120136 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\Mpfp.sys
2014-09-22 14:07 - 2014-09-22 14:29 - 00000000 ____D () C:\ComboFix
2014-09-21 04:45 - 2014-09-21 04:45 - 00000000 ____D () C:\Documents and Settings\Dagmara\Dane aplikacji\FirefoxToolbar
2014-09-21 04:44 - 2014-10-18 16:45 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\smdmf
2014-09-21 04:44 - 2014-09-21 04:44 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\systemk
2014-10-18 16:26 - 2014-02-07 17:55 - 00000486 _____ () C:\WINDOWS\Tasks\HP Photo Creations Communicator.job
2014-10-16 20:09 - 2011-11-04 18:21 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2014-09-22 14:29 - 2013-11-14 03:43 - 00000000 ____D () C:\Qoobox
EmptyTemp:
21 Paź 2014, 07:31
21 Paź 2014, 10:32
tak , problem pojawił sie po uzyciu combofix
FF SearchEngineOrder.1: Search the web
S2 SmdmFService; C:\Program Files\Settings Manager\smdmf\SmdmFService.exe [X]
22 Paź 2014, 06:15
22 Paź 2014, 11:12
23 Paź 2014, 07:16
23 Paź 2014, 10:09
folderu C:\FRST nie moge usunąć - odmowa dostępu
DeleteQuarantine:
23 Paź 2014, 17:37
23 Paź 2014, 22:30
23 Paź 2014, 23:11
23 Paź 2014, 23:45
24 Paź 2014, 02:07