UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Sarna\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Sarna\AppData\Roaming\FoxTab
Task: {E17D1B11-72C7-4C45-9234-0886D2CC5465} - System32\Tasks\FoxTab => C:\Users\Sarna\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
SearchScopes: HKU\S-1-5-21-3463613797-2275327166-651005633-1000 {3EDADD97-7D2F-4D35-B77F-27CA3F8E8E60} URL = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=kw&q={searchTerms}&locale=&apn_ptnrs=^FV&apn_dtid=^YYYYYY^YY^PL&apn_uid=396fa2a0-0528-4dd6-a649-08720a15f09c&apn_sauid=7AA07B6D-CF9D-4E8B-A06F-C9D8ECE810C1
FF SearchEngineOrder.1: Ask.com
FF SearchPlugin: C:\Users\Sarna\AppData\Roaming\Mozilla\Firefox\Profiles\56412c4i.default\searchplugins\askcom.xml
FF Extension: Foxtab Speed Dial - C:\Users\Sarna\AppData\Roaming\Mozilla\Firefox\Profiles\56412c4i.default\Extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab}.xpi [2014-03-25]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh [Not Found]
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
S3 WinRing0_1_2_0; \??\D:\Game Booster\Driver\WinRing0x64.sys [X]
U3 afldypow; \??\C:\Users\Sarna\AppData\Local\Temp\afldypow.sys [X]
2015-02-25 19:40 - 2013-10-31 18:40 - 00000288 _____ () C:\Windows\Tasks\FoxTab.job
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
http://i.imgur.com/v3nAU95.png
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
Operę mogę ręcznie usunąć?
2015-02-25 18:09 - 2015-02-25 18:09 - 00013653 _____ () C:\ComboFix.txt
2015-02-25 17:52 - 2015-02-25 18:09 - 00000000 ____D () C:\Qoobox
2015-02-25 17:52 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-25 17:52 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-25 17:52 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-25 17:52 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-25 17:52 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-25 17:52 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-25 17:52 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-25 17:52 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
EmptyTemp:
Dorzucam jego logi, bo coś znalazł, poza Juniper Networks (program uczelniany Junos Pulse, jakiś VPN), jakieś inne, już dziwne wpisy.
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
Zarejestrowani użytkownicy: Bing [Bot]