UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
2. W przypadku wklejania logów; należy je wykonać od razu przynajmniej z dwóch narzędzi: FRST oraz z GMER
UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
Task: C:\WINDOWS\Tasks\amisfileExdel.job => C:\WINDOWS\system32\cmd.exe0/c del C:\DOCUME~1\hiy\USTAWI~1\Temp\task.vbs <==== UWAGA
Task: C:\WINDOWS\Tasks\amiupdaterExdel.job => C:\WINDOWS\system32\cmd.exe:/c del C:\DOCUME~1\hiy\USTAWI~1\Temp\amiupdater2240.exe <==== UWAGA
ShortcutWithArgument: C:\Documents and Settings\hiy\Pulpit\Nieużywane skróty pulpitu\Start Tor Browser.lnkC:\Documents and Settings\hiy\Moje dokumenty\Tor Browser\Browser\firefox.exe (Mozilla Corporation)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
ShortcutWithArgument: C:\Documents and Settings\hiy\Menu Start\Programy\Internet Explorer.lnkC:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
ShortcutWithArgument: C:\Documents and Settings\hiy\Menu Start\Programy\Google Chrome\Program uruchamiający aplikacje Chrome.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\hiy\Menu Start\Programy\Aplikacje Chrome\Gom VPN - App to bypass blocked sites.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\hiy\Menu Start\Programy\Aplikacje Chrome\ZenMate.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\hiy\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Internet Explorer (bez dodatków).lnkC:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
ShortcutWithArgument: C:\Documents and Settings\hiy\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\hiy\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Program uruchamiający aplikacje Chrome.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\hiy\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Sparta.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnkC:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Opera.lnkC:\Program Files\Opera\launcher.exe (Opera Software)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnkC:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?4d90e27ed79ce9f16251bd43188d42f95224390
ShortcutWithArgument: C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnkC:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
ShortcutWithArgument: C:\Documents and Settings\All Users\Pulpit\Opera.lnkC:\Program Files\Opera\launcher.exe (Opera Software)
"hxxp://esurf.biz/?ssid=1454076611&a=1002708&src=sh&uuid=e5f98d9b-516c-45d1-b160-97cca2c39923"
Startup: C:\Documents and Settings\hiy\Menu Start\Programy\Autostart\readme.txt [2016-01-29] ()
GroupPolicyScripts: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=29065018_243_hao_pg
HKU\S-1-5-21-789336058-616249376-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=29065018_243_hao_pg
SearchScopes: HKU\S-1-5-21-789336058-616249376-682003330-1003DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/yandsearch?win=213&clid=1950378&text={searchTerms}
SearchScopes: HKU\S-1-5-21-789336058-616249376-682003330-1003{0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/yandsearch?win=213&clid=1950378&text={searchTerms}
BHO: Brak nazwy{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}
Brak pliku
FF SelectedSearchEngine: Yandex
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono
CHR Extension: (__MSG_name__) - C:\Documents and Settings\hiy\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nkcpopggjcjkiicpenikeogioednjeac [2016-01-29] [UpdateUrl: hxxp://download.yandex.ru/bar/chrome/updates-vb.xml] <==== UWAGA
C:\Program Files\Tencent
R2 QQPCRtp; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QQPCRTP.exe [301728 2016-01-29] (Tencent)
R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QMIEProtect.sys [50488 2016-01-12] ()
R1 QMUdisk; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QMUdisk.sys [78776 2016-01-29] (Tencent)
R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QQSysMon.sys [108984 2016-01-29] (电脑管家)
R1 softaal; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\softaal.sys [36280 2016-01-29] (Tencent)
R3 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator.sys [114616 2016-01-29] (Tencent)
R1 TAOKernelDriver; C:\WINDOWS\system32\Drivers\TAOKernelXP.sys [95032 2016-01-29] (Tencent Technology(Shenzhen) Company Limited)
R1 TsDefenseBt; C:\WINDOWS\System32\DRIVERS\TSDefenseBt.sys [14008 2016-01-29] (Tencent)
R1 TFsFlt; C:\WINDOWS\System32\Drivers\TFsFlt.sys [150072 2016-01-29] (电脑管家)
R0 TSFLTMGR; C:\WINDOWS\System32\DRIVERS\TSFLTMGR.SYS [128280 2016-01-14] (电脑管家)
R1 Tsksp; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\TSKsp.sys [210072 2016-01-29] (电脑管家)
R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\TSSysKit.sys [102200 2016-01-29] (电脑管家)
S3 BT; system32\DRIVERS\btnetdrv.sys [X]
S3 BTCOM; system32\DRIVERS\btcomport.sys [X]
S3 catchme; \??\C:\DOCUME~1\hiy\USTAWI~1\Temp\catchme.sys [X]
S3 cpuz134; \??\C:\DOCUME~1\hiy\USTAWI~1\Temp\cpuz134\cpuz134_x32.sys [X]
S4 IntelIde; Brak ImagePath
S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X]
S3 mdareDriver_62; \??\C:\DOCUME~1\hiy\USTAWI~1\Temp\FCPreScan\mdare32_62.sys [X]
S3 pflt; system32\DRIVERS\vfilter.sys [X]
S3 vnet; system32\DRIVERS\virtualnet.sys [X]
S3 vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys [X]
2016-01-29 00:34 - 2016-01-31 20:54 - 00000000 ____D C:\Documents and Settings\hiy\Dane aplikacji\Tencent
2016-01-29 00:34 - 2016-01-31 15:09 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-01-29 00:28 - 2016-01-29 00:28 - 00005120 _____ C:\Documents and Settings\hiy\Dane aplikacji\GiftBag.db
2016-01-29 00:27 - 2016-01-29 00:27 - 00000000 ____D C:\Documents and Settings\All Users\TXQMPC
2016-01-29 00:26 - 2016-01-31 15:43 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Tencent
2016-01-29 00:24 - 2016-01-29 00:24 - 00000000 ____D C:\Documents and Settings\hiy\Dane aplikacji\Baidu
2016-01-29 00:24 - 2016-01-29 00:24 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Baidu
2016-01-29 00:23 - 2016-01-29 00:23 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\ĂŔÍĽäŻŔŔ
2016-01-29 00:22 - 2016-01-29 16:36 - 00000000 ____D C:\Program Files\ppt
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
HKU\S-1-5-21-789336058-616249376-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=97530839_hao_pg
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=97530839_hao_pg
CHR Extension: (__MSG_name__) - C:\Documents and Settings\hiy\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nkcpopggjcjkiicpenikeogioednjeac [2016-01-29] [UpdateUrl: hxxp://download.yandex.ru/bar/chrome/updates-vb.xml] <==== UWAGA
R2 QQPCRtp; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QQPCRTP.exe [301728 2016-01-29] (Tencent)
C:\Program Files\Tencent
R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QMIEProtect.sys [50488 2016-01-12] ()
R1 QMUdisk; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QMUdisk.sys [78776 2016-01-29] (Tencent)
R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\QQSysMon.sys [108984 2016-01-29] (电脑管家)
R1 softaal; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\softaal.sys [36280 2016-01-29] (Tencent)
R3 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator.sys [114616 2016-01-29] (Tencent)
R1 TAOKernelDriver; C:\WINDOWS\system32\Drivers\TAOKernelXP.sys [95032 2016-01-29] (Tencent Technology(Shenzhen) Company Limited)
R1 TFsFlt; C:\WINDOWS\System32\Drivers\TFsFlt.sys [150072 2016-01-29] (电脑管家)
R3 TS888; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\TS888.sys [30392 2016-02-08] (Tencent)
R1 TsDefenseBt; C:\WINDOWS\System32\DRIVERS\TSDefenseBt.sys [14008 2016-01-29] (Tencent)
R0 TSFLTMGR; C:\WINDOWS\System32\DRIVERS\TSFLTMGR.SYS [128280 2016-01-14] (电脑管家)
R1 Tsksp; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\TSKsp.sys [210072 2016-01-29] (电脑管家)
R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\11.2.17063.223\TSSysKit.sys [102200 2016-01-29] (电脑管家)
S3 BT; system32\DRIVERS\btnetdrv.sys [X]
S3 BTCOM; system32\DRIVERS\btcomport.sys [X]
S3 catchme; \??\C:\DOCUME~1\hiy\USTAWI~1\Temp\catchme.sys [X]
S3 cpuz134; \??\C:\DOCUME~1\hiy\USTAWI~1\Temp\cpuz134\cpuz134_x32.sys [X]
S4 IntelIde; Brak ImagePath
S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X]
S3 mdareDriver_62; \??\C:\DOCUME~1\hiy\USTAWI~1\Temp\FCPreScan\mdare32_62.sys [X]
S3 pflt; system32\DRIVERS\vfilter.sys [X]
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
S3 vnet; system32\DRIVERS\virtualnet.sys [X]
S3 vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys [X]
2016-01-31 21:34 - 2016-01-31 21:34 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\腾讯软件
2016-01-31 21:33 - 2016-01-31 21:33 - 00000000 ____D C:\Documents and Settings\hiy\Menu Start\Programy\腾讯软件
2016-01-29 00:34 - 2016-01-31 21:32 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-01-29 00:34 - 2016-01-31 20:54 - 00000000 ____D C:\Documents and Settings\hiy\Dane aplikacji\Tencent
BHO: Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ{50F4150A-48B2-417A-BE4C-C83F580FB904}
C:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin: @qq.com/npAndroidAssistantC:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
Reboot:
UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
HKLM\...\Run: [MSConfig] => C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [171520 2008-04-14] (Microsoft Corporation)
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam32.sys [X]
S1 ZAM_Guard; \??\C:\WINDOWS\System32\drivers\zamguard32.sys [X]
2016-01-29 00:36 - 2016-01-14 10:47 - 00128280 _____ (电脑管家) C:\WINDOWS\system32\Drivers\TsFltMgr.sys
2016-01-29 00:28 - 2016-01-29 00:28 - 00005120 _____ C:\Documents and Settings\hiy\Dane aplikacji\GiftBag.db
2016-01-29 00:27 - 2016-01-29 00:27 - 00150072 ____N (电脑管家) C:\WINDOWS\system32\Drivers\TFsFlt.sys
2016-01-29 00:27 - 2016-01-29 00:27 - 00067896 _____ (电脑管家) C:\WINDOWS\system32\TSSK.sys
2016-01-29 00:27 - 2016-01-29 00:27 - 00014008 ____N (Tencent) C:\WINDOWS\system32\Drivers\TSDefenseBt.sys
2016-01-29 00:27 - 2016-01-29 00:27 - 00000000 ____D C:\Documents and Settings\All Users\TXQMPC
2016-01-29 00:26 - 2016-01-31 15:43 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Tencent
2016-01-29 00:26 - 2016-01-29 00:26 - 01507840 _____ C:\Documents and Settings\hiy\Pulpit\adwcleaner_5.031.exe
2016-01-29 00:24 - 2016-01-29 00:24 - 00000000 ____D C:\Documents and Settings\hiy\Dane aplikacji\Baidu
2016-01-29 00:24 - 2016-01-29 00:24 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Baidu
2016-01-29 00:23 - 2016-01-29 00:23 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\ĂŔÍĽäŻŔŔ
Zarejestrowani użytkownicy: Bing [Bot]