Logi, zabezpieczenie komputera, danych. Programy antywirusowe antyspyware, firewall itp.

Regulamin forum

1. Każdy temat powinien odzwierciedlać treść wątku.
2. W przypadku wklejania logów; należy je wykonać od razu przynajmniej z dwóch narzędzi: FRST oraz z GMER
3. Wszelkie logi proszę publikować na przeznaczonych do tego stronach a w poście wklejać tylko link.
4. Nie wskazane jest skracanie logów, należy wkleić cały - od początku, do końca.
5. Nie wskazane jest podczepianie się do tematów innych użytkowników - proszę założyć nowy temat w dziale Bezpieczeństwo, ułatwi to pomoc sprawdzającemu.
6. Osoby nie posiadające odpowiedniej wiedzy, nie powinny sprawdzać logów, ponieważ grozi to poważnym uszkodzeniem systemu lub aplikacji zainstalowanych na komputerze.
7. Należy dokładnie opisać problem, występujące objawy oraz wszelkie podjęte działania.
8. Każdy skrypt jest unikatowy, napisany dla każdego przypadku z osobna, więc nie może być stosowany przez innych.
9. W przypadku zamieszczenia zrzutu ekranu (screenshot'a) proszę korzystać z zewnętrznego serwisu oferującego hosting zdjęć.
Wyślij odpowiedź

PROBLEM Z RUNDLL

22 Lut 2016, 15:57

Witam za każdym razem po uruchomieniu systemu Windows 7 wyskakują mi 2 komunikaty i nie wiem jak się tego pozbyć, skanowałem malwarebytes i spyhunter'em, używałem CCleaner'a i nic, gdzieś wyczytałem że jest to jakiś wirus ale nie mam pomysłu jak to ugryźć. Wysyłam także logi z OTL'a

Image

Kod:
OTL logfile created on: 2016-02-22 11:48:56 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Jarek\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18204)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
 
1,99 Gb Total Physical Memory | 0,70 Gb Available Physical Memory | 35,14% Memory free
3,98 Gb Paging File | 2,64 Gb Available in Paging File | 66,38% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 119,14 Gb Total Space | 55,46 Gb Free Space | 46,55% Space Free | Partition Type: NTFS
Drive N: | 536,01 Gb Total Space | 525,22 Gb Free Space | 97,99% Space Free | Partition Type: NTFS
 
Computer Name: JAREK-KOMPUTER | User Name: Jarek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2016-02-18 05:15:35 | 000,746,648 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2016-02-16 19:39:50 | 025,122,080 | ---- | M] (Dropbox, Inc.) -- C:\Program Files\Dropbox\Client\Dropbox.exe
PRC - [2016-01-22 06:12:59 | 002,973,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2016-01-15 21:43:14 | 006,628,056 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2015-12-15 13:35:37 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jarek\Downloads\OTL.exe
PRC - [2015-12-08 22:53:17 | 000,443,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\GWX\GWX.exe
PRC - [2015-09-11 16:54:31 | 004,346,640 | ---- | M] (TeamViewer GmbH) -- c:\users\jarek\appdata\local\temp\teamviewer\TeamViewer_Service.exe
PRC - [2012-11-23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2016-02-16 19:39:34 | 000,024,904 | ---- | M] () -- C:\Program Files\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
MOD - [2016-02-16 19:39:34 | 000,021,840 | ---- | M] () -- C:\Program Files\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
MOD - [2016-02-16 19:39:32 | 000,021,832 | ---- | M] () -- C:\Program Files\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
MOD - [2016-02-16 19:39:32 | 000,020,800 | ---- | M] () -- C:\Program Files\Dropbox\Client\_cffi_python_x66cf7a7cx17a72769.pyd
MOD - [2016-02-16 19:39:30 | 000,023,376 | ---- | M] () -- C:\Program Files\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
MOD - [2016-02-16 19:39:30 | 000,022,352 | ---- | M] () -- C:\Program Files\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
MOD - [2016-02-16 19:39:28 | 000,021,824 | ---- | M] () -- C:\Program Files\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
MOD - [2016-02-16 19:39:28 | 000,020,800 | ---- | M] () -- C:\Program Files\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
MOD - [2016-02-16 19:39:28 | 000,019,776 | ---- | M] () -- C:\Program Files\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
MOD - [2016-02-16 19:39:26 | 000,020,800 | ---- | M] () -- C:\Program Files\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
MOD - [2016-02-16 19:39:24 | 000,381,752 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32com.shell.shell.pyd
MOD - [2016-02-16 19:39:24 | 000,019,760 | ---- | M] () -- C:\Program Files\Dropbox\Client\tornado.speedups.pyd
MOD - [2016-02-16 19:39:18 | 003,928,880 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtWidgets.pyd
MOD - [2016-02-16 19:39:18 | 000,223,544 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
MOD - [2016-02-16 19:39:16 | 000,158,008 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
MOD - [2016-02-16 19:39:16 | 000,132,912 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtWebKit.pyd
MOD - [2016-02-16 19:39:14 | 000,042,808 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtWebChannel.pyd
MOD - [2016-02-16 19:39:12 | 000,531,248 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtNetwork.pyd
MOD - [2016-02-16 19:39:12 | 000,207,672 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtPrintSupport.pyd
MOD - [2016-02-16 19:39:10 | 001,971,504 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtGui.pyd
MOD - [2016-02-16 19:39:10 | 001,826,096 | ---- | M] () -- C:\Program Files\Dropbox\Client\PyQt5.QtCore.pyd
MOD - [2016-02-16 19:39:08 | 000,052,024 | ---- | M] () -- C:\Program Files\Dropbox\Client\psutil._psutil_windows.pyd
MOD - [2016-02-16 19:39:06 | 000,038,696 | ---- | M] () -- C:\Program Files\Dropbox\Client\fastpath.pyd
MOD - [2016-02-16 19:39:06 | 000,024,392 | ---- | M] () -- C:\Program Files\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
MOD - [2016-02-16 19:39:04 | 000,084,792 | ---- | M] () -- C:\Program Files\Dropbox\Client\dropbox_sqlite_ext.dll
MOD - [2016-02-16 19:39:02 | 000,026,456 | ---- | M] () -- C:\Program Files\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
MOD - [2016-02-16 19:38:52 | 000,020,808 | ---- | M] () -- C:\Program Files\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
MOD - [2016-02-16 19:38:50 | 001,682,760 | ---- | M] () -- C:\Program Files\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
MOD - [2016-02-16 19:38:50 | 000,020,816 | ---- | M] () -- C:\Program Files\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
MOD - [2016-02-16 19:38:48 | 000,117,056 | ---- | M] () -- C:\Program Files\Dropbox\Client\breakpad.client.windows.handler.pyd
MOD - [2016-02-16 19:38:48 | 000,020,280 | ---- | M] () -- C:\Program Files\Dropbox\Client\cpuid.compiled._cpuid.pyd
MOD - [2016-01-15 21:45:02 | 000,061,440 | ---- | M] () -- C:\Program Files\CCleaner\Lang\lang-1045.dll
MOD - [2016-01-12 19:49:22 | 001,631,184 | ---- | M] () -- C:\Program Files\Dropbox\Client\libGLESv2.dll
MOD - [2016-01-12 19:49:12 | 000,017,864 | ---- | M] () -- C:\Program Files\Dropbox\Client\libEGL.dll
MOD - [2016-01-12 19:47:34 | 000,036,296 | ---- | M] () -- C:\Program Files\Dropbox\Client\librsync.dll
MOD - [2016-01-12 19:47:08 | 000,350,152 | ---- | M] () -- C:\Program Files\Dropbox\Client\winxpgui.pyd
MOD - [2016-01-12 19:47:04 | 000,114,640 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32security.pyd
MOD - [2016-01-12 19:47:04 | 000,048,592 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32service.pyd
MOD - [2016-01-12 19:47:04 | 000,028,616 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32ts.pyd
MOD - [2016-01-12 19:47:02 | 000,043,472 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32process.pyd
MOD - [2016-01-12 19:47:02 | 000,030,160 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32pipe.pyd
MOD - [2016-01-12 19:47:02 | 000,024,016 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32profile.pyd
MOD - [2016-01-12 19:46:50 | 000,175,560 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32gui.pyd
MOD - [2016-01-12 19:46:46 | 000,124,880 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32file.pyd
MOD - [2016-01-12 19:46:40 | 000,057,808 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32evtlog.pyd
MOD - [2016-01-12 19:46:40 | 000,024,528 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32event.pyd
MOD - [2016-01-12 19:46:38 | 000,105,928 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32api.pyd
MOD - [2016-01-12 19:46:38 | 000,024,016 | ---- | M] () -- C:\Program Files\Dropbox\Client\win32clipboard.pyd
MOD - [2016-01-12 19:46:38 | 000,020,936 | ---- | M] () -- C:\Program Files\Dropbox\Client\mmapfile.pyd
MOD - [2016-01-12 19:45:54 | 000,112,592 | ---- | M] () -- C:\Program Files\Dropbox\Client\_cffi_backend.pyd
MOD - [2016-01-12 19:45:50 | 000,083,912 | ---- | M] () -- C:\Program Files\Dropbox\Client\sip.pyd
MOD - [2016-01-12 19:45:42 | 000,240,584 | ---- | M] () -- C:\Program Files\Dropbox\Client\jpegtran.pyd
MOD - [2016-01-12 19:45:36 | 000,019,408 | ---- | M] () -- C:\Program Files\Dropbox\Client\faulthandler.pyd
MOD - [2016-01-12 19:44:48 | 000,134,608 | ---- | M] () -- C:\Program Files\Dropbox\Client\_elementtree.pyd
MOD - [2016-01-12 19:44:48 | 000,034,768 | ---- | M] () -- C:\Program Files\Dropbox\Client\_multiprocessing.pyd
MOD - [2016-01-12 19:44:46 | 000,093,640 | ---- | M] () -- C:\Program Files\Dropbox\Client\_ctypes.pyd
MOD - [2016-01-12 19:44:44 | 000,692,688 | ---- | M] () -- C:\Program Files\Dropbox\Client\unicodedata.pyd
MOD - [2016-01-12 19:44:42 | 000,018,376 | ---- | M] () -- C:\Program Files\Dropbox\Client\select.pyd
MOD - [2016-01-12 19:44:40 | 000,134,088 | ---- | M] () -- C:\Program Files\Dropbox\Client\pyexpat.pyd
MOD - [2016-01-12 19:44:34 | 000,116,688 | ---- | M] () -- C:\Program Files\Dropbox\Client\pywintypes27.dll
MOD - [2016-01-12 19:44:30 | 000,392,144 | ---- | M] () -- C:\Program Files\Dropbox\Client\pythoncom27.dll
 
 
[color=#E56717]========== Services (SafeList) ==========[/color]
 
SRV - [2016-01-22 06:52:03 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2016-01-04 15:02:19 | 000,143,144 | ---- | M] (Dropbox, Inc.) [On_Demand | Stopped] -- C:\Program Files\Dropbox\Update\DropboxUpdate.exe -- (dbupdatem)
SRV - [2016-01-04 15:02:19 | 000,143,144 | ---- | M] (Dropbox, Inc.) [Auto | Stopped] -- C:\Program Files\Dropbox\Update\DropboxUpdate.exe -- (dbupdate)
SRV - [2015-12-11 16:29:05 | 000,268,976 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015-10-05 09:48:46 | 001,135,416 | ---- | M] (Malwarebytes) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2015-09-11 16:54:31 | 004,346,640 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- c:\users\jarek\appdata\local\temp\teamviewer\TeamViewer_Service.exe -- (TeamViewer)
SRV - [2015-07-22 18:53:34 | 000,937,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
SRV - [2013-05-27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2016-02-22 11:29:34 | 000,170,200 | ---- | M] (Malwarebytes) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV - [2015-10-05 09:50:16 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV - [2015-10-05 09:50:04 | 000,023,256 | ---- | M] (Malwarebytes) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010-11-20 22:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 22:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010-11-20 22:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/pl-pl/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7E EA 55 87 FF C8 D0 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {DD662589-73F5-43A9-8660-E4AC3E01A580}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\..\SearchScopes\{DD662589-73F5-43A9-8660-E4AC3E01A580}: "URL" = https://www.google.com/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
 
 
 
[color=#E56717]========== Chrome  ==========[/color]
 
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpcpblpdkddoicgechaickbldbieccko\1.0.0_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.10.1_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.1_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.50_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgpclmlekpklcnjkabiaaljhpfpjlged\2.0.1_0\
CHR - Extension: No name found = C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
 
O1 HOSTS File: ([2015-12-11 14:56:14 | 000,000,862 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       down.baidu2016.com
O4 - HKLM..\Run: [Dropbox] C:\Program Files\Dropbox\Client\Dropbox.exe (Dropbox, Inc.)
O4 - HKLM..\Run: [Sage Komunikator] C:\Program Files\Sage\Komunikator\SageUpdt.exe ()
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.152.34 194.204.159.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16A11A0E-0DE6-459F-BD57-B5EDCA54ED19}: DhcpNameServer = 194.204.152.34 194.204.159.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2016-02-22 11:31:45 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2016-02-22 11:24:56 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2016-02-22 11:02:12 | 000,170,200 | ---- | C] (Malwarebytes) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2016-02-22 11:01:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2016-02-22 11:01:54 | 000,094,936 | ---- | C] (Malwarebytes) -- C:\Windows\System32\drivers\mbamchameleon.sys
[2016-02-22 11:01:54 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
[2016-02-22 11:01:54 | 000,023,256 | ---- | C] (Malwarebytes) -- C:\Windows\System32\drivers\mbam.sys
[2016-02-22 11:01:54 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2016-02-19 07:09:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
[2016-02-10 07:20:39 | 001,198,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appraiser.dll
[2016-02-10 07:20:39 | 000,949,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
[2016-02-10 07:20:39 | 000,591,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\invagent.dll
[2016-02-10 07:20:39 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\generaltel.dll
[2016-02-10 07:20:38 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\devinv.dll
[2016-02-10 07:20:38 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\acmigration.dll
[2016-02-10 07:20:38 | 000,022,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CompatTelRunner.exe
[2016-02-10 07:20:32 | 002,973,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2016-02-10 07:20:32 | 001,805,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2016-02-10 07:20:32 | 001,498,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2016-02-10 07:20:30 | 002,386,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2016-02-10 07:20:30 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\InkEd.dll
[2016-02-10 07:20:30 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jnwmon.dll
[2016-02-10 07:20:28 | 003,993,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2016-02-10 07:20:28 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2016-02-10 07:20:28 | 000,535,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2016-02-10 07:20:27 | 003,938,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2016-02-10 07:20:27 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
[2016-02-10 07:20:27 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2016-02-10 07:20:27 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2016-02-10 07:20:27 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rstrui.exe
[2016-02-10 07:20:27 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2016-02-10 07:20:27 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msorcl32.dll
[2016-02-10 07:20:27 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2016-02-10 07:20:27 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msaudite.dll
[2016-02-10 07:20:27 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
[2016-02-10 07:20:27 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\auditpol.exe
[2016-02-10 07:20:27 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2016-02-10 07:20:27 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2016-02-10 07:20:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apisetschema.dll
[2016-02-10 07:20:27 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2016-02-10 07:20:27 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2016-02-10 07:20:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2016-02-10 07:20:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2016-02-10 07:20:24 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2016-02-10 07:20:24 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2016-02-10 07:20:17 | 000,684,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2016-02-10 07:20:17 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2016-02-10 07:20:17 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2016-02-10 07:20:17 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2016-02-10 07:20:16 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2016-02-10 07:20:16 | 000,687,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2016-02-10 07:20:16 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2016-02-10 07:20:16 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2016-02-10 07:20:16 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2016-02-10 07:20:16 | 000,341,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2016-02-10 07:20:16 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2016-02-10 07:20:16 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2016-02-10 07:20:16 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2016-02-10 07:20:16 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2016-02-10 07:20:15 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2016-02-10 07:20:15 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2016-02-10 07:20:15 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2016-02-10 07:20:14 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2016-02-10 07:20:14 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2016-02-10 07:20:12 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2016-02-10 07:20:11 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2016-02-10 07:20:11 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
[2016-02-10 07:20:09 | 004,611,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2016-02-10 07:20:06 | 002,956,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2016-02-10 07:20:06 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2016-02-10 07:20:06 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2016-02-10 07:20:06 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2016-02-10 07:20:06 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSetupUI.dll
[2016-02-10 07:20:06 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2016-02-10 07:20:06 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2016-02-10 07:20:06 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2016-02-10 07:20:06 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wu.upgrade.ps.dll
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2016-02-22 11:40:28 | 000,021,856 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016-02-22 11:40:28 | 000,021,856 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016-02-22 11:36:55 | 000,739,694 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2016-02-22 11:36:55 | 000,653,526 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2016-02-22 11:36:55 | 000,155,268 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2016-02-22 11:36:55 | 000,121,398 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2016-02-22 11:32:47 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016-02-22 11:32:46 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskMachineCore.job
[2016-02-22 11:32:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016-02-22 11:32:38 | 1602,936,832 | -HS- | M] () -- C:\hiberfil.sys
[2016-02-22 11:29:34 | 000,170,200 | ---- | M] (Malwarebytes) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2016-02-22 11:11:00 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016-02-22 11:07:06 | 000,001,138 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskMachineUA.job
[2016-02-22 10:51:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016-02-19 16:37:49 | 002,149,778 | ---- | M] () -- C:\Users\Jarek\Desktop\pilsko.png
[2016-02-19 16:30:25 | 000,021,625 | ---- | M] () -- C:\Users\Jarek\Desktop\ricom.pdf
[2016-02-19 11:07:56 | 000,021,744 | ---- | M] () -- C:\Users\Jarek\Desktop\lechar19,02.pdf
[2016-02-19 08:42:51 | 000,023,266 | ---- | M] () -- C:\Users\Jarek\Desktop\gola2.pdf
[2016-02-19 08:37:13 | 000,025,671 | ---- | M] () -- C:\Users\Jarek\Desktop\gola1.pdf
[2016-02-19 08:31:30 | 000,022,050 | ---- | M] () -- C:\Users\Jarek\Desktop\parka.pdf
[2016-02-19 07:12:23 | 000,002,135 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016-02-18 16:03:52 | 000,022,050 | ---- | M] () -- C:\Users\Jarek\Desktop\parkanex chorzelow.pdf
[2016-02-18 15:39:57 | 000,021,204 | ---- | M] () -- C:\Users\Jarek\Desktop\tech.pdf
[2016-02-18 13:38:20 | 000,090,479 | ---- | M] () -- C:\Users\Jarek\Desktop\Dokument VAT I - 00311 02 2016 FV H.pdf
[2016-02-18 12:55:05 | 000,090,479 | ---- | M] () -- C:\Users\Jarek\Desktop\evan proforma1.pdf
[2016-02-18 12:51:54 | 000,090,443 | ---- | M] () -- C:\Users\Jarek\Desktop\evan proforma.pdf
[2016-02-17 16:55:36 | 000,021,964 | ---- | M] () -- C:\Users\Jarek\Desktop\dgd.pdf
[2016-02-17 14:49:17 | 000,026,657 | ---- | M] () -- C:\Users\Jarek\Desktop\evan.pdf
[2016-02-17 10:06:53 | 000,026,961 | ---- | M] () -- C:\Users\Jarek\Desktop\introl.pdf
[2016-02-17 09:38:28 | 000,088,897 | ---- | M] () -- C:\Users\Jarek\Desktop\chsm.pdf
[2016-02-16 16:43:46 | 000,022,449 | ---- | M] () -- C:\Users\Jarek\Desktop\ott.pdf
[2016-02-16 11:33:13 | 000,021,709 | ---- | M] () -- C:\Users\Jarek\Desktop\rury.pdf
[2016-02-15 14:08:58 | 000,086,655 | ---- | M] () -- C:\Users\Jarek\Desktop\kryza.pdf
[2016-02-15 13:43:24 | 000,022,661 | ---- | M] () -- C:\Users\Jarek\Desktop\alfa.pdf
[2016-02-15 13:25:43 | 000,045,959 | ---- | M] () -- C:\Users\Jarek\Desktop\lesniak stryzowice.pdf
[2016-02-15 11:02:01 | 000,026,784 | ---- | M] () -- C:\Users\Jarek\Desktop\carbo2.pdf
[2016-02-15 10:59:33 | 000,028,918 | ---- | M] () -- C:\Users\Jarek\Desktop\carbo1.pdf
[2016-02-11 13:00:24 | 000,031,511 | ---- | M] () -- C:\Users\Jarek\Desktop\sroka.pdf
[2016-02-11 11:39:18 | 000,021,461 | ---- | M] () -- C:\Users\Jarek\Desktop\tech 11,02.pdf
[2016-02-11 10:55:07 | 000,085,462 | ---- | M] () -- C:\Users\Jarek\Desktop\niebieska.pdf
[2016-02-11 09:44:53 | 000,023,668 | ---- | M] () -- C:\Users\Jarek\Desktop\marbud grzejniki.pdf
[2016-02-11 06:41:18 | 000,294,328 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2016-02-10 12:26:44 | 000,028,320 | ---- | M] () -- C:\Users\Jarek\Desktop\pewima oc.pdf
[2016-02-10 11:25:05 | 000,025,780 | ---- | M] () -- C:\Users\Jarek\Desktop\sr pcv.pdf
[2016-02-09 13:05:06 | 000,022,574 | ---- | M] () -- C:\Users\Jarek\Desktop\zebiec11.pdf
[2016-02-09 13:02:39 | 000,028,977 | ---- | M] () -- C:\Users\Jarek\Desktop\gejzer.pdf
[2016-02-09 12:40:54 | 000,024,739 | ---- | M] () -- C:\Users\Jarek\Desktop\ustm.pdf
[2016-02-09 12:31:10 | 000,032,047 | ---- | M] () -- C:\Users\Jarek\Desktop\storen.pdf
[2016-02-09 12:07:44 | 000,110,209 | ---- | M] () -- C:\Users\Jarek\Desktop\wiek styczeń.pdf
[2016-02-08 14:07:06 | 000,087,989 | ---- | M] () -- C:\Users\Jarek\Desktop\abs2.pdf
[2016-02-08 12:23:50 | 000,095,951 | ---- | M] () -- C:\Users\Jarek\Desktop\domb.pdf
[2016-02-08 11:01:58 | 000,092,672 | ---- | M] () -- C:\Users\Jarek\Desktop\abs.pdf
[2016-02-08 10:57:28 | 000,035,794 | ---- | M] () -- C:\Users\Jarek\Desktop\budamar1.pdf
[2016-02-08 10:53:27 | 000,035,794 | ---- | M] () -- C:\Users\Jarek\Desktop\budamar.pdf
[2016-02-06 10:54:50 | 002,724,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2016-02-06 10:38:27 | 000,476,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2016-02-05 14:38:16 | 000,085,199 | ---- | M] () -- C:\Users\Jarek\Desktop\nieb.pdf
[2016-02-05 14:25:32 | 000,023,584 | ---- | M] () -- C:\Users\Jarek\Desktop\plstim.pdf
[2016-02-04 16:29:47 | 000,091,991 | ---- | M] () -- C:\Users\Jarek\Desktop\kamsoft.pdf
[2016-02-04 16:22:13 | 000,086,775 | ---- | M] () -- C:\Users\Jarek\Desktop\flow.pdf
[2016-02-03 14:10:34 | 000,928,676 | ---- | M] () -- C:\Users\Jarek\Desktop\smartplus.pdf
[2016-02-03 12:23:27 | 000,022,455 | ---- | M] () -- C:\Users\Jarek\Desktop\lechar.pdf
[2016-02-03 11:56:16 | 000,031,008 | ---- | M] () -- C:\Users\Jarek\Desktop\Adam K.pdf
[2016-02-03 11:11:06 | 000,023,171 | ---- | M] () -- C:\Users\Jarek\Desktop\leo.pdf
[2016-02-03 09:27:18 | 000,086,175 | ---- | M] () -- C:\Users\Jarek\Desktop\12..pdf
[2016-02-03 09:26:59 | 000,084,975 | ---- | M] () -- C:\Users\Jarek\Desktop\12.pdf
[2016-02-02 17:11:51 | 000,085,375 | ---- | M] () -- C:\Users\Jarek\Desktop\pierwsza1.pdf
[2016-02-02 15:39:36 | 000,085,608 | ---- | M] () -- C:\Users\Jarek\Desktop\pierwsza.pdf
[2016-02-02 15:34:17 | 000,094,939 | ---- | M] () -- C:\Users\Jarek\Desktop\DHL24.pdf
[2016-02-01 16:10:16 | 000,088,476 | ---- | M] () -- C:\Users\Jarek\Desktop\krzychu.pdf
[2016-02-01 16:03:22 | 000,024,317 | ---- | M] () -- C:\Users\Jarek\Desktop\ele.pdf
[2016-02-01 16:02:23 | 000,024,317 | ---- | M] () -- C:\Users\Jarek\Desktop\elekrtownia.pdf
[2016-02-01 15:59:25 | 000,024,334 | ---- | M] () -- C:\Users\Jarek\Desktop\elektrownia .pdf
[2016-02-01 15:37:13 | 000,087,267 | ---- | M] () -- C:\Users\Jarek\Desktop\instyt.pdf
[2016-01-28 11:42:55 | 000,086,433 | ---- | M] () -- C:\Users\Jarek\Desktop\Dokument VAT I - 00467 01 2016 FV H.pdf
[2016-01-27 16:30:47 | 000,025,840 | ---- | M] () -- C:\Users\Jarek\Desktop\marko kom5.pdf
[2016-01-27 16:27:47 | 000,024,858 | ---- | M] () -- C:\Users\Jarek\Desktop\marko 4.pdf
[2016-01-27 16:24:24 | 000,026,061 | ---- | M] () -- C:\Users\Jarek\Desktop\marko kom3.pdf
[2016-01-27 16:19:43 | 000,025,662 | ---- | M] () -- C:\Users\Jarek\Desktop\marko kom2.pdf
[2016-01-27 16:16:07 | 000,025,560 | ---- | M] () -- C:\Users\Jarek\Desktop\Marko kom1.pdf
[2016-01-27 14:54:11 | 000,027,367 | ---- | M] () -- C:\Users\Jarek\Desktop\kamsoft 1.pdf
[2016-01-27 14:36:41 | 000,085,077 | ---- | M] () -- C:\Users\Jarek\Desktop\tasta.pdf
[2016-01-27 10:58:01 | 000,084,732 | ---- | M] () -- C:\Users\Jarek\Desktop\lgm.pdf
[2016-01-26 12:47:29 | 000,029,085 | ---- | M] () -- C:\Users\Jarek\Desktop\elektr bet.pdf
[2016-01-26 12:25:32 | 000,087,639 | ---- | M] () -- C:\Users\Jarek\Desktop\green.pdf
[2016-01-25 14:29:30 | 000,024,444 | ---- | M] () -- C:\Users\Jarek\Desktop\kam.pdf
[2016-01-25 11:15:25 | 000,026,577 | ---- | M] () -- C:\Users\Jarek\Desktop\sr purmo.pdf
[2016-01-25 09:49:00 | 000,028,466 | ---- | M] () -- C:\Users\Jarek\Desktop\pbpw.pdf
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2016-02-19 16:37:49 | 002,149,778 | ---- | C] () -- C:\Users\Jarek\Desktop\pilsko.png
[2016-02-19 11:07:56 | 000,021,744 | ---- | C] () -- C:\Users\Jarek\Desktop\lechar19,02.pdf
[2016-02-19 08:42:51 | 000,023,266 | ---- | C] () -- C:\Users\Jarek\Desktop\gola2.pdf
[2016-02-19 08:37:13 | 000,025,671 | ---- | C] () -- C:\Users\Jarek\Desktop\gola1.pdf
[2016-02-19 08:31:30 | 000,022,050 | ---- | C] () -- C:\Users\Jarek\Desktop\parka.pdf
[2016-02-18 16:03:52 | 000,022,050 | ---- | C] () -- C:\Users\Jarek\Desktop\parkanex chorzelow.pdf
[2016-02-18 13:38:20 | 000,090,479 | ---- | C] () -- C:\Users\Jarek\Desktop\Dokument VAT I - 00311 02 2016 FV H.pdf
[2016-02-18 12:55:05 | 000,090,479 | ---- | C] () -- C:\Users\Jarek\Desktop\evan proforma1.pdf
[2016-02-18 12:51:54 | 000,090,443 | ---- | C] () -- C:\Users\Jarek\Desktop\evan proforma.pdf
[2016-02-17 14:49:17 | 000,026,657 | ---- | C] () -- C:\Users\Jarek\Desktop\evan.pdf
[2016-02-17 10:06:53 | 000,026,961 | ---- | C] () -- C:\Users\Jarek\Desktop\introl.pdf
[2016-02-17 09:38:28 | 000,088,897 | ---- | C] () -- C:\Users\Jarek\Desktop\chsm.pdf
[2016-02-16 11:33:13 | 000,021,709 | ---- | C] () -- C:\Users\Jarek\Desktop\rury.pdf
[2016-02-15 14:08:58 | 000,086,655 | ---- | C] () -- C:\Users\Jarek\Desktop\kryza.pdf
[2016-02-15 13:25:43 | 000,045,959 | ---- | C] () -- C:\Users\Jarek\Desktop\lesniak stryzowice.pdf
[2016-02-15 11:02:01 | 000,026,784 | ---- | C] () -- C:\Users\Jarek\Desktop\carbo2.pdf
[2016-02-15 10:59:33 | 000,028,918 | ---- | C] () -- C:\Users\Jarek\Desktop\carbo1.pdf
[2016-02-11 13:00:24 | 000,031,511 | ---- | C] () -- C:\Users\Jarek\Desktop\sroka.pdf
[2016-02-11 11:39:18 | 000,021,461 | ---- | C] () -- C:\Users\Jarek\Desktop\tech 11,02.pdf
[2016-02-11 09:44:53 | 000,023,668 | ---- | C] () -- C:\Users\Jarek\Desktop\marbud grzejniki.pdf
[2016-02-10 12:26:44 | 000,028,320 | ---- | C] () -- C:\Users\Jarek\Desktop\pewima oc.pdf
[2016-02-10 11:25:05 | 000,025,780 | ---- | C] () -- C:\Users\Jarek\Desktop\sr pcv.pdf
[2016-02-09 13:05:06 | 000,022,574 | ---- | C] () -- C:\Users\Jarek\Desktop\zebiec11.pdf
[2016-02-09 12:31:10 | 000,032,047 | ---- | C] () -- C:\Users\Jarek\Desktop\storen.pdf
[2016-02-09 12:07:44 | 000,110,209 | ---- | C] () -- C:\Users\Jarek\Desktop\wiek styczeń.pdf
[2016-02-08 14:07:06 | 000,087,989 | ---- | C] () -- C:\Users\Jarek\Desktop\abs2.pdf
[2016-02-08 12:23:50 | 000,095,951 | ---- | C] () -- C:\Users\Jarek\Desktop\domb.pdf
[2016-02-08 11:01:58 | 000,092,672 | ---- | C] () -- C:\Users\Jarek\Desktop\abs.pdf
[2016-02-08 10:57:28 | 000,035,794 | ---- | C] () -- C:\Users\Jarek\Desktop\budamar1.pdf
[2016-02-08 10:53:27 | 000,035,794 | ---- | C] () -- C:\Users\Jarek\Desktop\budamar.pdf
[2016-02-05 14:38:16 | 000,085,199 | ---- | C] () -- C:\Users\Jarek\Desktop\nieb.pdf
[2016-02-05 14:25:32 | 000,023,584 | ---- | C] () -- C:\Users\Jarek\Desktop\plstim.pdf
[2016-02-04 16:22:13 | 000,086,775 | ---- | C] () -- C:\Users\Jarek\Desktop\flow.pdf
[2016-02-03 14:10:34 | 000,928,676 | ---- | C] () -- C:\Users\Jarek\Desktop\smartplus.pdf
[2016-02-03 12:23:27 | 000,022,455 | ---- | C] () -- C:\Users\Jarek\Desktop\lechar.pdf
[2016-02-03 11:56:16 | 000,031,008 | ---- | C] () -- C:\Users\Jarek\Desktop\Adam K.pdf
[2016-02-03 09:27:18 | 000,086,175 | ---- | C] () -- C:\Users\Jarek\Desktop\12..pdf
[2016-02-03 09:26:59 | 000,084,975 | ---- | C] () -- C:\Users\Jarek\Desktop\12.pdf
[2016-02-02 17:11:51 | 000,085,375 | ---- | C] () -- C:\Users\Jarek\Desktop\pierwsza1.pdf
[2016-02-02 15:39:36 | 000,085,608 | ---- | C] () -- C:\Users\Jarek\Desktop\pierwsza.pdf
[2016-02-02 15:34:17 | 000,094,939 | ---- | C] () -- C:\Users\Jarek\Desktop\DHL24.pdf
[2016-02-01 16:10:16 | 000,088,476 | ---- | C] () -- C:\Users\Jarek\Desktop\krzychu.pdf
[2016-02-01 16:03:22 | 000,024,317 | ---- | C] () -- C:\Users\Jarek\Desktop\ele.pdf
[2016-02-01 16:02:23 | 000,024,317 | ---- | C] () -- C:\Users\Jarek\Desktop\elekrtownia.pdf
[2016-02-01 15:59:25 | 000,024,334 | ---- | C] () -- C:\Users\Jarek\Desktop\elektrownia .pdf
[2016-02-01 15:37:13 | 000,087,267 | ---- | C] () -- C:\Users\Jarek\Desktop\instyt.pdf
[2016-01-28 11:42:55 | 000,086,433 | ---- | C] () -- C:\Users\Jarek\Desktop\Dokument VAT I - 00467 01 2016 FV H.pdf
[2016-01-27 16:30:47 | 000,025,840 | ---- | C] () -- C:\Users\Jarek\Desktop\marko kom5.pdf
[2016-01-27 16:27:47 | 000,024,858 | ---- | C] () -- C:\Users\Jarek\Desktop\marko 4.pdf
[2016-01-27 16:24:24 | 000,026,061 | ---- | C] () -- C:\Users\Jarek\Desktop\marko kom3.pdf
[2016-01-27 16:19:43 | 000,025,662 | ---- | C] () -- C:\Users\Jarek\Desktop\marko kom2.pdf
[2016-01-27 16:16:07 | 000,025,560 | ---- | C] () -- C:\Users\Jarek\Desktop\Marko kom1.pdf
[2016-01-27 14:54:11 | 000,027,367 | ---- | C] () -- C:\Users\Jarek\Desktop\kamsoft 1.pdf
[2016-01-27 14:36:41 | 000,085,077 | ---- | C] () -- C:\Users\Jarek\Desktop\tasta.pdf
[2016-01-27 10:58:01 | 000,084,732 | ---- | C] () -- C:\Users\Jarek\Desktop\lgm.pdf
[2016-01-26 12:47:29 | 000,029,085 | ---- | C] () -- C:\Users\Jarek\Desktop\elektr bet.pdf
[2016-01-26 10:21:38 | 000,085,462 | ---- | C] () -- C:\Users\Jarek\Desktop\niebieska.pdf
[2016-01-25 14:29:30 | 000,024,444 | ---- | C] () -- C:\Users\Jarek\Desktop\kam.pdf
[2016-01-25 11:15:25 | 000,026,577 | ---- | C] () -- C:\Users\Jarek\Desktop\sr purmo.pdf
[2016-01-25 09:49:00 | 000,028,466 | ---- | C] () -- C:\Users\Jarek\Desktop\pbpw.pdf
[2015-12-15 07:02:49 | 000,004,688 | ---- | C] () -- C:\Windows\System32\Jupdafexiv.ini
[2015-12-15 07:02:49 | 000,002,408 | ---- | C] () -- C:\Windows\System32\JupdafexivOff.ini
[2015-12-14 11:11:46 | 009,545,216 | ---- | C] () -- C:\Users\Jarek\AppData\Roaming\agent.dat
[2015-12-14 11:11:46 | 000,058,272 | ---- | C] () -- C:\Users\Jarek\AppData\Roaming\Config.xml
[2015-12-14 11:11:46 | 000,017,920 | ---- | C] () -- C:\Users\Jarek\AppData\Roaming\Main.dat
[2015-12-14 11:11:46 | 000,005,568 | ---- | C] () -- C:\Users\Jarek\AppData\Roaming\md.xml
[2015-12-14 11:11:46 | 000,004,134 | ---- | C] () -- C:\Users\Jarek\AppData\Roaming\pic1.jpg
[2015-12-14 11:11:46 | 000,004,134 | ---- | C] () -- C:\Users\Jarek\AppData\Roaming\pic.jpg
[2015-07-30 05:52:08 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2015-07-29 09:54:14 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2015-07-28 15:38:10 | 000,001,205 | ---- | C] () -- C:\Windows\Amhm.INI
[2015-07-28 15:36:12 | 000,000,078 | R--- | C] () -- C:\Windows\bti.ini
[2015-07-28 15:30:59 | 000,000,259 | ---- | C] () -- C:\Windows\ODBCINST.INI
 
[color=#E56717]========== ZeroAccess Check ==========[/color]
 
[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016-01-22 07:05:58 | 012,877,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

Re: PROBLEM Z RUNDLL

22 Lut 2016, 16:43

Podaj komplet logów z FRST -> otl-gmer-i-inne-poradnik-t13967-15.html#p164179

i spyhunter'em

Od tego dziadostwa radzę trzymać się z daleka.

Re: PROBLEM Z RUNDLL

23 Lut 2016, 11:23

Logi z FRST

FRST.txt - http://wklej.to/n2UCm
addition.txt - http://wklej.to/aLaSp
shortcut.txt - http://wklej.to/hj2EH

Re: PROBLEM Z RUNDLL

23 Lut 2016, 20:03

Wklej do notatnika:
Task: {46257FC4-F018-4481-BFF6-B86EADB74826} - System32\Tasks\Bubble Comp => Rundll32.exe "C:\Users\Jarek\AppData\Local\Bubble Comp\{4B6D9488-C2D1-11A9-C91F-6CC5F9AD92BE}\BubbleComp.dll",#1 <==== UWAGA
Task: {48932456-719E-45F6-8639-DE330F7B387B} - \SmartWeb Upgrade Trigger Task -> Brak pliku <==== UWAGA
C:\Users\Jarek\AppData\Local\Bubble Comp
Task: {9C21D007-3A3A-48B3-858E-ACEA9AA8354F} - System32\Tasks\{26376799-CCB5-40B4-A2E6-A122C0ED53F5} => pcalua.exe -a C:\Users\Jarek\AppData\Roaming\yoursearching\UninstallManager.exe -c -ptid=face
C:\Users\Jarek\AppData\Roaming\yoursearching
Task: {B1AD48C0-63CD-4448-AFC3-D93BEC797D24} - System32\Tasks\Suigzoa => C:\PROGRA~1\GROOVE~1\Rhkab.bat
C:\PROGRA~1\GROOVE~1
Task: {E91A105C-24AA-4DCB-9C6E-922C1ACF6C07} - System32\Tasks\Bubble Comp2 => Rundll32.exe "C:\Users\Jarek\AppData\Local\Bubble Comp\{4B6D9488-C2D1-11A9-C91F-6CC5F9AD92BE}\oirltn.dll",#1 <==== UWAGA
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [253672 2011-01-07] (Sun Microsystems, Inc.)
CHR Extension: (AdThwart Legacy) - C:\Users\Jarek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpcpblpdkddoicgechaickbldbieccko [2015-12-15]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
2016-02-22 12:10 - 2016-02-22 12:12 - 00000000 ___HD C:\b1xjOKJzX4hJCkfk
2016-02-22 11:59 - 2016-02-22 11:59 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-12-15 13:14 - 2015-12-15 13:47 - 00000000 ____D C:\AdwCleaner
Task: {AE30345B-B0AB-45BA-9B05-CB217507CC72} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe

HOSTS:
EmptyTemp:

Plik zapisujesz pod nazwą fixlist.txt i umieszczasz obok FRST. Uruchom FRST i kliknij w nim Napraw. Powstanie plik fixlog.txt, który podajesz na forum.
Następnie podaj nowe logi z FRST.
Wyślij odpowiedź