UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
FRST extras
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2013-12-19] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039240 2013-05-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2014-02-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-2906923548-928406369-4133591688-1000\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [3510704 2014-07-23] (ALLPlayer Group Ltd.)
HKU\S-1-5-21-2906923548-928406369-4133591688-1000\...\Run: [CubeDesktop] => [X]
HKU\S-1-5-21-2906923548-928406369-4133591688-1000\...\Run: [tsiVideo] => C:\Windows\SysWOW64\rundll32.exe C:\Users\Leo\AppData\Local\Temp\\mdi364.dll,runme <===== ATTENTION
C:\Users\Leo\AppData\Local\Temp\\mdi364.dll
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1407946145&from=sof&uid=SamsungXSSDX840XEVOX120GB_S1D5NSBDA30545J&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1407946145&from=sof&uid=SamsungXSSDX840XEVOX120GB_S1D5NSBDA30545J&q={searchTerms}
CHR dev: Chrome dev build detected! <======= ATTENTION
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
Task: {DD759B3A-206A-4209-9E05-9C249420E5DD} - System32\Tasks\GoforFilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION
C:\Program Files (x86)\GoforFiles
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
Task: C:\Windows\Tasks\SpyHunter4.job => C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe
Task: {4F016D44-DDB5-4593-8DA4-058E9212367E} - System32\Tasks\SpyHunter4 => C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe
S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
2014-10-20 21:20 - 2014-10-20 23:11 - 00000000 ____D () C:\ProgramData\GoSavve
2014-10-20 21:20 - 2014-10-20 22:46 - 00000000 ____D () C:\ProgramData\5de12486ec9c508d
2014-10-20 21:20 - 2014-10-20 22:45 - 00000000 ____D () C:\Program Files (x86)\GoSavve
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Leo\AppData\Local\Torch
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Leo\AppData\Local\Comodo
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Leo\AppData\Local\Chromatic Browser
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Gość\AppData\Local\Torch
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Gość\AppData\Local\Google
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Gość\AppData\Local\Comodo
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Gość\AppData\Local\Chromatic Browser
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-10-20 21:20 - 2014-10-20 21:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników