UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12856936 2011-09-09] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKU\S-1-5-21-3723663294-3655808551-748276165-1000\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\Lupa Jan\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
C:\Users\Lupa Jan\AppData\Roaming\newnext.me
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx []
CHR HKLM-x32\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\LUPAJA~1\AppData\Local\Temp\crx8686.tmp []
CHR HKLM-x32\...\Chrome\Extension: [bildoibdboopgomcbiplincneeicgipj] - C:\Program Files (x86)\StartSearch plugin\startsplg.crx []
CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx []
CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx []
C:\Program Files (x86)\StartSearch plugin
C:\Program Files (x86)\vShare.tv plugin
C:\Program Files\IB Updater
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox
S2 SetupARService; "C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe" [X]
S3 dump_wmimmc; \??\D:\NewEliteSRO\GameGuard\dump_wmimmc.sys [X]
S3 GGSAFERDriver; \??\D:\Garena Plus\Room\safedrv.sys [X]
S3 injectDLL; \??\C:\Users\Lupa Jan\Desktop\xqz ring0 by dedi\injectDLL.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S4 NVHDA; system32\drivers\nvhda64v.sys [X]
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
S3 Lavasoft Kernexplorer; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [X]
2014-11-15 09:58 - 2014-11-15 09:58 - 00055384 _____ (Sunbelt Software) C:\Windows\system32\Drivers\SBREDrv.sys
2014-11-15 09:47 - 2014-11-15 09:58 - 00003622 _____ () C:\Windows\System32\Tasks\Ad-Aware Update (Weekly)
2014-11-15 09:47 - 2014-11-15 09:47 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-11-15 09:47 - 2014-11-15 09:47 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
C:\Windows\Tasks\Ad-Aware Update (Weekly).job
DeleteQuarantine:
Zarejestrowani użytkownicy: Bing [Bot]