UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.75 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.75 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.75 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
HKLM-x32\...\Run: [mpck_en_005030299] => [X]
HKLM-x32\...\Run: [BCSSync] => D:\Programy\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-681492101-2902284270-3531814063-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
CHR HomePage: Default hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=F6DB18B58530815FCB9978AA02599349&v=20160415&ts=AHEqA3QtC3EtA0..
CHR StartupUrls: Default "hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=F6DB18B58530815FCB9978AA02599349&v=20160415&ts=AHEqA3QtC3EtA0.."
R1 {7f21ea28-929b-4f19-b057-483d53f11b0d}Gw64; C:\Windows\System32\drivers\{7f21ea28-929b-4f19-b057-483d53f11b0d}Gw64.sys [48784 2015-03-06] (StdLib)
R1 {a55667f1-a319-4629-a8b6-a68d9d3313ee}Gw64; C:\Windows\System32\drivers\{a55667f1-a319-4629-a8b6-a68d9d3313ee}Gw64.sys [48784 2015-03-06] (StdLib)
S3 atidgllk; \??\C:\Program Files (x86)\Gigabyte\ET5Pro\atidgllk.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2016-04-16 20:04 - 2016-04-16 20:04 - 00020270 _____ C:\ComboFix.txt
2016-04-16 19:57 - 2016-04-16 20:04 - 00000000 ____D C:\Qoobox
2016-04-16 19:57 - 2016-04-16 20:03 - 00000000 ____D C:\Windows\erdnt
2016-04-16 19:57 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2016-04-16 19:57 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2016-04-16 19:57 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-04-16 19:57 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-04-16 19:57 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-04-16 19:57 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2016-04-16 19:57 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2016-04-16 19:57 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2016-04-16 19:56 - 2016-04-16 19:57 - 05660069 ____R (Swearware) C:\Users\Damdan\Downloads\ComboFix.exe
2016-04-16 19:53 - 2016-04-16 19:53 - 00001184 _____ C:\Users\Damdan\Desktop\CFScript.txt
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.75 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.87 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
Zarejestrowani użytkownicy: Bing [Bot]