UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
Task: {3EAEF22B-A3C8-479B-85F0-397D5C89AD4A} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION
Task: {82AF2E68-DCC1-47D5-8D61-D11C4ACCBBE6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1334356865-621788237-3232505872-1000Core => C:\Users\Pawel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-09] (Facebook Inc.)
Task: {F229F8C5-7F70-43D6-A7B1-F1F242A1F2F3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1334356865-621788237-3232505872-1000UA => C:\Users\Pawel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-09] (Facebook Inc.)
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1334356865-621788237-3232505872-1000Core.job => C:\Users\Pawel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1334356865-621788237-3232505872-1000UA.job => C:\Users\Pawel\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKLM-x32\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
C:\Program Files (x86)\AVG Secure Search
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.)
HKU\S-1-5-21-1334356865-621788237-3232505872-1000\...\Run: [Facebook Update] => C:\Users\Pawel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-01-09] (Facebook Inc.)
HKU\S-1-5-21-1334356865-621788237-3232505872-1000\...\Run: [Yontoo Desktop] => C:\Users\Pawel\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-03-23] (Yontoo LLC)
C:\Users\Pawel\AppData\Roaming\Yontoo
AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll File Not Found
ShortcutTarget: McAfee Security Scan Plus.lnk C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
Startup: C:\Users\Pawel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
Startup: C:\Users\Pawel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119828&tt=190313_wo1&babsrc=HP_ss&mntrId=8010BC5FF448EB26
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?affID=119828&tt=190313_wo1&babsrc=HP_ss&mntrId=8010BC5FF448EB26
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119828&tt=190313_wo1&babsrc=SP_ss&mntrId=8010BC5FF448EB26
SearchScopes: HKCU - bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
BHO-x32: delta Helper Object {C1AF5FA5-852C-4C90-812E-A7F75E011D87} C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
C:\Program Files (x86)\Delta
BHO-x32: Yontoo {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
FF NewTab: hxxp://www.delta-search.com/?affID=119828&tt=190313_wo1&babsrc=NT_ss&mntrId=8010BC5FF448EB26
FF SearchEngineOrder.1: Delta Search
FF SearchPlugin: C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\oc0p1z56.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\oc0p1z56.default\searchplugins\BrowserProtect.xml
FF SearchPlugin: C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\oc0p1z56.default\searchplugins\delta.xml
FF Extension: Delta Toolbar - C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\oc0p1z56.default\Extensions\[email protected] [2013-03-26]
FF Extension: Yontoo - C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\oc0p1z56.default\Extensions\[email protected] [2013-03-26]
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Pawel\AppData\Roaming\BabSolution\CR\Delta.crx [2013-03-26]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 pxldapow; \??\C:\Users\Pawel\AppData\Local\Temp\pxldapow.sys [X]
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
S2 HPSLPSVC; C:\Users\Pawel\AppData\Local\Temp\7zS6F43\hpslpsvc64.dll [X]
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
Zarejestrowani użytkownicy: Bing [Bot]