
FRST.txt: http://wklej.org/id/1923342/
Addition.txt: http://wklej.org/id/1923344/
Shortcut.txt: http://wklej.org/id/1923345/
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.245 - SurfRight B.V.)
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-21-2917954556-79250000-1762670911-1000\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HitmanPro37
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HitmanPro 3.7
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyHunter 4.21.10.4585
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HitmanPro 3.7
Task: {479D0D6C-0A85-4EF5-8902-6E7C97AD0C80} - \Java Platform SE Auto Updater -> Brak pliku <==== UWAGA
Task: {860B3189-5239-4CBF-AC67-6F3301C254BF} - \GridinSoft Anti-Malware -> Brak pliku <==== UWAGA
Task: {F164E90D-A231-42C8-8D1A-CAE81EF16B08} - \SpyHunter4Startup -> Brak pliku <==== UWAGA
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-21-2917954556-79250000-1762670911-1000\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
BHO: Brak nazwy -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> Brak pliku
BHO-x32: Brak nazwy -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> Brak pliku
BHO-x32: Brak nazwy -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> Brak pliku
Toolbar: HKLM - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - Brak pliku
Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - Brak pliku
Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - Brak pliku
S2 hmpalertsvc; "(null)" /service [X]
S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]
S2 EncDisk; Brak ImagePath
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-11-13] ()
S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys [22704 2015-12-19] ()
R3 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [198216 2015-09-26] (SurfRight B.V.)
S3 hmpnet; C:\Windows\system32\drivers\hmpnet.sys [75640 2015-09-26] (SurfRight B.V.)
C:\Windows\system32\drivers\hmpalert.sys
C:\Windows\system32\drivers\hmpnet.sys
S1 epp64; \??\C:\PROGRAM FILES (X86)\EMSISOFT INTERNET SECURITY\epp64.sys [X]
S3 esgiguard; \??\C:\Program Files (x86)\SpyHunter\esgiguard.sys [X]
S3 icsak; \??\C:\Program Files (x86)\CheckPoint\AKL\ak\icsak.sys [X]
S3 mdareDriver_60; \??\C:\Users\user\AppData\Local\Temp\FCPreScan\mdare64_60.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
C:\Users\user\AppData\Roaming\Enigma Software Group
C:\Users\Public\Desktop\SpyHunter4.lnk
C:\Program Files\SpyHunter
C:\Users\user\Start Menu\Programs\SpyHunter\SpyHunter Emergency Startup.lnk
C:\Users\user\Start Menu\Programs\SpyHunter
C:\Users\user\AppData\Roaming\Enigma Software Group
C:\Program Files\HitmanPro
C:\Users\Public\Desktop\HitmanPro.lnk
EmptyTemp:
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyHunter 4.21.10.4585
Task: {479D0D6C-0A85-4EF5-8902-6E7C97AD0C80} - \Java Platform SE Auto Updater -> Brak pliku <==== UWAGA
Task: {860B3189-5239-4CBF-AC67-6F3301C254BF} - \GridinSoft Anti-Malware -> Brak pliku <==== UWAGA
Task: {F164E90D-A231-42C8-8D1A-CAE81EF16B08} - \SpyHunter4Startup -> Brak pliku <==== UWAGA
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-21-2917954556-79250000-1762670911-1000\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\system32\explorer.exe [2616320 2015-12-26] (Microsoft Corporation) <==== UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
BHO: Brak nazwy -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> Brak pliku
BHO-x32: Brak nazwy -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> Brak pliku
BHO-x32: Brak nazwy -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> Brak pliku
Toolbar: HKLM - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - Brak pliku
Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - Brak pliku
Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - Brak pliku
S2 hmpalertsvc; "(null)" /service [X]
S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]
S2 EncDisk; Brak ImagePath
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-11-13] ()
S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys [22704 2015-12-19] ()
R3 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [198216 2015-09-26] (SurfRight B.V.)
S3 hmpnet; C:\Windows\system32\drivers\hmpnet.sys [75640 2015-09-26] (SurfRight B.V.)
C:\Windows\system32\drivers\hmpalert.sys
C:\Windows\system32\drivers\hmpnet.sys
S1 epp64; \??\C:\PROGRAM FILES (X86)\EMSISOFT INTERNET SECURITY\epp64.sys [X]
S3 esgiguard; \??\C:\Program Files (x86)\SpyHunter\esgiguard.sys [X]
S3 icsak; \??\C:\Program Files (x86)\CheckPoint\AKL\ak\icsak.sys [X]
S3 mdareDriver_60; \??\C:\Users\user\AppData\Local\Temp\FCPreScan\mdare64_60.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
C:\Users\user\AppData\Roaming\Enigma Software Group
C:\Users\Public\Desktop\SpyHunter4.lnk
C:\Program Files\SpyHunter
C:\Users\user\Start Menu\Programs\SpyHunter\SpyHunter Emergency Startup.lnk
C:\Users\user\Start Menu\Programs\SpyHunter
C:\Users\user\AppData\Roaming\Enigma Software Group
EmptyTemp:
chociaż w system32 wciąż został mi ten explorer.exe. Podobnie chyba dla temu że ja mam Windows 7 Home Premium 64bit.
C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości