

Logi z FRST:
http://wklej.org/id/1498508/
http://wklej.org/id/1498509/
HKU\S-1-5-21-4085879218-2218372132-1531984322-1000\...\Run: [CMD] => cmd.exe /c start http://adverttraff.org && exit <===== ATTENTION
HKU\S-1-5-21-4085879218-2218372132-1531984322-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CMD] => cmd.exe /c start http://adverttraff.org && exit <===== ATTENTION
HKU\S-1-5-21-4085879218-2218372132-1531984322-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [minert] => C:\Users\pc\AppData\Roaming\minert\nircmd.exe
C:\Users\pc\AppData\Roaming\minert\nircmd.exe
C:\Users\pc\AppData\Roaming\minert
Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\pc\AppData\Local\41\a18467.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
C:\Program Files (x86)\AnyProtectEx
C:\Users\pc\AppData\Local\41
Task: C:\Windows\Tasks\Update Service YourFileDownloader.job => C:\Program Files (x86)\YourFileDownloaderUpdater\YourFileDownloaderUpdater.exe <==== ATTENTION
C:\Program Files (x86)\YourFileDownloaderUpdater
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=1373052757
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=1380282512
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=0
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=0
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=0
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=0
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=1380282512&type=default&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=ST3500320AS_9QM08SMBXXXX9QM08SMB&ts=1380282512&type=default&q={searchTerms}
R1 {572f484b-455f-44b0-9d6a-da3ad2071365}Gw64; C:\Windows\System32\drivers\{572f484b-455f-44b0-9d6a-da3ad2071365}Gw64.sys
C:\Users\pc\AppData\Roaming\Origin\update.vbe
EmptyTemp:
2014-09-29 23:07 - 2009-07-14 04:34 - 80740352 _____ () C:\Windows\system32\config\SOFTWARE.gu.bak
2014-09-29 23:07 - 2009-07-14 04:34 - 18350080 _____ () C:\Windows\system32\config\SYSTEM.gu.bak
2014-09-29 23:06 - 2014-05-06 19:19 - 00028672 _____ () C:\Windows\system32\config\SYSTEM.gu
HKU\S-1-5-21-4085879218-2218372132-1531984322-1000\...\Run: [minert] => "C:\Users\pc\AppData\Roaming\minert\nircmd.exe" exec hide "C:\Users\pc\AppData\Roaming\minert\start.bat"
C:\Users\pc\AppData\Roaming\minert\start.bat
C:\Users\pc\AppData\Roaming\minert\nircmd.exe
C:\Users\pc\AppData\Roaming\minert
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
C:\Windows\system32\config\DEFAULT.gu
C:\Windows\system32\config\SECURITY.gu
C:\Windows\system32\config\SAM.gu
C:\Windows\system32\config\SOFTWARE.gu.bak
C:\Windows\system32\config\SYSTEM.gu.bak
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 18 gości