HKU\S-1-5-21-2978983933-760802533-2435125460-1001…\Policies\system: [] 0
ProxyServer: http=127.0.0.1:8555;https=127.0.0.1:8555
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {504DF7E7-923A-4910-95BF-3BB377DC7C38} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN67468363610668286&UM=1
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
FF Extension: Movies Toolbar (Dist. by Bandoo Media, Inc.) - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\2e9co3sy.default\Extensions{d1dac034-9fd9-4c13-a388-d2e10e57707f} [2014-03-28]
FF Extension: Start Page - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\2e9co3sy.default\Extensions{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi [2014-01-10]
FF Extension: BonanzaDeals - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\2e9co3sy.default\Extensions{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi [2013-12-18]
FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com [2014-05-14]
FF HKLM-x32…\Firefox\Extensions: [quiknowledge@quiknowledge.com] - C:\Program Files (x86)\Mozilla Firefox\extensions\quiknowledge@quiknowledge.com
FF Extension: Ask New Tabs - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\2e9co3sy.default\Extensions{2FD73609-F02D-3849-D765-5F8F93ECC348} [2014-05-19]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj [2013-11-25]
CHR Extension: (DealPly UK) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\hggpkhijoeadmdfmlbdepfbngmhaldci [2013-08-29]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj [2013-11-25]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo [2013-08-29]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfilpkikcipkfjgnfehdomcnpfpipnha [2013-11-18]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk [2013-11-25]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\onmmfaeddjmhcdnmkipjljbpmjimkilb [2013-11-18]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff [2013-12-14]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk [2013-08-20]
CHR Extension: (No Name) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp [2013-11-25]
CHR HKLM-x32…\Chrome\Extension: [hggpkhijoeadmdfmlbdepfbngmhaldci] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-11-25]
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software)
S3 bxyxepzn; C:\Windows\System32\Drivers\bxyxepzn.sys [423240 2014-05-23] (AVAST Software)
S3 lvifangk; C:\Windows\System32\Drivers\lvifangk.sys [423240 2014-05-22] (AVAST Software)
S3 rtjoiwpy; C:\Windows\System32\Drivers\rtjoiwpy.sys [423240 2014-05-22] (AVAST Software)
S3 waxghbka; C:\Windows\System32\Drivers\waxghbka.sys [423240 2014-05-21] (AVAST Software)
S3 btmaux; system32\DRIVERS\btmaux.sys [X]
C:\Windows\System32\Drivers\aswKbd.sys
C:\Windows\System32\Drivers\bxyxepzn.sys
C:\Windows\System32\Drivers\lvifangk.sys
C:\Windows\System32\Drivers\rtjoiwpy.sys
C:\Windows\System32\Drivers\waxghbka.sys
C:\AdwCleaner
C:\ProgramData\ESET
C:\ProgramData\afb69e2f0ff54cd2
C:\Users\HP\AppData\Local\Temp*.exe
C:\Users\HP\AppData\Local\Temp*.dll
Task: {1D7E8F29-5E00-4270-812A-88B2B4A55396} - \RunAsStdUser No Task File <==== ATTENTION
Task: {38A88590-E1D5-478C-B5E4-4B116815EB75} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
Task: {3BEC39B8-261C-4C77-847A-A57C88E6E35B} - \BrowserProtect No Task File <==== ATTENTION
Task: {558AB17D-17D4-4778-9767-C1BB4023FCE5} - \Hoolapp For Android No Task File <==== ATTENTION
Task: {740014E7-ADA9-4206-9C90-C46016DDFAA9} - \EPUpdater No Task File <==== ATTENTION
Task: {90CE2E00-DFCC-4138-96E8-8EBF2ED320F7} - \SpeedUpMyPC No Task File <==== ATTENTION
Task: {936F837F-B12A-408D-B470-A65F7D7E7AC6} - System32\Tasks{2879EF41-165E-4F42-8B62-40271AF1E352} => c:\program files (x86)\opera\opera.exe [2013-08-10] (Opera Software)
Task: {A1379743-DB15-46E3-A931-0C926EAD5AAA} - System32\Tasks{E2CE923B-E760-4D5A-9F89-EB41FDF2F306} => c:\program files (x86)\opera\opera.exe [2013-08-10] (Opera Software)
Task: {B4AEB465-BD86-43CC-B836-8E7715A25FF7} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
Task: {CFAF3F84-0342-40E7-90EA-EA78748E073D} - \Desk 365 RunAsStdUser No Task File <==== ATTENTION
Task: {F6F8F208-57EC-4BC4-9CF1-4B0B3E4EB7A4} - \spmonitor No Task File <==== ATTENTION
Task: {F98BA6D3-12F1-4A52-BB50-AECE33F46C89} - \Hoolapp Init No Task File <==== ATTENTION
Task: C:\Windows\Tasks\WOT N.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT T.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT W1.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT W2.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WFRI1.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WMON1.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WTHUR1.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WTUE1.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WW1.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WW2.job => C:\Program Files\Internet Explorer\iexplore.exe
Task: C:\Windows\Tasks\WOT WWED1.job => C:\Program Files\Internet Explorer\iexplore.exe
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\BackgroundContainer” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\Hoolapp Android” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\mobilegeni daemon” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\SearchSettings” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\BrowserProtect” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\desksvc” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SbieSvc” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\vToolbarUpdater15.3.0” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^HP^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lollipop.lnk” /f
Reg: reg delete “HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk” /f
C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
C:\Windows\pss\lollipop.lnk.Startup
Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.
Kliknij Scan i pokaż nowy raport z FRST bez Addition.