CloseProcesses: CreateRestorePoint: EmptyTemp: HKLM-x32\...\Run: [] => [X] ProxyEnable: [.DEFAULT] => Proxy [funkcja włączona] ProxyServer: [.DEFAULT] => 127.0.0.1:1080 ProxyEnable: [S-1-5-19] => Proxy [funkcja włączona] ProxyServer: [S-1-5-19] => 127.0.0.1:1080 Tcpip\..\Interfaces\{8547FE26-4585-426A-8618-1AEF6BEE2D37}: [DhcpNameServer] 192.168.28.241 ManualProxies: 1127.0.0.1:1080 SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = SearchScopes: HKU\S-1-5-21-1921431682-952469367-1298936472-1000 -> {48F12AE4-A9F7-47d8-9C15-F14D94E1FC92} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=PROTOSV SearchScopes: HKU\S-1-5-21-1921431682-952469367-1298936472-1000 -> {8932C717-C3D5-4de5-8A01-5280570AB8A2} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A4107735745&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4107735745&q={searchTerms} SearchScopes: HKU\S-1-5-21-1921431682-952469367-1298936472-1000 -> {B3DD183E-B868-403f-AEF2-706DBF88644F} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=PROTOSV SearchScopes: HKU\S-1-5-21-1921431682-952469367-1298936472-1000 -> {C1B39C5D-75D5-4e82-B614-78B291B098BC} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A4107735745&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4107735745&q={searchTerms} SearchScopes: HKU\S-1-5-21-1921431682-952469367-1298936472-1000 -> {F464C6B0-0D21-4733-8F29-EDA3D1A51572} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLEP1&pc=SPLH BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll => Brak pliku Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll Brak pliku FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [Brak pliku] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\cfg [2015-07-20] <==== UWAGA S2 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll -> Brak pliku ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll -> Brak pliku ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll -> Brak pliku Task: {0D66A4A6-2819-4DB9-8DD8-016A408C65A2} - System32\Tasks\{AAE3FCC8-ED9F-4212-A14E-8984B2C8372C} => C:\Windows\system32\pcalua.exe -a E:\Setup.EXE -d E:\ Task: {0FAE9DA2-2277-4AEF-AB71-9102DE39CFD0} - System32\Tasks\{8A0F479C-5DCC-4E89-8A17-6AB10301265A} => C:\Windows\system32\pcalua.exe -a C:\Users\Sekretariat\Desktop\ABC\start.exe -d C:\Users\Sekretariat\Desktop\ABC Task: {16A74723-5BBD-4871-BE02-8EFA34FC0DE3} - System32\Tasks\{11D3BB8E-2CF9-4B48-B7D9-E35C870C3B11} => C:\Windows\system32\pcalua.exe -a E:\start.exe -d E:\ Task: {A24364AC-DDF7-42BB-A1B3-5F6EE3F81474} - System32\Tasks\{F7C99BBF-666E-40BB-B0DB-DCA713B9DF43} => C:\Windows\system32\pcalua.exe -a E:\start.exe -d E:\ Task: {EDA25343-E615-492A-8ED1-39688AD488EA} - System32\Tasks\{0CB3F02B-07FB-44DB-AC6D-3C1E70A653F6} => C:\Windows\system32\pcalua.exe -a C:\Users\Sekretariat\Downloads\Rejestracja_www.exe -d C:\Users\Sekretariat\Desktop Task: {F6210D6C-7E3F-407C-A95A-303FB56F94A4} - System32\Tasks\{E7357839-199C-4249-9E10-C907B8BA9257} => C:\Windows\system32\pcalua.exe -a E:\start.exe -d E:\ FirewallRules: [{95BDF800-D57C-488D-89AC-9A689A2F3AAC}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{5695B32A-FF16-4377-BD37-FA691D4DCE1C}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{317ECB5E-5EE4-4910-BC54-72D477E81E65}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{3CCEB7E2-94C5-406C-A69E-08368BAB4532}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{583692EE-DF64-4FB8-A1AD-8B68CF4B2A7E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{F78A5C46-6E9F-4400-8877-4A1C4D1E4E36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{1842C69A-E877-42D6-9158-FBB375CA7D80}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{EA2DCA15-2A94-4575-A204-7400A214BB14}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{5463FFF5-5740-4921-B947-F409E93791AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{1265A83B-82B1-4884-A182-85DEA49785BF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{6F9B740C-9DB1-408F-A4E5-D52F90AA5863}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{DCE17922-08A6-4D61-99BF-90DB13BD06BC}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{5B044079-9D94-4BC1-B19F-86BFE49CD5BB}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe C:\ProgramData\WindowsMangerProtect C:\Users\Sekretariat\AppData\Roaming\sweet-page RemoveProxy: