Task: {B4CEEEDA-0F95-485C-8197-052FEC710C83} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION
Task: C:\windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-1.job => C:\Program Files (x86)\PHD-V1.4\PHD-V1.4-codedownloader.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-11.job => C:\Program Files (x86)\PHD-V1.4\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-11.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-2.job => C:\Program Files (x86)\PHD-V1.4\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-2.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-3.job => C:\Program Files (x86)\PHD-V1.4\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-3.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-4.job => C:\Program Files (x86)\PHD-V1.4\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-4.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-5.job => C:\Program Files (x86)\PHD-V1.4\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-5.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-5_user.job => C:\Program Files (x86)\PHD-V1.4\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-5.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-6.job => C:\Program Files (x86)\PHD-V1.4\PHD-V1.4-novainstaller.exe <==== ATTENTION
Task: C:\windows\Tasks\e45b0a1a-9ba8-49b2-9360-d03dce7d97e5-7.job => C:\Program Files (x86)\PHD-V1.4\PHD-V1.4-nova.exe <==== ATTENTION
Task: C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-1045163953-2008573954-4170960092-1000\...\Run: [Akamai NetSession Interface] => C:\Users\EWELINA\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1045163953-2008573954-4170960092-1000\...\MountPoints2: {37e71cf2-e1a1-11e3-8826-e840f2c4021e} - C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1045163953-2008573954-4170960092-1000\...\MountPoints2: {ac16487a-0d9f-11e4-a067-446d57001eca} - H:\setup.exe
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0249D3F3-F125-4EE5-A698-2F4620B4FF6F} URL =
http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0CyEtDtBtC0EzyyByCtAtN0D0Tzu0CtBtAzytN1L2XzutBtFtCtFtCtFtAtCtB&cr=44183356
SearchScopes: HKLM-x32 - {0249D3F3-F125-4EE5-A698-2F4620B4FF6F} URL =
http://search.certified-toolbar.com?si=41460&bs=true&tid=592&q={searchTerms}
BHO: No Name -> {04FA341E-B989-813A-D8BA-E2F9328E5E05} -> No File
BHO: No Name -> {11111111-1111-1111-1111-110511831162} -> No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () [File not signed]
S3 osppsvc; "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S1 orstzflq; \??\C:\windows\system32\drivers\orstzflq.sys [X]
S3 TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [X]
2014-10-06 21:53 - 2014-10-06 22:08 - 00000000 ____D () C:\AdwCleaner
2014-10-06 19:41 - 2014-10-06 21:51 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-10-06 19:41 - 2014-10-06 19:41 - 00000000 ____D () C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-06 19:41 - 2014-10-06 19:41 - 00000000 ____D () C:\sh4ldr
EmptyTemp: