Task: {1EDA6819-E617-484D-80E8-F65C07E8F520} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{8412ADCC-3593-43A1-BC9F-2DCB1355E0AC}.exe
Task: {3363DE40-1F76-459F-9C80-FD742D5F9A5A} - System32\Tasks\BobyLyrics Update => C:\Program Files (x86)\ver3BobyLyrics\z4BobyLyricsh21.exe [2014-08-04] () <==== ATTENTION
Task: {625195E3-E546-4F9C-ACC6-6C28E4073538} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1132783732-2883385480-2822838315-1000UA => C:\Users\Piotr\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-11] (Facebook Inc.)
Task: {742DBFCC-86E7-43F3-91F0-CB4C40BFEC26} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION
Task: {84133496-27A2-4E47-BA4A-20DC37FDEA6A} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{D79E2905-A264-4062-A17E-3F8D58CAD175}.exe
Task: {CB191CC9-F02E-4C76-AF61-F99300F60919} - System32\Tasks\SPBIW_UpdateTask_Time_323436343837303339332d3437415a556c2a3223346c41 => Wscript.exe //B "C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe /invoke /f:check_services /l:0 <==== ATTENTION
Task: {DF05E0B5-48D4-4FC5-95AC-19720DE7D119} - System32\Tasks\BobyLyrics_wd => C:\Program Files (x86)\ver3BobyLyrics\Q3BobyLyricsV.exe [2014-08-04] () <==== ATTENTION
Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove No Task File <==== ATTENTION
Task: {FADFC5AC-A90B-4076-B585-00B852E0A6FA} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1132783732-2883385480-2822838315-1000Core => C:\Users\Piotr\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-11] (Facebook Inc.)
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{D79E2905-A264-4062-A17E-3F8D58CAD175}.exe <==== ATTENTION
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{8412ADCC-3593-43A1-BC9F-2DCB1355E0AC}.exe <==== ATTENTION
Task: C:\Windows\Tasks\BobyLyrics Update.job => C:\Program Files (x86)\ver3BobyLyrics\z4BobyLyricsh21.exe <==== ATTENTION
Task: C:\Windows\Tasks\BobyLyrics_wd.job => C:\Program Files (x86)\ver3BobyLyrics\Q3BobyLyricsV.exe <==== ATTENTION
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1132783732-2883385480-2822838315-1000Core.job => C:\Users\Piotr\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1132783732-2883385480-2822838315-1000UA.job => C:\Users\Piotr\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKLM-x32\...\Run: [mbot_pl_173] => [X]
HKU\S-1-5-21-1132783732-2883385480-2822838315-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Piotr\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1132783732-2883385480-2822838315-1000\...\Policies\Explorer: []
HKU\S-1-5-21-1132783732-2883385480-2822838315-1000\...\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-1132783732-2883385480-2822838315-1000\...\MountPoints2: {a6f45052-2cd7-11e2-8bfb-e006e6d846fe} - F:\sldim\sldim.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-1132783732-2883385480-2822838315-1000] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-1132783732-2883385480-2822838315-1000] => http=127.0.0.1:13832;https=127.0.0.1:13832
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.interia.pl/#utm_source=instalki&utm_medium=installer&utm_campaign=instalki
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://www.interia.pl/#utm_source=instalki&utm_medium=installer&utm_campaign=instalki
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1132783732-2883385480-2822838315-1000 -> {4ED9195F-EE3D-463C-8110-550D96C0EA4D} URL =
BHO-x32: Winamp Toolbar Loader -> {4accc990-3dc7-4456-a734-5cb4b610a7f5} -> C:\Program Files (x86)\Winamp Toolbar\winamppltb.dll No File
BHO-x32: BobyLyrics -> {6C4B4C4D-0634-A2B0-D5D8-923C72E27D30} -> C:\Program Files (x86)\ver3BobyLyrics\175.dll ()
Toolbar: HKLM-x32 - Winamp Toolbar - {a0b1221c-a3ff-4f7c-a393-dc63af5301e9} - C:\Program Files (x86)\Winamp Toolbar\winamppltb.dll No File
Toolbar: HKU\S-1-5-21-1132783732-2883385480-2822838315-1000 -> No Name - {A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} - No File
FF HKLM-x32\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - C:\Program Files (x86)\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - C:\Program Files (x86)\Fiddler2\FiddlerHook [2013-08-07]
FF HKU\S-1-5-21-1132783732-2883385480-2822838315-1000\...\Firefox\Extensions: [{CC60CF5B-61BD-F8C6-D2E2-8C216EA2A5B2}] - C:\Program Files (x86)\ver3BobyLyrics\175.xpi
FF Extension: BobyLyrics - C:\Program Files (x86)\ver3BobyLyrics\175.xpi [2014-08-04]
OPR Extension: (Radio Canyon) - C:\Users\Piotr\AppData\Roaming\Opera Software\Opera Stable\Extensions\bikofacodmhdpkfdeeocponfcgjcdfbk [2014-09-25]
R2 BobyLyrics; C:\Program Files (x86)\ver3BobyLyrics\b1BobyLyricsAn175.exe [162304 2014-08-04] () [File not signed]
S2 SPDRIVER_1488.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1488.0.0.0\jsdrv.sys [X]
2015-02-26 11:36 - 2014-04-15 14:55 - 00000000 ____D () C:\AdwCleaner
EmptyTemp: