@b4rt0 nie podczepiaj sie pod inne watki!
Fixlist.txt dla FRST:
Task: {0E73998A-3595-4802-94BB-BF1160BA1DA9} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA
Task: {1BF61AAB-8BD0-4231-8F58-B0BAB0BC7B59} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA
Task: {23371BC8-302C-42F2-8699-562C21E1C380} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
Task: {3B67D81E-A1B2-49FA-8BB2-39F25C511F92} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3543108252-308360466-193487373-1001UA => C:\Users\Bgoszczy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-10-22] (Facebook Inc.)
Task: {5DEFCA39-A01B-4C01-B7C5-6C9B5DA48418} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
Task: {5EA83DC4-9FB6-4414-8066-F8E6CD155F82} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
Task: {67701D76-3CA3-4867-8ACF-BF71A95AD504} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
Task: {6CD1AD99-07D1-49FC-874D-C85B6FFB86EC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
Task: {8001320F-C8EE-4205-843E-7471638BF3DD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA
Task: {8B9819DE-E115-4422-8996-4E74B3A6147A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA
Task: {9DF50979-2B43-47BE-8E96-A0D2DFF84675} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
Task: {A5C5651C-F96D-4EF7-8E38-C927E0740DFA} - System32\Tasks\{2EA0FEE2-04D0-4E44-ADBC-3E93C3A281DC} => Chrome.exe hxxp://ui.skype.com/ui/0/7.3.0.101/pl/abandoninstall?source=lightinstaller&page=tsBing
Task: {C2E811B6-1B2D-494E-965A-0D054D077156} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3543108252-308360466-193487373-1001Core => C:\Users\Bgoszczy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-10-22] (Facebook Inc.)
Task: {F0E9641F-9AF9-4F89-A51F-5C20DC4C1A00} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA
ShortcutWithArgument: C:\Users\Bgoszczy\Desktop\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\Users\Bgoszczy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\Users\Bgoszczy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\Users\Bgoszczy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\Users\Bgoszczy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\Users\Bgoszczy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168 <==== UWAGA
AlternateDataStreams: C:\6bfda727f87a59d61308b437:Win32App
AlternateDataStreams: C:\b4cf8c0febf6e0b91469f4d1d6:Win32App
AlternateDataStreams: C:\ccdd50c23ef913ef292d36302b:Win32App
AlternateDataStreams: C:\ed8751e2742391498edf2392b67e:Win32App
AlternateDataStreams: C:\Program Files\ATI Technologies:Win32App
AlternateDataStreams: C:\Program Files\Bonjour:Win32App
AlternateDataStreams: C:\Program Files\CCleaner:Win32App
AlternateDataStreams: C:\Program Files\Intel:Win32App
AlternateDataStreams: C:\Program Files\iTunes:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Office:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App
AlternateDataStreams: C:\Program Files (x86)\ATI Technologies:Win32App
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server Compact Edition:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft.NET:Win32App
AlternateDataStreams: C:\Program Files (x86)\NapiProjekt:Win32App
AlternateDataStreams: C:\Program Files (x86)\Napisy24:Win32App
AlternateDataStreams: C:\Program Files (x86)\Windows Live:Win32App
AlternateDataStreams: C:\Program Files (x86)\WinRAR:Win32App
AlternateDataStreams: C:\Program Files\Common Files\DESIGNER:Win32App
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App
AlternateDataStreams: C:\ProgramData\regid.1991-06.com.microsoft:Win32App
AlternateDataStreams: C:\ProgramData\Sony Corporation:Win32App
(TFuns LIMITED) C:\ProgramData\4WdM4\WdMan.exe
HKU\S-1-5-21-3543108252-308360466-193487373-1001\...\Run: [Facebook Update] => C:\Users\Bgoszczy\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-10-22] (Facebook Inc.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
HKU\S-1-5-21-3543108252-308360466-193487373-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
HKU\S-1-5-21-3543108252-308360466-193487373-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3543108252-308360466-193487373-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3543108252-308360466-193487373-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3543108252-308360466-193487373-1001 -> {B774E84B-35CC-47EA-AE1D-FDD8EE7D290C} URL =
Edge HomeButtonPage: HKU\S-1-5-21-3543108252-308360466-193487373-1001 -> hxxp://www.yoursites123.com/?type=hp&ts=1449730211&z=aabd68cdff6bc56e87bbabdg8z5z2t2mfcceaodo0e&from=ient07021&uid=SAMSUNGXMZMTD128HAFV-000_S15MNEBD109168
CHR HKU\S-1-5-21-3543108252-308360466-193487373-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
R2 WdMan; C:\ProgramData\4WdM4\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
2015-12-10 23:09 - 2015-12-10 23:11 - 00000000 ____D C:\AdwCleaner
2015-12-10 07:50 - 2015-12-10 07:51 - 00000000 ____D C:\ProgramData\4WdM4
2015-12-10 07:50 - 2015-12-10 07:50 - 00000380 _____ C:\WINDOWS\SysWOW64\data.bin
2015-12-10 07:50 - 2015-12-10 07:50 - 00000001 _____ C:\WINDOWS\SysWOW64\pl.html
2015-12-10 07:49 - 2015-12-10 07:49 - 00000000 ____D C:\ProgramData\yWdMy
EmptyTemp: