Malwarebytes Anti-Malware www.malwarebytes.org Data skanowania: 2015-12-08 Czas skanowania: 22:33:50 Raport: Scan 01.txt Administrator: Tak Wersja: 2.2.0.1024 Baza szkodliwego oprogramowania: v2015.12.08.05 Baza danych rootkitów: v2015.12.07.01 Licencja: Darmowa Ochrona przed złośliwym oprogramowaniem: Wyłączony Ochrona przed szkodliwymi stronami: Wyłączony Samoobrona: Wyłączony System operacyjny: Windows XP Service Pack 3 Procesor: x86 System plików: NTFS Użytkownik: Aras Typ skanowania: Dokładne skanowanie Wynik: Zakończono Obiekty przeskanowane: 337543 Czas, który upłynął: 26 min, 50 s Pamięć: Włączony Autostart: Włączony System plików: Włączony Archiwa: Włączony Rootkity: Wyłączony Heurystyka: Włączony PUP: Włączony PUM: Włączony Procesy: 2 PUP.Optional.ChinAd, C:\Program Files\SFK\SSFK.exe, 800, , [198c455d325995a1f283dfd19b66ef11] PUP.Optional.ChinAd, C:\Program Files\SFK\SSFK.exe, 2220, , [198c455d325995a1f283dfd19b66ef11] Moduły: 2 PUP.Optional.CrossRider, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Bin\PoolBrowser.dll, , [485d287ac4c71f1772f56905669efd03], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Bin\pztsv.dll, , [bbead3cf7a1105319ad600a0e0248a76], Klucze rejestru: 24 PUP.Optional.CrossRider, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9563BC59-9556-4805-8CD4-886781779D8D}, , [485d287ac4c71f1772f56905669efd03], PUP.Optional.ChinAd, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SSFK, , [198c455d325995a1f283dfd19b66ef11], PUP.Optional.Babylon, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [0e971092d3b88bab79a08ac148ba936d], PUP.Optional.AceRace, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{68182220-3C75-49D9-A9C4-4093D3986279}, , [d9cc2f730388ef47f7b1d179b64c50b0], PUP.Optional.AceRace, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{68182220-3C75-49D9-A9C4-4093D3986279}, , [d9cc2f730388ef47f7b1d179b64c50b0], Trojan.VBCrypt, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SETUP.EXE, , [782d8a18e0abd1652c0dc364d130718f], PUP.Optional.ModGoog, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GLOBALUPDATE.EXE, , [a302e0c2becd47ef122f837202fee818], PUP.Optional.HighDefAction, HKLM\SOFTWARE\HighDefAction, , [4c59f7ab5932cf676c15464dbd46c937], PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\istartsurfSoftware, , [0d98762cbbd0fd39dead24c4778cab55], PUP.Optional.Omniboxes.ShrtCln, HKLM\SOFTWARE\omniboxesSoftware, , [0a9bfba7fc8fd75f2342bdecf909966a], PUP.Optional.WPM, HKLM\SOFTWARE\supWindowsMangerProtect, , [81246939b9d2dd59588517a37e859e62], PUP.Optional.YorkNewCin, HKLM\SOFTWARE\YorkNewCin, , [b7ee0999444775c19f8fe5d642c1fa06], PUP.Optional.CrossRider, HKLM\SOFTWARE\_CrossriderRegNamePlaceHolder_, , [abfa1f83b2d95fd7f024b8d1e41fd62a], PUP.Optional.CinemaPlus, HKLM\SOFTWARE\ARENAHD, , [6d386141cac10f276f12c5bded1611ef], Worm.Magania, HKLM\SOFTWARE\CLASSES\CLSID\MADOWN, , [099cdfc31b7050e68ac43cc4d231ea16], PUP.Optional.WindowsMangerProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [a5008a182764b581a39ab9018182eb15], PUP.Optional.CinemaPlus, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\CinemaPlus-3.2cV30.07-nv-ie, , [b5f0178b7c0fb18585ecb6cce41f27d9], PUP.Optional.HighDefAction, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\HighDefAction, , [4560148e167540f63050484be320f50b], PUP.Optional.YorkNewCin, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\YorkNewCin, , [6b3aa8fa4a41a88e909d813ab053768a], PUP.Optional.CrossRider, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\_CrossriderRegNamePlaceHolder_, , [40656e34454644f2edf8bdcad13256aa], PUP.Optional.CinemaPlus, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\ARENAHD, , [52537d258a01b680c59ddfa3d033b44c], PUP.Optional.CrossRider, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\CROSSRIDER, , [8c19cdd5e2a987af1be41c6b1de61be5], PUP.Optional.GlobalUpdate, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, , [bfe62b77355604326335801124df639d], PUP.Optional.OutBrowse, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\OB, , [c4e1980ac0cb66d02b87fba7af54a65a], Wartości rejestru: 9 PUP.Optional.CinemaPlus, HKLM\SOFTWARE\ARENAHD|value, 1, , [6d386141cac10f276f12c5bded1611ef] PUP.Optional.PCTuner, HKLM\SOFTWARE\HIGHDEFACTION|value, 1, , [198cdec49deebe789127782bd231659b] PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SSFK|ImagePath, C:\Program Files\SFK\SSFK.exe -s, , [772e1b8792f9290d0751baec679b5aa6] PUP.Optional.CinemaPlus, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\ARENAHD|value, 1, , [52537d258a01b680c59ddfa3d033b44c] PUP.Optional.CrossRider, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\CROSSRIDER|Verifier, aae66173f12cfbd7267e2bf74a94fbdd, , [8c19cdd5e2a987af1be41c6b1de61be5] PUP.Optional.GlobalUpdate, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, , [bfe62b77355604326335801124df639d] PUP.Optional.PCTuner, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\HIGHDEFACTION|value, 1, , [00a5732fff8c2b0b0ca83a69fd069d63] PUP.Optional.OutBrowse, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\OB|monitype15, 8/7/15 14:25:39, , [c4e1980ac0cb66d02b87fba7af54a65a] PUP.Optional.OutBrowse, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\OB|monitype25, 8/7/15 14:26:55, , [e6bfd7cbee9d3afc9e14aef49b68d729] Dane rejestru: 12 PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX, Dobry: (iexplore.exe), Zły: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX),,[4362247e9bf0999da472b8b912f22fd1] PUP.Optional.SearchSimple, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|Tabs, http://q.search-simple.com/?m=tab&affID=na, Dobry: (www.google.com), Zły: (http://q.search-simple.com/?m=tab&affID=na),,[f7ae7230b2d9d462ce8a75059f65aa56] PUP.Optional.Omniboxes.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.omniboxes.com/?type=hp&ts=1449043289&z=b1f6f826539a6e7ae8d90e2gdzcz6t7e1z5c2o8b8b&from=ient07021&uid=ST3250820A_5QF35XMXXXXX5QF35XMX, Dobry: (www.google.com), Zły: (http://www.omniboxes.com/?type=hp&ts=1449043289&z=b1f6f826539a6e7ae8d90e2gdzcz6t7e1z5c2o8b8b&from=ient07021&uid=ST3250820A_5QF35XMXXXXX5QF35XMX),,[baebc4deff8cc86ee52e4335e71d956b] PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}, Dobry: (www.google.com), Zły: (http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}),,[277e3b678704e056cdf2c1afb35153ad] PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}, Dobry: (www.google.com), Zły: (http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}),,[2c79178bb8d32c0a4778d49ce91b639d] PUP.Optional.Omniboxes.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.omniboxes.com/?type=hp&ts=1449043289&z=b1f6f826539a6e7ae8d90e2gdzcz6t7e1z5c2o8b8b&from=ient07021&uid=ST3250820A_5QF35XMXXXXX5QF35XMX, Dobry: (www.google.com), Zły: (http://www.omniboxes.com/?type=hp&ts=1449043289&z=b1f6f826539a6e7ae8d90e2gdzcz6t7e1z5c2o8b8b&from=ient07021&uid=ST3250820A_5QF35XMXXXXX5QF35XMX),,[edb8bce673182b0bfb181266c63e6c94] PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}, Dobry: (www.google.com), Zły: (http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}),,[792ceab8c8c36ec806ba91df54b0a957] PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|CustomizeSearch, http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}, Dobry: (www.google.com), Zły: (http://www.istartsurf.com/web/?type=ds&ts=1438950240&z=1a25207ddc3255d8bfcfa49g9z8cbbetcwde0g3w1b&from=obw&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}),,[d9ccc7db5c2f181e744c650bd232f20e] PUM.Optional.DisplayHiddenFolder, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED\FOLDER\HIDDEN\SHOWALL|CheckedValue, 0, Dobry: (1), Zły: (0),,[3f665d45ddae6dc93b4d15661fe5946c] PUP.Optional.Omniboxes.ShrtCln, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.omniboxes.com/web/?type=ds&ts=1447423066&z=22e49a485801c231e49de94gbz8z5mazdo7c8e8qcm&from=wpm07173&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}, Dobry: (www.google.com), Zły: (http://www.omniboxes.com/web/?type=ds&ts=1447423066&z=22e49a485801c231e49de94gbz8z5mazdo7c8e8qcm&from=wpm07173&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}),,[1e87614117743df949cbaecabf45fc04] PUP.Optional.Omniboxes.ShrtCln, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.omniboxes.com/?type=hp&ts=1449043289&z=b1f6f826539a6e7ae8d90e2gdzcz6t7e1z5c2o8b8b&from=ient07021&uid=ST3250820A_5QF35XMXXXXX5QF35XMX, Dobry: (www.google.com), Zły: (http://www.omniboxes.com/?type=hp&ts=1449043289&z=b1f6f826539a6e7ae8d90e2gdzcz6t7e1z5c2o8b8b&from=ient07021&uid=ST3250820A_5QF35XMXXXXX5QF35XMX),,[a7fe069ca4e72115c54f027614f029d7] PUP.Optional.Omniboxes.ShrtCln, HKU\S-1-5-21-1390067357-1677128483-1060284298-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.omniboxes.com/web/?type=ds&ts=1447423066&z=22e49a485801c231e49de94gbz8z5mazdo7c8e8qcm&from=wpm07173&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}, Dobry: (www.google.com), Zły: (http://www.omniboxes.com/web/?type=ds&ts=1447423066&z=22e49a485801c231e49de94gbz8z5mazdo7c8e8qcm&from=wpm07173&uid=ST3250820A_5QF35XMXXXXX5QF35XMX&q={searchTerms}),,[9b0a3b675b3058de36de95e320e4619f] Foldery: 18 PUP.Optional.Elex, C:\Documents and Settings\Aras\Dane aplikacji\TSv, , [4461fea43c4fdf578403dbc760a2a858], PUP.Optional.Elex, C:\Program Files\SFK, , [0b9a6240c2c996a0ecfcd0f649baa65a], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.GlobalUpdate, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157, , [5d48ced4d6b55bdb8f180b796999fd03], PUP.Optional.ProtectWindowsManager, C:\Documents and Settings\All Users\Dane aplikacji\3WinManPro3, , [e4c1e9b9dfacd85ec3ff1486e51d53ad], PUP.Optional.ProtectWindowsManager, C:\Documents and Settings\All Users\Dane aplikacji\3WinManPro3\update, , [e4c1e9b9dfacd85ec3ff1486e51d53ad], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\5WMiniPro5, , [ccd9acf6b8d3cd697e49d0cd0ef47e82], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\5WMiniPro5\mitest, , [ccd9acf6b8d3cd697e49d0cd0ef47e82], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\BWMiniProB, , [6045534ff596ea4cfccb603d04fe58a8], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\BWMiniProB\mitest, , [6045534ff596ea4cfccb603d04fe58a8], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\cWMiniProc, , [5e475052fc8fb680b116bde0fc06a45c], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\cWMiniProc\mitest, , [5e475052fc8fb680b116bde0fc06a45c], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Bin, , [bbead3cf7a1105319ad600a0e0248a76], Pliki: 63 PUP.Optional.CrossRider, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Bin\PoolBrowser.dll, , [485d287ac4c71f1772f56905669efd03], PUP.Optional.ChinAd, C:\Program Files\SFK\SSFK.exe, , [198c455d325995a1f283dfd19b66ef11], PUP.Optional.CinemaPlus, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\5087.exe, , [2580950dfd8ec472bb980d88d2327e82], PUP.Optional.CinemaPlus, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\5178.exe, , [4f566939b4d71224b89b474ea55ffe02], Trojan.VBCrypt, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\setup.exe, , [782d8a18e0abd1652c0dc364d130718f], PUP.Optional.PayByAds, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\res.dll, , [782d1c86a2e93402e4185a3be3219e62], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\globalupdate.exe, , [a302e0c2becd47ef122f837202fee818], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\globalupdateBroker.exe, , [6c39435fbfcc999d99a8d32231cfd22e], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\globalupdateCrashHandler.exe, , [b6ef069c1774b185eb5621d4b050738d], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\globalupdateOnDemand.exe, , [b3f2d9c9a4e7a096be8306efaa5630d0], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\goopdate.dll, , [61442082870460d645fc9b5a916f22de], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\goopdateres_en.dll, , [efb6faa86e1de452ff42a451d32d619f], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\npglobalupdateUpdate4.dll, , [71341191ee9dd75f1928c72e37c920e0], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\psmachine.dll, , [0d98653d068570c65ae76590c63af50b], PUP.Optional.ModGoog, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\psuser.dll, , [9b0aa4feadde88ae9ca5777e69974bb5], PUP.Optional.Somoto, C:\Documents and Settings\Aras\Local Settings\Application Data\Bundled software uninstaller\biclient.exe, , [b4f1b3efeaa149edc2f198988f727f81], PUP.Optional.Elex, C:\Documents and Settings\Aras\Dane aplikacji\TSv\TSvr.exe, , [4461fea43c4fdf578403dbc760a2a858], PUP.Optional.Elex, C:\Documents and Settings\Aras\Dane aplikacji\TSv\msvcp100.dll, , [4461fea43c4fdf578403dbc760a2a858], PUP.Optional.Elex, C:\Documents and Settings\Aras\Dane aplikacji\TSv\msvcr100.dll, , [4461fea43c4fdf578403dbc760a2a858], PUP.Optional.Elex, C:\Program Files\SFK\SFK.ini, , [0b9a6240c2c996a0ecfcd0f649baa65a], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\543.json, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\MessageBox.xml, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\bg.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\bg1.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\bk_shadow.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\button.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\button1.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\checkbox.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\checkbox_select.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\checked.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\close.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\loading_bg.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\loading_light.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\min.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\scrollbar.bmp, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\Thumbs.db, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\unchecked.png, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\code1.jpg, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\code2.jpg, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\code3.jpg, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\code4.jpg, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\code5.jpg, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\code6.jpg, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.IStartSurf.ShrtCln, C:\Documents and Settings\Aras\Dane aplikacji\istartsurf\images\code\Thumbs.db, , [dcc9643e9cefa5916e10373614ee0af6], PUP.Optional.GlobalUpdate, C:\Documents and Settings\Aras\Ustawienia lokalne\Temp\comh.77157\globalupdateHelper.msi, , [5d48ced4d6b55bdb8f180b796999fd03], PUP.Optional.ProtectWindowsManager, C:\Documents and Settings\All Users\Dane aplikacji\3WinManPro3\updateconf, , [e4c1e9b9dfacd85ec3ff1486e51d53ad], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp\000003.log, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp\CURRENT, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp\LOCK, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp\LOG, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp\LOG.old, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.MindSpark, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Extension Settings\fphnecoppfkhnnbhhmdmpldmkpnflegp\MANIFEST-000001, , [b3f2e4be870496a03d201a81ac56d52b], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\5WMiniPro5\mitestconf, , [ccd9acf6b8d3cd697e49d0cd0ef47e82], PUP.Optional.WindowsProtectManager, C:\Documents and Settings\All Users\Dane aplikacji\BWMiniProB\mitestconf, , [6045534ff596ea4cfccb603d04fe58a8], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component\config.json, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component\hello.js, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component\manifest.json, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component\scriptTagContext.js, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component\tmp_bg.js, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Component\uconfig.json, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Bin\c.dat, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.CrossAd.Gen, C:\Documents and Settings\Aras\Local Settings\Application Data\Pool Browser\Bin\pztsv.dll, , [bbead3cf7a1105319ad600a0e0248a76], PUP.Optional.BDYahoo, C:\Documents and Settings\Aras\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Secure Preferences, Dobry: ("session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/restorebrowser/"]}}), Zły: ("session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":["http://google.com/"],"urls_to_restore_on_startup":["http://search.yahoo.com/?fr=hp-ddc-bd&type=616_pr__alt__ddc_dsssyc_bd_com"]},"software_reporter":{"prompt_seed":"20150601","prompt_version":"4.28.1"}}), ,[079e148ec2c90d292ea9a00542c239c7] Sektory fizyczne: 0 (Nie wykryto zagrożeń) (end)