CloseProcesses:
NETSVCx32: HpSvc -> C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll ()
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
R2 KuaiZipDrive; C:\Windows\system32\drivers\KuaiZipDrive.sys [92872 2016-06-14] (WinMount International Inc)
R2 HpSvc; C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll [239528 2016-05-25] ()
CHR HKLM-x32\...\Chrome\Extension: [jidkebcigjgheaahopdnlfaohgnocfai] -
hxxps://clients2.google.com/service/update2/crxCHR Extension: (SafeFinder Search) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\jidkebcigjgheaahopdnlfaohgnocfai [2016-06-14]
CHR HomePage: ChromeDefaultData ->
hxxp://%66%65%65%64.%68%65%6C%70%65%72% ... w5uH5_WDfjCHR StartupUrls: ChromeDefaultData -> "hxxp://www.youndoo.com/?z=63cbb318ee62a39cb58d4d1gdz8q6wftecaedw9q8m&from=wak&uid=HitachiXHTS547564A9E384_J25N0054G9NNSEG9NNSEX&type=hp"
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.google.comShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => Brak pliku
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\żěŃą\X64\KZipShell.dll [2016-06-14] ()
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ComputerZ-Tray] => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe [2926504 2016-05-19] ()
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: G - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {06337fd0-2e09-11e6-99ee-6c626d2b97f6} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {7b6c276e-00d8-11e6-b06f-6c626d2b97f6} - I:\setup.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {b8b7c15d-00a6-11e6-b9df-6c626d2b97f6} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000\...\Run: [ComputerZ-Tray] => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe [2926504 2016-05-19] ()
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000\...\MountPoints2: G - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000\...\MountPoints2: {06337fd0-2e09-11e6-99ee-6c626d2b97f6} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000\...\MountPoints2: {7b6c276e-00d8-11e6-b06f-6c626d2b97f6} - I:\setup.exe
HKU\S-1-5-21-3723223452-1779111536-4020893689-1000\...\MountPoints2: {b8b7c15d-00a6-11e6-b9df-6c626d2b97f6} - G:\HTC_Sync_Manager_PC.exe
2016-06-14 22:04 - 2016-06-14 23:37 - 00000885 _____ C:\Users\Krzysiek\AppData\Roaming\Microsoft\Windows\Start Menu\żěŃą.lnk
2016-06-14 22:04 - 2016-06-14 23:37 - 00000861 _____ C:\Users\Krzysiek\Desktop\żěŃą.lnk
2016-06-14 22:04 - 2016-06-14 22:29 - 00000000 ____D C:\Users\Krzysiek\AppData\Roaming\Kuaizip
2016-06-14 22:04 - 2016-06-14 22:04 - 00092872 _____ (WinMount International Inc) C:\Windows\system32\Drivers\KuaiZipDrive.sys
2016-06-14 22:04 - 2016-06-14 22:04 - 00000000 ____D C:\Users\Krzysiek\AppData\Roaming\Softlink
2016-06-14 22:04 - 2016-06-14 22:04 - 00000000 ____D C:\Program Files\żěŃą
2016-06-14 22:04 - 2016-02-18 10:10 - 05267952 _____ () C:\Users\Krzysiek\AppData\Roaming\ziptool_wc-9015_setup.exe
2016-06-14 22:01 - 2016-05-27 11:27 - 51990120 _____ C:\Users\Krzysiek\AppData\Roaming\qqpcmgr_v11.5.17490.219_90138_Silence.exe
2016-06-14 22:01 - 2016-04-22 09:45 - 51987648 _____ C:\Users\Krzysiek\AppData\Roaming\qqpcmgr_v11.5.17490.219_90061_Silence.exe
2016-06-14 21:09 - 2016-06-14 22:26 - 00000000 ____D C:\Users\Krzysiek\AppData\Roaming\lockhomepage
2016-06-14 21:08 - 2016-06-15 00:25 - 00000000 ____D C:\Users\Krzysiek\AppData\Roaming\Ludashi
2016-06-14 21:08 - 2016-06-14 22:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师
2016-06-14 21:08 - 2016-06-14 21:08 - 00000000 ____D C:\Users\Krzysiek\AppData\Roaming\LDSGameAssistant
2016-06-14 21:07 - 2016-06-14 22:42 - 00000000 ____D C:\Program Files (x86)\LuDaShi
2016-06-14 21:07 - 2015-09-01 05:26 - 01099376 _____ C:\Users\Krzysiek\AppData\Roaming\inst_buychannel_01.exe
2016-06-14 21:04 - 2016-06-14 21:15 - 00000000 ____D C:\Program Files (x86)\mpck
2016-06-14 21:03 - 2016-06-14 23:36 - 00000000 ____D C:\Users\Krzysiek\AppData\Roaming\Gefxoix
2016-06-14 21:03 - 2016-06-14 23:34 - 00000000 ____D C:\Program Files (x86)\Wutaingjlaph_
2016-06-14 21:03 - 2016-06-14 23:34 - 00000000 ____D C:\Program Files (x86)\Arerack
2016-06-14 21:03 - 2016-06-14 21:56 - 00000000 ____D C:\Users\Krzysiek\AppData\LocalLow\Company
2016-06-14 21:03 - 2016-06-14 21:11 - 00000000 ____D C:\Program Files\Symemidce
2016-06-14 21:03 - 2016-06-14 21:06 - 00000000 ____D C:\Program Files (x86)\Wutaingjlaph
2016-06-14 21:03 - 2016-06-14 21:03 - 00008962 _____ C:\Windows\System32\Tasks\Arerack Server
2016-06-14 21:03 - 2016-06-14 21:03 - 00000000 ____D C:\Users\Krzysiek\AppData\Local\Tempfolder
2016-06-14 21:03 - 2016-06-14 21:03 - 00000000 _____ C:\Windows\SysWOW64\Number of results
2016-06-14 20:56 - 2016-06-14 23:34 - 00000000 ____D C:\Program Files (x86)\Duvoshlecition
2016-06-14 20:56 - 2016-06-14 21:57 - 00000000 ____D C:\Program Files (x86)\Plunasystagedom
2016-06-14 20:56 - 2016-06-14 21:00 - 00000000 ____D C:\Program Files (x86)\Anageiedphluk
2016-06-14 20:56 - 2016-06-14 20:56 - 00009012 _____ C:\Windows\System32\Tasks\Duvoshlecition Collector
2016-04-12 22:29 - 2016-04-12 22:29 - 6504960 _____ () C:\Users\Krzysiek\AppData\Roaming\agent.dat
2016-04-12 22:28 - 2016-04-12 22:28 - 0127488 _____ () C:\Users\Krzysiek\AppData\Roaming\Installer.dat
2016-06-14 21:07 - 2015-09-01 05:26 - 1099376 _____ () C:\Users\Krzysiek\AppData\Roaming\inst_buychannel_01.exe
2016-04-12 22:29 - 2016-04-12 22:29 - 0018432 _____ () C:\Users\Krzysiek\AppData\Roaming\Main.dat
2016-04-12 22:29 - 2016-04-12 22:29 - 1932216 _____ () C:\Users\Krzysiek\AppData\Roaming\Ozerhatstrong.bin
2016-06-14 21:03 - 2016-04-22 12:39 - 51987648 _____ () C:\Users\Krzysiek\AppData\Roaming\qqpcmgr_v11.5.17490.219_72530_Silence.exe
2016-06-14 22:01 - 2016-04-22 09:45 - 51987648 _____ () C:\Users\Krzysiek\AppData\Roaming\qqpcmgr_v11.5.17490.219_90061_Silence.exe
2016-06-14 22:01 - 2016-05-27 11:27 - 51990120 _____ () C:\Users\Krzysiek\AppData\Roaming\qqpcmgr_v11.5.17490.219_90138_Silence.exe
2016-06-14 21:03 - 2016-05-27 11:26 - 51990120 _____ () C:\Users\Krzysiek\AppData\Roaming\qqpcmgr_v11.5.17490.219_90139_Silence.exe
2016-06-14 22:04 - 2016-02-18 10:10 - 5267952 _____ () C:\Users\Krzysiek\AppData\Roaming\ziptool_wc-9015_setup.exe
2016-06-06 11:19 - 2016-06-06 11:19 - 0003584 _____ () C:\Users\Krzysiek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Task: {09E21533-05FF-4BF0-8FD4-799539DF2769} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-18] (Google Inc.)
Task: {19C2E7AA-7406-455A-AB66-D4FB0AF92A37} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-18] (Google Inc.)
Task: {1EBAA02C-21DB-4234-9B37-B8C835E458CF} - System32\Tasks\{5F4B6862-F201-45AF-A430-FA37D648981E} => Chrome.exe
hxxp://ui.skype.com/ui/0/7.22.0.109/pl/ ... rogressBarTask: {22BAF529-5A39-47DC-8D35-276B0E15EBC1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {2D1239FB-6C33-4138-BC6F-E509D9BB721E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {37D13495-B9FE-4214-960D-30C9E52602A6} - System32\Tasks\Duvoshlecition Collector => C:\Program Files (x86)\Duvoshlecition\duvoshlecitionCollectorTs.exe
Task: {46AF17FA-42FE-4316-99B3-C3FD180C6FFF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-03-11] (Piriform Ltd)
Task: {478C20D9-24ED-4C3C-9267-B5BF5B473837} - System32\Tasks\{BE203CA8-5C29-4520-940E-1698E9F3BA13} => Chrome.exe
hxxp://ui.skype.com/ui/0/7.22.0.109/pl/ ... rogressBarTask: {64C28CDB-4313-424C-BAB2-CB29A82E0752} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2016-04-02] ()
Task: {90134E81-865F-4D81-A410-C738C194E2B8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)
Task: {A4FC1ACF-05A2-4E84-8C0F-650648247025} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {F52F88F1-6B68-4F53-996C-72CDF5FB7654} - System32\Tasks\Arerack Server => C:\Program Files (x86)\Arerack\ArerackServerTask.exe <==== UWAGA
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师\卸载鲁大师.lnk -> C:\Program Files (x86)\LuDaShi\uninst.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师\鲁大师.lnk -> C:\Program Files (x86)\LuDaShi\ComputerZ_CN.exe (鲁大师)
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师\卸载小鲁苹果助手.lnk -> C:\Program Files (x86)\LuDaShi\ComputerZTray.exe () -> /uninstioszhushou
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师\卸载鲁大师手机助手.lnk -> C:\Program Files (x86)\LuDaShi\MobileMgr\LdsMobileMgr.exe (360.cn) -> /uninstzhushou
CMD: netsh winsock reset
ResetHosts:
EmptyTemp: