CloseProcesses:
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 Tosrfcom; No ImagePath
S3 TpChoice; system32\DRIVERS\TpChoice.sys [X]
R2 VSSS; C:\Users\EWELINA\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [97999104 2015-06-25] (Microsoft Corporation) [File not signed] <==== ATTENTION
C:\Users\EWELINA\AppData\Roaming\Microsoft\SystemCertificates
CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] -
Dostępne tylko dla zarejestrowanych użytkownikówFF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-06-03]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-11-21]
FF user.js: detected! => C:\Users\EWELINA\AppData\Roaming\Mozilla\Firefox\Profiles\nhg51ge4.default\user.js [2015-03-25]
Toolbar: HKU\S-1-5-21-1736996108-1665394498-2651624930-1000 -> No Name - {1CC372FF-D019-4922-AE0F-2534117F028B} - No File
SearchScopes: HKLM -> {3658A8AD-157F-4999-A42A-7F0B8E75A7A6} URL =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&rls=com.microsoft:*:IE-SearchBox&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7;
HKU\S-1-5-21-1736996108-1665394498-2651624930-1000\...\CurrentVersion\Windows: [Load] C:\ProgramData\msculku.exe <===== ATTENTION
C:\ProgramData\msculku.exe
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKLM\...\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [227840 2008-01-19] (Microsoft Corporation)
C:\Program Files\*.exe
EmptyTemp: