programy dały się usunąć, ale i tak krzyczało o braku jakiegos pliku.
Rowniez skanowanie na awaryjnym się powiodło.
Wklejam raport:
Malwarebytes Anti-Malware
www.malwarebytes.org
Data skanu: 2014-10-20
Czas skanu: 18:49:35
Raport: malware.txt
Administrator: Tak
Wersja: 2.00.3.1025
Baza danych malware: v2014.10.18.05
Baza danych rootkitów: v2014.10.17.01
Licencja: Darmowy
Ochrona przeciw malware: Wyłączony
Ochrona przeciw szkodliwymi stronami: Wyłączony
Samoobrony: Wyłączony
System operacyjny: Windows 7 Service Pack 1
Procesor: x86
System plików: NTFS
Użytkownik: Admin
Typ skanu: Skanowanie niestandardowe
Wynik: Zakończono
Objekty zeskanowane: 424393
Minęło: 1 h, 17 min, 6 s
Pamięć: Włączony
Autostart: Włączony
System plików: Włączony
Archiwa: Włączony
Rootkity: Włączony
Heurystyka: Włączony
PNP: Włączony
PNM: Włączony
Procesy: 0
(Nie wykryto groźnych)
Moduły: 0
(Nie wykryto groźnych)
Klucze rejestru: 46
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{AD25754E-D76C-42B3-A335-2F81478B722F}, , [01c99085a9d39d9953e8f45c6c990df3],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}, , [01c99085a9d39d9953e8f45c6c990df3],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [309a27eefb814fe70ce532a6e51d6997],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0D7562AE-8EF6-416d-A838-AB665251703A}, , [47839b7a126a44f2dbda4e5411f18d73],
PUP.Optional.Babylon.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [2e9cdb3adaa2b6809fe50d929b677d83],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{64182481-4F71-486B-A045-B233BD0DA8FC}, , [b218fb1a80fcfc3aaa099e04788a12ee],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\facemoods.facemoodsHlpr, , [b218fb1a80fcfc3aaa099e04788a12ee],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\facemoods.facemoodsHlpr.1, , [b218fb1a80fcfc3aaa099e04788a12ee],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}, , [458563b20e6e072fc6ee930fd1314bb5],
PUP.Optional.Conduit, HKLM\SOFTWARE\CLASSES\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}, , [c505a86d77053105ac0bab8412ee1ce4],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\CLSID\{AD20D01C-C939-4dd2-8C55-56935A48987E}, , [25a519fcaece14223dfe82ce11f4be42],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\facemoodsApp.appCore.1, , [25a519fcaece14223dfe82ce11f4be42],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\facemoodsApp.appCore, , [25a519fcaece14223dfe82ce11f4be42],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\CLSID\{A5B99E41-E157-4209-8AAC-DB003A816079}, , [1ab0ac693b41b4827cbf0f41ad58c33d],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B12E99ED-69BD-437C-86BE-C862B9E5444D}, , [1ab0ac693b41b4827cbf0f41ad58c33d],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}, , [1ab0ac693b41b4827cbf0f41ad58c33d],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\facemoods.xtrnl.1, , [1ab0ac693b41b4827cbf0f41ad58c33d],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\facemoods.xtrnl, , [1ab0ac693b41b4827cbf0f41ad58c33d],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\CLSID\{DDE2C74F-58CC-4d71-8CE1-09DEBB8CFB78}, , [cffbe2337804ce68003b8fc16e97da26],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{09C554C3-109B-483C-A06B-F14172F1A947}, , [cffbe2337804ce68003b8fc16e97da26],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A9379648-F6EB-4F65-A624-1C10411A15D0}, , [cffbe2337804ce68003b8fc16e97da26],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}, , [cffbe2337804ce68003b8fc16e97da26],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\DataMngr, , [5377a76e29535cdaeb664ee7d92ad52b],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\facemoods.com, , [09c1f025a1dbb680a6e4182ce41f857b],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\IB Updater, , [49819085a7d5db5b70416ed100038a76],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlfienamagdnkekbbbocojppncdambda, , [ad1d67ae7408ca6c65ab3cfdb64d37c9],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, , [a723fb1a314b9d99347c1c2353b027d9],
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\ihflimipbcaljfnojhhknppphnnciiif, , [fdcd71a45f1dce686821ce76d2317090],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\jcdgjdiieiljkfkdcloehkohchhpekkn, , [6664ed283c4072c43711b977bd462dd3],
PUP.Optional.Perion.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\niogeckbkdcabhnapjbkeiklablhjoca, , [0ebc1005a4d81a1c73594dcce61d5da3],
PUP.Optional.FastSearchings, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, , [e8e2ae67acd072c4c5075d2cdf25ec14],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM, , [0cbecb4a5527ec4a75abe28764a08e72],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\IB Updater, , [daf0be57186441f51e932b14d033da26],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlfienamagdnkekbbbocojppncdambda, , [04c629ec2755ff379a762e0bd132718f],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, , [8d3d56bfb6c696a0d9d707388c77f30d],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [c604977e592361d504105b0d1ee62cd4],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\facemoods.com, , [3595a075ee8e94a2cbc098aca1620af6],
PUP.Optional.SProtector.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SProtector, , [8149b65f1c60cb6b6946b9b105ff4db3],
PUP.Optional.Babylon.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Redir, , [557547ced9a3f83e20f6e0897f85ec14],
PUP.Optional.Babylon.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, , [bc0e45d06913a49240d76801689cc63a],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [eae0b0653a421125fcf4341d4db67987],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [c307da3bc7b58aaca493a7c120e4649c],
PUP.Optional.WebSearchInfo, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, , [0dbd8e879ae29e984b0e6f07cb3933cd],
PUP.Optional.BProtector.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, , [3c8ed5402c50c76f78e52a41b74d49b7],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [6961c94c037991a5141dc77aef1448b8],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, , [08c20a0bceae4cea23fc0d5c84809e62],
Wartości rejestru: 10
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|facemoods, "C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I, , [01c99085a9d39d9953e8f45c6c990df3]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, , [1fab2bea324ab086e83fccd3b34feb15],
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, , [1fab2bea324ab086e83fccd3b34feb15]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, , [1fab2bea324ab086e83fccd3b34feb15]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, , [4882849184f8a1959b8c841b16ec6898],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM|simapp_id, {AAFA44B1-656F-11E2-AF8C-002220087764}, , [0cbecb4a5527ec4a75abe28764a08e72]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, , [c307da3bc7b58aaca493a7c120e4649c]
PUP.BProtector, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page,
http://www2.delta-se...3_ctrl&tsp=5008, , [408a6da81c60b482090ce97f000426da]
PUP.BProtector, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [3c8e0015cab240f671a5a3c536ce54ac]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2766724538-3362004814-157077177-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {AAFA44B1-656F-11E2-AF8C-002220087764}, , [08c20a0bceae4cea23fc0d5c84809e62]
Dane rejestru: 1
Foldery: 10
PUP.Optional.OpenCandy, C:\Users\Admin\AppData\Roaming\OpenCandy, , [8149be579ddf2412a0d2e9030200af51],
PUP.Optional.OpenCandy, C:\Users\Admin\AppData\Roaming\OpenCandy\454AF1F0CE9B4900BB2D1BDE9C58E34A, , [8149be579ddf2412a0d2e9030200af51],
PUP.Optional.OpenCandy, C:\Users\Admin\AppData\Roaming\OpenCandy\A798A80E140042F6BFDF1418B734A783, , [8149be579ddf2412a0d2e9030200af51],
PUP.Optional.FaceMoods.A, C:\Users\Admin\AppData\LocalLow\facemoods.com, , [feccd2433f3db2845135dc1715edd32d],
PUP.Optional.FaceMoods.A, C:\Users\Admin\AppData\LocalLow\facemoods.com\facemoods, , [feccd2433f3db2845135dc1715edd32d],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com, , [2d9d3ed7c1bbec4ae6a3f9facd35fb05],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods, , [2d9d3ed7c1bbec4ae6a3f9facd35fb05],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11, , [2d9d3ed7c1bbec4ae6a3f9facd35fb05],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh, , [2d9d3ed7c1bbec4ae6a3f9facd35fb05],
PUP.Optional.Complitly.A, C:\Users\Admin\AppData\Roaming\Complitly, , [08c2c253047850e685d723e2c83b817f],
Pliki: 20
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe, , [01c99085a9d39d9953e8f45c6c990df3],
Malware.Gen, C:\Adobe Photoshop CS5 Extended PL\keygen.exe, , [cdfd67ae304ceb4bd1699dcd3ec242be],
PUP.Optional.Conduit, C:\Program Files\Conduit\Community Alerts\Alert.dll, , [c505a86d77053105ac0bab8412ee1ce4],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll, , [25a519fcaece14223dfe82ce11f4be42],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll, , [1ab0ac693b41b4827cbf0f41ad58c33d],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll, , [c00a64b1afcd63d3ea513a1616ef847c],
PUP.Optional.FaceMoods.A, C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll, , [cffbe2337804ce68003b8fc16e97da26],
PUP.Optional.MultiPlug.A, C:\ProgramData\Brrowse2save\512e2d0f5c0ce.dll, , [b61421f4f88447eff093df3c6f92916f],
PUP.Optional.MultiPlug.A, C:\ProgramData\Searcch-NeiwTab\512e2d858db7c.dll, , [3397b263d7a51422285bbe5d0001be42],
PUP.Optional.Softonic.A, C:\Users\Admin\Videos\SoftonicDownloader_dla_rmvb-player.exe, , [8149be5744385cdab52cb28254adbb45],
Malware.Gen, D:\Adobe Photoshop CS5 Extended PL\keygen.exe, , [7a5067ae4933de5840fac0aabf41718f],
PUP.Optional.Conduit, D:\Program Files\Conduit\Community Alerts\Alert.dll, , [34969481601c20165166072813edaa56],
PUP.Optional.FaceMoods.A, D:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll, , [e1e97e97760654e2dc5f3f11bc49a65a],
PUP.Optional.FaceMoods.A, D:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll, , [05c562b3067692a4df5c064a27de857b],
PUP.Optional.FaceMoods.A, D:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe, , [5773898cd5a7181e81ba5df309fcaa56],
PUP.Optional.FaceMoods.A, D:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll, , [07c348cd5b21f24443f8cf817491e917],
PUP.Optional.FaceMoods.A, D:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll, , [21a9b362661647ef5cdfc888f70ef907],
PUP.Optional.BitGuard.A, C:\Windows\System32\Tasks\BitGuard, , [04c645d0106c4aecec7031fe0ef520e0],
PUP.Optional.OpenCandy, C:\Users\Admin\AppData\Roaming\OpenCandy\454AF1F0CE9B4900BB2D1BDE9C58E34A\TuneUpUtilities2013_2200266_pl-PL.exe, , [8149be579ddf2412a0d2e9030200af51],
PUP.Optional.OpenCandy, C:\Users\Admin\AppData\Roaming\OpenCandy\A798A80E140042F6BFDF1418B734A783\TuneUpUtilities2013_2200266_pl-PL.exe, , [8149be579ddf2412a0d2e9030200af51],
Sektory fizyczne: 0
(Nie wykryto groźnych)
(end)