UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
Task: {B0E7C44E-CDF4-4CCB-8B05-F8D77F383DB1} - System32\Tasks\gabiPeckAfterlivesV2 => Rundll32.exe NeutralizersButtoned.dll,main 7 1 <==== UWAGA
Shortcut: C:\Users\gabi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехplоrеr.lnk C:\Program Files (x86)\Internet Explorer\iexplore.bat ()
Shortcut: C:\Users\gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnеt Ехplоrеr Вrоwsеr.lnk C:\Program Files (x86)\Internet Explorer\iexplore.bat ()
Shortcut: C:\Users\gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехplоrеr (2).lnk C:\Program Files (x86)\Internet Explorer\iexplore.bat ()
Shortcut: C:\Users\gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Intеrnеt Ехplоrеr.lnk C:\Program Files (x86)\Internet Explorer\iexplore.bat ()
Shortcut: C:\Users\gabi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Оpеrа11.50 1074.lnk C:\Program Files (x86)\Opera\opera.bat ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Оpеrа.lnk C:\Program Files (x86)\Opera\opera.bat ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449819881&z=b78679c35f7a50a2546773eg2z7z3t8b0g1t6b7meq&from=ient07021&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1448348319&z=8d4c6661f067d5f767f30f9g8z9z2beccz8b2cfg7t&from=ient07031&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1452239077&z=fe20de7533a02779a42910cgazbw0oco9cat8e8m8b&from=wpm01073&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1452239077&z=fe20de7533a02779a42910cgazbw0oco9cat8e8m8b&from=wpm01073&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449819881&z=b78679c35f7a50a2546773eg2z7z3t8b0g1t6b7meq&from=ient07021&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1448348319&z=8d4c6661f067d5f767f30f9g8z9z2beccz8b2cfg7t&from=ient07031&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts=1445851384&from=mych123&uid=toshibaxmk7559gsxp_41mjb1ohbxx41mjb1ohb&z=66a603d699890e0c0e38f1fg9z6zewfbbw6gdc5b7c
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts=1445851384&from=mych123&uid=toshibaxmk7559gsxp_41mjb1ohbxx41mjb1ohb&z=66a603d699890e0c0e38f1fg9z6zewfbbw6gdc5b7c
HKU\S-1-5-21-62747294-790118831-3170373538-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449819881&z=b78679c35f7a50a2546773eg2z7z3t8b0g1t6b7meq&from=ient07021&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB&q={searchTerms}
HKU\S-1-5-21-62747294-790118831-3170373538-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://services.eshield.com/general/newhometab.php?hometab=home&partner=11433&guid={884D0E7D-CB61-4A21-9488-C89EFDA13351}&i=
HKU\S-1-5-21-62747294-790118831-3170373538-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449819881&z=b78679c35f7a50a2546773eg2z7z3t8b0g1t6b7meq&from=ient07021&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB&q={searchTerms}
URLSearchHook: [S-1-5-21-62747294-790118831-3170373538-1000] UWAGA => Brak domyślnego URLSearchHook
URLSearchHook: HKU\S-1-5-21-62747294-790118831-3170373538-1000 - (Brak nazwy) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - Brak pliku
DefaultPrefix-x32: => http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=7d53b7936dc60e6d5466f1c787f2cb37&text= <==== UWAGA
StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1452239077&z=fe20de7533a02779a42910cgazbw0oco9cat8e8m8b&from=wpm01073&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB
StartMenuInternet: (HKLM) Opera - c:\program files (x86)\opera\opera.exe hxxp://www.yoursearching.com/?type=sc&ts=1448623532&z=09d0644218742e0f14059ceg8z9z7b9qdo1cbw0c7o&from=cornl&uid=TOSHIBAXMK7559GSXP_41MJB1OHBXX41MJB1OHB
R1 {5f03a891-cf74-4af4-a050-5f9ff20bc012}Gw64; C:\Windows\System32\drivers\{5f03a891-cf74-4af4-a050-5f9ff20bc012}Gw64.sys [48784 2015-08-10] (StdLib)
S1 QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.0.16779.224\QMUdisk64.sys [X]
S1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.82 Safari/537.36 OPR/39.0.2256.48
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0
DeleteQuarantine:
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników