ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Football Manager 2014\Football Manager 2014.lnk

C:\Games\Football Manager 2014\Launcher.exe ()

hxxp://www.yoursearching.com/?type=sc&ts=1449917022&z=0f1ee82fcaee055e4959304gbz2zbt1t9g5m6eao8w&from=cornl&uid=ST1000DM003-1ER162_W4Y2STNZXXXXW4Y2STNZ
ShortcutWithArgument: C:\Users\Public\Desktop\Football Manager 2014.lnk

C:\Games\Football Manager 2014\Launcher.exe ()

hxxp://www.yoursearching.com/?type=sc&ts=1449917022&z=0f1ee82fcaee055e4959304gbz2zbt1t9g5m6eao8w&from=cornl&uid=ST1000DM003-1ER162_W4Y2STNZXXXXW4Y2STNZ
Task: {00A87E76-CF6A-48A1-B334-A6B68AA26E2C} - System32\Tasks\FloristsPipefulsV2 => Rundll32.exe SexlessApocalyptical.dll,main 7 1 <==== UWAGA
Task: {493A4123-9108-4FC9-AF28-D072D9DE6FCE} - System32\Tasks\Price Fountain => C:\Users\Prezes\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
C:\Users\Prezes\AppData\Roaming\PRICEF~1
Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\Prezes\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1446578731&z=8e6098eb7d1d730b57e6cd2gazezfq0w6mbbazbwbt&from=cor&uid=ST1000DM003-1ER162_W4Y2STNZXXXXW4Y2STNZ
StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.yoursearching.com/?type=sc&ts=1449917022&z=0f1ee82fcaee055e4959304gbz2zbt1t9g5m6eao8w&from=cornl&uid=ST1000DM003-1ER162_W4Y2STNZXXXXW4Y2STNZ
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
C:\Program Files (x86)\wondershare
2015-12-18 23:47 - 2015-12-18 23:47 - 00000000 ____D C:\Users\Prezes\AppData\Roaming\spotmau
2015-12-18 23:47 - 2015-12-18 23:47 - 00075905 _____ C:\Users\Prezes\AppData\Roaming\userenv.xml
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp: