21 Cze 2017, 21:48
11 Lip 2017, 11:53
Task: {F0B52C2D-0B70-489B-B7BD-B1FF891BA3E0} - System32\Tasks\MinistrantIntegersV2 => Rundll32.exe ProvokinglyKidnaped.dll,main 7 1 <==== UWAGA
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2010-06-15] (Analog Devices, Inc.)
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hp&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hp&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA&q={searchTerms}
CHR StartupUrls: Default"hxxp://do-search.com/?type=hp&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA"
CHR DefaultSearchURL: Defaulthxxp://do-search.com/web/?type=ds&ts=1429116032&from=cor&uid=ST3160812AS_5LS91MNAXXXX5LS91MNA&q={searchTerms}
CHR DefaultSearchKeyword: Defaultdo-search
EmptyTemp: