UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://Lasaoren.com/?f=1&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1866668609&ir=
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1343071672&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1343071672&ir=
SearchScopes: HKLM - {A25AC313-DD19-4238-ACA2-401D6BEE4321} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1866668609&ir=
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1343071672&ir=
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1343071672&ir=
SearchScopes: HKCU - {A25AC313-DD19-4238-ACA2-401D6BEE4321} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_39_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0BtD0DtCtD0EyCzz0B0CtCtN0D0Tzu0SzyzyzztN1L2XzutAtFtBtFyEtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0AtCtBzy0AtG0FtA0E0CtGyDtA0AtAtGtB0BzzyCtGyEyDyE0FyBtC0FtD0Dzy0BtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtCtBtDyBtA0AzztG0A0DtDtDtGyEyC0FtDtGzztCyEzztGyE0FyCzy0EtCtDtDyEyCtBtA2Q&cr=1866668609&ir=
BHO-x32: Wondershare AllMyTube 4.1.0 {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll No File
Handler: WSAllMyTubechrome - {0A0C95CF-A116-4C74 - No File
Handler-x32: WSAllMyTubechrome - {0A0C95CF-A116-4C74 - No File
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
U3 uwldqpoc; \??\C:\Users\RAFA~1\AppData\Local\Temp\uwldqpoc.sys [X]
R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys [61120 2014-06-11] (StdLib)
2014-09-24 22:58 - 2014-09-29 21:01 - 00000308 _____ () C:\WINDOWS\Tasks\WSE_Lasaoren.job
2014-09-24 22:58 - 2014-09-24 23:01 - 00002646 _____ () C:\WINDOWS\System32\Tasks\WSE_Lasaoren
2014-09-24 22:57 - 2014-09-24 22:58 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\WSE_Lasaoren
2014-09-24 22:57 - 2014-09-24 22:58 - 00000000 ____D () C:\Program Files (x86)\WSE_Lasaoren
2014-09-24 22:56 - 2014-09-24 22:56 - 00747456 _____ ( ) C:\Users\Rafał\Desktop\SpeedFan(13166)-dp.exe
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
Task: C:\WINDOWS\Tasks\WSE_Lasaoren.job => C:\Users\RAFA~1\AppData\Roaming\WSE_LA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
Task: {120B8597-DC68-4411-A60B-152698045F12} - \WSE_Lasaoren No Task File <==== ATTENTION
HKU\S-1-5-21-2370329703-81669117-2710482987-1002\...\Run: [Akamai NetSession Interface] => "C:\Users\RafaB\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-2370329703-81669117-2710482987-1002\...\Run: [BRS] => C:\Program Files (x86)\WSE_Lasaoren\BRS\brs.exe -runBRS
C:\Program Files (x86)\WSE_Lasaoren
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
Zarejestrowani użytkownicy: Bing [Bot]