UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.91 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
UA: Mozilla/5.0 (Linux; Android 4.4.4; SM-N910F Build/KTU84P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.93 Mobile Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.111 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Task: {2778EA23-43C5-47D4-9B0F-E2375C3DD2DC} - System32\Tasks\epkpapn => C:\Users\Justyna\AppData\Local\Temp\azzlepf.exe [2015-02-04] () <==== ATTENTION
Task: {45C558E6-5C8F-485F-B51E-FDF304A6D192} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-11-25] (MyPC Backup) <==== ATTENTION
ShellIconOverlayIdentifiers: [00avast]{472083B0-C522-11CF-8763-00608CC02F24} => No File
KLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX&q={searchTerms}
HKU\S-1-5-21-3971440189-4188189226-3082623173-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX&q={searchTerms}
HKU\S-1-5-21-3971440189-4188189226-3082623173-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX&q={searchTerms}
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1412126623&from=cor&uid=HitachiXHTS545050B9A300_101116PBN403M7C8JWBEX
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
U3 kgliraog; \??\C:\Users\Justyna\AppData\Local\Temp\kgliraog.sys [X]
2015-02-04 16:55 - 2015-02-04 16:55 - 03148854 _____ () C:\Users\Justyna\Documents\!Decrypt-All-Files-lfmhtjh.bmp
2015-02-04 16:55 - 2015-02-04 16:55 - 00001266 _____ () C:\Users\Justyna\Documents\!Decrypt-All-Files-lfmhtjh.txt
2015-02-04 15:55 - 2015-02-04 16:55 - 01035672 _____ () C:\ProgramData\qofrgsh.html
2015-02-04 15:47 - 2013-12-29 21:02 - 00000000 ____D () C:\ProgramData\giffmhoghihemcajgfhcocceagggnflf
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.111 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
C:\ProgramData\IePluginServices
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [705416 2014-09-24] (Cherished Technololgy LIMITED)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.111 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
DeleteQuarantine:
Task: {E26B5355-98FE-4CA9-9BDE-9E39E6D39AC0} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask No Task File <==== ATTENTION
Task: {ABF28430-BC3E-4D44-A793-49E7FD7D377C} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline No Task File <==== ATTENTION
Task: {A72AA8EE-3255-461E-9A56-F213661A2A8F} - System32\Tasks\{D6556565-A461-44D9-8895-34C1B0B12BF6} => pcalua.exe -a C:\Users\marcinek\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
C:\Users\marcinek\AppData\Roaming\sweet-page
HKU\S-1-5-21-1026863621-3163709612-1001100603-1000\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2765256 2014-11-03] (ALLPlayer Group Ltd.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.111 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
CHR Extension: (Faster Light) - C:\Users\marcinek\AppData\Local\Google\Chrome\User Data\Default\Extensions\alfoljaapgobblfpenmdcfdjeiaoodce [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
2015-02-08 15:25 - 2015-02-08 15:31 - 00000000 ____D () C:\AdwCleaner
DeleteQuarantine:
Zarejestrowani użytkownicy: Bing [Bot]