01 Mar 2016, 19:46
01 Mar 2016, 21:48
02 Mar 2016, 22:10
02 Mar 2016, 22:44
Task: C:\WINDOWS\Tasks\OEMSlabberOutthinkV2.job => C:\WINDOWS\system32\rundll32.exeViscositySanely.dll
Task: C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job => C:\WINDOWS\system32\xp_eos.exe
ShortcutWithArgument: C:\Documents and Settings\OEM\Pulpit\Mozilla Firefox.lnk C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) hxxp://www.yoursearching.com/?type=sc&ts=1451578203&z=72d34fd3cad7fefbcfac2d4gdz5w7gcw6m1b9o7e6c&from=cor&uid=wdcxwd2500ks-00mjb0_wd-wcankl18351483514
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) hxxp://www.yoursearching.com/?type=sc&ts=1451578203&z=72d34fd3cad7fefbcfac2d4gdz5w7gcw6m1b9o7e6c&from=cor&uid=wdcxwd2500ks-00mjb0_wd-wcankl18351483514
HKU\S-1-5-21-4064956397-524745609-764872598-1004\...\MountPoints2: {433f45fe-0661-11df-8699-001d7d944675} - G:\ZURIM/prazno.exe
G:\ZURIM/prazno.exe
HKU\S-1-5-21-4064956397-524745609-764872598-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono
S3 Ad-Watch Connect Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys [X]
S3 Ad-Watch Real-Time Scanner; \??\C:\WINDOWS\system32\drivers\AWRTPD.sys [X]
S3 Ad-Watch Registry Filter; \??\C:\WINDOWS\system32\drivers\AWRTRD.sys [X]
U2 CertPropSvc; Brak ImagePath
S4 IntelIde; Brak ImagePath
S0 Lbd; system32\DRIVERS\Lbd.sys [X]
C:\Documents and Settings\OEM\pitw03.dll
EmptyTemp: