09 Mar 2017, 16:58
10 Mar 2017, 21:25
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Darek\Desktop\firefox.lnk C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Darek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Darek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) hxxp://www.startpageing123.com/?type=sc&ts=1488822734&z=b582f33fe26644392484e3ag1zdb0b2bao5o9m5c5c&from=che0812&uid=ST1000LM014-1EJ164_W380NPCWXXXXW380NPCW
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) hxxp://qtipr.com/
Shortcut: C:\Users\Darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk 0x4C0000000114020000000000C000000000000046800000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000
Shortcut: C:\Users\Darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk 0x4C0000000114020000000000C000000000000046800000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000
WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA
2017-03-05 16:44 - 2017-03-05 16:44 - 00524696 ____N () C:\Program Files\żěŃą\X64\KZipShell.dll
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-145523208-3615491097-2993822386-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1488822734&z=b582f33fe26644392484e3ag1zdb0b2bao5o9m5c5c&from=che0812&uid=ST1000LM014-1EJ164_W380NPCWXXXXW380NPCW&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1488822734&z=b582f33fe26644392484e3ag1zdb0b2bao5o9m5c5c&from=che0812&uid=ST1000LM014-1EJ164_W380NPCWXXXXW380NPCW&q={searchTerms}
BHO: Brak nazwy {11111111-1111-1111-1111-110611171152} Brak pliku
BHO: Brak nazwy {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} Brak pliku
FF Homepage: Mozilla\Firefox\Profiles\4f19p46w.default hxxp://www.startpageing123.com/?type=hp&ts=1488822734&z=b582f33fe26644392484e3ag1zdb0b2bao5o9m5c5c&from=che0812&uid=ST1000LM014-1EJ164_W380NPCWXXXXW380NPCW
FF ProfilePath: C:\Users\Darek\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\4f19p46w.default\Profiles\4f19p46w.default [nie znaleziono]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn => nie znaleziono
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx <nie znaleziono>
S4 ed2kidle; "C:\Program Files (x86)\amulell\ed2k.exe" -downloadwhenidle [X]
S2 WinSnare; C:\Users\Darek\AppData\Roaming\WinSnare\WinSnare.dll [776704 2017-03-08] (InterSect Alliance Pty Ltd) [Brak podpisu cyfrowego] <==== UWAGA
C:\Users\Darek\AppData\Roaming\WinSnare
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [80768 2016-04-13] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== UWAGA
S1 a2util; \??\C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2util64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 GUMHFilters; \??\C:\Program Files (x86)\Glarysoft\Malware Hunter\Native\winxp_x64\GUMHFilter.sys [X]
C:\ProgramData\a.bat
EmptyTemp:
12 Mar 2017, 17:29
14 Mar 2017, 00:12
Task: {395595DD-B903-4BD6-BAB0-C2FF230D308A} - Brak ścieżki do pliku
SearchScopes: HKLM DefaultScope - brak wartości
SearchScopes: HKLM-x32 DefaultScope - brak wartości
S1 a2util; \??\C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2util64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 GUMHFilters; \??\C:\Program Files (x86)\Glarysoft\Malware Hunter\Native\winxp_x64\GUMHFilter.sys [X]
C:\ProgramData\a.bat
14 Mar 2017, 19:25
14 Mar 2017, 21:54
DeleteQuarantine:
19 Mar 2017, 16:34