UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
HKU\S-1-5-21-3648106757-2650601888-2698748550-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyE0C0DyB0CyCyCyEtGyEtAyD0EtGtBtDyEtAtGyDyD0FyBtGyC0FyDtCzztBtC0AyEtCtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D1120955622%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N
SearchScopes: HKLM DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtB0FtAyByCyD0AtG0AyDtA0FtG0A0CyD0FtG0DyDyC0CtGyC0A0DyBtCtDyBzzzz0C0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D508202451%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N&p={searchTerms}
SearchScopes: HKLM {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtB0FtAyByCyD0AtG0AyDtA0FtG0A0CyD0FtG0DyDyC0CtGyC0A0DyBtCtDyBzzzz0C0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D508202451%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N&p={searchTerms}
SearchScopes: HKLM {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyE0C0DyB0CyCyCyEtGyEtAyD0EtGtBtDyEtAtGyDyD0FyBtGyC0FyDtCzztBtC0AyEtCtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D1120955622%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3648106757-2650601888-2698748550-1001 DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtB0FtAyByCyD0AtG0AyDtA0FtG0A0CyD0FtG0DyDyC0CtGyC0A0DyBtCtDyBzzzz0C0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D508202451%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3648106757-2650601888-2698748550-1001 {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBtB0FtAyByCyD0AtG0AyDtA0FtG0A0CyD0FtG0DyDyC0CtGyC0A0DyBtCtDyBzzzz0C0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D508202451%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3648106757-2650601888-2698748550-1001 {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_20¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDtD0ByC0FyC0F0FyB0E0BtN0D0Tzu0StCtBtBzztN1L2XzutAtFtCtDtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyE0C0DyB0CyCyCyEtGyEtAyD0EtGtBtDyEtAtGyDyD0FyBtGyC0FyDtCzztBtC0AyEtCtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0D0C0CtDzy0FtDtG0B0CyCtDtGyEyDyC0DtGzy0EtB0EtGzz0A0F0CtBtB0AtAyDzz0FtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyByDyB%26cr%3D1120955622%26a%3Dwncy_ir_15_20%26os%3DWindows 8.1 Pro N&p={searchTerms}
CHR HomePage: Default hxxp://www.yessearches.com/?mode=nnnb&ptid=ior&uid=B4A2B182F3A666AE0CD5A1C0574BF485&v=20160202&ts=AHEpB3QoBnAsAU..
CHR StartupUrls: Default "hxxp://www.yessearches.com/?mode=nnnb&ptid=ior&uid=B4A2B182F3A666AE0CD5A1C0574BF485&v=20160202&ts=AHEpB3QoBnAsAU.."
CHR DefaultSearchURL: Default hxxp://www.yessearches.com/chrome.php?q={searchTerms}&ts=AHEpB3QoBnAsAU..&v=20160202&uid=B4A2B182F3A666AE0CD5A1C0574BF485&ptid=ior&mode=nnnb
CHR DefaultSearchKeyword: Default yessearches.com
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk C:\Program Files (x86)\SearchesToYesbnd\shortboost.exe (Brak pliku)
Shortcut: C:\Users\Hajduk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk C:\Program Files (x86)\SearchesToYesbnd\shortboost.exe (Brak pliku)
2016-03-12 09:15 - 2016-02-06 09:29 - 00000000 ____D C:\Program Files (x86)\SearchesToYesbnd
2016-03-12 09:05 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
Task: {3BEF0C71-B965-4260-9F4C-CF7492E2E6C1} - System32\Tasks\HajdukContendsCrypticV2 => Rundll32.exe FungicidallyPhalluses.dll,main 7 1 <==== UWAGA
Task: {FA3BF35D-78FF-4746-AB82-3AEE85601D45} - System32\Tasks\SystemSoundsService => C:\Users\Hajduk\AppData\Local\Temp\nsisvc.exe <==== UWAGA
C:\Users\Hajduk\AppData\Local\Temp\nsisvc.exe
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
przy próbie odinstalowania yessearches Uninstall wyskakuje http://img24.otofotki.pl/us293_Bez%C2%A0tytulu.jpg.html
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono
UA: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
Zarejestrowani użytkownicy: Bing [Bot]