UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
Task: C:\Windows\Tasks\PC_Booster-S-493389286.job => c:\programdata\trusted publisher\pc_booster\PC_Booster.exe <==== ATTENTION
Task: C:\Windows\Tasks\WSE_Astromenda.job => C:\Users\Samsung\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
HKU\S-1-5-21-1764646856-2919567012-2249729535-1000\...\Run: [PeenyBee] => C:\Users\Samsung\AppData\Local\PennyBee\PennyBeeW.exe
C:\Users\Samsung\AppData\Local\PennyBee
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://astromenda.com/?f=1&a=ast_ir_14_34_ff&cd=2XzuyEtN2Y1L1Qzu0EzztAzy0D0F0DyByByEyCzy0ByDtBtCtN0D0Tzu0SzyyCtAtN1L2XzutAtFtDtFtCtDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEyEtDtAyBtC0E0AtGtDyEyE0CtGyB0F0B0BtGzzzz0DtBtGyC0A0DtCtA0BtDzztAtCzy0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0ByE0AyE0ByEyDtGzz0AyB0DtGyEzztA0CtGzztBtBtDtGtBtCtAyDtB0C0A0FtCtDyE0E2Q&cr=29572766&ir=
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_33_ff&cd=2XzuyEtN2Y1L1Qzu0EzztAzy0D0F0DyByByEyCzy0ByDtBtCtN0D0Tzu0SzyyDyBtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDzzyCyCyBtBtAtCtGyCyE0E0CtGtD0FzytAtGyDtDyDtBtGtBzztDyCzztCzyzz0EyByC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0ByE0AyE0ByEyDtGzz0AyB0DtGyEzztA0CtGzztBtBtDtGtBtCtAyDtB0C0A0FtCtDyE0E2Q&cr=1515780790&ir=
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_33_ff&cd=2XzuyEtN2Y1L1Qzu0EzztAzy0D0F0DyByByEyCzy0ByDtBtCtN0D0Tzu0SzyyDyBtN1L2XzutAtFtDtFtCtDtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDzzyCyCyBtBtAtCtGyCyE0E0CtGtD0FzytAtGyDtDyDtBtGtBzztDyCzztCzyzz0EyByC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0ByE0AyE0ByEyDtGzz0AyB0DtGyEzztA0CtGzztBtBtDtGtBtCtAyDtB0C0A0FtCtDyE0E2Q&cr=1515780790&ir=
SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_34_ff&cd=2XzuyEtN2Y1L1Qzu0EzztAzy0D0F0DyByByEyCzy0ByDtBtCtN0D0Tzu0SzyyCtAtN1L2XzutAtFtDtFtCtDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyEyEtDtAyBtC0E0AtGtDyEyE0CtGyB0F0B0BtGzzzz0DtBtGyC0A0DtCtA0BtDzztAtCzy0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0ByE0AyE0ByEyDtGzz0AyB0DtGyEzztA0CtGzztBtBtDtGtBtCtAyDtB0C0A0FtCtDyE0E2Q&cr=29572766&ir=
SearchScopes: HKCU - {E64C30FB-4C8B-4862-8260-0532921DBC58} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_33_ff&cd=2XzuyEtN2Y1L1Qzu0EzztAzy0D0F0DyByByEyCzy0ByDtBtCtN0D0Tzu0SzyyDyCtN1L2XzutAtFtDtFtCtDtFtAtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByBtD0EtC0DzzyCtGyDyDyCyBtGtBtBtByDtG0CtByBzztGyB0D0EzztDzy0A0BzyyB0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0ByE0AyE0ByEyDtGzz0AyB0DtGyEzztA0CtGzztBtBtDtGtBtCtAyDtB0C0A0FtCtDyE0E2Q&cr=996614763&ir=
FF SearchPlugin: C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\g3blov3l.default\searchplugins\Astromenda.xml
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Extension: PRicecchop - C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\g3blov3l.default\Extensions\[email protected] [2014-08-30]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
2014-08-30 15:22 - 2014-08-30 17:04 - 00000000 ____D () C:\ProgramData\pricecHop
2014-08-30 15:22 - 2014-08-30 17:03 - 00000000 ____D () C:\Program Files\pricecHop
2014-08-30 15:22 - 2014-08-30 15:28 - 00000000 ____D () C:\Program Files\PC_Booster
Task: {9B99A8E8-73EC-480A-AB3B-515DADF13D5E} - System32\Tasks\WSE_Astromenda => C:\Users\Samsung\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
Task: {37D6371D-3D36-4181-A2CC-2F53F02D2035} - System32\Tasks\PC_Booster-S-493389286 => c:\programdata\trusted publisher\pc_booster\PC_Booster.exe <==== ATTENTION
UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
Czy był to jakiś keylogger, czy coś takiego i mogę się obawiać o hasła na kontach internetowych z których korzystałem w tym czasie ?
UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
UA: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
Zarejestrowani użytkownicy: Google [Bot]