UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.101 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.101 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
Task: {52B77894-E898-4B1D-BA70-0B1CEC120593} - System32\Tasks\Run_dregol => C:\Users\bartek\AppData\Roaming\Run_dregol\UpdateProc\UpdateTask.exe [2015-03-31] () <==== ATTENTION
C:\Users\bartek\AppData\Roaming\Run_dregol
Task: {B3D7211C-DF9F-4390-AC29-FD1713040D94} - System32\Tasks\Binkiland fime => C:\ProgramData\{3C6FD4AC-6CED-052A-DD6B-75A80DE9A626}\1.9.3.1\f <==== ATTENTION
C:\ProgramData\{3C6FD4AC-6CED-052A-DD6B-75A80DE9A626}
Task: C:\Windows\Tasks\Run_dregol.job => C:\Users\bartek\AppData\Roaming\RUN_DR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [973176 2010-12-15] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-05-04] (Toshiba Europe GmbH)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1406248 2011-01-07] (Nero AG)
HKLM-x32\...\RunOnce: [Run_dregol] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\bartek\AppData\Roaming\Run_dregol\UpdateProc\bkup.dat"
HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-21-3708295588-139061678-3123888192-1001\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
HKU\S-1-5-21-3708295588-139061678-3123888192-1001\...\RunOnce: [Run_dregol] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\bartek\AppData\Roaming\Run_dregol\UpdateProc\bkup.dat"
HKU\S-1-5-21-3708295588-139061678-3123888192-1003\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA)
AppInit_DLLs-x32: C:/PROGRA~3/{8E336~1/193~1.1/mole.dll => C:\ProgramData\{8E3366F0-DEB1-B776-6F37-C7F4BFB5147A}\1.9.3.1\mole.dll [1010688 2015-03-31] ()
AppInit_DLLs-x32: C:/PROGRA~3/{3C6FD~1/193~1.1/fime.dll => C:\ProgramData\{3C6FD4AC-6CED-052A-DD6B-75A80DE9A626}\1.9.3.1\fime.dll [1010688 2015-03-22] ()
C:/PROGRA~3/{8E336~1/193~1.1/mole.dll => C:\ProgramData\{8E3366F0-DEB1-B776-6F37-C7F4BFB5147A}
HKU\S-1-5-21-3708295588-139061678-3123888192-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dregol.com/?f=1&a=drg_ir_15_14&cd=2XzuyEtN2Y1L1Qzu0Ezzzy0Azz0FyCzy0C0F0F0FyC0ByCtCtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFzztFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyCtC0FtC0C0FtCtAtGyC0AyEyCtGtCyEtByCtGyDyDyBtAtGyBtCzy0D0EyDyDzyyEtByDzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytDyE0B0ByEzzyCtG0B0DyBtDtGyEyByEyDtG0BtA0BzztG0FyBtA0B0E0AtAtC0F0EtD0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyEyD&cr=410039088&ir=
SearchScopes: HKU\S-1-5-21-3708295588-139061678-3123888192-1001 {783DC9ED-9610-47F8-8B86-BAE7988DE46F} URL = http://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3708295588-139061678-3123888192-1001 {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = http://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ir_15_14&cd=2XzuyEtN2Y1L1Qzu0Ezzzy0Azz0FyCzy0C0F0F0FyC0ByCtCtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFzztFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyCtC0FtC0C0FtCtAtGyC0AyEyCtGtCyEtByCtGyDyDyBtAtGyBtCzy0D0EyDyDzyyEtByDzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytDyE0B0ByEzzyCtG0B0DyBtDtGyEyByEyDtG0BtA0BzztG0FyBtA0B0E0AtAtC0F0EtD0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyEyD&cr=410039088&ir=
BHO-x32: No Name {ed66005b-3c60-469c-a11b-211b53e83d9e} No File
CHR HomePage: Default hxxp://www.dregol.com/?f=1&a=drg_ir_15_14&cd=2XzuyEtN2Y1L1Qzu0Ezzzy0Azz0FyCzy0C0F0F0FyC0ByCtCtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFzztFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyCtC0FtC0C0FtCtAtGyC0AyEyCtGtCyEtByCtGyDyDyBtAtGyBtCzy0D0EyDyDzyyEtByDzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytDyE0B0ByEzzyCtG0B0DyBtDtGyEyByEyDtG0BtA0BzztG0FyBtA0B0E0AtAtC0F0EtD0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyEyD&cr=410039088&ir=
CHR StartupUrls: Default "hxxp://www.dregol.com/?f=7&a=drg_ir_15_14&cd=2XzuyEtN2Y1L1Qzu0Ezzzy0Azz0FyCzy0C0F0F0FyC0ByCtCtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFzztFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyCtC0FtC0C0FtCtAtGyC0AyEyCtGtCyEtByCtGyDyDyBtAtGyBtCzy0D0EyDyDzyyEtByDzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytDyE0B0ByEzzyCtG0B0DyBtDtGyEyByEyDtG0BtA0BzztG0FyBtA0B0E0AtAtC0F0EtD0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyEyD&cr=410039088&ir=", "https://www.google.com/?trackid=sp-006"
CHR Extension: (Between Lines) - C:\Users\bartek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcleckandofjmcoaohlkeifkpjfobdka [2015-03-25]
S3 Tosrfcom; No ImagePath
2015-03-21 11:23 - 2015-03-21 11:23 - 0004939 _____ () C:\ProgramData\flwjycbm.bab
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.101 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
DeleteQuarantine:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.118 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników