11 Sty 2015, 23:59
12 Sty 2015, 14:09
12 Sty 2015, 14:25
12 Sty 2015, 14:37
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2012-03-13] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-22] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
ShellIconOverlayIdentifiers: [00avast] {472083B0-C522-11CF-8763-00608CC02F24} => No File
BootExecute: autocheck autochk * aswBoot.exe /M:4cbc45213 /wow /dir:"C:\Program Files\AVAST Software\Avast"
BHO-x32: No Name {b608cc98-54de-4775-96c9-097de398500c} No File
CHR DefaultSearchKeyword: Default DC8086BC7A6A1B7DFAE64B153147ADE998985732AE07FAB436CB5127267C9BC6
CHR DefaultSearchURL: Default 9DED0D10782B3848F8DB7A0AF071CBB36F68E4AF47A7E8BD9ECB2074870F94FB
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Extension: (tpeRFEctaccooupon) - C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggonifdegfgifebkiokadkaljdjemlgn [2015-01-11]
CHR Extension: (Browser Champion) - C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhajokkdlhllmgenmniigcnlefjakobn [2015-01-11]
CHR Extension: (ipfnecmlncaiipncipkgijboddcdmego) - C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipfnecmlncaiipncipkgijboddcdmego [2015-01-10]
CHR Extension: (deaoL4rreoal) - C:\ProgramData\mfofiohiplokdpnlafpaemfojccfmdma\ [2015-01-10]
C:\ProgramData\mfofiohiplokdpnlafpaemfojccfmdma
R2 7baa6e25; c:\Program Files (x86)\SystemHero\SystemHero.dll [1917440 2015-01-10] () [File not signed]
c:\Program Files (x86)\SystemHero
2015-01-11 22:15 - 2015-01-11 22:15 - 00000000 ____D () C:\Program Files (x86)\deAolster
2015-01-11 22:14 - 2015-01-11 22:14 - 00000000 ____D () C:\Program Files (x86)\FFineDealSofft
2015-01-11 21:58 - 2015-01-11 22:17 - 00000000 ____D () C:\ProgramData\FFineDealSofft
2015-01-11 21:57 - 2015-01-11 22:15 - 00000000 ____D () C:\ProgramData\a659a42d9d6a3e6b
2015-01-11 21:56 - 2015-01-11 22:17 - 00000000 ____D () C:\ProgramData\deAolster
2015-01-10 18:15 - 2015-01-10 19:30 - 00000000 ____D () C:\Update
2015-01-10 16:36 - 2015-01-10 16:36 - 00000000 ____D () C:\ProgramData\951918458
2015-01-10 15:56 - 2015-01-10 18:32 - 00000000 ____D () C:\AdwCleaner
2015-01-10 12:57 - 2015-01-10 12:58 - 00583536 _____ () C:\Users\Magda\Downloads\Java.exe
Task: {C9B581AD-0EC0-481F-952F-73C8FC7BFF32} - System32\Tasks\AMFUPMNF => C:\Users\Magda\AppData\Roaming\AMFUPMNF.exe [2014-11-09] (CinemaPlusV09.11) <==== ATTENTION
C:\Users\Magda\AppData\Roaming\AMFUPMNF.exe
Task: C:\Windows\Tasks\AMFUPMNF.job => C:\Users\Magda\AppData\Roaming\AMFUPMNF.exe <==== ATTENTION
Hosts:
EmptyTemp:
12 Sty 2015, 14:56
13 Sty 2015, 00:34
C:\ProgramData\a5d1a7040000094a
DeleteQuarantine:
13 Sty 2015, 01:57
13 Sty 2015, 13:25
13 Sty 2015, 18:01
14 Sty 2015, 14:14
14 Sty 2015, 15:36
14 Sty 2015, 15:42
14 Sty 2015, 16:02
16 Sty 2015, 22:30
20 Sty 2015, 16:44