
Dodano 18.12.2015 15:57:38:
Dodano 18.12.2015 17:20:18:
skan z gmera
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKU\S-1-5-21-1757981266-562591055-725345543-1003\...\Run: [cable-4] => C:\Documents and Settings\All Users\cable-7\cable-8.exe [452096 2015-12-18] ()
HKU\S-1-5-21-1757981266-562591055-725345543-1003\...\Winlogon: [Shell] C:\Documents and Settings\All Users\codec-6\codec-75.exe -2,explorer.exe <==== UWAGA
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-1757981266-562591055-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://q.search-simple.com/?m=tab&affID=na" <======= UWAGA
DeleteKey: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes
SearchScopes: HKU\S-1-5-21-1757981266-562591055-725345543-1003 -> {4B93B1D9-CF79-4967-8321-CD89BA29C697} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}
FF SelectedSearchEngine: Yahoo! Search
FF SearchPlugin: C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\searchplugins\istartpageing.xml [2015-12-18]
FF SearchPlugin: C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\searchplugins\search-simple.xml [2015-03-21]
FF Extension: FirefixTab - C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\extensions\deskCutv2@gmail.com [2015-12-18] [Brak podpisu cyfrowego]
FF Extension: YahooToolsProtected - C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\extensions\yahooprotected@gmail.com [2015-12-18] [Brak podpisu cyfrowego]
FF Extension: Discovery App - C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\Extensions\{63c7087a-cae6-482e-8a61-426a4c6dfc53}.xpi [2015-12-18] [Brak podpisu cyfrowego]
FF HKLM\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\extensions\deskCutv2@gmail.com
FF HKLM\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Documents and Settings\komp\Dane aplikacji\Mozilla\Firefox\Profiles\21ae3oae.default\extensions\yahooprotected@gmail.com
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [771456 2015-04-19] (Enigma Software Group USA, LLC.)
C:\Program Files\Enigma Software Group
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-04-19] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
C:\WINDOWS\System32\DRIVERS\EsgScanner.sys
2015-12-18 14:51 - 2015-12-18 14:52 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Tmp0x0x
2015-12-18 14:51 - 2015-12-18 14:51 - 00000000 ____D C:\Documents and Settings\komp\Dane aplikacji\istartpageing
2015-12-18 14:50 - 2015-12-18 14:50 - 00000000 ____D C:\Program Files\Common Files\653ac11b-b606-42c5-b357-bca0fd28d1cd
2015-12-18 14:49 - 2015-12-18 14:50 - 00000000 ____D C:\Program Files\Discovery App
2015-12-18 14:49 - 2015-12-18 14:50 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\653ac11b-b606-42c5-b357-bca0fd28d1cd
EmptyTemp:
mss3.*
nss3
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 1 gość