
Gmera zablokowalo cos i przy pre-scanie i w trakcie drugiego.
OTL:
http://wklej.org/hash/0cc8112c243/
http://wklej.org/id/1515368/
[2014-11-09 13:27:16 | 000,000,000 | ---D | C] -- C:\ProgramData\ddc24aa9-6c5d-44d0-8c40-9bed83bb2ab7
[2014-11-09 12:36:02 | 000,000,000 | ---D | C] -- C:\ProgramData\7bcda15dcba290de
[2014-11-09 11:58:34 | 000,000,000 | ---D | C] -- C:\Users\Magda\AppData\Local\StormFall
[2014-11-09 11:58:03 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2014-11-09 11:57:56 | 000,000,000 | ---D | C] -- C:\Users\Magda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceFountain
[2014-11-10 10:43:59 | 000,000,117 | ---- | M] () -- C:\Users\Magda\Desktop\546096df35fd3 (1)
[2014-11-10 10:43:50 | 000,000,112 | ---- | M] () -- C:\Users\Magda\Desktop\546096df35fd3
[2014-11-10 10:34:33 | 000,380,416 | ---- | M] () -- C:\Users\Magda\Desktop\ek443ut1.exe
[2014-11-10 10:33:44 | 000,380,416 | ---- | M] () -- C:\Users\Magda\Desktop\tsciwrj1.exe
[2014-11-10 09:58:00 | 000,000,306 | ---- | M] () -- C:\Windows\tasks\Price Fountain.job
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\ProgramData\ddc24aa9-6c5d-44d0-8c40-9bed83bb2ab7
C:\ProgramData\7bcda15dcba290de
C:\Windows\Tasks\Price Fountain.job
C:\Windows\System32\Tasks\Price Fountain
C:\Users\Magda\AppData\Local\StormFall
C:\ProgramData\boost_interprocess
C:\{b6a94784-0ffb-4121-88c6-435139067ee2}.xpi
C:\Users\Magda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceFountain
C:\Users\Magda\AppData\Local\Sparta
Task: {6E01D1F4-8DFF-4189-BA97-ABAB9775C31C} - System32\Tasks\Price Fountain => C:\Users\Magda\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\Magda\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
HKU\S-1-5-21-2750239122-3784559806-2899919771-1001\...\Run: [pricefountainw.exe] => C:\Users\Magda\AppData\Local\PriceFountain\pricefountainw.exe HKEY_CURRENT_USER Software\PriceFountain
:\Users\Magda\AppData\Local\PriceFountain
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 4 gości