
ShortcutWithArgument: C:\Users\Jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.attirerpage.com/?type=sc&ts=1467034272&z=4239846f6ec2cb333bb2c65g0z3q9mee7c0z3o6mfo&from=ihpm0627&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
ShortcutWithArgument: C:\Users\Jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.attirerpage.com/?type=sc&ts=1467034272&z=4239846f6ec2cb333bb2c65g0z3q9mee7c0z3o6mfo&from=ihpm0627&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
ShortcutWithArgument: C:\Users\Jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.nuesearch.com/?type=sc&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk -> C:\Program Files\AVAST Software\SZBrowser\launcher.exe (Avast Software) -> hxxp://www.attirerpage.com/?type=sc&ts=1467034272&z=4239846f6ec2cb333bb2c65g0z3q9mee7c0z3o6mfo&from=ihpm0627&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.nuesearch.com/?type=sc&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.nuesearch.com/?type=sc&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
RemoveDirectory: C:\Program Files (x86)\jIxmRfR
RemoveDirectory: C:\ProgramData\ChelfNotify
RemoveDirectory: C:\Program Files (x86)\Uncheckit
RemoveDirectory: C:\Program Files (x86)\SFK
RemoveDirectory: C:\Program Files (x86)\WinSaber
RemoveDirectory: C:\ProgramData\jIxmRfR
RemoveDirectory: C:\ProgramData\cwinpc
RemoveDirectory: C:\Users\Jacek\AppData\Roaming\setup1
RemoveDirectory: C:\Program Files (x86)\yesbnd
RemoveDirectory: C:\ProgramData\desktopfind
FirewallRules: [{801185C7-1789-4126-8239-C95BB7B7A245}] => (Allow) C:\ProgramData\jIxmRfR\protect\protect.exe
FirewallRules: [{D650365D-43FB-4D7C-9ECA-DC4F3AD4220F}] => (Allow) C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
FirewallRules: [{2EC39420-1578-44F5-AB0C-98E4761B9094}] => (Allow) C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe
appInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => Brak pliku
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
HKU\S-1-5-21-4138440711-1150469708-1476838973-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
HKU\S-1-5-21-4138440711-1150469708-1476838973-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4138440711-1150469708-1476838973-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4138440711-1150469708-1476838973-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.attirerpage.com/search/?type=ds&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.piesearch.com/?uid=b66c080c-b693-4c8a-bd8e-f02b7f5010e2
Edge HomeButtonPage: HKU\S-1-5-21-4138440711-1150469708-1476838973-1001 -> hxxp://www.attirerpage.com/?type=hp&ts=1466149130&z=421f29b9a71c2a162d0a594g9zeq1q3g0z5t7gdocb&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
FF NewTab: about:newtab
Task: {09338F8B-2662-4473-B0F6-532CA0A47945} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA
Task: {3E89B765-0E7E-45F5-B0E2-2B4EC2634672} - System32\Tasks\ChelfNotify Task => C:\ProgramData\ChelfNotify\BrowserUpdate.exe [2016-06-30] (Tencent)
Task: {43EDFA3A-1517-4D4C-ABF1-FF559ABA6D27} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
Task: {452FA334-F467-4CB2-9BE9-091C9659CB40} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
Task: {6D5464B1-829F-4020-A514-4305BDB74F52} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Brak pliku <==== UWAGA
Task: {6E1619C9-53D9-4B84-9CC4-CBE6B7665018} - System32\Tasks\Browser Updater Task(Core) => C:\Program Files (x86)\TXQQBrowser\Update\EBA1B7E7D62E0AD55B80AE9E49F97C1A\Update\BrowserUpdate.exe [2016-04-25] (Tencent) <==== UWAGA
Task: {744E8030-DCFC-4A4C-8FE3-859E0B3DB620} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
Task: {7BF05449-2F19-489B-8E6E-7CE93760C05F} - System32\Tasks\UncheckitUpdateTaskC => C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe <==== UWAGA
Task: {7D2DCE4E-8D2C-4D30-9D86-61E7B40D2EC4} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA
Task: {983BF1C2-16FC-45C2-8902-EE2DCB833E87} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA
Task: {98AD6BA1-EAB1-483E-825A-1F8817C9A362} - System32\Tasks\UncheckitUpdateTaskDB => C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe <==== UWAGA
Task: {B078C9D2-0315-454E-A90D-D9BB5584B892} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA
Task: {C8E3B4F0-F7F4-4A8E-8D28-2AA47AE35970} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Brak pliku <==== UWAGA
Task: {CA0FDB3A-06B9-4167-85C8-D3E23C7AE795} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
Task: {D425727D-583B-4FCD-98BD-C474488F297E} - System32\Tasks\UncheckitTaskMN => C:\Program Files (x86)\Uncheckit\cktSvc.exe <==== UWAGA
Task: {DFE89174-F060-476E-8B16-CEC83FCEF149} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
Task: {F3133911-BB9E-4B3F-BF32-D77E72325FFC} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
FF Homepage: hxxp://www.nuesearch.com/?type=hp&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
FF Plugin HKU\S-1-5-21-4138440711-1150469708-1476838973-1001: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll [Brak pliku]
FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\Jacek\AppData\Roaming\Mozilla\Firefox\Profiles\zqagu4cy.default\extensions\arthurj8283@gmail.com => nie znaleziono
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.nuesearch.com/?type=sc&ts=1471341874&z=44027a6172a74e2174b1cc5g7z0m4gdc5zbg4bfm7c&from=wpm0616&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4
CHR HomePage: Default -> hxxp://www.nicesearches.com?type=hp&ts=1461573457&from=86490425&uid=st500lt012-1dg142_s3pklal4xxxxs3pklal4&z=77d2858b151431bfee3f563gbz1q6g7w4mdc4zdw4m
CHR StartupUrls: Default -> "hxxp://www.nicesearches.com?type=hp&ts=1461573457&from=86490425&uid=st500lt012-1dg142_s3pklal4xxxxs3pklal4&z=77d2858b151431bfee3f563gbz1q6g7w4mdc4zdw4m"
CHR DefaultSearchURL: Default -> hxxp://www.nuesearch.com/search/?type=ds&ts=1469459929&z=ddf389da043d5056e34ccfegdz5q5tdzaw7t1tao3t&from=ihpm0722&uid=ST500LT012-1DG142_S3PKLAL4XXXXS3PKLAL4&q={searchTerms}
CHR DefaultSearchKeyword: Default -> nuesearch
S2 BugreportW; C:\Program Files (x86)\yesbnd\mbat.exe [990336 2016-04-12] ()
S2 DeskTop_F; C:\ProgramData\desktopfind\desktop244.exe [236728 2016-03-16] (DeskTopService)
R2 IhPul; C:\Users\Jacek\AppData\Roaming\setup1\TSvr.exe [210120 2016-08-16] (Trend Corp.)
R2 jIxmRfR_protect; C:\ProgramData\jIxmRfR\protect\protect.exe [303016 2016-04-21] ()
R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [162528 2016-07-27] ()
R2 WdMan; C:\ProgramData\cwinpc\WFini.exe [541928 2016-08-15] (WFini LIMITED)
R2 winsaber; C:\Program Files (x86)\WinSaber\WinSaber.exe [427256 2016-08-15] ()
S2 cktSvc; "C:\Program Files (x86)\Uncheckit\cktSvc.exe" {92E162D7-70FD-48F7-A779-91154F8FD518} [X]
S2 qkseeService; C:\Program Files (x86)\qksee\qkseeSvc.exe [X]
S2 UncheckitSvc; C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe [X]
C:\Program Files (x86)\qksee
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [260856 2015-05-14] (Elex do Brasil cenzura!ções Ltda)
C:\Program Files (x86)\Elex-tech
C:\WINDOWS\SysWOW64\pl.html
C:\Program Files (x86)\vcpcltsm
C:\ProgramData\WwinpW
C:\WINDOWS\SysWOW64\pl_*.html
C:\WINDOWS\SysWOW64\EN_*.html
C:\ProgramData\9winp9
C:\ProgramData\RwinpR
2016-07-26 12:43 - 2016-07-26 12:43 - 00000000 ____D C:\ProgramData\uckt
2016-07-26 12:43 - 2016-07-26 12:43 - 00000000 ____D C:\ProgramData\NwinpN
2016-07-26 12:43 - 2016-07-26 12:43 - 00000000 ____D C:\Program Files (x86)\064iwpk3
2016-07-25 17:18 - 2016-08-14 11:37 - 00000000 ____D C:\WINDOWS\SysWOW64\_SSpm
2016-07-21 08:43 - 2016-07-21 08:43 - 00000000 ____D C:\ProgramData\AwinpA
2016-07-21 08:43 - 2016-07-21 08:43 - 00000000 ____D C:\Program Files (x86)\WinSaber
2016-07-21 08:43 - 2016-07-21 08:43 - 00000000 ____D C:\Program Files (x86)\v2u7wtkw
C:\Program Files (x86)\WinZipper
2016-08-14 11:37 - 2016-06-27 15:31 - 00000000 ____D C:\WINDOWS\SysWOW64\_TSpm
2016-08-14 11:37 - 2016-06-17 09:38 - 00000000 ____D C:\WINDOWS\SysWOW64\_tWm
2016-08-14 10:23 - 2016-04-15 15:01 - 00000000 ____D C:\ProgramData\5winp5
2016-08-14 10:22 - 2016-06-16 13:05 - 00000000 ____D C:\Program Files (x86)\TData
2016-07-27 09:23 - 2016-07-01 14:44 - 03124116 _____ (Update) C:\Program Files (x86)\SSFK.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
C:\Users\Jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\qksee.lnk
HOSTS:
EmptyTemp:
[-] Usunięto folder: C:\Program Files (x86)\advanced system optimizer 3
Task: {58B49E8E-554E-4B64-94A3-EBC55997209F} - System32\Tasks\ASO-OneClickCare => C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe
Task: {5A950030-7F1B-4080-90EE-AA9EBF4BDE3B} - System32\Tasks\ASO-AutoCheckUpdate7Days => C:\Program Files (x86)\Advanced System Optimizer 3\CheckUpdate.exe
Task: {6C84D6A2-35A4-40E8-A6C5-6CCDC33D4F92} - System32\Tasks\ASOService => C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe
Task: C:\WINDOWS\Tasks\ASO-AutoCheckUpdate7Days.job => C:\Program Files (x86)\Advanced System Optimizer 3\CheckUpdate.exe
Task: C:\WINDOWS\Tasks\ASO-OneClickCare.job => C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe
Task: C:\WINDOWS\Tasks\ASOService.job => C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe-checklastscanstatus C:\Program Files (x86)\Advanced System Optimizer 3\aso3.exe
Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v Advanced System Optimizer /f
Reg: reg delete HKU\S-1-5-21-4138440711-1150469708-1476838973-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Advanced System Optimizer /f /f
FirewallRules: [{A885928B-81CC-4D53-B091-CA87EECED074}] => (Allow) C:\ProgramData\jIxmRfR\protect\protect.exe
HKLM-x32\...\Run: [Advanced System Optimizer] => "C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe" /autorun
C:\Program Files (x86)\Advanced System Optimizer 3
RemoveDirectory: C:\ProgramData\jIxmRfR
AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => Brak pliku
C:\PROGRA~2\Amazon
HKU\S-1-5-21-4138440711-1150469708-1476838973-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
HKU\S-1-5-21-4138440711-1150469708-1476838973-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://mystart.lenovo.com
C:\Program Files (x86)\Firefox_temp
C:\Users\Public\Documents\report1.dat
EmptyTemp:
w nowej karcie pojawia się inme
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości