

Sale Charger (HKLM-x32\...\Sale Charger) (Version: 2.0.5599.8363 - Sale Charger)
2015-05-17 05:32 - 2015-06-07 11:39 - 00650512 _____ () C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe
2015-05-01 17:39 - 2015-06-07 12:40 - 00572688 _____ () C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe
C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad
C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad
BHO-x32: Sale Charger -> {7a38e53c-e000-41e4-9b5a-47447db81c2b} -> C:\Program Files (x86)\Sale Charger\Extensions\7a38e53c-e000-41e4-9b5a-47447db81c2b.dll ()
C:\Program Files (x86)\Sale Charger
R2 Service Mgr SaleCharger; C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe [650512 2015-06-07] ()
R2 Update Mgr SaleCharger; C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe [572688 2015-06-07] ()
HKU\S-1-5-21-716756963-157338070-3420724354-1000\...\Run: [Direct-link] => wscript.exe //B "C:\Users\Ala\AppData\Local\Temp\Direct-link.vbs" <===== ATTENTION
Startup: C:\Users\Ala\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Direct-link.vbs ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1430497240&from=cor&uid=ST9250315AS_5VCAVDHWXXXX5VCAVDHW&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1430497240&from=cor&uid=ST9250315AS_5VCAVDHWXXXX5VCAVDHW&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1430497240&from=cor&uid=ST9250315AS_5VCAVDHWXXXX5VCAVDHW&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1430497240&from=cor&uid=ST9250315AS_5VCAVDHWXXXX5VCAVDHW&q={searchTerms}
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 1 gość