
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\globalupdate Helper" /f
Task: {5547EC1D-2474-449E-8B78-9E6BD1F1EE55} - System32\Tasks\Origin => C:\Users\Artur\AppData\Roaming\Origin\update.vbe [2015-07-23] () <==== ATTENTION
C:\Users\Artur\AppData\Roaming\Origin\update.vbe
Task: {600ECB01-33FB-47DB-A91F-30440FC77F00} - System32\Tasks\YAkiUXoNRQEwFp => C:\Users\Artur\AppData\Roaming\YAkiUXoNRQEwFp.exe <==== ATTENTION
C:\Users\Artur\AppData\Roaming\YAkiUXoNRQEwFp.exe
Task: {848D6B3C-0EB2-49D4-86D4-17A4C73B9D26} - System32\Tasks\{FC4E4997-9E58-40E3-AE62-088EE49ECEBB} => pcalua.exe -a C:\Users\Artur\AppData\Local\71FAB307-1439980954-A446-BBA4-6DC79FC573D4\Uninstall.exe
Task: {FF6D48C5-FC07-4D2A-8210-3FBF0D403934} - System32\Tasks\{77F7D155-5071-4CF2-9571-C2624341B79B} => pcalua.exe -a C:\Users\Artur\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=obw
C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\hnsq47D1.tmp
2015-08-12 10:45 - 2015-08-12 10:45 - 00171848 _____ () C:\Program Files\shopperz12082015\LuacRouct.exe
2015-08-19 10:42 - 2015-08-19 10:42 - 00209920 _____ () C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\jnsf2C0A.tmp
2015-08-19 10:41 - 2015-08-19 10:41 - 00053760 _____ () C:\Users\Artur\AppData\Local\Quoteelectrics.exe
2015-08-19 09:01 - 2015-08-19 09:01 - 00759296 _____ () C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\knsq765.tmpfs
2015-08-12 10:45 - 2015-08-12 10:45 - 02043720 _____ () C:\Program Files\shopperz12082015\Uiviuuj.exe
C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4
C:\Program Files (x86)\baidu\pps.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Uiviuuj => ""="service"
FirewallRules: [{4DB408DB-C082-4785-9359-AD94C01735BB}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
C:\ProgramData\SetStretch.VBS
C:\Program Files\shopperz12082015
HKLM\...\Run: [gpuminer] => C:\Users\Artur\AppData\Roaming\cpuminer\sgminer\sgminer.cmd
HKLM\...\Run: [cpuminer] => C:\Windows\system32\cpuminer-gw64.exe
C:\Users\Artur\AppData\Roaming\cpuminer
C:\Windows\system32\cpuminer-gw64.exe
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\pps.exe [77824 2015-08-12] ()
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\...\Run: [GoogleChromeAutoLaunch_AB36A643445FA0F587EA483D7DEFCA2C] => "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
C:\Program Files (x86)\Crossbrowse
FF Plugin: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [No File]
FF Plugin: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
R2 comyninu; C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\hnsq47D1.tmp [161792 2015-08-19] () [File not signed]
R2 hyverumu; C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\jnsf2C0A.tmp [209920 2015-08-19] () [File not signed]
R2 posdoonioadowaeoad; C:\Users\Artur\AppData\Local\Quoteelectrics.exe [53760 2015-08-19] () [File not signed]
R3 Uiviuuj; C:\Program Files\shopperz12082015\Uiviuuj.exe [2043720 2015-08-12] ()
R2 tobywimy; C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\knsq765.tmpfs [X]
C:\ProgramData\HWinManProH
c:\ProgramData\FWinManProF
c:\Windows\SysWOW64\Uiviuuj.ini
2015-08-19 11:16 - 2015-08-19 12:53 - 00002488 _____ C:\Windows\SysWOW64\UiviuujOff.ini
2015-08-19 11:16 - 2015-08-19 12:53 - 00002488 _____ C:\Windows\system32\UiviuujOff.ini
2015-08-19 11:16 - 2015-08-19 11:16 - 00000000 ____D C:\Users\Public\QiYi
2015-08-19 11:16 - 2015-08-12 10:45 - 00353608 _____ C:\Windows\system32\Uiviuuj64.dll
2015-08-19 11:16 - 2015-08-12 10:45 - 00283464 _____ C:\Windows\SysWOW64\Uiviuuj.dll
2015-08-19 11:15 - 2015-08-19 11:41 - 00000000 ____D C:\Program Files\shopperz12082015
2015-08-19 11:15 - 2015-08-19 11:16 - 00000000 ____D C:\Program Files (x86)\MyBrowser 1.0.2V18.08
2015-08-19 11:15 - 2015-08-19 11:15 - 00000045 _____ C:\user.js
2015-08-19 11:15 - 2015-08-19 11:15 - 00000000 ____D C:\Windows\system32\rie
2015-08-19 11:15 - 2015-08-19 11:15 - 00000000 ____D C:\Program Files (x86)\56f91ca9-7c67-4896-90b4-2816b6cacefc
2015-08-19 11:14 - 2015-08-19 12:31 - 00000651 _____ C:\task.vbs
2015-08-19 11:14 - 2015-08-19 11:14 - 00000000 ____D C:\ProgramData\ZWinManProZ
2015-08-19 11:14 - 2015-08-19 11:14 - 00000000 ____D C:\Program Files (x86)\baidu
2015-08-19 10:42 - 2015-08-19 10:43 - 00000000 ____D C:\ProgramData\OWinManProO
2015-08-19 10:42 - 2015-08-19 10:42 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
EmptyTemp:
S2 ElejooLyunp; "C:\Program Files\shopperz12082015\LuacRouct.exe" -cmd [X]
S2 retixoty; C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4\knswFD95.tmp [X]
C:\Program Files (x86)\71FAB307-1439973707-A446-BBA4-6DC79FC573D4
C:\Program Files\shopperz12082015
C:\Windows\Tasks\YAkiUXoNRQEwFp.job
Task: C:\Windows\Tasks\YAkiUXoNRQEwFp.job => C:\Users\Artur\AppData\Roaming\YAkiUXoNRQEwFp.exe <==== ATTENTION
C:\Users\Artur\AppData\Roaming\YAkiUXoNRQEwFp.exe
EmptyTemp:
DeleteQuarantine:
C:\Users\Artur\AppData\Roaming\YAkiUXoNRQEwFp
AppInit_DLLs: C:\ProgramData\ExtTag\Greentouch.dll => C:\ProgramData\ExtTag\Greentouch.dll [128000 2015-08-20] ()
AppInit_DLLs-x32: C:\ProgramData\ExtTag\Greentouch.dll => C:\ProgramData\ExtTag\Greentouch.dll [128000 2015-08-20] ()
C:\ProgramData\ExtTag
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1530302485-96551884-1675906368-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1530302485-96551884-1675906368-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
C:\Windows\SysWOW64\findit.xml
C:\ProgramData\ExtTags
C:\WebStorage
EmptyTemp:
*sidecubes.*.*
sidecubes.
C:\Users\Artur\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.sidecubes.com_0.localstorage
C:\Users\Artur\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.sidecubes.com_0.localstorage-journal
Task: {67701D7B-CDD7-4627-B41A-F82D55F94672} - System32\Tasks\snf => C:\ProgramData\ExtTag\Y--Ity.exe [2015-08-20] ()
C:\ProgramData\ExtTag
Task: {06ACE391-DABD-429D-8851-3B33D71269BA} - System32\Tasks\snp => C:\ProgramData\ExtTag\Y--Ity.exe [2015-08-20] ()
AppInit_DLLs: C:\ProgramData\ExtTag\Lot-Tip.dll => C:\ProgramData\ExtTag\Lot-Tip.dll [135680 2015-08-20] ()
AppInit_DLLs-x32: C:\ProgramData\ExtTag\Zontex.dll => C:\ProgramData\ExtTag\Zontex.dll [121344 2015-08-20] ()
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nF_fW_wDXODHo3LQ-BqHqnOIXtPzZv14bzqZsb6RFrOgNIy-Ibm9pP7z5FG-mvf_J2yWETQBCn6eg0vn
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
HKU\S-1-5-21-1530302485-96551884-1675906368-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1530302485-96551884-1675906368-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1530302485-96551884-1675906368-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3vZOxc6r0vkIwdRc1DOTbdhEGWqmDm5EVMb1RGlWshug7boYh6iEzt-Hcn8PTEXdyNni1o3WxIV-nFM-NaDJ0gP1OQn961OUUZ16YQhlqv8fuUl-ZaIZhgAr7oBE4EH4-45glPzh9Y3W6IMilH5CKLOPzSTV&q={searchTerms}
R2 ExtTag; C:\ProgramData\ExtTag\ExtTag.exe [22528 2015-08-20] () [File not signed]
R2 igfx32; C:\Program Files\igfx32\igfx32.exe [379392 2015-08-16] () [File not signed]
C:\Windows\SysWOW64\findit.xml
C:\ProgramData\ExtTags
C:\WebStorage
C:\Program Files\igfx32
EmptyTemp:
*sidecubes*.*
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości