
DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software
Task: {B3D5053F-FC9B-462D-9317-47CA5CD75651} - System32\Tasks\{919D85BA-17A2-4749-82EE-AF58FD7180CA} => pcalua.exe -a C:\Users\ASus\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=cor
Task: {C2948BB5-0E3B-4FD1-BC03-FC106AAFA4D1} - System32\Tasks\{FEF688DE-A2A3-4CC7-9736-AE39C6203E20} => pcalua.exe -a C:\Users\ASus\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cor
Task: {E537FCBD-80FD-4C98-A67F-69D6F6018F33} - System32\Tasks\{9A44926A-79B2-44D7-82C0-81A76AEC7406} => pcalua.exe -a E:\Autorun.exe -d E:\
ShortcutWithArgument: C:\Users\ASus\Desktop\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\Users\ASus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\Users\ASus\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\Users\ASus\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\Users\ASus\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\Users\ASus\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
C:\Program Files (x86)\SFK
C:\ProgramData\lWdMl
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629&q={searchTerms}
HKU\S-1-5-21-379229587-4176076998-1202267418-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
HKU\S-1-5-21-379229587-4176076998-1202267418-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
SearchScopes: HKU\S-1-5-21-379229587-4176076998-1202267418-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1444675996&z=3d56ca7bcf814d90eadf53fg1z0z7z7qbmbw0m3m6q&from=cor&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
FF NewTab: hxxp://www.yoursites123.com/newtab/?type=nt&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
FF DefaultSearchEngine: yoursites123
FF Homepage: hxxp://www.yoursites123.com/?type=hp&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
FF SearchPlugin: C:\Users\ASus\AppData\Roaming\Mozilla\Firefox\Profiles\8ts8b5fp.default\searchplugins\yoursites123.xml [2016-01-13]
FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\ASus\AppData\Roaming\Mozilla\Firefox\Profiles\8ts8b5fp.default\extensions\defsearchp@gmail.com => nie znaleziono
FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\ASus\AppData\Roaming\Mozilla\Firefox\Profiles\8ts8b5fp.default\extensions\deskCutv2@gmail.com => nie znaleziono
FF HKLM-x32\...\Firefox\Extensions: [sidebarff@gmail.com] - C:\Users\ASus\AppData\Roaming\Mozilla\Firefox\Profiles\8ts8b5fp.default\extensions\sidebarff@gmail.com => nie znaleziono
FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\ASus\AppData\Roaming\Mozilla\Firefox\Profiles\8ts8b5fp.default\extensions\default_newtabff@gmail.com => nie znaleziono
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1452693405&z=12b87137a9e7e0d62afbbfbgfz8wbo6q2t9c8z4edw&from=ient07021&uid=ST1000LM024XHN-M101MBB_S32XJ9EF457629
R2 IhPul; C:\Users\ASus\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [183488 2016-01-12] (TODO: <公司名>)
R2 WdMan; C:\ProgramData\lWdMl\WdMan.exe [326656 2016-01-07] (TU-Funs LIMITED) [Brak podpisu cyfrowego]
C:\Users\ASus\AppData\Roaming\TSv
C:\ProgramData\MailUpdate
C:\Users\ASus\AppData\Roaming\MailUpdate
C:\ProgramData\tWMiniProt
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości