
SpyHunter (HKLM-x32\...\{AF549236-6258-4AC6-A043-5B5B89C6EB61}) (Version: 4.17.6.4336 - Enigma Software Group USA, LLC)
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Interenet Optimizer" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{c632643}" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Performance Optimizer" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{892cc6a3}" /f
CHR Extension: (Strong Signal) - C:\Users\H3r\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccdbmmgcjoehfmgnfikopjehmfbbgnef [2015-03-19]
Task: {613D34F7-A4F4-437B-AD19-C49BDCACE11B} - System32\Tasks\YTAHelper => C:\Program Files (x86)\YTAHelper\YTAHelper.exe <==== ATTENTION
Task: {0571AEAC-E7A4-42CC-96A0-BB89D8DA661F} - System32\Tasks\{16787738-696F-4367-9ADB-480D8F68EA65} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe"
C:\Program Files (x86)\YouTube Accelerator
C:\Program Files (x86)\YTAHelper
Task: {97D1756E-EA3B-4484-A79B-170684A07176} - System32\Tasks\SpyHunter4Startup => C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe
C:\Program Files (x86)\Enigma Software Group
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
HKU\S-1-5-21-3024732471-1128164967-2066428131-1001\...\Run: [AdobeBridge] => [X]
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1416253010&from=cor&uid=ST3160811AS_6PT33MFAXXXX6PT33MFA&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1416253010&from=cor&uid=ST3160811AS_6PT33MFAXXXX6PT33MFA&q={searchTerms}
CHR StartupUrls: Default -> "hxxp://www.sweet-page.com/?type=hp&ts=1416253010&from=cor&uid=ST3160811AS_6PT33MFAXXXX6PT33MFA"
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe
S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys
R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys
C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys
C:\Windows\System32\Tasks\SpyHunter4Startup
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\ProgramData\.bf45c81f8dc8abfeecf09.dat
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 12 gości