Task: {7B22859E-9B3A-4148-B967-87138B84DB44} - System32\Tasks\B5FC2DBA-817C-4480-972E-4419B75E75 => C:\Users\Sara\AppData\Local\B5FC2DBA-817C-4480-972E-4419B75E75\B5FC2DBA-817C-4480-972E-4419B75E75.exe [2015-11-30] () <==== UWAGA
C:\Users\Sara\AppData\Local\B5FC2DBA-817C-4480-972E-4419B75E75
ShortcutWithArgument: C:\Users\Sara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
ShortcutWithArgument: C:\Users\Sara\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
ShortcutWithArgument: C:\Users\Sara\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
ShortcutWithArgument: C:\Users\Sara\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa <==== UWAGA
C:\Program Files (x86)\RayDld
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Brak pliku
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Brak pliku
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Brak pliku
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Brak pliku
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
SearchScopes: HKU\S-1-5-21-521238696-2074372863-601001458-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
SearchScopes: HKU\S-1-5-21-521238696-2074372863-601001458-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
CHR HomePage: Default -> hxxp://www.mystartsearch.com/?type=hp&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa
CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hp&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa"
CHR DefaultSearchURL: Default -> hxxp://www.mystartsearch.com/web/?type=ds&ts=1447455820&z=29c14bd8532fafe3077f336gaz8z3m3z5w7w8b5o8e&from=cornl&uid=st500lt012-1dg142_s3p2edwaxxxxs3p2edwa&q={searchTerms}
CHR DefaultSearchKeyword: Default -> mystartsearch
OPR Session Restore: -> [funkcja włączona]
R2 ihpmServer; C:\Program Files (x86)\RayDld\ihpmServer.exe [271464 2015-11-10] ()
R1 wafd_vw_1_10_0_20; C:\Windows\System32\drivers\wafd_vw_1_10_0_20.sys [57728 2015-07-06] (WA)
C:\Users\Sara\AppData\Roaming\mystartsearch
C:\Users\Sara\Downloads\Spotify-48247-dp.exe
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\ProgramData\lWdsManProl
EmptyTemp:
Użytkownicy przeglądający to forum: bokovi3991, negim28716 oraz 3 gości