http://wklej.org/id/1934624/
http://wklej.org/id/1934625/
2016-02-10 18:30 - 2016-02-10 18:30 - 00186760 _____ () C:\Users\brzenka\Documents\ScsiAccess.exe
ShortcutWithArgument: C:\Users\brzenka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mysites123.com/?type=sc&ts=1455128249&z=287c715e6011fe8b0c14fd6g8zewdw5g8o3b4o9z4t&from=amt&uid=hitachixhts547575a9e384_j1140021g7wknkg7wknkx
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mysites123.com/?type=sc&ts=1455128249&z=287c715e6011fe8b0c14fd6g8zewdw5g8o3b4o9z4t&from=amt&uid=hitachixhts547575a9e384_j1140021g7wknkg7wknkx
SearchScopes: HKU\S-1-5-21-1577275202-546194520-1271563289-1001 -> DefaultScope {255F6B65-DB46-4392-A798-6749D0F7F98F} URL =
SearchScopes: HKU\S-1-5-21-1577275202-546194520-1271563289-1001 -> {255F6B65-DB46-4392-A798-6749D0F7F98F} URL =
FF NewTab: hxxp://www.mysites123.com/newtab/?type=nt&ts=1455128249&z=287c715e6011fe8b0c14fd6g8zewdw5g8o3b4o9z4t&from=amt&uid=hitachixhts547575a9e384_j1140021g7wknkg7wknkx
FF DefaultSearchEngine: mysites123
FF Homepage: hxxp://www.mysites123.com/?type=hp&ts=1455128249&z=287c715e6011fe8b0c14fd6g8zewdw5g8o3b4o9z4t&from=amt&uid=hitachixhts547575a9e384_j1140021g7wknkg7wknkx
FF SearchPlugin: C:\Users\brzenka\AppData\Roaming\Mozilla\Firefox\Profiles\6vxw6v1o.default\searchplugins\mysites123.xml [2016-02-10]
FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\brzenka\AppData\Roaming\Mozilla\Firefox\Profiles\6vxw6v1o.default\extensions\deskCutv2@gmail.com => nie znaleziono
C:\Users\brzenka\AppData\Roaming\mysites123
File: C:\Users\brzenka\Documents\ScsiAccess.exe
EmptyTemp:
========================= File: C:\Users\brzenka\Documents\ScsiAccess.exe ========================
"C:\Users\brzenka\Documents\ScsiAccess.exe" => nie znaleziono.
Task: {B3D05C4B-43FD-489F-8E00-FB9DE48C799F} - System32\Tasks\{6D632551-72EC-46E8-A2B5-DB482A0D76D8} => pcalua.exe -a "C:\Program Files (x86)\Photodex\ProShow Producer\remove.exe"
FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [Brak pliku]
HOSTS:
EmptyTemp:
mysites
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 16 gości