# AdwCleaner v5.025 - Utworzono raport 14/12/2015 o 15:31:28 # Ostatnia aktualizacja 13/12/2015 przez Xplode # Baza danych : 2015-12-13.2 [Serwer] # System operacyjny : Windows 7 Professional Service Pack 1 (x64) # Nazwa użytkownika : Krzysztof - KOMPUTER # Lokalizacja programu : C:\Users\Krzysztof\Downloads\adwcleaner_5.025.exe # Działanie : Skanuj # Wsparcie : http://toolslib.net/forum ***** [ Usługi ] ***** ***** [ Foldery ] ***** ***** [ Pliki ] ***** Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.kingtopdeals.com_0.localstorage Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.kingtopdeals.com_0.localstorage-journal Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.safesidesearch.com_0.localstorage Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.safesidesearch.com_0.localstorage-journal Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.piesearch.com_0.localstorage Plik znaleziono : C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.piesearch.com_0.localstorage-journal Plik znaleziono : C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\user.js Plik znaleziono : C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\searchplugins\yahoo.xml Plik znaleziono : C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\searchplugins\default.xml ***** [ DLL ] ***** ***** [ Skróty ] ***** Skrót Zainfekowany : C:\Users\Public\Desktop\Mozilla Firefox.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) Skrót Zainfekowany : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) Skrót Zainfekowany : C:\Users\Krzysztof\Desktop\Google Chrome.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) Skrót Zainfekowany : C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) Skrót Zainfekowany : C:\Users\Krzysztof\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) Skrót Zainfekowany : C:\Users\Krzysztof\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) Skrót Zainfekowany : C:\Users\Krzysztof\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ) ***** [ Zaplanowane zadania ] ***** ***** [ Rejestr ] ***** Wartość znaleziono : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [smartffsearch@gmail.com] Wartość znaleziono : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ffsmartsearchbar@gmail.com] Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\{85198F55-85AC-498A-BFE4-BBC33840F4AB} Klucz znaleziono : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8} Klucz znaleziono : HKCU\Software\PRODUCTSETUP Klucz znaleziono : HKLM\SOFTWARE\dt soft\daemon tools toolbar Klucz znaleziono : HKLM\SOFTWARE\RayDld Klucz znaleziono : HKLM\SOFTWARE\ihpmserver Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggUcFtdBVtJERgbdQxcTA1FGAMOeQlaUxRJRQdAdQgAUw1DF1QFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE6T1pU Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918 Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918&q={searchTerms} Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918 Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918&q={searchTerms} Dane wartości znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918&q={searchTerms} Dane wartości znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918 Dane wartości znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggUcFtdBVtJERgbdQxcTA1FGAMOeQlaUxRJRQdAdQgAUw1DF1QFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE6T1pU Dane wartości znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds&ts=1445107308&z=0f59c000119752e30b35b1ag1z4z6wag3e7m0c1eeb&from=cor&uid=395049983_266162_64ac4918&q={searchTerms} Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86} Dane wartości znaleziono : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [] - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.piesearch.com/?type=sc&ts=1445521256&pid=etc22&uid=c1037548-dd5d-4438-ac96-9ea7e684d301 ***** [ Przeglądarki internetowe ] ***** [C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\prefs.js] [Preference] znaleziono : user_pref("browser.newtab.url", "hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAITIlxcAwFBDA0WdV0VVQ1IFxgacFsKTAEVE1YWcQEKVQtHQBNBNARaB0tXUUEeGGlxR1dMclBCMlpQKlceVg=="); [C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\prefs.js] [Preference] znaleziono : user_pref("browser.search.selectedEngine", "piesearch"); [C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\prefs.js] [Preference] znaleziono : user_pref("keyword.URL", "hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ4IA1wVQw0TbQENVF1cFQEadhQBUVtDDA1HcloNUAFDFQcVIR9aFQQTR0cFME0FB18EURNNfWpdAEsSSX5NL04=&q={searchTerms}"); ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7777 bajty] ##########