07 Cze 2010, 11:31
07 Cze 2010, 14:24
:OTL
PRC - [2010/05/24 23:42:02 | 000,180,736 | ---- | M] () -- C:\Windows\Fzoqyb.exe
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15183&l=dis
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..extensions.enabledItems: [email protected]:3.5.0.145
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.1.0014
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=PF&o=15180&locale=en_US&apn_uid=874B9BB1-E541-4385-8B99-3E26B1D9A1AA&apn_ptnrs=RX&apn_sauid=A9CF46B5-6E08-4D3C-AF34-99D4286F6CDC&apn_dtid=&q="
[2010/03/07 10:05:03 | 000,000,000 | ---D | M] -- C:\Users\euro\AppData\Roaming\mozilla\Firefox\Profiles\e2s8zn08.default\extensions\[email protected]
[2010/06/03 16:05:10 | 000,000,000 | ---D | M] -- C:\Users\euro\AppData\Roaming\mozilla\Firefox\Profiles\e2s8zn08.default\extensions\[email protected]
[2010/06/06 22:57:16 | 000,002,554 | ---- | M] () -- C:\Users\euro\AppData\Roaming\Mozilla\FireFox\Profiles\e2s8zn08.default\searchplugins\askcom.xml
[2010/03/07 10:04:57 | 000,002,059 | ---- | M] () -- C:\Users\euro\AppData\Roaming\Mozilla\FireFox\Profiles\e2s8zn08.default\searchplugins\daemon-search.xml
[2010/05/03 20:04:34 | 000,001,598 | ---- | M] () -- C:\Users\euro\AppData\Roaming\Mozilla\FireFox\Profiles\e2s8zn08.default\searchplugins\web-search.xml
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKCU..\Run: [Canaveral] C:\windows\System32\sshnas21.DLL File not found
O4 - HKCU..\Run: [M5T8QL3YW3] C:\Users\euro\AppData\Local\Temp\Fhl.exe File not found
:Files
C:\Windows\Fzoqyb.exe
C:\Program Files\Ask.com
C:\Program Files\DAEMON Tools Toolbar
C:\windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
C:\windows\Fzoqya.exe
C:\Users\euro\AppData\Local\Temp*.html
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBKeyScan"=-
"NeroFilterCheck"=-
"RtHDVCpl"=-
"StartCCC"=-
"WinampAgent"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
:Commands
[emptytemp]
07 Cze 2010, 21:21
07 Cze 2010, 21:47
08 Cze 2010, 13:22
08 Cze 2010, 13:39
08 Cze 2010, 14:09