UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
dzisiaj czytajac fora zainstalowalem Windows Worms Doors Cleaner,i po jego uruchomieniu,wszystko swiecilo na czerwono,udalo mi sie zmienic na zielono jedynie port DCOM,pozostale swieca na zolto.
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
:OTL
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
[2011/05/24 23:14:55 | 000,002,561 | ---- | M] () -- C:\Users\MAREK\AppData\Roaming\Mozilla\FireFox\Profiles\qienb6mc.default\searchplugins\askcom.xml
[2011/10/19 21:35:03 | 000,002,191 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No CLSID value found.
O4 - HKCU..\Run: [] File not found
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.6.0_20)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
[2012/02/15 11:31:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/15 08:05:48 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/14 23:06:24 | 000,000,808 | ---- | C] () -- C:\Users\MAREK\Desktop\ComboFix - Shortcut.lnk
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
:Commands
[emptytemp]
faktycznie mam Viste,i teraz mam cieplo,bo nie mam pojecia w jaki sposob to odkrecic,czy wystarczy odinstalowac aplikacje?czy jest jakis sposob na powrot to stanu sprzed moich kombinacji?
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
UA: Mozilla/5.0 (Windows NT 6.0; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
:OTL
IE - HKU\S-1-5-21-2567114353-2995694879-958528206-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
[2011/06/07 05:48:41 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\MAREK\AppData\Roaming\mozilla\Firefox\Profiles\qienb6mc.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/download/scanner/pl-pl/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6BB2089-163F-466B-812A-748096614DFD} http://cainternetsecurity.net/scanner/cascanner.cab (CAScanner Control)
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:0F8F5844
@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:CD060F93
:Files
C:\Windows\tasks\SA.DAT
C:\Users\MAREK\Desktop\gmer.zip
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonSolutionMenu"=-
"MobileBroadband"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
:OTL
O3 - HKU\S-1-5-21-2567114353-2995694879-958528206-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
@Alternate Data Stream - 98 bytesC:\ProgramData\TEMP:0F8F5844
@Alternate Data Stream - 150 bytesC:\ProgramData\TEMP:CD060F93
:Files
C:\Users\MAREK\AppData\Roaming\PCPro
C:\Users\MAREK\AppData\Roaming\PC Cleaners
C:\Windows\uninst.exe
C:\ProgramData\PC1Data
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
:OTL
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKU\S-1-5-21-2567114353-2995694879-958528206-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
:Files
C:\Users\MAREK\Documents\cc_20120215_194624.reg
C:\Windows\tasks\SA.DAT
:Commands
[clearallrestorepoints]
[emptytemp]
8.8.8.8
8.8.4.4
208.67.222.222
208.67.220.220
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
Zarejestrowani użytkownicy: Bing [Bot]