UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=12f57830-16d4-11e1-acb6-001e4ccfc2f0
IE - HKLM\..\SearchScopes\{F75A2100-06E5-4397-89D3-62803BA4C3B9}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2481033
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\URLSearchHook: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No CLSID value found
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=12f57830-16d4-11e1-acb6-001e4ccfc2f0&q={searchTerms}
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\SearchScopes\{F75A2100-06E5-4397-89D3-62803BA4C3B9}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=12f57830-16d4-11e1-acb6-001e4ccfc2f0&q="
[2012-04-26 21:04:21 | 000,000,000 | ---D | M] (Ashampoo PO Community Toolbar) -- C:\Users\Dominik\AppData\Roaming\mozilla\Firefox\Profiles\9gyrzka4.default\extensions\{d43723ae-1ae1-4a25-a6a4-bf0929273cab}
[2011-07-11 20:04:02 | 000,000,633 | ---- | M] () -- C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\9gyrzka4.default\searchplugins\startsear.xml
[2011-10-03 11:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
O3 - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
[2012-05-14 17:29:01 | 000,001,038 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-05-14 17:23:03 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1575673227-4166462027-3530635042-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
[2011-11-24 21:40:13 | 000,000,000 | ---D | M] (VshareComplete - Speed up your search with your personal search suggestions tool) -- C:\Users\Dominik\AppData\Roaming\mozilla\Firefox\Profiles\9gyrzka4.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}
[2011-08-22 00:53:41 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Users\Dominik\AppData\Roaming\mozilla\Firefox\Profiles\9gyrzka4.default\extensions\[email protected]
[2011-06-20 15:47:30 | 000,189,088 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll
[2007-03-10 01:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
:Files
C:\Program Files\Google\Update
C:\Program Files\Yahoo!
C:\axdiifod.sys
C:\Users\Dominik\AppData\Local\Temp
C:\Windows\tasks\*.job
C:\Users\Dominik\Desktop\gmer.exe
C:\Users\Dominik\AppData\Roaming\EurekaLog
C:\Users\Dominik\AppData\Roaming\Temp
C:\Users\Dominik\AppData\Roaming\VshareComplete
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=-
"KiesTrayAgent"=-
"PSQLLauncher"=-
"WLSS"=-
"Wow Video&Audio"=-
[HKEY_USERS\S-1-5-21-1575673227-4166462027-3530635042-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"ChomikBox"=-
"KiesHelper"=-
"KiesPDLR"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
:Files
C:\Users\Dominik\Desktop\BlueScreenView.cfg
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.5.26955/27.1662; U; pl) Presto/2.8.119 Version/11.10
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
C:\Windows\KMService.exe (RiskWare.Tool.CK)Usuń po ponownym uruchomieniu.
F:\Install\KMS Activator for Microsoft Office 2010 Applications x86 x64 Multilingual-FIXISO~DiBYA\mini-KMS_Activator_v1.053.exe (PUP.Hacktool.Office)Dodanie do kwarantanny i usunięcie pliku zakończyły się powodzeniem.
UA: Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0
Zarejestrowani użytkownicy: Bing [Bot]