UA: Mozilla/5.0 (Windows NT 6.0; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 6.0; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=81&bd=Pavilion&pf=laptop
IE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2462558366-2056182412-3808007147-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
FF - prefs.js..keyword.URL: "http://startsear.ch/?q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2011-07-19 20:54:21 | 000,001,565 | ---- | M] () -- C:\Users\Darek\AppData\Roaming\Mozilla\Firefox\Profiles\zi5rannc.default\searchplugins\web-search.xml
[2010-01-02 22:29:41 | 000,024,683 | ---- | M] (Ask.com) -- C:\Program Files\mozilla firefox\plugins\NPAskSBr.dll
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
[2011-10-30 22:08:05 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{22009BFE-A3BA-4D31-9E7F-2A2811B9A946}.job
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:63238B95
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:C895616B
:Files
C:\ProgramData\AVAST Software
C:\Program Files\AVAST Software
C:\Windows\PEV.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\zip.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ContentTransferWMDetector"=-
"NvCplDaemon"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:Files
C:\ComboFix
C:\Qoobox
C:\Windows\tasks\User_Feed_Synchronization-{22009BFE-A3BA-4D31-9E7F-2A2811B9A946}.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ContentTransferWMDetector.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
dariopi napisał(a):log z otl http://www.wklej.eu/index.php?id=0ad83b5edd
UA: Mozilla/5.0 (Windows NT 6.0; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.1.25378/26.1069; U; pl) Presto/2.8.119 Version/10.54
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
dariopi napisał(a):a jaki antivirus proponujesz?
Zarejestrowani użytkownicy: Bing [Bot]