UA: Mozilla/5.0 (Windows NT 4.10; rv:23.0) Gecko/20100101 Firefox/23.0
UA: Mozilla/5.0 (Windows NT 4.10; rv:23.0) Gecko/20100101 Firefox/23.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0
UA: Mozilla/5.0 (Windows NT 4.10; rv:23.0) Gecko/20100101 Firefox/23.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0
Windows NT 4.10
:OTL
DRV - File not found [Kernel | System | Running] -- C:\Program Files\iSafe\iSafeNetFilter.sys -- (iSafeNetFilter)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\Admin\USTAWI~1\Temp\fwacyfog.sys -- (fwacyfog)
DRV - File not found [Kernel | On_Demand | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.26010003&st=12&barid={4376BCC3-A72D-41C9-B93D-C3E27D7D6283}
IE - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\InprocServer32 File not found
IE - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\InprocServer32 File not found
IE - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.26010003&st=12&q={searchTerms}&barid={4376BCC3-A72D-41C9-B93D-C3E27D7D6283}
[2013-10-21 12:28:29 | 000,002,115 | ---- | M] () -- C:\Documents and Settings\Admin\Dane aplikacji\Mozilla\Firefox\Profiles\7phoiz0r.default\searchplugins\MyStart Search.xml
[2012-09-15 09:47:15 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Admin\Dane aplikacji\Mozilla\Firefox\Profiles\7phoiz0r.default\searchplugins\sweetim.xml
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
[2014-01-15 14:50:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Dane aplikacji\eCyber
[2014-01-15 14:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\iSafe
[2014-01-15 14:50:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Dane aplikacji\iSafe
[2014-01-15 18:14:00 | 000,000,452 | ---- | M] () -- C:\WINDOWS\tasks\DTReg.job
[2014-01-15 16:15:13 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
[2014-01-15 16:15:12 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
[2014-01-15 14:52:40 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2013-12-29 11:12:40 | 001,488,176 | ---- | M] () -- C:\WINDOWS\System32\dmwu.exe
[2013-12-22 03:24:50 | 000,000,440 | ---- | M] () -- C:\WINDOWS\tasks\SlimDrivers Scan.job
[2013-06-28 10:32:50 | 000,003,730 | ---- | C] () -- C:\Program Files\Mozilla Firefoxavg-secure-search.xml
[2013-08-20 13:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Babylon
[2013-02-07 15:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\DealPly
[2014-01-15 14:54:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\eCyber
[2014-01-15 16:16:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\iSafe
[2012-09-15 12:11:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ask
[2013-08-20 13:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2013-11-29 23:02:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive
[2014-01-15 17:17:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Doctor Web
[2012-10-01 20:19:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SweetIM
:Files
C:\WINDOWS\system32\jmdp
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe"=-
"C:\WINDOWS\system32\dmwu.exe"=-
"C:\Documents and Settings\Admin\Ustawienia lokalne\Temp\incredibar_install.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 4.10; rv:23.0) Gecko/20100101 Firefox/23.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0
:OTL
IE - HKU\S-1-5-21-484763869-1844823847-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredibar.com/?a=6R8SBR8vmU&loc=skw
IE - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/?a=6R8SBR8vmU&loc=skw&search={searchTerms}
[2013-05-23 15:10:09 | 000,003,716 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\Program Files\IB Updater\Firefox
O2 - BHO: (no name) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - No CLSID value found.
O2 - BHO: (no name) - {336D0C35-8A85-403a-B9D2-65C292C39087} - No CLSID value found.
O2 - BHO: (no name) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - No CLSID value found.
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKU\S-1-5-21-484763869-1844823847-682003330-1003\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
[2014-01-15 17:17:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Doctor Web
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]