UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
:OTL
MOD - [2009-03-21 15:21:24 | 000,028,160 | ---- | M] () -- C:\Documents and Settings\Tomasz\winlogon.exe
IE - HKU\S-1-5-21-343818398-2025429265-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://vshare.toolbarhome.com/?hp=df
IE - HKU\S-1-5-21-343818398-2025429265-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..extensions.enabledItems: [email protected]:4.1.3
FF - prefs.js..keyword.URL: "http://vshare.toolbarhome.com/search.aspx?srch=ku&q="
FF - prefs.js..network.proxy.type: 4
[2011-04-16 15:58:04 | 000,001,583 | ---- | M] () -- C:\Documents and Settings\Tomasz\Dane aplikacji\Mozilla\Firefox\Profiles\1do6jpo0.default\searchplugins\web-search.xml
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Tomasz\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll File not found
O4 - HKLM..\Run: [crrss] C:\WINDOWS\system32\crrss.exe ()
O4 - HKLM..\Run: [services] C:\WINDOWS\system\services.exe File not found
O4 - HKU\S-1-5-21-343818398-2025429265-839522115-1004..\Run: [Badoo Desktop] C:\Documents and Settings\All Users\Dane aplikacji\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe File not found
O4 - HKU\S-1-5-21-343818398-2025429265-839522115-1004..\Run: [winlogon] C:\Documents and Settings\Tomasz\winlogon.exe ()
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
[2012-02-22 10:54:47 | 000,000,983 | ---- | C] () -- C:\Documents and Settings\Tomasz\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
:Reg
[HKEY_USERS\S-1-5-21-343818398-2025429265-839522115-1004\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=-
"nwiz"=-
"SoundMAXPnP"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
:OTL
MOD - [2012-02-23 12:39:42 | 000,167,936 | ---- | M] () -- C:\Documents and Settings\Tomasz\Dane aplikacji\4C30B\C21A4.exe
MOD - [2012-02-22 15:55:05 | 000,283,136 | ---- | M] () -- C:\Program Files\LP\A424\12F.exe
MOD - [2012-02-22 15:54:24 | 000,184,320 | ---- | M] () -- C:\Program Files\0B089\lvvm.exe
IE - HKU\S-1-5-21-343818398-2025429265-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61980
O4 - HKLM..\Run: [12F.exe] C:\Program Files\LP\A424\12F.exe ()
O4 - HKU\S-1-5-21-343818398-2025429265-839522115-1004..\Run: [Akamai NetSession Interface] "C:\Documents and Settings\Tomasz\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe" File not found
[2012-02-22 15:00:04 | 000,000,000 | ---D | C] -- C:\Program Files\0B089
[2012-02-22 14:59:30 | 000,000,000 | ---D | C] -- C:\Program Files\LP
[2012-02-22 14:59:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tomasz\Dane aplikacji\4C30B
:Reg
[HKEY_USERS\S-1-5-21-343818398-2025429265-839522115-1004\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system\services.exe"=-
"C:\Documents and Settings\Tomasz\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe"=-
:Commands
[clearallrestorepoints]
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
Folder::
c:\program files\0B089
File::
c:\windows\Tasks\AppleSoftwareUpdate.job
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"QuickTime Task"=-
"HP Software Update"=-
"GrooveMonitor"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = pl.v9.com/ins/ins_1330101696_732556
IE - HKU\S-1-5-21-343818398-2025429265-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61980
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 61980
[2012-02-24 17:41:36 | 000,002,415 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
:Commands
[clearallrestorepoints]
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
Java(TM) 6 Update 26
Adobe Reader 9.5.0 - Polish
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]