16 Kwi 2014, 07:31
16 Kwi 2014, 09:50
ps. Tibia auto zostaje, wiem że ma jakiś syf ale na tyle nieszkodliwy że zaryzykuję pozostawienie tego
proszę o wyrozumiałość
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1392127644&from=cor&uid=TOSHIBAXMQ01ABD050_43LGSG68SXX43LGSG68S&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1392127644&from=cor&uid=TOSHIBAXMQ01ABD050_43LGSG68SXX43LGSG68S&q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1392127644&from=cor&uid=TOSHIBAXMQ01ABD050_43LGSG68SXX43LGSG68S&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1392127644&from=cor&uid=TOSHIBAXMQ01ABD050_43LGSG68SXX43LGSG68S&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1392127644&from=cor&uid=TOSHIBAXMQ01ABD050_43LGSG68SXX43LGSG68S&q={searchTerms}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1392127644&from=cor&uid=TOSHIBAXMQ01ABD050_43LGSG68SXX43LGSG68S&q={searchTerms}
O4 - HKU\S-1-5-21-2370329703-81669117-2710482987-1002..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-2370329703-81669117-2710482987-1002..\Run: [cev86.exe] C:\Users\Rafał\Desktop\cev86.exe (Symantec ® Corporation Winter)
[2014-04-15 10:27:49 | 000,000,000 | ---D | C] -- C:\ProgramData\rvlkl
[2014-03-18 22:59:29 | 000,015,227 | ---- | C] (Wookash) -- C:\Program Files (x86)\logonInit.dll
[2014-03-18 22:59:25 | 000,015,227 | ---- | C] (Wookash) -- C:\Program Files\logonInit.dll
[2014-04-16 07:12:53 | 000,000,372 | ---- | M] () -- C:\WINDOWS\tasks\DriverToolkit Autorun.job
[2014-04-16 07:12:53 | 000,000,316 | ---- | M] () -- C:\WINDOWS\tasks\dsmonitor.job
[2014-04-16 07:14:47 | 000,000,062 | ---- | M] () -- C:\Users\Rafał\AppData\Roaming\sp_data.sys
[2014-04-15 16:58:00 | 000,000,920 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-2370329703-81669117-2710482987-1002Core.job
[2014-04-15 10:27:51 | 000,000,611 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk
[2014-04-09 07:48:05 | 000,000,026 | ---- | M] () -- C:\Users\Rafał\AppData\Roaming\tbi60.dll
[2014-02-11 16:10:14 | 000,000,000 | ---D | M] -- C:\Users\Rafał\AppData\Roaming\sweet-page
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Creative Cloud"=-
"Adobe Reader Speed Launcher"=-
"AdobeCS6ServiceManager"=-
"RemoteControl10"=-
"SwitchBoard"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=-
"Spotify"=-
"Spotify Web Helper"=-
"uTorrent"=-
"GoogleDriveSync"=-
:Commands
[clearallrestorepoints]
[emptytemp]
16 Kwi 2014, 11:32
16 Kwi 2014, 12:05
:OTL
O4 - HKU\S-1-5-21-2370329703-81669117-2710482987-1002..\Run: [Akamai NetSession Interface] "C:\Users\Rafał\AppData\Local\Akamai\netsession_win.exe" File not found
16 Kwi 2014, 12:22
16 Kwi 2014, 13:17
16 Kwi 2014, 18:21
16 Kwi 2014, 20:12
16 Kwi 2014, 20:26
ComboFixa używamy tylko wtedy, gdy zostaniemy o to wyraźnie poproszeni na forum. Nie korzystamy z niego na własną rękę![]()
![]()
16 Kwi 2014, 23:27
Azazell napisał(a):A próbowałeś programu - ComboFix ?
17 Kwi 2014, 23:26
17 Kwi 2014, 23:29
17 Kwi 2014, 23:40
17 Kwi 2014, 23:45
:OTL
:Files
C:\Program Files\Tibia\Tibia.exe
C:\Program Data\QBRKDY
17 Kwi 2014, 23:49