UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search the web"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web"
FF - prefs.js..browser.search.selectedEngine: "Search the web"
FF - prefs.js..extensions.enabledItems: [email protected]:1.03
FF - prefs.js..keyword.URL: "http://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - user.js..browser.search.selectedEngine: "Search the web"
FF - user.js..browser.search.order.1: "Search the web"
FF - user.js..browser.search.defaultenginename: "Search the web"
FF - user.js..keyword.URL: "http://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
[2011-11-04 16:40:52 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\BERYL\Dane aplikacji\Mozilla\Firefox\Profiles\2o3co0xt.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011-10-15 16:39:56 | 000,002,368 | ---- | M] () -- C:\Documents and Settings\BERYL\Dane aplikacji\Mozilla\Firefox\Profiles\2o3co0xt.default\searchplugins\askcom.xml
[2011-11-03 17:54:14 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\BERYL\Dane aplikacji\Mozilla\Firefox\Profiles\2o3co0xt.default\searchplugins\conduit.xml
[2011-10-15 10:22:32 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\BERYL\Dane aplikacji\Mozilla\Firefox\Profiles\2o3co0xt.default\searchplugins\daemon-search.xml
[2011-11-07 15:01:01 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011-11-07 14:27:34 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2011-10-15 16:30:14 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
:Files
C:\Documents and Settings\BERYL\Pulpit\gmer
C:\Documents and Settings\BERYL\Pulpit\ComboFix.exe
C:\found.*
C:\Program Files\StartNow Toolbar(2)
C:\WINDOWS\ERDNT
C:\Qoobox
C:\Program Files\Ask.com
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\PEV.exe
C:\WINDOWS\sed.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\zip.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\CurrentVersion\Run]
"AdslTaskBar"=-
"APSDaemon"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
O3 - HKU\S-1-5-21-790525478-616249376-1801674531-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdslTaskBar"=-
"APSDaemon"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
O4 - HKU\S-1-5-21-790525478-616249376-1801674531-1003..\Run: [uTorrent] "D:\uTORRENT\uTorrent.exe" /MINIMIZED File not found
:Files
C:\RECYCLER(2)
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.1.25378/26.1069; U; pl) Presto/2.8.119 Version/10.54
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23
Zarejestrowani użytkownicy: Bing [Bot]