UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:24.0) Gecko/20100101 Firefox/24.0
:OTL
[2013-10-18 11:47:38 | 000,000,000 | RHSD | M] -- C:\Users\-X-\AppData\Roaming\System32
O4 - Startup: C:\Users\-X-\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GlobeTrotter Connect.lnk = File not found
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=-
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382787168&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1382787168&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382787169&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382787168&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1382787168&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382787169&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7&q={searchTerms}
IE - HKU\S-1-5-21-903701354-447844701-965418101-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382787168&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7
IE - HKU\S-1-5-21-903701354-447844701-965418101-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1382787168&from=wpc&uid=ST9500325AS_6VEE7VH7XXXX6VEE7VH7
FF - prefs.js..browser.search.defaultenginename: "qone8"
[2013-11-01 17:36:35 | 000,000,000 | ---D | M] (Download keeeoper) -- C:\Users\-X-\AppData\Roaming\mozilla\Firefox\Profiles\kfdjexwv.default\extensions\[email protected]
O20 - AppInit_DLLs: (c:\progra~2\sshelp~1\psupport.dll) - c:\Program Files (x86)\ss helper\psupport.dll ()
[2013-10-26 12:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Download keeeoper
:Files
c:\Program Files (x86)\ss helper
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Java(TM) 6 Update 24
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
Zarejestrowani użytkownicy: Bing [Bot]