UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 3.5.30729)
UA: Opera/9.80 (Windows NT 6.1; WOW64; U; pl) Presto/2.10.229 Version/11.62
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
mch73 napisał(a):Coś takiego mam poinstalowanego...
UA: Opera/9.80 (Windows NT 6.1; WOW64; U; pl) Presto/2.10.229 Version/11.62
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.19) Gecko/2010031422 Firefox/3.0.19
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 2.0.50727)
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=109805&babsrc=HP_ss&mntrId=2cc0e351000000000000001a4d818063
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: \"URL\" = http://search.babylon.com/?q={searchTerms}&AF=109805&babsrc=SP_ss&mntrId=2cc0e351000000000000001a4d818063
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: \"URL\" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060}: \"URL\" = http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
FF - prefs.js..browser.search.defaultenginename: \"Search the web (Babylon)\"
FF - prefs.js..browser.search.order.1: \"Search the web (Babylon)\"
FF - prefs.js..keyword.URL: \"http://search.babylon.com/?AF=109805&babsrc=adbartrp&mntrId=2cc0e351000000000000001a4d818063&q=\"
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
[2012-02-28 15:07:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\BERYL\Dane aplikacji\Mozilla\Firefox\Profiles\mvsnl040.default\extensions\[email protected]
O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found.
O3 - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {09900DE8-1DCA-443F-9243-26FF581438AF} - No CLSID value found.
O3 - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Files
RECYCLER /alldrives
C:\Documents and Settings\BERYL\Dane aplikacji\QuickStoresToolbar
C:\Documents and Settings\BERYL\Pulpit\gmer.zip.part
C:\Documents and Settings\BERYL\Pulpit\gmer.zip
C:\WINDOWS\tasks\*.job
C:\Program Files\Google\Update
C:\Documents and Settings\LocalService\Dane aplikacji\{DCD48218-E972-4d0c-9E5F-43462BC13E3B}
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"AdslTaskBar"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"Adobe ARM"=-
"UnlockerAssistant"=-
"SunJavaUpdateSched"=-
"APSDaemon"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.27) Gecko/20120216 Firefox/3.6.27 (.NET CLR 2.0.50727)
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=109805&babsrc=adbartrp&mntrId=2cc0e351000000000000001a4d818063&q="
:Files
RECYCLER /alldrives
C:\ComboFix
C:\Documents and Settings\BERYL\Pulpit\gmer
C:\WINDOWS\ERDNT
C:\Documents and Settings\BERYL\Pulpit\vcredist_x86.exe
C:\Documents and Settings\BERYL\Pulpit\dotNetFx35setup.exe
C:\Documents and Settings\BERYL\Pulpit\Defogger.exe
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]