27 Mar 2012, 13:43
27 Mar 2012, 21:22
27 Mar 2012, 23:08
30 Mar 2012, 08:58
30 Mar 2012, 10:57
30 Mar 2012, 16:27
mch73 napisał(a):Coś takiego mam poinstalowanego...
30 Mar 2012, 16:31
30 Mar 2012, 23:06
01 Kwi 2012, 11:54
01 Kwi 2012, 12:20
01 Kwi 2012, 20:25
01 Kwi 2012, 23:03
02 Kwi 2012, 19:15
:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=109805&babsrc=HP_ss&mntrId=2cc0e351000000000000001a4d818063
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: \"URL\" = http://search.babylon.com/?q={searchTerms}&AF=109805&babsrc=SP_ss&mntrId=2cc0e351000000000000001a4d818063
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: \"URL\" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060}: \"URL\" = http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
FF - prefs.js..browser.search.defaultenginename: \"Search the web (Babylon)\"
FF - prefs.js..browser.search.order.1: \"Search the web (Babylon)\"
FF - prefs.js..keyword.URL: \"http://search.babylon.com/?AF=109805&babsrc=adbartrp&mntrId=2cc0e351000000000000001a4d818063&q=\"
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
[2012-02-28 15:07:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\BERYL\Dane aplikacji\Mozilla\Firefox\Profiles\mvsnl040.default\extensions\[email protected]
O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found.
O3 - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {09900DE8-1DCA-443F-9243-26FF581438AF} - No CLSID value found.
O3 - HKU\S-1-5-21-1390067357-839522115-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Files
RECYCLER /alldrives
C:\Documents and Settings\BERYL\Dane aplikacji\QuickStoresToolbar
C:\Documents and Settings\BERYL\Pulpit\gmer.zip.part
C:\Documents and Settings\BERYL\Pulpit\gmer.zip
C:\WINDOWS\tasks\*.job
C:\Program Files\Google\Update
C:\Documents and Settings\LocalService\Dane aplikacji\{DCD48218-E972-4d0c-9E5F-43462BC13E3B}
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"AdslTaskBar"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"Adobe ARM"=-
"UnlockerAssistant"=-
"SunJavaUpdateSched"=-
"APSDaemon"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
:Commands
[clearallrestorepoints]
[emptytemp]
02 Kwi 2012, 20:12
04 Kwi 2012, 14:01
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=109805&babsrc=adbartrp&mntrId=2cc0e351000000000000001a4d818063&q="
:Files
RECYCLER /alldrives
C:\ComboFix
C:\Documents and Settings\BERYL\Pulpit\gmer
C:\WINDOWS\ERDNT
C:\Documents and Settings\BERYL\Pulpit\vcredist_x86.exe
C:\Documents and Settings\BERYL\Pulpit\dotNetFx35setup.exe
C:\Documents and Settings\BERYL\Pulpit\Defogger.exe
:Commands
[clearallrestorepoints]
[emptytemp]