UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Reasumacja.
Optymalizacja.
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
jak to możliwe że wirus mógłby przetrwać format?
12:09:46.0593 3764 sptd ( LockedFile.Multi.Generic ) - User select action: Delete
Autoruns.
Adobe ARM
ApnUpdater
HDAudDeck
NvCplDaemon
NvMediaCenter
nwiz
SunJavaUpdateSched
Książka adresowa 6
Microsoft Outlook Express 6
ALLUpdate
0
Adobe PDF Link Helper
Ask Toolbar
Java(tm) Plug-In 2 SSV Helper
Java(tm) Plug-In SSV Helper
StartNow Toolbar Helper
UrlSearchHook Class
Ask Toolbar
StartNow Toolbar
Windows Messenger
Wszystko.
nvsvc
Updater Service for StartNow Toolbar
Changer
i2omgmt
lbrtfdc
PCIDump
PDCOMP
PDFRAME
PDRELI
PDRFRAME
WDICA
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"StartNow Toolbar" = StartNow Toolbar
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
Logi.
:OTL
IE - HKU\S-1-5-21-1935655697-963894560-725345543-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=&locale=&apn_uid=A8E619F0-4BFB-453F-B2A3-0FD46A60B69D&apn_ptnrs=9M&apn_sauid=68A8E141-5C84-4170-AE77-384252F68442&apn_dtid=OSJ000&&q="
[2012-07-07 16:05:58 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\g4bvxoma.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012-07-08 20:42:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\g4bvxoma.default\extensions\[email protected]
[2012-07-08 20:42:44 | 000,002,299 | ---- | M] () -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\g4bvxoma.default\searchplugins\askcom.xml
O4 - HKLM..\Run: [] File not found
:Files
C:\Program Files\Ask.com
C:\Documents and Settings\Przemek\Ustawienia lokalne\Dane aplikacji\AskToolbar
C:\Documents and Settings\All Users\Dane aplikacji\Ask
RECYCLER /alldrives
C:\Program Files\StartNow Toolbar
C:\WINDOWS\Temp
C:\WINDOWS\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11 Comodo_Dragon/20.0.1.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.47 Safari/536.11 Comodo_Dragon/20.0.1.0
Zarejestrowani użytkownicy: Bing [Bot]