31 Mar 2013, 18:57
31 Mar 2013, 22:03
:OTL
MOD - [2008-05-27 23:17:49 | 000,003,584 | ---- | M] () -- D:\SKUTECZNE I DARMOWE ANTYVIRY\SmitfraudFix\Policies.exe
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.protectedsearch.com?si=41570&home=true&tid=3026
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.protectedsearch.com?si=41570&home=true&tid=3026
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.protectedsearch.com?si=41570&home=true&tid=3026
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.protectedsearch.com?si=41570&bs=true&tid=3026&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.protectedsearch.com?si=41570&bs=true&tid=3026&q={searchTerms}
IE - HKLM\..\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm007^YY^pl&si=CJyro6GFsbUCFUdY3god2mIA5w&ptb=59CA2C6B-FD55-407E-9A84-5B7CE91FFAD7&ind=2013032411&n=77fc6fdb&psa=&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=ST3750528AS_9VPA12S8____9VPA12S8&ts=1352921824
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\URLSearchHook: {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - No CLSID value found
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\URLSearchHook: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No CLSID value found
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\SearchScopes\{23AE2381-CE82-415F-8B77-CD4FAAC641AA}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms}
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm007^YY^pl&si=CJyro6GFsbUCFUdY3god2mIA5w&ptb=59CA2C6B-FD55-407E-9A84-5B7CE91FFAD7&ind=2013032411&n=77fc6fdb&psa=&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\SearchScopes\{F68B5B91-BF4B-48E5-8C17-B40FE26F534A}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033&SSPV=IEOB14
FF - prefs.js..browser.search.defaultenginename: "My Web Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=198484"
FF - prefs.js..extensions.enabledAddons: toolbar%40alexa.com:1.7.1
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=2&CUI=UN35111760384346813&UM=&q="
FF - user.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=59CA2C6B-FD55-407E-9A84-5B7CE91FFAD7&n=77fc728f&ind=2013033103&p2=^HJ^xdm007^YY^pl&si=CJyro6GFsbUCFUdY3god2mIA5w&searchfor="
FF - user.js..extensions.toolbar.mindspark._4zMembers_.last.keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=59CA2C6B-FD55-407E-9A84-5B7CE91FFAD7&n=77fc728f&ind=2013033103&p2=^HJ^xdm007^YY^pl&si=CJyro6GFsbUCFUdY3god2mIA5w&searchfor="
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: File not found
[2012-12-18 20:12:46 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012-11-14 21:37:05 | 000,000,402 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml
[2012-11-19 21:48:59 | 000,003,265 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml
CHR - Extension: Protected Toolbar = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjlkjjohncghchjiniokhljcgmlajgpb\1.6_0\
CHR - Extension: Amazon Shopping Assistant by Spigot = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_0\
CHR - Extension: BrowserProtect = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\
O2 - BHO: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - No CLSID value found.
O2 - BHO: (no name) - {61096323-3324-48fb-925b-4206f342e162} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {61096323-3324-48fb-925b-4206f342e162} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-3209543867-2111507504-3020928955-1000\..\Toolbar\WebBrowser: (no name) - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
[2013-03-31 16:42:18 | 000,289,144 | ---- | C] (S!Ri) -- C:\Windows\SysWow64\VCCLSID.exe
[2013-03-31 16:42:18 | 000,288,417 | ---- | C] (S!Ri) -- C:\Windows\SysWow64\SrchSTS.exe
[2013-03-31 16:42:18 | 000,135,168 | ---- | C] (SteelWerX) -- C:\Windows\SysWow64\swreg.exe
[2013-03-31 16:42:18 | 000,087,552 | ---- | C] (S!Ri.URZ) -- C:\Windows\SysWow64\VACFix.exe
[2013-03-31 16:42:18 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\Windows\SysWow64\IEDFix.exe
[2013-03-31 16:42:18 | 000,082,944 | ---- | C] (S!Ri.URZ) -- C:\Windows\SysWow64\IEDFix.C.exe
[2013-03-31 16:42:18 | 000,082,432 | ---- | C] (S!Ri.URZ) -- C:\Windows\SysWow64\404Fix.exe
[2013-03-31 16:42:18 | 000,080,384 | ---- | C] (S!Ri.URZ) -- C:\Windows\SysWow64\o4Patch.exe
[2013-03-31 16:42:18 | 000,079,360 | ---- | C] (SteelWerX) -- C:\Windows\SysWow64\swxcacls.exe
[2013-03-31 16:42:18 | 000,078,336 | ---- | C] (S!Ri.URZ) -- C:\Windows\SysWow64\Agent.OMZ.Fix.exe
[2013-03-31 16:42:18 | 000,053,248 | ---- | C] (http://www.beyondlogic.org) -- C:\Windows\SysWow64\Process.exe
[2013-03-24 13:42:17 | 000,000,000 | ---D | C] -- C:\SDFix
[2013-03-31 16:58:08 | 000,000,322 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2013-03-06 01:01:20 | 000,000,276 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
:Files
C:\Program Files (x86)\Application Updater
:Commands
[clearallrestorepoints]
[emptytemp]
01 Kwi 2013, 12:39
01 Kwi 2013, 17:28
:OTL
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=2&CUI=UN35111760384346813&UM=&q="
[2012-11-20 16:29:16 | 000,086,166 | ---- | M] () (No name found) -- C:\Users\NIGHT\AppData\Roaming\mozilla\firefox\profiles\ljpqqras.default\extensions\[email protected]
CHR - Extension: DealPly = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.0.7.2_0\
CHR - Extension: Ebay Shopping Assistant by Spigot = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.0_0\
01 Kwi 2013, 21:56
mati8898 napisał(a):Wklej w OTL::OTL
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=2&CUI=UN35111760384346813&UM=&q="
[2012-11-20 16:29:16 | 000,086,166 | ---- | M] () (No name found) -- C:\Users\NIGHT\AppData\Roaming\mozilla\firefox\profiles\ljpqqras.default\extensions\[email protected]
CHR - Extension: DealPly = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.0.7.2_0\
CHR - Extension: Ebay Shopping Assistant by Spigot = C:\Users\NIGHT\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.0_0\
Klikasz Wykonaj skrypt i podajesz log z usuwania.
01 Kwi 2013, 22:21
02 Kwi 2013, 00:30
mati8898 napisał(a):Tu infekcji żadnej nie ma.
W OTL Sprzątanie
Przeczyść dysk oraz rejestr CCleaner
Sprawdź, czy problem występuje w trybie awaryjnym z obsługą sieci.
02 Kwi 2013, 10:34
02 Kwi 2013, 12:28
mati8898 napisał(a):Ale gdzie i jakie infekcje wykrył Dr.Web??
02 Kwi 2013, 13:47