UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{670A2206-F20A-490C-8C13-25EA88BF8E53}_is1" = e-pity 2010
"{670A2206-F20A-490C-8C13-25EA88BF8E54}_is1" = e-pity 2011
"{549197A2-8484-426C-814F-81A6535A24D6}" = Foxit Reader
"ABBYY FineReader 4.0 Sprint" = ABBYY FineReader 4.0 Sprint
Logi.
:OTL
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\JZEF~1\USTAWI~1\Temp\pxtdipow.sys -- (pxtdipow)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
IE - HKLM\..\SearchScopes,DefaultScope = {AD2B9F91-1679-4323-AEF4-606F30382A70}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{AD2B9F91-1679-4323-AEF4-606F30382A70}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-1214440339-1078081533-682003330-1003\..\SearchScopes,DefaultScope = {AD2B9F91-1679-4323-AEF4-606F30382A70}
IE - HKU\S-1-5-21-1214440339-1078081533-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1214440339-1078081533-682003330-1003\..\SearchScopes\{AD2B9F91-1679-4323-AEF4-606F30382A70}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_plPL451
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
:Files
C:\DOCUME~1\JZEF~1\USTAWI~1\Temp
C:\Program Files\Google\Update
C:\WINDOWS\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Autoruns.
Adobe ARM
Alcmtr
NvCplDaemon
NvMediaCenter
nwiz
RTHDCPL
SkyTel
SunJavaUpdateSched
Aktywacja Testera.lnk
Ulead Photo Express 4.0 SE Calendar Checker .lnk
Książka adresowa 6
Microsoft Outlook Express 6
MSMSGS
0
Wszystko.
Windows Messenger
gupdate
gupdatem
JavaQuickStarterService
NVSvc
ose
WMPNetworkSvc
Changer
i2omgmt
lbrtfdc
PCIDump
PDCOMP
PDFRAME
PDRELI
PDRFRAME
WDICA
HPLJ1018LM
Logi.
:OTL
O3 - HKU\S-1-5-21-1214440339-1078081533-682003330-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
:Services
gupdate
gupdatem
:Files
C:\Documents and Settings\Józef\Pulpit\avast_free_antivirus_setup.exe
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Logi.
:OTL
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
"{549197A2-8484-426C-814F-81A6535A24D6}" = Foxit Reader
"ABBYY FineReader 4.0 Sprint" = ABBYY FineReader 4.0 Sprint
Kroki Finalizujące.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
TrevorGryffits napisał(a):Usunąłem co trzeba, przeskanowałem CCleanerem, Anti-Malware nic nie znalazł.
Log z wykonania skryptu
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Zarejestrowani użytkownicy: Bing [Bot]