22 Sie 2011, 11:11
22 Sie 2011, 11:58
:OTL
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14149"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://my.daemon-search.com/startpage|http://www.google.pl/"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=adbartrp&AF=14149&q="
[2011-07-23 19:52:03 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\RESYL\AppData\Roaming\mozilla\Firefox\Profiles\4kpik8fn.default\extensions\[email protected]
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - File not found
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-196931066-2618462160-3552708504-1006..\Run: [Iqegoluqo] C:\Users\RESYL\AppData\Local\dbtarary.dll (NETGEAR Corporation.)
O4 - HKLM..\RunOnce: [] File not found
O4 - HKU\S-1-5-21-196931066-2618462160-3552708504-1006..\RunOnce: [cJ13602DbNcA13602] C:\ProgramData\cJ13602DbNcA13602\cJ13602DbNcA13602.exe ()
MsConfig - StartUpReg: FlashPlayerUpdate - hkey= - key= - File not found
MsConfig - StartUpReg: IgfxTray - hkey= - key= - File not found
MsConfig - StartUpReg: Persistence - hkey= - key= - File not found
MsConfig - StartUpReg: QlbCtrl - hkey= - key= - File not found
[2011-08-21 20:54:39 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Users\RESYL\taskmgr.exe
[2011-08-21 20:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\cJ13602DbNcA13602
:Commands
[clearallrestorepoints]
[emptytemp]
22 Sie 2011, 19:21
22 Sie 2011, 20:06
:OTL
[2010-11-23 11:18:56 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\RESYL\AppData\Roaming\mozilla\Firefox\Profiles\4kpik8fn.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011-07-23 19:51:43 | 000,002,055 | ---- | M] () -- C:\Users\RESYL\AppData\Roaming\Mozilla\Firefox\Profiles\4kpik8fn.default\searchplugins\daemon-search.xml
[2011-02-01 14:05:47 | 000,001,196 | ---- | M] () -- C:\Users\RESYL\AppData\Roaming\Mozilla\Firefox\Profiles\4kpik8fn.default\searchplugins\winamp-search.xml
O4 - HKLM..\RunOnce: [] File not found
[2011-08-22 18:56:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-196931066-2618462160-3552708504-1006UA.job
[2011-08-22 18:34:00 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-08-22 16:15:23 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-08-22 10:56:01 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-196931066-2618462160-3552708504-1006Core.job
:Files
C:\ProgramData\cJ13602DbNcA13602
C:\Program Files\DAEMON Tools Toolbar
:Commands
[clearallrestorepoints]
[emptytemp]
22 Sie 2011, 22:13
22 Sie 2011, 22:21
:OTL
SRV - File not found [Auto | Stopped] -- -- (Harmonogram automatycznej usługi LiveUpdate)
Java(TM) 6 Update 13
Adobe Reader 9.4.5 - Polish
23 Sie 2011, 13:24
23 Sie 2011, 13:49
Zainfekowanych plików:
c:\Windows\kmservice.exe (RiskWare.Tool.CK)Quarantined and deleted successfully.
23 Sie 2011, 14:38