
Logi z OTL:
http://wklej.eu/index.php?id=fc8fa29454
http://wklej.eu/index.php?id=243773f217
PS: Jezeli uda mi sie zrobic logi z Hijackthis to takze je wkleje.
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
PS: Jezeli uda mi sie zrobic logi z Hijackthis to takze je wkleje.
:OTL
FF - prefs.js..browser.search.defaultenginename: \"AIM Search\"
FF - prefs.js..browser.search.defaulturl: \"http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=\"
FF - prefs.js..keyword.URL: \"http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=\"
[2009/09/12 19:21:24 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Marlena\Application Data\Mozilla\Firefox\Profiles\pz74kfnc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/06/12 16:30:33 | 000,004,207 | ---- | M] () -- C:\Documents and Settings\Marlena\Application Data\Mozilla\Firefox\Profiles\pz74kfnc.default\searchplugins\aim-search.xml
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKU\S-1-5-21-4242460850-1627793051-1047745362-1006..\Run: [jkmcoprm] C:\Documents and Settings\Marlena\Local Settings\Temp\awnhroghs\opkmcfolajb.exe ()
O33 - MountPoints2\{04b714e1-6a1c-11dd-9c12-001372d54b9a}\Shell - \"\" = Autorun
O33 - MountPoints2\{04b714e1-6a1c-11dd-9c12-001372d54b9a}\Shell\AutoRun - \"\" = Auto&Play
O33 - MountPoints2\{04b714e1-6a1c-11dd-9c12-001372d54b9a}\Shell\Open\command - \"\" = F:\chess.exe -- File not found
O33 - MountPoints2\{9b19870c-6a1e-11dd-9c14-001372d54b9a}\Shell - \"\" = Autorun
O33 - MountPoints2\{9b19870c-6a1e-11dd-9c14-001372d54b9a}\Shell\AutoRun - \"\" = Auto&Play
O33 - MountPoints2\{9b19870c-6a1e-11dd-9c14-001372d54b9a}\Shell\Open\command - \"\" = E:\chess.exe -- File not found
O33 - MountPoints2\{c00760f7-b4a9-11de-9f8d-001372d54b9a}\Shell\AutoRun\command - \"\" = E:\t.com -- File not found
O33 - MountPoints2\{c00760f7-b4a9-11de-9f8d-001372d54b9a}\Shell\explore\Command - \"\" = E:\t.com -- File not found
O33 - MountPoints2\{c00760f7-b4a9-11de-9f8d-001372d54b9a}\Shell\open\Command - \"\" = E:\t.com -- File not found
:Files
C:\Documents and Settings\Marlena\Local Settings\Temp\awnhroghs
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.16) Gecko/20101130 Firefox/3.5.16 ( .NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
:OTL
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query="
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query="
:Files
C:\WINDOWS\tasks\*.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"NeroCheck"=-
"TkBellExe"=-
"WinampAgent"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IPLA!"=-
"swg"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"=-
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"=-
"C:\Program Files\America Online 9.0\waol.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"=-
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"=-
"C:\Program Files\America Online 9.0\waol.exe"=-
"C:\Program Files\SopCast\adv\SopAdver.exe"=-
:Commands
[clearallrestorepoints]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.16) Gecko/20101130 Firefox/3.5.16 ( .NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
:OTL
O3 - HKU\S-1-5-21-4242460850-1627793051-1047745362-1006\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
:Files
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
Zarejestrowani użytkownicy: Bing [Bot]