19 Wrz 2012, 21:06
20 Wrz 2012, 13:00
:OTL
IE - HKU\S-1-5-21-1708537768-1677128483-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={05423E4D-8B3A-4763-B855-3F4CB03353F6}&mid=b892dfa4331a47d08343d144c1d1b876-06ce4fc639803a2e3563922518183d8e94088cb9&lang=pl&ds=xn011&pr=sa&d=2012-09-12 20:27:21&v=13.0.0.7&sap=hp
IE - HKU\S-1-5-21-1708537768-1677128483-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.ask.com/?l=dis&o=101702
IE - HKU\S-1-5-21-1708537768-1677128483-839522115-1003\..\SearchScopes\{0388404D-6072-4CEB-B521-8F090FEAEE57}: "URL" = http://klit.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120620&user_guid=788DB94CA645452F9E2F94FC827B007A&machine_id=82f301fe3c2aa5a96d6fbfe23ce54a74&browser=IE&os=win&os_version=5.1-x86-SP2&iesrc={referrer:source}
IE - HKU\S-1-5-21-1708537768-1677128483-839522115-1003\..\SearchScopes\{53C68391-62E3-4E46-B92E-48B37E1D4BBD}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=FXTV5&o=101699&src=crm&q={searchTerms}&locale=&apn_ptnrs=F4&apn_dtid=YYYYYYYYPL&apn_uid=b90abd22-a47f-4da7-ba6a-1fafae8932ec&apn_sauid=B912D4BD-50F8-40A8-BB7B-51D98A847045
IE - HKU\S-1-5-21-1708537768-1677128483-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={05423E4D-8B3A-4763-B855-3F4CB03353F6}&mid=b892dfa4331a47d08343d144c1d1b876-06ce4fc639803a2e3563922518183d8e94088cb9&lang=pl&ds=xn011&pr=sa&d=2012-09-12 20:27:21&v=13.0.0.7&sap=dsp&q={searchTerms}
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "https://isearch.avg.com/?cid={05423E4D-8B3A-4763-B855-3F4CB03353F6}&mid=b892dfa4331a47d08343d144c1d1b876-06ce4fc639803a2e3563922518183d8e94088cb9&lang=pl&ds=xn011&pr=sa&d=&v=&sap=hp"
FF - prefs.js..keyword.URL: "http://klit.startnow.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120620&user_guid=788DB94CA645452F9E2F94FC827B007A&machine_id=82f301fe3c2aa5a96d6fbfe23ce54a74&browser=FF&os=win&os_version=5.1-x86-SP2&q="
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search\FireFoxExt\13.0.0.7 [2012-09-12 20:27:34 | 000,000,000 | ---D | M]
[2012-06-20 15:51:31 | 000,000,000 | ---D | M] (StartNow Toolbar) -- C:\Documents and Settings\Mariusz\Dane aplikacji\Mozilla\Firefox\Profiles\oiv8im8l.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2012-06-12 16:42:07 | 000,000,000 | ---D | M] (Foxit PDF Creator Toolbar) -- C:\Documents and Settings\Mariusz\Dane aplikacji\Mozilla\Firefox\Profiles\oiv8im8l.default\extensions\[email protected]
[2012-06-20 15:51:28 | 000,001,390 | ---- | M] () -- C:\Documents and Settings\Mariusz\Dane aplikacji\Mozilla\Firefox\Profiles\oiv8im8l.default\searchplugins\yahoo-zugo.xml
[2012-09-12 20:27:09 | 000,003,743 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
:Files
C:\WINDOWS\tasks\At*.job
:Commands
[clearallrestorepoints]
[emptytemp]
20 Wrz 2012, 23:45
21 Wrz 2012, 13:33
07 Paź 2012, 20:25
08 Paź 2012, 08:39
zainstalowałęm teraz darmowego antiv Kingsoft i nie wiem,czy to dobra decyzja?
:OTL
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"SunJavaUpdateSched"=-
"HP Software Update"=-
"QuickTime Task"=-
"IndexSearch"=-
:Commands
[clearallrestorepoints]