OTL
http://wklej.eu/index.php?id=01d60ffa14
Extras
http://wklej.eu/index.php?id=f3a69bb361
HiJacks
http://wklej.eu/index.php?id=32802811b0
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2
http://wklej.eu/index.php?id=01d60ffa14
http://wklej.eu/index.php?id=f3a69bb361
http://wklej.eu/index.php?id=32802811b0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
SRV - File not found [Auto | Stopped] -- -- (mwnzr)
IE - HKU\S-1-5-21-1645522239-839522115-64698920-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&affID=101538&mntrId=70b4fc1000000000000000138ff0de88
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic.com.PL FF Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2860351&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?babsrc=HP_ss&affID=101538&mntrId=70b4fc1000000000000000138ff0de88"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=adbartrp&affID=101538&mntrId=70b4fc1000000000000000138ff0de88&q="
[2011-05-29 08:41:17 | 000,000,000 | ---D | M] (Softonic.com.PL FF Community Toolbar) -- C:\Documents and Settings\MARCINEK\Dane aplikacji\Mozilla\Firefox\Profiles\rz2dg6m2.default\extensions\{a31ac2d0-a903-45d6-82be-3c0206868997}
[2011-02-14 22:28:40 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\MARCINEK\Dane aplikacji\Mozilla\Firefox\Profiles\rz2dg6m2.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011-02-14 22:28:40 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\MARCINEK\Dane aplikacji\Mozilla\Firefox\Profiles\rz2dg6m2.default\extensions\[email protected]
[2011-09-11 08:38:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\MARCINEK\Dane aplikacji\Mozilla\Firefox\Profiles\rz2dg6m2.default\extensions\[email protected]
[2011-02-12 11:29:59 | 000,002,566 | ---- | M] () -- C:\Documents and Settings\MARCINEK\Dane aplikacji\Mozilla\Firefox\Profiles\rz2dg6m2.default\searchplugins\askcom.xml
[2010-12-04 09:45:28 | 000,000,939 | ---- | M] () -- C:\Documents and Settings\MARCINEK\Dane aplikacji\Mozilla\Firefox\Profiles\rz2dg6m2.default\searchplugins\conduit.xml
[2011-02-12 07:42:09 | 003,056,008 | ---- | C] (Ask) -- C:\Program Files\Common Files\AskToolbarInstaller.exe
[2011-11-27 20:13:34 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-839522115-64698920-1004UA.job
[2011-11-27 20:07:02 | 000,001,040 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-11-27 15:43:21 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-11-20 14:13:04 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-839522115-64698920-1004Core.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"SunJavaUpdateSched"=-
"MSConfig"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
mati8898 napisał(a):Skoro Gmer nie hula to podaj raport z TDSSKillerotl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p120292
A folder zostaw, zostanie usunięty na koniec.
:OTL
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\MARCINEK\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\MARCINEK\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
:Files
C:\Documents and Settings\MARCINEK\Ustawienia lokalne\Dane aplikacji\Google\Update
C:\Program Files\Trend Micro
C:\WINDOWS\tasks\Game_Booster_AutoUpdate.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=-
"NvMediaCenter"=-
"Tweak UI"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
O3 - HKU\S-1-5-21-1645522239-839522115-64698920-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
Zarejestrowani użytkownicy: Bing [Bot]