31 Maj 2011, 13:33
31 Maj 2011, 15:20
31 Maj 2011, 16:03
31 Maj 2011, 16:43
File not found -- C:\Users\InGusIA\Desktop\hgfhm
http://www.instalki.pl/programy/downloa ... Files.html
w oknie Własne opcje skanowania/skrypt wklej::OTL
PRC - [2006-11-21 01:26:34 | 000,042,675 | ---- | M] () -- C:\Users\InGusIA\AppData\Local\winlogon.exe
PRC - [2006-11-21 01:26:34 | 000,042,675 | ---- | M] () -- C:\Users\InGusIA\AppData\Local\services.exe
PRC - [2006-11-21 01:26:34 | 000,042,675 | ---- | M] () -- C:\Users\InGusIA\AppData\Local\lsass.exe
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
IE - HKU\S-1-5-21-2255306595-560806786-3909007887-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=ddrnw
FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Free Lunch Design Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://start.facemoods.com/?a=ddrnw"
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.1
FF - prefs.js..keyword.URL: "http://utils.babylon.com/abt/index.php?url="
[2010-05-14 13:32:36 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Users\InGusIA\AppData\Roaming\mozilla\Firefox\Profiles\af5a0r9f.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2011-01-13 16:00:54 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\InGusIA\AppData\Roaming\mozilla\Firefox\Profiles\af5a0r9f.default\extensions\[email protected]
[2011-05-04 14:33:18 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\InGusIA\AppData\Roaming\mozilla\Firefox\Profiles\af5a0r9f.default\extensions\[email protected]
[2010-01-20 12:14:04 | 000,000,937 | ---- | M] () -- C:\Users\InGusIA\AppData\Roaming\Mozilla\Firefox\Profiles\af5a0r9f.default\searchplugins\conduit.xml
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O4 - HKU\S-1-5-21-2255306595-560806786-3909007887-1005..\Run: [Tok-Cirrhatus] C:\Users\InGusIA\AppData\Local\smss.exe ()
O4 - Startup: C:\Users\InGusIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif ()
[2011-05-31 13:26:50 | 000,000,000 | ---D | C] -- C:\Users\InGusIA\AppData\Local\Bron.tok-12-31
[2011-05-09 14:32:49 | 000,000,000 | ---D | C] -- C:\Users\InGusIA\AppData\Local\Loc.Mail.Bron.Tok
[2011-05-09 14:32:12 | 000,000,000 | ---D | C] -- C:\Users\InGusIA\AppData\Local\Ok-SendMail-Bron-tok
[2011-05-31 15:59:00 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{09868DCE-FBE8-4B25-988A-068FAF251252}.job
[2011-05-31 15:55:00 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\Sprawdź aktualizacje paska narzędzi Windows Live Toolbar.job
[2011-05-31 15:30:00 | 000,001,038 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-03-08 17:49:13 | 000,042,675 | ---- | C] () -- C:\Users\InGusIA\AppData\Local\winlogon.exe
[2011-03-08 17:49:13 | 000,042,675 | ---- | C] () -- C:\Users\InGusIA\AppData\Local\smss.exe
[2011-03-08 17:49:13 | 000,042,675 | ---- | C] () -- C:\Users\InGusIA\AppData\Local\services.exe
[2011-03-08 17:49:13 | 000,042,675 | ---- | C] () -- C:\Users\InGusIA\AppData\Local\lsass.exe
[2011-03-08 17:49:13 | 000,042,675 | ---- | C] () -- C:\Users\InGusIA\AppData\Local\inetinfo.exe
[2011-03-08 17:49:13 | 000,042,675 | ---- | C] () -- C:\Users\InGusIA\AppData\Local\csrss.exe
:Files
C:\Users\InGusIA\AppData\Local\Temp*.html
:Commands
[clearallrestorepoints]
[emptytemp]
31 Maj 2011, 17:05
31 Maj 2011, 17:58
31 Maj 2011, 18:13
31 Maj 2011, 18:25
31 Maj 2011, 18:35
31 Maj 2011, 18:41
Files to delete:
C:\Windows\tasks\User_Feed_Synchronization-{09868DCE-FBE8-4B25-988A-068FAF251252}.job
C:\Windows\tasks\Sprawdź aktualizacje paska narzędzi Windows Live Toolbar.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Users\InGusIA\AppData\Local\winlogon.exe
C:\Users\InGusIA\AppData\Local\smss.exe
C:\Users\InGusIA\AppData\Local\services.exe
C:\Users\InGusIA\AppData\Local\lsass.exe
C:\Users\InGusIA\AppData\Local\inetinfo.exe
C:\Users\InGusIA\AppData\Local\csrss.exe
C:\Users\InGusIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
C:\Users\InGusIA\AppData\Local\smss.exe
C:\Users\InGusIA\AppData\Roaming\Mozilla\Firefox\Profiles\af5a0r9f.default\searchplugins\conduit.xml
Folders to delete:
C:\Users\InGusIA\AppData\Local\Bron.tok-12-31
C:\Users\InGusIA\AppData\Local\Loc.Mail.Bron.Tok
C:\Users\InGusIA\AppData\Local\Ok-SendMail-Bron-tok
C:\Users\InGusIA\AppData\Roaming\mozilla\Firefox\Profiles\af5a0r9f.default\extensions\[email protected]
C:\Users\InGusIA\AppData\Roaming\mozilla\Firefox\Profiles\af5a0r9f.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
C:\Users\InGusIA\AppData\Roaming\mozilla\Firefox\Profiles\af5a0r9f.default\extensions\[email protected]
Potwierdzasz i zgadzasz się na restart klikając OK.31 Maj 2011, 19:02
31 Maj 2011, 19:12
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=ddrnw
FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Free Lunch Design Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://start.facemoods.com/?a=ddrnw"
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.1
FF - prefs.js..keyword.URL: "http://utils.babylon.com/abt/index.php?url="
[2011-01-13 16:00:53 | 000,002,226 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010-04-01 19:33:11 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2011-05-04 14:33:19 | 000,002,048 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O4 - HKCU..\Run: [Tok-Cirrhatus] File not found
:Files
C:\Users\InGusIA\AppData\Local\Temp*.html
:Commands
[clearallrestorepoints]
31 Maj 2011, 19:28
31 Maj 2011, 19:40
http://www.instalki.pl/programy/downloa ... ack_2.htmlAdobe Reader 9.4.4 - Polish
http://www.instalki.pl/programy/downloa ... eader.html