UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2 ( )
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.4) Gecko/20100611 Firefox/3.6.4
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2 ( )
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6
:OTL
IE - HKU\S-1-5-21-2926381558-1381126248-674188307-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15003&l=dis
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.3
[2009-09-28 13:06:15 | 000,000,687 | ---- | M] () -- C:\Users\ppp\AppData\Roaming\Mozilla\FireFox\Profiles\lglzj72s.default\searchplugins\ask.xml
[2010-05-29 22:53:44 | 000,002,425 | ---- | M] () -- C:\Users\ppp\AppData\Roaming\Mozilla\FireFox\Profiles\lglzj72s.default\searchplugins\askcom.xml
[2009-12-16 18:20:43 | 000,000,362 | ---- | M] () -- C:\Users\ppp\AppData\Roaming\Mozilla\FireFox\Profiles\lglzj72s.default\searchplugins\winamp-search.xml
O3 - HKU\S-1-5-21-2926381558-1381126248-674188307-1003\..\Toolbar\ShellBrowser: (no name) - {B5A34A93-D538-43A7-8371-864CB6148D12} - No CLSID value found.
O3 - HKU\S-1-5-21-2926381558-1381126248-674188307-1003\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-F7ED0776FB27} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O33 - MountPoints2\{3bd26cbe-00f1-11df-bd13-001dd9f973d4}\Shell\AutoRun\command - "" = F:\kmj.exe -- File not found
O33 - MountPoints2\{3bd26cbe-00f1-11df-bd13-001dd9f973d4}\Shell\open\Command - "" = F:\kmj.exe -- File not found
:Files
C:\found.00*
C:\Windows\tasks\Sprawdź aktualizacje paska narzędzi Windows Live Toolbar.job
C:\Users\ppp\AppData\Local\Temp*.html
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DiskeeperSystray"=-
"LanguageShortcut"=-
"NvSvc"=-
"RemoteControl"=-
"RtHDVCpl"=-
"SearchSettings"=-
"Skytel"=-
:Commands
[emptytemp]
[clearallrestorepoints]
Nie mogę wstawic loga z GMERa bo jak skanuj to mi kompa restartuje
DRV - [2008-09-25 02:05:41 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
Zarejestrowani użytkownicy: Google [Bot]