HijackThis
- Kod: Zaznacz wszystko
http://wklej.org/id/475493/
GMER
- Kod: Zaznacz wszystko
http://wklej.org/id/475501/
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
http://wklej.org/id/475493/
http://wklej.org/id/475501/
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( )
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
http://wklej.org/id/478341/
http://wklej.org/id/478342/
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
:OTL
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=panda&type=panda1_0yatb&p="
[2011-02-04 12:43:24 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\euro\AppData\Roaming\mozilla\Firefox\Profiles\071j6ddq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011-02-04 12:43:25 | 000,000,000 | ---D | M] -- C:\Users\euro\AppData\Roaming\mozilla\Firefox\Profiles\071j6ddq.default\extensions\[email protected]
[2010-03-28 10:04:34 | 000,002,476 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {8532a8b7-c06a-41bb-936a-8ce73e4711ed} - No CLSID value found.
O3 - HKU\S-1-5-21-3666655984-1327925536-1845967947-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [cfFncEnabler.exe] File not found
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKU\S-1-5-21-3666655984-1327925536-1845967947-1001..\Run: [BatteryCare] F:\Wintools\aaaa\BatteryCarePortable\App\BatteryCare\BatteryCare.exe File not found
O4 - HKU\S-1-5-21-3666655984-1327925536-1845967947-1001..\Run: [Wru] C:\Program Files\Wru\Wru.exe File not found
[2011-02-18 21:48:06 | 000,000,472 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for euro.job
:Files
C:\Users\euro\AppData\Local\Temp*.html
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"=-
"Toshiba TEMPRO"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]