UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11 Comodo_Dragon/20.1.1.0
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\Drivers\iqvw32.sys -- (NAL)
IE - HKLM\..\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=UXxdm007YYpl&ptnrS=UXxdm007YYpl&si=CJml3fX-8bACFcNN3wodGVdjxQ&ptb=0ED1A702-BA5D-4B09-B323-9FD84865B4CC&ind=2012062818&n=77eda462&psa=&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?n=77DE8857&ptnrS=UXxdm007YYpl&ptb=0ED1A702-BA5D-4B09-B323-9FD84865B4CC&si=CJml3fX-8bACFcNN3wodGVdjxQ
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\..\URLSearchHook: {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No CLSID value found
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\..\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=UXxdm007YYpl&ptnrS=UXxdm007YYpl&si=CJml3fX-8bACFcNN3wodGVdjxQ&ptb=0ED1A702-BA5D-4B09-B323-9FD84865B4CC&ind=2012062818&n=77eda462&psa=&st=sb&searchfor={searchTerms}
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/english/?search={searchTerms}&loc=search_box
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O32 - AutoRun File - [2012-05-18 15:53:08 | 000,000,100 | -HS- | M] () - C:\autorun.inf.old -- [ NTFS ]
:Files
C:\Documents and Settings\User\Menu Start\Programy\Autostart\OpenOffice.org 2.3.lnk
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
Combofix.
Logi.
:OTL
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\User\USTAWI~1\Temp\uftdypob.sys -- (uftdypob)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
IE - HKLM\..\SearchScopes,DefaultScope = {b0441a0e-a49a-4e16-afc1-74ecced1921f}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
:Files
C:\Program Files\39Uninstall MapsGalaxy.dll
C:\Documents and Settings\User\Pulpit\gmer
RECYCLER /alldrives
C:\WINDOWS\temp
C:\Qoobox
C:\WINDOWS\erdnt
C:\WINDOWS\tasks\*.*
C:\Program Files\39res.dll
C:\Documents and Settings\User\Moje dokumenty\*.reg
C:\Documents and Settings\User\Pulpit\avast_free_antivirus_setup.exe
C:\Documents and Settings\All Users\Dane aplikacji\ESET
C:\Documents and Settings\All Users\Dane aplikacji\IM
C:\Documents and Settings\All Users\Dane aplikacji\IncrediMail
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
Optymalizacja.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11 Comodo_Dragon/20.1.1.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Nie pomyliłeś go przypadkiem z IncrediMail Toolbar, który jest często spotykany z tym programem??
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11 Comodo_Dragon/20.1.1.0
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11 Comodo_Dragon/20.1.1.0
:OTL
IE - HKU\S-1-5-21-1655781432-987303751-859408246-1008\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/english/?search={searchTerms}&loc=search_box
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Adobe Reader 9.5.1 - Polish
Zarejestrowani użytkownicy: Bing [Bot]