UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:22.0) Gecko/20100101 Firefox/22.0
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=1373011290
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=3670082
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=1373011290
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=1373011290
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=3670082
IE - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
IE - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=3670082
F3:64bit: - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000 WinNT: Load - (C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe) - C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe (AHJBVDHAF)
F3 - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000 WinNT: Load - (C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe) - C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe (AHJBVDHAF)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: 43974 = C:\PROGRA~3\LOCALS~1\Temp\msiujyeug.cmd (AHJBVDHAF)
[2013-08-06 17:22:26 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2013-08-06 17:22:16 | 000,063,488 | ---- | M] () -- C:\Users\Wepster\AppData\Roaming\RZR_00702dbf4443a2f9c79b03b7ca12.db
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
"Acrobat Reader"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:22.0) Gecko/20100101 Firefox/22.0
:OTL
:Files
C:\ProgramData\eSafe
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:22.0) Gecko/20100101 Firefox/22.0
Adobe Reader 9
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:22.0) Gecko/20100101 Firefox/22.0
Zarejestrowani użytkownicy: Bing [Bot]