06 Sie 2013, 18:16
06 Sie 2013, 18:40
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=1373011290
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=3670082
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=1373011290
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=1373011290
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=3670082
IE - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
IE - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3500418AS_9VM02BBBXXXX9VM02BBB&ts=3670082
F3:64bit: - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000 WinNT: Load - (C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe) - C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe (AHJBVDHAF)
F3 - HKU\S-1-5-21-2231361402-3911154358-2268299652-1000 WinNT: Load - (C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe) - C:\Users\Wepster\LOCALS~1\Temp\msvatybay.exe (AHJBVDHAF)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: 43974 = C:\PROGRA~3\LOCALS~1\Temp\msiujyeug.cmd (AHJBVDHAF)
[2013-08-06 17:22:26 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2013-08-06 17:22:16 | 000,063,488 | ---- | M] () -- C:\Users\Wepster\AppData\Roaming\RZR_00702dbf4443a2f9c79b03b7ca12.db
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
"Acrobat Reader"=-
:Commands
[clearallrestorepoints]
[emptytemp]
06 Sie 2013, 18:53
06 Sie 2013, 19:06
:OTL
:Files
C:\ProgramData\eSafe
06 Sie 2013, 19:38
07 Sie 2013, 11:33
Adobe Reader 9
07 Sie 2013, 16:03
08 Sie 2013, 10:43