25 Paź 2013, 01:21
25 Paź 2013, 16:50
25 Paź 2013, 18:19
25 Paź 2013, 19:59
25 Paź 2013, 20:44
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
IE - HKU\S-1-5-21-3769144204-2254581525-2510006046-500\..\SearchScopes\{735D91FB-C5B7-40A9-851A-8C910A173FBA}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=SLS&o=APN10610&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^ADI&apn_dtid=^YYYYYY^YY^PL&apn_uid=5d9fe07c-9fd3-471c-a3a6-c4a4adf642c7&apn_sauid=42E7CB9D-73DF-49AE-996C-D2E68AD6A9F1
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
[2013-05-27 06:10:39 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\j8nbk9uq.default\extensions\[email protected]
[2013-01-24 15:16:00 | 000,002,333 | ---- | M] () -- C:\Users\Administrator\AppData\Roaming\mozilla\firefox\profiles\j8nbk9uq.default\searchplugins\askcom.xml
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKU\S-1-5-21-3769144204-2254581525-2510006046-500..\Run: [] File not found
O4 - HKU\S-1-5-21-3769144204-2254581525-2510006046-500..\Run: [Crystal.exe] C:\Users\Administrator\AppData\Roaming\Crystal.exe File not found
O4 - HKU\S-1-5-21-3769144204-2254581525-2510006046-500..\Run: [nvwiz] C:\ProgramData\nvwiz.exe ( )
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
:Files
C:\Users\Administrator\AppData\Local\Temp*.html
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pokki"=-
"ALLUpdate"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"GrooveMonitor"=-
"SunJavaUpdateSched"=-
:Commands
[clearallrestorepoints]
[emptytemp]
26 Paź 2013, 00:10
26 Paź 2013, 00:20
26 Paź 2013, 18:35
27 Paź 2013, 11:54
27 Paź 2013, 12:03
27 Paź 2013, 13:46
:OTL
[2013-10-25 23:30:23 | 000,694,864 | ---- | C] (WilSys Co., Ltd.) -- C:\Users\Administrator\AppData\Roaming\qone8.exe
[2013-10-25 20:01:06 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
[2013-10-25 19:20:21 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SecureSearch
[2013-10-25 19:19:38 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2013-10-25 19:15:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
O4 - HKU\S-1-5-21-3769144204-2254581525-2510006046-500..\Run: [Pokki] C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\LaunchDeskband.dll",RunLaunchDeskband File not found
O4 - HKLM..\Run: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe File not found
O3 - HKU\S-1-5-21-3769144204-2254581525-2510006046-500\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
FF - prefs.js..keyword.URL: "http://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_6&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q="
IE - HKU\S-1-5-21-3769144204-2254581525-2510006046-500\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutDtDtBtAzz0BtCyCtBzytB0F0FyEyDyBtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=23758743&ir=
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutDtDtBtAzz0BtCyCtBzytB0F0FyEyDyBtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=23758743&ir=
:Files
C:\Users\Administrator\AppData\Local\Temp*.html
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
:Commands
[clearallrestorepoints]
[emptytemp]
27 Paź 2013, 16:16
27 Paź 2013, 22:13
28 Paź 2013, 09:58
Java(TM) 7 Update 5
28 Paź 2013, 19:42