UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
:filefind
services.exe
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\igdkmd32.sys -- (igfx)
IE - HKLM\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q={searchTerms}&crm=1
IE - HKLM\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=f33e1c30-1944-11e1-8680-001e3382a7af&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-940793152-2448901089-3330387304-1000\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q={searchTerms}&crm=1
IE - HKU\S-1-5-21-940793152-2448901089-3330387304-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=f33e1c30-1944-11e1-8680-001e3382a7af&q={searchTerms}
IE - HKU\S-1-5-21-940793152-2448901089-3330387304-1000\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=f33e1c30-1944-11e1-8680-001e3382a7af
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Search the web"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.order.1: "Search the web"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..keyword.URL: "http://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2010-11-06 17:20:47 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Users\ada\AppData\Roaming\mozilla\Firefox\Profiles\2a24vt5a.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2012-03-27 22:04:45 | 000,000,000 | ---D | M] (vShare) -- C:\Users\ada\AppData\Roaming\mozilla\Firefox\Profiles\2a24vt5a.default\extensions\vshare@toolbar
[2012-02-16 22:05:32 | 000,000,000 | ---D | M] (toolplugin) -- C:\Users\ada\AppData\Roaming\mozilla\Firefox\Profiles\2a24vt5a.default\extensions\[email protected]
[2011-10-27 14:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2012-02-16 22:05:32 | 000,000,158 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search the web.src
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O4 - HKU\S-1-5-21-940793152-2448901089-3330387304-1000..\Run: [] File not found
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
[2012-11-08 08:57:55 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-940793152-2448901089-3330387304-1000UA.job
[2012-11-08 08:57:55 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-11-08 08:57:55 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-11-08 08:57:55 | 000,000,998 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-940793152-2448901089-3330387304-1000Core.job
[2012-11-08 08:57:55 | 000,000,488 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3 Startup Task.job
[2012-11-08 08:57:55 | 000,000,464 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Registration3.job
[2012-11-08 08:57:55 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3.job
[2012-11-08 08:57:55 | 000,000,392 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Pro.job
[2012-11-08 02:01:30 | 000,075,111 | ---- | M] () -- C:\Users\ada\ms.exe
[2010-09-10 10:27:12 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\Tempqm5180.html
[2010-09-10 10:27:12 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempFA5180.html
[2010-05-19 21:25:33 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempWD5812.html
[2010-05-19 21:25:33 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\Tempng5812.html
[2010-05-19 21:19:33 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempNK6640.html
[2010-05-19 21:19:33 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempXe6640.html
[2010-05-19 17:06:07 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempMm3180.html
[2010-05-18 13:52:38 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempAF7788.html
[2010-05-18 13:52:38 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempsE7788.html
[2010-05-16 14:31:20 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempWE6024.html
[2010-05-16 14:31:20 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempfP6024.html
[2010-05-15 10:51:20 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempTS5984.html
[2010-05-15 10:51:20 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempBV5984.html
[2010-05-14 11:51:51 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempxO4804.html
[2010-05-14 11:51:51 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempGL4804.html
[2010-05-13 11:42:46 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TemppK2108.html
[2010-05-13 11:42:46 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempeU2108.html
[2010-05-12 17:17:14 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempCC2716.html
[2010-05-12 17:17:14 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\TempeY2716.html
[2010-05-11 17:03:19 | 000,002,432 | ---- | C] () -- C:\Users\ada\AppData\Local\TempPy6900.html
[2010-05-11 17:03:19 | 000,002,089 | ---- | C] () -- C:\Users\ada\AppData\Local\Tempsr6900.html
:Files
C:\Windows\System32\services.exe|C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe /replace
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_USERS\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\S-1-5-21-940793152-2448901089-3330387304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Live Security Platinum"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
:OTL
IE - HKLM\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=f33e1c30-1944-11e1-8680-001e3382a7af&q={searchTerms}
IE - HKU\S-1-5-21-940793152-2448901089-3330387304-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=f33e1c30-1944-11e1-8680-001e3382a7af&q={searchTerms}
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..keyword.URL: "http://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O4 - HKU\S-1-5-21-940793152-2448901089-3330387304-1000..\Run: [TOSCDSPD] TOSCDSPD.EXE File not found
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Value error.)
[2012-11-08 08:57:55 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-940793152-2448901089-3330387304-1000UA.job
[2012-11-08 08:57:55 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-11-08 08:57:55 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-11-08 08:57:55 | 000,000,998 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-940793152-2448901089-3330387304-1000Core.job
[2012-11-08 08:57:55 | 000,000,488 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3 Startup Task.job
[2012-11-08 08:57:55 | 000,000,464 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Registration3.job
[2012-11-08 08:57:55 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3.job
[2012-11-08 08:57:55 | 000,000,392 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Pro.job
[2012-11-08 02:01:30 | 000,075,111 | ---- | M] () -- C:\Users\ada\ms.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_USERS\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\S-1-5-21-940793152-2448901089-3330387304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Live Security Platinum"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
:OTL
:Reg
[HKEY_USERS\S-1-5-21-940793152-2448901089-3330387304-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[-HKEY_USERS\S-1-5-21-940793152-2448901089-3330387304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum]
:Commands
[reboot]
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
Adobe Reader 8 - Polish
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.94 Safari/537.4
UA: Mozilla/5.0 (Windows NT 6.0; rv:16.0) Gecko/20100101 Firefox/16.0
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników