11 Mar 2010, 15:42
11 Mar 2010, 15:44
11 Mar 2010, 16:08
11 Mar 2010, 16:39
http://www.speedyshare.com/files/21370658/alg.zip
:OTL
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
[2010-02-15 19:42:23 | 000,002,424 | ---- | M] () -- C:\Documents and Settings\kropek\Dane aplikacji\Mozilla\Firefox\Profiles\jjzsss7t.default\searchplugins\askcom.xml
O32 - AutoRun File - [2010-02-27 21:30:52 | 000,000,053 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-27 21:30:52 | 000,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-27 21:30:52 | 000,000,053 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-27 21:30:52 | 000,000,053 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{4fb78624-1e31-11df-a04b-001966898565}\Shell\AutoRun\command - "" = I:\c2e.exe -- File not found O33 - MountPoints2\{4fb78624-1e31-11df-a04b-001966898565}\Shell\open\Command - "" = I:\c2e.exe -- File not found
:Files
C:\32788R22FWJFW
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"AudioHQ"=-
"WinampAgent"=-
:Commands
[emptytemp]
11 Mar 2010, 16:57
11 Mar 2010, 17:06
11 Mar 2010, 17:10
11 Mar 2010, 17:26
11 Mar 2010, 17:36
11 Mar 2010, 17:37
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 03/11/2010 at 04:36 PM
Application Version : 4.34.1000
Core Rules Database Version : 4596
Trace Rules Database Version: 1978
Scan type : Complete Scan
Total Scan Time : 00:04:38
Memory items scanned : 435
Memory threats detected : 0
Registry items scanned : 6709
Registry threats detected : 1
File items scanned : 0
File threats detected : 0
Trojan.DNS-Changer (Hi-Jacked DNS)
HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{4E95EB64-D36E-4D30-B513-89ECB5899596}#NAMESERVER
11 Mar 2010, 18:23
11 Mar 2010, 18:28
11 Mar 2010, 18:37
http://www.avast.com/, http://www.kaspersky.com/, http://www.eset.com/ ???
11 Mar 2010, 18:49
11 Mar 2010, 19:22