UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.15) Gecko/2009101601 Firefox/3.0.15 hotvideobar_1_3_325525813876174_1_659 VB_gameztar
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
:OTL
PRC - [2004-08-03 22:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
FF - HKLM\software\mozilla\Firefox\extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\3.1.0.1840\FF [2009-12-02 20:58:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5190\FF [2009-12-02 20:58:36 | 00,000,000 | ---D | M]
:Files
C:\Program Files\Web Search Operator
C:\Program Files\Automated Content Enhancer
C:\Qoobox
C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Web Search Operator
C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Gameztar Toolbar
C:\Program Files\Gameztar Toolbar
C:\FOUND.005
C:\FOUND.004
C:\FOUND.003
C:\Documents and Settings\All Users\Dane aplikacji\Wru
c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Automated Content Enhancer
:Commands
[emptytemp]
[start explorer]
[Reboot]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.15) Gecko/2009101601 Firefox/3.0.15 hotvideobar_1_3_325525813876174_1_659 VB_gameztar
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.15) Gecko/2009101601 Firefox/3.0.15 hotvideobar_1_3_325525813876174_1_659 VB_gameztar
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRTCLK"=-
"VMSnap3"=-
"Domino"=-
"NeroFilterCheck"=-
"Malwarebytes Anti-Malware (reboot)"=-
"nwiz"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
c:\\Program Files\\Wru\\Wru.exe"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.4) Gecko/20091016 Firefox/3.5.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.4) Gecko/20091016 Firefox/3.5.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.4) Gecko/20091016 Firefox/3.5.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.4) Gecko/20091016 Firefox/3.5.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"SunJavaUpdateSched"=-
"WinampAgent"=-
"SoundMan"=-
"nwiz"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.4) Gecko/20091016 Firefox/3.5.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 hotvideobar_1_3_325525813876174_1_659 VB_gameztar
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
ComboFix-quarantined-files.txt 2010-01-24 15:47
ComboFix2.txt 2010-01-19 15:54
ComboFix3.txt 2010-01-13 18:51
ComboFix4.txt 2010-01-03 11:12
ComboFix5.txt 2010-01-24 15:38
:OTL
IE - HKU\S-1-5-21-1715567821-1214440339-839522115-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
:Files
C:\FOUND.004
C:\FOUND.003
C:\temp
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 hotvideobar_1_3_325525813876174_1_659 VB_gameztar
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników