Robi się tak przy otwieraniu nowej strony w przeglądarce
Przepraszam za niewiedzę.
otl http://wklej.eu/index.php?id=2ca1dd836d
Combofix http://wklej.eu/index.php?id=a4ea9e06dd
UA: Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 Firefox/24.0
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:24.0) Gecko/20100101 Firefox/24.0
:OTL
SRV - File not found [Auto | Running] -- C:\Program Files\Yontoo\Y2Desktop.Updater.exe C:\Users\Natalia\AppData\Roaming\Yontoo\YontooDesktop.exe -- (Yontoo Desktop Updater)
MOD - [2013-10-14 10:33:19 | 000,013,600 | ---- | M] () -- C:\Users\Natalia\AppData\Roaming\Yontoo\dat\Desktop.OS.Plugin.dll
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Natalia\AppData\Local\Temp\catchme.sys -- (catchme)
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10025&barid={A652C865-5F4F-11E2-A80C-001FD0528D5D}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss_din2g&mntrId=82A3001FD0528D5D&affID=119357&tt=040713_ifrmful&tsp=4934
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&babsrc=SP_ss_din2g&mntrId=82A3001FD0528D5D&affID=119357&tt=040713_ifrmful&tsp=4934
IE - HKCU\..\SearchScopes\{A02BE3E5-894C-4C6C-9E1B-17F84106D67F}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=48D83446-7E23-449A-8F30-165A0F47C703&apn_sauid=9D6F72B4-697A-4768-AAB8-67182E563F2D
IE - HKCU\..\SearchScopes\{B224AA02-F7C8-3A2B-859F-560B80767E4A}: "URL" = http://kl.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=876&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=PL&install_date=20130219&user_guid=3949140A1A5543399004E269B867C73E&machine_id=aacd3b46e1028a8c59f9ea1eb576b979&browser=IE&os=win&os_version=6.1-x86-SP1&iesrc={referrer:source}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10025&barid={A652C865-5F4F-11E2-A80C-001FD0528D5D}
[2013-10-13 09:57:13 | 000,000,000 | ---D | M] ("a2zLyrics-15") -- C:\Users\Natalia\AppData\Roaming\mozilla\Firefox\Profiles\vbm75ov2.default\extensions\acec7c99-b789-494a-9cd9-cf2130be4fe2@7837d0b0-c968-42e7-b0ac-b09c864a5978.com
[2013-10-07 16:36:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
CHR - Extension: a2zLyrics-15 = C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Default\Extensions\loblblopcimdjlmbialgooenabfognaf\1.25.5_0\crossrider
CHR - Extension: a2zLyrics-15 = C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Default\Extensions\loblblopcimdjlmbialgooenabfognaf\1.25.5_0\
CHR - Extension: Yontoo = C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_1\
O4 - HKCU..\Run: [Yontoo Desktop] C:\Users\Natalia\AppData\Roaming\Yontoo\YontooDesktop.exe (Yontoo LLC)
[2013-10-14 10:33:13 | 000,001,930 | ---- | M] () -- C:\Windows\tasks\a2zLyrics-15-chromeinstaller.job
[2013-10-14 10:33:13 | 000,001,856 | ---- | M] () -- C:\Windows\tasks\a2zLyrics-15-firefoxinstaller.job
[2013-10-14 10:33:13 | 000,001,328 | ---- | M] () -- C:\Windows\tasks\a2zLyrics-15-updater.job
[2013-10-14 10:33:13 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-10-14 10:33:12 | 000,001,234 | ---- | M] () -- C:\Windows\tasks\a2zLyrics-15-codedownloader.job
[2013-10-14 10:33:12 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\a2zLyrics-15-enabler.job
[2013-01-06 11:26:37 | 000,000,000 | ---D | M] -- C:\Users\Natalia\AppData\Roaming\Babylon
:Files
c:\users\Natalia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"=-
"Facebook Update"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"HP Software Update"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"QuickTime Task"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 Firefox/24.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:24.0) Gecko/20100101 Firefox/24.0
:OTL
SRV - File not found [Auto | Running] -- C:\Program Files\Yontoo\Y2Desktop.Updater.exe C:\Users\Natalia\AppData\Roaming\Yontoo\YontooDesktop.exe -- (Yontoo Desktop Updater)
CHR - Extension: a2zLyrics-15 = C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Default\Extensions\loblblopcimdjlmbialgooenabfognaf\1.25.5_0\crossrider
CHR - Extension: a2zLyrics-15 = C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Default\Extensions\loblblopcimdjlmbialgooenabfognaf\1.25.5_0\
[2013-10-14 18:05:01 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-738174641-4256900879-461992290-1000UA.job
[2013-10-14 18:05:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-738174641-4256900879-461992290-1000Core.job
[2013-10-14 18:00:56 | 000,000,000 | ---D | M] -- C:\Users\Natalia\AppData\Roaming\Yontoo
Java 7 Update 17
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników