UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 AskTbPF/3.9.1.14019 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 AskTbPF/3.9.1.14019 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 AskTbPF/3.9.1.14019 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
proszę o to wpis z OTL http://www.wklej.eu/index.php?id=0e6598d863
http://www.wklej.eu/index.php?id=d0a64e71b5 <<tu z GMER
:OTL
PRC - [2010-12-18 04:55:15 | 000,280,064 | ---- | M] () -- C:\WINDOWS\spolvs.exe
IE - HKU\S-1-5-21-1292428093-1993962763-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=15627
IE - HKU\S-1-5-21-1292428093-1993962763-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.imesh.com/sidebar.html?src=ssb&sysid=1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.imesh.com/sidebar.html?src=ssb&sysid=1
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "XfireXO Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://start24.pl/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2.0185
FF - prefs.js..extensions.enabledItems: [email protected]:3.9.1.14019
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=PF&o=15180&locale=en_US&apn_uid=BF78444F-BFE1-4BFB-BE6D-EBC767E725B4&apn_ptnrs=RX&apn_sauid=07CBC439-8824-4A65-9D34-03385591E8A3&apn_dtid=YYYYYYYYPL&q="
[2010-10-03 16:58:53 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\extensions\{28D35620-51D9-11DE-9D13-2DB156D89593}
[2010-08-06 12:39:48 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2010-07-24 21:58:03 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\extensions\[email protected]
[2010-10-24 17:02:33 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\extensions\[email protected]
[2011-01-14 12:40:32 | 000,002,566 | ---- | M] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\searchplugins\askcom.xml
[2009-12-03 10:54:24 | 000,002,476 | ---- | M] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\searchplugins\BearShareWebSearch.xml
[2010-08-05 20:30:44 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\searchplugins\conduit.xml
[2010-01-28 21:58:15 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\searchplugins\daemon-search.xml
[2010-08-12 09:21:14 | 000,002,486 | ---- | M] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\al13vlhw.default\searchplugins\iMeshWebSearch.xml
[2009-12-03 10:54:24 | 000,002,476 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml
[2010-08-12 09:21:14 | 000,002,486 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml
O4 - HKLM..\Run: [A0003107 Agent] File not found
O4 - HKLM..\Run: [C6501Sound] File not found
O4 - HKU\S-1-5-21-1292428093-1993962763-839522115-1003..\Run: [AutoConnect] File not found
O4 - HKU\S-1-5-21-1292428093-1993962763-839522115-1003..\Run: [Microsoft Intero Services] File not found
O4 - HKU\S-1-5-21-1292428093-1993962763-839522115-1003..\Run: [spolvs.exe] C:\WINDOWS\spolvs.exe ()
(Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Właściciel\Menu Start\Programy\Autostart\xe0305.exe ()
O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~1\MediaBar\DataMngr\datamngr.dll) - File not found
O20 - Winlogon\Notify\LogonInit: DllName - logonInit.dll - C:\Program Files\Common Files\logonInit.dll ()
[2011-01-14 18:01:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Ardamax Keylogger
[2011-01-14 22:01:00 | 000,000,244 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011-01-14 18:04:17 | 000,000,320 | -HS- | M] () -- C:\WINDOWS\tasks\PPIIVGRE.job
[2011-01-14 17:00:06 | 000,001,073 | ---- | M] () -- C:\Program Files\Common Files\userInit.dll
[2011-01-14 16:05:08 | 000,000,484 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Właściciel.job
:Files
C:\Documents and Settings\Właściciel\Menu Start\Programy\Autostart\Microsoft Office.lnk
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"Office"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
Extras musisz mi podać linka
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( .NET CLR 3.5.30729; .NET4.0E)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 ( )
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
ComboFixa używamy tylko wtedy, gdy zostaniemy o to wyraźnie poproszeni na forum. Nie korzystamy z niego na własną rękę
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\system.exe"=-
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\system.exe
Zarejestrowani użytkownicy: Bing [Bot]