UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
:OTL
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=687efc300000000000000016d4c7569a&tlver=1.4.23.10&affID=100607"
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
[2011-07-24 19:13:35 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2011-07-24 19:13:40 | 000,002,424 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
http://www.przeklej.pl/plik/security-tak-manager-processinfo-2011-07-30-21-12-html-002bru7gp2673sp
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
:OTL
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=687efc300000000000000016d4c7569a&tlver=1.4.23.10&affID=100607"
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
[2011-07-24 19:13:35 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2011-07-24 19:13:40 | 000,002,424 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
:OTL
DRV - File not found [File_System | Unknown | Running] -- -- (DwProt)
[2011-07-31 09:17:23 | 000,000,372 | ---- | M] () -- C:\Windows\tasks\IObit Security 360 Updater.job
@Alternate Data Stream - 98 bytesC:\ProgramData\TEMP:70F32378
@Alternate Data Stream - 164 bytesC:\ProgramData\TEMP:6C3B8FB5
@Alternate Data Stream - 157 bytesC:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 129 bytesC:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 122 bytesC:\ProgramData\TEMP:DDF13E9F
@Alternate Data Stream - 121 bytesC:\ProgramData\TEMP:B3D74A13
:Files
C:\ProgramData\mxnhytee.feu
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IObit Security 360"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
:OTL
[2011-07-31 09:17:23 | 000,000,372 | ---- | M] () -- C:\Windows\tasks\IObit Security 360 Updater.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IObit Security 360"=-
:OTL
[2011-07-31 18:45:05 | 000,004,109 | ---- | M] () -- C:\ProgramData\mxnhytee.feu
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
mati8898 napisał(a)::OTL
[2011-07-31 09:17:23 | 000,000,372 | ---- | M] () -- C:\Windows\tasks\IObit Security 360 Updater.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IObit Security 360"=-
Co ty robisz??? Usuwasz wpisy od programu zabezpieczającego
Końcowy skrypt powinien wyglądać tak::OTL
[2011-07-31 18:45:05 | 000,004,109 | ---- | M] () -- C:\ProgramData\mxnhytee.feu
UA: Mozilla/5.0 (Windows NT 6.0; rv:5.0) Gecko/20100101 Firefox/5.0
========== OTL ==========
C:\ProgramData\mxnhytee.feu moved successfully.
OTL by OldTimer - Version 3.2.26.1 log created on 07312011_222716
========== OTL ==========
C:\ProgramData\mxnhytee.feu moved successfully.
OTL by OldTimer - Version 3.2.26.1 log created on 07312011_222716
DRV - File not found [File_System | Unknown | Running] -- -- (DwProt)
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:70F32378
@Alternate Data Stream - 164 bytes -> C:\ProgramData\TEMP:6C3B8FB5
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DDF13E9F
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:B3D74A13
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników