UA: Mozilla/5.0 (Windows NT 6.0; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-2759657243-3996208387-2974778866-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-2759657243-3996208387-2974778866-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=;ftp=;https=;
FF - user.js..browser.search.openintab: false
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\user\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\user\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
[2011-05-02 21:00:34 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\r6yd7ja3.default\extensions\[email protected]
[2011-03-16 14:19:26 | 000,180,896 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DDF13E9F
:Files
C:\Program Files\Google\Update
C:\Users\user\AppData\Local\Google\Update
C:\UsbFix
C:\$RECYCLE.BIN
C:\Users\user\AppData\Roaming\KoshyJohn.com
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KoshyJohn.com
C:\Windows\System32\ClearEvent.exe
C:\UsbFix_Upload_Me_MARTITA.zip
C:\Windows\unins000.exe
C:\Windows\EurekaLog.ini
C:\Windows\System32\KmRemove.exe
C:\Windows\unins000.dat
C:\Windows\IVO Glossary Uninstaller.exe
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"UDP Query User{F8998C0A-4F7E-4940-8C9D-6E750C58BD13}C:\program files\sopcast\adv\sopadver.exe"=-
"TCP Query User{27943271-2BFA-4A45-BC2C-ABFB52FDFEAA}C:\program files\sopcast\adv\sopadver.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
:Files
C:\Windows\tasks\ASCv5_AutoUpdateD.job
C:\$RECYCLE.BIN
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
:Services
gupdatem
gupdate
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 6.0; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
kominekl napisał(a):Daj znać, kiedy już wszystko wykonasz.
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.102 Safari/535.2
Zarejestrowani użytkownicy: Bing [Bot]