03 Kwi 2011, 16:36
03 Kwi 2011, 17:01
:OTL
PRC - [2011/04/02 23:10:22 | 000,239,213 | -HS- | M] () -- C:\Users\gprz\AppData\Local\ahm.exe
IE - HKU\S-1-5-21-108679968-3426115008-719098160-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.speedbit.com/?aff=205
FF - prefs.js..browser.search.defaultenginename: "SpeedBit Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Free Ride Games Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://home.speedbit.com/search.aspx?aff=206&q="
FF - prefs.js..browser.search.order.1: "SpeedBit Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=685749"
FF - prefs.js..browser.search.selectedEngine: "SpeedBit Search"
FF - prefs.js..browser.startup.homepage: "http://home.speedbit.com/?aff=205"
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2
FF - prefs.js..keyword.URL: "http://home.speedbit.com/search.aspx?aff=206&q="
[2011/03/24 20:25:06 | 000,000,000 | ---D | M] (Free Ride Games Community Toolbar) -- C:\Users\gprz\AppData\Roaming\Mozilla\Firefox\Profiles\si00p44o.default\extensions\{f92a9fe4-2850-4198-b9d5-279880e49b16}
[2011/03/24 20:25:09 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\gprz\AppData\Roaming\Mozilla\Firefox\Profiles\si00p44o.default\extensions\[email protected]
[2010/07/12 19:44:46 | 000,000,933 | ---- | M] () -- C:\Users\gprz\AppData\Roaming\Mozilla\Firefox\Profiles\si00p44o.default\searchplugins\conduit.xml
[2011/04/01 15:13:00 | 000,002,534 | ---- | M] () -- C:\Users\gprz\AppData\Roaming\Mozilla\Firefox\Profiles\si00p44o.default\searchplugins\speedbit.xml
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKU\S-1-5-21-108679968-3426115008-719098160-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O35 - HKU\S-1-5-21-108679968-3426115008-719098160-1000..exefile [open] -- "C:\Users\gprz\AppData\Local\ahm.exe" -a "%1" %* ()
O37 - HKU\S-1-5-21-108679968-3426115008-719098160-1000\...exe [@ = exefile] -- "C:\Users\gprz\AppData\Local\ahm.exe" -a "%1" %* ()
[2011/04/02 23:10:37 | 000,114,688 | -HS- | C] (Microsoft Corporation) -- C:\Users\gprz\AppData\Local\xbb.exe
[2011/04/03 14:38:37 | 000,010,532 | -HS- | M] () -- C:\Users\gprz\AppData\Local\jcl665ep0rnlp562hps
[2011/04/03 14:38:37 | 000,010,532 | -HS- | M] () -- C:\ProgramData\jcl665ep0rnlp562hps
[2011/04/03 14:37:40 | 000,000,368 | ---- | M] () -- C:\Windows\tasks\AWC Startup.job
[2011/04/02 23:10:22 | 000,239,213 | -HS- | M] () -- C:\Users\gprz\AppData\Local\nqu.exe
[2011/04/02 23:10:22 | 000,239,213 | -HS- | M] () -- C:\Users\gprz\AppData\Local\ahm.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=-
"HotKeysCmds"=-
"Persistence"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"Adobe Reader Speed Launcher"=-
:Commands
[clearallrestorepoints]
[emptytemp]
A i jeszcze pytanko, czy taka infekcja może zaatakować zainstalowane programy?? BO Emsisoft wywalił mi całego UltraISO i Aresa mówiąc że to wirusy?? A ściągałem z Instalek.
03 Kwi 2011, 17:28
03 Kwi 2011, 18:15
:OTL
FF - prefs.js..browser.search.defaultenginename: "SpeedBit Search"
IE - HKU\S-1-5-21-108679968-3426115008-719098160-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.speedbit.com/?aff=205
FF - prefs.js..browser.search.order.1: "SpeedBit Search"
FF - prefs.js..browser.search.param.yahoo-fr: ""
FF - prefs.js..browser.search.selectedEngine: "SpeedBit Search"
FF - prefs.js..browser.search.defaulturl: "http://home.speedbit.com/search.aspx?aff=206&q="
FF - prefs.js..keyword.URL: "http://home.speedbit.com/search.aspx?aff=206&q="
[2011/04/03 16:21:00 | 000,002,534 | ---- | M] () -- C:\Users\gprz\AppData\Roaming\Mozilla\Firefox\Profiles\si00p44o.default\searchplugins\speedbit.xml
Adobe Reader 9.4.3 MUI
03 Kwi 2011, 18:29