OTL.txt
- Kod: Zaznacz wszystko
http://wklej.to/pQ77o
Extras.txt
- Kod: Zaznacz wszystko
http://wklej.org/id/969090/
GMER
- Kod: Zaznacz wszystko
http://wklej.org/id/970921/
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.97 Safari/537.22
http://wklej.to/pQ77o
http://wklej.org/id/969090/
http://wklej.org/id/970921/
UA: Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.2.0 Safari/537.22
:OTL
IE - HKCU\..\URLSearchHook: {32b29df0-2237-4370-9a29-37cebb730e9b} - No CLSID value found
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=08041819-0953-11e1-9372-001d7d07dc7a&q={searchTerms}
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-10-29 19:17:34 | 000,000,000 | ---D | M] (vShare Add-On) -- C:\Program Files (x86)\mozilla firefox\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}
O4:64bit: - HKLM..\Run: [Windows Defender] File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32B29DF0-2237-4370-9A29-37CEBB730E9B} - No CLSID value found.
O4 - HKCU..\Run: [AdobeBridge] File not found
O8:64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
[2013-02-28 20:20:00 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\dmolvyznd.job
[2013-02-28 00:09:36 | 000,061,440 | ---- | M] () -- C:\Windows\SysWow64\drivers\avlzetz.sys
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeCS6ServiceManager"=-
"SwitchBoard"=-
"TkBellExe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.97 Safari/537.22
http://wklej.org/id/971292/
http://wklej.org/id/971304/
http://wklej.org/id/971314/
http://wklej.org/id/971315/
UA: Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.2.0 Safari/537.22
15:24:11.0751 2772 C:\Windows\System32\Drivers\sptd.sys - copied to quarantine
15:24:11.0752 2772 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted on reboot
15:24:11.0782 2772 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted on reboot
15:24:11.0900 2772 C:\Windows\System32\Drivers\sptd.sys - will be deleted on reboot
15:24:11.0900 2772 sptd ( LockedFile.Multi.Generic ) - User select action: Delete
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.97 Safari/537.22
UA: Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.2.0 Safari/537.22
Zarejestrowani użytkownicy: Google [Bot]