19 Lis 2011, 19:14
19 Lis 2011, 19:16
20 Lis 2011, 02:39
20 Lis 2011, 09:49
20 Lis 2011, 11:17
mati8898 napisał(a):A kto Ci kazał używać ComboFix`a??? To nie jest narzędzie, z którego korzysta się na własną rękę. Podaj log, który utworzył, bo nie wiadomo nawet co on tam nawyprawiał.
ComboFixa używamy tylko wtedy, gdy zostaniemy o to wyraźnie poproszeni na forum. Nie korzystamy z niego na własną rękę![]()
![]()
![]()
20 Lis 2011, 21:23
21 Lis 2011, 09:02
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=100476&babsrc=HP_ss&mntrId=e81c166700000000000070f1a1ca676b
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?AF=100476&babsrc=HP_ss&mntrId=e81c166700000000000070f1a1ca676b"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=100476&babsrc=adbartrp&mntrId=e81c166700000000000070f1a1ca676b&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2011-11-19 21:24:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Piotr\AppData\Roaming\mozilla\Firefox\Profiles\wbj3grwu.default\extensions\[email protected]
[2011-11-19 21:24:52 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
[2011-11-19 21:10:54 | 000,000,322 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"SunJavaUpdateSched"=-
"LManager"=-
:Commands
[clearallrestorepoints]
[emptytemp]
21 Lis 2011, 18:02
Masz dwa antywiry: Avasta i Nortona
21 Lis 2011, 19:41
21 Lis 2011, 20:24
21 Lis 2011, 20:32
21 Lis 2011, 20:59
:OTL
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0415&m=easynote_tm87&r=27360511s475l0484z185f47m2h276IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0415&m=easynote_tm87&r=27360511s475l0484z185f47m2h276
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}: C:\Program Files (x86)\RelevantKnowledge
:Files
C:\Program Files (x86)\RelevantKnowledge
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
C:\ProgramData\Spybot - Search & Destroy
C:\Program Files (x86)\Spybot - Search & Destroy
C:\ComboFix
C:\32788R22FWJFW
C:\Users\Piotr\AppData\Local\Babylon
C:\ProgramData\Babylon
C:\Users\Piotr\AppData\Roaming\Babylon
C:\$RECYCLE.BIN
C:\Windows\ERDNT
C:\Qoobox
C:\Users\Piotr\Desktop\ComboFix.exe
C:\Users\Piotr\Desktop\Spybot - Search & Destroy.lnk
C:\Windows\PEV.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\zip.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=-
"BackupManagerTray"=-
:Commands
[clearallrestorepoints]
[emptytemp]
21 Lis 2011, 21:51
22 Lis 2011, 17:49
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
Adobe Reader 9.1 MUI
22 Lis 2011, 20:17