22 Kwi 2012, 19:13
22 Kwi 2012, 19:58
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com/?cid={DEA8D535-B026-40CD-97FB-79F412E3F338}&mid=b776be58b52447d0831fd16c64584e7a-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=st011&pr=sa&d=2012-04-10 16:56:44&v=10.0.0.7&sap=hp
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\Splashtop\Splashtop Connect IE\AddressBarSearch.dll (Splashtop Inc.)
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\${searchCLSID}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SPLEP1&pc=SPLH
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\{11B73D49-CD49-44f1-948A-C942C65CF499}: "URL" = http://www.google.com/cse?cx=partner-pub-3794288947762788%3A4107735745&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4107735745&q={searchTerms}
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\{3ED04DDF-F2C9-4BEC-BB66-85B0F9CB4E61}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=kw&q={searchTerms}&locale=&apn_ptnrs=PV&apn_dtid=YYYYYYYYPL&apn_uid=81aade6b-a10e-4ed9-9584-b4836ab621c6&apn_sauid=65E179D7-FC2E-405F-9E6E-9EFCB81E132E
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={DEA8D535-B026-40CD-97FB-79F412E3F338}&mid=b776be58b52447d0831fd16c64584e7a-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=st011&pr=sa&d=2012-04-10 16:56:44&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\{B9D9CF2B-B8D5-42ed-8F31-461A79D158BB}: "URL" = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=PROTOSV
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:1CE11B51
:Files
C:\ProgramData\{8533ADFA-85F0-4dc1-946A-2A0BA58E78E3}
C:\ProgramData\TEMP
C:\Windows\tasks\*.job
C:\Users\Konrad\AppData\Roaming\Malwarebytes
C:\ProgramData\Malwarebytes
C:\KWBYV
C:\Users\Konrad\AppData\Roaming\EurekaLog
:Commands
[clearallrestorepoints]
[emptytemp]
22 Kwi 2012, 20:40
22 Kwi 2012, 21:01
:OTL
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\${searchCLSID}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
:Files
C:\Users\Konrad\Desktop\AutoRuns.arn
:Commands
[clearallrestorepoints]
[emptytemp]
23 Kwi 2012, 16:42
23 Kwi 2012, 20:16
23 Kwi 2012, 22:30
24 Kwi 2012, 15:25
:OTL
IE - HKU\S-1-5-21-2912975821-3514601545-274534835-1000\..\SearchScopes\${searchCLSID}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
O2:[b]64bit:[/b] - BHO: (no name) - AutorunsDisabled - No CLSID value found.
:Commands
[clearallrestorepoints]
[emptytemp]
29 Kwi 2012, 13:19
30 Kwi 2012, 17:48
01 Maj 2012, 15:40
01 Maj 2012, 15:53
01 Maj 2012, 15:59