UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.75 Safari/535.7
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=1&cf=bc5cc9fe-36cd-11e1-a443-0008023871fd"
FF - prefs.js..extensions.enabledItems: [email protected]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: mil@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=bc5cc9fe-36cd-11e1-a443-0008023871fd&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
[2009-11-12 12:50:24 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\extensions\[email protected]
[2010-08-25 06:32:33 | 000,000,000 | ---D | M] (MakeItLive) -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\extensions\mil@toolbar
[2011-05-11 13:07:39 | 000,000,000 | ---D | M] (vShare) -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\extensions\vshare@toolbar
[2011-09-26 06:52:29 | 000,002,396 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\askcom.xml
[2009-06-08 08:00:54 | 000,002,428 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\babylon.xml
[2012-01-04 13:15:29 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\startsear.xml
[2010-08-25 06:33:54 | 000,001,574 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\web-search.xml
[2011-10-03 10:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize File not found
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
:Files
C:\Program Files\Google\Update
C:\Program Files\Veetle
C:\Program Files\Trend Micro
C:\Program Files\vShare.tv plugin
C:\WINDOWS\tasks\*.job
C:\Documents and Settings\COMPAQ\Dane aplikacji\vShare
C:\Documents and Settings\COMPAQ\Dane aplikacji\Malwarebytes
C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
C:\Program Files\Malwarebytes' Anti-Malware
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=-
"nwiz"=-
"TkBellExe"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Wyskoczyło, że trzeba ponownie uruchomić kompa.
:OTL
FF - prefs.js..babylon.toolbar.keyword.enabled: "true"
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=1&cf=bc5cc9fe-36cd-11e1-a443-0008023871fd"
FF - prefs.js..extensions.enabledItems: mil@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=bc5cc9fe-36cd-11e1-a443-0008023871fd&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
[2009-11-12 12:50:24 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\extensions\[email protected]
[2010-08-25 06:32:33 | 000,000,000 | ---D | M] (MakeItLive) -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\extensions\mil@toolbar
[2011-09-26 06:52:29 | 000,002,396 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\askcom.xml
[2009-06-08 08:00:54 | 000,002,428 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\babylon.xml
[2012-01-04 13:15:29 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\startsear.xml
[2010-08-25 06:33:54 | 000,001,574 | ---- | M] () -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Mozilla\Firefox\Profiles\hj23glbd.default\searchplugins\web-search.xml
O3 - HKU\S-1-5-21-1004336348-343818398-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-1004336348-343818398-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize File not found
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
[2012-01-24 18:13:31 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1004336348-343818398-1606980848-1003.job
[2012-01-24 18:13:12 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1004336348-343818398-1606980848-1003.job
[2012-01-24 18:11:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-01-24 17:59:40 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-01-24 15:39:18 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012-01-19 11:45:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\COMPAQ\Dane aplikacji\Malwarebytes
[2012-01-19 11:45:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
'TkBellExe"=-
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
O3 - HKU\S-1-5-21-1004336348-343818398-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-1004336348-343818398-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
:Files
C:\Documents and Settings\COMPAQ\Dane aplikacji\Malwarebytes
C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
C:\WINDOWS\tasks\*.job
C:\Program Files\AVG
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=-
"BluetoothAuthenticationAgent"=-
"nwiz"=-
"TkBellExe"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\SopCast\adv\SopAdver.exe"=-
"C:\Program Files\AVG\AVG2012\avgnsx.exe"=-
"C:\Program Files\AVG\AVG2012\avgdiagex.exe"=-
"C:\Program Files\AVG\AVG2012\avgmfapx.exe"=-
"C:\Program Files\AVG\AVG2012\avgemcx.exe"=-
:Commands
[clearallrestorepoints]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:Files
C:\WINDOWS\tasks\*.job
:Commands
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]