UA: Mozilla/5.0 (Windows NT 5.1; rv:24.0) Gecko/20100101 Firefox/24.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Ardamax Keylogger 2.8
:OTL
MOD - [2012-11-27 20:32:46 | 000,027,958 | ---- | M] () -- C:\Program Files\Common Files\logonInit.dll
IE - HKU\S-1-5-21-1960408961-1844237615-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=185B000FEA2B630A&affID=119357&tsp=4952
IE - HKU\S-1-5-21-1960408961-1844237615-1801674531-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110808&tt=3412_1&babsrc=SP_ss&mntrId=185be7f9000000000000000fea2b630a
IE - HKU\S-1-5-21-1960408961-1844237615-1801674531-1003\..\SearchScopes\{ED95F7DF-CFBE-498D-BC6A-1F96D590CEE8}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NDV&o=15765&src=crm&q={searchTerms}&locale=&apn_ptnrs=NY&apn_dtid=YYYYYYYYPL&apn_uid=CD608BD4-09E0-4F0E-BC6C-32B24B8B9117&apn_sauid=87127FD1-EE15-43EE-835C-B92A7B73E5AB&
[2011-11-17 18:25:44 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\Bimbrownik\Dane aplikacji\Mozilla\Firefox\Profiles\y4ywe30x.default\searchplugins\askcom.xml
[2013-07-23 16:30:25 | 000,006,507 | ---- | M] () -- C:\Documents and Settings\Bimbrownik\Dane aplikacji\Mozilla\Firefox\Profiles\y4ywe30x.default\searchplugins\babylon.xml
[2013-07-23 16:31:21 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\Bimbrownik\Dane aplikacji\Mozilla\Firefox\Profiles\y4ywe30x.default\searchplugins\delta.xml
[2013-01-16 15:47:19 | 000,002,203 | ---- | M] () -- C:\Documents and Settings\Bimbrownik\Dane aplikacji\Mozilla\Firefox\Profiles\y4ywe30x.default\searchplugins\MyStart Search.xml
O20 - Winlogon\Notify\LogonInit: DllName - (logonInit.dll) - C:\Program Files\Common Files\logonInit.dll ()
[2012-08-15 15:34:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2012-08-15 15:34:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bimbrownik\Dane aplikacji\Babylon
[2012-09-20 14:15:04 | 000,000,282 | ---- | C] () -- C:\WINDOWS\Tasks\RMAutoUpdate.job
:Files
C:\Program Files\Common Files\userInit.dll
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=-
"SoundMan"=-
"nwiz"=-
"NvMediaCenter"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GG"=-
"spoolsv32"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:24.0) Gecko/20100101 Firefox/24.0
UA: Mozilla/5.0 (Windows; U; Windows NT 5.2; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Zarejestrowani użytkownicy: Bing [Bot]