
Log: HijackThis
http://www.wklej.org/id/541209/
Log: OTL
http://www.wklej.org/id/541213/
Log: OTL Extras
http://www.wklej.org/id/541214/
D:\TheMummy.exe
D:\Overlay.exe
:OTL
IE - HKLM\..\URLSearchHook: {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files (x86)\Mario_Forever\tbMari.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2247187
IE - HKCU\..\URLSearchHook: {707db484-2428-402d-afb5-d85b387544c7} - C:\Program Files (x86)\Mario_Forever\tbMari.dll (Conduit Ltd.)
[2011/04/29 17:23:40 | 000,000,000 | ---D | M] (Mario Forever Toolbar) -- C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\tef1elcn.default\extensions\{707db484-2428-402d-afb5-d85b387544c7}
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
@Alternate Data Stream - 150 bytes -> C:\ProgramData\Temp:268F887D
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:5C270C64
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:798A3728
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:2430E4FC
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:9E22BBE8
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:8530A643
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:4CF61E54
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:E7BA7168
:Files
C:\Program Files (x86)\Panda Security
C:\Users\Adam\AppData\Local\Conduit
:Commands
[emptytemp]
[emptyflash]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 13 gości