
z góry dzięki
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\massfilter.sys -- (massfilter)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchya.com/?s=0&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzutDtDtC0D0EtDtB0AtBtCzytCyEtByDtDtN0D0Tzu0CtBtBtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=421050454
IE - HKLM\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzutDtDtC0D0EtDtB0AtBtCzytCyEtByDtDtN0D0Tzu0CtBtBtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=421050454
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?affID=110000&tt=3012_3&babsrc=HP_ss&mntrId=487de9ed000000000000001de02a2191
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchya.com/?s=0&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzutDtDtC0D0EtDtB0AtBtCzytCyEtByDtDtN0D0Tzu0CtBtBtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=421050454
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - D:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzutDtDtC0D0EtDtB0AtBtCzytCyEtByDtDtN0D0Tzu0CtBtBtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=421050454
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031817
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..backup.old.browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..backup.old.browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=110000&tt=3012_3&babsrc=HP_ss&mntrId=487de9ed000000000000001de02a2191"
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchya.com/?s=0&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1QzutDtDtC0D0EtDtB0AtBtCzytCyEtByDtDtN0D0Tzu0CtBtBtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=421050454"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=110000&tt=3012_3&babsrc=KW_ss&mntrId=487de9ed000000000000001de02a2191&q="
[2012-07-19 10:26:42 | 000,000,000 | ---D | M] (SFT_Polska Community Toolbar) -- D:\Documents and Settings\Alicja\Dane aplikacji\Mozilla\Firefox\Profiles\o6xanumr.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}
[2012-07-19 23:56:12 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- D:\Documents and Settings\Alicja\Dane aplikacji\Mozilla\Firefox\Profiles\o6xanumr.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012-01-02 16:01:41 | 000,000,000 | ---D | M] (DealPly) -- D:\Documents and Settings\Alicja\Dane aplikacji\Mozilla\Firefox\Profiles\o6xanumr.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012-08-08 21:11:53 | 000,000,000 | ---D | M] (searchya.com) -- D:\Documents and Settings\Alicja\Dane aplikacji\Mozilla\Firefox\Profiles\o6xanumr.default\extensions\ffxtlbr@searchya.com
[2012-08-08 21:12:04 | 000,002,335 | ---- | M] () -- D:\Documents and Settings\Alicja\Dane aplikacji\Mozilla\Firefox\Profiles\o6xanumr.default\searchplugins\Search.xml
[2012-07-28 17:21:15 | 000,002,349 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012-02-07 14:25:44 | 000,002,415 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\v9.xml
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - D:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - D:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - D:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - D:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe File not found
O4 - HKLM..\Run: [snpstd] D:\WINDOWS\vsnpstd.exe ()
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [erlfdhknzkznmji] D:\Documents and Settings\All Users\Dane aplikacji\erlfdhkn.exe ()
O4 - HKCU..\Run: [Facebook Update] D:\Documents and Settings\Alicja\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Kookos] D:\Documents and Settings\Alicja\Ustawienia lokalne\Dane aplikacji\Kookos\kookos.exe silent File not found
O33 - MountPoints2\{61a5c69c-1ff3-11e1-bb15-001060d10c6a}\Shell - "" = AutoRun
O33 - MountPoints2\{61a5c69c-1ff3-11e1-bb15-001060d10c6a}\Shell\AutoRun\command - "" = D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL WinJoke.exe
O33 - MountPoints2\{ac24e5e0-4c0d-11e0-b9e9-001060d10c6a}\Shell - "" = AutoRun
O33 - MountPoints2\{ac24e5e0-4c0d-11e0-b9e9-001060d10c6a}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
[2012-07-28 17:21:05 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2012-07-28 17:21:05 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Alicja\Dane aplikacji\Babylon
[2012-08-08 18:10:22 | 000,001,156 | ---- | M] () -- D:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1202660629-1123561945-839522115-1003UA.job
[2012-08-08 18:10:08 | 000,001,134 | ---- | M] () -- D:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1202660629-1123561945-839522115-1003Core.job
[2012-08-04 02:00:01 | 000,000,344 | ---- | M] () -- D:\WINDOWS\tasks\AdobeAAMUpdater-1.0-ALA-M78O6V57Z54-Alicja.job
:Files
D:\Documents and Settings\All Users\Dane aplikacji\pzwbqqxuflkflpi
D:\Documents and Settings\All Users\Dane aplikacji\levfpoinztqgzfz
D:\Documents and Settings\All Users\Dane aplikacji\mhakxlzpnufeqsa
D:\Documents and Settings\All Users\Dane aplikacji\eujmaxgqhktzkwp
D:\Documents and Settings\All Users\Dane aplikacji\erlfdhkn.exe
D:\Documents and Settings\Alicja\0.8420682035441753.exe
D:\WINDOWS\tasks\At4.job
D:\WINDOWS\tasks\At3.job
D:\WINDOWS\tasks\At2.job
D:\WINDOWS\tasks\At1.job
D:\WINDOWS\vsnpstd.exe
:Commands
[emptytemp]
!!!Windows XP Professional Edition Dodatek Service Pack 2 -> http://www.microsoft.com/pl-pl/download/details.aspx?id=24
Java(TM) 6 Update 31 -> http://www.oracle.com/technetwork/java/javase/downloads/index.html
Adobe Flash Player 10 ActiveX -> http://get.adobe.com/pl/flashplayer/
Skype™ 5.3 -> http://www.skype.com/intl/pl/home/
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 24 gości