
Tutaj zamieszczam wyniki skanowania z OTL:
:OTL
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={0CA66133-4C13-47E7-B503-904CEC672BB7}
IE - HKU\.DEFAULT\..\SearchScopes\{33524C00-63FB-43DB-A6BF-0A4E14B24649}: "URL" = http://www.basicscan.com/?prt=BASICSCAN115&keywords={searchTerms}
IE - HKU\S-1-5-18\..\SearchScopes\{33524C00-63FB-43DB-A6BF-0A4E14B24649}: "URL" = http://www.basicscan.com/?prt=BASICSCAN115&keywords={searchTerms}
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2830765
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\InprocServer32 File not found
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\URLSearchHook: {0b1be383-efa8-44d5-a7c2-9a39594575a1} - No CLSID value found
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\URLSearchHook: {8c5878d0-6106-423b-aaa8-144c143dbf44} - C:\Program Files\Bitlord_1.2\prxtbBit2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&tt=050412_30b&babsrc=SP_ss&mntrId=3c7b7a8c000000000000001d7dd478d2
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{115B1B5A-84AF-490A-9161-265BD3FEBE6E}: "URL" = http://websearch.ask.com/redirect?clien ... &src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=C0B186BA-C550-48B9-A9E4-E72636F58E07&apn_sauid=0A8F44DD-7B6B-49C7-81DD-AC4A82590F9D
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{33524C00-63FB-43DB-A6BF-0A4E14B24649}: "URL" = http://www.basicscan.com/?prt=BscscnPB&keywords={searchTerms}
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/?source=c3348dd4&tbp= ... BB46BB0&q={searchTerms}
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcB&keywords={searchTerms}
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{7A195E29-4517-4D8D-AF40-8FA55C253631}: "URL" = http://search.softonic.com/MON00084/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=705
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{BA49E597-4345-4037-8FC3-90182B045C79}: "URL" = http://searchya.com/?chnl=ft-100&s=1&cr ... DtAtBtD&q={searchTerms}
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{E2C1ABF4-462D-4444-950D-124EB4C4B2D2}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={0CA66133-4C13-47E7-B503-904CEC672BB7}
IE - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\SearchScopes\{F3FE0A1F-6777-4281-B5D1-D6C33F8106A4}: "URL" = http://mp3tubetoolbar.com/?tmp=toolbar_ ... &Keywords={searchTerms}&clid=54284d23d17f44938a796553e7e71a69
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "http://searchya.com"
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.1.9
FF - prefs.js..extensions.enabledAddons: ffxtlbr@searchya.com:1.5.0
FF - prefs.js..extensions.enabledAddons: m3ffxtbr@mywebsearch.com:1.3
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCYYYYYYYYPL&ptnrS=ZCYYYYYYYYPL&ptb=8eKvHLtNwjUbi0SAfVkW4g&ind=2012071705&n=77edc719&psa=&st=kwd&searchfor="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://searchya.com"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://www.basicscan.com/?tmp=nemo_results_removelink&prt=BscscnPB&keywords="
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll (MyWebSearch.com)
[2012-02-04 20:39:57 | 000,000,000 | ---D | M] (Spam Free Search Bar) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\{00f12770-e60e-4dc6-9105-425bface7c73}
[2012-08-27 09:55:34 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012-03-20 15:43:35 | 000,000,000 | ---D | M] (DealPly) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012-05-18 13:27:37 | 000,000,000 | ---D | M] (TheBflix) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\4fb5b0aad0ad6@4fb5b0aad0b0f.info
[2012-04-16 20:24:31 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\ffxtlbr@babylon.com
[2012-03-20 15:43:33 | 000,000,000 | ---D | M] (searchya.com) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\ffxtlbr@searchya.com
[2012-07-17 11:07:07 | 000,000,000 | ---D | M] (My Web Search) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\m3ffxtbr@mywebsearch.com
[2012-07-22 08:36:53 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Dawidos\AppData\Roaming\mozilla\Firefox\Profiles\a0nz5abl.default\extensions\toolbar@ask.com
[2012-07-22 08:36:53 | 000,002,299 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\mozilla\firefox\profiles\a0nz5abl.default\searchplugins\askcom.xml
[2012-04-05 08:32:42 | 000,000,939 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\mozilla\firefox\profiles\a0nz5abl.default\searchplugins\conduit.xml
[2012-07-17 14:44:38 | 000,009,897 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\mozilla\firefox\profiles\a0nz5abl.default\searchplugins\mywebsearch.xml
[2012-03-20 13:55:59 | 000,001,496 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\mozilla\firefox\profiles\a0nz5abl.default\searchplugins\searchya.xml
[2012-06-26 21:10:17 | 000,002,060 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\mozilla\firefox\profiles\a0nz5abl.default\searchplugins\softonic.xml
[2012-07-17 14:44:54 | 000,004,089 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\mozilla\firefox\profiles\a0nz5abl.default\searchplugins\sweetim.xml
[2012-09-07 15:55:36 | 000,000,000 | ---D | M] (MP3Tube Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com
[2012-02-04 20:39:58 | 000,002,127 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\blekkotb.xml
[2012-09-21 15:08:48 | 000,001,211 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Mp3Tube.xml
[2012-03-15 15:04:59 | 000,002,415 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
CHR - Extension: DealPly = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.0.7.2_0\
CHR - Extension: TheBflix = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgahmohjcabchobmmbfnpmealjkgnacp\5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: DealPly = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.0.7.2_0\
CHR - Extension: TheBflix = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgahmohjcabchobmmbfnpmealjkgnacp\5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Dawidos\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
O3 - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\Toolbar\WebBrowser: (no name) - {0B1BE383-EFA8-44D5-A7C2-9A39594575A1} - No CLSID value found.
O3 - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\Toolbar\WebBrowser: (Mp3Tube Toolbar) - {46897C77-E7A6-4C33-BFFB-E9C2E2718942} - "C:\Program Files\Mp3Tube Toolbar\mp3tubetb.DLL" File not found
O4 - HKLM..\Run: [] File not found
O20 - HKU\S-1-5-21-1666787875-368454409-2231153585-1000 Winlogon: Shell - (C:\Users\Dawidos\AppData\Roaming\msconfig.dat) - C:\Users\Dawidos\AppData\Roaming\msconfig.dat ()
[2012-06-22 22:21:40 | 001,501,457 | ---- | C] (run32dll) -- C:\Users\Dawidos\AppData\Roaming\time.exe
[2012-09-14 14:51:49 | 000,000,380 | -H-- | M] () -- C:\Windows\tasks\TheBflixUpdaterLogonTask.job
[2012-09-13 22:09:16 | 000,000,360 | -H-- | M] () -- C:\Windows\tasks\TheBflixUpdaterRefreshTask.job
[2011-12-05 08:36:25 | 000,061,440 | RHS- | C] () -- C:\Users\Dawidos\homep.exe
[2009-07-14 02:20:27 | 000,010,752 | -HS- | C] () -- C:\Users\Dawidos\AppData\Roaming\484CB8.exe
:Files
C:\Users\Dawidos\AppData\Roaming\*.exe
C:\Users\Dawidos\AppData\Roaming\Qoda
C:\Users\Dawidos\AppData\Roaming\Penu
C:\Users\Dawidos\AppData\Roaming\Kaicq
C:\Users\Dawidos\AppData\Roaming\ijjigame
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
:OTL
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\zzcuhjjt.sys -- (zzcuhjjt)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (azafu2xf)
O3 - HKU\S-1-5-21-1666787875-368454409-2231153585-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
[2012-09-21 16:31:37 | 000,000,045 | ---- | M] () -- C:\Users\Dawidos\AppData\Roaming\msconfig.ini
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 20 gości