
:OTL
O4 - Startup: C:\Documents and Settings\SK\Menu Start\Programy\Autostart\ctfmon.lnk = C:\Documents and Settings\All Users\Dane aplikacji\lsass.exe (Microsoft Corporation)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=e0517e27-4452-11e1-93c3-0018de5bf60e
IE - HKLM\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=e0517e27-4452-11e1-93c3-0018de5bf60e&q={searchTerms}
IE - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=e0517e27-4452-11e1-93c3-0018de5bf60e
IE - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
IE - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=e0517e27-4452-11e1-93c3-0018de5bf60e&q={searchTerms}
IE - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=STC-US&o=1716&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^AAO&apn_dtid=^YYYYYY^YY^PL&apn_uid=F8440C6C-6192-4CB6-8C74-08C275D29A8F&apn_sauid=80B55764-8C4E-4A8E-93CC-262B6AE82E39&
IE - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\SearchScopes\{75AC11C6-CE50-4454-93A6-570D34D91702}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=100478&babsrc=SP_ss&mntrId=28c3b7b00000000000000018de5bf60e
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=1&cf=e0517e27-4452-11e1-93c3-0018de5bf60e"
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=e0517e27-4452-11e1-93c3-0018de5bf60e&q="
[2012-01-21 18:11:39 | 000,000,000 | ---D | M] (VshareComplete - Speed up your search with your personal search suggestions tool) -- C:\Documents and Settings\SK\Dane aplikacji\Mozilla\Firefox\Profiles\6sujlvny.default\extensions\{4ac04d99-3f4b-4ec5-bd2d-216d59822f8a}
[2010-10-03 16:22:01 | 000,000,000 | ---D | M] (vShare Plugin) -- C:\Documents and Settings\SK\Dane aplikacji\Mozilla\Firefox\Profiles\6sujlvny.default\extensions\vshare@toolbar
[2011-12-03 16:42:34 | 000,002,578 | ---- | M] () -- C:\Documents and Settings\SK\Dane aplikacji\Mozilla\Firefox\Profiles\6sujlvny.default\searchplugins\askcom.xml
[2012-01-21 18:11:25 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\SK\Dane aplikacji\Mozilla\Firefox\Profiles\6sujlvny.default\searchplugins\startsear.xml
[2011-10-03 10:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011-12-14 17:26:17 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (VshareComplete) - {222f31fb-a14e-4af2-bb14-997f28294370} - C:\Documents and Settings\SK\Dane aplikacji\VshareComplete\VshareComplete.dll (SimplyGen)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\StartSearch plugin\BarLcher.dll (VShare Inc.)
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\StartSearch plugin\BarLcher.dll (VShare Inc.)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\StartSearch plugin\BarLcher.dll (VShare Inc.)
O4 - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006..\Run: [dhfh22] C:\DOCUME~1\STEFAN~1\USTAWI~1\Temp\sample.exe File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
:Files
C:\Documents and Settings\SK\Menu Start\Programy\Autostart\ctfmon.lnk
C:\Documents and Settings\All Users\Dane aplikacji\lsass.exe
C:\Documents and Settings\All Users\Dane aplikacji\0tbpw.pad
C:\Documents and Settings\SK\Dane aplikacji\3.exe
C:\Documents and Settings\SK\Dane aplikacji\2.exe
C:\Documents and Settings\SK\Dane aplikacji\1.exe
C:\Documents and Settings\SK\Dane aplikacji\Oenonc.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
:OTL
[2012-11-24 17:45:37 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\0tbpw.pad
O4 - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006..\Run: [dhfh22] C:\Documents and Settings\SK\Ustawienia lokalne\Temp\sample.exe ()
[2012-11-24 17:42:27 | 000,255,776 | ---- | M] () -- C:\Documents and Settings\SK\Dane aplikacji\1.exe
[2012-11-24 17:03:00 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDRm.sys -- (InCDRm)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDPass.sys -- (InCDPass)
DRV - File not found [File_System | Disabled | Stopped] -- system32\drivers\InCDFs.sys -- (InCDFs)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
O3 - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
[2012-11-26 13:40:55 | 000,255,776 | ---- | M] () -- C:\Documents and Settings\SK\Dane aplikacji\4.exe
[2012-11-26 13:40:51 | 000,255,776 | ---- | M] () -- C:\Documents and Settings\SK\Dane aplikacji\3.exe
[2012-11-26 13:40:45 | 000,255,776 | ---- | M] () -- C:\Documents and Settings\SK\Dane aplikacji\2.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
Files to delete:
C:\Documents and Settings\SK\Dane aplikacji\3.exe
C:\Documents and Settings\SK\Dane aplikacji\2.exe
C:\Documents and Settings\SK\Dane aplikacji\1.exe
C:\Documents and Settings\SK\Dane aplikacji\4.exe
:filefind
3.exe
2.exe
1.exe
sample.exe
sample.jpg
sample.*
:file
C:\Documents and Settings\SK\Dane aplikacji\3.exe
C:\Documents and Settings\SK\Dane aplikacji\2.exe
C:\Documents and Settings\SK\Dane aplikacji\1.exe
C:\Documents and Settings\SK\Ustawienia lokalne\Temp\sample.exe
:regfind
1.exe
2.exe
3.exe
4.exe
sample.exe
C:\Documents and Settings\SK\Dane aplikacji\3.exe
C:\Documents and Settings\SK\Dane aplikacji\2.exe
C:\Documents and Settings\SK\Dane aplikacji\1.exe
C:\Documents and Settings\SK\Ustawienia lokalne\Temp\sample.exe
C:\Documents and Settings\SK\Dane aplikacji\4.exe
Files to delete:
C:\Documents and Settings\SK\Dane aplikacji\6.exe
C:\Documents and Settings\SK\Dane aplikacji\5.exe
Windows Registry Editor Version 5.00
[HKEY_USERS\S-1-5-21-3043955707-3700624690-1729636746-1006\software\microsoft\windows\currentversion\policies\explorer\Run]
"dhfh22"=-
Files to delete:
C:\Documents and Settings\SK\Ustawienia lokalne\Temp\sample.exe
C:\Documents and Settings\SK\Dane aplikacji\3.exe
C:\Documents and Settings\SK\Dane aplikacji\2.exe
C:\Documents and Settings\SK\Dane aplikacji\1.exe
C:\Documents and Settings\SK\Dane aplikacji\4.exe
C:\Documents and Settings\SK\Dane aplikacji\5.exe
C:\Documents and Settings\SK\Dane aplikacji\6.exe
:OTL
O4 - HKU\S-1-5-21-3043955707-3700624690-1729636746-1006..\Run: [dhfh22] C:\DOCUME~1\STEFAN~1\USTAWI~1\Temp\sample.exe File not found
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 17 gości