
GMER
http://wklej.org/id/579735/
OTL
http://wklej.org/id/579745/
EXTRAS
http://wklej.org/id/579748/
ANTI-MALWARE
http://wklej.org/id/579754/
:OTL
SRV - File not found [Auto | Stopped] -- -- (NIHardwareService)
IE - HKU\S-1-5-21-2044775212-447502082-407128720-1000\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.5\pdfforgeToolbarIE.dll (Spigot, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-2044775212-447502082-407128720-1000..\Run: [TOSCDSPD] File not found
[2011-08-20 12:35:00 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-08-20 12:05:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2044775212-447502082-407128720-1000UA.job
[2011-08-20 11:45:13 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-08-19 23:37:25 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{2CEE0712-9E32-47EF-A2A7-30CF7F427623}.job
[2011-08-19 23:05:00 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2044775212-447502082-407128720-1000Core.job
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:0B4227B4
:Files
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Windows\lsb_un20.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"00TCrdMain"=-
"Google EULA Launcher"=-
"NeroFilterCheck"=-
"RtHDVCpl"=-
"SearchSettings"=-
"SmoothView"=-
"topi"=-
"Toshiba Registration"=-
[HKEY_USER\S-1-5-21-2044775212-447502082-407128720-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
:Processes
killallprocesses
:OTL
SRV - [2011-06-24 17:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKU\S-1-5-21-2044775212-447502082-407128720-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKU\S-1-5-21-2044775212-447502082-407128720-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=616163"
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
:Files
C:\Program Files\Application Updater
:Commands
[clearallrestorepoints]
[emptytemp]
:OTL
:Reg
[HKEY_USERS\S-1-5-21-2044775212-447502082-407128720-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 17 gości