[2012/12/12 17:46:06 | 000,352,276 | ---- | M] () -- C:\Users\Anwender\Desktop\POPR. aktualne.block
Hm, w logu widzę tylko 1 plik z dopiskiem BLOCK,
Nie widzę też żadnej infekcji.
Kosmetyka:
Uruchom
OTL i w oknie
Własne opcje skanowania/Skrypt wklej to:
:OTL
[2012/12/13 01:32:20 | 000,000,000 | ---D | M] -- C:\Users\Anwender\AppData\Roaming\Yfjey
[2012/08/24 15:21:02 | 000,000,000 | -HSD | M] -- C:\Users\Anwender\AppData\Roaming\.#
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_DE Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851647&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "uTorrentBar_DE Customized Web Search"
IE - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647
IE - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=UT2V5&o=15158&src=crm&q={searchTerms}&locale=de_US&apn_ptnrs=UG&apn_dtid=YYYYYYYYPL&apn_uid=5B4DDFED-A66E-4590-B93B-B21E5EEECA32&apn_sauid=FACCFDDB-798E-46D1-B5A1-E008D24D2AD3
IE - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No CLSID value found
IE - HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2851647
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
:Files
C:\Users\Anwender\AppData\Local\Temp*.html
C:\found.00*
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
Kliknij w
Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.