
Bede wdzieczny za pomoc.
Pozdrawiam.
screen z pop-up na internet explorer o dziwo strona chodzi swietnie

Uploaded with ImageShack.us
Extras
http://wklej.org/id/690209/
OTL
http://wklej.org/id/690212/
Gmer
http://wklej.org/id/690215/
:OTL
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.4.0024
FF - prefs.js..extensions.enabledItems: m3ffxtbr@mywebsearch.com:1.1
[2011-02-21 18:12:56 | 000,002,059 | ---- | M] () -- C:\Users\kasieczka\AppData\Roaming\Mozilla\Firefox\Profiles\69inuvu3.default\searchplugins\daemon-search.xml
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKU\S-1-5-21-1258016191-82154845-3909291589-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1258016191-82154845-3909291589-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [AirCardEnabler] File not found
O4 - HKU\S-1-5-21-1258016191-82154845-3909291589-1000..\Run: [{F3FFD16B-EAA2-768C-33C4-C63FF098256F}] C:\Users\kasieczka\AppData\Roaming\Guma\tytuud.exe (Mach5 Software)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm File not found
[2010-12-06 22:56:59 | 000,040,411 | ---- | C] () -- C:\Users\kasieczka\AppData\Roaming\fb.exe
[2010-12-06 22:56:59 | 000,038,704 | ---- | C] () -- C:\Users\kasieczka\AppData\Roaming\Done.exe
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:DCAF903C
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:BB24555F
@Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:B203B914
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:4F636E25
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:3064D21D
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:CDFF58FE
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:131C0EE9
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:E1982A23
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:ABE89FFE
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:B623B5B8
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:798A3728
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:CE0A077E
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:E5F85065
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:41099CE9
:Files
C:\Users\kasieczka\AppData\Local\Temp*.html
C:\Windows\tasks\*.job
C:\Users\kasieczka\AppData\Roaming\wklnhst.dat
:Commands
[emptytemp]
[emptyflash]
19:52:08.0803 2368 giveio ( UnsignedFile.Multi.Generic ) - skipped by user
19:52:08.0803 2368 giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:52:08.0811 2368 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - skipped by user
19:52:08.0811 2368 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Skip
19:52:08.0819 2368 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
19:52:08.0819 2368 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 19 gości