
Oto logi: http://wklej.org/id/541142/
http://wklej.org/id/541144/
:OTL
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3450475010-2691413337-1342543737-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://vshare.toolbarhome.com/?hp=df
IE - HKU\S-1-5-21-3450475010-2691413337-1342543737-1000\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll (Conduit Ltd.)
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
[2011-03-31 16:51:57 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Grzin\AppData\Roaming\mozilla\Firefox\Profiles\ai9z392z.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011-03-31 16:51:56 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Grzin\AppData\Roaming\mozilla\Firefox\Profiles\ai9z392z.default\extensions\engine@conduit.com
[2011-04-05 20:53:02 | 000,000,000 | ---D | M] (vShare) -- C:\Users\Grzin\AppData\Roaming\mozilla\Firefox\Profiles\ai9z392z.default\extensions\vshare@toolbar
[2011-03-19 19:59:42 | 000,000,863 | ---- | M] () -- C:\Users\Grzin\AppData\Roaming\Mozilla\Firefox\Profiles\ai9z392z.default\searchplugins\conduit.xml
[2011-04-05 20:53:08 | 000,001,583 | ---- | M] () -- C:\Users\Grzin\AppData\Roaming\Mozilla\Firefox\Profiles\ai9z392z.default\searchplugins\web-search.xml
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
:Files
C:\Users\Grzin\AppData\Local\Temp*.html
:Commands
[emptytemp]
[emptyflash]
C:\Windows\SysWow64\slmgr.vbs
C:\Windows\SysWow64\winver.exe
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 7 gości