
Czy to wirus?
Oto logi
Gmer
http://wklej.org/id/438218/
OTL
http://wklej.org/id/438224/
Extras
http://wklej.org/id/438227/
C:\Documents and Settings\Przemek.MAKROFAG\Moje dokumenty\?? ???) -- C:\Documents and Settings\Przemek.MAKROFAG\Moje dokumenty\넥슨 플러그
C:\Documents and Settings\Przemek.MAKROFAG\Moje dokumenty\?? ???) -- C:\Documents and Settings\Przemek.MAKROFAG\Moje dokumenty\넥슨 플러그
:OTL
IE - HKU\S-1-5-21-329068152-1677128483-839522115-1003\..\URLSearchHook: {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-329068152-1677128483-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=14676
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Gamezilla Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://chameleontom.iamwired.net/search.php?src=tops&q="
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.2
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (P2P Torrent Toolbar) - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (P2P Torrent Toolbar) - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-329068152-1677128483-839522115-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-329068152-1677128483-839522115-1003\..\Toolbar\WebBrowser: (P2P Torrent Toolbar) - {BC4BE15D-6A34-4356-9E97-79E43DA32B1D} - C:\Program Files\P2P_Torrent\tbP2P_.dll (Conduit Ltd.)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O32 - AutoRun File - [2009-11-21 16:54:41 | 000,000,011 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-11-21 17:14:44 | 000,000,011 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
@Alternate Data Stream - 172 bytes -> C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP:0B4227B4
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP:A9662AE0
:Files
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\extensions\{73b7ae0f-b395-40b3-a39f-59913538ddb7}
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\extensions\{bc4be15d-6a34-4356-9e97-79e43da32b1d}
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\extensions\DTToolbar@toolbarnet.com
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\extensions\eafo3fflauncher@ea.comrzemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\searchplugins\conduit.xml
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\searchplugins\daemon-search.xml
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\searchplugins\Search.xml
C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
C:\Program Files\AVG\AVG10\Toolbar
C:\Program Files\DAEMON Tools Toolbar
C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\AVG Security Toolbar
C:\Documents and Settings\Przemek.MAKROFAG\Ustawienia lokalne\Dane aplikacji\AVG Security Toolbar
C:\WINDOWS\tasks\*.job
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
[resethosts]
[emptyflash]
[clearallrestorepoints]
:OTL
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
O3 - HKU\S-1-5-21-329068152-1677128483-839522115-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
:Files
C:\Documents and Settings\Przemek.MAKROFAG\Dane aplikacji\Mozilla\Firefox\Profiles\qf0g52wh.default\extensions\ffxtlbr@babylon.com
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 16 gości