
GMER:
http://wklej.org/id/501548/
OTL:
http://wklej.org/id/501514/
http://wklej.org/id/501520/
RSIT:
http://wklej.org/id/501518/
http://wklej.org/id/501519/
DDS:
http://wklej.org/id/501524/
http://wklej.org/id/501527/
??O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
:OTL
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
File not found (No name found) -- C:\USERS\MIROSłAWA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G564NDG5.DEFAULT\EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C}
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - File not found
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
DRV - [2009/05/16 03:15:14 | 000,214,024 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/05/16 03:15:14 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfeavfk.sys -- (MfeAVFK)
DRV - [2009/05/16 03:15:14 | 000,055,336 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2009/05/16 03:15:14 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (MfeBOPK)
DRV - [2009/05/16 03:15:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (MfeRKDK)
:Files
C:\Users\Mirosława\AppData\Roaming\mozilla\Firefox\Profiles\g564ndg5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
C:\Users\Mirosława\AppData\Roaming\Mozilla\Firefox\Profiles\g564ndg5.default\searchplugins\bing.xml
c:\Users\Mirosława\AppData\Local\Temp*.html
:Commands
[emptytemp]
[emptyflash]
:OTL
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O33 - MountPoints2\{6d46de06-08e6-11e0-b7b5-8e91b0c2192e}\Shell - "" = AutoRun
O33 - MountPoints2\{6d46de06-08e6-11e0-b7b5-8e91b0c2192e}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -a
O33 - MountPoints2\{9b5b2dec-effa-11de-a37f-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{9b5b2dec-effa-11de-a37f-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{9b5b2df3-effa-11de-a37f-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{9b5b2df3-effa-11de-a37f-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{9b5b2e4e-effa-11de-a37f-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{9b5b2e4e-effa-11de-a37f-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{9b5b2e51-effa-11de-a37f-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{9b5b2e51-effa-11de-a37f-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{9b5b2e55-effa-11de-a37f-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{9b5b2e55-effa-11de-a37f-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{c52ca017-f3c0-11de-98e3-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{c52ca017-f3c0-11de-98e3-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{eae93a8d-f08a-11de-9464-00247ed7e9b6}\Shell - "" = AutoRun
O33 - MountPoints2\{eae93a8d-f08a-11de-9464-00247ed7e9b6}\Shell\AutoRun\command - "" = D:\AutoRun.exe
:Files
C:\Users\Mirosława\Downloads\winlogon.exe
:Commands
[emptytemp]
[emptyflash]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 8 gości