
GMER:
http://www.wklej.org/id/525686/
OTL:
http://www.wklej.org/id/525688/
http://www.wklej.org/id/525690/
:OTL
SRV - [2008-12-09 18:40:16 | 000,464,264 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBarDis\bar\bin\AskService.exe -- (ASKService)
SRV - [2008-12-09 18:40:16 | 000,234,888 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)
FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://www.daemon-search.com/startpage"
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query="
[2010-04-07 16:59:57 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Documents and Settings\Tomek\Dane aplikacji\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010-07-28 23:56:37 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Tomek\Dane aplikacji\Mozilla\Firefox\Profiles\lcnjs668.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010-11-29 21:56:36 | 000,000,000 | ---D | M] (vShare) -- C:\Documents and Settings\Tomek\Dane aplikacji\Mozilla\Firefox\Profiles\lcnjs668.default\extensions\vshare@toolbar
[2010-09-12 17:39:45 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\Tomek\Dane aplikacji\Mozilla\Firefox\Profiles\lcnjs668.default\searchplugins\daemon-search.xml
[2010-07-30 18:49:22 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Tomek\Dane aplikacji\Mozilla\Firefox\Profiles\lcnjs668.default\searchplugins\winamp-search.xml
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKCU..\Run: [SpybotSD TeaTimer] File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\{24d106c6-73d4-11df-84dc-96dbaee7f4d1}\Shell\AUtoplay\commANd - "" = G:\vxhdj.exe
O33 - MountPoints2\{24d106c6-73d4-11df-84dc-96dbaee7f4d1}\Shell\AutoRun\command - "" = G:\vxhdj.exe
O33 - MountPoints2\{24d106c6-73d4-11df-84dc-96dbaee7f4d1}\Shell\expLOrE\ComManD - "" = G:\vxhdj.exe
O33 - MountPoints2\{24d106c6-73d4-11df-84dc-96dbaee7f4d1}\Shell\open\COMmANd - "" = G:\vxhdj.exe
O33 - MountPoints2\{a3699927-6e53-11e0-88fa-00ff01000001}\Shell\AutoRun\command - "" = G:\urDrive.exe
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:0B4227B4
:Files
C:\Program Files\AskBarDis
C:\Program Files\Common Files\Akamai
C:\WINDOWS\tasks\*.job
C:\Documents and Settings\Tomek\Ustawienia lokalne\Dane aplikacji\1y6p453646exnf5s31f73u2i843
C:\Documents and Settings\All Users\Dane aplikacji\1y6p453646exnf5s31f73u2i843
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1143:TCP"=-
"5000:UDP"=-
:Commands
[emptytemp]
[emptyflash]
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
:Files
C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG10\avgmfapx.exe"=-
"C:\Program Files\AVG\AVG10\avgemcx.exe"=-
"C:\Program Files\AVG\AVG10\avgdiagex.exe"=-
"C:\Program Files\AVG\AVG10\avgnsx.exe"=-
:Commands
[emptytemp]
[emptyflash]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 15 gości