blekko search bar
VShareToolBar
:OTL
O4 - HKU\S-1-5-21-4051395316-4194294487-934062712-1003..\RunOnce: [036DFF610007E156025DF9266C44B161] C:\ProgramData\036DFF610007E156025DF9266C44B161\036DFF610007E156025DF9266C44B161.exe ()
O7 - HKU\S-1-5-21-4051395316-4194294487-934062712-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Apple Inc. = C:\Users\Anna\AppData\Roaming\693181.exe
:Files
C:\Users\Anna\AppData\Roaming\xvayiqjitfdzmpmdtaswgkrnwzo2veog2
C:\Users\Anna\AppData\Local\{4052b4de-2d6b-945b-3ab0-996fc3a7a328}
C:\Windows\Installer\{4052b4de-2d6b-945b-3ab0-996fc3a7a328}
:Commands
[emptytemp]
:reg
HKEY_CURRENT_USER\Software\Classes\CLSID\{4052b4de-2d6b-945b-3ab0-996fc3a7a328} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4052b4de-2d6b-945b-3ab0-996fc3a7a328} /s
:filefind
services.exe
:OTL
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=2&src=sp&cf=2164e460-479c-11e1-87f9-0013776f0d56&q="
O3 - HKU\S-1-5-21-4051395316-4194294487-934062712-1003\..\Toolbar\WebBrowser: (no name) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No CLSID value found.
IE - HKU\S-1-5-21-4051395316-4194294487-934062712-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=21 ... 76f0d56&q={searchTerms}
IE - HKU\S-1-5-21-4051395316-4194294487-934062712-1003\..\SearchScopes\{1F410A06-A8CF-4B27-AFFC-54FDEF8A00E0}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=21 ... 76f0d56&q={searchTerms}
IE - HKU\S-1-5-21-4051395316-4194294487-934062712-1003\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws/?source=c3348dd4&t ... 6ACB4A1&q={searchTerms}
IE - HKU\S-1-5-21-4051395316-4194294487-934062712-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://blekko.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=2164e460- ... 13776f0d56
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=21 ... 76f0d56&q={searchTerms}
:Files
C:\ProgramData\036DFF610007E156025DF9266C44B161
C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum
:Commands
[emptytemp]
(UAC is disabled!)
:OTL
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=2&src=sp&cf=2164e460-479c-11e1-87f9-0013776f0d56&q="
:Files
C:\Users\Anna\Desktop\Live Security Platinum.lnk
:Commands
[emptytemp]
picasso http://www.fixitpc.pl/topic/6855-rekons ... u-windows/ napisał(a):1. Pobierz narzędzie SetACL. Z folderu "Command line version" wypakuj wersję SetACL.exe dopasowaną do systemu (x86 = 32-bit, x64 = 64-bit) i umieść w katalogu C:\Windows.
Zidentyfikowani użytkownicy: 1q2w3e4r, Acorus, Bilauta, Bing [Bot], blooom, chrucik, eddie71, Fajrant166, floyd, garbar89, Goga#, Google [Bot], Google Adsense [Bot], hasdrabul_skaras, jangiz, jerzytom, kalindor7, kijek, Lara2013, Majestic-12 [Bot], manieKMP, mati19957, Miszkurka2000, MSN [Bot], plitom, Razi, silvver, siodlo111, SnykeShadow, srrs, Veers, wampiros6, XMan