03 Lis 2010, 14:56
03 Lis 2010, 16:41
:OTL
SRV - File not found [Auto | Stopped] -- C:\Windows\System32\appdrvrem01.exe -- (appdrvrem01) Application Driver Auto Removal Service (01)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eis.esnips.com/page/search/?clie ... fde8d1391d
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.startup.homepage: "http://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d"
FF - prefs.js..browser.search.defaultenginename: "eSnips Search"
FF - prefs.js..browser.search.order.1: "eSnips Search"
FF - prefs.js..browser.search.selectedEngine: "eSnips Search"
FF - prefs.js..keyword.URL: "http://eis.esnips.com/page/search_provider/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d&q="
[2010-04-27 10:02:51 | 000,000,000 | ---D | M] (WeFi Toolbar) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\gqqvamoz.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}
[2010-09-04 09:13:59 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\gqqvamoz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009-01-01 14:22:49 | 000,024,683 | ---- | M] (Ask.com) -- C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
O4 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000..\Run: [3FWHZQA3LT] C:\Users\1\AppData\Local\Temp\Cgd.exe File not found
O4 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000..\Run: [Automatic Networking Tether] C:\Users\1\AppData\Roaming\ant0.exe ()
O4 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000..\Run: [Metropolis] C:\Users\1\AppData\Local\Temp\sshnas21.DLL File not found
O4 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe File not found
O4 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000..\Run: [UniblueRegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe File not found
O37 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000\...com [@ = ComFile] -- Reg Error: Key error. File not found
O37 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000\...exe [@ = exefile] -- Reg Error: Key error. File not found
:Files
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore1ca5bd39f2946f0.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"=-
"IndexSearch"=-
"ISUSScheduler"=-
"NeroFilterCheck"=-
"RtHDVCpl"=-
"SearchSettings"=-
"SSBkgdUpdate"=-
"StartCCC"=-
"WinampAgent"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=-
"swg"=-
:Commands
[clearallrestorepoints]
[emptytemp]
03 Lis 2010, 21:17
03 Lis 2010, 21:18
04 Lis 2010, 14:28
04 Lis 2010, 14:45
:OTL
PRC - [2010-05-18 19:22:02 | 000,039,424 | ---- | M] (Microsoft) -- C:\Users\1\AppData\Local\Gforce Drivers\GForce_Driver.exe
PRC - [2010-05-17 10:49:32 | 000,038,912 | RHS- | M] (Microsoft) -- C:\Users\1\AppData\Local\Intel\motherboard_driver_install.exe
PRC - [2010-05-16 22:49:02 | 000,038,912 | ---- | M] (Microsoft) -- C:\Users\1\AppData\Local\AMD\intel pro.exe
O2 - BHO: (no name) - {3303e956-2a3a-48e0-be39-2e0ef11a2f44} - No CLSID value found.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eis.esnips.com/page/search/?clie ... fde8d1391d
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [Gforce Drivers] C:\Users\1\AppData\Local\Gforce Drivers\GForce_Driver.exe (Microsoft)
O4 - HKLM..\Run: [Intel Pro Motherboard] C:\Users\1\AppData\Local\Intel\motherboard_driver_install.exe (Microsoft)
O4 - HKCU..\Run: [Gforce Drivers] C:\Users\1\AppData\Local\Gforce Drivers\GForce_Driver.exe (Microsoft)
O4 - HKCU..\Run: [Intel Pro Motherboard] C:\Users\1\AppData\Local\Intel\motherboard_driver_install.exe (Microsoft)
O4 - HKCU..\Run: [Intel Pro Wireless] C:\Users\1\AppData\Local\AMD\intel pro.exe (Microsoft)
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe File not found
DRV - [2010-01-18 17:00:56 | 000,029,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RKHit.sys -- (RkHit)
@Alternate Data Stream - 24 bytesC:\Windows:F9CEFF2263F5C0DF
:Commands
[clearallrestorepoints]
[reboot]
04 Lis 2010, 22:24
04 Lis 2010, 22:36
:OTL
O3 - HKU\S-1-5-21-3337699514-1478966208-3422552759-1000\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-8287-79A187E26987} - No CLSID value found.
O4 - HKLM..\Run: [Intel Pro Wireless] C:\Users\1\AppData\Local\AMD\intel pro.exe File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
05 Lis 2010, 17:03
05 Lis 2010, 19:21
05 Lis 2010, 19:26