26 Wrz 2012, 15:14
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"AVG Secure Search" = AVG Security Toolbar
Logi.
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=SAMSUNG_HD502HJ_S20BJ9BZA27932&ts=1348429478
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=SAMSUNG_HD502HJ_S20BJ9BZA27932&ts=1348429478
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/home?affID=112763&tt=120912_pcp_3812_7
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=SAMSUNG_HD502HJ_S20BJ9BZA27932&ts=1348429478
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={5D22154A-ECA0-43B7-827D-0468A2C258AF}&mid=fe0f99602f2947d0b1cdcd2623da4cdb-68cc4614dbe090db72cce0baf0b18639ee3168ac&lang=pl&ds=xn011&pr=sa&d=2012-09-07 20:35:38&v=12.2.0.5&sap=hp
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112763&tt=120912_pcp_3812_7&babsrc=SP_def&mntrId=6e4797a100000000000000ffcda01115
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={5D22154A-ECA0-43B7-827D-0468A2C258AF}&mid=fe0f99602f2947d0b1cdcd2623da4cdb-68cc4614dbe090db72cce0baf0b18639ee3168ac&lang=pl&ds=xn011&pr=sa&d=2012-09-07 20:35:38&v=12.2.0.5&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O4 - HKU\S-1-5-21-1267917107-777748536-2660093714-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
:Files
C:\Users\Jurek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\foobar2000 - Shortcut.lnk
C:\Windows\SysWow64\searchplugins
C:\Windows\SysWow64\Extensions
C:\Users\Jurek\AppData\Roaming\OpenCandy
C:\Users\Jurek\AppData\Local\AVG Secure Search
C:\ProgramData\AVG Secure Search
C:\Windows\SysNative\drivers\avgtpx64.sys
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\AVG Secure Search
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
01 Paź 2012, 20:22
01 Paź 2012, 21:47
Wykonywanie Skryptu.
02 Paź 2012, 00:05
02 Paź 2012, 20:57
Autoruns.
APSDaemon
iTunesHelper
NUSB3MON
ROC_roc_ssl_v12
SunJavaUpdateSched
Wszystko.
Wszystko.
Wszystko.
gusvc
Microsoft Office Groove
odserv
ose
WinDefend
WMPNetworkSvc
Wszystko.
Logi.
:OTL
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jurek\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jurek\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found
O4 - HKU\S-1-5-21-1267917107-777748536-2660093714-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\system32\StikyNot.exe File not found
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
:Files
C:\Users\Jurek\AppData\Local\Google\Update
C:\Users\Jurek\Desktop\Autoruns
C:\Users\Jurek\Desktop\tdsskiller.exe
C:\Windows\tasks\*.*
C:\Users\Jurek\Desktop\AutoRuns.arn
C:\Users\Jurek\Desktop\adwcleaner (1).exe
C:\Users\Jurek\Desktop\adwcleaner.exe
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
02 Paź 2012, 21:56
03 Paź 2012, 09:43
30 Mar 2014, 21:17
30 Mar 2014, 22:16
8.8.8.8
8.8.4.4
:OTL
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SupTab\SEARCH~2.DLL) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\SupTab\SEARCH~1.DLL) - File not found
[2014-03-25 11:41:18 | 000,000,000 | ---D | M] -- C:\Users\Jurek\AppData\Roaming\qone8
:Commands
[emptytemp]
31 Mar 2014, 19:39
31 Mar 2014, 21:18
68.168.98.196
02 Kwi 2014, 22:46
03 Kwi 2014, 14:30
03 Kwi 2014, 23:35
04 Kwi 2014, 21:45