01 Gru 2010, 21:49
01 Gru 2010, 21:52
01 Gru 2010, 22:46
01 Gru 2010, 23:00
Poza tym po restarcie , zanim wykonałem logi , wywaliłem z procesów w menedżerze TMonitor.
01 Gru 2010, 23:08
01 Gru 2010, 23:16
01 Gru 2010, 23:38
PRC - [2010-10-04 11:35:40 | 000,071,680 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\TMonitor.exe
w oknie Własne opcje skanowania/skrypt wklej::OTL
SRV - [2010-12-01 14:42:13 | 003,020,376 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_5632d69.dll -- (Akamai)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\usbVM303.sys -- (ZSMC303)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\UltraStar Deluxe\zlportio.sys -- (zlportio)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\vmfilter303.sys -- (vmfilter303)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\SBREdrv.sys -- (SBRE)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PCAMPR5.SYS -- (PCAMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
IE - HKU\S-1-5-21-527237240-308236825-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = kino-on-line.my1.ru
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.1.313
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2.0185
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=937811&p="
[2010-09-26 12:25:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\My\Dane aplikacji\Mozilla\Firefox\Profiles\ajzo4gww.default\extensions\[email protected]
[2010-05-16 09:27:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\My\Dane aplikacji\Mozilla\Firefox\Profiles\ajzo4gww.default\extensions\[email protected]
[2010-09-26 12:25:12 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\My\Dane aplikacji\Mozilla\Firefox\Profiles\ajzo4gww.default\searchplugins\daemon-search.xml
[2009-09-21 11:24:16 | 000,001,329 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
C:\WINDOWS\tasks\*.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=-
"NeroFilterCheck"=-
"SecurDisc"=-
"InCD"=-
"NvCplDaemon"=-
"nwiz"=-
"SearchSettings"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
"Google Update"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Nowe Gadu-Gadu\gg.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"=-
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"=-
"D:\Program Files\ITTerritory\DragonsPl\DwarClientPl.exe"=-
"C:\Program Files\NMG\The Aztec\Aztec.exe"=-
"D:\Worms 4\Worms 4.exe"=-
"D:\Age\age2_x1\age2_x1.exe"=-
"D:\Age\empires2.exe"=-
"D:\Program Files\TmNationsForever\TmForever.exe"=-
"D:\Program Files\SopCast\adv\SopAdver.exe"=-
"D:\Prometheus\Binaries\Win32\UDK.exe"=-
"C:\Program Files\FlashGet\flashget.exe"=-
"C:\Program Files\Tremulous\tremulous.exe"=-
"D:\Program Files\TrackMania Sunrise\TmSunrise.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Kontrolery IDE ATA/ATAPI
Podstawowy kanał IDE
Ustawienia zaawansowane
Sprawdź, jak jest ustawiony Bieżący tryb transferu01 Gru 2010, 23:41
01 Gru 2010, 23:44
02 Gru 2010, 00:50
02 Gru 2010, 14:23
:OTL
FF - HKLM\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKU\S-1-5-21-527237240-308236825-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-527237240-308236825-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKU\S-1-5-21-527237240-308236825-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No CLSID value found.
O3 - HKU\S-1-5-21-527237240-308236825-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {CB789373-04D5-4EF4-9C16-871463FD0830} - No CLSID value found.
O3 - HKU\S-1-5-21-527237240-308236825-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-527237240-308236825-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
[2010-12-01 23:37:20 | 000,000,972 | ---- | C] () -- C:\WINDOWS\tasks\Google Software Updater.job
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"8461:TCP"=-
"8462:TCP"=-
"1036:TCP"=-
"5000:UDP"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Haemimont Games\Rising Kingdoms\RK.exe"=-
"C:\Program Files\Games\Q.U.B.E. v1.2\Binaries\Win32\UDK.exe"=-
InstrukcjaJava(TM) 6 Update 17
Java 2 Runtime Environment, SE v1.4.0_03
http://www.instalki.pl/programy/downloa ... %29_6.htmlAdobe Reader 7.0 - Polish
http://www.instalki.pl/programy/downloa ... der_X.html
02 Gru 2010, 16:04
02 Gru 2010, 18:36
Typ skanowania: Szybkie skanowanie
02 Gru 2010, 21:43
02 Gru 2010, 21:47