UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
:OTL
[2010-05-28 18:45:36 | 000,002,059 | ---- | M] () -- C:\Users\Dom\AppData\Roaming\Mozilla\FireFox\Profiles\ynmtpigd.default\searchplugins\daemon-search.xml
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll File not found
O3 - HKU\S-1-5-21-44447241-2020705860-2327783831-1001\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll File not found
O4 - HKU\S-1-5-21-44447241-2020705860-2327783831-1001..\Run: [ISUSPM] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
:Files
C:\Users\Dom\AppData\Local\Temp*.html
C:\Windows\SysWow64\sknc.dll
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
Możesz mi powiedzieć skąd wiesz co należy usunąć z programu OTL i jak napisać ten własny skrypt?
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
:Processes
killallprocesses
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\wojtek\USTAWI~1\Temp\ALSysIO.sys -- (ALSysIO)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
IE - HKU\S-1-5-21-1177238915-1844823847-1417001333-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
FF - prefs.js..browser.search.defaultenginename: "BearShare Web Search"
FF - prefs.js..browser.search.order.1: "BearShare Web Search"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2.0185
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.21
FF - prefs.js..keyword.URL: "http://search.bearshare.com/webResults.html?src=ffb&q="
[2010-02-12 17:04:05 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\5xskxta0.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2010-05-31 21:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\5xskxta0.default\extensions\[email protected]
[2009-12-03 11:54:24 | 000,002,476 | ---- | M] () -- C:\Documents and Settings\wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\5xskxta0.default\searchplugins\BearShareWebSearch.xml
[2010-05-31 21:19:07 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\5xskxta0.default\searchplugins\daemon-search.xml
[2009-12-03 11:54:24 | 000,002,476 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe File not found
O33 - MountPoints2\{0ba58466-3d82-11df-8cee-0016e68aab13}\Shell\AutoRun\command - "" = F:\eer6ril9.exe -- File not found
O33 - MountPoints2\{0ba58466-3d82-11df-8cee-0016e68aab13}\Shell\open\Command - "" = F:\eer6ril9.exe -- File not found
O33 - MountPoints2\{3af6db36-27b9-11df-8ca2-0016e68aab13}\Shell - "" = AutoRun
O33 - MountPoints2\{8fea76fe-47a1-11df-8d1b-0016e68aab13}\Shell\AutoRun\command - "" = E:\rg9g9bgq.exe -- File not found
O33 - MountPoints2\{8fea76fe-47a1-11df-8d1b-0016e68aab13}\Shell\open\Command - "" = E:\rg9g9bgq.exe -- File not found
@Alternate Data Stream - 48 bytes C:\Documents and Settings\All Users\DRM:مايكروسوفت
:Files
C:\Documents and Settings\wojtek\Menu Start\Programy\Autostart\csrss.exe
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DataMngr"=-
"CTSysVol"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]