19 Kwi 2012, 15:11
19 Kwi 2012, 16:52
w oknie Własne opcje skanowania/skrypt wklej::OTL
MOD - [2012.04.14 09:50:24 | 000,834,560 | ---- | M] () -- C:\WINDOWS\Temp\temp91.exe
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://pl.v9.com/?utm_source=b&utm_medium=ins
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://pl.v9.com/?utm_source=b&utm_medium=ins
IE - HKU\S-1-5-21-1004336348-725345543-516097429-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://pl.v9.com/?utm_source=b&utm_medium=ins
IE - HKU\S-1-5-21-1004336348-725345543-516097429-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=100481&babsrc=SP_ss&mntrId=484d536d000000000000000d606ba387
IE - HKU\S-1-5-21-1004336348-725345543-516097429-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_Prot
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge [2012.04.17 11:27:26 | 000,000,000 | ---D | M]
O4 - HKLM..\Run: [AmdAgent] C:\WINDOWS\Temp\temp91.exe ()
O4 - HKU\S-1-5-21-1004336348-725345543-516097429-1004..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6.4; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.dragongamez.com/castleattack2.htm" File not found
O20 - Winlogon\Notify\RelevantKnowledge: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O29 - HKLM SecurityProviders - (negotiat.dll) - File not found
O33 - MountPoints2\{3c419968-f9ca-11dd-9518-000d606ba387}\Shell\AutoRun\command - "" = E:\ur0.com
O33 - MountPoints2\{3c419968-f9ca-11dd-9518-000d606ba387}\Shell\open\Command - "" = E:\ur0.com
[2012.04.14 09:50:25 | 000,281,104 | ---- | C] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\wpcap.dll
[2012.04.14 09:50:25 | 000,100,880 | ---- | C] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\Packet.dll
[2012.04.14 09:50:25 | 000,050,704 | ---- | C] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\drivers\npf.sys
:Services
NPF
:Files
C:\Program Files\RelevantKnowledge
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"=-
"nwiz"=-
"Smapp"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\stacja1\Ustawienia lokalne\Temp\~os4.tmp\rlvknlg.exe"=-
"C:\WINDOWS\Temp\~osF.tmp\rlvknlg.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]20 Kwi 2012, 11:04
20 Kwi 2012, 13:36
Napraw??
20 Kwi 2012, 14:02
20 Kwi 2012, 14:08
:OTL
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
[2012.04.17 15:10:19 | 000,000,000 | ---D | C] -- C:\Program Files\v9Soft
http://www.instalki.pl/programy/downloa ... _8_XP.htmlJava(TM) 6 Update 29
Java(TM) 6 Update 7
http://www.instalki.pl/programy/downloa ... /Java.htmlAdobe Reader 8 - Polish
http://www.instalki.pl/programy/downloa ... eader.html
20 Kwi 2012, 16:50
20 Kwi 2012, 16:53
Nie wykonano akcji.
21 Kwi 2012, 11:57
21 Kwi 2012, 12:03
21 Kwi 2012, 12:50
21 Kwi 2012, 17:46
23 Kwi 2012, 13:19
23 Kwi 2012, 14:26
23 Kwi 2012, 14:53