09 Wrz 2011, 20:54
09 Wrz 2011, 21:25
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=iron&s={searchTerms}&f=4
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2010-04-25 11:02:59 | 000,000,000 | ---D | M] (EN - Real Madrid FC Toolbar) -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\eg1r8kcl.default\extensions\{b27f0bf1-55e9-4f63-8f3b-130501130af5}
[2010-03-06 17:05:05 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\eg1r8kcl.default\extensions\[email protected]
[2011-05-20 23:34:28 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\eg1r8kcl.default\extensions\[email protected]
[2011-04-25 11:36:03 | 000,000,000 | ---D | M] (Facemoods) -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\eg1r8kcl.default\extensions\[email protected]
[2011-02-25 21:19:21 | 000,000,000 | ---D | M] (vShare) -- C:\Documents and Settings\Przemek\Dane aplikacji\Mozilla\Firefox\Profiles\eg1r8kcl.default\extensions\vshare@toolbar
O2 - BHO: (no name) - {39f3528e-41cf-a302-19da-4490aa8deeb3} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {2F7DB8D7-9BE7-4666-901E-F380555BCAC7} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1003..\Run: [Twoje TVN24] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1006..\RunOnce: [NeroHomeFirstStart] File not found
O9 - Extra 'Tools' menuitem : @C:\Program Files\Russkij Translator\InternetTranslatorRusPol.dll,-103 - {94C70A96-012C-4171-98FC-C1971511F20D} - Reg Error: Key error. File not found
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - File not found
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (Reg Error: Key error.)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\POV.exe
[2011-09-09 15:46:13 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc6ef6d6dc087a.job
[2011-09-09 15:42:43 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-630328440-839522115-1003Core1cc6ef659e9cbea.job
[2010-08-29 00:19:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010-09-09 13:04:00 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{E74E0C5A-DF4F-47CC-98A4-1A094B60AE97}.job
@Alternate Data Stream - 131 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:9494338C
@Alternate Data Stream - 103 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A8ADE5D8
:Files
C:\Documents and Settings\Przemek\Dane aplikacji\ArcaBit
C:\Documents and Settings\All Users\Dane aplikacji\ArcaBit
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"=-
"GUCI_AVS"=-
"nwiz"=-
"PAP7501_Monitor"=-
:Commands
[clearallrestorepoints]
[emptytemp]
10 Wrz 2011, 01:30
10 Wrz 2011, 14:22
:OTL
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {2F7DB8D7-9BE7-4666-901E-F380555BCAC7} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-1993962763-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] File not found
O4 - HKLM..\Run: [Google Desktop Search] File not found
O4 - HKLM..\Run: [PDF Converter Registry Controller] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1003..\Run: [Gadu-Gadu 10] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1003..\Run: [RGSC] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1003..\Run: [Skype] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1003..\Run: [Steam] File not found
O4 - HKU\S-1-5-21-1993962763-630328440-839522115-1003..\Run: [uTorrent] File not found
@Alternate Data Stream - 131 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:9494338C
@Alternate Data Stream - 103 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A8ADE5D8
:Files
C:\WINDOWS\System32\msfffff2b7.dll
C:\Documents and Settings\LocalService\Dane aplikacji\ArcaBit
C:\Documents and Settings\Przemek\Dane aplikacji\BabylonToolbar
C:\Documents and Settings\Przemek\Dane aplikacji\facemoods.com
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"H:\Program Files\SopCast\SopCast.exe"=-
"C:\Program Files\Ares\Ares.exe"=-
"H:\Program Files\Ares\Ares.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]