UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2011-09-28 21:18:42 | 000,000,000 | ---D | M] (Hotspot Shield Community Toolbar) -- C:\Documents and Settings\marcin\Dane aplikacji\Mozilla\Firefox\Profiles\tii9culz.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
[2011-03-25 21:04:13 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\marcin\Dane aplikacji\Mozilla\Firefox\Profiles\tii9culz.default\extensions\[email protected]
O3 - HKU\S-1-5-21-725345543-1454471165-682003330-1003\..\Toolbar\ShellBrowser: (no name) - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - No CLSID value found.
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - File not found
[2011-10-20 18:31:00 | 000,001,136 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1454471165-682003330-1003UA.job
[2011-10-20 17:44:19 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2011-10-17 19:31:00 | 000,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1454471165-682003330-1003Core.job
[2011-09-26 14:42:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
:Files
C:\rsit
C:\Qoobox
C:\WINDOWS\PEV.exe
C:\WINDOWS\sed.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\zip.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=-
"NvMediaCenter"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
[2011-06-28 20:39:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\marcin\Dane aplikacji\Mozilla\Firefox\Profiles\tii9culz.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
:Files
C:\Program Files\trend micro
C:\Documents and Settings\All Users\Dane aplikacji\Azureus
C:\Documents and Settings\marcin\Dane aplikacji\Azureus
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
c:\program files\universal document converter\Patch.exe (PUP.Hacktool.Patcher) Quarantined and deleted successfully.
d:\soft\universal document converter\Patch\Patch.exe (PUP.Hacktool.Patcher) Quarantined and deleted successfully.
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
zmieniłem też w Msconfig'u na opcje normalnego uruchamiania systemu
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników