13 Paź 2011, 09:37
13 Paź 2011, 12:40
13 Paź 2011, 21:23
13 Paź 2011, 22:06
:OTL
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/410
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [DATAMNGR] C:\PROGRA~2\WIA6EB~1\Datamngr\DATAMN~1.EXE (Bandoo Media, inc)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000..\Run: [RGSC] H:\Gta IV\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\WIA6EB~1\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\WIA6EB~1\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll) -C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll) -C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll (Bandoo Media, inc)
[2011-10-13 21:12:08 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1319517385-3152798655-1197978329-1000UA.job
[2011-10-13 20:57:04 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-10-13 20:33:09 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
@Alternate Data Stream - 231 bytesC:\ProgramData\Temp:6BE50C2B
@Alternate Data Stream - 122 bytesC:\ProgramData\Temp:A724744F
@Alternate Data Stream - 121 bytesC:\ProgramData\Temp:AB689DEA
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKMEDIA"=-
"ATKOSD2"=-
"HControlUser"=-
"RemoteControl9"=--
"StartCCC"=-
"UpdateLBPShortCut"=-
"UpdateP2GoShortCut"=-
"UpdatePSTShortCut"=-
"WinampAgent"'=-
[HKEY_USERS\S-1-5-21-1319517385-3152798655-1197978329-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Syncables"=-
:Commands
[clearallrestorepoints]
[emptytemp]
15 Paź 2011, 14:26
15 Paź 2011, 15:01
:OTL
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/410
IE - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [RemoteControl9] -- File not found
O4 - HKU\S-1-5-21-1319517385-3152798655-1197978329-1000..\Run: [RGSC] H:\Gta IV\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
[2011-10-15 14:17:00 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1319517385-3152798655-1197978329-1000UA.job
[2011-10-15 14:16:22 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-10-15 13:57:00 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-10-15 13:17:00 | 000,001,010 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1319517385-3152798655-1197978329-1000Core.job
@Alternate Data Stream - 231 bytesC:\ProgramData\Temp:6BE50C2B
@Alternate Data Stream - 122 bytesC:\ProgramData\Temp:A724744F
@Alternate Data Stream - 121 bytesC:\ProgramData\Temp:AB689DEA
:Files
C:\Program Files (x86)\Conduit
C:\Users\Franek\AppData\Local\Conduit
C:\Users\Franek\AppData\Roaming\ESET
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"=-
"ContentTransferWMDetector.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
16 Paź 2011, 10:17
kominekl napisał(a):Czy używaszWireless Console 3?
16 Paź 2011, 10:56
Tak, a czy to może być powodem problemu z hamahci?
16 Paź 2011, 14:27
16 Paź 2011, 15:41
c:\Users\Franek\Desktop\Crack\nfshp_activator.exe (RiskWare.Tool.CK)Quarantined and deleted successfully.
c:\Users\Franek\downloads\elfbotng.4.5.9.final.crack.by.evolution\ElfCrack.exe (Spyware.PWS)Quarantined and deleted successfully.
h:\NFS\nfshp_activator.exe (RiskWare.Tool.CK)Quarantined and deleted successfully.
Hamachi dalej ma problem z VPN Wieczorem spróbuje uruchomić za pomocą poradnika który wysłałeś