30 Gru 2011, 21:39
30 Gru 2011, 22:11
31 Gru 2011, 10:10
:OTL
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
IE - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZRxdm427YYPL&ptb=riD9Yo5LkdCF6si9L81RpA&psa=&ind=2010042713&ptnrS=ZRxdm427YYPL&si=&st=sb&n=77ced159&searchfor={searchTerms}
IE - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\..\URLSearchHook: {83821C2B-32A8-4DD7-B6D4-44309A78E668} - SOFTWARE\Classes\CLSID\{83821C2B-32A8-4DD7-B6D4-44309A78E668}\InprocServer32 File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O3 - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\..\Toolbar\WebBrowser: (no name) - {09900DE8-1DCA-443F-9243-26FF581438AF} - No CLSID value found.
O4 - HKU\S-1-5-21-1123561945-1708537768-839522115-1003..\Run: [Registry Reviver] C:\Program Files\Reviversoft\Registry Reviver\RegistryReviver.exe File not found
O32 - AutoRun File - [2008-11-24 18:20:44 | 000,000,081 | RHS- | M] () - D:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2008-11-24 18:20:44 | 000,000,081 | RHS- | M] () - E:\autorun.inf -- [ FAT32 ]
[2011-12-30 18:10:34 | 000,000,306 | -HS- | M] () -- C:\WINDOWS\tasks\JLGS.job
[2011-04-12 07:18:21 | 000,102,400 | RHS- | C] () -- C:\WINDOWS\System32\mqsnap4.dll
[2011-06-22 18:29:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software
:Files
C:\Documents and Settings\Janek\Menu Start\Programy\Autostart\OpenOffice.org 3.3.lnk
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"NvMediaCenter"=-
"nwiz"=-
:Commands
[clearallrestorepoints]
[emptytemp]
[resethosts]
31 Gru 2011, 14:51
31 Gru 2011, 14:55
31 Gru 2011, 14:58
31 Gru 2011, 15:08
31 Gru 2011, 16:19
31 Gru 2011, 17:19
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O2 - BHO: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\..\Toolbar\WebBrowser: (BrotherSoft Extreme Toolbar) - {51A86BB3-6602-4C85-92A5-130EE4864F13} - C:\Program Files\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O15 - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://access.roechling-automotive.com/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
:Files
C:\Program Files\Ad-Remover
C:\Program Files\Trend Micro
C:\WINDOWS\tasks\SA.DAT
C:\Program Files\BrotherSoft_Extreme
C:\Ad-Report-CLEAN[1].txt
C:\Ad-Report-SCAN[1].txt
C:\Program Files\IncrediMail
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrotherSoft_Extreme Toolbar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IncrediMail\Bin\IncMail.exe"=-
"C:\Program Files\IncrediMail\Bin\ImApp.exe"=-
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=-
"SolidWorks_CheckForUpdates"=-
:Commands
[clearallrestorepoints]
[emptytemp]
31 Gru 2011, 18:57
01 Sty 2012, 13:28
Borat napisał(a):A tak btw to jaki av polecacie?
01 Sty 2012, 15:06
:OTL
O3 - HKU\S-1-5-21-1123561945-1708537768-839522115-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
Java(TM) 6 Update 22
Adobe Reader 9.3.3 - Polish