UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {599695B4-129D-4CE2-8E12-0C7F1B5B01E8}
IE - HKLM\..\SearchScopes\{599695B4-129D-4CE2-8E12-0C7F1B5B01E8}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=a3c3d9b9-67d4-11e1-bec3-7c4fb56bc8eb&q={searchTerms}
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.pl/http://www.google.pl/ [binary data]
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes,DefaultScope = {CF739809-1C6C-47C0-85B9-569DBB141420}
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes\{00BAD86B-CDF5-4C34-A882-132EB5872468}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes\{3052C89B-EEB7-43AC-9B57-51790FEF220A}: "URL" = http://start.funmoods.com/results.php?f=4&a=make&q={searchTerms}
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes\{78506AA0-E339-4BA4-9A03-8B695D98352C}: "URL" = http://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms}
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes\{B7E5998A-AB97-4202-A501-636AF13BEC79}: "URL" = http://toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&toolbar=PD
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=a3c3d9b9-67d4-11e1-bec3-7c4fb56bc8eb&q={searchTerms}
IE - HKU\S-1-5-21-2591103998-1093498974-2332618709-1001\..\SearchScopes\{DA89CC1F-7F8D-4562-99E6-CC341C5C08A5}: "URL" = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=a3c3d9b9-67d4-11e1-bec3-7c4fb56bc8eb&q="
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012/03/13 20:46:35 | 000,000,000 | ---D | M]
[2012/02/29 17:06:27 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Sebastian\AppData\Roaming\mozilla\Firefox\Profiles\y5hlfmu7.default\extensions\[email protected]
[2012/02/29 17:06:26 | 000,001,798 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\y5hlfmu7.default\searchplugins\funmoods.xml
[2012/03/06 22:38:14 | 000,000,792 | ---- | M] () -- C:\Users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\y5hlfmu7.default\searchplugins\startsear.xml
[2011/10/03 10:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8 - Extra context menu item: Dodaj do programu TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-229 - {97F922BD-8563-4184-87EE-8C4ACA438823} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-228 - {97F922BD-8563-4184-87EE-8C4ACA438823} - Reg Error: Key error. File not found
:Files
C:\Program Files (x86)\Google\Update
C:\Users\Sebastian\AppData\Roaming\Malwarebytes
C:\ProgramData\Malwarebytes
C:\Users\Sebastian\AppData\Local\{8A206DD2-6C0E-41F9-8EAA-966CD411C296}
C:\Users\Sebastian\AppData\Local\{144622E0-394E-4765-90A2-B067025EC95B}
C:\Program Files (x86)\vShare.tv plugin
C:\Users\Sebastian\AppData\Local\{2CB8454E-736C-4E15-A693-AA31944D8EF1}
C:\Users\Sebastian\AppData\Local\{880E3A83-1379-42BF-96AB-08DD47A79236}
$RECYCLE.BIN /alldrives
C:\Windows\tasks\*.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"=-
"KeNotify"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
kolorowy0706 napisał(a):jedynie w msconfig zakladce uruchamianie jest adobe arm odznaczyc
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
:OTL
[2012/03/23 21:25:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/23 20:26:41 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/23 20:26:41 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"WinampAgent"=-
"HWSetup"=-
"KeNotify"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"=-
:Files
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0) Gecko/20100101 Firefox/10.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
:OTL
:Files
C:\Users\Sebastian\AppData\Roaming\Malwarebytes
C:\ProgramData\Malwarebytes
C:\Users\Sebastian\AppData\Local\{8A206DD2-6C0E-41F9-8EAA-966CD411C296}
C:\Users\Sebastian\AppData\Local\{144622E0-394E-4765-90A2-B067025EC95B}
C:\Users\Sebastian\AppData\Local\{2CB8454E-736C-4E15-A693-AA31944D8EF1}
C:\Users\Sebastian\AppData\Local\{880E3A83-1379-42BF-96AB-08DD47A79236}
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"=-
"ToshibaServiceStation"=-
[HKEY_USERS\S-1-5-21-2591103998-1093498974-2332618709-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
:Commands
[clearallrestorepoints]
[emptytemp]
[2012/03/20 20:38:56 | 000,065,943 | ---- | M] () -- C:\Users\Sebastian\Documents\HDTune_Info_TOSHIBA_MK6476GSXN.png
[2012/03/20 20:37:56 | 000,068,882 | ---- | M] () -- C:\Users\Sebastian\Documents\HDTune_Benchmark_TOSHIBA_MK6476GSXN.png
[2012/03/20 20:20:48 | 000,057,906 | ---- | M] () -- C:\Users\Sebastian\Documents\HDTune_Error_Scan_TOSHIBA_MK6476GSXN.png
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników