06 Sty 2012, 19:44
06 Sty 2012, 21:26
06 Sty 2012, 22:28
07 Sty 2012, 09:26
program nazywał się Koodo jakoś tak ale właśnie je znalazłem i usunąłem
07 Sty 2012, 14:00
07 Sty 2012, 20:48
08 Sty 2012, 13:20
08 Sty 2012, 23:03
:OTL
IE - HKU\.DEFAULT\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - No CLSID value found
IE - HKU\S-1-5-21-908395614-2790017876-2893910143-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9514
FF - prefs.js..browser.search.defaultenginename: "http://www.mail.ru/"
FF - prefs.js..browser.search.defaulturl: "http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "mail.ru: ПоиŃĐş в Đнтернете"
FF - prefs.js..browser.startup.homepage: "http://www.mail.ru/cnt/9514"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=937811&ilc=12&p="
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
[2012-01-07 22:25:45 | 000,000,000 | ---D | M] (СпŃтник @Mail.Ru) -- C:\Users\Pabloss\AppData\Roaming\mozilla\Firefox\Profiles\ksl6conz.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D}
CHR - default_search_provider: Yahoo! UK & Ireland (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8&ilc=12&type=937811&p={searchTerms}
CHR - default_search_provider: suggest_url = http://uk-sayt.ff.search.yahoo.com/gossip-uk-sayt?output=fxjson&command={searchTerms}
O4 - HKU\S-1-5-21-908395614-2790017876-2893910143-1000..\Run: [ASRockIES] File not found
O4 - HKU\S-1-5-21-908395614-2790017876-2893910143-1000..\Run: [ASRockOCTuner] File not found
O4 - HKU\S-1-5-21-908395614-2790017876-2893910143-1000..\Run: [Kookos] C:\Users\Pabloss\AppData\Local\Kookos\kookos.exe silent File not found
O4 - HKU\S-1-5-21-908395614-2790017876-2893910143-1000..\Run: [zASRockInstantBoot] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
[2012-01-08 11:59:01 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-01-08 11:27:49 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-01-08 11:27:32 | 000,000,538 | ---- | M] () -- C:\Windows\tasks\Scheduled scanning task.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=-
"NBAgent"=-
"ZyngaGamesAgent"=-
:Commands
[clearallrestorepoints]
[emptytemp]
09 Sty 2012, 01:22
09 Sty 2012, 16:17
:OTL
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found.
:Files
C:\Program Files (x86)\Google\Update
C:\Windows\tasks\*.job
C:\Users\Pabloss\AppData\Local\setup.exe
C:\Users\Pabloss\Documents\cc_20120105_154004.reg
C:\Program Files (x86)\Mail.Ru
C:\ProgramData\Guard.Mail.Ru
C:\Program Files (x86)\Common Files\Spigot
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=-
"STCAgent"=-
"ZyngaGamesAgent"=-
:Commands
[clearallrestorepoints]
[emptytemp]
09 Sty 2012, 17:06
09 Sty 2012, 18:30
:OTL
:Files
C:\Windows\tasks\Scheduled scanning task.job
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"=-
"ZyngaGamesAgent"=-
:Commands
[clearallrestorepoints]
[emptytemp]
09 Sty 2012, 21:00
09 Sty 2012, 22:00
09 Sty 2012, 22:12