24 Gru 2013, 21:16
25 Gru 2013, 11:12
:OTL
MOD - [2013-11-07 03:47:00 | 001,972,304 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\taskmrg.exe
MOD - [2013-11-07 03:47:00 | 000,599,040 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\backtrace.dll
MOD - [2013-11-07 03:47:00 | 000,369,664 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libcurl-4.dll
MOD - [2013-11-07 03:47:00 | 000,314,368 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libevent-2-0-5.dll
MOD - [2013-11-07 03:47:00 | 000,132,096 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libplibc-1.dll
MOD - [2013-11-07 03:47:00 | 000,109,568 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\zlib1.dll
MOD - [2013-11-07 03:47:00 | 000,102,912 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\pdcurses.dll
MOD - [2013-11-07 03:47:00 | 000,082,944 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libmicrohttpd-10.dll
MOD - [2013-11-07 03:47:00 | 000,052,736 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libjansson-4.dll
MOD - [2013-11-07 03:47:00 | 000,043,854 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libblkmaker-0.1-0.dll
MOD - [2013-11-07 03:47:00 | 000,038,190 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libblkmaker_jansson-0.1-0.dll
MOD - [2013-11-07 03:47:00 | 000,015,360 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\Opencl\libhidapi-0.dll
MOD - [2013-09-19 03:39:36 | 001,688,723 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\bfgminer.exe
MOD - [2013-09-19 03:39:36 | 000,599,040 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\backtrace.dll
MOD - [2013-09-19 03:39:36 | 000,369,664 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\libcurl-4.dll
MOD - [2013-09-19 03:39:36 | 000,132,096 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\libplibc-1.dll
MOD - [2013-09-19 03:39:36 | 000,109,568 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\zlib1.dll
MOD - [2013-09-19 03:39:36 | 000,102,912 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\pdcurses.dll
MOD - [2013-09-19 03:39:36 | 000,082,944 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\libmicrohttpd-10.dll
MOD - [2013-09-19 03:39:36 | 000,052,736 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\libjansson-4.dll
MOD - [2013-09-19 03:39:36 | 000,044,781 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\libblkmaker-0.1-0.dll
MOD - [2013-09-19 03:39:36 | 000,040,717 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\minerd\libblkmaker_jansson-0.1-0.dll
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382528020&from=cor&uid=WDCXWD5000AVJS-63TRA0_WD-WCAPW490925409254&q={searchTerms}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382528020&from=cor&uid=WDCXWD5000AVJS-63TRA0_WD-WCAPW490925409254&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382528020&from=cor&uid=WDCXWD5000AVJS-63TRA0_WD-WCAPW490925409254
IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382528020&from=cor&uid=WDCXWD5000AVJS-63TRA0_WD-WCAPW490925409254&q={searchTerms}
O4 - HKCU..\Run: [minerd] C:\Users\Właściciel\AppData\Roaming\minerd\nircmd.exe (NirSoft)
O4 - HKCU..\Run: [Opencl] C:\Users\Właściciel\AppData\Roaming\Opencl\nircmd.exe (NirSoft)
[2013-10-23 12:33:40 | 000,694,864 | ---- | C] (WilSys Co., Ltd.) -- C:\Users\Właściciel\AppData\Roaming\qone8.exe
[2013-12-24 16:33:00 | 000,000,308 | ---- | M] () -- C:\Windows\tasks\DigitalSite.job
[2013-12-24 15:33:06 | 000,000,102 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\WB.CFG
[2013-12-24 15:33:05 | 000,000,006 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\WBPU-TTL.DAT
:Files
C:\ProgramData\eSafe
:Commands
[clearallrestorepoints]
[emptytemp]
25 Gru 2013, 23:35
26 Gru 2013, 12:53
:OTL
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1580014734-1479623805-1116131239-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
:Services
WsysSvc
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
26 Gru 2013, 14:26
26 Gru 2013, 18:26
Nie wykonano akcji.
26 Gru 2013, 22:50
26 Gru 2013, 22:51
27 Gru 2013, 15:29
27 Gru 2013, 19:16
chyba format będzie najlepszy
28 Gru 2013, 15:56
31 Gru 2013, 13:46