UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
FF - prefs.js..network.proxy.backup.ftp: "128.232.103.203"
FF - prefs.js..network.proxy.backup.ftp_port: 3124
FF - prefs.js..network.proxy.backup.socks: "128.232.103.203"
FF - prefs.js..network.proxy.backup.socks_port: 3124
FF - prefs.js..network.proxy.backup.ssl: "128.232.103.203"
FF - prefs.js..network.proxy.backup.ssl_port: 3124
FF - prefs.js..network.proxy.ftp: "128.232.103.203"
FF - prefs.js..network.proxy.ftp_port: 3124
FF - prefs.js..network.proxy.http: "128.232.103.203"
FF - prefs.js..network.proxy.http_port: 3124
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "128.232.103.203"
FF - prefs.js..network.proxy.socks_port: 3124
FF - prefs.js..network.proxy.ssl: "128.232.103.203"
FF - prefs.js..network.proxy.ssl_port: 3124
:OTL
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
[2011-11-10 18:09:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Ula\AppData\Roaming\mozilla\Firefox\Profiles\oicgkkc7.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-726175504-1238075440-3985729556-1000\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-726175504-1238075440-3985729556-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-726175504-1238075440-3985729556-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKU\S-1-5-21-726175504-1238075440-3985729556-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O16 - DPF: {66D845A0-C3BB-45AD-807C-9BFEAF20EF2C} http://my.ohm-hochschule.de/content/sta ... _Place.cab (InPEditor Class)
:Files
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\ProgramData\Spybot - Search & Destroy
C:\Program Files (x86)\Spybot - Search & Destroy
C:\Program Files\wlsetup-web.exe
:Reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Następnie podajesz nowe logi z OTL.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
FF - prefs.js..network.proxy.backup.ftp: "128.232.103.203"
FF - prefs.js..network.proxy.backup.ftp_port: 3124
FF - prefs.js..network.proxy.backup.socks: "128.232.103.203"
FF - prefs.js..network.proxy.backup.socks_port: 3124
FF - prefs.js..network.proxy.backup.ssl: "128.232.103.203"
FF - prefs.js..network.proxy.backup.ssl_port: 3124
FF - prefs.js..network.proxy.ftp: "128.232.103.203"
FF - prefs.js..network.proxy.ftp_port: 3124
FF - prefs.js..network.proxy.http: "128.232.103.203"
FF - prefs.js..network.proxy.http_port: 3124
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "128.232.103.203"
FF - prefs.js..network.proxy.socks_port: 3124
FF - prefs.js..network.proxy.ssl: "128.232.103.203"
FF - prefs.js..network.proxy.ssl_port: 3124
FF - prefs.js..network.proxy.type: 0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Pojawiły się na pulpicie 3 ikonki, których usunąć nie mogę bo to pliki systemowe. Jak mam się ich pozbyć?
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
FF - prefs.js..network.proxy.autoconfig_url: "http://www.stuwodu.de/proxy.pac"
FF - prefs.js..network.proxy.backup.ftp: "128.232.103.203"
FF - prefs.js..network.proxy.backup.ftp_port: 3124
FF - prefs.js..network.proxy.backup.socks: "128.232.103.203"
FF - prefs.js..network.proxy.backup.socks_port: 3124
FF - prefs.js..network.proxy.backup.ssl: "128.232.103.203"
FF - prefs.js..network.proxy.backup.ssl_port: 3124
FF - prefs.js..network.proxy.ftp: "128.232.103.203"
FF - prefs.js..network.proxy.ftp_port: 3124
FF - prefs.js..network.proxy.http: "128.232.103.203"
FF - prefs.js..network.proxy.http_port: 3124
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "128.232.103.203"
FF - prefs.js..network.proxy.socks_port: 3124
FF - prefs.js..network.proxy.ssl: "128.232.103.203"
FF - prefs.js..network.proxy.ssl_port: 3124
FF - prefs.js..network.proxy.type: 2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Adobe Reader 9.1 - Polish
Zarejestrowani użytkownicy: Bing [Bot]