09 Mar 2012, 09:30
09 Mar 2012, 12:00
:OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=WCV5&o=13757&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=W3&apn_dtid=YYYYYYYYPL&apn_uid=980BB2B7-4E7F-4E4B-89DA-6EC5F36A6332&apn_sauid=1D811D31-7327-4198-B41B-4A8A5F0B2D7F
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=WCV5&o=13757&locale=en_US&apn_uid=980BB2B7-4E7F-4E4B-89DA-6EC5F36A6332&apn_ptnrs=W3&apn_sauid=1D811D31-7327-4198-B41B-4A8A5F0B2D7F&apn_dtid=YYYYYYYYPL&q="
FF - prefs.js..network.proxy.backup.ftp: "24.23.29.41"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "24.23.29.41"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "24.23.29.41"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "24.23.29.41"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "212.100.209.50"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "212.100.209.50"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "212.100.209.50"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "212.100.209.50"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "212.100.209.50"
FF - prefs.js..network.proxy.ssl_port: 8080
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
[2011-01-07 11:22:43 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Users\Killer\AppData\Roaming\mozilla\Firefox\Profiles\9a7hye6x.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2011-12-23 21:26:41 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Killer\AppData\Roaming\mozilla\Firefox\Profiles\9a7hye6x.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010-10-27 21:33:36 | 000,002,568 | ---- | M] () -- C:\Users\Killer\AppData\Roaming\Mozilla\Firefox\Profiles\9a7hye6x.default\searchplugins\askcom.xml
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Killer\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll File not found
O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
:Files
C:\Program Files (x86)\Google\Update
C:\Qoobox
C:\Users\Public\Desktop\Internet Security.lnk
C:\Windows\temp
C:\Users\Killer\Desktop\xd2.exe
C:\Windows\tasks\*.job
C:\Users\Killer\AppData\Local\Temp*.html
c:\users\Public\AppData\Local\temp
c:\users\Default\AppData\Local\temp
:Commands
[clearallrestorepoints]
[emptytemp]
09 Mar 2012, 12:54
09 Mar 2012, 14:39
09 Mar 2012, 18:21
09 Mar 2012, 19:17
kominekl napisał(a):odznacz, a następnie usuń
10 Mar 2012, 09:07
10 Mar 2012, 09:23
:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 94.251.182.30:8080
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
[2012-03-09 12:18:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\v9Soft
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"AdobeCS5ServiceManager"=-
:Files
c:\users\Killer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
:Commands
[clearallrestorepoints]
[emptytemp]
10 Mar 2012, 10:33
10 Mar 2012, 12:54
10 Mar 2012, 14:18
10 Mar 2012, 15:20
10 Mar 2012, 15:43