30 Sty 2014, 00:52
30 Sty 2014, 14:53
:OTL
[2013-09-14 14:55:38 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\RADEK\AppData\Roaming\mozilla\Firefox\Profiles\dn54sacg.default\extensions\[email protected]
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-995265764-3047322453-1426277618-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
[2014-01-29 18:57:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobogenie
[2014-01-29 19:19:20 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Roaming\eCyber
[2014-01-29 19:19:13 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Roaming\iSafe
[2014-01-29 18:58:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SupTab
[2014-01-29 18:58:21 | 000,000,000 | ---D | C] -- C:\ProgramData\IePluginService
[2014-01-29 18:58:19 | 000,000,000 | ---D | C] -- C:\ProgramData\WPM
[2014-01-13 18:58:30 | 000,000,000 | ---D | C] -- C:\Users\RADEK\.android
[2014-01-13 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Roaming\newnext.me
[2014-01-13 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Local\Mobogenie
[2014-01-13 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Local\genienext
[2014-01-13 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Local\cache
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=-
"USB3MON"=-
:Commands
[clearallrestorepoints]
[emptytemp]
30 Sty 2014, 16:35
30 Sty 2014, 16:53
30 Sty 2014, 19:17
:OTL
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
[2014-01-13 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Roaming\newnext.me
[2014-01-13 18:58:29 | 000,000,000 | ---D | C] -- C:\Users\RADEK\AppData\Local\genienext
[2014-01-29 18:57:18 | 000,001,972 | ---- | C] () -- C:\Users\RADEK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk
:Commands
[reboot]
30 Sty 2014, 20:45
30 Sty 2014, 21:21