
Ps. Nie mogłem zeskanować systemu programem gmer. Program wyłaczał się w trakcie skanowania. Nie mam zainstalowanych programów typu deamon tools itd. W systemie niema też pliku sptd.sys
:OTL
IE - HKLM\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKU\S-1-5-21-3226712050-1171243571-513269105-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3226712050-1171243571-513269105-1000\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
IE - HKU\S-1-5-21-3226712050-1171243571-513269105-1000\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
FF - prefs.js..keyword.URL: "http://search.myheritage.com/?orig=ds&q="
[2010-04-18 16:55:00 | 000,000,000 | ---D | M] (Family Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2010-04-18 16:54:35 | 000,003,803 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MyHeritage.xml
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O3 - HKU\S-1-5-21-3226712050-1171243571-513269105-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-3226712050-1171243571-513269105-1000\..\Toolbar\WebBrowser: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O4 - HKU\S-1-5-21-3226712050-1171243571-513269105-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-3226712050-1171243571-513269105-1000..\Run: [king_mg] C:\Windows\system32\mgking.exe File not found
O4 - HKU\S-1-5-21-3226712050-1171243571-513269105-1000..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKU\S-1-5-21-3226712050-1171243571-513269105-1000..\Run: [Pexoadz] C:\Users\media\AppData\Roaming\Ofwo\efux.exe File not found
O9 - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found
O9 - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found
O33 - MountPoints2\{7b6885c6-c3e3-11df-979e-001a92d5ba3c}\Shell - "" = Autorun
O33 - MountPoints2\{7b6885c6-c3e3-11df-979e-001a92d5ba3c}\Shell\AutoRun\command - "" = E:\Install_Nokia_Ovi_Suite.exe
O33 - MountPoints2\{864c6d36-e17a-11dc-88c6-001a92d5ba3c}\Shell\AutoRun\command - "" = F:\CruzerProfile.exe /autorun
O33 - MountPoints2\{bf7cfa07-211c-11df-a846-001a92d5ba3c}\Shell\Auto\command - "" = E:\BootIO.exe
O33 - MountPoints2\{bf7cfa07-211c-11df-a846-001a92d5ba3c}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\BootIO.exe
O33 - MountPoints2\{f5588984-dfd8-11de-8d2a-001a92d5ba3c}\Shell - "" = AutoRun
O33 - MountPoints2\{f5588984-dfd8-11de-8d2a-001a92d5ba3c}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
[2012-08-02 18:35:32 | 000,000,000 | ---D | C] -- C:\Users\media\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum
[2012-08-02 18:33:22 | 000,000,000 | ---D | C] -- C:\ProgramData\6F638C23006D93E0186889906C44B161
[2012-08-02 18:31:57 | 000,000,000 | ---D | C] -- C:\Users\media\AppData\Roaming\Ypbu
[2012-08-02 18:31:56 | 000,000,000 | ---D | C] -- C:\Users\media\AppData\Roaming\Ofwo
[2012-08-02 18:31:56 | 000,000,000 | ---D | C] -- C:\Users\media\AppData\Roaming\Ikow
:Files
C:\Program Files\Family Toolbar
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_USERS\S-1-5-21-3226712050-1171243571-513269105-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Live Security Platinum"=-
:Commands
[emptytemp]
C:\ProgramData\6F638C23006D93E0186889906C44B161
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 30 gości