:Processes
killallprocesses
:OTL
SRV - File not found [On_Demand | Stopped] -- -- (gusvc)
IE - HKU\S-1-5-21-602162358-1500820517-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems:
personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
[2010-10-30 21:54:36 | 000,000,000 | ---D | M] (vShare Plugin) -- C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Firefox\Profiles\qbhcz01r.default\extensions\vshare@toolbar
[2010-10-30 21:54:49 | 000,001,583 | ---- | M] () -- C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Firefox\Profiles\qbhcz01r.default\searchplugins\web-search.xml
O4 - HKU\S-1-5-21-602162358-1500820517-725345543-1004..\Run: [HEXelon MAX] File not found
O4 - HKU\S-1-5-21-602162358-1500820517-725345543-1004..\Run: [MaxUp Video Downloader] File not found
O4 - HKU\S-1-5-21-602162358-1500820517-725345543-1004..\Run: [swg] File not found
[2011-08-20 12:00:00 | 000,000,360 | ---- | M] () -- C:\WINDOWS\tasks\HPpromotions journeysoftware.job
[2011-08-16 11:19:06 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:D1B5B4F1
:Files
C:\WINDOWS\System32\unrar.dll
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Image Zone - szybkie uruchamianie.lnk
:Services
gupdate
gupdatem
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Echo Control"=-
"NeroFilterCheck"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"RemoteControl"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]