-
👋 Witaj na MPCForum!
Przeglądasz forum jako gość, co oznacza, że wiele świetnych funkcji jest jeszcze przed Tobą! 😎
- ✅ Pełny dostęp do działów i ukrytych treści
- ✅ Możliwość pisania i odpowiadania w tematach
- ✅ System prywatnych wiadomości
- ✅ Zbieranie reputacji i rozwijanie swojego profilu
- ✅ Członkostwo w jednej z największych społeczności graczy
👉 Dołączenie zajmie Ci mniej niż minutę – a zyskasz znacznie więcej!
Zarejestruj się teraz
- 0

Pytanie
Tekson
Tekson
Witam. Mam problem z ciągle wyskakującymi reklamami w przegląrce Mozilla Firefox. Te reklamy pochodzą od Online Advertising Support. Co prawda, kiedy zrobię przywracanie systemu do dnia 31.03 wszystko znika, ale po paru godzinach znów te reklamy wracają i muszę robić przywracanie od nowa. W innych przeglądarkach sprawdzałem i wszystko działa normalnie...
Resetowałem już Firefoxa, usunąłem wszystkie dodatki, pousowałem wszystkie programy, które ostatnio instalowałem. Te podejrzane programy też usunąłem i nic... Ciągle te wyskakujące okna z reklamami, które strasznie utrudniają korzystanie z Firefoxa i przeglądarka strasznie mi od nich muli.
Jest ktoś kto mógłby mi pomóc?
Dodaję jeszcze skan z OTL
OTL logfile created on: Pt-2015-04-03 20:07:28 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Damian\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: ddd-yyyy-MM-dd
2,00 Gb Total Physical Memory | 0,98 Gb Available Physical Memory | 48,79% Memory free
4,00 Gb Paging File | 2,71 Gb Available in Paging File | 67,77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,66 Gb Total Space | 54,69 Gb Free Space | 56,00% Space Free | Partition Type: NTFS
Drive D: | 200,43 Gb Total Space | 130,27 Gb Free Space | 65,00% Space Free | Partition Type: NTFS
Computer Name: DAMIAN-KOMPUTER | User Name: Damian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015-04-03 19:59:37 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Damian\Downloads\OTL.exe
PRC - [2015-03-27 07:00:03 | 000,376,944 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2015-02-06 16:51:59 | 001,880,752 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
PRC - [2014-12-13 09:30:19 | 000,971,920 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2014-07-21 18:08:28 | 001,905,488 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2014-07-18 14:13:22 | 000,009,216 | ---- | M] (Hi-Rez Studios) -- D:\Program Files\Hi-Rez Studios\HiPatchService.exe
PRC - [2014-07-16 10:53:38 | 000,375,056 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
PRC - [2009-07-14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009-07-14 03:14:12 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2007-09-02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
========== Modules (No Company Name) ==========
MOD - [2007-09-02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
MOD - [2007-09-02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc -- (globalUpdatem)
SRV - File not found [Auto | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /svc -- (globalUpdate)
SRV - [2015-03-27 07:00:16 | 000,148,080 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015-03-24 06:22:24 | 000,836,288 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2015-01-02 20:45:12 | 000,315,488 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014-11-22 08:57:16 | 000,088,400 | ---- | M] (Perfect World Entertainment Inc) [On_Demand | Stopped] -- D:\Program Files\RaiderZ\Arc\ArcService.exe -- (ArcService)
SRV - [2014-07-21 18:08:28 | 001,905,488 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2014-07-18 14:13:22 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- D:\Program Files\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2014-07-16 10:53:38 | 000,375,056 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\wpnfd_1_10_0_6.sys -- (wpnfd_1_10_0_6)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2015-01-30 12:44:32 | 000,043,192 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\System32\drivers\{743e5ec0-5922-485f-b9a2-ad3da2380d62}w.sys -- ({743e5ec0-5922-485f-b9a2-ad3da2380d62}w)
DRV - [2015-01-15 14:51:46 | 008,536,208 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2015-01-15 14:50:52 | 000,161,424 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2015-01-08 18:31:50 | 000,023,840 | ---- | M] (REALiX) [Kernel | System | Running] -- C:\Windows\System32\drivers\HWiNFO32.SYS -- (HWiNFO32)
DRV - [2014-11-20 18:38:06 | 000,243,128 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2014-07-19 03:27:35 | 000,296,936 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2009-07-14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009-07-14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009-03-18 18:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?type=ds&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7&q={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.wonderfulsearches.info/?l=1&q={searchTerms}&pid=1539&r=2014/07/26&hid=1156995406958126068&lg=EN&cc=PL&unqvl=60
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1422682954&from=sien&uid=395049983_397234_A43DB8E7
IE - HKCU\..\SearchScopes,DefaultScope = {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=sien&utm_campaign=install_ie&utm_content=ds&from=sien&uid=395049983_397234_A43DB8E7&ts=1422683070&type=default&q={searchTerms}
IE - HKCU\..\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}: "URL" = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=sien&utm_campaign=install_ie&utm_content=ds&from=sien&uid=395049983_397234_A43DB8E7&ts=1422683070&type=default&q={searchTerms}
IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=sien&utm_campaign=install_ie&utm_content=ds&from=sien&uid=395049983_397234_A43DB8E7&ts=1422683070&type=default&q={searchTerms}
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=sien&utm_campaign=install_ie&utm_content=ds&from=sien&uid=395049983_397234_A43DB8E7&ts=1422683070&type=default&q={searchTerms}
IE - HKCU\..\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}: "URL" = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=sien&utm_campaign=install_ie&utm_content=ds&from=sien&uid=395049983_397234_A43DB8E7&ts=1422683070&type=default&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.countryCode: "PL"
FF - prefs.js..browser.search.region: "PL"
FF - prefs.js..browser.startup.homepage: "www.google.pl"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:37.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1212152.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin: D:\Program Files\RaiderZ\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll File not found
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 37.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 37.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2015-04-03 19:50:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Damian\AppData\Roaming\mozilla\Extensions
[2015-04-03 19:50:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2015-04-03 19:50:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnhdjbfjheoohmhpakglckehdcgfffbl\18968.94.7_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpkonlbialedjgeegikdallckpnliboc\12264.76.1_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfdklionolegofhffnhoagpmlailnnni\10305.24.5_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\idggmlekajlpkppfjdadikipagekmfdn\11100.96.0_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhekfgkiebcdiemikbpipliohcokogk\16946.9051.345_0\
CHR - Extension: No name found = C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2014-07-23 16:07:02 | 000,000,921 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 genuine.microsoft.com
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 127.0.0.1 sls.microsoft.com
O2 - BHO: (Adblocker) - {3C9F2E9F-338C-0FD2-3919-840C4BDFDCB5} - C:\Program Files\Adblocker\PkJKMO.dll File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ArcPluginIEBHO Class) - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - D:\Program Files\RaiderZ\Arc\plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {b608cc98-54de-4775-96c9-097de398500c} - No CLSID value found.
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [bCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mbot_pl_175] File not found
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [spotify] C:\Users\Damian\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [spotify Web Helper] C:\Users\Damian\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.159.1 194.204.152.34
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{73452AB7-21E4-4AE2-8979-BEDF145449DF}: DhcpNameServer = 194.204.159.1 194.204.152.34
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27 - HKLM IFEO\bitguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bprotect.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserdefender.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserprotect.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\dprotectsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\jumpflip: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchinstaller.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotector.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings64.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\snapdo.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\umbrella.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\utiljumpflip.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\volaro: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\vonteera: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroids.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroidsservice.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{67c536d4-70ca-11e4-bc64-001fd0b43554}\Shell - "" = AutoRun
O33 - MountPoints2\{67c536d4-70ca-11e4-bc64-001fd0b43554}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\{8748b348-3f11-11e4-a7c5-001fd0b43554}\Shell - "" = AutoRun
O33 - MountPoints2\{8748b348-3f11-11e4-a7c5-001fd0b43554}\Shell\AutoRun\command - "" = J:\LGAutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: x64 - (c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll) - File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015-04-03 20:01:29 | 000,000,000 | ---D | C] -- C:\_OTL
[2015-04-03 19:50:20 | 000,000,000 | ---D | C] -- C:\Users\Damian\AppData\Roaming\Mozilla
[2015-04-03 19:50:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2015-04-02 19:28:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015-03-22 16:27:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2015-03-21 16:11:32 | 000,000,000 | ---D | C] -- C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Korner 5
[2015-03-21 16:10:57 | 000,000,000 | ---D | C] -- C:\Users\Damian\AppData\Roaming\Korner 5
[2015-03-11 20:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX
[2015-03-11 20:35:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Digidesign
[2015-03-11 20:35:15 | 001,332,224 | ---- | C] (AD © 2009) -- C:\Windows\System32\SYNSOEMU.DLL
========== Files - Modified Within 30 Days ==========
[2015-04-03 20:07:00 | 000,001,310 | ---- | M] () -- C:\Windows\tasks\disco_games_notification_service.job
[2015-04-03 20:06:00 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015-04-03 20:04:32 | 000,001,817 | ---- | M] () -- C:\Users\Damian\Desktop\Spotify.lnk
[2015-04-03 20:04:05 | 000,001,014 | ---- | M] () -- C:\Windows\tasks\aOYh8RxJ4GF2cDn7vb6.job
[2015-04-03 20:04:05 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\0xCXfHG9B1yD.job
[2015-04-03 20:03:41 | 000,004,796 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-11.job
[2015-04-03 20:03:41 | 000,003,770 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-7.job
[2015-04-03 20:03:41 | 000,003,052 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-1.job
[2015-04-03 20:03:41 | 000,002,402 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-5.job
[2015-04-03 20:03:41 | 000,002,066 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-2.job
[2015-04-03 20:03:41 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2015-04-03 20:03:41 | 000,000,672 | ---- | M] () -- C:\Windows\tasks\disco_games_updating_service.job
[2015-04-03 20:03:40 | 000,005,474 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-6.job
[2015-04-03 20:03:40 | 000,005,138 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-7.job
[2015-04-03 20:03:40 | 000,004,796 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-11.job
[2015-04-03 20:03:40 | 000,004,114 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-6.job
[2015-04-03 20:03:40 | 000,004,114 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-4.job
[2015-04-03 20:03:40 | 000,004,114 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-4.job
[2015-04-03 20:03:40 | 000,003,430 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-1-7.job
[2015-04-03 20:03:40 | 000,003,094 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-1-6.job
[2015-04-03 20:03:40 | 000,002,402 | ---- | M] () -- C:\Windows\tasks\d3e51b3f-c522-4385-aa6f-19b2774fa609-5_user.job
[2015-04-03 20:03:40 | 000,002,402 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-5_user.job
[2015-04-03 20:03:40 | 000,002,402 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-5.job
[2015-04-03 20:03:40 | 000,002,068 | ---- | M] () -- C:\Windows\tasks\33df6f68-f96c-460c-a75a-596495b19470-10_user.job
[2015-04-03 20:03:40 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015-04-03 20:03:40 | 000,000,450 | -H-- | M] () -- C:\Windows\tasks\SW_Booster-S-608891039.job
[2015-04-03 20:03:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015-04-03 20:03:26 | 1610,260,480 | -HS- | M] () -- C:\hiberfil.sys
[2015-04-03 19:50:15 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2015-04-03 19:49:01 | 000,243,544 | ---- | M] () -- C:\Users\Damian\Desktop\Firefox Setup Stub 37.0.exe
[2015-04-03 19:35:35 | 000,009,584 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015-04-03 19:35:35 | 000,009,584 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015-04-03 19:30:00 | 000,000,296 | ---- | M] () -- C:\Windows\tasks\Price Fountain.job
[2015-04-03 19:07:15 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2015-04-03 15:49:34 | 001,224,704 | ---- | M] () -- C:\Users\Damian\AppData\Roaming\aOYh8RxJ4GF2cDn7vb6.exe
[2015-04-03 15:49:12 | 001,577,472 | ---- | M] () -- C:\Users\Damian\AppData\Roaming\0xCXfHG9B1yD.exe
[2015-04-03 13:37:55 | 000,738,468 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2015-04-03 13:37:55 | 000,652,488 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015-04-03 13:37:55 | 000,154,578 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2015-04-03 13:37:55 | 000,120,890 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015-04-03 13:26:19 | 000,000,648 | ---- | M] () -- C:\Windows\tasks\dress4u_updating_service.job
[2015-03-31 10:14:36 | 000,004,387 | ---- | M] () -- C:\Users\Damian\AppData\Roaming\MT2kDzWeEDBuwPfnUxijR5
[2015-03-31 10:14:36 | 000,004,387 | ---- | M] () -- C:\Users\Damian\AppData\Roaming\aOYh8RxJ4GF2cDn7vb6
[2015-03-31 10:14:20 | 000,005,655 | ---- | M] () -- C:\Users\Damian\AppData\Roaming\J7u9MeKsQNZCNWj8SICoqOff
[2015-03-31 10:14:20 | 000,005,655 | ---- | M] () -- C:\Users\Damian\AppData\Roaming\0xCXfHG9B1yD
[2015-03-30 01:18:14 | 000,126,630 | ---- | M] () -- C:\Users\Damian\Desktop\bookmarks-2015-03-30_650_Nk2SlS7MEUmJ-Erqr4WnKA==.jsonlz4
[2015-03-28 02:26:06 | 000,054,335 | ---- | M] () -- C:\Users\Damian\AppData\Local\recently-used.xbel
[2015-03-23 21:22:17 | 041,123,884 | ---- | M] () -- C:\Users\Damian\Desktop\test3.wav
[2015-03-21 16:12:46 | 000,001,096 | ---- | M] () -- C:\Users\Damian\Desktop\Korner 5 Website.lnk
[2015-03-05 22:16:25 | 179,045,192 | ---- | M] () -- C:\Windows\MEMORY.DMP
========== Files Created - No Company Name ==========
[2015-04-03 19:50:15 | 000,001,121 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015-04-03 19:50:15 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2015-04-03 19:49:01 | 000,243,544 | ---- | C] () -- C:\Users\Damian\Desktop\Firefox Setup Stub 37.0.exe
[2015-04-03 19:47:32 | 000,126,630 | ---- | C] () -- C:\Users\Damian\Desktop\bookmarks-2015-03-30_650_Nk2SlS7MEUmJ-Erqr4WnKA==.jsonlz4
[2015-04-03 19:07:33 | 000,001,014 | ---- | C] () -- C:\Windows\tasks\aOYh8RxJ4GF2cDn7vb6.job
[2015-04-03 19:07:29 | 000,001,000 | ---- | C] () -- C:\Windows\tasks\0xCXfHG9B1yD.job
[2015-04-03 19:07:25 | 000,000,672 | ---- | C] () -- C:\Windows\tasks\disco_games_updating_service.job
[2015-04-03 19:07:24 | 000,001,310 | ---- | C] () -- C:\Windows\tasks\disco_games_notification_service.job
[2015-04-03 15:49:34 | 001,224,704 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\aOYh8RxJ4GF2cDn7vb6.exe
[2015-04-03 15:49:12 | 001,577,472 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\0xCXfHG9B1yD.exe
[2015-04-03 01:09:59 | 000,000,648 | ---- | C] () -- C:\Windows\tasks\dress4u_updating_service.job
[2015-03-31 10:14:36 | 000,004,387 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\MT2kDzWeEDBuwPfnUxijR5
[2015-03-31 10:14:36 | 000,004,387 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\aOYh8RxJ4GF2cDn7vb6
[2015-03-31 10:14:20 | 000,005,655 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\J7u9MeKsQNZCNWj8SICoqOff
[2015-03-31 10:14:20 | 000,005,655 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\0xCXfHG9B1yD
[2015-03-28 02:26:06 | 000,054,335 | ---- | C] () -- C:\Users\Damian\AppData\Local\recently-used.xbel
[2015-03-23 21:22:14 | 041,123,884 | ---- | C] () -- C:\Users\Damian\Desktop\test3.wav
[2015-03-21 16:12:46 | 000,001,096 | ---- | C] () -- C:\Users\Damian\Desktop\Korner 5 Website.lnk
[2015-03-20 20:18:21 | 000,001,817 | ---- | C] () -- C:\Users\Damian\Desktop\Spotify.lnk
[2015-01-08 19:30:05 | 000,000,086 | ---- | C] () -- C:\Users\Damian\AppData\Roaming\WB.CFG
[2015-01-08 18:39:38 | 005,804,772 | ---- | C] () -- C:\Windows\System32\drivers\rtvienna.dat
[2015-01-08 18:39:37 | 001,443,340 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2015-01-08 18:39:36 | 000,087,864 | ---- | C] () -- C:\Windows\System32\audioLibVc.dll
[2014-11-01 20:35:39 | 000,018,168 | ---- | C] () -- C:\Windows\System32\roboot.exe
[2014-08-24 02:26:43 | 000,000,432 | ---- | C] () -- C:\Windows\wininit.ini
[2014-08-04 08:31:08 | 000,007,597 | ---- | C] () -- C:\Users\Damian\AppData\Local\resmon.resmoncfg
[2014-07-26 20:45:33 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014-07-19 03:35:32 | 002,140,976 | ---- | C] () -- C:\Windows\System32\SStudio.dll
[2014-07-19 03:35:29 | 000,188,696 | ---- | C] () -- C:\Windows\System32\AcpiServiceVnA.dll
[2014-07-19 03:31:26 | 004,151,176 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin
[2014-07-19 03:31:11 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2014-07-19 03:31:11 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2014-07-19 03:31:11 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\lagarith.dll
[2014-07-19 03:31:10 | 000,178,688 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2014-07-19 03:31:08 | 000,112,640 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2014-07-19 03:27:49 | 000,010,084 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
========== ZeroAccess Check ==========
[2009-07-14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 03:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >
7 odpowiedzi na to pytanie
Rekomendowane odpowiedzi
Zarchiwizowany
Ten temat przebywa obecnie w archiwum. Dodawanie nowych odpowiedzi zostało zablokowane.