:OTL
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {1838EEB7-D790-4C38-977B-7610FC411ABC}
IE:
64bit: - HKLM\..\SearchScopes\{1838EEB7-D790-4C38-977B-7610FC411ABC}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
IE - HKLM\..\SearchScopes,DefaultScope = {1838EEB7-D790-4C38-977B-7610FC411ABC}
IE - HKLM\..\SearchScopes\{1838EEB7-D790-4C38-977B-7610FC411ABC}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
IE - HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\..\SearchScopes,DefaultScope = {1838EEB7-D790-4C38-977B-7610FC411ABC}
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-1229153242-3201741155-1693493588-1001..\Run: [AdobeBridge] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O15 - HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\..Trusted Domains: 4game.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\..Trusted Ranges: Range1 ([https] in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 10.25.2)
[2013-09-24 21:06:14 | 000,000,000 | ---D | C] -- C:\FRST
[2013-09-24 21:02:47 | 001,955,802 | ---- | C] (Farbar) -- C:\Users\Odyn\Desktop\FRST64.exe
[2013-09-24 20:32:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
[2013-09-24 20:32:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavalys
[2013-09-16 20:54:03 | 001,848,552 | ---- | C] (CPUID) -- C:\Users\Odyn\Desktop\HWMonitor_x64.exe
[2013-09-16 19:29:02 | 000,000,000 | ---D | C] -- C:\Users\Odyn\AppData\Local\PMB Files
[2013-09-16 19:29:00 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2013-09-13 09:45:49 | 000,000,000 | -H-D | C] -- C:\$WINDOWS.~BT
[2013-09-13 09:43:10 | 000,000,000 | -HSD | C] -- C:\AI_RecycleBin
[2012-09-19 12:59:52 | 002,258,432 | ---- | C] (Samsung Electronics) -- C:\ProgramData\MakeMarkerFile.exe
[2013-09-24 21:08:30 | 000,891,144 | ---- | M] () -- C:\Users\Odyn\Desktop\SecurityCheck.exe
[2013-03-24 13:17:20 | 000,000,022 | -HS- | C] () -- C:\Users\Odyn\AppData\Roaming\Windows1569_SettingsRepository.bin
[2013-03-24 13:17:20 | 000,000,022 | -HS- | C] () -- C:\windows\90C7D912BE2316.sys
[2013-05-10 18:38:55 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Babylon
[2013-03-14 13:29:24 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\BESTplayer
[2013-03-22 23:34:06 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013-04-04 23:55:23 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Dropbox
[2013-05-10 18:38:46 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\DVDVideoSoft
[2013-05-10 18:38:38 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\DVDVideoSoftIEHelpers
[2013-09-04 00:11:46 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\eDownload
[2013-08-26 22:48:26 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\GenJ3
[2013-04-18 21:52:51 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\GHISLER
[2013-04-17 20:26:00 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\ImgBurn
[2013-03-14 21:53:50 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\LolClient
[2013-03-18 23:14:49 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\MAXON
[2013-04-09 16:42:07 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\NetBeans
[2013-05-30 16:48:40 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\NoteTable
[2013-04-10 23:55:53 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\NuGet
[2013-05-10 18:38:08 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\OpenCandy
[2013-03-24 12:10:44 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\PDAppFlex
[2013-04-20 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\PowerISO
[2013-05-25 12:18:41 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Samsung
[2013-05-27 16:00:39 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Scilab
[2013-03-14 13:23:51 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Shark007
[2013-04-23 20:47:20 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Softland
[2013-04-08 21:18:33 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013-03-13 16:55:55 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\Synaptics
[2013-05-10 12:12:28 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\TeamViewer
[2013-03-25 15:08:44 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\TightVNC
[2013-03-14 15:19:27 | 000,000,000 | ---D | M] -- C:\Users\Odyn\AppData\Roaming\TuneUp Software
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:05EE1EEF
:Services
gupdate
gupdatem
:Files
C:\windows\tasks\*.*
C:\Users\Odyn\Desktop\Report everest.txt
C:\Users\Odyn\Documents\EVEREST Reports
C:\Program Files (x86)\Lavalys
C:\Users\Odyn\Desktop\like.txt
C:\Users\Odyn\Desktop\HWMonitor_x64.exe
C:\Users\Odyn\AppData\Local\PMB Files
C:\ProgramData\PMB Files
C:\windows\*.log
C:\Users\Odyn\Downloads\K-Lite_Codec_Pack_1000_Full(dobreprogramy.pl).exe
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey
C:\Users\Odyn\.mongorc.js
C:\Program Files (x86)\Google\Update
C:\Program Files (x86)\Pando Networks
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]