:OTL SRV - File not found [On_Demand | Stopped] – -- (Usplogfpaad) SRV - [2012-05-25 15:12:54 | 000,785,344 | ---- | M] (Spigot, Inc.) [Auto | Running] – C:\Program Files\Application Updater\ApplicationUpdater.exe – (Application Updater) IE - HKU\S-1-5-21-1220945662-879983540-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.shareazaweb.com/sidebar.html?src=ssb IE - HKU\S-1-5-21-1220945662-879983540-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.shareazaweb.com/pl/ IE - HKU\S-1-5-21-1220945662-879983540-1801674531-1003…\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\5.8\pdfforgeToolbarIE.dll (Spigot, Inc.) IE - HKU\S-1-5-21-1220945662-879983540-1801674531-1003…\SearchScopes{71C63272-91A7-436a-843D-A1C641D1C626}: “URL” = http://search.shareazaweb.com/webResult … src=ieb&q={searchTerms} IE - HKU\S-1-5-21-1220945662-879983540-1801674531-1003…\SearchScopes{CF739809-1C6C-47C0-85B9-569DBB141420}: “URL” = http://toolbar.ask.com/toolbarv/askRedi … t=&gc=1&q={searchTerms}&crm=1&toolbar=VZ2 FF - prefs.js…browser.search.defaultenginename: “Ask” FF - prefs.js…browser.search.order.1: “Ask” FF - prefs.js…browser.search.param.yahoo-fr: “chr-greentree_ff&type=302398&ilc=12” FF - prefs.js…extensions.enabledItems: pdfforge@mybrowserbar.com:5.7 FF - prefs.js…extensions.enabledItems: wtxpcom@mybrowserbar.com:5.7 FF - prefs.js…keyword.URL: “http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=302398&p=” [2012-05-26 12:32:55 | 000,000,000 | —D | M] (pdfforge Toolbar) – C:\PROGRAM FILES\PDFFORGE TOOLBAR\FF O2 - BHO: (Reg Error: Value error.) - {65BFA841-C5A1-41D6-AD7F-8797348852C1} - C:\WINDOWS\system32\pmnmmJyW.dll File not found O4 - HKLM…\Run: [] File not found O4 - HKLM…\Run: [GEST] = File not found O4 - HKU.DEFAULT…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-18…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-19…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-20…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\secpol.exe) - File not found O20 - Winlogon\Notify\pmnmmJyW: DllName - (pmnmmJyW.dll) - File not found O27 - HKLM IFEO\taskmgr.exe: Debugger - “F:\XPPROCEXPLORE\PROCEXP.EXE” File not found O28 - HKLM ShellExecuteHooks: {65BFA841-C5A1-41D6-AD7F-8797348852C1} - C:\WINDOWS\system32\pmnmmJyW.dll File not found [2009-01-14 21:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\112AF [2009-02-25 22:03:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\151F [2009-04-26 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\15290 [2009-01-12 00:28:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\173C8 [2009-01-11 19:08:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\1B1A5 [2009-01-28 22:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\2034B [2009-06-29 19:44:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\212AF [2009-05-16 15:03:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\25138 [2009-06-28 22:28:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\277D [2009-06-22 18:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\282FD [2009-01-28 22:07:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\3432C [2009-07-29 20:55:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\37280 [2009-08-02 14:45:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\37CB [2009-08-09 15:11:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\931C [2009-04-28 21:07:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\93A9 [2009-06-02 21:25:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\C0 [2009-05-11 17:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\F157 [2009-07-09 00:05:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\F3B9 [2009-12-31 17:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\FNET @Alternate Data Stream - 40 bytes -> C:\windows\system32:5198d3af.zreglib @Alternate Data Stream - 24 bytes -> C:\WINDOWS:F022896B50AF07DC :Commands [emptytemp]