
Logi:
HJ: http://www.wklej.org/hash/82e165786f7/
OTL: http://www.wklej.org/hash/8aa453fbe28/
:OTL
PRC - [2004-08-03 23:44:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
MOD - [2010-02-05 09:41:54 | 000,099,840 | RHS- | M] () -- C:\Documents and Settings\Administrator\Ustawienia lokalne\temp\cvasds0.dll
MOD - [2010-01-29 20:14:14 | 000,589,824 | ---- | M] () -- C:\Program Files\QuestService\questservice.dll
SRV - [2010-01-29 20:14:20 | 000,058,744 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice121.exe -- (QuestService Service)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
FF - HKLM\software\mozilla\Firefox\Extensions\\{998B0A2E-1475-4318-8BE9-383A0E70DD2E}: C:\Program Files\RelevantKnowledge
FF - HKLM\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
FF - HKLM\software\mozilla\Firefox\Extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\4.1.0.2080\FF [2009-12-17 21:44:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF [2009-12-17 21:44:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF [2009-12-17 21:44:56 | 000,000,000 | ---D | M]
O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5290\ACEIEAddOn.dll ()
O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\4.1.0.1960\CPAIEAddOn.dll ()
O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1990\CMWIE.dll ()
O2 - BHO: (Textual Content Provider) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll ()
O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\4.1.0.2080\WSO.dll ()
O3 - HKLM\..\Toolbar: (&Tłumaczenie) - {0D704FAD-66E9-4F0A-BFED-4F665770DDB3} - E:\InternetTranslator.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Tłumaczenie) - {0D704FAD-66E9-4F0A-BFED-4F665770DDB3} - E:\InternetTranslator.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O4 - HKLM..\Run: [Internet Today Task] C:\Program Files\Internet Today\1.1.0.1260\InternetToday.exe ()
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Administrator\Ustawienia lokalne\temp\herss.exe ()
O4 - HKCU..\Run: [Vidalia] C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe File not found
O4 - HKCU..\Run: [Wru] C:\Program Files\Wru\Wru.exe File not found
O9 - Extra 'Tools' menuitem : @E:\InternetTranslator.dll,-103 - {b46b0919-62ba-4d99-a5c4-916b57a6805c} - E:\InternetTranslator.dll File not found
O28 - HKLM ShellExecuteHooks: {BB4C402F-882A-4526-8C08-51278EA437C1} - C:\WINDOWS\system32\e8main0.dll ()
O32 - AutoRun File - [2010-02-06 01:35:07 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-06 01:35:07 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-06 01:35:07 | 000,000,057 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-06 01:35:07 | 000,000,057 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{02b2948c-acfc-11de-84d3-000e504a3fdf}\Shell\autorun\command - "" = L:\cqb6wo.exe -- File not found
O33 - MountPoints2\{02b2948c-acfc-11de-84d3-000e504a3fdf}\Shell\open\command - "" = L:\cqb6wo.exe -- File not found
O33 - MountPoints2\{12f4b5da-ba40-11dc-9c9e-000e504a3fdf}\Shell\AutoRun\command - "" = L:\e9naq.exe -- File not found
O33 - MountPoints2\{12f4b5da-ba40-11dc-9c9e-000e504a3fdf}\Shell\open\Command - "" = L:\e9naq.exe -- File not found
O33 - MountPoints2\{225ef627-3712-11de-83cd-000e504a3fdf}\Shell\AutoRun\command - "" = L:\xh319r9b.bat -- File not found
O33 - MountPoints2\{225ef627-3712-11de-83cd-000e504a3fdf}\Shell\open\Command - "" = L:\xh319r9b.bat -- File not found
O33 - MountPoints2\{238f04a3-a154-11de-84b9-000e504a3fdf}\Shell\AutoRun\command - "" = L:\xh319r9b.bat -- File not found
O33 - MountPoints2\{238f04a3-a154-11de-84b9-000e504a3fdf}\Shell\open\Command - "" = L:\xh319r9b.bat -- File not found
O33 - MountPoints2\{5f6e6387-9eb6-11de-84b4-000e504a3fdf}\Shell\AutoRun\command - "" = M:\xh319r9b.bat -- File not found
O33 - MountPoints2\{5f6e6387-9eb6-11de-84b4-000e504a3fdf}\Shell\open\Command - "" = M:\xh319r9b.bat -- File not found
O33 - MountPoints2\{72488036-fc7f-11de-859d-001a4d357383}\Shell\AutoRun\command - "" = L:\Launcher.exe -- File not found
O33 - MountPoints2\{81c1ccbd-72ae-11de-8443-000e504a3fdf}\Shell\AutoRun\command - "" = L:\xh319r9b.bat -- File not found
O33 - MountPoints2\{81c1ccbd-72ae-11de-8443-000e504a3fdf}\Shell\open\Command - "" = L:\xh319r9b.bat -- File not found
O33 - MountPoints2\{888acf86-3e0b-11dd-80cc-000e504a3fdf}\Shell\AutoRun\command - "" = L:\e9naq.exe -- File not found
O33 - MountPoints2\{888acf86-3e0b-11dd-80cc-000e504a3fdf}\Shell\open\Command - "" = L:\e9naq.exe -- File not found
O33 - MountPoints2\{8cf3afdc-3958-11de-83d5-000e504a3fdf}\Shell\AutoRun\command - "" = L:\p.exe -- File not found
O33 - MountPoints2\{8cf3afdc-3958-11de-83d5-000e504a3fdf}\Shell\open\Command - "" = L:\p.exe -- File not found
:Files
C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\8mg9h2lr.default\extensions\{bc03d92d-9a29-4663-a16b-26fb5538975c}
C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\8mg9h2lr.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\8mg9h2lr.default\searchplugins\fast-browser-search.xml
C:\Program Files\Mozilla Firefox\extensions\{AAF6454A-4000-4015-84C1-6CD844C06B19}
C:\Program Files\Mozilla Firefox\extensions\{AAF6454A-4000-4015-84C1-6CD844C06B19}(2)
C:\Program Files\Mozilla Firefox\extensions\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}
C:\Program Files\Mozilla Firefox\searchplugins\questservice113.xml
C:\Program Files\Mozilla Firefox\searchplugins\questservice115.xml
C:\Program Files\Mozilla Firefox\searchplugins\questservice117.xml
C:\Program Files\Mozilla Firefox\searchplugins\questservice121.xml
C:\Program Files\Mozilla Firefox\searchplugins\questservice111.xml
:Services
QuestService Service
:Commands
[purity]
[emptytemp]
[start explorer]
[reboot]
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
C:\Windows\System32\Drivers\etc
C:\*
D:\*
E:\*
F:\*
G:\*
H:\*
%SYSTEMDRIVE%\*.
/md5start
netlogon.dll
ntelogon.dll
eventlog.dll
logevent.dll
atapi.sys
explorer.exe
/md5stop
CREATERESTOREPOINT
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 4 gości