
OTL http://www.wklej.org/id/270162/
Extras http://www.wklej.org/id/270167/
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: {8141440E-08F0-4339-9959-5C31C6A69F23}:4.1.0.5190
FF - prefs.js..extensions.enabledItems: {E889F097-B0BE-471B-89AD-B86B6F04B506}:4.1.0.1800
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.0.0.5
FF - prefs.js..extensions.enabledItems: {F2DDDB92-1605-4260-9B25-45A4DAE87B50}:1.0
FF - prefs.js..extensions.enabledItems: {E63605FC-D583-4C81-867F-9457BDB3EA1B}:3.1.0.1840
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.18
FF - HKLM\software\mozilla\Firefox\extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\3.1.0.1840\FF [2009-12-04 19:24:44 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5190\FF [2009-12-04 19:24:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.1.0.1800\FF [2009-12-04 19:24:58 | 00,000,000 | ---D | M]
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [NPSStartup] File not found
O32 - AutoRun File - [2009-12-05 11:48:38 | 00,000,011 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-10-14 16:04:46 | 00,000,000 | ---D | M] - D:\Auto cad 2007 -- [ NTFS ]
O32 - AutoRun File - [2009-12-01 15:40:33 | 00,000,011 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2006-02-20 04:23:32 | 00,000,100 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
:Files
C:\Program Files\Ask.com
C:\Program Files\Gameztar Toolbar
C:\Program Files\Textual Content Provider
C:\Program Files\Content Management Wizard
C:\Program Files\QuestService
C:\Program Files\DAEMON Tools Toolbar
C:\Program Files\Customized Platform Advancer
C:\Program Files\Automated Content Enhancer
C:\Program Files\Web Search Operator
C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\0vq7266l.default\searchplugins\askcom.xml
C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\0vq7266l.default\searchplugins\daemon-search.xml
C:\Program Files\Mozilla Firefox\extensions\{F2DDDB92-1605-4260-9B25-45A4DAE87B50}
C:\Program Files\Mozilla Firefox\searchplugins\questservice127.xml
C:\ComboFix
C:\WINDOWS\SWXCACLS.exe
C:\WINDOWS\SWREG.exe
C:\WINDOWS\SWSC.exe
C:\WINDOWS\ERDNT
C:\Qoobox
C:\WINDOWS\NIRCMD.exe
C:\WINDOWS\PEV.exe
C:\WINDOWS\sed.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\MBR.exe
C:\WINDOWS\zip.exe
:Services
QuestService Service
:Commands
[emptytemp]
SRV - [2004-08-04 00:44:02 | 00,161,513 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ensmsbol.dll -- (uvdtppeg)
SRV - [2004-08-04 00:44:02 | 00,161,513 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ensmsbol.dll -- (fosvwvvis)
SRV - [2004-08-04 00:44:02 | 00,161,513 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ensmsbol.dll -- (ededwzz)
:OTL
PRC - [2004-08-04 00:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
SRV - [2004-08-04 00:44:02 | 00,161,513 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ensmsbol.dll -- (uvdtppeg)
SRV - [2004-08-04 00:44:02 | 00,161,513 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ensmsbol.dll -- (fosvwvvis)
SRV - [2004-08-04 00:44:02 | 00,161,513 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ensmsbol.dll -- (ededwzz)
:Files
C:\WINDOWS\system32\ensmsbol.dll
:Registry
:Services
uvdtppeg
fosvwvvis
ededwzz
:Commands
[start explorer]
[reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 37 gości