
netsvcs
C:\*.*
D:\*.*
E:\*.*
F:\*.*
G:\*.*
H:\*.*
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.
/md5start
eventlog.dll
logevent.dll
netlogon.dll
ntelogon.dll
eNetHook.dll
sfc_os.dll
sfcfiles.dll
atapi.sys
AGP440.sys
beep.sys
ntfs.sys
ndis.sys
explorer.exe
svchost.exe
userinit.exe
/md5stop
CREATERESTOREPOINT
:OTL
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - [2009-10-08 17:10:59 | 00,412,205 | -HS- | M] ( ) -- c:\rq.pif
PRC - [2009-12-17 14:43:36 | 00,348,160 | ---- | M] () -- C:\Program Files\Internet Today\1.1.0.1260\InternetToday.exe
PRC - [2009-10-08 17:41:18 | 00,058,368 | ---- | M] () -- C:\Users\Maks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yuns32.exe
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://www.theprizeday.com/today.php|http://pl.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pl:official\n"
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.0.8.0552
O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\4.1.0.1960\CPAIEAddOn.dll ()
O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\4.1.0.2080\WSO.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1694272459-2536984464-3629638371-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [Internet Today Task] C:\Program Files\Internet Today\1.1.0.1260\InternetToday.exe ()
O4 - HKLM..\Run: [req] c:\rq.pif ( )
O4 - Startup: C:\Users\Maks\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yuns32.exe ()
@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:E41EAF13
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:F65733F1
:Files
C:\Users\Maks\AppData\Roaming\mozilla\Firefox\Profiles\hcezsww9.default\extensions\DTToolbar@toolbarnet.com
C:\Users\Maks\AppData\Roaming\Mozilla\FireFox\Profiles\hcezsww9.default\searchplugins\daemon-search.xml
C:\Users\Maks\AppData\Local\Internet Today
C:\Program Files\Internet Today
C:\Program Files\Customized Platform Advancer
C:\Program Files\Automated Content Enhancer
C:\Program Files\Web Search Operator
C:\ProgramData\{CA8CD71A-7992-4226-B949-0D7C9976D2F3}
C:\Users\Maks\AppData\Roaming\.#
C:\Program Files\DAEMON Tools Toolbar
:Commands
[emptytemp]
[start explorer]
[reboot]
:FIles
C:\Users\Maks\AppData\Roaming\Mozilla\FireFox\Profiles\hcezsww9.default\searchplugins\daemon-search.xml
C:\Users\Maks\AppData\Roaming\mozilla\Firefox\Profiles\hcezsww9.default\extensions\DTToolbar@toolbarnet.com
C:\Users\Maks\AppData\Local\Internet Today
C:\Program Files\Internet Today
C:\Program Files\Customized Platform Advancer
C:\Program Files\Automated Content Enhancer
C:\Program Files\Web Search Operator
C:\ProgramData\{CA8CD71A-7992-4226-B949-0D7C9976D2F3}
C:\Users\Maks\AppData\Roaming\.#
:Commands
[start explorer]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości