
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1682929
IE - HKCU\..\URLSearchHook: {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeFi.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.)
FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2
FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3
O2 - BHO: (WeFiBar Toolbar) - {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeFi.dll (Conduit Ltd.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (WeFiBar Toolbar) - {0b876028-b388-4f6d-922f-f52faec8535f} - C:\Program Files\WeFiBar\tbWeFi.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.)
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Nygus\Ustawienia lokalne\Temp\herss.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O32 - AutoRun File - [2010-03-01 08:21:20 | 000,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-01 08:21:20 | 000,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-01 08:21:20 | 000,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{bcc84605-c738-11de-b5b8-00500448b1b7}\Shell\AutoRun\command - "" = H:\p3vwxx.exe -- File not found
O33 - MountPoints2\{bcc84605-c738-11de-b5b8-00500448b1b7}\Shell\open\Command - "" = H:\p3vwxx.exe -- File not found
:Files
C:\Documents and Settings\Nygus\Ustawienia lokalne\Temp\cvasds1.dll
C:\Documents and Settings\Nygus\Dane aplikacji\Mozilla\Firefox\Profiles\maf0yuuf.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}
C:\Program Files\pdfforge Toolbar
C:\Program Files\WeFiBar
C:\Documents and Settings\Nygus\Ustawienia lokalne\Dane aplikacji\WeFiBar
C:\Program Files\Conduit
C:\Documents and Settings\Nygus\Ustawienia lokalne\Dane aplikacji\Conduit
C:\s1.exe
C:\autorun.inf
d:\s1.exe
d:\autorun.inf
e:\s1.exe
e:\autorun.inf
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
Folder::
c:\program files\pdfforge Toolbar
C:\_OTL
c:\program files\Conduit
c:\documents and settings\Nygus\Ustawienia lokalne\Dane aplikacji\WeFiBar
c:\documents and settings\Nygus\Ustawienia lokalne\Dane aplikacji\Conduit
c:\program files\WeFiBar
c:\documents and settings\Nygus\Dane aplikacji\Search Settings
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdoosoft]
[-HKEY_CLASSES_ROOT\clsid\{b922d405-6d13-4a2b-ae89-08a030da4402}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 9 gości