
Oto mój log http://wklej.org/id/244495/
Proszę o pomoc!!
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKCU\..\URLSearchHook: {208722fa-38e0-4142-83e5-a341b43a35dd} - C:\Program Files\Power_Challenge\tbPow0.dll (Conduit Ltd.)
FF - prefs.js..extensions.enabledItems: {8141440E-08F0-4339-9959-5C31C6A69F23}:4.2.0.5360
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
FF - prefs.js..extensions.enabledItems: {E889F097-B0BE-471B-89AD-B86B6F04B506}:4.2.0.2050
FF - prefs.js..extensions.enabledItems: {AAF6454A-4000-4015-84C1-6CD844C06B19}:1.0
FF - prefs.js..extensions.enabledItems: {E63605FC-D583-4C81-867F-9457BDB3EA1B}:4.2.0.2150
FF - HKLM\software\mozilla\Firefox\Extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\4.2.0.2150\FF [2009-12-22 13:54:58 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.2.0.5360\FF [2009-12-22 13:55:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.2.0.2050\FF [2009-12-22 13:55:15 | 00,000,000 | ---D | M]
O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.2.0.5360\ACEIEAddOn.dll ()
O2 - BHO: (Power Challenge Toolbar) - {208722fa-38e0-4142-83e5-a341b43a35dd} - C:\Program Files\Power_Challenge\tbPow0.dll (Conduit Ltd.)
O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\4.2.0.2050\CPAIEAddOn.dll ()
O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.2.0.2080\CMWIE.dll ()
O2 - BHO: (Textual Content Provider) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.2.0.1960\TCPIE.dll ()
O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\4.2.0.2150\WSO.dll ()
O3 - HKLM\..\Toolbar: (Power Challenge Toolbar) - {208722fa-38e0-4142-83e5-a341b43a35dd} - C:\Program Files\Power_Challenge\tbPow0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Power Challenge Toolbar) - {208722FA-38E0-4142-83E5-A341B43A35DD} - C:\Program Files\Power_Challenge\tbPow0.dll (Conduit Ltd.)
O4 - HKCU..\Run: [cdoosoft] C:\DOCUME~1\XP\USTAWI~1\Temp\herss.exe File not found
O4 - HKCU..\Run: [wsctf.exe] File not found
O4 - HKCU..\Run: [PowerBar] File not found
O32 - AutoRun File - [2009-12-23 13:17:11 | 00,000,055 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{8492e394-4db8-11dc-9914-000ea6777cb0}\Shell\AutoRun\command - "" = E:\s.exe -- File not found
O33 - MountPoints2\{8492e394-4db8-11dc-9914-000ea6777cb0}\Shell\open\Command - "" = E:\s.exe -- File not found
O33 - MountPoints2\{efe2278e-8af5-11dc-9985-000ea6777cb0}\Shell\AutoRun\command - "" = E:\m9ma.exe -- File not found
O33 - MountPoints2\{efe2278e-8af5-11dc-9985-000ea6777cb0}\Shell\explore\Command - "" = E:\m9ma.exe -- File not found
O33 - MountPoints2\{efe2278e-8af5-11dc-9985-000ea6777cb0}\Shell\open\Command - "" = E:\m9ma.exe -- File not found
:Files
C:\Program Files\Mozilla Firefox\extensions\{AAF6454A-4000-4015-84C1-6CD844C06B19}
C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Textual Content Provider
C:\Program Files\QuestService
C:\Documents and Settings\All Users\Dane aplikacji\QuestService
C:\Program Files\Textual Content Provider
C:\Program Files\Content Management Wizard
C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Internet Today
C:\Program Files\Internet Today
C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Customized Platform Advancer
C:\Program Files\Customized Platform Advancer
C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Automated Content Enhancer
C:\Program Files\Automated Content Enhancer
C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Web Search Operator
C:\Program Files\Web Search Operator
C:\Documents and Settings\All Users\Dane aplikacji\{CA8CD71A-7992-4226-B949-0D7C9976D2F3}
C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Gameztar Toolbar
C:\9ffp.exe
C:\autorun.inf
C:\nx.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
:OTL
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -Mozilla\5.0_( File not found
O28 - HKLM ShellExecuteHooks: {BB4C402F-882A-4526-8C08-51278EA437C1} - C:\WINDOWS\System32\e8main1.dll File not found
:Services
QuestService Service
:Commands
[reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 21 gości