08 Sie 2010, 13:27
08 Sie 2010, 19:31
:OTL
PRC - [2010-08-06 18:11:26 | 000,057,616 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice153.exe
PRC - [2010-08-06 18:11:26 | 000,057,616 | ---- | M] () -- C:\Program Files\QuestService\questservice.exe
MOD - [2010-08-06 18:12:44 | 000,581,632 | ---- | M] () -- C:\Program Files\QuestService\questservice.dll
SRV - [2010-08-06 18:11:26 | 000,057,616 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice153.exe -- (QuestService Service)
IE - HKU\S-1-5-21-4161038609-944087134-1085268042-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
FF - prefs.js..browser.startup.homepage: "http://www.theprizeday.com/today.php|http://www.onet.pl/"
FF - prefs.js..extensions.enabledItems: {8141440E-08F0-4339-9959-5C31C6A69F23}:4.1.0.5290
FF - prefs.js..extensions.enabledItems: {E889F097-B0BE-471B-89AD-B86B6F04B506}:4.1.0.1960
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.18
FF - prefs.js..extensions.enabledItems: {40f1eb95-4de4-4f36-a826-054ee36bb905}:2.1.3.0
FF - prefs.js..extensions.enabledItems: {AAF6454A-4000-4015-84C1-6CD844C06B19}:1.0
FF - prefs.js..extensions.enabledItems: {E63605FC-D583-4C81-867F-9457BDB3EA1B}:4.1.0.2080
FF - HKLM\software\mozilla\Firefox\Extensions\\{40f1eb95-4de4-4f36-a826-054ee36bb905}: C:\Program Files\Gameztar Toolbar\2.1.3.6670\FFToolbar [2009-12-18 20:50:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\4.1.0.2080\FF [2009-12-18 20:50:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF [2009-12-18 20:50:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF [2009-12-18 20:50:25 | 000,000,000 | ---D | M]
[2008-03-14 17:02:26 | 000,002,920 | ---- | M] () -- C:\Documents and Settings\Kamilek\Dane aplikacji\Mozilla\Firefox\Profiles\74gbpbmo.default\searchplugins\daemon-search.xml
[2010-08-07 12:41:52 | 000,000,000 | ---D | M] (QuestService) -- C:\Program Files\Mozilla Firefox\extensions\{AAF6454A-4000-4015-84C1-6CD844C06B19}
O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\4.1.0.1960\CPAIEAddOn.dll ()
O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5290\ACEIEAddOn.dll ()
O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1990\CMWIE.dll ()
O2 - BHO: (Textual Content Provider) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll ()
O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\4.1.0.2080\WSO.dll ()
O3 - HKU\S-1-5-21-4161038609-944087134-1085268042-1006\..\Toolbar\WebBrowser: (Gameztar Toolbar) - {D45817B8-3EAD-4D1D-8FCA-EC63A8E35DE2} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [MS32DLL] C:\WINDOWS\.MS32DLL.dll.vbs ()
O32 - Unable to obtain root file information for disk C:\
:Files
C:\Program Files\QuestService
C:\Program Files\Automated Content Enhancer
C:\Documents and Settings\All Users\Dane aplikacji\QuestService
C:\Program Files\Customized Platform Advancer
C:\Program Files\Web Search Operator
C:\Program Files\Gameztar Toolbar
C:\Program Files\Content Management Wizard
C:\Program Files\Textual Content Provider
C:\.MS32DLL.dll.vbs
C:\autorun.inf
C:\Documents and Settings\All Users\Dane aplikacji\{0188C6A8-B559-4C1F-AA44-D0347C445C52}
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"Gainward"=-
"nwiz"=-
"SunJavaUpdateSched"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
:Commands
[clearallrestorepoints]
[emptytemp]