08 Lut 2010, 21:17
15 Lut 2010, 21:58
15 Lut 2010, 23:51
16 Lut 2010, 21:28
16 Lut 2010, 22:14
:OTL
SRV - File not found [Auto | Stopped] -- -- (StarWindServiceAE)
IE - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2233703
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2453368&SearchSource=3&q={searchTerms}"
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2453368&q="
[2010-02-16 17:40:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\Firefox\Profiles\wz9rblpv.default\extensions\[email protected]
[2009-09-02 14:52:02 | 000,002,257 | ---- | M] () -- D:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\Firefox\Profiles\wz9rblpv.default\searchplugins\askcom.xml
[2010-01-20 12:40:06 | 000,000,933 | ---- | M] () -- D:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\Firefox\Profiles\wz9rblpv.default\searchplugins\conduit.xml
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - D:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - D:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O4 - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003..\Run: [cdoosoft] D:\DOCUME~1\Jacek\USTAWI~1\Temp\herss.exe File not found
O4 - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003..\Run: [psysnew] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe File not found
O20 - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe) - C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe File not found
O20 - HKU\S-1-5-21-1220945662-2077806209-1177238915-1003 Winlogon: Shell - (D:\RECYCLER\S-1-5-21-8853109893-1389937294-463231734-4486\winmap32.exe) - D:\RECYCLER\S-1-5-21-8853109893-1389937294-463231734-4486\winmap32.exe File not found
O32 - AutoRun File - [2010-02-16 00:57:48 | 000,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-16 00:57:48 | 000,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-16 00:57:48 | 000,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{2c718e11-0074-11df-8d6d-000e50b2429d}\Shell\AutoRun\command - "" = K:\RECYCLER32\dmgr.exe -- File not found
O33 - MountPoints2\{2c718e11-0074-11df-8d6d-000e50b2429d}\Shell\open\command - "" = K:\RECYCLER32\dmgr.exe -- File not found
O33 - MountPoints2\{5d007ccd-964c-11de-8c74-000e50b2429d}\Shell\AutoRun\command - "" = J:\1di1w.exe -- File not found
O33 - MountPoints2\{5d007ccd-964c-11de-8c74-000e50b2429d}\Shell\open\Command - "" = J:\1di1w.exe -- File not found
:Files
D:\Program Files\Ask.com
C:\RECYCLER
D:\RECYCLER
E:\RECYCLER
D:\RECYCLER(2)
D:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\Documents and Settings\All Users\Dane aplikacji\Wru
D:\p3vwxx.exe
C:\p3vwxx.exe
E:\p3vwxx.exe
D:\1di1w.exe
C:\1di1w.exe
E:\1di1w.exe
:Reg
[HKEY_USERS\S-1-5-21-1220945662-2077806209-1177238915-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[reboot]
16 Lut 2010, 23:26
17 Lut 2010, 16:58
18 Lut 2010, 13:05
18 Lut 2010, 16:37