08 Sty 2010, 16:04
:OTL
PRC - [2009-09-10 14:45:00 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.ask.com/?o=0&l=dir"
FF - prefs.js..extensions.enabledItems: [email protected]:3.5.0.145
FF - prefs.js..keyword.URL: "http://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=BT3&o=14979&locale=en_US&q="
[2010-01-04 19:17:17 | 00,000,000 | ---D | M] (DigitalPowered Toolbar) -- C:\Documents and Settings\Sławek\Dane aplikacji\Mozilla\Firefox\Profiles\d8dhoyl5.default\extensions\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}
[2009-12-30 22:09:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sławek\Dane aplikacji\Mozilla\Firefox\Profiles\d8dhoyl5.default\extensions\[email protected]
[2009-12-30 22:09:59 | 00,002,255 | ---- | M] () -- C:\Documents and Settings\Sławek\Dane aplikacji\Mozilla\Firefox\Profiles\d8dhoyl5.default\searchplugins\askcom.xml
O2 - BHO: (DigitalPowered Toolbar) - {b317125e-2f10-4388-bf1f-2c31c6cd89ed} - C:\Program Files\DigitalPowered\tbDigi.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (DigitalPowered Toolbar) - {b317125e-2f10-4388-bf1f-2c31c6cd89ed} - C:\Program Files\DigitalPowered\tbDigi.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (DigitalPowered Toolbar) - {B317125E-2F10-4388-BF1F-2C31C6CD89ED} - C:\Program Files\DigitalPowered\tbDigi.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - Startup: C:\Documents and Settings\Sławek\Menu Start\Programy\Autostart\siszyd32.exe ()
O33 - MountPoints2\{34422fc7-d443-11de-bd15-a2db19d298a0}\Shell - "" = Autorun
O33 - MountPoints2\{34422fc7-d443-11de-bd15-a2db19d298a0}\Shell\AutoRun\command - "" = H:\winfiles.exe -- File not found
O33 - MountPoints2\{34422fc7-d443-11de-bd15-a2db19d298a0}\Shell\Open\command - "" = H:\winfiles.exe -- File not found
:Files
C:\Program Files\Ask.com
C:\Documents and Settings\Sławek\Menu Start\Programy\Autostart\siszyd32.exe
C:\Program Files\Conduit
C:\Documents and Settings\Sławek\Ustawienia lokalne\Dane aplikacji\Conduit
C:\Documents and Settings\Sławek\Ustawienia lokalne\Dane aplikacji\AskToolbar
C:\WINDOWS\System32\drivers\hnoqjbmn.sys
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\System32\fjhdyfhsn.bat
C:\Documents and Settings\LocalService\Dane aplikacji\fvgqad.dat
C:\Documents and Settings\Sławek\Dane aplikacji\avdrn.dat
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
:Services
hnoqjbmn
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
"QuickTime Task"=-
"SoundMAX"=-
"SoundMAXPnP"=-
"SunJavaUpdateSched"=-
:Commands
[emptytemp]
[reboot]
08 Sty 2010, 18:46
08 Sty 2010, 20:31
Files to delete:
C:\WINDOWS\System32\drivers\hnoqjbmn.sys
Drivers to delete:
hnoqjbmn
08 Sty 2010, 22:10
08 Sty 2010, 22:21
08 Sty 2010, 23:20
09 Sty 2010, 09:49
09 Sty 2010, 12:13