09 Sty 2010, 17:14
09 Sty 2010, 17:21
09 Sty 2010, 17:39
09 Sty 2010, 18:46
09 Sty 2010, 18:50
:OTL
PRC - [2008-04-15 13:00:00 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
SRV - [2009-12-09 14:06:42 | 00,046,456 | ---- | M] () [Auto | Stopped] -- C:\Documents and Settings\All Users\Dane aplikacji\QuestService\questservice111.exe -- (QuestService Service)
FF - HKLM\software\mozilla\Firefox\extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\4.2.0.2150\FF [2010-01-08 09:36:02 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.2.0.5360\FF [2009-12-23 09:01:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.2.0.2050\FF [2009-12-23 09:01:27 | 00,000,000 | ---D | M]
[2009-12-27 15:19:45 | 00,000,000 | ---D | M] (QuestService) -- C:\Program Files\Mozilla Firefox\extensions\{AAF6454A-4000-4015-84C1-6CD844C06B19}
O3 - HKU\S-1-5-21-1085031214-484061587-527237240-1004\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Files
C:\Documents and Settings\All Users\Dane aplikacji\QuestService
C:\Program Files\Web Search Operator
C:\Program Files\Automated Content Enhancer
C:\Program Files\Customized Platform Advancer
C:\WINDOWS\A6448DEA02A34BDEA2C39C431ABCF2D2.TMP
C:\temp
C:\Documents and Settings\TaT\Ustawienia lokalne\Dane aplikacji\Textual Content Provider
C:\Program Files\QuestService
C:\Documents and Settings\All Users\Dane aplikacji\QuestService
C:\Program Files\Textual Content Provider
C:\Program Files\Content Management Wizard
C:\Documents and Settings\TaT\Ustawienia lokalne\Dane aplikacji\Internet Today
C:\Program Files\Internet Today
C:\Documents and Settings\TaT\Ustawienia lokalne\Dane aplikacji\Customized Platform Advancer
C:\Documents and Settings\TaT\Ustawienia lokalne\Dane aplikacji\Automated Content Enhancer
C:\Documents and Settings\TaT\Ustawienia lokalne\Dane aplikacji\Web Search Operator
C:\Program Files\Gameztar Toolbar
C:\Documents and Settings\TaT\Ustawienia lokalne\Dane aplikacji\Gameztar Toolbar
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"Adobe Reader Speed Launcher"=-
"HotKeysCmds"=-
"IgfxTray"=-
"Persistence"=-
"RTHDCPL"=-
"SunJavaUpdateSched"=-
:Commands
[emptytemp]
[start explorer]
09 Sty 2010, 19:11
09 Sty 2010, 19:14
09 Sty 2010, 19:16
09 Sty 2010, 20:43
09 Sty 2010, 20:52
No action taken.
09 Sty 2010, 20:59
09 Sty 2010, 21:02
09 Sty 2010, 21:05