06 Sty 2010, 23:40
07 Sty 2010, 17:06
:OTL
PRC - [2009-12-31 21:09:58 | 00,058,744 | ---- | M] () -- C:\Program Files\QuestService\questservice.exe
PRC - [2009-12-31 21:09:58 | 00,058,744 | ---- | M] () -- C:\ProgramData\QuestService\questservice133.exe
PRC - [2009-07-06 10:14:52 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
MOD - [2009-12-31 21:09:50 | 00,598,016 | ---- | M] () -- C:\Program Files\QuestService\questservice.dll
SRV - [2009-12-31 21:09:58 | 00,058,744 | ---- | M] () [Auto | Running] -- C:\ProgramData\QuestService\questservice133.exe -- (QuestService Service)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\3.1.0.1800\FF [2009-11-27 22:31:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5050\FF [2009-11-27 22:31:11 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\3.1.0.1540\FF [2009-11-27 22:31:19 | 00,000,000 | ---D | M]
O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5050\ACEIEAddOn.dll ()
O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\3.1.0.1540\CPAIEAddOn.dll ()
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1820\CMWIE.dll ()
O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\3.1.0.1800\WSO.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D45817B8-3EAD-4D1D-8FCA-EC63A8E35DE2} - No CLSID value found.
O20 - AppInit_DLLs: (TeknoGods.dll) - File not found
:Files
C:\ProgramData\QuestService
C:\Program Files\QuestService
C:\Program Files\Web Search Operator
C:\Program Files\Automated Content Enhancer
C:\Program Files\Customized Platform Advancer
C:\Program Files\Content Management Wizard
C:\Users\Grzesiek\AppData\Local\Textual Content Provider
C:\Program Files\Textual Content Provider
C:\Users\Grzesiek\AppData\Local\Internet Today
C:\Program Files\Internet Today
C:\Users\Grzesiek\AppData\Local\Web Search Operator
C:\ProgramData\{E44AB4E0-C03E-42A0-A133-858C5B8AD6CB}
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DpAgent"=-
"GrooveMonitor"=-
"HP Health Check Scheduler"=-
"HP Software Update"=-
"QlbCtrl.exe"=-
"StartCCC"=-
"SunJavaUpdateSched"=-
"SynTPEnh"=-
"UpdateLBPShortCut"=-
"UpdateP2GoShortCut"=-
"UpdatePDIRShortCut"=-
"UpdatePSTShortCut"=-
:Commands
[emptytemp]
[start explorer]
07 Sty 2010, 19:30
07 Sty 2010, 19:34
:OTL
O2 - BHO: (TCP) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1380\TCPIE.dll File not found
08 Sty 2010, 00:23
08 Sty 2010, 15:46
No action taken.
Pojawił się jeden problem. DigitalPersona nie działa prawidłowo. Podczas logowania się do Windowsa jest wszystko ok, ale w Windowsie już nie działa. Zniknęła ikona w tray'u, nie można się logować na żadną stronę i maila poprzez czytnik linii papilarnych.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DpAgent"="C:\Program Files\DigitalPersona\Bin\DpAgent.exe"
08 Sty 2010, 16:05
08 Sty 2010, 16:05
08 Sty 2010, 16:08
08 Sty 2010, 16:12
08 Sty 2010, 16:13
08 Sty 2010, 16:19
08 Sty 2010, 16:27