UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
:OTL
SRV - [2010/05/11 23:31:16 | 002,478,640 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\rswin_3697.dll -- (Akamai)
IE - HKU\S-1-5-21-823518204-515967899-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15183&l=dis
FF - prefs.js..browser.startup.homepage: "http://www.ask.com?o=15183&l=dis"
[2010/01/16 18:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maciej\Application Data\Mozilla\Firefox\Profiles\oln4uhhb.default\extensions\[email protected]
[2010/03/31 23:14:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maciej\Application Data\Mozilla\Firefox\Profiles\oln4uhhb.default\extensions\[email protected]
[2009/07/10 17:26:08 | 000,002,257 | ---- | M] () -- C:\Documents and Settings\Maciej\Application Data\Mozilla\Firefox\Profiles\oln4uhhb.default\searchplugins\askcom.xml
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-9591373620-0237939322-801104184-4057\nissan.exe) - C:\RECYCLER\S-1-5-21-9591373620-0237939322-801104184-4057\nissan.exe ()
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-9591373620-0237939322-801104184-4057\nissan.exe) - C:\RECYCLER\S-1-5-21-9591373620-0237939322-801104184-4057\nissan.exe ()
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Maciej\ctfmon.exe) - C:\Documents and Settings\Maciej\ctfmon.exe File not found
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Maciej\Application Data\tnzbrg.exe) - C:\Documents and Settings\Maciej\Application Data\tnzbrg.exe File not found
:Files
C:\RECYCLER
C:\Documents and Settings\Maciej\Application Data\.#
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
:Processes
killallprocesses
:OTL
O3 - HKU\S-1-5-21-823518204-515967899-725345543-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-823518204-515967899-725345543-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-9591373620-0237939322-801104184-4057\nissan.exe) - C:\RECYCLER\S-1-5-21-9591373620-0237939322-801104184-4057\nissan.exe File not found
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Maciej\ctfmon.exe) - C:\Documents and Settings\Maciej\ctfmon.exe File not found
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-823518204-515967899-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Maciej\Application Data\tnzbrg.exe) - C:\Documents and Settings\Maciej\Application Data\tnzbrg.exe File not found
:Commands
[reboot]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_USERS\S-1-5-21-823518204-515967899-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\S-1-5-21-823518204-515967899-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\S-1-5-21-823518204-515967899-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\S-1-5-21-823518204-515967899-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12
UA: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Mozilla Firefox (1.5.0.12)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12
Zarejestrowani użytkownicy: Bing [Bot], Google Adsense [Bot]