UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
C:\WINDOWS\AhnRpta.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
File::
C:\bkha.exe
C:\otdfi.exe
C:\aqwnqun.exe
C:\-1472079967
C:\hl80c6b1.com
c:\windows\boxworld.ini
c:\windows\system32\ciuytr1.dll
c:\windows\AhnRpta.exe
c:\windows\system32\stmcfg32.dll
c:\windows\system32\stmctrl.dll
c:\windows\stsetup.htm
c:\windows\system32\ljJATMDv.dll
H:\gfqgq.cmd
G:\gy.exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd0ae76f-476f-11dd-90b7-000e5024f9ac}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e32dfd24-e6ed-11dd-9fc8-000e5024f9ac}]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
File::
C:\WINDOWS\system32\afmain0.dll
C:\a2h2.com
C:\Documents and Settings\Karolina\Ustawienia lokalne\Temporary Internet Files\Content.IE5\6YZRA2UD\help[1].rar
C:\hl80c6b1.com
C:\WINDOWS\ServicePackFiles\i386\installutil.exe
C:\WINDOWS\system32\afmain1.dll
C:\WINDOWS\system32\afmain2.dll
C:\WINDOWS\system32\olhrwef.exe
D:\a2h2.com
D:\hl80c6b1.com
G:\hl80c6b1.com
G:\a2h2.com
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
UA: Opera/9.63 (Windows NT 5.1; U; pl) Presto/2.1.1
. . . jest zainfekowany!!
Zainfekowana kopia została znaleziona. Problem naprawiono
Plik odzyskano z -
. . . jest zainfekowany!!
. . . jest zainfekowany!!
File::
c:\windows\system32\drivers\a3185a32.sys
c:\windows\system32\jqzgfpy.sys
c:\windows\Tasks\wchrjndj.job
Folder::
c:\documents and settings\Karolina\Dane aplikacji\cogad
Driver::
jqzgfpy
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\a3185a32]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
UA: Opera/9.63 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
Zarejestrowani użytkownicy: Bing [Bot]