UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.2.15 Version/10.00
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.2.15 Version/10.00
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:Processes
killallprocesses
:OTL
[2009-12-21 06:47:02 | 000,063,488 | ---- | M] (Nullsoft) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O4 - HKLM..\Run: [TempCom] C:\WINDOWS\Fonts\4E738.com (gy)
O4 - HKCU..\Run: [FlashGet] C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Autostart.exe (gy)
O28 - HKLM ShellExecuteHooks: {B03A4BE6-5E5A-483E-B9B3-C484D4B20B72} - C:\WINDOWS\System32\softqq0.dll File not found
:Files
C:\WINDOWS\Fonts\4E738.com
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Autostart.exe
C:\Program Files\Program Files.exe
C:\Documents and Settings\Hellon\Dane aplikacji\Dane aplikacji.exe
C:\Program Files\Common Files\Common Files.exe
C:\Documents and Settings\All Users\Dane aplikacji\Dane aplikacji.exe
C:\WINDOWS\Fonts\C2C9C.com
C:\WINDOWS\Fonts\4E738.com
C:\Documents and Settings\All Users\Dane aplikacji\.zreglib
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
"Shell"="Explorer.exe"
"Userinit"=-
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"Adobe Reader Speed Launcher"=-
"CloneCDTray"=-
"GrooveMonitor"=-
"IndexSearch"=-
"NeroFilterCheck"=-
"nwiz"=-
"SSBkgdUpdate"=-
"SunJavaUpdateSched"=-
"WinampAgent"=-
:Commands
[emptytemp]
[reboot]
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.2.15 Version/10.00
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:OTL
O20 - Winlogon\Notify\LogonInit: DllName - logonInit.dll - C:\Program Files\Common Files\logonInit.dll ()
:Files
C:\Program Files\folder.htt
C:\Program Files\Common Files\userInit.dll
C:\Program Files\Common Files\logonInit.dll
C:\WINDOWS\System32\mdgnagkj.dll
C:\WINDOWS\System32\softqq1.dll
C:\WINDOWS\System32\ieencode.dll
C:\WINDOWS\System32\msssc.dll
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników