UA: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20100101 Firefox/17.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.4.0.0 Safari/537.11
:OTL
IE - HKU\S-1-5-21-1957994488-573735546-842925246-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=110824&tt=4212_5&babsrc=HP_ss&mntrId=b01c0588000000000000000bcd467543
IE - HKU\S-1-5-21-1957994488-573735546-842925246-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110824&tt=4212_5&babsrc=SP_ss&mntrId=b01c0588000000000000000bcd467543
IE - HKU\S-1-5-21-1957994488-573735546-842925246-1003\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=3F9B06C7-2564-46EC-B933-C647DCDC82CF&apn_sauid=2242D6B7-37DB-4357-94B1-9EE545D2C303
SRV - [2008-04-14 21:50:36 | 000,161,768 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\mlgrfi.dll -- (ddczwg)
O4 - HKU\S-1-5-21-1957994488-573735546-842925246-1003..\Run: [MSConfig] C:\Documents and Settings\Biały\emog.exe (TODO: <Название компании>)
:Files
RECYCLER /alldrives
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3250:TCP"=-
:Commands
[clearallrestorepoints]
[emptytemp]
netsvcs
UA: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20100101 Firefox/17.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.4.0.0 Safari/537.11
:OTL
O4 - HKCU..\Run: [MSConfig] C:\Documents and Settings\Biały\emog.exe (TODO: <Название компании>)
:Commands
[reboot]
UA: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20100101 Firefox/17.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.4.0.0 Safari/537.11
Files to delete:
C:\Documents and Settings\Biały\emog.exe
:OTL
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=-
UA: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20100101 Firefox/17.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.4.0.0 Safari/537.11
UA: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20100101 Firefox/17.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.4.0.0 Safari/537.11
Zarejestrowani użytkownicy: Bing [Bot]