UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"SynTPEnh"=-
"IgfxTray"=-
"HotKeysCmds"=-
"Persistence"=-
"UpdateManager"=-
"dla"=-
"hpWirelessAssistant"=-
"WatchDog"=-
"AGRSMMSG"=-
Files to delete:
D:\instalki\BSINSTALLPL.exe
E:\instalki_2\BSINSTALLPL.exe
E:\RECYCLER\S-1-5-21-682003330-1957994488-725345543-1004
E:\shitki\bs\RunMSC.dll
E:\shitki\bs\Installer\BSINSTALLPL.exe
E:\stuff od Efci\BSINSTALLPL.exe
Folders to delete:
E:\RECYCLER\S-1-5-21-682003330-1957994488-725345543-1004
D:\System Volume Information\_restore{B7CDD19E-3E63-4E10-B2DD-BE098D36821E}\RP95
E:\System Volume Information\_restore{B7CDD19E-3E63-4E10-B2DD-BE098D36821E}\RP95
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
SDFix: Version 1.236
Run by Administrator on 2008-10-18 at 23:26
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-18 23:30:08
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
Files with Hidden Attributes :
Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\SDHelper (Spybot - Search & Destroy)\SDHelper.dll"
Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe"
Fri 7 Sep 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 31 Jul 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Finished!
UA: Opera/9.60 (Windows NT 5.1; U; pl) Presto/2.1.1
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników