UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.21) Gecko/20110830 Firefox/3.6.21
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.21) Gecko/20110830 Firefox/3.6.21
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1
:OTL
O33 - MountPoints2\{7ed33dda-d21c-11e0-b385-001d7da4edd0}\Shell\AutoRun\command - "" = luk1ylq.com
O33 - MountPoints2\{7ed33dda-d21c-11e0-b385-001d7da4edd0}\Shell\open\Command - "" = luk1ylq.com
O33 - MountPoints2\{a049678f-a0b5-11e0-81aa-001d7da4edd0}\Shell\AutoRun\command - "" = F:\cold\hott\Ą¶ľłż¸¤Łů˛Ż˛
O33 - MountPoints2\{a049678f-a0b5-11e0-81aa-001d7da4edd0}\Shell\Explore\Command - "" = F:\cold\hott\Ą¶ľłż¸¤Łů˛Ż˛
O33 - MountPoints2\{a049678f-a0b5-11e0-81aa-001d7da4edd0}\Shell\open\command - "" = F:\cold\hott\Ą¶ľłż¸¤Łů˛Ż˛
[2011-09-07 15:26:24 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
:Files
C:\Windows\System32\dosx.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.22) Gecko/20110902 Firefox/3.6.22
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
:OTL
[2011-09-08 16:30:17 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.2.22) Gecko/20110902 Firefox/3.6.22
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]