UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.16) Gecko/20110319 Firefox/3.6.16
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
:OTL
PRC - [2011-03-31 17:58:12 | 000,570,658 | ---- | M] () -- C:\Documents and Settings\user\Menu Start\Programy\Autostart\lass.exe
IE - HKU\S-1-5-21-1275210071-1425521274-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-1275210071-1425521274-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.iminent.com/?appId=3d9c2d4d-5bdf-41b4-a547-be3fc3a1855a&ref=homepage
FF - prefs.js..browser.search.defaultenginename: \"SearchTheWeb\"
[2011-03-25 16:49:07 | 000,000,000 | ---D | M] (Softonic-Eng7 Community Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2008-02-02 15:31:23 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011-03-04 20:24:09 | 000,000,000 | ---D | M] (IMinent Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
[2011-01-14 21:33:32 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2011-03-25 16:49:06 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\extensions\[email protected]
[2011-03-19 12:01:22 | 000,000,000 | ---D | M] (vShare) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\extensions\vshare@toolbar
[2010-09-14 14:48:25 | 000,002,506 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\searchplugins\BearShareWebSearch.xml
[2010-12-08 16:46:22 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\searchplugins\conduit.xml
[2011-03-07 21:02:21 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\searchplugins\daemon-search.xml
[2011-03-28 14:53:56 | 000,002,230 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\searchplugins\SearchTheWeb.xml
[2010-12-11 11:08:53 | 000,001,583 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\b2jql3x4.default\searchplugins\web-search.xml
[2010-09-14 14:48:25 | 000,002,506 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml
[2010-07-10 03:21:02 | 000,002,157 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\SearchTheWeb.xml
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1275210071-1425521274-839522115-1004\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKU\S-1-5-21-1275210071-1425521274-839522115-1004..\RunOnce: [.IMinentUpdate] File not found
PRC - [2010-09-11 17:05:23 | 000,269,824 | ---- | M] () -- C:\Documents and Settings\user\Menu Start\Programy\Autostart\WinSvc.exe
PRC - [2010-03-11 20:35:44 | 000,547,858 | ---- | M] () -- C:\Documents and Settings\user\Menu Start\Programy\Autostart\csrss.exe
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\csrss.exe ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\lass.exe ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\raw32.dll ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\raw32.VIR ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\rhin13.dll ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\scvhost.VIR ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\spoolsvcs.VIR ()
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\WinSvc.exe ()
[2011-03-07 20:49:31 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2011-03-31 13:18:05 | 000,027,958 | ---- | M] () -- C:\Program Files\Common Files\logonInit.dll
[2011-03-31 17:06:28 | 000,000,000 | ---- | C] () -- C:\Program Files\Common Files\userInit.dll
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
C:\WINDOWS\Tasks\*.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DATAMNGR"=-
"NokiaMServer"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"TkBellExe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.16) Gecko/20110319 Firefox/3.6.16
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.16) Gecko/20110319 Firefox/3.6.16 ( )
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
Files to delete:
C:\Documents and Settings\user\Menu Start\Programy\Autostart\csrss.exe
C:\Documents and Settings\user\Menu Start\Programy\Autostart\lass.exe
C:\Documents and Settings\user\Menu Start\Programy\Autostart\rhin13.dll
C:\Documents and Settings\user\Menu Start\Programy\Autostart\scvhost.VIR
C:\Documents and Settings\user\Menu Start\Programy\Autostart\spoolsvcs.VIR
C:\Documents and Settings\user\Menu Start\Programy\Autostart\WinSvc.exe
C:\Program Files\Common Files\userInit.dll
C:\Program Files\Common Files\logonInit.dll
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
:OTL
IE - HKU\S-1-5-21-1275210071-1425521274-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.iminent.com/?appId=3d9c2d4d-5bdf-41b4-a547-be3fc3a1855a&ref=homepage
O3 - HKLM\..\Toolbar: (no name) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1275210071-1425521274-839522115-1004\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-781CD0E19F00} - No CLSID value found.
O4 - HKLM..\Run: [IMBooster] File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\WinSvc.exe.vir ()
[2011-03-07 20:49:31 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2011-03-28 15:27:34 | 000,547,858 | ---- | C] () -- C:\WINDOWS\System32\serwer.exe
[2011-03-28 15:27:34 | 000,297,472 | ---- | C] () -- C:\WINDOWS\System32\loader.exe
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
C:\WINDOWS\tasks\*.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DATAMNGR"=-
"NokiaMServer"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"TkBellExe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
:OTL
FF - prefs.js..browser.search.defaultenginename: "SearchTheWeb"
O4 - HKLM..\Run: [IMBooster] File not found
IE - HKU\S-1-5-21-1275210071-1425521274-839522115-1004\..\URLSearchHook: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll (Iminent)
O2 - BHO: (Iminent.BHO.NavigationError) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll (Iminent)
O4 - HKLM..\Run: [Iminent.Notifier] C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe (Iminent)
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omgmt]
"Start"=dword:00000004
Java(TM) 6 Update 19
Adobe Reader 7.0 - Polish
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
c:\documents and settings\user\moje dokumenty\downloads\ventrilo-2.1.4-windows-i386.exe (Trojan.Dropper) Quarantined and deleted successfully.
c:\documents and settings\user\moje dokumenty\pobieranie\multihack 4.0.exe (Trojan.Fakealert) Quarantined and deleted successfully.
c:\documents and settings\user\Pulpit\paweł moje dokumenty\elfbot ng\whrr.bat (PWS.Tibia) Quarantined and deleted successfully.
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:2.0) Gecko/20100101 Firefox/4.0
:OTL
PRC - [2011-04-04 15:49:22 | 000,570,658 | ---- | M] () -- C:\Documents and Settings\user\Menu Start\Programy\Autostart\lass.exe
O4 - HKLM..\Run: [IMBooster] File not found
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\lass.exe ()
[2011-04-04 15:59:27 | 000,027,958 | ---- | M] () -- C:\Program Files\Common Files\logonInit.dll
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]