UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
Logi.
:OTL
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_7.0 [2011/11/25 07:56:28 | 000,000,000 | ---D | M]
[2012/02/15 20:17:03 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2008/01/23 06:48:42 | 000,491,520 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2012/01/23 12:50:38 | 000,170,080 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll
@Alternate Data Stream - 98 bytesC:\ProgramData\TEMP:0F8F5844
@Alternate Data Stream - 150 bytesC:\ProgramData\TEMP:CD060F93
:Files
C:\Windows\tasks\*.*
C:\Users\MAREK\AppData\Roaming\KC Softwares
C:\Users\MAREK\AppData\Roaming\PC Cleaners
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/5.0; .NET4.0C; .NET CLR 3.5.30729; InfoPath.2)
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/7.0.29915/28.2313; U; pl) Presto/2.8.119 Version/11.10
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/5.0; .NET4.0C; .NET CLR 3.5.30729; InfoPath.2)
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Wykonywanie skryptu.
moze robie cos nie tak,sam juz nie wiem
http://hostuje.net/
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/5.0; .NET4.0C; .NET CLR 3.5.30729; InfoPath.2)
scrypt;
http://www.wklej.eu/index.php?id=90821df94a
autoruns;
http://hostuje.net/file.php?id=05399fda10f0992caf01754ebee8a2d2
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Autoruns.
rdpclip
Malwarebytes' Anti-Malware
O2DA
SunJavaUpdateSched
Wszystko.
Advanced SystemCare 5
Google Update
Wszystko.
Wszystko.
Ati External Event Utility
gupdate
gupdatem
IJPLMSVC
LightScribeService
MBAMService
MozillaMaintenance
NBService
NMIndexingService
odserv
ose
ServiceLayer
SkypeUpdate
sprtsvc_O2DA
SupportSoft RemoteAssist
tgsrvc_O2DA
WinDefend
WMPNetworkSvc
Wszystkie File Not Found.
Wszystko.
ale wysylam nowe;
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/5.0; .NET4.0C; .NET CLR 3.5.30729; InfoPath.2)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.83 Safari/537.1 Comodo_Dragon/21.1.1.0
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/5.0; .NET4.0C; .NET CLR 3.5.30729; InfoPath.2)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.83 Safari/537.1 Comodo_Dragon/21.1.1.0
:OTL
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2567114353-2995694879-958528206-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
Zarejestrowani użytkownicy: Bing [Bot]