UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
rocesses
killallprocesses
:OTL
MOD - [2010-12-14 13:36:24 | 000,404,299 | -HS- | M] () -- C:\WINDOWS\system32\server.exe
IE - HKU\S-1-5-21-448539723-1972579041-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15161&l=dis
IE - HKU\S-1-5-21-448539723-1972579041-725345543-1003\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.)
IE - HKU\S-1-5-21-448539723-1972579041-725345543-1003\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..extensions.enabledItems: [email protected]:4.3
FF - prefs.js..extensions.enabledItems: [email protected]:4.3
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Service] C:\WINDOWS\system32\server.exe ()
O4 - HKU\S-1-5-21-448539723-1972579041-725345543-1003..\Run: [Service] C:\WINDOWS\system32\server.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [nlpo_01] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nlpo_01] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... vc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O33 - MountPoints2\{05c35488-8eb2-11e0-bab2-001fd0848611}\Shell - "" = AutoRun
O33 - MountPoints2\{05c35488-8eb2-11e0-bab2-001fd0848611}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL WinJoke.exe
O33 - MountPoints2\{06abc50b-932f-11e0-bac0-001fd0848611}\Shell - "" = AutoRun
O33 - MountPoints2\{06abc50b-932f-11e0-bac0-001fd0848611}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL WinJoke.exe
O33 - MountPoints2\{96d8f987-9995-11e0-badd-001fd0848611}\Shell - "" = AutoRun
O33 - MountPoints2\{96d8f987-9995-11e0-badd-001fd0848611}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL WinJoke.exe
[2011-10-21 20:12:11 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-10-21 20:12:04 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2011-10-21 19:12:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
:Files
C:\WINDOWS\system32\server.exe
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk
C:\Documents and Settings\Michał\Menu Start\Programy\Autostart\PowerReg Scheduler V3.exe
C:\Program Files\Common Files\Spigot
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"WinFast Schedule"=-
"WinFastDTV"=-
[HKEY_USERS\S-1-5-21-448539723-1972579041-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"=-
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
O4 - HKU\S-1-5-19..\RunOnce: [nlpo_01] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nlpo_01] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
:OTL
PRC - [2010-12-14 13:36:24 | 000,404,299 | -HS- | M] () -- C:\WINDOWS\system32\server.exe
MOD - [2010-12-14 13:36:24 | 000,404,299 | -HS- | M] () -- C:\WINDOWS\system32\server.exe
IE - HKU\S-1-5-21-448539723-1972579041-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15161&l=dis
IE - HKU\S-1-5-21-448539723-1972579041-725345543-1003\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.)
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..extensions.enabledItems: [email protected]:4.3
FF - prefs.js..extensions.enabledItems: [email protected]:4.3
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p="
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [Service] C:\WINDOWS\system32\server.exe ()
[2011-03-20 21:38:42 | 000,404,299 | -HS- | C] () -- C:\WINDOWS\System32\server.exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"WinFast Schedule"=-
"WinFastDTV"=-
[HKEY_USERS\S-1-5-21-448539723-1972579041-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"=-
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
[2011-10-22 22:45:38 | 008,405,015 | ---- | M] () -- C:\WINDOWS\hlktmp
O4 - HKU\S-1-5-21-448539723-1972579041-725345543-1003..\Run: [Service] C:\WINDOWS\system32\server.exe File not found
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
Adobe Reader 9.4.6 - Polish
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
PROGRAMY\autodesk robot structural analysis professional 2009\keygen\keygen\keygen.exe (Malware.Packer.Gen) Quarantined and deleted successfully.
PROGRAMY\autodesk.keygens\3ds max 2009\max2009-32bit-keygen.exe (RiskWare.Tool.HCK) Quarantined and deleted successfully.
PROGRAMY\autodesk.keygens\autocad 2009\xf-acad9-32-bits.exe (RiskWare.Tool.HCK) Quarantined and deleted successfully.
PROGRAMY\autodesk.keygens\autocad 2009\xf-acad9-64-bits.exe (RiskWare.Tool.CK) Quarantined and deleted successfully.
PROGRAMY\autodesk.keygens\autocad architecture 2009\xf-acada2k9-32bit-kg.exe (RiskWare.Tool.CK) Quarantined and deleted successfully.
PROGRAMY\autodesk.keygens\autocad architecture 2009\xf-acada2k9-64bit-kg.exe (RiskWare.Tool.CK) Quarantined and deleted successfully.
PROGRAMY\autodesk.keygens\inventor pro 2009\xf-aip2k9-32bit-kg.exe (RiskWare.Tool.CK) Quarantined and deleted successfully.
PROGRAMY\robot 2011\activation\activation\keygens\xf-a2011-32bits.exe (RiskWare.Tool.CK) Quarantined and deleted successfully.
PROGRAMY\robot 2011\activation\activation\keygens\xf-a2011-64bits.exe (RiskWare.Tool.CK) Quarantined and deleted successfully.
Windows 5.1.2600 Dodatek Service Pack 2
Internet Explorer 6.0.2900.2180
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników