UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
File::
c:\windows\Qnegya.exe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=-
"igfxtray"=-
"igfxhkcmd"=-
"igfxpers"=-
"HP Software Update"=-
"GrooveMonitor"=-
"DivXUpdate"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
:OTL
FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=18&q="
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=18&tid={BBE9BE8C-D086-6637-B1ED-692967992443}&q="
[2009-10-08 23:41:15 | 000,003,700 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fast.png
[2009-10-08 23:41:44 | 000,001,963 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fast.xml
O37 - HKU\S-1-5-21-1231801968-2961785710-2835965827-1006\...exe [@ = exefile] -- Reg Error: Key error. File not found
:Files
c:\windows\system32\drivers\drw705.tmp
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.14) Gecko/2009082707 Firefox/3.0.14 (.NET CLR 3.5.30729) FBSMTWB
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
:OTL
PRC - [2010-04-21 21:20:17 | 000,141,824 | ---- | M] () -- C:\Documents and Settings\Viktor\Ustawienia lokalne\temp\pdfupd.exe
:Files
C:\Documents and Settings\Viktor\Ustawienia lokalne\temp\pdfupd.exe
C:\Documents and Settings\Viktor\Ustawienia lokalne\Dane aplikacji\ave.exe
C:\Documents and Settings\Viktor\Ustawienia lokalne\Dane aplikacji\760y
C:\Documents and Settings\All Users\Dane aplikacji\760y
C:\Documents and Settings\Viktor\Ustawienia lokalne\Dane aplikacji\22k5paIc
C:\Documents and Settings\All Users\Dane aplikacji\22k5paIc
:Commands
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]