UA:
UA:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wm ... Ojg5&lid=2
O2 - BHO: (no name) - {c34641a3-9451-4d36-8a39-99935c41b07d} - C:\WINDOWS\system32\yumifesu.dll
O4 - HKLM\..\Run: [sihuhisiva] Rundll32.exe "C:\WINDOWS\system32\daholose.dll",s
O20 - AppInit_DLLs: C:\WINDOWS\system32\fajejako.dll
Files to delete:
C:\WINDOWS\system32\cmd.cfexe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\yumifesu.dll
C:\WINDOWS\system32\daholose.dll
C:\WINDOWS\system32\fajejako.dll
UA:
UA:
File::
C:\WINDOWS\system32\ckvo.exe
C:\WINDOWS\system32\ckvo0.dll
C:\WINDOWS\system32\vlscvdro.ini
C:\WINDOWS\system32\ordvcslv.dll
C:\WINDOWS\system32\byXPJBuR.dll
C:\WINDOWS\system32\tdssserf1.dll
C:\WINDOWS\fbxrqtwn.exe
C:\rdsfk.com
C:\taqhptr.bat
D:\taqhptr.bat
F:\taqhptr.bat
Folder::
C:\FOUND.000
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44b23873-880b-11dd-874f-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44b23874-880b-11dd-874f-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e62dbaac-883b-11dd-88ad-000e50e9d59e}]
UA:
UA:
UA:
UA:
UA:
UA:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\fajejako.dll
UA:
File::
C:\WINDOWS\system32\fajejako.dll
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
Zarejestrowani użytkownicy: Bing [Bot]