UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
:OTL
PRC - [2004-08-03 23:44:20 | 03,195,904 | ---- | M] (Microsoft Corporation) -- C:\WIN_XP\explorer.exe
SRV - File not found -- -- (PEVSystemStart)
O4 - HKU\S-1-5-21-1409082233-57989841-725345543-1003..\Run: [iGoD] C:\PROFILE\my5ha\Moje dokumenty\Pobieranie\iGoDr0882.exe File not found
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE File not found
O27 - HKLM IFEO\ctfmon.exe: Debugger - msnwm.exe ( )
:Files
C:\WIN_XP\System32\msnwm.exe
C:\WIN_XP\System32\qxzv47.exe@
C:\WIN_XP\System32\qxzv85łÇ®e
C:\WIN_XP\System32\qxzv44.exe@
C:\WIN_XP\System32\qxzv44łÇ®e
C:\WIN_XP\System32\qxzv54.exe@
C:\WIN_XP\System32\qxzv54łÇ®e
C:\WIN_XP\System32\qxzv47łÇ®e
C:\WIN_XP\System32\qxzv10.exe@
C:\WIN_XP\System32\qxzv10łÇ®e
C:\WIN_XP\System32\qxzv12.exe@
C:\WIN_XP\System32\qxzv12łÇ®e
C:\WIN_XP\System32\qxzv24.exe@
C:\WIN_XP\System32\qxzv24łÇ®e
C:\WIN_XP\System32\qxzv37.exe@
C:\WIN_XP\System32\qxzv37łÇ®e
C:\WIN_XP\System32\qxzv55.exe@
C:\WIN_XP\System32\qxzv55łÇ®e
C:\WIN_XP\System32\qxzv58.exe@
C:\WIN_XP\System32\qxzv58łÇ®e
C:\WIN_XP\System32\qxzv74.exe@
C:\WIN_XP\System32\qxzv74łÇ®e
C:\WIN_XP\System32\qxzv73.exe@
C:\WIN_XP\System32\qxzv73łÇ®e
C:\WIN_XP\System32\qxzv32.exe@
C:\WIN_XP\System32\qxzv32łÇ®e
C:\WIN_XP\System32\qxzv26.exe@
C:\WIN_XP\System32\qxzv26łÇ®e
C:\WIN_XP\System32\qxzv62.exe@
C:\WIN_XP\System32\qxzv62łÇ®e
C:\WIN_XP\PEV.exe
C:\WIN_XP\System32\svchost.exe:exe.exe
:Commands
[emptytemp]
[resethosts]
[start explorer]
[Reboot]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
:OTL
PRC - [2004-08-03 23:44:20 | 03,195,904 | ---- | M] (Microsoft Corporation) -- C:\WIN_XP\explorer.exe
O20 - HKU\S-1-5-21-1409082233-57989841-725345543-1003 Winlogon: Shell - ("C:\PROFILE\my5ha\oggitv.exe") - C:\PROFILE\my5ha\oggitv.exe ()
:Files
C:\PROFILE\my5ha\oggitv.exe
C:\Qoobox
C:\PROFILE\my5ha\DoctorWeb
C:\PROFILE\my5ha\secupdat.dat
C:\WIN_XP\System32\secupdat.dat
C:\WIN_XP\System32\qxzv18.exe@
C:\WIN_XP\System32\qxzv85.exe@
C:\WIN_XP\System32\qxzv03.exe@
C:\WIN_XP\System32\drivers\edzlwrgl.sys
:Commands
[start explorer]
[Reboot]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
File::
c:\temp\Scr3.tmp
c:\profile\my5ha\secupdat.dat
c:\win_xp\system32\drivers\edzlwrgl.sys
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
Zarejestrowani użytkownicy: Bing [Bot]