UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
C:\Program Files\Cerklib
C:\WINDOWS\program.exe
C:\WINDOWS\Waprop.exe
:Services
McComponentHostService
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"NvCplDaemon"=-
"NvMediaCenter"=-
"nwiz"=-
"WinampAgent"=-
[HKEY_USERS\S-1-5-21-436374069-1085031214-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
"EPSON Stylus DX4400 Series"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
PRC - [2011-11-02 17:05:01 | 001,077,248 | ---- | M] () -- C:\WINDOWS\Waprop.exe
PRC - [2011-10-20 19:07:41 | 004,210,688 | ---- | M] () -- D:\NeoBot\vbaejz.exe
MOD - [2011-11-02 17:05:01 | 001,077,248 | ---- | M] () -- C:\WINDOWS\Waprop.exe
MOD - [2011-10-20 19:07:41 | 004,210,688 | ---- | M] () -- D:\NeoBot\vbaejz.exe
MOD - [2010-05-13 16:22:36 | 000,119,808 | ---- | M] () -- D:\NeoBot\qtplugins\imageformats\qjpeg4.dll
MOD - [2010-05-13 08:27:48 | 000,610,304 | ---- | M] () -- D:\NeoBot\QtOpenGL4.dll
MOD - [2010-05-13 07:15:27 | 007,971,840 | ---- | M] () -- D:\NeoBot\QtGui4.dll
MOD - [2010-05-13 06:53:23 | 000,678,912 | ---- | M] () -- D:\NeoBot\QtNetwork4.dll
MOD - [2010-05-13 06:51:05 | 002,141,696 | ---- | M] () -- D:\NeoBot\QtCore4.dll
MOD - [2010-02-27 11:58:56 | 000,334,848 | ---- | M] () -- D:\NeoBot\QtXml4.dll
[2011-11-02 17:05:27 | 001,958,839 | ---- | M] () -- C:\WINDOWS\program.exe
[2011-11-03 17:57:10 | 000,000,494 | ---- | C] () -- C:\Documents and Settings\Mateusz\Pulpit\NeoBot.lnk
O4 - HKLM..\Run: [WinPrafik] C:\WINDOWS\Waprop.exe ()
:Files
D:\NeoBot
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"nwiz"=-
"WinampAgent"=-
"SunJavaUpdateSched"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\NeoBot\vbaejz.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
MOD - [2011-11-02 17:05:01 | 001,077,248 | ---- | M] () -- C:\WINDOWS\Waprop.exe
MOD - [2011-10-20 19:07:41 | 004,210,688 | ---- | M] () -- D:\NeoBot\vbaejz.exe
MOD - [2010-05-13 16:22:36 | 000,119,808 | ---- | M] () -- D:\NeoBot\qtplugins\imageformats\qjpeg4.dll
MOD - [2010-05-13 08:27:48 | 000,610,304 | ---- | M] () -- D:\NeoBot\QtOpenGL4.dll
MOD - [2010-05-13 07:15:27 | 007,971,840 | ---- | M] () -- D:\NeoBot\QtGui4.dll
MOD - [2010-05-13 06:53:23 | 000,678,912 | ---- | M] () -- D:\NeoBot\QtNetwork4.dll
MOD - [2010-05-13 06:51:05 | 002,141,696 | ---- | M] () -- D:\NeoBot\QtCore4.dll
MOD - [2010-02-27 11:58:56 | 000,334,848 | ---- | M] () -- D:\NeoBot\QtXml4.dll
[2011-11-02 17:05:27 | 001,958,839 | ---- | M] () -- C:\WINDOWS\program.exe
[2011-11-03 17:57:10 | 000,000,494 | ---- | C] () -- C:\Documents and Settings\Mateusz\Pulpit\NeoBot.lnk
O4 - HKLM..\Run: [WinPrafik] C:\WINDOWS\Waprop.exe ()
:Files
D:\NeoBot
C:\Program Files\Cerklib
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\NeoBot\vbaejz.exe"=-
:Commands
[clearallrestorepoints]
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
:OTL
O4 - HKLM..\Run: [WinPrafik] C:\WINDOWS\Waprop.exe ()
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Adobe Reader 6.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
d:\system volume information\_restore{c4e8c730-7a7b-444e-9555-576def4c39c7}\RP34\A0054532.exe (PasswordStealer.Tibia) No action taken.
Zarejestrowani użytkownicy: Bing [Bot]