UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 GTB6 FirePHP/0.4
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
:OTL
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [nwiz] File not found
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - G:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - H:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - I:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - J:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-14 19:37:21 | 00,000,059 | RHS- | M] () - K:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-15 15:28:22 | 00,000,276 | RHS- | M] () - L:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{11e66b54-ec85-11de-af2f-001970077939}\Shell\AutoRun\command - "" = L:\nqdymj.exe -- File not found
O33 - MountPoints2\{11e66b54-ec85-11de-af2f-001970077939}\Shell\open\Command - "" = L:\nqdymj.exe -- File not found
O33 - MountPoints2\{44658c5d-d9e5-11de-b692-806d6172696f}\Shell\AutoRun\command - "" = L:\yudald.bat -- [2009-12-12 13:50:16 | 00,116,812 | RHS- | M] ()
O33 - MountPoints2\{44658c5d-d9e5-11de-b692-806d6172696f}\Shell\open\Command - "" = L:\yudald.bat -- [2009-12-12 13:50:16 | 00,116,812 | RHS- | M] ()
O33 - MountPoints2\{ae9ff5cd-d9e1-11de-aef0-001970077939}\Shell\AutoRun\command - "" = L:\yudald.bat -- [2009-12-12 13:50:16 | 00,116,812 | RHS- | M] ()
O33 - MountPoints2\{ae9ff5cd-d9e1-11de-aef0-001970077939}\Shell\open\Command - "" = L:\yudald.bat -- [2009-12-12 13:50:16 | 00,116,812 | RHS- | M] ()
O33 - MountPoints2\{bdad1918-e269-11de-af0a-001970077939}\Shell\AutoRun\command - "" = L:\yudald.bat -- [2009-12-12 13:50:16 | 00,116,812 | RHS- | M] ()
O33 - MountPoints2\{bdad1918-e269-11de-af0a-001970077939}\Shell\open\Command - "" = L:\yudald.bat -- [2009-12-12 13:50:16 | 00,116,812 | RHS- | M] ()
O33 - MountPoints2\{c3a19e84-f087-11de-af40-001970077939}\Shell\AutoRun\command - "" = L:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- [2008-12-01 16:26:00 | 00,010,240 | RHS- | M] ()
O33 - MountPoints2\{c3a19e84-f087-11de-af40-001970077939}\Shell\open\command - "" = L:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- [2008-12-01 16:26:00 | 00,010,240 | RHS- | M] ()
O33 - MountPoints2\{dff5cd6e-eb26-11de-af2a-001970077939}\Shell\AutoRun\command - "" = L:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- [2008-12-01 16:26:00 | 00,010,240 | RHS- | M] ()
O33 - MountPoints2\{dff5cd6e-eb26-11de-af2a-001970077939}\Shell\open\command - "" = L:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- [2008-12-01 16:26:00 | 00,010,240 | RHS- | M] ()
O33 - MountPoints2\{f610cdf0-ea60-11de-af28-001970077939}\Shell - "" = AutoRun
O33 - MountPoints2\{f610cdf1-ea60-11de-af28-001970077939}\Shell\AutoRun\command - "" = Q:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- File not found
O33 - MountPoints2\{f610cdf1-ea60-11de-af28-001970077939}\Shell\open\command - "" = Q:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- File not found
:Files
C:\yudald.bat
D:\yudald.bat
E:\yudald.bat
F:\yudald.bat
G:\yudald.bat
H:\yudald.bat
I:\yudald.bat
J:\yudald.bat
K:\yudald.bat
L:\yudald.bat
C:\RECYCLER
D:\RECYCLER
E:\RECYCLER
F:\RECYCLER
G:\RECYCLER
H:\RECYCLER
I:\RECYCLER
J:\RECYCLER
K:\RECYCLER
L:\RECYCLER
C:\WINDOWS\65F1CF6331E0450B96F34A88BE7361A6.TMP
C:\WINDOWS\System32\nmdfgds0.dll
C:\WINDOWS\System32\nmdfgds1.dll
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
:OTL
MOD - [2010-01-16 12:59:50 | 00,075,928 | RHS- | M] () -- C:\WINDOWS\system32\nmdfgds0.dll
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe ()
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - G:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - H:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - I:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - J:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-16 13:02:24 | 00,000,059 | RHS- | M] () - K:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{c757aaca-012f-11df-af83-001970077939}\Shell\AutoRun\command - "" = L:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- File not found
O33 - MountPoints2\{c757aaca-012f-11df-af83-001970077939}\Shell\open\command - "" = L:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1033\conmgr.exe -- File not found
:Files
C:\WINDOWS\system32\nmdfgds0.dll
C:\yudald.bat
D:\yudald.bat
E:\yudald.bat
F:\yudald.bat
G:\yudald.bat
H:\yudald.bat
I:\yudald.bat
J:\yudald.bat
K:\yudald.bat
L:\yudald.bat
L:\autorun.inf
L:\RECYCLER
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
:OTL
:Files
P:\autorun.inf
P:\yudald.bat
P:\RECYCLER
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 GTB6 FirePHP/0.4
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O1 - Hosts: 193.23.48.100 kemonart.istore.pl
O1 - Hosts: 193.23.48.100 kemonart.istore.pl
Zarejestrowani użytkownicy: Bing [Bot]