UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5 Comodo_Dragon/19.1.0.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5 Comodo_Dragon/19.1.0.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5 Comodo_Dragon/19.1.0.0
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\xhunter1.sys -- (xhunter1)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\vtany.sys -- (vtany)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\tokii\USTAWI~1\Temp\pxtdipod.sys -- (pxtdipod)
DRV - File not found [Kernel | On_Demand | Stopped] -- G:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\tokii\USTAWI~1\Temp\catchme.sys -- (catchme)
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=3b05ada0-92fb-11e1-b5e5-001617d5fcfe&q="
[2012-04-30 21:32:53 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\tokii\Dane aplikacji\Mozilla\Firefox\Profiles\jh6jvhnt.default\searchplugins\startsear.xml
[2012-06-05 18:34:02 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-TOKI-tokii.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"SkyTel"=-
"SwitchBoard"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"amd_dc_opt"=-
"StartCCC"=-
:Commands
[emptytemp]
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
DRV - File not found [Kernel | Disabled | Stopped] -- System32\Drivers\sptd.sys -- (sptd)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
:Files
RECYCLER /alldrives
C:\ComboFix
C:\WINDOWS\temp
C:\WINDOWS\ERDNT
C:\Qoobox
C:\Documents and Settings\tokii\Dane aplikacji\EurekaLog
C:\Documents and Settings\tokii\Pulpit\EmsisoftAntiMalwareSetup.exe
C:\WINDOWS\tasks\*.job
C:\Documents and Settings\tokii\Moje dokumenty\*.reg
c:\documents and settings\All Users\Menu Start\Programy\Autostart\GamersFirst LIVE!.lnk
C:\Documents and Settings\tokii\Pulpit\12-4_xp32_dd_ccc.exe
C:\STF9E.tmp
c:\windows\DEA314C409294250BC9298E4C105F28D.TMP
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"SkyTel"=-
"SwitchBoard"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"amd_dc_opt"=-
"StartCCC"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=-
[-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^GamersFirst LIVE!.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPeerNexonEU]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
[-HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
[-HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
DRV - File not found [Kernel | Disabled | Unknown] -- System32\Drivers\sptd.sys -- (sptd)
:Files
RECYCLER /alldrives
C:\Program Files\Emsisoft Anti-Malware
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5 Comodo_Dragon/19.1.0.0
Java(TM) 6 Update 29
Adobe Reader 8.3.1
UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5 Comodo_Dragon/19.1.0.0
UA: Opera/9.80 (Windows NT 5.1; U; Edition Campaign 21; pl) Presto/2.10.229 Version/11.64
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników