UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
:OTL
MOD - [2012-06-22 12:09:18 | 000,115,204 | R-S- | M] () -- C:\Users\Aga\AppData\Local\rtbogs.exe
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-3166458494-3295765406-3981349245-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://domredi.com/1/
IE - HKU\S-1-5-21-3166458494-3295765406-3981349245-1000\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
O4 - HKU\S-1-5-21-3166458494-3295765406-3981349245-1000..\Run: [eyeBeam SIP Client] File not found
O4 - HKU\S-1-5-21-3166458494-3295765406-3981349245-1000..\Run: [sgpxyjm] C:\Users\Aga\AppData\Local\rtbogs.exe ()
O4 - Startup: C:\Users\Aga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\phqht.exe ()
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D292789-06BD-40B6-94A1-7D8E85540C85}: DhcpNameServer = 212.27.40.241 212.27.40.240
O29 - HKLM SecurityProviders - (digiwet.dll) - File not found
O33 - MountPoints2\{41e3f504-f00e-11de-924e-001060d00fa6}\Shell\AutoRun\command - "" = G:\mk28sp.exe
O33 - MountPoints2\{41e3f504-f00e-11de-924e-001060d00fa6}\Shell\open\Command - "" = G:\mk28sp.exe
O33 - MountPoints2\{41e3f50a-f00e-11de-924e-001060d00fa6}\Shell\AutoRun\command - "" = H:\mk28sp.exe
O33 - MountPoints2\{41e3f50a-f00e-11de-924e-001060d00fa6}\Shell\open\Command - "" = H:\mk28sp.exe
O33 - MountPoints2\{437d6d74-f20c-11de-9a31-001060d00fa6}\Shell - "" = Autorun
O33 - MountPoints2\{507a2c3d-01ce-11de-abec-001060d00fa6}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\avi32.exe
O33 - MountPoints2\{507a2c3d-01ce-11de-abec-001060d00fa6}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\avi32.exe
O33 - MountPoints2\{5e421047-9012-11de-88ea-001060d00fa6}\Shell - "" = Autorun
O33 - MountPoints2\{70e0de1f-878c-11df-899a-00030d6d0d46}\Shell\AutoRun\command - "" = F:\mk28sp.exe
O33 - MountPoints2\{70e0de1f-878c-11df-899a-00030d6d0d46}\Shell\open\Command - "" = F:\mk28sp.exe
O33 - MountPoints2\{77b644cc-e0c9-11dd-b864-001060d00fa6}\Shell - "" = Autorun
O33 - MountPoints2\{f66faa1b-759f-11de-a030-001060d00fa6}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\avi32.exe
O33 - MountPoints2\{f66faa1b-759f-11de-a030-001060d00fa6}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\avi32.exe
O33 - MountPoints2\{fbaa3458-af3a-11de-baac-001060d00fa6}\Shell - "" = Autorun
[2012-06-22 16:27:02 | 000,000,226 | -H-- | M] () -- C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[2012-06-22 15:52:02 | 000,000,236 | -H-- | M] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2012-06-21 23:41:15 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3166458494-3295765406-3981349245-1000Core.job
[2012-06-22 14:25:05 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3166458494-3295765406-3981349245-1000UA.job
:Services
0109661339761091mcinstcleanup
:Files
RECYCLER /alldrives
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
Adobe Reader 7.0.5 - Polish
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.0; rv:13.0) Gecko/20100101 Firefox/13.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5 Comodo_Dragon/19.2.0.0
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]