UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
Files to delete:
C:\Documents and Settings\Ja\Menu Start\Programy\Autostart\winesm32.exe
C:\Documents and Settings\NetworkService\Dane aplikacji\rbuwzv.dat
C:\WINDOWS\System32\drivers\scmbkhst.sys
C:\Documents and Settings\Ja\Dane aplikacji\rbuwzv.dat
C:\Documents and Settings\Ja\Dane aplikacji\avdrn.dat
Drivers to delete:
scmbkhst
:OTL
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKCU..\Run: [Prec] C:\Program Files\Prec\PrecStarter.exe File not found
O20 - Winlogon\Notify\byXOhFWo: DllName - byXOhFWo.dll - File not found
O33 - MountPoints2\{4c53a644-7b36-11db-a8e9-0016e65f63b9}\Shell\AutoRun\command - "" = E:\jfvkcsy.bat -- File not found
O33 - MountPoints2\{4c53a644-7b36-11db-a8e9-0016e65f63b9}\Shell\explore\Command - "" = E:\jfvkcsy.bat -- File not found
O33 - MountPoints2\{5c2feda4-b198-11dc-ab49-0016e65f63b9}\Shell\AutoRun\command - "" = G:\sm.exe -- File not found
O33 - MountPoints2\{bc3037bd-c909-11dc-ab70-0016e65f63b9}\Shell\AutoRun\command - "" = RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
O33 - MountPoints2\{bc3037bd-c909-11dc-ab70-0016e65f63b9}\Shell\open\command - "" = RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
O33 - MountPoints2\{d656f892-ec4a-11dc-aba5-0016e65f63b9}\Shell\autorun\command - "" = ranvrgn.exe
O33 - MountPoints2\{d656f892-ec4a-11dc-aba5-0016e65f63b9}\Shell\explore\command - "" = ranvrgn.exe
O33 - MountPoints2\{d656f892-ec4a-11dc-aba5-0016e65f63b9}\Shell\open\command - "" = ranvrgn.exe
O33 - MountPoints2\{e513752c-5342-11dd-ac83-0016e65f63b9}\Shell\AutoRun\command - "" = ngp8l.exe
O33 - MountPoints2\{e513752c-5342-11dd-ac83-0016e65f63b9}\Shell\open\Command - "" = ngp8l.exe
@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}
:Files
C:\Program Files\DAEMON Tools Toolbar
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
C:\Documents and Settings\Ja\Menu Start\Programy\Autostart\Adobe Gamma.lnk
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"nwiz"=-
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4C4E7CDB-5BFC-4D74-83E2-8AE659B7EDA2} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O24 - Desktop Components:0 (Privacy Protection) -
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\awtrOfcD) - File not found
O28 - HKLM ShellExecuteHooks: {EEC73EA5-1367-49D1-93F4-CA1D8C22E9F9} - Reg Error: Key error. File not found
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD"=-
"NeroFilterCheck"=-
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników