
Log Gmar
http://www.wklej.eu/index.php?id=4fb6a7fb48
# Log Fsrt
1) Addition
http://www.wklej.eu/index.php?id=b051c756c9
2)FRST
http://www.wklej.eu/index.php?id=ef8d278664
3)Shortcut
http://www.wklej.eu/index.php?id=ebfb0d6ec4
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2768692697-353036645-4283053521-1000\...\Run: [CMD] => cmd.exe /c start http://adverttraff.org && exit <===== ATTENTION
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X]
2014-10-07 08:58 - 2014-10-07 08:58 - 00020927 _____ () C:\ComboFix.txt
2014-10-07 08:53 - 2014-10-07 08:59 - 00000000 ____D () C:\Qoobox
2014-10-07 08:53 - 2014-10-07 08:58 - 00000000 ____D () C:\Windows\erdnt
2014-10-07 08:53 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-07 08:53 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-07 08:53 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-07 08:53 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-07 08:53 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-07 08:53 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-07 08:53 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-07 08:53 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
EmptyTemp:
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36
http://img31.otofotki.pl/up388_Bez tytulu.jpg.html
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0
Zarejestrowani użytkownicy: Bing [Bot]