

wmic logicaldisk get caption,volumename
F:
autoruns.exe
:OTL
O4 - HKU\S-1-5-21-4231043965-2128743055-2275361071-1000..\Run: [lrwknktsnlrwutk] C:\ProgramData\lrwknkts.exe (RedFox)
O4 - HKU\S-1-5-21-4231043965-2128743055-2275361071-1000..\Run: [MSIDLL] C:\Windows\SysWOW64\rundll32.exe msihbu32.dll,SljeaKb File not found
O4 - HKU\S-1-5-21-4231043965-2128743055-2275361071-1000..\Run: [Ygytl] C:\Users\Jaga\AppData\Roaming\Ziixqy\emyre.exe ()
[2012/09/14 15:04:09 | 000,000,000 | ---D | C] -- C:\ProgramData\augivlbmnwkfjpb
[2012/09/14 13:39:53 | 000,000,000 | ---D | C] -- C:\Users\Jaga\AppData\Roaming\Ziixqy
[2012/09/14 13:39:53 | 000,000,000 | ---D | C] -- C:\Users\Jaga\AppData\Roaming\Piboy
[2012/09/14 13:39:53 | 000,000,000 | ---D | C] -- C:\Users\Jaga\AppData\Roaming\Evhi
[2012/09/14 15:04:10 | 000,078,031 | ---- | M] () -- C:\ProgramData\zyghgszrzljmgct
[2011/04/09 19:03:26 | 000,000,000 | -HSD | M] -- C:\Users\Jaga\AppData\Roaming\.#
:Commands
[emptytemp]
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=ins&from=ins&uid=132693_1050624_10150845_3219913727_BE448AF1&ts=1342384878
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=ins&from=ins&uid=132693_1050624_10150845_3219913727_BE448AF1&ts=1342384878
IE - HKU\S-1-5-21-4231043965-2128743055-2275361071-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=ins&from=ins&uid=132693_1050624_10150845_3219913727_BE448AF1&ts=1342384878
IE - HKU\S-1-5-21-4231043965-2128743055-2275361071-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKU\S-1-5-21-4231043965-2128743055-2275361071-1000\..\URLSearchHook: {90eee664-34b1-422a-a782-779af65cdf6d} - No CLSID value found
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości