
:OTL
PRC - [2012-03-06 03:13:05 | 000,890,368 | ---- | M] (X-Ways Software Technology AG) -- C:\Windows\Temp\_ex-68.exe
PRC - [2012-03-06 03:12:40 | 000,106,496 | ---- | M] () -- C:\Users\Dawid\AppData\Roaming\dgt.exe
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1082201271-966747228-3278269991-1004..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
[2012-02-08 21:08:38 | 000,000,000 | -HSD | C] -- C:\found.000
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[resethosts]
[emptytemp]
[emptyflash]
:OTL
O4 - HKLM..\Run: [MozillaAgent] C:\Windows\Temp\_ex-68.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O37 - HKU\S-1-5-21-1082201271-966747228-3278269991-1000\...exe [@ = B7E85] -- "C:\Windows\Temp\d2ga.exe" -s "%1" %*
:Commands
[emptytemp]
[emptyflash]
:OTL
PRC - [2012-03-06 03:12:40 | 000,106,496 | ---- | M] () -- C:\Users\Dawid\AppData\Roaming\dgt.exe
MOD - [2012-03-08 17:24:36 | 000,020,480 | ---- | M] () -- C:\Users\Dawid\AppData\Local\Temp\C8CC.tmp
[2012-03-08 17:08:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1082201271-966747228-3278269991-1000UA.job
[2012-03-08 16:08:03 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1082201271-966747228-3278269991-1000Core.job
:Commands
[emptytemp]
[emptyflash]
Files to delete:
C:\Users\Dawid\AppData\Roaming\dgt.exe
C:\Users\Dawid\AppData\Local\Temp\C5DF.tmp
C:\Users\Dawid\AppData\Local\Temp\C3AB.tmp
C:\ProgramData\B7E85886000151F51D6D2265B4EB2367\B7E85886000151F51D6D2265B4EB2367.exe
C:\Users\Dawid\AppData\Local\Temp\C3AC.tmp
D:\Download\album.exe
Folders to delete:
C:\ProgramData\B7E85886000151F51D6D2265B4EB2367
C:\Users\Dawid\AppData\Local\Temp
[2012-03-08 22:28:32 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\zofrwjo.sys
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 24 gości