
Logi w załącznikach.
@Alternate Data Stream - 168 bytes -> C:\Users\Xxx\Desktop\dowww.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 168 bytes -> C:\Users\Xxx\Desktop\dowod.jpg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 168 bytes -> C:\Users\Xxx\Desktop\dow.jpeg:3or4kl4x13tuuug3Byamue2s4b
:OTL
[2013-12-21 20:54:43 | 000,000,000 | ---D | C] -- C:\Users\Xxx\.android
[2013-12-21 20:54:41 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Local\cache
[2013-12-21 20:54:40 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\newnext.me
[2013-12-21 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Local\genienext
[2013-12-21 20:54:37 | 000,000,000 | ---D | C] -- C:\Users\Xxx\Documents\Mobogenie
[2013-12-21 20:54:37 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Local\Mobogenie
[2013-12-21 20:53:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobogenie
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKU\S-1-5-21-4012519471-1284521655-1563197006-1001..\Run: [] File not found
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = c:\windows\temp\install\alg.exe
O7 - HKU\S-1-5-21-4012519471-1284521655-1563197006-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = c:\windows\temp\install\alg.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 10.45.2)
O16 - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 1.7.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 10.45.2)
[2013-12-22 08:55:33 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\newnext.me
@Alternate Data Stream - 168 bytes -> C:\Users\Xxx\Desktop\dowww.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 168 bytes -> C:\Users\Xxx\Desktop\dowod.jpg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 168 bytes -> C:\Users\Xxx\Desktop\dow.jpeg:3or4kl4x13tuuug3Byamue2s4b
:Reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-4012519471-1284521655-1563197006-1001\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-4012519471-1284521655-1563197006-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 4 gości