
gmer
http://www.wklej.org/hash/50fa8d8d6cf/
:OTL
MOD - [2014-01-30 16:32:58 | 000,063,168 | ---- | M] () -- C:\Program Files\Mobogenie\MgAssist.exe
MOD - [2014-01-30 16:32:56 | 000,775,872 | ---- | M] () -- C:\Program Files\Mobogenie\DaemonProcess.exe
MOD - [2014-01-30 16:32:56 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobogenie\Device.dll
SRV - [2014-01-30 16:32:58 | 000,063,168 | ---- | M] () [Auto | Running] -- C:\Program Files\Mobogenie\MgAssist.exe -- (MgAssistService)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDRm.sys -- (InCDRm)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDPass.sys -- (InCDPass)
DRV - File not found [File_System | Disabled | Stopped] -- system32\drivers\InCDFs.sys -- (InCDFs)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleXNt.sys -- (EagleXNt)
O4 - HKLM..\Run: [fst_pl_41] File not found
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe ()
O4 - HKLM..\Run: [upfst_pl_41.exe] C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\fst_pl_41\upfst_pl_41.exe -runhelper File not found
[2014-02-09 15:54:08 | 000,000,000 | ---D | C] -- C:\Program Files\predm
[2014-02-09 15:53:36 | 000,017,280 | ---- | C] (Systweak Inc., (www.systweak.com)) -- C:\WINDOWS\System32\roboot.exe
[2014-02-09 15:53:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Dane aplikacji\systweak
[2014-02-03 15:09:54 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab
[2014-02-03 15:09:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService
[2014-02-03 15:09:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\WP
[2014-01-12 20:41:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\.android
[2014-01-12 20:41:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\cache
[2014-01-12 20:41:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\genienext
[2014-01-12 20:41:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\Mobogenie
[2014-01-12 20:41:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Moje dokumenty\Mobogenie
[2014-01-12 20:40:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Menu Start\Programy\Mobogenie
[2014-01-12 20:40:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mobogenie
[2014-02-03 21:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ja\Dane aplikacji\awesomehp
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com/"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-1708537768-1979792683-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-1708537768-1979792683-725345543-1003\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com/"
[HKEY_USERS\S-1-5-21-1708537768-1979792683-725345543-1003\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
:Commands
[emptytemp]
:OTL
MOD - [2014-01-30 16:32:58 | 000,063,168 | ---- | M] () -- C:\Program Files\Mobogenie\MgAssist.exe
MOD - [2014-01-30 16:32:56 | 000,775,872 | ---- | M] () -- C:\Program Files\Mobogenie\DaemonProcess.exe
MOD - [2014-01-30 16:32:56 | 000,061,440 | ---- | M] () -- C:\Program Files\Mobogenie\Device.dll
SRV - [2014-01-30 16:32:58 | 000,063,168 | ---- | M] () [Auto | Running] -- C:\Program Files\Mobogenie\MgAssist.exe -- (MgAssistService)
[2014-01-12 20:41:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\Mobogenie
[2014-01-12 20:41:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Moje dokumenty\Mobogenie
[2014-01-12 20:40:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Menu Start\Programy\Mobogenie
[2014-01-12 20:40:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mobogenie
:Commands
[emptytemp]
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fst_pl_41"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mobilegeni daemon"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"upfst_pl_41.exe"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com/"
:OTL
[2014-02-09 15:54:08 | 000,000,000 | ---D | C] -- C:\Program Files\predm
[2014-02-09 15:53:36 | 000,017,280 | ---- | C] (Systweak Inc., (www.systweak.com)) -- C:\WINDOWS\System32\roboot.exe
[2014-02-09 15:53:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Dane aplikacji\systweak
[2014-02-03 15:09:54 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab
[2014-02-03 15:09:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService
[2014-02-03 15:09:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\WPM
[2014-02-03 15:09:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ja\Dane aplikacji\awesomehp
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleXNt.sys -- (EagleXNt)
:Commands
[emptytemp]
Windows Registry Editor Version 5.00
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-1708537768-1979792683-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
Reg: reg add "HKLM\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S4 InCDFs; system32\drivers\InCDFs.sys [X]
S1 InCDPass; system32\drivers\InCDPass.sys [X]
S1 InCDRm; system32\drivers\InCDRm.sys [X]
C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\genienext
C:\Documents and Settings\ja\Ustawienia lokalne\Dane aplikacji\cache
C:\Documents and Settings\ja\.android
C:\Documents and Settings\ja\daemonprocess.txt
C:\Documents and Settings\ja\Dane aplikacji\0D1F1S1C1P0P1C1F1N1C1T1H2UtF1E1I
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 40 gości