:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\Senfilt.sys -- (SenFiltService)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\admin\USTAWI~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\AEAudio.sys -- (AEAudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
IE - HKU\S-1-5-21-1409082233-630328440-839522115-1004\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://dl.ask.com/toolbarv/askRedirect.jsp?gct=&gc=1&q={searchTerms}&crm=1&toolbar=GLS
O4 - HKU\S-1-5-21-1409082233-630328440-839522115-1004..\RunOnce: [6F63A5AB0062C46900087E8081CB3F95] C:\Documents and Settings\All Users\Dane aplikacji\6F63A5AB0062C46900087E8081CB3F95\6F63A5AB0062C46900087E8081CB3F95.exe ()
O37 - HKU\S-1-5-21-1409082233-630328440-839522115-1004\...exe [@ = exefile] -- Reg Error: Key error. File not found
[2012-08-02 22:39:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Menu Start\Programy\Live Security Platinum
[2012-08-02 22:39:28 | 000,002,248 | ---- | M] () -- C:\Documents and Settings\admin\Pulpit\Live Security Platinum.lnk
[2010-03-17 15:12:17 | 000,009,896 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\3yye
[2010-03-17 15:12:17 | 000,009,896 | -HS- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\3yye
:Files
C:\Windows\system32\fsutil.exe reparsepoint delete C:\WINDOWS\$NtUninstallKB7336$ /c
C:\WINDOWS\$NtUninstallKB7336$
C:\Documents and Settings\All Users\Dane aplikacji\6F63A5AB0062C46900087E8081CB3F95
:Reg
[-HKEY_USERS\S-1-5-21-1409082233-630328440-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum]
:Commands
[emptytemp]
HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
/md5start
services.exe
/md5stop
:OTL
O4 - HKU\S-1-5-21-1409082233-630328440-839522115-1004..\RunOnce: [6F63A5AB0062C46900087E8081CB3F95] C:\Documents and Settings\All Users\Dane aplikacji\6F63A5AB0062C46900087E8081CB3F95\6F63A5AB0062C46900087E8081CB3F95.exe ()
[2012-08-02 22:39:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Menu Start\Programy\Live Security Platinum
[2012-08-02 22:39:27 | 000,002,248 | ---- | C] () -- C:\Documents and Settings\admin\Pulpit\Live Security Platinum.lnk
:Files
C:\Documents and Settings\All Users\Dane aplikacji\6F63A5AB0062C46900087E8081CB3F95
:Reg
[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum]
:Commands
[emptytemp]
reg delete HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /f
reg add HKLM\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32 /ve /t REG_EXPAND_SZ /d ^%systemroot^%\system32\wbem\wbemess.dll /f
:Files
C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\{93a7c1ec-8107-a19d-8258-76495b6329e3}
C:\WINDOWS\Installer\{93a7c1ec-8107-a19d-8258-76495b6329e3}
C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\98657b32
C:\WINDOWS\$NtUninstallKB7336$
:Commands
[emptytemp]
HKEY_CURRENT_USER\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s
Zidentyfikowani użytkownicy: Alexa [Bot], Bing [Bot], Google [Bot], Google Adsense [Bot], manieKMP