:Processes
killallprocesses
:OTL
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\otslp.sys -- (asc3360pr)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\otslp.sys -- (amsint32)
IE - HKU\S-1-5-21-515967899-1935655697-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-515967899-1935655697-839522115-1003\..\URLSearchHook: {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.)
[2010-07-26 22:11:32 | 000,000,000 | ---D | M] (Softonic-Polska Toolbar) -- C:\Documents and Settings\Krystian\Dane aplikacji\Mozilla\Firefox\Profiles\urw4cete.default\extensions\{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}
[2010-06-08 11:30:50 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Krystian\Dane aplikacji\Mozilla\Firefox\Profiles\urw4cete.default\searchplugins\conduit.xml
O2 - BHO: (Softonic-Polska Toolbar) - {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic-Polska Toolbar) - {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.)
O32 - AutoRun File - [2010-07-26 18:28:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010-07-26 20:53:44 | 000,000,262 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-07-26 20:53:44 | 000,000,247 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{37d8b67d-98d3-11df-a5fd-cdf0c283089b}\Shell\AutoplAy\cOmmanD - "" = F:\xteo.exe -- File not found
O33 - MountPoints2\{37d8b67d-98d3-11df-a5fd-cdf0c283089b}\Shell\AutoRun\command - "" = F:\xteo.exe -- File not found
O33 - MountPoints2\{37d8b67d-98d3-11df-a5fd-cdf0c283089b}\Shell\ExplorE\COMMand - "" = F:\xteo.exe -- File not found
O33 - MountPoints2\{37d8b67d-98d3-11df-a5fd-cdf0c283089b}\Shell\opeN\comMaNd - "" = F:\xteo.exe -- File not found
:Files
C:\Documents and Settings\Krystian\Pulpit\ElfBotNG.4.5.9.Final.Crack.by.EvOlUtIoN
C:\Program Files\Softonic-Polska
C:\Documents and Settings\Krystian\Ustawienia lokalne\Dane aplikacji\Softonic-Polska
C:\Program Files\Conduit
C:\Documents and Settings\Krystian\Ustawienia lokalne\Dane aplikacji\Conduit
C:\Documents and Settings\Krystian\Pulpit\ElfBot NG
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winrdfun.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winqotxl.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winccpvs.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winptpg.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\vcolq.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winjeit.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\windjxlqt.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winxnkxvq.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winobxs.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\wingiiqy.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winsfbct.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\jmbri.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\mvdt.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winloikq.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winquhey.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\lgkwi.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\winqhhm.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\ronih.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\windvpyfi.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\mfxwfn.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\jlgqg.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\kiptuf.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\hkhad.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\uxhts.exe"=-
"C:\DOCUME~1\Krystian\USTAWI~1\Temp\gfhxhu.exe"=-
:Commands
[emptytemp]
[clearallrestorepoints]