Witam. Mam problem Spyware Doctor wykrywa i usuwa Adware.Agent.ZO jednak po ponownym uruchomieniu komputera i skanowaniu plików problem powraca i tak już od tygodnia.Jaj skanowałe pliki mks-em online, nic nie wykrywał.Często też samoistnie zaczyna mi się instalować program AntyVirus 2010. Prosze o poradę dodam tylko że nie mam dużego doświadczenia z komputerem.
OTL logfile created on: 2009-09-27 19:31:38 - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Właściciel\Moje dokumenty
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
2,00 Gb Total Physical Memory | 1,47 Gb Available Physical Memory | 73,38% Memory free
3,85 Gb Paging File | 3,24 Gb Available in Paging File | 84,19% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 49,32 Gb Total Space | 28,72 Gb Free Space | 58,24% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JA-1C5AE935FE48
Current User Name: Właściciel
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2009-09-11 20:49:18 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008-02-28 02:53:22 | 00,098,984 | ---- | M] (Lexmark International, Inc.) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe
PRC - [2008-02-28 02:53:25 | 00,594,600 | ---- | M] ( ) – C:\WINDOWS\System32\lxdxcoms.exe
PRC - [2009-02-09 07:18:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe
PRC - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2008-04-15 14:00:00 | 00,032,768 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\snmp.exe
PRC - [2008-04-15 14:00:00 | 01,035,264 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2008-12-08 13:33:48 | 01,173,384 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2008-08-15 05:13:26 | 30,003,200 | R— | M] (VIA Technologies, Inc.) – C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
PRC - [2008-06-13 18:04:01 | 00,668,328 | ---- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2008-06-13 18:04:02 | 00,025,256 | ---- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
PRC - [2009-09-11 20:49:18 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2007-06-27 19:03:40 | 00,152,872 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2009-07-14 21:56:42 | 00,039,408 | ---- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
PRC - [2007-06-27 19:04:00 | 01,213,736 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2008-04-07 09:17:30 | 00,430,592 | ---- | M] (Nokia.) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2008-03-10 09:58:18 | 00,130,560 | ---- | M] () – C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2008-02-22 09:11:02 | 00,120,320 | ---- | M] () – C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009-========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32*.tmp files]
[6 C:\WINDOWS*.tmp files]
[2009-09-27 19:31:19 | 00,514,560 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe
[2009-09-27 19:17:08 | 00,210,919 | ---- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009-09-27 19:17:04 | 00,001,032 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009-09-27 19:16:44 | 00,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT
[2009-09-27 19:16:42 | 00,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat
[2009-09-27 19:16:40 | 00,010,752 | ---- | M] () – C:\WINDOWS\System32\braviax.exe
[2009-09-27 13:51:00 | 00,001,036 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009-09-27 11:46:47 | 00,019,060 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\fodipaludo.vbs
[2009-09-27 11:46:47 | 00,018,888 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\luqepo.bin
[2009-09-27 11:46:47 | 00,018,254 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\perop.exe
[2009-09-27 11:46:47 | 00,013,725 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\tanidu.inf
[2009-09-27 11:46:47 | 00,012,579 | ---- | M] () – C:\Program Files\Common Files\etoxura._sy
[2009-09-27 11:46:47 | 00,011,458 | ---- | M] () – C:\WINDOWS\zuju.dl
[2009-09-27 11:46:46 | 00,019,856 | ---- | M] () – C:\Documents and Settings\All Users\Dokumenty\rivicot.pif
[2009-09-27 11:46:46 | 00,019,385 | ---- | M] () – C:\WINDOWS\evec.dl
[2009-09-27 11:46:46 | 00,018,635 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\cepoped.pif
[2009-09-27 11:46:46 | 00,018,210 | ---- | M] () – C:\Documents and Settings\All Users\Dokumenty\yjyg._dl
[2009-09-27 11:46:46 | 00,018,136 | ---- | M] () – C:\WINDOWS\System32\otahusadym.inf
[2009-09-27 11:46:46 | 00,016,738 | ---- | M] () – C:\WINDOWS\jymixyz.bin
[2009-09-27 11:46:46 | 00,016,653 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\icuz.inf
[2009-09-27 11:46:46 | 00,016,039 | ---- | M] () – C:\WINDOWS\yrirely.exe
[2009-09-27 11:46:46 | 00,014,486 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\avynypek.dat
[2009-09-27 11:46:46 | 00,014,090 | ---- | M] () – C:\WINDOWS\uxeg._dl
[2009-09-27 11:46:46 | 00,014,050 | ---- | M] () – C:\WINDOWS\yjasan.com
[2009-09-27 11:46:46 | 00,012,929 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\wuwot.bin
[2009-09-27 11:46:46 | 00,012,745 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ypovar.db
[2009-09-27 11:46:46 | 00,012,109 | ---- | M] () – C:\WINDOWS\ogoj.exe
[2009-09-27 11:46:46 | 00,011,948 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ymyb.sys
[2009-09-27 11:46:46 | 00,010,997 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\inevukeqy.bin
[2009-09-27 11:46:46 | 00,010,213 | ---- | M] () – C:\Documents and Settings\All Users\Dokumenty\agefebose.reg
[2009-09-27 11:46:46 | 00,010,119 | ---- | M] () – C:\WINDOWS\ofum.sys
[2009-09-27 11:46:46 | 00,010,067 | ---- | M] () – C:\WINDOWS\vodax.reg
[2009-09-27 11:42:57 | 02,804,430 | -H-- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-09-27 03:36:58 | 00,167,936 | ---- | M] (Legal Corporation) – C:\WINDOWS\System32_scui.cpl
[2009-09-26 19:14:29 | 00,002,267 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2009-09-26 14:18:53 | 00,013,722 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009-09-23 20:14:57 | 00,159,856 | ---- | M] (TheBestSoft Corporation) – C:\WINDOWS\System32\wisdstr.exe
[2009-09-19 13:53:04 | 00,001,813 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk
[2009-09-19 11:07:57 | 00,000,069 | ---- | M] () – C:\WINDOWS\NeroDigital.ini
[2009-09-18 21:24:27 | 00,028,672 | ---- | M] () – C:\WINDOWS\System32\drivers\beep.sys
[2009-09-11 21:18:23 | 00,001,655 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk
[2009-09-11 20:18:12 | 00,001,374 | ---- | M] () – C:\WINDOWS\imsins.BAK
[2009-09-11 20:07:33 | 00,019,915 | ---- | M] () – C:\WINDOWS\adevaz.vbs
[2009-09-11 20:07:33 | 00,019,506 | ---- | M] () – C:\WINDOWS\System32\axuxonalu.dat
[2009-09-11 20:07:33 | 00,018,374 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\epykokoh.bin
[2009-09-11 20:07:33 | 00,016,956 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\lyfip.dat
[2009-09-11 20:07:33 | 00,015,967 | ---- | M] () – C:\Program Files\Common Files\tewuxyp.reg
[2009-09-11 20:07:33 | 00,015,757 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ihuxuwiqoq.ban
[2009-09-11 20:07:33 | 00,015,674 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\xabykofohe.dl
[2009-09-11 20:07:33 | 00,015,438 | ---- | M] () – C:\WINDOWS\fiqoza.db
[2009-09-11 20:07:33 | 00,014,647 | ---- | M] () – C:\WINDOWS\System32\rihemyn._dl
[2009-09-11 20:07:33 | 00,014,276 | ---- | M] () – C:\Program Files\Common Files\eniwebu._sy
[2009-09-11 20:07:33 | 00,013,856 | ---- | M] () – C:\WINDOWS\System32\ozuxusa.pif
[2009-09-11 20:07:33 | 00,013,401 | ---- | M] () – C:\WINDOWS\isipyj.reg
[2009-09-11 20:07:33 | 00,013,303 | ---- | M] () – C:\WINDOWS\System32\cyjiwejoz.dl
[2009-09-11 20:07:33 | 00,013,193 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ekys.lib
[2009-09-11 20:07:33 | 00,012,835 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\wixyvug.sys
[2009-09-11 20:07:33 | 00,012,805 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\pyma.dat
[2009-09-11 20:07:33 | 00,012,784 | ---- | M] () – C:\WINDOWS\salajygyci._sy
[2009-09-11 20:07:33 | 00,012,148 | ---- | M] () – C:\WINDOWS\uvikecyna.dat
[2009-09-11 20:07:33 | 00,011,401 | ---- | M] () – C:\WINDOWS\igohog.exe
[2009-09-11 20:07:33 | 00,010,335 | ---- | M] () – C:\WINDOWS\agexupek.dat
[2009-09-11 20:07:33 | 00,010,025 | ---- | M] () – C:\Program Files\Common Files\anuwul.vbs
[2009-09-11 17:53:30 | 00,002,596 | ---- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009-09-11 15:22:05 | 01,114,842 | ---- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009-09-11 15:22:05 | 00,499,854 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat
[2009-09-11 15:22:05 | 00,440,820 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009-09-11 15:22:05 | 00,089,036 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat
[2009-09-11 15:22:05 | 00,071,138 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009-09-11 14:36:25 | 00,100,640 | ---- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009-09-10 22:18:49 | 00,018,187 | ---- | M] () – C:\WINDOWS\System32\peqac.sys
[2009-09-10 22:18:49 | 00,017,619 | ---- | M] () – C:\WINDOWS\epyfij.reg
[2009-09-10 22:18:49 | 00,015,955 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\gakemyroj.db
[2009-09-10 22:18:49 | 00,015,818 | ---- | M] () – C:\Program Files\Common Files\yfojones.inf
[2009-09-10 22:18:49 | 00,013,702 | ---- | M] () – C:\WINDOWS\System32\xexi.bat
[2009-09-10 22:18:49 | 00,013,587 | ---- | M] () – C:\WINDOWS\egimyxehyq.com
[2009-09-10 22:18:47 | 00,018,346 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\mibebeceji.bat
[2009-09-10 22:18:47 | 00,017,380 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\uhaxaw.reg
[2009-09-10 22:18:47 | 00,013,802 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\exomydotu.db
[2009-09-10 22:18:47 | 00,010,379 | ---- | M] () – C:\WINDOWS\System32\ruzuby.db
[2009-09-10 22:18:46 | 00,019,262 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\evuliqide.exe
[2009-09-10 22:18:46 | 00,018,337 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\ujywiret.sys
[2009-09-10 22:18:46 | 00,017,782 | ---- | M] () – C:\WINDOWS\System32\esijil.db
[2009-09-10 22:18:46 | 00,015,764 | ---- | M] () – C:\WINDOWS\amiw.db
[2009-09-10 22:18:46 | 00,015,297 | ---- | M] () – C:\WINDOWS\ibeb.db
[2009-09-10 22:18:46 | 00,012,087 | ---- | M] () – C:\Program Files\Common Files\vukefaqor.exe
[2009-09-10 22:18:46 | 00,011,950 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\okexoq.dat
[2009-09-10 22:18:46 | 00,011,635 | ---- | M] () – C:\Program Files\Common Files\osesyv.dll
[2009-09-10 21:52:48 | 00,025,748 | ---- | M] () – C:\WINDOWS\System32$winnt$.inf
[2009-09-10 21:49:45 | 00,316,640 | ---- | M] () – C:\WINDOWS\WMSysPr9.prx
[2009-09-10 21:49:44 | 00,023,392 | ---- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2009-09-10 21:49:44 | 00,016,832 | ---- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2009-09-10 21:49:34 | 00,004,293 | ---- | M] () – C:\WINDOWS\ODBCINST.INI
[2009-09-10 21:48:48 | 00,000,488 | RH-- | M] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2009-09-10 21:48:48 | 00,000,488 | RH-- | M] () – C:\WINDOWS\System32\logonui.exe.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\WindowsShell.Manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2009-09-10 21:48:35 | 00,000,507 | ---- | M] () – C:\WINDOWS\win.ini
[2009-09-10 21:48:09 | 00,023,640 | ---- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2009-09-10 21:44:55 | 00,000,211 | -HS- | M] () – C:\boot.ini
[2009-09-10 21:34:30 | 00,005,208 | ---- | M] () – C:\WINDOWS\System32\pid.PNF
[2009-09-10 21:34:23 | 00,000,231 | ---- | M] () – C:\WINDOWS\system.ini
[2009-09-10 21:19:05 | 00,878,141 | ---- | M] () – C:\WINDOWS\setupapi.old
[2009-09-10 20:12:47 | 00,019,574 | ---- | M] () – C:\WINDOWS\System32\zomisumilo.lib
[2009-09-10 20:12:47 | 00,018,949 | ---- | M] () – C:\WINDOWS\vajynoxewa._dl
[2009-09-10 20:12:47 | 00,018,335 | ---- | M] () – C:\WINDOWS\ketusenub.db
[2009-09-10 20:12:47 | 00,017,484 | ---- | M] () – C:\Program Files\Common Files\okugy.com
[2009-09-10 20:12:47 | 00,015,977 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\salu.sys
[2009-09-10 20:12:47 | 00,015,310 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\yjadyp.db
[2009-09-10 20:12:47 | 00,014,136 | ---- | M] () – C:\WINDOWS\System32\cyrevy._sy
[2009-09-10 20:12:47 | 00,013,695 | ---- | M] () – C:\Program Files\Common Files\ydedabu.pif
[2009-09-10 20:12:47 | 00,012,819 | ---- | M] () – C:\WINDOWS\ganeromus.reg
[2009-09-10 20:12:47 | 00,011,635 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\ojar.scr
[2009-09-10 20:12:47 | 00,011,070 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuro.lib
[2009-09-10 20:12:47 | 00,010,777 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll
[2009-09-10 20:12:47 | 00,010,548 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll
[2009-09-10 20:12:47 | 00,010,264 | ---- | M] () – C:\WINDOWS\System32\miju.lib
[2009-09-08 22:48:32 | 00,019,858 | ---- | M] () – C:\WINDOWS\rybeginude.inf
[2009-09-08 22:48:32 | 00,018,887 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\povevo.lib
[2009-09-08 22:48:32 | 00,018,541 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ixuduhemip.bin
[2009-09-08 22:48:32 | 00,018,286 | ---- | M] () – C:\WINDOWS\ypygim.bat
[2009-09-08 22:48:32 | 00,018,255 | ---- | M] () – C:\WINDOWS\wirofu._sy
[2009-09-08 22:48:32 | 00,017,241 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\isofit.db
[2009-09-08 22:48:32 | 00,014,929 | ---- | M] () – C:\WINDOWS\System32\topubopa._dl
[2009-09-08 22:48:32 | 00,013,979 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\gujatexy.ban
[2009-09-08 22:48:32 | 00,013,841 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\yremu.db
[2009-09-08 22:48:32 | 00,013,323 | ---- | M] () – C:\Program Files\Common Files\decy.lib
[2009-09-08 22:48:32 | 00,012,824 | ---- | M] () – C:\WINDOWS\vucolywo.lib
[2009-09-08 22:48:32 | 00,012,592 | ---- | M] () – C:\WINDOWS\fujufit.bat
[2009-09-08 22:48:32 | 00,012,555 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll
[2009-09-08 22:48:32 | 00,011,787 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\bomyvik._sy
[2009-09-08 22:48:32 | 00,011,398 | ---- | M] () – C:\WINDOWS\hygucucono.reg
[2009-09-08 22:48:32 | 00,011,085 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\oper.vbs
[2009-09-08 22:48:31 | 00,013,595 | ---- | M] () – C:\WINDOWS\System32\ifujohufo.dl
[2009-09-08 21:55:39 | 00,019,969 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\yhutiwym.dat
[2009-09-08 21:55:39 | 00,019,741 | ---- | M] () – C:\WINDOWS\ehefoxiku.dat
[2009-09-08 21:55:39 | 00,019,689 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\debohagi.dl
[2009-09-08 21:55:39 | 00,019,512 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\javani.vbs
[2009-09-08 21:55:39 | 00,018,674 | ---- | M] () – C:\WINDOWS\yqopose._dl
[2009-09-08 21:55:39 | 00,018,339 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\oqyvuru.bat
[2009-09-08 21:55:39 | 00,016,338 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ehisegidun.com
[2009-09-08 21:55:39 | 00,015,417 | ---- | M] () – C:\Program Files\Common Files\sewofybek.ban
[2009-09-08 21:55:39 | 00,014,763 | ---- | M] () – C:\WINDOWS\emogiqykas.lib
[2009-09-08 21:55:39 | 00,013,500 | ---- | M] () – C:\WINDOWS\desype.dll
[2009-09-08 21:55:39 | 00,013,078 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\uhiquwubaz.sys
[2009-09-08 21:55:39 | 00,013,010 | ---- | M] () – C:\WINDOWS\System32\zyky.sys
[2009-09-08 21:55:39 | 00,012,467 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\emumahidof.ban
[2009-09-08 21:55:39 | 00,012,261 | ---- | M] () – C:\WINDOWS\System32\lykymofezi.dll
[2009-09-08 21:55:39 | 00,012,203 | ---- | M] () – C:\Program Files\Common Files\rozina.inf
[2009-09-08 21:55:39 | 00,012,028 | ---- | M] () – C:\WINDOWS\System32\finy.ban
[2009-09-08 21:55:39 | 00,011,962 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ybexeb.bat
[2009-09-08 21:55:39 | 00,011,569 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\ryxyg.pif
[2009-09-08 21:55:39 | 00,011,078 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\gikazycu.vbs
[2009-09-08 21:55:39 | 00,010,753 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\wadypex.vbs
[2009-09-08 21:55:39 | 00,010,517 | ---- | M] () – C:\WINDOWS\System32\oqudodyx.bin
[2009-09-08 21:55:39 | 00,010,226 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ujajyrul.bat
[2009-09-08 21:51:38 | 00,019,906 | ---- | M] () – C:\WINDOWS\owad.dll
[2009-09-08 21:51:38 | 00,019,530 | ---- | M] () – C:\WINDOWS\usovypu.dll
[2009-09-08 21:51:38 | 00,018,338 | ---- | M] () – C:\Program Files\Common Files\ibew._sy
[2009-09-08 21:51:38 | 00,016,047 | ---- | M] () – C:\WINDOWS\hazakim.dll
[2009-09-08 21:51:38 | 00,015,900 | ---- | M] () – C:\WINDOWS\ydojures.inf
[2009-09-08 21:51:38 | 00,015,236 | ---- | M] () – C:\WINDOWS\gubycip.scr
[2009-09-08 21:51:38 | 00,014,718 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\zyhyzufime._sy
[2009-09-08 21:51:38 | 00,014,445 | ---- | M] () – C:\WINDOWS\ocuqajojam._sy
[2009-09-08 21:51:38 | 00,013,933 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\hebyrakyfi.dat
[2009-09-08 21:51:38 | 00,013,716 | ---- | M] () – C:\WINDOWS\ilibidabud._sy
[2009-09-08 21:51:38 | 00,013,071 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ymimacyf.bat
[2009-09-08 21:51:38 | 00,012,180 | ---- | M] () – C:\WINDOWS\ylexyzi.dat
[2009-09-08 21:51:38 | 00,012,177 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\bezuz.ban
[2009-09-08 21:51:38 | 00,012,007 | ---- | M] () – C:\WINDOWS\axovuq.dll
[2009-09-08 21:51:38 | 00,011,880 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cujoce.vbs
[2009-09-08 21:51:38 | 00,011,242 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ecerycakyr._dl
[2009-09-08 21:51:38 | 00,010,983 | ---- | M] () – C:\WINDOWS\System32\jifu.dl
[2009-09-08 21:51:38 | 00,010,191 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\turykeki.sys
[2009-09-08 20:49:18 | 00,018,532 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\ybasesalev.bin
[2009-09-08 20:49:18 | 00,016,927 | ---- | M] () – C:\WINDOWS\gilamefyx.pif
[2009-09-08 20:49:18 | 00,013,802 | ---- | M] () – C:\WINDOWS\sysejev.sys
[2009-09-08 20:49:18 | 00,012,709 | ---- | M] () – C:\Program Files\Common Files\ukax._sy
[2009-09-08 20:49:18 | 00,010,708 | ---- | M] () – C:\Program Files\Common Files\exowy.dl
[2009-09-08 20:49:17 | 00,019,778 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\rutumonys.lib
[2009-09-08 20:49:17 | 00,019,218 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\izupiqed.sys
[2009-09-08 20:49:17 | 00,016,231 | ---- | M] () – C:\Documents and Settings\All Users\Dane aplikacji\utelyquki.vbs
[2009-09-08 20:49:17 | 00,016,052 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\peby._dl
[2009-09-08 20:49:17 | 00,014,003 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\awularys.vbs
[2009-09-08 20:49:17 | 00,013,019 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\dawifi.db
[2009-09-08 20:49:17 | 00,012,046 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll
[2009-09-08 20:49:17 | 00,010,434 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuhoni.vbs
========== LOP Check ==========
[2009-09-27 11:55:27 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Dane aplikacji
[2009-06-27 11:37:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Ahead
[2009-06-18 19:33:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Aquadelic GT
[2009-08-16 10:55:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Installations
[2009-09-24 14:35:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-08-16 10:58:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
[2009-09-27 19:29:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-06-27 13:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\ThumbnailCache4R
[2009-06-15 22:16:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Default User\Dane aplikacji
[2009-09-19 09:32:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Dominik\Dane aplikacji
[2009-08-05 20:04:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Dominik\Dane aplikacji\Lexmark Productivity Studio
[2009-09-19 09:31:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Dominik\Dane aplikacji\Nowe Gadu-Gadu
[2009-08-10 10:49:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Dominik\Dane aplikacji\OpenFM
[2009-08-19 21:29:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Dominik\Dane aplikacji\PC Suite
[2009-08-22 18:06:49 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Dane aplikacji
[2009-06-15 20:27:26 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Dane aplikacji
[2009-09-27 11:46:47 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji
[2009-06-27 11:54:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Ahead
[2009-08-16 11:37:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Leadertech
[2009-06-18 18:16:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Lexmark Productivity Studio
[2009-07-26 18:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\MKS_VIR
[2009-08-16 11:04:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Nokia
[2009-09-05 20:08:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Nowe Gadu-Gadu
[2009-07-18 20:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\OpenFM
[2009-08-16 10:59:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\PC Suite
[2008-04-15 14:00:00 | 00,000,065 | RH-- | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009-09-27 19:17:04 | 00,001,032 | ---- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009-09-27 13:51:00 | 00,001,036 | ---- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009-09-27 19:16:44 | 00,000,006 | -H-- | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
< End of report >
Ależ jest tu tego.
Przy okazji daję do usunięcia “joby” Google - są zbędne i obciążają System.
Uruchom OTL i w oknie Custom Scans/Fixes wklej to:
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
:Files
C:\WINDOWS\System32\braviax.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\Documents and Settings\All Users\Dane aplikacji\fodipaludo.vbs
C:\Documents and Settings\Właściciel\Dane aplikacji\luqepo.bin
C:\Documents and Settings\All Users\Dane aplikacji\perop.exe
C:\Documents and Settings\All Users\Dane aplikacji\tanidu.inf
C:\Program Files\Common Files\etoxura._sy
C:\WINDOWS\zuju.dl
C:\Documents and Settings\All Users\Dokumenty\rivicot.pif
C:\WINDOWS\evec.dl
C:\Documents and Settings\Właściciel\Dane aplikacji\cepoped.pif
C:\Documents and Settings\All Users\Dokumenty\yjyg._dl
C:\WINDOWS\System32\otahusadym.inf
C:\WINDOWS\jymixyz.bin
C:\Documents and Settings\Właściciel\Dane aplikacji\icuz.inf
C:\WINDOWS\yrirely.exe
C:\Documents and Settings\All Users\Dane aplikacji\avynypek.dat
C:\WINDOWS\uxeg._dl
C:\WINDOWS\yjasan.com
C:\Documents and Settings\All Users\Dane aplikacji\wuwot.bin
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ypovar.db
C:\WINDOWS\ogoj.exe
C:\Documents and Settings\Właściciel\Dane aplikacji\ymyb.sys
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\inevukeqy.bin
C:\Documents and Settings\All Users\Dokumenty\agefebose.reg
C:\WINDOWS\ofum.sys
C:\WINDOWS\vodax.reg
C:\WINDOWS\adevaz.vbs
C:\WINDOWS\System32\axuxonalu.dat
C:\Documents and Settings\Właściciel\Dane aplikacji\epykokoh.bin
C:\Documents and Settings\All Users\Dane aplikacji\lyfip.dat
C:\Program Files\Common Files\tewuxyp.reg
C:\Documents and Settings\Właściciel\Dane aplikacji\ihuxuwiqoq.ban
C:\Documents and Settings\Właściciel\Dane aplikacji\xabykofohe.dl
C:\WINDOWS\fiqoza.db
C:\WINDOWS\System32\rihemyn._dl
C:\Program Files\Common Files\eniwebu._sy
C:\WINDOWS\System32\ozuxusa.pif
C:\WINDOWS\isipyj.reg
C:\WINDOWS\System32\cyjiwejoz.dl
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ekys.lib
C:\Documents and Settings\Właściciel\Dane aplikacji\wixyvug.sys
C:\Documents and Settings\All Users\Dane aplikacji\pyma.dat
C:\WINDOWS\salajygyci._sy
C:\WINDOWS\uvikecyna.dat
C:\WINDOWS\igohog.exe
C:\WINDOWS\agexupek.dat
C:\Program Files\Common Files\anuwul.vbs
C:\WINDOWS\System32\peqac.sys
C:\WINDOWS\epyfij.reg
C:\Documents and Settings\Właściciel\Dane aplikacji\gakemyroj.db
C:\Program Files\Common Files\yfojones.inf
C:\WINDOWS\System32\xexi.bat
C:\WINDOWS\egimyxehyq.com
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\mibebeceji.bat
C:\Documents and Settings\Właściciel\Dane aplikacji\uhaxaw.reg
C:\Documents and Settings\All Users\Dane aplikacji\exomydotu.db
C:\WINDOWS\System32\ruzuby.db
C:\Documents and Settings\Właściciel\Dane aplikacji\evuliqide.exe
C:\Documents and Settings\All Users\Dane aplikacji\ujywiret.sys
C:\WINDOWS\System32\esijil.db
C:\WINDOWS\amiw.db
C:\WINDOWS\ibeb.db
C:\Program Files\Common Files\vukefaqor.exe
C:\Documents and Settings\Właściciel\Dane aplikacji\okexoq.dat
C:\Program Files\Common Files\osesyv.dll
C:\WINDOWS\System32\zomisumilo.lib
C:\WINDOWS\vajynoxewa._dl
C:\WINDOWS\ketusenub.db
C:\Program Files\Common Files\okugy.com
C:\Documents and Settings\All Users\Dane aplikacji\salu.sys
C:\Documents and Settings\All Users\Dane aplikacji\yjadyp.db
C:\WINDOWS\System32\cyrevy._sy
C:\Program Files\Common Files\ydedabu.pif
C:\WINDOWS\ganeromus.reg
C:\Documents and Settings\All Users\Dane aplikacji\ojar.scr
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuro.lib
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll
C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll
C:\WINDOWS\System32\miju.lib
C:\WINDOWS\rybeginude.inf
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\povevo.lib
C:\Documents and Settings\Właściciel\Dane aplikacji\ixuduhemip.bin
C:\WINDOWS\ypygim.bat
C:\WINDOWS\wirofu._sy
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\isofit.db
C:\WINDOWS\System32\topubopa._dl
C:\Documents and Settings\All Users\Dane aplikacji\gujatexy.ban
C:\Documents and Settings\All Users\Dane aplikacji\yremu.db
C:\Program Files\Common Files\decy.lib
C:\WINDOWS\vucolywo.lib
C:\WINDOWS\fujufit.bat
C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll
C:\Documents and Settings\Właściciel\Dane aplikacji\bomyvik._sy
C:\WINDOWS\hygucucono.reg
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\oper.vbs
C:\WINDOWS\System32\ifujohufo.dl
C:\Documents and Settings\All Users\Dane aplikacji\yhutiwym.dat
C:\WINDOWS\ehefoxiku.dat
C:\Documents and Settings\Właściciel\Dane aplikacji\debohagi.dl
C:\Documents and Settings\All Users\Dane aplikacji\javani.vbs
C:\WINDOWS\yqopose._dl
C:\Documents and Settings\Właściciel\Dane aplikacji\oqyvuru.bat
C:\Documents and Settings\Właściciel\Dane aplikacji\ehisegidun.com
C:\Program Files\Common Files\sewofybek.ban
C:\WINDOWS\emogiqykas.lib
C:\WINDOWS\desype.dll
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\uhiquwubaz.sys
C:\WINDOWS\System32\zyky.sys
C:\Documents and Settings\Właściciel\Dane aplikacji\emumahidof.ban
C:\WINDOWS\System32\lykymofezi.dll
C:\Program Files\Common Files\rozina.inf
C:\WINDOWS\System32\finy.ban
C:\Documents and Settings\Właściciel\Dane aplikacji\ybexeb.bat
C:\Documents and Settings\All Users\Dane aplikacji\ryxyg.pif
C:\Documents and Settings\Właściciel\Dane aplikacji\gikazycu.vbs
C:\Documents and Settings\All Users\Dane aplikacji\wadypex.vbs
C:\WINDOWS\System32\oqudodyx.bin
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ujajyrul.bat
C:\WINDOWS\owad.dll
C:\WINDOWS\usovypu.dll
C:\Program Files\Common Files\ibew._sy
C:\WINDOWS\hazakim.dll
C:\WINDOWS\ydojures.inf
C:\WINDOWS\gubycip.scr
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\zyhyzufime._sy
C:\WINDOWS\ocuqajojam._sy
C:\Documents and Settings\Właściciel\Dane aplikacji\hebyrakyfi.dat
C:\WINDOWS\ilibidabud._sy
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ymimacyf.bat
C:\WINDOWS\ylexyzi.dat
C:\Documents and Settings\All Users\Dane aplikacji\bezuz.ban
C:\WINDOWS\axovuq.dll
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cujoce.vbs
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ecerycakyr._dl
C:\WINDOWS\System32\jifu.dl
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\turykeki.sys
C:\Documents and Settings\Właściciel\Dane aplikacji\ybasesalev.bin
C:\WINDOWS\gilamefyx.pif
C:\WINDOWS\sysejev.sys
C:\Program Files\Common Files\ukax._sy
C:\Program Files\Common Files\exowy.dl
C:\Documents and Settings\All Users\Dane aplikacji\rutumonys.lib
C:\Documents and Settings\Właściciel\Dane aplikacji\izupiqed.sys
C:\Documents and Settings\All Users\Dane aplikacji\utelyquki.vbs
C:\Documents and Settings\Właściciel\Dane aplikacji\peby._dl
C:\Documents and Settings\Właściciel\Dane aplikacji\awularys.vbs
C:\Documents and Settings\Właściciel\Dane aplikacji\dawifi.db
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuhoni.vbs
:Commands
[emptytemp]
[start explorer]
[Reboot]
Kliknij w Run Fix. Zatwierdź restart komputera.
Następnie uruchom OTL ponownie, tym razem wywołaj opcję Run Scan.
Pokaż nowy log OTL.txt oraz log z czyszczenia.
jessi
Tutaj radziłbym zastosować Combofix, gdyż ta infekcja często niszczy pliki systemowe.
W czasie pobierania zmień mu nazwę na losową z rozszerzeniem .com
Logi wklejasz na wklej.org lub wklej.to, a w poście dajesz link.
All processes killed
========== OTL ==========
Process explorer.exe killed successfully!
========== FILES ==========
File\Folder C:\WINDOWS\System32\braviax.exe not found.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\fodipaludo.vbs moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\luqepo.bin moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\perop.exe moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\tanidu.inf moved successfully.
C:\Program Files\Common Files\etoxura._sy moved successfully.
C:\WINDOWS\zuju.dl moved successfully.
C:\Documents and Settings\All Users\Dokumenty\rivicot.pif moved successfully.
C:\WINDOWS\evec.dl moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\cepoped.pif moved successfully.
C:\Documents and Settings\All Users\Dokumenty\yjyg._dl moved successfully.
C:\WINDOWS\System32\otahusadym.inf moved successfully.
C:\WINDOWS\jymixyz.bin moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\icuz.inf moved successfully.
C:\WINDOWS\yrirely.exe moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\avynypek.dat moved successfully.
C:\WINDOWS\uxeg._dl moved successfully.
C:\WINDOWS\yjasan.com moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\wuwot.bin moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ypovar.db moved successfully.
C:\WINDOWS\ogoj.exe moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\ymyb.sys moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\inevukeqy.bin moved successfully.
C:\Documents and Settings\All Users\Dokumenty\agefebose.reg moved successfully.
C:\WINDOWS\ofum.sys moved successfully.
C:\WINDOWS\vodax.reg moved successfully.
C:\WINDOWS\adevaz.vbs moved successfully.
C:\WINDOWS\System32\axuxonalu.dat moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\epykokoh.bin moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\lyfip.dat moved successfully.
C:\Program Files\Common Files\tewuxyp.reg moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\ihuxuwiqoq.ban moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\xabykofohe.dl moved successfully.
C:\WINDOWS\fiqoza.db moved successfully.
C:\WINDOWS\System32\rihemyn._dl moved successfully.
C:\Program Files\Common Files\eniwebu._sy moved successfully.
C:\WINDOWS\System32\ozuxusa.pif moved successfully.
C:\WINDOWS\isipyj.reg moved successfully.
C:\WINDOWS\System32\cyjiwejoz.dl moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ekys.lib moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\wixyvug.sys moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\pyma.dat moved successfully.
C:\WINDOWS\salajygyci._sy moved successfully.
C:\WINDOWS\uvikecyna.dat moved successfully.
C:\WINDOWS\igohog.exe moved successfully.
C:\WINDOWS\agexupek.dat moved successfully.
C:\Program Files\Common Files\anuwul.vbs moved successfully.
C:\WINDOWS\System32\peqac.sys moved successfully.
C:\WINDOWS\epyfij.reg moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\gakemyroj.db moved successfully.
C:\Program Files\Common Files\yfojones.inf moved successfully.
C:\WINDOWS\System32\xexi.bat moved successfully.
C:\WINDOWS\egimyxehyq.com moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\mibebeceji.bat moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\uhaxaw.reg moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\exomydotu.db moved successfully.
C:\WINDOWS\System32\ruzuby.db moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\evuliqide.exe moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\ujywiret.sys moved successfully.
C:\WINDOWS\System32\esijil.db moved successfully.
C:\WINDOWS\amiw.db moved successfully.
C:\WINDOWS\ibeb.db moved successfully.
C:\Program Files\Common Files\vukefaqor.exe moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\okexoq.dat moved successfully.
LoadLibrary failed for C:\Program Files\Common Files\osesyv.dll
C:\Program Files\Common Files\osesyv.dll NOT unregistered.
C:\Program Files\Common Files\osesyv.dll moved successfully.
C:\WINDOWS\System32\zomisumilo.lib moved successfully.
C:\WINDOWS\vajynoxewa._dl moved successfully.
C:\WINDOWS\ketusenub.db moved successfully.
C:\Program Files\Common Files\okugy.com moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\salu.sys moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\yjadyp.db moved successfully.
C:\WINDOWS\System32\cyrevy._sy moved successfully.
C:\Program Files\Common Files\ydedabu.pif moved successfully.
C:\WINDOWS\ganeromus.reg moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\ojar.scr moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuro.lib moved successfully.
LoadLibrary failed for C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll NOT unregistered.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll moved successfully.
LoadLibrary failed for C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll
C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll NOT unregistered.
C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll moved successfully.
C:\WINDOWS\System32\miju.lib moved successfully.
C:\WINDOWS\rybeginude.inf moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\povevo.lib moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\ixuduhemip.bin moved successfully.
C:\WINDOWS\ypygim.bat moved successfully.
C:\WINDOWS\wirofu._sy moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\isofit.db moved successfully.
C:\WINDOWS\System32\topubopa._dl moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\gujatexy.ban moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\yremu.db moved successfully.
C:\Program Files\Common Files\decy.lib moved successfully.
C:\WINDOWS\vucolywo.lib moved successfully.
C:\WINDOWS\fujufit.bat moved successfully.
LoadLibrary failed for C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll
C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll NOT unregistered.
C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\bomyvik._sy moved successfully.
C:\WINDOWS\hygucucono.reg moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\oper.vbs moved successfully.
C:\WINDOWS\System32\ifujohufo.dl moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\yhutiwym.dat moved successfully.
C:\WINDOWS\ehefoxiku.dat moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\debohagi.dl moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\javani.vbs moved successfully.
C:\WINDOWS\yqopose._dl moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\oqyvuru.bat moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\ehisegidun.com moved successfully.
C:\Program Files\Common Files\sewofybek.ban moved successfully.
C:\WINDOWS\emogiqykas.lib moved successfully.
LoadLibrary failed for C:\WINDOWS\desype.dll
C:\WINDOWS\desype.dll NOT unregistered.
C:\WINDOWS\desype.dll moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\uhiquwubaz.sys moved successfully.
C:\WINDOWS\System32\zyky.sys moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\emumahidof.ban moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\lykymofezi.dll
C:\WINDOWS\System32\lykymofezi.dll NOT unregistered.
C:\WINDOWS\System32\lykymofezi.dll moved successfully.
C:\Program Files\Common Files\rozina.inf moved successfully.
C:\WINDOWS\System32\finy.ban moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\ybexeb.bat moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\ryxyg.pif moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\gikazycu.vbs moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\wadypex.vbs moved successfully.
C:\WINDOWS\System32\oqudodyx.bin moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ujajyrul.bat moved successfully.
LoadLibrary failed for C:\WINDOWS\owad.dll
C:\WINDOWS\owad.dll NOT unregistered.
C:\WINDOWS\owad.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\usovypu.dll
C:\WINDOWS\usovypu.dll NOT unregistered.
C:\WINDOWS\usovypu.dll moved successfully.
C:\Program Files\Common Files\ibew._sy moved successfully.
LoadLibrary failed for C:\WINDOWS\hazakim.dll
C:\WINDOWS\hazakim.dll NOT unregistered.
C:\WINDOWS\hazakim.dll moved successfully.
C:\WINDOWS\ydojures.inf moved successfully.
C:\WINDOWS\gubycip.scr moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\zyhyzufime._sy moved successfully.
C:\WINDOWS\ocuqajojam._sy moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\hebyrakyfi.dat moved successfully.
C:\WINDOWS\ilibidabud._sy moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ymimacyf.bat moved successfully.
C:\WINDOWS\ylexyzi.dat moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\bezuz.ban moved successfully.
LoadLibrary failed for C:\WINDOWS\axovuq.dll
C:\WINDOWS\axovuq.dll NOT unregistered.
C:\WINDOWS\axovuq.dll moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cujoce.vbs moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ecerycakyr._dl moved successfully.
C:\WINDOWS\System32\jifu.dl moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\turykeki.sys moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\ybasesalev.bin moved successfully.
C:\WINDOWS\gilamefyx.pif moved successfully.
C:\WINDOWS\sysejev.sys moved successfully.
C:\Program Files\Common Files\ukax._sy moved successfully.
C:\Program Files\Common Files\exowy.dl moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\rutumonys.lib moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\izupiqed.sys moved successfully.
C:\Documents and Settings\All Users\Dane aplikacji\utelyquki.vbs moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\peby._dl moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\awularys.vbs moved successfully.
C:\Documents and Settings\Właściciel\Dane aplikacji\dawifi.db moved successfully.
LoadLibrary failed for C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll NOT unregistered.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuhoni.vbs moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Dominik
->Temp folder emptied: 170669 bytes
->Temporary Internet Files folder emptied: 364515 bytes
->FireFox cache emptied: 3239698 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WDMN41U7\control[6].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 2946805 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Właściciel
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2F4A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2F62.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2FC1.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2FE5.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF302A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF3044.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 235046559 bytes
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\SYELPZM7\hijackthis-rsit-otl-dds-inne-instrukcja-t36654[1].html scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\FB3UFS9X\ads[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\7WUVRNGG\OTL[1].exe scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 18411289 bytes
->Java cache emptied: 25493434 bytes
->FireFox cache emptied: 67664985 bytes
->Google Chrome cache emptied: 27223887 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 4704044 bytes
%systemroot%\System32 .tmp files removed: 2596 bytes
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_3f0.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_77c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 22468546 bytes
RecycleBin emptied: 9404 bytes
Total Files Cleaned = 388,98 mb
OTL by OldTimer - Version 3.0.16.0 log created on 09292009_192541
Files\Folders moved on Reboot…
C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WDMN41U7\control[6].htm moved successfully.
File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2F4A.tmp not found!
File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2F62.tmp not found!
File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2FC1.tmp not found!
File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF2FE5.tmp not found!
File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF302A.tmp not found!
File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp~DF3044.tmp not found!
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\SYELPZM7\hijackthis-rsit-otl-dds-inne-instrukcja-t36654[1].html moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\FB3UFS9X\ads[2].htm moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\7WUVRNGG\OTL[1].exe moved successfully.
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_3f0.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_77c.dat moved successfully.
Registry entries deleted on Reboot…
Zastosuj Combofix tak jak napisałem wyżej, bo tutaj może być infekcja w plikach systemowych.
No i przede wszystkim wklejaj logi na wklej.org lub wklej.to, a nie na forum.
OTL logfile created on: 2009-09-29 19:38:04 - Run 3
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Właściciel\Moje dokumenty
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
2,00 Gb Total Physical Memory | 1,47 Gb Available Physical Memory | 73,69% Memory free
3,85 Gb Paging File | 3,28 Gb Available in Paging File | 85,21% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 49,32 Gb Total Space | 29,05 Gb Free Space | 58,90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JA-1C5AE935FE48
Current User Name: Właściciel
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2008-04-15 14:00:00 | 01,035,264 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009-09-11 20:49:18 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-07-18 21:30:57 | 00,133,104 | ---- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2008-02-28 02:53:22 | 00,098,984 | ---- | M] (Lexmark International, Inc.) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe
PRC - [2008-02-28 02:53:25 | 00,594,600 | ---- | M] ( ) – C:\WINDOWS\System32\lxdxcoms.exe
PRC - [2009-02-09 07:18:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe
PRC - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2008-04-15 14:00:00 | 00,032,768 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\snmp.exe
PRC - [2008-12-08 13:33:48 | 01,173,384 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2008-08-15 05:13:26 | 30,003,200 | R— | M] (VIA Technologies, Inc.) – C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
PRC - [2008-06-13 18:04:01 | 00,668,328 | ---- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2005-06-06 23:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
PRC - [2009-09-11 20:49:18 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-06-13 18:04:02 | 00,025,256 | ---- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
PRC - [2007-06-27 19:03:40 | 00,152,872 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2009-07-14 21:56:42 | 00,039,408 | ---- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
PRC - [2007-06-27 19:04:00 | 01,213,736 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2008-04-07 09:17:30 | 00,430,592 | ---- | M] (Nokia.) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2008-03-10 09:58:18 | 00,130,560 | ---- | M] () – C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2008-02-22 09:11:02 | 00,120,320 | ---- | M] () – C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009-09-27 19:31:19 | 00,514,560 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2008-04-15 14:00:00 | 00,100,352 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\6to4svc.dll – (6to4 [Auto | Running])
SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009-07-18 21:30:57 | 00,133,104 | ---- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate1ca07de48b134ac [Auto | Stopped])
SRV - [2009-07-14 21:56:40 | 00,182,768 | ---- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2008-04-15 14:00:00 | 00,038,400 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [unknown | Stopped])
SRV - [2009-09-11 20:49:18 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2008-02-28 02:53:22 | 00,098,984 | ---- | M] (Lexmark International, Inc.) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe – (lxdxCATSCustConnectService [Auto | Running])
SRV - [2008-02-28 02:53:25 | 00,594,600 | ---- | M] ( ) – C:\WINDOWS\System32\lxdxcoms.exe – (lxdx_device [Auto | Running])
SRV - [2007-11-28 11:27:24 | 00,800,040 | ---- | M] (Nero AG) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe – (NBService [On_Demand | Stopped])
SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe – (NMIndexingService [On_Demand | Running])
SRV - [2009-02-09 07:18:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe – (NVSvc [Auto | Running])
SRV - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService [Auto | Running])
SRV - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService [Auto | Running])
SRV - [2008-04-07 09:17:30 | 00,430,592 | ---- | M] (Nokia.) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer [On_Demand | Running])
SRV - [2008-04-15 14:00:00 | 00,032,768 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\snmp.exe – (SNMP [Auto | Running])
SRV - [2004-08-11 01:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe – (UMWdf [On_Demand | Stopped])
SRV - [2006-12-01 11:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2009-09-18 21:24:27 | 00,028,672 | ---- | M] () – C:\WINDOWS\System32\drivers\beep.sys – (Beep [system | Running])
DRV - [2008-04-15 14:00:00 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2008-02-14 08:12:00 | 01,389,056 | R— | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\monfilt.sys – (monfilt [On_Demand | Running])
DRV - [2004-08-15 12:56:20 | 00,005,810 | R— | M] () – C:\WINDOWS\System32\DRIVERS\ASACPI.sys – (MTsensor [On_Demand | Running])
DRV - [2008-04-15 14:00:00 | 00,040,320 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\NMnt.sys – (nm [On_Demand | Stopped])
DRV - [2007-11-29 10:39:42 | 00,016,896 | ---- | M] (Nokia) – C:\WINDOWS\System32\drivers\ccdcmb.sys – (nmwcd [On_Demand | Stopped])
DRV - [2007-11-29 10:39:40 | 00,019,328 | ---- | M] (Nokia) – C:\WINDOWS\System32\drivers\ccdcmbo.sys – (nmwcdc [On_Demand | Stopped])
DRV - [2009-02-09 07:18:00 | 06,307,328 | ---- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Running])
DRV - [2008-04-15 14:00:00 | 00,088,320 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys – (NwlnkIpx [Auto | Running])
DRV - [2008-04-15 14:00:00 | 00,063,232 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\nwlnknb.sys – (NwlnkNb [Auto | Running])
DRV - [2008-04-15 14:00:00 | 00,055,936 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys – (NwlnkSpx [Auto | Running])
DRV - [2007-09-17 15:53:26 | 00,021,632 | ---- | M] (Nokia) – C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys – (pccsmcfd [On_Demand | Stopped])
DRV - [2009-04-03 11:18:26 | 00,130,936 | ---- | M] (PC Tools) – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore [boot | Running])
DRV - [2008-04-15 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007-11-21 21:09:22 | 00,104,320 | R— | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys – (RTL8023xp [On_Demand | Running])
DRV - [2008-04-15 14:00:00 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008-06-20 13:08:27 | 00,225,856 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\tcpip6.sys – (Tcpip6 [system | Running])
DRV - [2007-11-29 10:39:42 | 00,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) – C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys – (upperdev [On_Demand | Stopped])
DRV - [2008-04-15 14:00:00 | 00,026,112 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\usbser.sys – (usbser [On_Demand | Stopped])
DRV - [2007-11-29 10:39:52 | 00,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) – C:\WINDOWS\System32\DRIVERS\usbser_lowerfltj.sys – (UsbserFilt [On_Demand | Stopped])
DRV - [2008-07-25 14:09:24 | 00,845,184 | R— | M] (VIA Technologies, Inc.) – C:\WINDOWS\System32\drivers\viahduaa.sys – (VIAHdAudAddService [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
========== FireFox ==========
FF - prefs.js…extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js…extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js…extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js…extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1
FF - HKLM\software\mozilla\Firefox\Extensions\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-08-18 11:27:26 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-09-11 20:49:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\Components: C:\Program Files\Mozilla Firefox\components [2009-07-24 18:00:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-11 20:49:26 | 00,000,000 | —D | M]
[2009-07-24 18:00:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Extensions
[2009-07-24 18:00:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-09-14 12:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Firefox\Profiles\5kz83eb1.default\extensions
[2009-09-07 19:13:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Firefox\Profiles\5kz83eb1.default\extensions{20a82645-c095-46ed-80e3-08825760534b}
[2009-09-14 12:15:58 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009-07-24 18:00:39 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-09-11 20:49:27 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009-07-16 03:02:55 | 00,023,544 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-07-16 03:02:55 | 00,137,208 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-09-11 20:49:18 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009-07-16 03:02:55 | 00,065,016 | ---- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009-07-15 21:00:25 | 00,002,767 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009-07-15 21:00:25 | 00,001,406 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009-07-15 21:00:25 | 00,002,371 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-07-15 21:00:25 | 00,000,917 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009-07-15 21:00:25 | 00,000,858 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009-07-15 21:00:25 | 00,001,183 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009-07-15 21:00:25 | 00,001,683 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM…\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU…\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM…\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM…\Run: [Antivirus Pro 2010] C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe File not found
O4 - HKLM…\Run: [braviax] C:\WINDOWS\System32\braviax.exe ()
O4 - HKLM…\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe (VIA Technologies, Inc.)
O4 - HKLM…\Run: [iSTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM…\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM…\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM…\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM…\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM…\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM…\Run: [Regedit32] C:\WINDOWS\System32\regedit.exe File not found
O4 - HKLM…\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU…\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU…\Run: [MailScanner] C:\Program Files\MKS_VIR_2006\Mks_mail.exe File not found
O4 - HKCU…\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU…\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe (Time Information Services Ltd.)
O4 - HKCU…\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.)
O4 - HKCU…\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKCU…\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU…\Run: [sys32_nov] C:\Documents and Settings\Właściciel\sys32_nov.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceClassicControlPanel = 1
O9 - Extra ‘Tools’ menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra ‘Tools’ menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM…Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.pl/resources/virus … nicode.cab (CKAVWebScan Object)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.100
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (cru629.dat) - File not found
O20 - AppInit_DLLs: (FILES\COM) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-15 20:25:02 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009-09-29 19:27:18 | 00,010,752 | ---- | C] () – C:\WINDOWS\System32\braviax.exe
[2009-09-29 19:25:41 | 00,000,000 | —D | C] – C:_OTL
[2009-09-27 19:31:19 | 00,514,560 | ---- | C] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe
[2009-09-27 11:55:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
[2009-09-27 11:55:26 | 00,000,000 | —D | C] – C:\WINDOWS\System32\Kaspersky Lab
[2009-09-27 11:46:35 | 00,167,936 | ---- | C] (Legal Corporation) – C:\WINDOWS\System32_scui.cpl
[2009-09-23 20:14:56 | 00,159,856 | ---- | C] (TheBestSoft Corporation) – C:\WINDOWS\System32\wisdstr.exe
[2009-09-18 22:02:25 | 00,000,000 | —D | C] – C:\Program Files\ESET
[2009-09-17 19:33:45 | 00,028,672 | ---- | C] () – C:\WINDOWS\System32\drivers\beep.sys
[2009-09-11 21:21:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Pulpit\Nieużywane skróty pulpitu
[2009-09-11 21:18:32 | 00,159,600 | ---- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009-09-11 21:18:26 | 00,130,936 | ---- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2009-09-11 21:18:26 | 00,073,840 | ---- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009-09-11 21:18:23 | 00,001,655 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk
[2009-09-11 21:18:21 | 00,064,392 | ---- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2009-09-11 21:18:21 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009-09-11 21:18:17 | 00,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2009-09-11 21:18:17 | 00,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\PC Tools
[2009-09-11 21:18:17 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\PC Tools
[2009-09-11 21:01:06 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
[2009-09-11 20:49:15 | 00,000,000 | —D | C] – C:\Program Files\Java
[2009-09-11 20:47:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\Sun
[2009-09-11 20:02:54 | 00,000,000 | —D | C] – C:\Program Files\SkanerOnline
[2009-09-10 22:09:22 | 00,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2009-09-10 21:52:16 | 00,028,288 | ---- | C] () – C:\WINDOWS\System32\dllcache\xjis.nls
[2009-09-10 21:51:50 | 00,080,384 | ---- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2009-09-10 21:51:49 | 00,080,384 | ---- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2009-09-10 21:51:49 | 00,029,184 | ---- | C] (RICOH Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw330ext.dll
[2009-09-10 21:51:44 | 00,083,748 | ---- | C] () – C:\WINDOWS\System32\dllcache\prcp.nls
[2009-09-10 21:51:44 | 00,083,748 | ---- | C] () – C:\WINDOWS\System32\dllcache\prc.nls
[2009-09-10 21:51:41 | 00,175,104 | ---- | C] () – C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2009-09-10 21:51:24 | 00,047,066 | ---- | C] () – C:\WINDOWS\System32\dllcache\ksc.nls
[2009-09-10 21:51:23 | 01,158,818 | ---- | C] () – C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009-09-10 21:51:12 | 00,059,392 | ---- | C] () – C:\WINDOWS\System32\dllcache\imscinst.exe
[2009-09-10 21:51:10 | 00,196,665 | ---- | C] () – C:\WINDOWS\System32\dllcache\imjpinst.exe
[2009-09-10 21:51:07 | 00,134,339 | ---- | C] () – C:\WINDOWS\System32\dllcache\imekr.lex
[2009-09-10 21:51:00 | 13,463,552 | ---- | C] () – C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2009-09-10 21:50:57 | 00,108,827 | ---- | C] () – C:\WINDOWS\System32\dllcache\hanja.lex
[2009-09-10 21:50:51 | 00,094,208 | ---- | C] () – C:\WINDOWS\System32\dllcache\fpencode.dll
[2009-09-10 21:50:49 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009-09-10 21:50:49 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunid.dll
[2009-09-10 21:50:48 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucmd.dll
[2009-09-10 21:50:39 | 00,173,568 | ---- | C] () – C:\WINDOWS\System32\dllcache\chtskf.dll
[2009-09-10 21:50:35 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
– Dodane 29.09.2009 (Wt) 19:40 –
[2009-09-10 21:50:34 | 00,066,594 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_864.nls
[2009-09-10 21:50:34 | 00,066,594 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_862.nls
[2009-09-10 21:50:34 | 00,066,594 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_858.nls
[2009-09-10 21:50:34 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_870.nls
[2009-09-10 21:50:33 | 00,066,594 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_720.nls
[2009-09-10 21:50:33 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_708.nls
[2009-09-10 21:50:33 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_28596.nls
[2009-09-10 21:50:33 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_21027.nls
[2009-09-10 21:50:33 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_21025.nls
[2009-09-10 21:50:32 | 00,180,770 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20932.nls
[2009-09-10 21:50:32 | 00,177,698 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20949.nls
[2009-09-10 21:50:32 | 00,173,602 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20936.nls
[2009-09-10 21:50:32 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20924.nls
[2009-09-10 21:50:32 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20880.nls
[2009-09-10 21:50:31 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20871.nls
[2009-09-10 21:50:31 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20838.nls
[2009-09-10 21:50:31 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20833.nls
[2009-09-10 21:50:31 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20424.nls
[2009-09-10 21:50:31 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20423.nls
[2009-09-10 21:50:31 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20420.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20297.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20290.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20285.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20284.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20280.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20278.nls
[2009-09-10 21:50:30 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20277.nls
[2009-09-10 21:50:29 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20273.nls
[2009-09-10 21:50:29 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20269.nls
[2009-09-10 21:50:29 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20108.nls
[2009-09-10 21:50:29 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20107.nls
[2009-09-10 21:50:29 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20106.nls
[2009-09-10 21:50:29 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20105.nls
[2009-09-10 21:50:28 | 00,187,938 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20005.nls
[2009-09-10 21:50:28 | 00,186,402 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20001.nls
[2009-09-10 21:50:28 | 00,185,378 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20003.nls
[2009-09-10 21:50:28 | 00,180,258 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20004.nls
[2009-09-10 21:50:28 | 00,173,602 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20002.nls
[2009-09-10 21:50:27 | 00,189,986 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1361.nls
[2009-09-10 21:50:27 | 00,180,258 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_20000.nls
[2009-09-10 21:50:27 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1149.nls
[2009-09-10 21:50:27 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1148.nls
[2009-09-10 21:50:27 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1147.nls
[2009-09-10 21:50:26 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1146.nls
[2009-09-10 21:50:26 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1145.nls
[2009-09-10 21:50:26 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1144.nls
[2009-09-10 21:50:26 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1143.nls
[2009-09-10 21:50:26 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1142.nls
[2009-09-10 21:50:26 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1141.nls
[2009-09-10 21:50:25 | 00,173,602 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10008.nls
[2009-09-10 21:50:25 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1140.nls
[2009-09-10 21:50:25 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_1047.nls
[2009-09-10 21:50:25 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10021.nls
[2009-09-10 21:50:25 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10005.nls
[2009-09-10 21:50:24 | 00,195,618 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10002.nls
[2009-09-10 21:50:24 | 00,177,698 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10003.nls
[2009-09-10 21:50:24 | 00,162,850 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10001.nls
[2009-09-10 21:50:24 | 00,066,082 | ---- | C] () – C:\WINDOWS\System32\dllcache\c_10004.nls
[2009-09-10 21:50:23 | 00,082,172 | ---- | C] () – C:\WINDOWS\System32\dllcache\bopomofo.nls
[2009-09-10 21:50:23 | 00,066,728 | ---- | C] () – C:\WINDOWS\System32\dllcache\big5.nls
[2009-09-10 21:48:48 | 00,000,488 | RH-- | C] () – C:\WINDOWS\System32\logonui.exe.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | C] () – C:\WINDOWS\WindowsShell.Manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | C] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | C] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | C] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2009-09-10 21:34:04 | 00,171,588 | ---- | C] () – C:\WINDOWS\System32\dllcache\startoc.cat
[2009-09-10 21:34:04 | 00,037,509 | ---- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2009-09-10 21:34:04 | 00,016,825 | ---- | C] () – C:\WINDOWS\System32\dllcache\IMS.CAT
[2009-09-10 21:34:04 | 00,013,497 | ---- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2009-09-10 21:34:04 | 00,012,363 | ---- | C] () – C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2009-09-10 21:34:04 | 00,010,027 | ---- | C] () – C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2009-09-10 21:34:04 | 00,008,599 | ---- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2009-09-10 21:34:04 | 00,007,407 | ---- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2009-09-10 21:34:03 | 02,033,887 | ---- | C] () – C:\WINDOWS\System32\dllcache\NT5.CAT
[2009-09-10 21:34:03 | 01,246,357 | ---- | C] () – C:\WINDOWS\System32\dllcache\SP3.CAT
[2009-09-10 21:34:03 | 01,089,883 | ---- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009-09-10 21:34:03 | 00,808,524 | ---- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2009-09-10 21:34:03 | 00,399,670 | ---- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2009-09-10 21:34:03 | 00,033,765 | ---- | C] () – C:\WINDOWS\System32\dllcache\FP4.CAT
[2009-09-10 21:34:02 | 00,545,588 | ---- | C] () – C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009-09-10 21:22:44 | 00,000,000 | —D | C] – C:\WINDOWS\setup.pss
[2009-09-09 18:21:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-09-08 14:04:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cache
[2009-06-18 19:49:20 | 00,000,151 | ---- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2009-06-18 18:08:31 | 00,040,960 | ---- | C] () – C:\WINDOWS\System32\lxdxvs.dll
[2009-06-18 18:08:29 | 00,360,448 | ---- | C] () – C:\WINDOWS\System32\lxdxcoin.dll
[2009-06-18 18:08:01 | 00,782,336 | ---- | C] () – C:\WINDOWS\System32\lxdxdrs.dll
[2009-06-18 18:08:01 | 00,081,920 | ---- | C] () – C:\WINDOWS\System32\lxdxcaps.dll
[2009-06-18 18:08:01 | 00,069,632 | ---- | C] () – C:\WINDOWS\System32\lxdxcnv4.dll
[2009-06-18 18:02:02 | 00,000,044 | ---- | C] () – C:\WINDOWS\System32\lxdxrwrd.ini
[2009-06-18 18:01:40 | 00,438,272 | ---- | C] ( ) – C:\WINDOWS\System32\LXDXhcp.dll
[2009-06-18 18:01:40 | 00,364,544 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxinpa.dll
[2009-06-18 18:01:40 | 00,348,160 | ---- | C] () – C:\WINDOWS\System32\LXDXinst.dll
[2009-06-18 18:01:39 | 00,339,968 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxiesc.dll
[2009-06-18 18:01:38 | 00,843,776 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxusb1.dll
[2009-06-18 18:01:37 | 01,105,920 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxserv.dll
[2009-06-18 18:01:37 | 00,647,168 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxpmui.dll
[2009-06-18 18:01:37 | 00,053,248 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxprox.dll
[2009-06-18 18:01:36 | 00,569,344 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxlmpm.dll
[2009-06-18 18:01:34 | 00,663,552 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxhbn3.dll
[2009-06-18 18:01:33 | 00,208,896 | ---- | C] () – C:\WINDOWS\System32\lxdxgrd.dll
[2009-06-18 18:01:30 | 00,851,968 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxcomc.dll
[2009-06-18 18:01:30 | 00,376,832 | ---- | C] ( ) – C:\WINDOWS\System32\lxdxcomm.dll
[2009-06-16 00:24:26 | 00,000,069 | ---- | C] () – C:\WINDOWS\NeroDigital.ini
[2009-06-15 20:35:00 | 00,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009-06-15 20:34:52 | 00,020,228 | ---- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009-06-15 20:34:52 | 00,010,296 | ---- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009-02-09 07:18:00 | 01,724,416 | ---- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009-02-09 07:18:00 | 01,507,328 | ---- | C] () – C:\WINDOWS\System32\nview.dll
[2009-02-09 07:18:00 | 01,101,824 | ---- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009-02-09 07:18:00 | 00,466,944 | ---- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008-10-07 09:13:30 | 00,197,912 | ---- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008-10-07 09:13:22 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008-10-07 09:13:20 | 00,058,648 | ---- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008-04-15 14:00:00 | 00,000,507 | ---- | C] () – C:\WINDOWS\win.ini
[2008-04-15 14:00:00 | 00,000,231 | ---- | C] () – C:\WINDOWS\system.ini
[2007-03-29 23:00:40 | 00,203,264 | R— | C] () – C:\WINDOWS\System32\CddbCdda.dll
========== Files - Modified Within 30 Days ==========
[2009-09-29 19:28:05 | 00,210,919 | ---- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009-09-29 19:27:26 | 00,013,722 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009-09-29 19:27:22 | 00,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT
[2009-09-29 19:27:21 | 00,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat
[2009-09-29 19:27:18 | 00,010,752 | ---- | M] () – C:\WINDOWS\System32\braviax.exe
[2009-09-29 19:07:50 | 03,079,316 | -H-- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-09-27 19:31:19 | 00,514,560 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe
[2009-09-27 03:36:58 | 00,167,936 | ---- | M] (Legal Corporation) – C:\WINDOWS\System32_scui.cpl
[2009-09-26 19:14:29 | 00,002,267 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2009-09-23 20:14:57 | 00,159,856 | ---- | M] (TheBestSoft Corporation) – C:\WINDOWS\System32\wisdstr.exe
[2009-09-19 13:53:04 | 00,001,813 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk
[2009-09-19 11:07:57 | 00,000,069 | ---- | M] () – C:\WINDOWS\NeroDigital.ini
[2009-09-18 21:24:27 | 00,028,672 | ---- | M] () – C:\WINDOWS\System32\drivers\beep.sys
[2009-09-11 21:18:23 | 00,001,655 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk
[2009-09-11 20:18:12 | 00,001,374 | ---- | M] () – C:\WINDOWS\imsins.BAK
[2009-09-11 17:53:30 | 00,002,596 | ---- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009-09-11 15:22:05 | 01,114,842 | ---- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009-09-11 15:22:05 | 00,499,854 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat
[2009-09-11 15:22:05 | 00,440,820 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009-09-11 15:22:05 | 00,089,036 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat
[2009-09-11 15:22:05 | 00,071,138 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009-09-11 14:36:25 | 00,100,640 | ---- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009-09-10 21:52:48 | 00,025,748 | ---- | M] () – C:\WINDOWS\System32$winnt$.inf
[2009-09-10 21:49:45 | 00,316,640 | ---- | M] () – C:\WINDOWS\WMSysPr9.prx
[2009-09-10 21:49:44 | 00,023,392 | ---- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2009-09-10 21:49:44 | 00,016,832 | ---- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2009-09-10 21:49:34 | 00,004,293 | ---- | M] () – C:\WINDOWS\ODBCINST.INI
[2009-09-10 21:48:48 | 00,000,488 | RH-- | M] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2009-09-10 21:48:48 | 00,000,488 | RH-- | M] () – C:\WINDOWS\System32\logonui.exe.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\WindowsShell.Manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2009-09-10 21:48:44 | 00,000,749 | RH-- | M] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2009-09-10 21:48:35 | 00,000,507 | ---- | M] () – C:\WINDOWS\win.ini
[2009-09-10 21:48:09 | 00,023,640 | ---- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2009-09-10 21:44:55 | 00,000,211 | -HS- | M] () – C:\boot.ini
[2009-09-10 21:34:30 | 00,005,208 | ---- | M] () – C:\WINDOWS\System32\pid.PNF
[2009-09-10 21:34:23 | 00,000,231 | ---- | M] () – C:\WINDOWS\system.ini
[2009-09-10 21:19:05 | 00,878,141 | ---- | M] () – C:\WINDOWS\setupapi.old
========== LOP Check ==========
[2009-09-29 19:26:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Dane aplikacji
[2009-06-27 11:37:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Ahead
[2009-06-18 19:33:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Aquadelic GT
[2009-08-16 10:55:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Installations
[2009-09-24 14:35:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-08-16 10:58:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
[2009-09-29 19:38:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-06-27 13:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\ThumbnailCache4R
[2009-09-29 19:26:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji
[2009-06-27 11:54:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Ahead
[2009-08-16 11:37:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Leadertech
[2009-06-18 18:16:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Lexmark Productivity Studio
[2009-07-26 18:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\MKS_VIR
[2009-08-16 11:04:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Nokia
[2009-09-05 20:08:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\Nowe Gadu-Gadu
[2009-07-18 20:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\OpenFM
[2009-08-16 10:59:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Właściciel\Dane aplikacji\PC Suite
[2008-04-15 14:00:00 | 00,000,065 | RH-- | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009-09-29 19:27:22 | 00,000,006 | -H-- | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
< End of report >
Czy ty czytasz moje posty? :evil:
Z takiego wklejania logów na forum to się kiszka robi i się można pogubić.
No i przestań robić logi OTL, tylko zrób log Combofix.
nie mogę uruchomić Combofixa,
Usuń go i pobierz go na nowo - już w czasie pobierania zmień mu nazwę na losową z rozszerzeniem .com
Podczas pobierania i skanowania Combofixem należy wyłączyć wszelkie antywirusy i firewalle.
Podaj link do strony, która Ci się pojawiła po kliknięciu Wklej.
@ deFco247
Znalazłam ten log na wklej org (był podpisany przez @paszko-tp):
Miałeś rację - plik c:\windows\system32\drivers\beep.sys . . . jest zainfekowany
jessi
No i całe szczęście Combofix odnalazł zdrową kopię zapasową tego pliku i podmienił ją.
Log wygląda na czysty.
Jeśli masz jeszcze OTL-a, to uruchom go i kliknij w nim CleanUp ,
lub zastosuj OTC.
Wykonaj pełny skan DR WEB CureIt.
Gdy będą wirusy pokaż raport.
Wyczyść rejestr i dysk CCleaner.
Usuń zbędniki z autostartu.