Adware.Agent.ZO


(Tpwips) #1

Witam. Mam problem Spyware Doctor wykrywa i usuwa Adware.Agent.ZO jednak po ponownym uruchomieniu komputera i skanowaniu plików problem powraca i tak już od tygodnia.Jaj skanowałe pliki mks-em online, nic nie wykrywał.Często też samoistnie zaczyna mi się instalować program AntyVirus 2010. Prosze o poradę dodam tylko że nie mam dużego doświadczenia z komputerem.


(jessica) #2

Na dobry początek:

Daj log z OTL

jessi


(Tpwips) #3

OTL logfile created on: 2009-09-27 19:31:38 - Run 1

OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Właściciel\Moje dokumenty

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,47 Gb Available Physical Memory | 73,38% Memory free

3,85 Gb Paging File | 3,24 Gb Available in Paging File | 84,19% Paging File free

Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 49,32 Gb Total Space | 28,72 Gb Free Space | 58,24% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: JA-1C5AE935FE48

Current User Name: Właściciel

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2009-09-11 20:49:18 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2008-02-28 02:53:22 | 00,098,984 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe

PRC - 2008-02-28 02:53:25 | 00,594,600 | ---- | M -- C:\WINDOWS\System32\lxdxcoms.exe

PRC - [2009-02-09 07:18:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe

PRC - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe

PRC - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe

PRC - [2008-04-15 14:00:00 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe

PRC - [2008-04-15 14:00:00 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE

PRC - [2008-12-08 13:33:48 | 01,173,384 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsTray.exe

PRC - [2008-08-15 05:13:26 | 30,003,200 | R--- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe

PRC - 2008-06-13 18:04:01 | 00,668,328 | ---- | M -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe

PRC - 2008-06-13 18:04:02 | 00,025,256 | ---- | M -- C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe

PRC - [2009-09-11 20:49:18 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe

PRC - [2007-06-27 19:03:40 | 00,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

PRC - [2009-07-14 21:56:42 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

PRC - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

PRC - [2007-06-27 19:04:00 | 01,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

PRC - 2008-04-07 09:17:30 | 00,430,592 | ---- | M -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

PRC - 2008-03-10 09:58:18 | 00,130,560 | ---- | M -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

PRC - 2008-02-22 09:11:02 | 00,120,320 | ---- | M -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe

PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe

PRC - [2009-========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32*.tmp files]

[6 C:\WINDOWS*.tmp files]

[2009-09-27 19:31:19 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe

2009-09-27 19:17:08 | 00,210,919 | ---- | M -- C:\WINDOWS\System32\nvapps.xml

2009-09-27 19:17:04 | 00,001,032 | ---- | M -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

2009-09-27 19:16:44 | 00,000,006 | -H-- | M -- C:\WINDOWS\tasks\SA.DAT

2009-09-27 19:16:42 | 00,002,048 | --S- | M -- C:\WINDOWS\bootstat.dat

2009-09-27 19:16:40 | 00,010,752 | ---- | M -- C:\WINDOWS\System32\braviax.exe

2009-09-27 13:51:00 | 00,001,036 | ---- | M -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

2009-09-27 11:46:47 | 00,019,060 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\fodipaludo.vbs

2009-09-27 11:46:47 | 00,018,888 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\luqepo.bin

2009-09-27 11:46:47 | 00,018,254 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\perop.exe

2009-09-27 11:46:47 | 00,013,725 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\tanidu.inf

2009-09-27 11:46:47 | 00,012,579 | ---- | M -- C:\Program Files\Common Files\etoxura._sy

2009-09-27 11:46:47 | 00,011,458 | ---- | M -- C:\WINDOWS\zuju.dl

2009-09-27 11:46:46 | 00,019,856 | ---- | M -- C:\Documents and Settings\All Users\Dokumenty\rivicot.pif

2009-09-27 11:46:46 | 00,019,385 | ---- | M -- C:\WINDOWS\evec.dl

2009-09-27 11:46:46 | 00,018,635 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\cepoped.pif

2009-09-27 11:46:46 | 00,018,210 | ---- | M -- C:\Documents and Settings\All Users\Dokumenty\yjyg._dl

2009-09-27 11:46:46 | 00,018,136 | ---- | M -- C:\WINDOWS\System32\otahusadym.inf

2009-09-27 11:46:46 | 00,016,738 | ---- | M -- C:\WINDOWS\jymixyz.bin

2009-09-27 11:46:46 | 00,016,653 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\icuz.inf

2009-09-27 11:46:46 | 00,016,039 | ---- | M -- C:\WINDOWS\yrirely.exe

2009-09-27 11:46:46 | 00,014,486 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\avynypek.dat

2009-09-27 11:46:46 | 00,014,090 | ---- | M -- C:\WINDOWS\uxeg._dl

2009-09-27 11:46:46 | 00,014,050 | ---- | M -- C:\WINDOWS\yjasan.com

2009-09-27 11:46:46 | 00,012,929 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\wuwot.bin

2009-09-27 11:46:46 | 00,012,745 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ypovar.db

2009-09-27 11:46:46 | 00,012,109 | ---- | M -- C:\WINDOWS\ogoj.exe

2009-09-27 11:46:46 | 00,011,948 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ymyb.sys

2009-09-27 11:46:46 | 00,010,997 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\inevukeqy.bin

2009-09-27 11:46:46 | 00,010,213 | ---- | M -- C:\Documents and Settings\All Users\Dokumenty\agefebose.reg

2009-09-27 11:46:46 | 00,010,119 | ---- | M -- C:\WINDOWS\ofum.sys

2009-09-27 11:46:46 | 00,010,067 | ---- | M -- C:\WINDOWS\vodax.reg

2009-09-27 11:42:57 | 02,804,430 | -H-- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2009-09-27 03:36:58 | 00,167,936 | ---- | M] (Legal Corporation) -- C:\WINDOWS\System32_scui.cpl

2009-09-26 19:14:29 | 00,002,267 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk

2009-09-26 14:18:53 | 00,013,722 | ---- | M -- C:\WINDOWS\System32\wpa.dbl

[2009-09-23 20:14:57 | 00,159,856 | ---- | M] (TheBestSoft Corporation) -- C:\WINDOWS\System32\wisdstr.exe

2009-09-19 13:53:04 | 00,001,813 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk

2009-09-19 11:07:57 | 00,000,069 | ---- | M -- C:\WINDOWS\NeroDigital.ini

2009-09-18 21:24:27 | 00,028,672 | ---- | M -- C:\WINDOWS\System32\drivers\beep.sys

2009-09-11 21:18:23 | 00,001,655 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk

2009-09-11 20:18:12 | 00,001,374 | ---- | M -- C:\WINDOWS\imsins.BAK

2009-09-11 20:07:33 | 00,019,915 | ---- | M -- C:\WINDOWS\adevaz.vbs

2009-09-11 20:07:33 | 00,019,506 | ---- | M -- C:\WINDOWS\System32\axuxonalu.dat

2009-09-11 20:07:33 | 00,018,374 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\epykokoh.bin

2009-09-11 20:07:33 | 00,016,956 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\lyfip.dat

2009-09-11 20:07:33 | 00,015,967 | ---- | M -- C:\Program Files\Common Files\tewuxyp.reg

2009-09-11 20:07:33 | 00,015,757 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ihuxuwiqoq.ban

2009-09-11 20:07:33 | 00,015,674 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\xabykofohe.dl

2009-09-11 20:07:33 | 00,015,438 | ---- | M -- C:\WINDOWS\fiqoza.db

2009-09-11 20:07:33 | 00,014,647 | ---- | M -- C:\WINDOWS\System32\rihemyn._dl

2009-09-11 20:07:33 | 00,014,276 | ---- | M -- C:\Program Files\Common Files\eniwebu._sy

2009-09-11 20:07:33 | 00,013,856 | ---- | M -- C:\WINDOWS\System32\ozuxusa.pif

2009-09-11 20:07:33 | 00,013,401 | ---- | M -- C:\WINDOWS\isipyj.reg

2009-09-11 20:07:33 | 00,013,303 | ---- | M -- C:\WINDOWS\System32\cyjiwejoz.dl

2009-09-11 20:07:33 | 00,013,193 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ekys.lib

2009-09-11 20:07:33 | 00,012,835 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\wixyvug.sys

2009-09-11 20:07:33 | 00,012,805 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\pyma.dat

2009-09-11 20:07:33 | 00,012,784 | ---- | M -- C:\WINDOWS\salajygyci._sy

2009-09-11 20:07:33 | 00,012,148 | ---- | M -- C:\WINDOWS\uvikecyna.dat

2009-09-11 20:07:33 | 00,011,401 | ---- | M -- C:\WINDOWS\igohog.exe

2009-09-11 20:07:33 | 00,010,335 | ---- | M -- C:\WINDOWS\agexupek.dat

2009-09-11 20:07:33 | 00,010,025 | ---- | M -- C:\Program Files\Common Files\anuwul.vbs

2009-09-11 17:53:30 | 00,002,596 | ---- | M -- C:\WINDOWS\System32\CONFIG.NT

2009-09-11 15:22:05 | 01,114,842 | ---- | M -- C:\WINDOWS\System32\PerfStringBackup.INI

2009-09-11 15:22:05 | 00,499,854 | ---- | M -- C:\WINDOWS\System32\perfh015.dat

2009-09-11 15:22:05 | 00,440,820 | ---- | M -- C:\WINDOWS\System32\perfh009.dat

2009-09-11 15:22:05 | 00,089,036 | ---- | M -- C:\WINDOWS\System32\perfc015.dat

2009-09-11 15:22:05 | 00,071,138 | ---- | M -- C:\WINDOWS\System32\perfc009.dat

2009-09-11 14:36:25 | 00,100,640 | ---- | M -- C:\WINDOWS\System32\FNTCACHE.DAT

2009-09-10 22:18:49 | 00,018,187 | ---- | M -- C:\WINDOWS\System32\peqac.sys

2009-09-10 22:18:49 | 00,017,619 | ---- | M -- C:\WINDOWS\epyfij.reg

2009-09-10 22:18:49 | 00,015,955 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\gakemyroj.db

2009-09-10 22:18:49 | 00,015,818 | ---- | M -- C:\Program Files\Common Files\yfojones.inf

2009-09-10 22:18:49 | 00,013,702 | ---- | M -- C:\WINDOWS\System32\xexi.bat

2009-09-10 22:18:49 | 00,013,587 | ---- | M -- C:\WINDOWS\egimyxehyq.com

2009-09-10 22:18:47 | 00,018,346 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\mibebeceji.bat

2009-09-10 22:18:47 | 00,017,380 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\uhaxaw.reg

2009-09-10 22:18:47 | 00,013,802 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\exomydotu.db

2009-09-10 22:18:47 | 00,010,379 | ---- | M -- C:\WINDOWS\System32\ruzuby.db

2009-09-10 22:18:46 | 00,019,262 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\evuliqide.exe

2009-09-10 22:18:46 | 00,018,337 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\ujywiret.sys

2009-09-10 22:18:46 | 00,017,782 | ---- | M -- C:\WINDOWS\System32\esijil.db

2009-09-10 22:18:46 | 00,015,764 | ---- | M -- C:\WINDOWS\amiw.db

2009-09-10 22:18:46 | 00,015,297 | ---- | M -- C:\WINDOWS\ibeb.db

2009-09-10 22:18:46 | 00,012,087 | ---- | M -- C:\Program Files\Common Files\vukefaqor.exe

2009-09-10 22:18:46 | 00,011,950 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\okexoq.dat

2009-09-10 22:18:46 | 00,011,635 | ---- | M -- C:\Program Files\Common Files\osesyv.dll

2009-09-10 21:52:48 | 00,025,748 | ---- | M -- C:\WINDOWS\System32\$winnt$.inf

2009-09-10 21:49:45 | 00,316,640 | ---- | M -- C:\WINDOWS\WMSysPr9.prx

2009-09-10 21:49:44 | 00,023,392 | ---- | M -- C:\WINDOWS\System32\nscompat.tlb

2009-09-10 21:49:44 | 00,016,832 | ---- | M -- C:\WINDOWS\System32\amcompat.tlb

2009-09-10 21:49:34 | 00,004,293 | ---- | M -- C:\WINDOWS\ODBCINST.INI

2009-09-10 21:48:48 | 00,000,488 | RH-- | M -- C:\WINDOWS\System32\WindowsLogon.manifest

2009-09-10 21:48:48 | 00,000,488 | RH-- | M -- C:\WINDOWS\System32\logonui.exe.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\WindowsShell.Manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\wuaucpl.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\sapi.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\nwc.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\ncpa.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\cdplayer.exe.manifest

2009-09-10 21:48:35 | 00,000,507 | ---- | M -- C:\WINDOWS\win.ini

2009-09-10 21:48:09 | 00,023,640 | ---- | M -- C:\WINDOWS\System32\emptyregdb.dat

2009-09-10 21:44:55 | 00,000,211 | -HS- | M -- C:\boot.ini

2009-09-10 21:34:30 | 00,005,208 | ---- | M -- C:\WINDOWS\System32\pid.PNF

2009-09-10 21:34:23 | 00,000,231 | ---- | M -- C:\WINDOWS\system.ini

2009-09-10 21:19:05 | 00,878,141 | ---- | M -- C:\WINDOWS\setupapi.old

2009-09-10 20:12:47 | 00,019,574 | ---- | M -- C:\WINDOWS\System32\zomisumilo.lib

2009-09-10 20:12:47 | 00,018,949 | ---- | M -- C:\WINDOWS\vajynoxewa._dl

2009-09-10 20:12:47 | 00,018,335 | ---- | M -- C:\WINDOWS\ketusenub.db

2009-09-10 20:12:47 | 00,017,484 | ---- | M -- C:\Program Files\Common Files\okugy.com

2009-09-10 20:12:47 | 00,015,977 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\salu.sys

2009-09-10 20:12:47 | 00,015,310 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\yjadyp.db

2009-09-10 20:12:47 | 00,014,136 | ---- | M -- C:\WINDOWS\System32\cyrevy._sy

2009-09-10 20:12:47 | 00,013,695 | ---- | M -- C:\Program Files\Common Files\ydedabu.pif

2009-09-10 20:12:47 | 00,012,819 | ---- | M -- C:\WINDOWS\ganeromus.reg

2009-09-10 20:12:47 | 00,011,635 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\ojar.scr

2009-09-10 20:12:47 | 00,011,070 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuro.lib

2009-09-10 20:12:47 | 00,010,777 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll

2009-09-10 20:12:47 | 00,010,548 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll

2009-09-10 20:12:47 | 00,010,264 | ---- | M -- C:\WINDOWS\System32\miju.lib

2009-09-08 22:48:32 | 00,019,858 | ---- | M -- C:\WINDOWS\rybeginude.inf

2009-09-08 22:48:32 | 00,018,887 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\povevo.lib

2009-09-08 22:48:32 | 00,018,541 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ixuduhemip.bin

2009-09-08 22:48:32 | 00,018,286 | ---- | M -- C:\WINDOWS\ypygim.bat

2009-09-08 22:48:32 | 00,018,255 | ---- | M -- C:\WINDOWS\wirofu._sy

2009-09-08 22:48:32 | 00,017,241 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\isofit.db

2009-09-08 22:48:32 | 00,014,929 | ---- | M -- C:\WINDOWS\System32\topubopa._dl

2009-09-08 22:48:32 | 00,013,979 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\gujatexy.ban

2009-09-08 22:48:32 | 00,013,841 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\yremu.db

2009-09-08 22:48:32 | 00,013,323 | ---- | M -- C:\Program Files\Common Files\decy.lib

2009-09-08 22:48:32 | 00,012,824 | ---- | M -- C:\WINDOWS\vucolywo.lib

2009-09-08 22:48:32 | 00,012,592 | ---- | M -- C:\WINDOWS\fujufit.bat

2009-09-08 22:48:32 | 00,012,555 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll

2009-09-08 22:48:32 | 00,011,787 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\bomyvik._sy

2009-09-08 22:48:32 | 00,011,398 | ---- | M -- C:\WINDOWS\hygucucono.reg

2009-09-08 22:48:32 | 00,011,085 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\oper.vbs

2009-09-08 22:48:31 | 00,013,595 | ---- | M -- C:\WINDOWS\System32\ifujohufo.dl

2009-09-08 21:55:39 | 00,019,969 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\yhutiwym.dat

2009-09-08 21:55:39 | 00,019,741 | ---- | M -- C:\WINDOWS\ehefoxiku.dat

2009-09-08 21:55:39 | 00,019,689 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\debohagi.dl

2009-09-08 21:55:39 | 00,019,512 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\javani.vbs

2009-09-08 21:55:39 | 00,018,674 | ---- | M -- C:\WINDOWS\yqopose._dl

2009-09-08 21:55:39 | 00,018,339 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\oqyvuru.bat

2009-09-08 21:55:39 | 00,016,338 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ehisegidun.com

2009-09-08 21:55:39 | 00,015,417 | ---- | M -- C:\Program Files\Common Files\sewofybek.ban

2009-09-08 21:55:39 | 00,014,763 | ---- | M -- C:\WINDOWS\emogiqykas.lib

2009-09-08 21:55:39 | 00,013,500 | ---- | M -- C:\WINDOWS\desype.dll

2009-09-08 21:55:39 | 00,013,078 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\uhiquwubaz.sys

2009-09-08 21:55:39 | 00,013,010 | ---- | M -- C:\WINDOWS\System32\zyky.sys

2009-09-08 21:55:39 | 00,012,467 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\emumahidof.ban

2009-09-08 21:55:39 | 00,012,261 | ---- | M -- C:\WINDOWS\System32\lykymofezi.dll

2009-09-08 21:55:39 | 00,012,203 | ---- | M -- C:\Program Files\Common Files\rozina.inf

2009-09-08 21:55:39 | 00,012,028 | ---- | M -- C:\WINDOWS\System32\finy.ban

2009-09-08 21:55:39 | 00,011,962 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ybexeb.bat

2009-09-08 21:55:39 | 00,011,569 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\ryxyg.pif

2009-09-08 21:55:39 | 00,011,078 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\gikazycu.vbs

2009-09-08 21:55:39 | 00,010,753 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\wadypex.vbs

2009-09-08 21:55:39 | 00,010,517 | ---- | M -- C:\WINDOWS\System32\oqudodyx.bin

2009-09-08 21:55:39 | 00,010,226 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ujajyrul.bat

2009-09-08 21:51:38 | 00,019,906 | ---- | M -- C:\WINDOWS\owad.dll

2009-09-08 21:51:38 | 00,019,530 | ---- | M -- C:\WINDOWS\usovypu.dll

2009-09-08 21:51:38 | 00,018,338 | ---- | M -- C:\Program Files\Common Files\ibew._sy

2009-09-08 21:51:38 | 00,016,047 | ---- | M -- C:\WINDOWS\hazakim.dll

2009-09-08 21:51:38 | 00,015,900 | ---- | M -- C:\WINDOWS\ydojures.inf

2009-09-08 21:51:38 | 00,015,236 | ---- | M -- C:\WINDOWS\gubycip.scr

2009-09-08 21:51:38 | 00,014,718 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\zyhyzufime._sy

2009-09-08 21:51:38 | 00,014,445 | ---- | M -- C:\WINDOWS\ocuqajojam._sy

2009-09-08 21:51:38 | 00,013,933 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\hebyrakyfi.dat

2009-09-08 21:51:38 | 00,013,716 | ---- | M -- C:\WINDOWS\ilibidabud._sy

2009-09-08 21:51:38 | 00,013,071 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ymimacyf.bat

2009-09-08 21:51:38 | 00,012,180 | ---- | M -- C:\WINDOWS\ylexyzi.dat

2009-09-08 21:51:38 | 00,012,177 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\bezuz.ban

2009-09-08 21:51:38 | 00,012,007 | ---- | M -- C:\WINDOWS\axovuq.dll

2009-09-08 21:51:38 | 00,011,880 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cujoce.vbs

2009-09-08 21:51:38 | 00,011,242 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ecerycakyr._dl

2009-09-08 21:51:38 | 00,010,983 | ---- | M -- C:\WINDOWS\System32\jifu.dl

2009-09-08 21:51:38 | 00,010,191 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\turykeki.sys

2009-09-08 20:49:18 | 00,018,532 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\ybasesalev.bin

2009-09-08 20:49:18 | 00,016,927 | ---- | M -- C:\WINDOWS\gilamefyx.pif

2009-09-08 20:49:18 | 00,013,802 | ---- | M -- C:\WINDOWS\sysejev.sys

2009-09-08 20:49:18 | 00,012,709 | ---- | M -- C:\Program Files\Common Files\ukax._sy

2009-09-08 20:49:18 | 00,010,708 | ---- | M -- C:\Program Files\Common Files\exowy.dl

2009-09-08 20:49:17 | 00,019,778 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\rutumonys.lib

2009-09-08 20:49:17 | 00,019,218 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\izupiqed.sys

2009-09-08 20:49:17 | 00,016,231 | ---- | M -- C:\Documents and Settings\All Users\Dane aplikacji\utelyquki.vbs

2009-09-08 20:49:17 | 00,016,052 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\peby._dl

2009-09-08 20:49:17 | 00,014,003 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\awularys.vbs

2009-09-08 20:49:17 | 00,013,019 | ---- | M -- C:\Documents and Settings\Właściciel\Dane aplikacji\dawifi.db

2009-09-08 20:49:17 | 00,012,046 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll

2009-09-08 20:49:17 | 00,010,434 | ---- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuhoni.vbs

========== LOP Check ==========

[2009-09-27 11:55:27 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji

[2009-06-27 11:37:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ahead

[2009-06-18 19:33:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Aquadelic GT

[2009-08-16 10:55:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations

[2009-09-24 14:35:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM

[2009-08-16 10:58:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite

[2009-09-27 19:29:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP

[2009-06-27 13:03:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ThumbnailCache4R

[2009-06-15 22:16:20 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dane aplikacji

[2009-09-19 09:32:53 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Dominik\Dane aplikacji

[2009-08-05 20:04:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dominik\Dane aplikacji\Lexmark Productivity Studio

[2009-09-19 09:31:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dominik\Dane aplikacji\Nowe Gadu-Gadu

[2009-08-10 10:49:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dominik\Dane aplikacji\OpenFM

[2009-08-19 21:29:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dominik\Dane aplikacji\PC Suite

[2009-08-22 18:06:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji

[2009-06-15 20:27:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji

[2009-09-27 11:46:47 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji

[2009-06-27 11:54:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Ahead

[2009-08-16 11:37:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Leadertech

[2009-06-18 18:16:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Lexmark Productivity Studio

[2009-07-26 18:47:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\MKS_VIR

[2009-08-16 11:04:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Nokia

[2009-09-05 20:08:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Nowe Gadu-Gadu

[2009-07-18 20:30:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\OpenFM

[2009-08-16 10:59:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\PC Suite

2008-04-15 14:00:00 | 00,000,065 | RH-- | M -- C:\WINDOWS\Tasks\desktop.ini

2009-09-27 19:17:04 | 00,001,032 | ---- | M -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2009-09-27 13:51:00 | 00,001,036 | ---- | M -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2009-09-27 19:16:44 | 00,000,006 | -H-- | M -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2

< End of report >


(jessica) #4

Ależ jest tu tego.

Przy okazji daję do usunięcia "joby" Google - są zbędne i obciążają System.

Uruchom OTL i w oknie Custom Scans/Fixes wklej to:

:OTL

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


:Files

C:\WINDOWS\System32\braviax.exe

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

C:\Documents and Settings\All Users\Dane aplikacji\fodipaludo.vbs

C:\Documents and Settings\Właściciel\Dane aplikacji\luqepo.bin

C:\Documents and Settings\All Users\Dane aplikacji\perop.exe

C:\Documents and Settings\All Users\Dane aplikacji\tanidu.inf

C:\Program Files\Common Files\etoxura._sy

C:\WINDOWS\zuju.dl

C:\Documents and Settings\All Users\Dokumenty\rivicot.pif

C:\WINDOWS\evec.dl

C:\Documents and Settings\Właściciel\Dane aplikacji\cepoped.pif

C:\Documents and Settings\All Users\Dokumenty\yjyg._dl

C:\WINDOWS\System32\otahusadym.inf

C:\WINDOWS\jymixyz.bin

C:\Documents and Settings\Właściciel\Dane aplikacji\icuz.inf

C:\WINDOWS\yrirely.exe

C:\Documents and Settings\All Users\Dane aplikacji\avynypek.dat

C:\WINDOWS\uxeg._dl

C:\WINDOWS\yjasan.com

C:\Documents and Settings\All Users\Dane aplikacji\wuwot.bin

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ypovar.db

C:\WINDOWS\ogoj.exe

C:\Documents and Settings\Właściciel\Dane aplikacji\ymyb.sys

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\inevukeqy.bin

C:\Documents and Settings\All Users\Dokumenty\agefebose.reg

C:\WINDOWS\ofum.sys

C:\WINDOWS\vodax.reg

C:\WINDOWS\adevaz.vbs

C:\WINDOWS\System32\axuxonalu.dat

C:\Documents and Settings\Właściciel\Dane aplikacji\epykokoh.bin

C:\Documents and Settings\All Users\Dane aplikacji\lyfip.dat

C:\Program Files\Common Files\tewuxyp.reg

C:\Documents and Settings\Właściciel\Dane aplikacji\ihuxuwiqoq.ban

C:\Documents and Settings\Właściciel\Dane aplikacji\xabykofohe.dl

C:\WINDOWS\fiqoza.db

C:\WINDOWS\System32\rihemyn._dl

C:\Program Files\Common Files\eniwebu._sy

C:\WINDOWS\System32\ozuxusa.pif

C:\WINDOWS\isipyj.reg

C:\WINDOWS\System32\cyjiwejoz.dl

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ekys.lib

C:\Documents and Settings\Właściciel\Dane aplikacji\wixyvug.sys

C:\Documents and Settings\All Users\Dane aplikacji\pyma.dat

C:\WINDOWS\salajygyci._sy

C:\WINDOWS\uvikecyna.dat

C:\WINDOWS\igohog.exe

C:\WINDOWS\agexupek.dat

C:\Program Files\Common Files\anuwul.vbs

C:\WINDOWS\System32\peqac.sys

C:\WINDOWS\epyfij.reg

C:\Documents and Settings\Właściciel\Dane aplikacji\gakemyroj.db

C:\Program Files\Common Files\yfojones.inf

C:\WINDOWS\System32\xexi.bat

C:\WINDOWS\egimyxehyq.com

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\mibebeceji.bat

C:\Documents and Settings\Właściciel\Dane aplikacji\uhaxaw.reg

C:\Documents and Settings\All Users\Dane aplikacji\exomydotu.db

C:\WINDOWS\System32\ruzuby.db

C:\Documents and Settings\Właściciel\Dane aplikacji\evuliqide.exe

C:\Documents and Settings\All Users\Dane aplikacji\ujywiret.sys

C:\WINDOWS\System32\esijil.db

C:\WINDOWS\amiw.db

C:\WINDOWS\ibeb.db

C:\Program Files\Common Files\vukefaqor.exe

C:\Documents and Settings\Właściciel\Dane aplikacji\okexoq.dat

C:\Program Files\Common Files\osesyv.dll

C:\WINDOWS\System32\zomisumilo.lib

C:\WINDOWS\vajynoxewa._dl

C:\WINDOWS\ketusenub.db

C:\Program Files\Common Files\okugy.com

C:\Documents and Settings\All Users\Dane aplikacji\salu.sys

C:\Documents and Settings\All Users\Dane aplikacji\yjadyp.db

C:\WINDOWS\System32\cyrevy._sy

C:\Program Files\Common Files\ydedabu.pif

C:\WINDOWS\ganeromus.reg

C:\Documents and Settings\All Users\Dane aplikacji\ojar.scr

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuro.lib

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll

C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll

C:\WINDOWS\System32\miju.lib

C:\WINDOWS\rybeginude.inf

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\povevo.lib

C:\Documents and Settings\Właściciel\Dane aplikacji\ixuduhemip.bin

C:\WINDOWS\ypygim.bat

C:\WINDOWS\wirofu._sy

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\isofit.db

C:\WINDOWS\System32\topubopa._dl

C:\Documents and Settings\All Users\Dane aplikacji\gujatexy.ban

C:\Documents and Settings\All Users\Dane aplikacji\yremu.db

C:\Program Files\Common Files\decy.lib

C:\WINDOWS\vucolywo.lib

C:\WINDOWS\fujufit.bat

C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll

C:\Documents and Settings\Właściciel\Dane aplikacji\bomyvik._sy

C:\WINDOWS\hygucucono.reg

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\oper.vbs

C:\WINDOWS\System32\ifujohufo.dl

C:\Documents and Settings\All Users\Dane aplikacji\yhutiwym.dat

C:\WINDOWS\ehefoxiku.dat

C:\Documents and Settings\Właściciel\Dane aplikacji\debohagi.dl

C:\Documents and Settings\All Users\Dane aplikacji\javani.vbs

C:\WINDOWS\yqopose._dl

C:\Documents and Settings\Właściciel\Dane aplikacji\oqyvuru.bat

C:\Documents and Settings\Właściciel\Dane aplikacji\ehisegidun.com

C:\Program Files\Common Files\sewofybek.ban

C:\WINDOWS\emogiqykas.lib

C:\WINDOWS\desype.dll

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\uhiquwubaz.sys

C:\WINDOWS\System32\zyky.sys

C:\Documents and Settings\Właściciel\Dane aplikacji\emumahidof.ban

C:\WINDOWS\System32\lykymofezi.dll

C:\Program Files\Common Files\rozina.inf

C:\WINDOWS\System32\finy.ban

C:\Documents and Settings\Właściciel\Dane aplikacji\ybexeb.bat

C:\Documents and Settings\All Users\Dane aplikacji\ryxyg.pif

C:\Documents and Settings\Właściciel\Dane aplikacji\gikazycu.vbs

C:\Documents and Settings\All Users\Dane aplikacji\wadypex.vbs

C:\WINDOWS\System32\oqudodyx.bin

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ujajyrul.bat

C:\WINDOWS\owad.dll

C:\WINDOWS\usovypu.dll

C:\Program Files\Common Files\ibew._sy

C:\WINDOWS\hazakim.dll

C:\WINDOWS\ydojures.inf

C:\WINDOWS\gubycip.scr

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\zyhyzufime._sy

C:\WINDOWS\ocuqajojam._sy

C:\Documents and Settings\Właściciel\Dane aplikacji\hebyrakyfi.dat

C:\WINDOWS\ilibidabud._sy

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ymimacyf.bat

C:\WINDOWS\ylexyzi.dat

C:\Documents and Settings\All Users\Dane aplikacji\bezuz.ban

C:\WINDOWS\axovuq.dll

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cujoce.vbs

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ecerycakyr._dl

C:\WINDOWS\System32\jifu.dl

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\turykeki.sys

C:\Documents and Settings\Właściciel\Dane aplikacji\ybasesalev.bin

C:\WINDOWS\gilamefyx.pif

C:\WINDOWS\sysejev.sys

C:\Program Files\Common Files\ukax._sy

C:\Program Files\Common Files\exowy.dl

C:\Documents and Settings\All Users\Dane aplikacji\rutumonys.lib

C:\Documents and Settings\Właściciel\Dane aplikacji\izupiqed.sys

C:\Documents and Settings\All Users\Dane aplikacji\utelyquki.vbs

C:\Documents and Settings\Właściciel\Dane aplikacji\peby._dl

C:\Documents and Settings\Właściciel\Dane aplikacji\awularys.vbs

C:\Documents and Settings\Właściciel\Dane aplikacji\dawifi.db

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuhoni.vbs


:Commands

[emptytemp]

[start explorer]

[Reboot]

Kliknij w Run Fix. Zatwierdź restart komputera.

Następnie uruchom OTL ponownie, tym razem wywołaj opcję Run Scan.

Pokaż nowy log OTL.txt oraz log z czyszczenia.

jessi


(deFco247) #5

Tutaj radziłbym zastosować Combofix, gdyż ta infekcja często niszczy pliki systemowe.

W czasie pobierania zmień mu nazwę na losową z rozszerzeniem .com

Logi wklejasz na wklej.org lub wklej.to, a w poście dajesz link.


(Tpwips) #6

All processes killed

========== OTL ==========

Process explorer.exe killed successfully!

========== FILES ==========

File\Folder C:\WINDOWS\System32\braviax.exe not found.

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.

C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\fodipaludo.vbs moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\luqepo.bin moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\perop.exe moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\tanidu.inf moved successfully.

C:\Program Files\Common Files\etoxura._sy moved successfully.

C:\WINDOWS\zuju.dl moved successfully.

C:\Documents and Settings\All Users\Dokumenty\rivicot.pif moved successfully.

C:\WINDOWS\evec.dl moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\cepoped.pif moved successfully.

C:\Documents and Settings\All Users\Dokumenty\yjyg._dl moved successfully.

C:\WINDOWS\System32\otahusadym.inf moved successfully.

C:\WINDOWS\jymixyz.bin moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\icuz.inf moved successfully.

C:\WINDOWS\yrirely.exe moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\avynypek.dat moved successfully.

C:\WINDOWS\uxeg._dl moved successfully.

C:\WINDOWS\yjasan.com moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\wuwot.bin moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ypovar.db moved successfully.

C:\WINDOWS\ogoj.exe moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\ymyb.sys moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\inevukeqy.bin moved successfully.

C:\Documents and Settings\All Users\Dokumenty\agefebose.reg moved successfully.

C:\WINDOWS\ofum.sys moved successfully.

C:\WINDOWS\vodax.reg moved successfully.

C:\WINDOWS\adevaz.vbs moved successfully.

C:\WINDOWS\System32\axuxonalu.dat moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\epykokoh.bin moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\lyfip.dat moved successfully.

C:\Program Files\Common Files\tewuxyp.reg moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\ihuxuwiqoq.ban moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\xabykofohe.dl moved successfully.

C:\WINDOWS\fiqoza.db moved successfully.

C:\WINDOWS\System32\rihemyn._dl moved successfully.

C:\Program Files\Common Files\eniwebu._sy moved successfully.

C:\WINDOWS\System32\ozuxusa.pif moved successfully.

C:\WINDOWS\isipyj.reg moved successfully.

C:\WINDOWS\System32\cyjiwejoz.dl moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ekys.lib moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\wixyvug.sys moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\pyma.dat moved successfully.

C:\WINDOWS\salajygyci._sy moved successfully.

C:\WINDOWS\uvikecyna.dat moved successfully.

C:\WINDOWS\igohog.exe moved successfully.

C:\WINDOWS\agexupek.dat moved successfully.

C:\Program Files\Common Files\anuwul.vbs moved successfully.

C:\WINDOWS\System32\peqac.sys moved successfully.

C:\WINDOWS\epyfij.reg moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\gakemyroj.db moved successfully.

C:\Program Files\Common Files\yfojones.inf moved successfully.

C:\WINDOWS\System32\xexi.bat moved successfully.

C:\WINDOWS\egimyxehyq.com moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\mibebeceji.bat moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\uhaxaw.reg moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\exomydotu.db moved successfully.

C:\WINDOWS\System32\ruzuby.db moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\evuliqide.exe moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\ujywiret.sys moved successfully.

C:\WINDOWS\System32\esijil.db moved successfully.

C:\WINDOWS\amiw.db moved successfully.

C:\WINDOWS\ibeb.db moved successfully.

C:\Program Files\Common Files\vukefaqor.exe moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\okexoq.dat moved successfully.

LoadLibrary failed for C:\Program Files\Common Files\osesyv.dll

C:\Program Files\Common Files\osesyv.dll NOT unregistered.

C:\Program Files\Common Files\osesyv.dll moved successfully.

C:\WINDOWS\System32\zomisumilo.lib moved successfully.

C:\WINDOWS\vajynoxewa._dl moved successfully.

C:\WINDOWS\ketusenub.db moved successfully.

C:\Program Files\Common Files\okugy.com moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\salu.sys moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\yjadyp.db moved successfully.

C:\WINDOWS\System32\cyrevy._sy moved successfully.

C:\Program Files\Common Files\ydedabu.pif moved successfully.

C:\WINDOWS\ganeromus.reg moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\ojar.scr moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuro.lib moved successfully.

LoadLibrary failed for C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll NOT unregistered.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\xileceka.dll moved successfully.

LoadLibrary failed for C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll

C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll NOT unregistered.

C:\Documents and Settings\Właściciel\Dane aplikacji\wydi.dll moved successfully.

C:\WINDOWS\System32\miju.lib moved successfully.

C:\WINDOWS\rybeginude.inf moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\povevo.lib moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\ixuduhemip.bin moved successfully.

C:\WINDOWS\ypygim.bat moved successfully.

C:\WINDOWS\wirofu._sy moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\isofit.db moved successfully.

C:\WINDOWS\System32\topubopa._dl moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\gujatexy.ban moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\yremu.db moved successfully.

C:\Program Files\Common Files\decy.lib moved successfully.

C:\WINDOWS\vucolywo.lib moved successfully.

C:\WINDOWS\fujufit.bat moved successfully.

LoadLibrary failed for C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll

C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll NOT unregistered.

C:\Documents and Settings\Właściciel\Dane aplikacji\ehipe.dll moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\bomyvik._sy moved successfully.

C:\WINDOWS\hygucucono.reg moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\oper.vbs moved successfully.

C:\WINDOWS\System32\ifujohufo.dl moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\yhutiwym.dat moved successfully.

C:\WINDOWS\ehefoxiku.dat moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\debohagi.dl moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\javani.vbs moved successfully.

C:\WINDOWS\yqopose._dl moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\oqyvuru.bat moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\ehisegidun.com moved successfully.

C:\Program Files\Common Files\sewofybek.ban moved successfully.

C:\WINDOWS\emogiqykas.lib moved successfully.

LoadLibrary failed for C:\WINDOWS\desype.dll

C:\WINDOWS\desype.dll NOT unregistered.

C:\WINDOWS\desype.dll moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\uhiquwubaz.sys moved successfully.

C:\WINDOWS\System32\zyky.sys moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\emumahidof.ban moved successfully.

LoadLibrary failed for C:\WINDOWS\System32\lykymofezi.dll

C:\WINDOWS\System32\lykymofezi.dll NOT unregistered.

C:\WINDOWS\System32\lykymofezi.dll moved successfully.

C:\Program Files\Common Files\rozina.inf moved successfully.

C:\WINDOWS\System32\finy.ban moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\ybexeb.bat moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\ryxyg.pif moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\gikazycu.vbs moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\wadypex.vbs moved successfully.

C:\WINDOWS\System32\oqudodyx.bin moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ujajyrul.bat moved successfully.

LoadLibrary failed for C:\WINDOWS\owad.dll

C:\WINDOWS\owad.dll NOT unregistered.

C:\WINDOWS\owad.dll moved successfully.

LoadLibrary failed for C:\WINDOWS\usovypu.dll

C:\WINDOWS\usovypu.dll NOT unregistered.

C:\WINDOWS\usovypu.dll moved successfully.

C:\Program Files\Common Files\ibew._sy moved successfully.

LoadLibrary failed for C:\WINDOWS\hazakim.dll

C:\WINDOWS\hazakim.dll NOT unregistered.

C:\WINDOWS\hazakim.dll moved successfully.

C:\WINDOWS\ydojures.inf moved successfully.

C:\WINDOWS\gubycip.scr moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\zyhyzufime._sy moved successfully.

C:\WINDOWS\ocuqajojam._sy moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\hebyrakyfi.dat moved successfully.

C:\WINDOWS\ilibidabud._sy moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ymimacyf.bat moved successfully.

C:\WINDOWS\ylexyzi.dat moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\bezuz.ban moved successfully.

LoadLibrary failed for C:\WINDOWS\axovuq.dll

C:\WINDOWS\axovuq.dll NOT unregistered.

C:\WINDOWS\axovuq.dll moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cujoce.vbs moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ecerycakyr._dl moved successfully.

C:\WINDOWS\System32\jifu.dl moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\turykeki.sys moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\ybasesalev.bin moved successfully.

C:\WINDOWS\gilamefyx.pif moved successfully.

C:\WINDOWS\sysejev.sys moved successfully.

C:\Program Files\Common Files\ukax._sy moved successfully.

C:\Program Files\Common Files\exowy.dl moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\rutumonys.lib moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\izupiqed.sys moved successfully.

C:\Documents and Settings\All Users\Dane aplikacji\utelyquki.vbs moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\peby._dl moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\awularys.vbs moved successfully.

C:\Documents and Settings\Właściciel\Dane aplikacji\dawifi.db moved successfully.

LoadLibrary failed for C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll NOT unregistered.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\letadu.dll moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\kuhoni.vbs moved successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: Dominik

->Temp folder emptied: 170669 bytes

->Temporary Internet Files folder emptied: 364515 bytes

->FireFox cache emptied: 3239698 bytes

User: LocalService

->Temp folder emptied: 66016 bytes

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WDMN41U7\control[6].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 2946805 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: Właściciel

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2F4A.tmp scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2F62.tmp scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2FC1.tmp scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2FE5.tmp scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF302A.tmp scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF3044.tmp scheduled to be deleted on reboot.

->Temp folder emptied: 235046559 bytes

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\SYELPZM7\hijackthis-rsit-otl-dds-inne-instrukcja-t36654[1].html scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\FB3UFS9X\ads[2].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\7WUVRNGG\OTL[1].exe scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 18411289 bytes

->Java cache emptied: 25493434 bytes

->FireFox cache emptied: 67664985 bytes

->Google Chrome cache emptied: 27223887 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 4704044 bytes

%systemroot%\System32 .tmp files removed: 2596 bytes

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_3f0.dat scheduled to be deleted on reboot.

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_77c.dat scheduled to be deleted on reboot.

Windows Temp folder emptied: 22468546 bytes

RecycleBin emptied: 9404 bytes

Total Files Cleaned = 388,98 mb

OTL by OldTimer - Version 3.0.16.0 log created on 09292009_192541

Files\Folders moved on Reboot...

C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WDMN41U7\control[6].htm moved successfully.

File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2F4A.tmp not found!

File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2F62.tmp not found!

File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2FC1.tmp not found!

File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF2FE5.tmp not found!

File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF302A.tmp not found!

File\Folder C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\~DF3044.tmp not found!

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\SYELPZM7\hijackthis-rsit-otl-dds-inne-instrukcja-t36654[1].html moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\FB3UFS9X\ads[2].htm moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\Content.IE5\7WUVRNGG\OTL[1].exe moved successfully.

C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

File\Folder C:\WINDOWS\temp\Perflib_Perfdata_3f0.dat not found!

C:\WINDOWS\temp\Perflib_Perfdata_77c.dat moved successfully.

Registry entries deleted on Reboot...


(deFco247) #7

Zastosuj Combofix tak jak napisałem wyżej, bo tutaj może być infekcja w plikach systemowych.

No i przede wszystkim wklejaj logi na wklej.org lub wklej.to, a nie na forum.


(Tpwips) #8

OTL logfile created on: 2009-09-29 19:38:04 - Run 3

OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Właściciel\Moje dokumenty

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,47 Gb Available Physical Memory | 73,69% Memory free

3,85 Gb Paging File | 3,28 Gb Available in Paging File | 85,21% Paging File free

Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 49,32 Gb Total Space | 29,05 Gb Free Space | 58,90% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: JA-1C5AE935FE48

Current User Name: Właściciel

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2008-04-15 14:00:00 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE

PRC - [2009-09-11 20:49:18 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2009-07-18 21:30:57 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe

PRC - [2008-02-28 02:53:22 | 00,098,984 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe

PRC - 2008-02-28 02:53:25 | 00,594,600 | ---- | M -- C:\WINDOWS\System32\lxdxcoms.exe

PRC - [2009-02-09 07:18:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe

PRC - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe

PRC - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe

PRC - [2008-04-15 14:00:00 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe

PRC - [2008-12-08 13:33:48 | 01,173,384 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsTray.exe

PRC - [2008-08-15 05:13:26 | 30,003,200 | R--- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe

PRC - 2008-06-13 18:04:01 | 00,668,328 | ---- | M -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe

PRC - [2005-06-06 23:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

PRC - [2009-09-11 20:49:18 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe

PRC - 2008-06-13 18:04:02 | 00,025,256 | ---- | M -- C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe

PRC - [2007-06-27 19:03:40 | 00,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

PRC - [2009-07-14 21:56:42 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

PRC - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

PRC - [2007-06-27 19:04:00 | 01,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

PRC - 2008-04-07 09:17:30 | 00,430,592 | ---- | M -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

PRC - 2008-03-10 09:58:18 | 00,130,560 | ---- | M -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

PRC - 2008-02-22 09:11:02 | 00,120,320 | ---- | M -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe

PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe

PRC - [2009-09-27 19:31:19 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2008-04-15 14:00:00 | 00,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\6to4svc.dll -- (6to4 [Auto | Running])

SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])

SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])

SRV - [2009-07-18 21:30:57 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca07de48b134ac [Auto | Stopped])

SRV - 2009-07-14 21:56:40 | 00,182,768 | ---- | M -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])

SRV - [2008-04-15 14:00:00 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])

SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [unknown | Stopped])

SRV - [2009-09-11 20:49:18 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

SRV - [2008-02-28 02:53:22 | 00,098,984 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe -- (lxdxCATSCustConnectService [Auto | Running])

SRV - 2008-02-28 02:53:25 | 00,594,600 | ---- | M -- C:\WINDOWS\System32\lxdxcoms.exe -- (lxdx_device [Auto | Running])

SRV - [2007-11-28 11:27:24 | 00,800,040 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])

SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])

SRV - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Running])

SRV - [2009-02-09 07:18:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])

SRV - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService [Auto | Running])

SRV - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService [Auto | Running])

SRV - 2008-04-07 09:17:30 | 00,430,592 | ---- | M -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Running])

SRV - [2008-04-15 14:00:00 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe -- (SNMP [Auto | Running])

SRV - [2004-08-11 01:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [On_Demand | Stopped])

SRV - [2006-12-01 11:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - 2009-09-18 21:24:27 | 00,028,672 | ---- | M -- C:\WINDOWS\System32\drivers\beep.sys -- (Beep [system | Running])

DRV - [2008-04-15 14:00:00 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])

DRV - [2008-02-14 08:12:00 | 01,389,056 | R--- | M] (Creative Technology Ltd.) -- C:\WINDOWS\System32\drivers\monfilt.sys -- (monfilt [On_Demand | Running])

DRV - 2004-08-15 12:56:20 | 00,005,810 | R--- | M -- C:\WINDOWS\System32\DRIVERS\ASACPI.sys -- (MTsensor [On_Demand | Running])

DRV - [2008-04-15 14:00:00 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])

DRV - 2007-11-29 10:39:42 | 00,016,896 | ---- | M -- C:\WINDOWS\System32\drivers\ccdcmb.sys -- (nmwcd [On_Demand | Stopped])

DRV - 2007-11-29 10:39:40 | 00,019,328 | ---- | M -- C:\WINDOWS\System32\drivers\ccdcmbo.sys -- (nmwcdc [On_Demand | Stopped])

DRV - [2009-02-09 07:18:00 | 06,307,328 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])

DRV - [2008-04-15 14:00:00 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])

DRV - [2008-04-15 14:00:00 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])

DRV - [2008-04-15 14:00:00 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])

DRV - 2007-09-17 15:53:26 | 00,021,632 | ---- | M -- C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys -- (pccsmcfd [On_Demand | Stopped])

DRV - [2009-04-03 11:18:26 | 00,130,936 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore [boot | Running])

DRV - [2008-04-15 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])

DRV - [2007-11-21 21:09:22 | 00,104,320 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Running])

DRV - [2008-04-15 14:00:00 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])

DRV - [2008-06-20 13:08:27 | 00,225,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\tcpip6.sys -- (Tcpip6 [system | Running])

DRV - [2007-11-29 10:39:42 | 00,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys -- (upperdev [On_Demand | Stopped])

DRV - [2008-04-15 14:00:00 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\usbser.sys -- (usbser [On_Demand | Stopped])

DRV - [2007-11-29 10:39:52 | 00,008,064 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerfltj.sys -- (UsbserFilt [On_Demand | Stopped])

DRV - [2008-07-25 14:09:24 | 00,845,184 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\drivers\viahduaa.sys -- (VIAHdAudAddService [On_Demand | Running])

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1

FF - HKLM\software\mozilla\Firefox\Extensions\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-08-18 11:27:26 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-09-11 20:49:18 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\Components: C:\Program Files\Mozilla Firefox\components [2009-07-24 18:00:44 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-11 20:49:26 | 00,000,000 | ---D | M]

[2009-07-24 18:00:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Extensions

[2009-07-24 18:00:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009-09-14 12:15:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Firefox\Profiles\5kz83eb1.default\extensions

[2009-09-07 19:13:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\mozilla\Firefox\Profiles\5kz83eb1.default\extensions{20a82645-c095-46ed-80e3-08825760534b}

[2009-09-14 12:15:58 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions

[2009-07-24 18:00:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-09-11 20:49:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

[2009-07-16 03:02:55 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2009-07-16 03:02:55 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2009-09-11 20:49:18 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

2009-07-16 03:02:55 | 00,065,016 | ---- | M -- C:\Program Files\mozilla firefox\plugins\npnul32.dll

2009-07-15 21:00:25 | 00,002,767 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml

2009-07-15 21:00:25 | 00,001,406 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml

2009-07-15 21:00:25 | 00,002,371 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\google.xml

2009-07-15 21:00:25 | 00,000,917 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml

2009-07-15 21:00:25 | 00,000,858 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml

2009-07-15 21:00:25 | 00,001,183 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml

2009-07-15 21:00:25 | 00,001,683 | ---- | M -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O3 - HKLM..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKCU..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Antivirus Pro 2010] C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe File not found

O4 - HKLM..\Run: [braviax] C:\WINDOWS\System32\braviax.exe ()

O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe (VIA Technologies, Inc.)

O4 - HKLM..\Run: [iSTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)

O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()

O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()

O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()

O4 - HKLM..\Run: [Regedit32] C:\WINDOWS\System32\regedit.exe File not found

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKCU..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)

O4 - HKCU..\Run: [MailScanner] C:\Program Files\MKS_VIR_2006\Mks_mail.exe File not found

O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O4 - HKCU..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe (Time Information Services Ltd.)

O4 - HKCU..\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.)

O4 - HKCU..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKCU..\Run: [sys32_nov] C:\Documents and Settings\Właściciel\sys32_nov.exe File not found

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceClassicControlPanel = 1

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O15 - HKLM..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.pl/resources/virus ... nicode.cab (CKAVWebScan Object)

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.100

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - AppInit_DLLs: (cru629.dat) - File not found

O20 - AppInit_DLLs: (FILES\COM) - File not found

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - 2009-06-15 20:25:02 | 00,000,000 | ---- | M - C:\AUTOEXEC.BAT -- [NTFS]

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

2009-09-29 19:27:18 | 00,010,752 | ---- | C -- C:\WINDOWS\System32\braviax.exe

[2009-09-29 19:25:41 | 00,000,000 | ---D | C] -- C:_OTL

[2009-09-27 19:31:19 | 00,514,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe

[2009-09-27 11:55:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab

[2009-09-27 11:55:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Kaspersky Lab

[2009-09-27 11:46:35 | 00,167,936 | ---- | C] (Legal Corporation) -- C:\WINDOWS\System32_scui.cpl

[2009-09-23 20:14:56 | 00,159,856 | ---- | C] (TheBestSoft Corporation) -- C:\WINDOWS\System32\wisdstr.exe

[2009-09-18 22:02:25 | 00,000,000 | ---D | C] -- C:\Program Files\ESET

2009-09-17 19:33:45 | 00,028,672 | ---- | C -- C:\WINDOWS\System32\drivers\beep.sys

[2009-09-11 21:21:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\Nieużywane skróty pulpitu

[2009-09-11 21:18:32 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys

[2009-09-11 21:18:26 | 00,130,936 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys

[2009-09-11 21:18:26 | 00,073,840 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys

2009-09-11 21:18:23 | 00,001,655 | ---- | C -- C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk

[2009-09-11 21:18:21 | 00,064,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys

[2009-09-11 21:18:21 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools

[2009-09-11 21:18:17 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor

[2009-09-11 21:18:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\PC Tools

[2009-09-11 21:18:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Tools

[2009-09-11 21:01:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files

[2009-09-11 20:49:15 | 00,000,000 | ---D | C] -- C:\Program Files\Java

[2009-09-11 20:47:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Sun

[2009-09-11 20:02:54 | 00,000,000 | ---D | C] -- C:\Program Files\SkanerOnline

[2009-09-10 22:09:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch

2009-09-10 21:52:16 | 00,028,288 | ---- | C -- C:\WINDOWS\System32\dllcache\xjis.nls

[2009-09-10 21:51:50 | 00,080,384 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll

[2009-09-10 21:51:49 | 00,080,384 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll

[2009-09-10 21:51:49 | 00,029,184 | ---- | C] (RICOH Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll

2009-09-10 21:51:44 | 00,083,748 | ---- | C -- C:\WINDOWS\System32\dllcache\prcp.nls

2009-09-10 21:51:44 | 00,083,748 | ---- | C -- C:\WINDOWS\System32\dllcache\prc.nls

2009-09-10 21:51:41 | 00,175,104 | ---- | C -- C:\WINDOWS\System32\dllcache\pintlcsa.dll

2009-09-10 21:51:24 | 00,047,066 | ---- | C -- C:\WINDOWS\System32\dllcache\ksc.nls

2009-09-10 21:51:23 | 01,158,818 | ---- | C -- C:\WINDOWS\System32\dllcache\korwbrkr.lex

2009-09-10 21:51:12 | 00,059,392 | ---- | C -- C:\WINDOWS\System32\dllcache\imscinst.exe

2009-09-10 21:51:10 | 00,196,665 | ---- | C -- C:\WINDOWS\System32\dllcache\imjpinst.exe

2009-09-10 21:51:07 | 00,134,339 | ---- | C -- C:\WINDOWS\System32\dllcache\imekr.lex

2009-09-10 21:51:00 | 13,463,552 | ---- | C -- C:\WINDOWS\System32\dllcache\hwxjpn.dll

2009-09-10 21:50:57 | 00,108,827 | ---- | C -- C:\WINDOWS\System32\dllcache\hanja.lex

2009-09-10 21:50:51 | 00,094,208 | ---- | C -- C:\WINDOWS\System32\dllcache\fpencode.dll

[2009-09-10 21:50:49 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll

[2009-09-10 21:50:49 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll

[2009-09-10 21:50:48 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll

2009-09-10 21:50:39 | 00,173,568 | ---- | C -- C:\WINDOWS\System32\dllcache\chtskf.dll

[2009-09-10 21:50:35 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys

-- Dodane 29.09.2009 (Wt) 19:40 --

2009-09-10 21:50:34 | 00,066,594 | ---- | C -- C:\WINDOWS\System32\dllcache\c_864.nls

2009-09-10 21:50:34 | 00,066,594 | ---- | C -- C:\WINDOWS\System32\dllcache\c_862.nls

2009-09-10 21:50:34 | 00,066,594 | ---- | C -- C:\WINDOWS\System32\dllcache\c_858.nls

2009-09-10 21:50:34 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_870.nls

2009-09-10 21:50:33 | 00,066,594 | ---- | C -- C:\WINDOWS\System32\dllcache\c_720.nls

2009-09-10 21:50:33 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_708.nls

2009-09-10 21:50:33 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_28596.nls

2009-09-10 21:50:33 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_21027.nls

2009-09-10 21:50:33 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_21025.nls

2009-09-10 21:50:32 | 00,180,770 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20932.nls

2009-09-10 21:50:32 | 00,177,698 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20949.nls

2009-09-10 21:50:32 | 00,173,602 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20936.nls

2009-09-10 21:50:32 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20924.nls

2009-09-10 21:50:32 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20880.nls

2009-09-10 21:50:31 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20871.nls

2009-09-10 21:50:31 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20838.nls

2009-09-10 21:50:31 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20833.nls

2009-09-10 21:50:31 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20424.nls

2009-09-10 21:50:31 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20423.nls

2009-09-10 21:50:31 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20420.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20297.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20290.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20285.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20284.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20280.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20278.nls

2009-09-10 21:50:30 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20277.nls

2009-09-10 21:50:29 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20273.nls

2009-09-10 21:50:29 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20269.nls

2009-09-10 21:50:29 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20108.nls

2009-09-10 21:50:29 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20107.nls

2009-09-10 21:50:29 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20106.nls

2009-09-10 21:50:29 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20105.nls

2009-09-10 21:50:28 | 00,187,938 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20005.nls

2009-09-10 21:50:28 | 00,186,402 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20001.nls

2009-09-10 21:50:28 | 00,185,378 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20003.nls

2009-09-10 21:50:28 | 00,180,258 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20004.nls

2009-09-10 21:50:28 | 00,173,602 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20002.nls

2009-09-10 21:50:27 | 00,189,986 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1361.nls

2009-09-10 21:50:27 | 00,180,258 | ---- | C -- C:\WINDOWS\System32\dllcache\c_20000.nls

2009-09-10 21:50:27 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1149.nls

2009-09-10 21:50:27 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1148.nls

2009-09-10 21:50:27 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1147.nls

2009-09-10 21:50:26 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1146.nls

2009-09-10 21:50:26 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1145.nls

2009-09-10 21:50:26 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1144.nls

2009-09-10 21:50:26 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1143.nls

2009-09-10 21:50:26 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1142.nls

2009-09-10 21:50:26 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1141.nls

2009-09-10 21:50:25 | 00,173,602 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10008.nls

2009-09-10 21:50:25 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1140.nls

2009-09-10 21:50:25 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_1047.nls

2009-09-10 21:50:25 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10021.nls

2009-09-10 21:50:25 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10005.nls

2009-09-10 21:50:24 | 00,195,618 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10002.nls

2009-09-10 21:50:24 | 00,177,698 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10003.nls

2009-09-10 21:50:24 | 00,162,850 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10001.nls

2009-09-10 21:50:24 | 00,066,082 | ---- | C -- C:\WINDOWS\System32\dllcache\c_10004.nls

2009-09-10 21:50:23 | 00,082,172 | ---- | C -- C:\WINDOWS\System32\dllcache\bopomofo.nls

2009-09-10 21:50:23 | 00,066,728 | ---- | C -- C:\WINDOWS\System32\dllcache\big5.nls

2009-09-10 21:48:48 | 00,000,488 | RH-- | C -- C:\WINDOWS\System32\logonui.exe.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | C -- C:\WINDOWS\WindowsShell.Manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | C -- C:\WINDOWS\System32\wuaucpl.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | C -- C:\WINDOWS\System32\sapi.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | C -- C:\WINDOWS\System32\ncpa.cpl.manifest

2009-09-10 21:34:04 | 00,171,588 | ---- | C -- C:\WINDOWS\System32\dllcache\startoc.cat

2009-09-10 21:34:04 | 00,037,509 | ---- | C -- C:\WINDOWS\System32\dllcache\MW770.CAT

2009-09-10 21:34:04 | 00,016,825 | ---- | C -- C:\WINDOWS\System32\dllcache\IMS.CAT

2009-09-10 21:34:04 | 00,013,497 | ---- | C -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT

2009-09-10 21:34:04 | 00,012,363 | ---- | C -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT

2009-09-10 21:34:04 | 00,010,027 | ---- | C -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT

2009-09-10 21:34:04 | 00,008,599 | ---- | C -- C:\WINDOWS\System32\dllcache\IASNT4.CAT

2009-09-10 21:34:04 | 00,007,407 | ---- | C -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT

2009-09-10 21:34:03 | 02,033,887 | ---- | C -- C:\WINDOWS\System32\dllcache\NT5.CAT

2009-09-10 21:34:03 | 01,246,357 | ---- | C -- C:\WINDOWS\System32\dllcache\SP3.CAT

2009-09-10 21:34:03 | 01,089,883 | ---- | C -- C:\WINDOWS\System32\dllcache\ntprint.cat

2009-09-10 21:34:03 | 00,808,524 | ---- | C -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT

2009-09-10 21:34:03 | 00,399,670 | ---- | C -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT

2009-09-10 21:34:03 | 00,033,765 | ---- | C -- C:\WINDOWS\System32\dllcache\FP4.CAT

2009-09-10 21:34:02 | 00,545,588 | ---- | C -- C:\WINDOWS\System32\dllcache\NT5INF.CAT

[2009-09-10 21:22:44 | 00,000,000 | ---D | C] -- C:\WINDOWS\setup.pss

[2009-09-09 18:21:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP

[2009-09-08 14:04:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\cache

2009-06-18 19:49:20 | 00,000,151 | ---- | C -- C:\WINDOWS\PhotoSnapViewer.INI

2009-06-18 18:08:31 | 00,040,960 | ---- | C -- C:\WINDOWS\System32\lxdxvs.dll

2009-06-18 18:08:29 | 00,360,448 | ---- | C -- C:\WINDOWS\System32\lxdxcoin.dll

2009-06-18 18:08:01 | 00,782,336 | ---- | C -- C:\WINDOWS\System32\lxdxdrs.dll

2009-06-18 18:08:01 | 00,081,920 | ---- | C -- C:\WINDOWS\System32\lxdxcaps.dll

2009-06-18 18:08:01 | 00,069,632 | ---- | C -- C:\WINDOWS\System32\lxdxcnv4.dll

2009-06-18 18:02:02 | 00,000,044 | ---- | C -- C:\WINDOWS\System32\lxdxrwrd.ini

2009-06-18 18:01:40 | 00,438,272 | ---- | C -- C:\WINDOWS\System32\LXDXhcp.dll

2009-06-18 18:01:40 | 00,364,544 | ---- | C -- C:\WINDOWS\System32\lxdxinpa.dll

2009-06-18 18:01:40 | 00,348,160 | ---- | C -- C:\WINDOWS\System32\LXDXinst.dll

2009-06-18 18:01:39 | 00,339,968 | ---- | C -- C:\WINDOWS\System32\lxdxiesc.dll

2009-06-18 18:01:38 | 00,843,776 | ---- | C -- C:\WINDOWS\System32\lxdxusb1.dll

2009-06-18 18:01:37 | 01,105,920 | ---- | C -- C:\WINDOWS\System32\lxdxserv.dll

2009-06-18 18:01:37 | 00,647,168 | ---- | C -- C:\WINDOWS\System32\lxdxpmui.dll

2009-06-18 18:01:37 | 00,053,248 | ---- | C -- C:\WINDOWS\System32\lxdxprox.dll

2009-06-18 18:01:36 | 00,569,344 | ---- | C -- C:\WINDOWS\System32\lxdxlmpm.dll

2009-06-18 18:01:34 | 00,663,552 | ---- | C -- C:\WINDOWS\System32\lxdxhbn3.dll

2009-06-18 18:01:33 | 00,208,896 | ---- | C -- C:\WINDOWS\System32\lxdxgrd.dll

2009-06-18 18:01:30 | 00,851,968 | ---- | C -- C:\WINDOWS\System32\lxdxcomc.dll

2009-06-18 18:01:30 | 00,376,832 | ---- | C -- C:\WINDOWS\System32\lxdxcomm.dll

2009-06-16 00:24:26 | 00,000,069 | ---- | C -- C:\WINDOWS\NeroDigital.ini

2009-06-15 20:35:00 | 00,005,810 | R--- | C -- C:\WINDOWS\System32\drivers\ASACPI.sys

2009-06-15 20:34:52 | 00,020,228 | ---- | C -- C:\WINDOWS\Ascd_tmp.ini

2009-06-15 20:34:52 | 00,010,296 | ---- | C -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

2009-02-09 07:18:00 | 01,724,416 | ---- | C -- C:\WINDOWS\System32\nvwdmcpl.dll

2009-02-09 07:18:00 | 01,507,328 | ---- | C -- C:\WINDOWS\System32\nview.dll

2009-02-09 07:18:00 | 01,101,824 | ---- | C -- C:\WINDOWS\System32\nvwimg.dll

2009-02-09 07:18:00 | 00,466,944 | ---- | C -- C:\WINDOWS\System32\nvshell.dll

2008-10-07 09:13:30 | 00,197,912 | ---- | C -- C:\WINDOWS\System32\physxcudart_20.dll

2008-10-07 09:13:22 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelSwedish.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelSpanish.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelPortugese.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelKorean.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelJapanese.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelGerman.dll

2008-10-07 09:13:20 | 00,058,648 | ---- | C -- C:\WINDOWS\System32\AgCPanelFrench.dll

2008-04-15 14:00:00 | 00,000,507 | ---- | C -- C:\WINDOWS\win.ini

2008-04-15 14:00:00 | 00,000,231 | ---- | C -- C:\WINDOWS\system.ini

2007-03-29 23:00:40 | 00,203,264 | R--- | C -- C:\WINDOWS\System32\CddbCdda.dll

========== Files - Modified Within 30 Days ==========

2009-09-29 19:28:05 | 00,210,919 | ---- | M -- C:\WINDOWS\System32\nvapps.xml

2009-09-29 19:27:26 | 00,013,722 | ---- | M -- C:\WINDOWS\System32\wpa.dbl

2009-09-29 19:27:22 | 00,000,006 | -H-- | M -- C:\WINDOWS\tasks\SA.DAT

2009-09-29 19:27:21 | 00,002,048 | --S- | M -- C:\WINDOWS\bootstat.dat

2009-09-29 19:27:18 | 00,010,752 | ---- | M -- C:\WINDOWS\System32\braviax.exe

2009-09-29 19:07:50 | 03,079,316 | -H-- | M -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2009-09-27 19:31:19 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Moje dokumenty\OTL.exe

[2009-09-27 03:36:58 | 00,167,936 | ---- | M] (Legal Corporation) -- C:\WINDOWS\System32_scui.cpl

2009-09-26 19:14:29 | 00,002,267 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk

[2009-09-23 20:14:57 | 00,159,856 | ---- | M] (TheBestSoft Corporation) -- C:\WINDOWS\System32\wisdstr.exe

2009-09-19 13:53:04 | 00,001,813 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk

2009-09-19 11:07:57 | 00,000,069 | ---- | M -- C:\WINDOWS\NeroDigital.ini

2009-09-18 21:24:27 | 00,028,672 | ---- | M -- C:\WINDOWS\System32\drivers\beep.sys

2009-09-11 21:18:23 | 00,001,655 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk

2009-09-11 20:18:12 | 00,001,374 | ---- | M -- C:\WINDOWS\imsins.BAK

2009-09-11 17:53:30 | 00,002,596 | ---- | M -- C:\WINDOWS\System32\CONFIG.NT

2009-09-11 15:22:05 | 01,114,842 | ---- | M -- C:\WINDOWS\System32\PerfStringBackup.INI

2009-09-11 15:22:05 | 00,499,854 | ---- | M -- C:\WINDOWS\System32\perfh015.dat

2009-09-11 15:22:05 | 00,440,820 | ---- | M -- C:\WINDOWS\System32\perfh009.dat

2009-09-11 15:22:05 | 00,089,036 | ---- | M -- C:\WINDOWS\System32\perfc015.dat

2009-09-11 15:22:05 | 00,071,138 | ---- | M -- C:\WINDOWS\System32\perfc009.dat

2009-09-11 14:36:25 | 00,100,640 | ---- | M -- C:\WINDOWS\System32\FNTCACHE.DAT

2009-09-10 21:52:48 | 00,025,748 | ---- | M -- C:\WINDOWS\System32\$winnt$.inf

2009-09-10 21:49:45 | 00,316,640 | ---- | M -- C:\WINDOWS\WMSysPr9.prx

2009-09-10 21:49:44 | 00,023,392 | ---- | M -- C:\WINDOWS\System32\nscompat.tlb

2009-09-10 21:49:44 | 00,016,832 | ---- | M -- C:\WINDOWS\System32\amcompat.tlb

2009-09-10 21:49:34 | 00,004,293 | ---- | M -- C:\WINDOWS\ODBCINST.INI

2009-09-10 21:48:48 | 00,000,488 | RH-- | M -- C:\WINDOWS\System32\WindowsLogon.manifest

2009-09-10 21:48:48 | 00,000,488 | RH-- | M -- C:\WINDOWS\System32\logonui.exe.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\WindowsShell.Manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\wuaucpl.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\sapi.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\nwc.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\ncpa.cpl.manifest

2009-09-10 21:48:44 | 00,000,749 | RH-- | M -- C:\WINDOWS\System32\cdplayer.exe.manifest

2009-09-10 21:48:35 | 00,000,507 | ---- | M -- C:\WINDOWS\win.ini

2009-09-10 21:48:09 | 00,023,640 | ---- | M -- C:\WINDOWS\System32\emptyregdb.dat

2009-09-10 21:44:55 | 00,000,211 | -HS- | M -- C:\boot.ini

2009-09-10 21:34:30 | 00,005,208 | ---- | M -- C:\WINDOWS\System32\pid.PNF

2009-09-10 21:34:23 | 00,000,231 | ---- | M -- C:\WINDOWS\system.ini

2009-09-10 21:19:05 | 00,878,141 | ---- | M -- C:\WINDOWS\setupapi.old

========== LOP Check ==========

[2009-09-29 19:26:02 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji

[2009-06-27 11:37:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ahead

[2009-06-18 19:33:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Aquadelic GT

[2009-08-16 10:55:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations

[2009-09-24 14:35:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM

[2009-08-16 10:58:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite

[2009-09-29 19:38:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP

[2009-06-27 13:03:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ThumbnailCache4R

[2009-09-29 19:26:02 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji

[2009-06-27 11:54:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Ahead

[2009-08-16 11:37:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Leadertech

[2009-06-18 18:16:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Lexmark Productivity Studio

[2009-07-26 18:47:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\MKS_VIR

[2009-08-16 11:04:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Nokia

[2009-09-05 20:08:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Nowe Gadu-Gadu

[2009-07-18 20:30:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\OpenFM

[2009-08-16 10:59:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\PC Suite

2008-04-15 14:00:00 | 00,000,065 | RH-- | M -- C:\WINDOWS\Tasks\desktop.ini

2009-09-29 19:27:22 | 00,000,006 | -H-- | M -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2

< End of report >


(deFco247) #9

Czy ty czytasz moje posty? :evil:

Z takiego wklejania logów na forum to się kiszka robi i się można pogubić.

No i przestań robić logi OTL, tylko zrób log Combofix.


(Tpwips) #10

nie mogę uruchomić Combofixa,


(deFco247) #11

Usuń go i pobierz go na nowo - już w czasie pobierania zmień mu nazwę na losową z rozszerzeniem .com

Podczas pobierania i skanowania Combofixem należy wyłączyć wszelkie antywirusy i firewalle.


(Tpwips) #12

zeskanowałem w końcu Combofixem, loga wkleiłem na wklej.org


(deFco247) #13

Podaj link do strony, która Ci się pojawiła po kliknięciu Wklej.


(jessica) #14

@ deFco247

Znalazłam ten log na wklej org (był podpisany przez @paszko-tp):

http://wklej.org/id/160608/

Miałeś rację - plik c:\windows\system32\drivers\beep.sys . . . jest zainfekowany

jessi


(deFco247) #15

No i całe szczęście Combofix odnalazł zdrową kopię zapasową tego pliku i podmienił ją. :slight_smile:

Log wygląda na czysty.

Jeśli masz jeszcze OTL-a, to uruchom go i kliknij w nim CleanUp ,

lub zastosuj OTC.

Wykonaj pełny skan DR WEB CureIt.

Gdy będą wirusy pokaż raport.

Wyczyść rejestr i dysk CCleaner.

Usuń zbędniki z autostartu.