:OTL PRC - [2011-10-30 10:49:56 | 000,344,576 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011-10-30 10:49:56 | 000,344,576 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:45:11 | 001,942,528 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-10-30 10:41:41 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe PRC - [2011-10-30 10:26:48 | 001,109,504 | -H-- | M] (Cronosoft) – C:\Windows\update.1\svchost.exe SRV - [2011-10-30 10:41:41 | 000,258,048 | ---- | M] () [Auto | Running] – C:\Windows\sysdriver32.exe – (srvsysdriver32) FF - prefs.js…extensions.enabledItems: engine@conduit.com:3.2.5.2 [2011-01-31 22:39:20 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\DOMOWY\AppData\Roaming\mozilla\Firefox\Profiles\aucjy6o2.default\extensions\engine@conduit.com [2010-01-20 12:16:28 | 000,000,939 | ---- | M] () – C:\Users\DOMOWY\AppData\Roaming\Mozilla\Firefox\Profiles\aucjy6o2.default\searchplugins\conduit.xml O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll File not found O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll File not found O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll File not found O3 - HKLM…\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll File not found O4 - HKLM…\Run: [1539350.exe] C:\Windows\Temp\1539350.exe () O4 - HKLM…\Run: [2505195.exe] C:\Windows\Temp\2505195.exe () O4 - HKLM…\Run: [6485491.exe] C:\Windows\Temp\6485491.exe () O4 - HKLM…\Run: [8219204.exe] C:\Users\DOMOWY\AppData\Local\Temp\8219204.exe () O4 - HKLM…\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe () O4 - HKLM…\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe () O4 - HKLM…\Run: [tray_ico] File not found O4 - HKLM…\Run: [tray_ico0] C:\Windows\update.tray-7-0\svchost.exe (Cronosoft) O4 - HKLM…\Run: [tray_ico1] C:\Windows\update.tray-12-0\svchost.exe (Cronosoft) O4 - HKLM…\Run: [tray_ico2] C:\Windows\update.tray-13-0\svchost.exe (Cronosoft) O4 - HKLM…\Run: [tray_ico3] File not found O4 - HKLM…\Run: [tray_ico4] File not found O4 - HKLM…\Run: [vProt] “C:\Program Files (x86)\AVG Secure Search\vprot.exe” File not found O4 - HKLM…\Run: [wxpdrv] C:\Windows\services32.exe (Cronosoft) O4 - HKCU…\Run: [] File not found O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8:64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll File not found O31 - SafeBoot: AlternateShell - services32.exe [2011-10-30 12:32:15 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-13-0-lnk [2011-10-30 12:32:15 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-13-0 [2011-10-30 11:12:21 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-12-0-lnk [2011-10-30 11:12:21 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-12-0 [2011-10-30 10:51:13 | 000,000,000 | —D | C] – C:\Windows\ufa [2011-10-30 10:51:13 | 000,000,000 | —D | C] – C:\Windows\rpcminer [2011-10-30 10:51:13 | 000,000,000 | —D | C] – C:\Windows\phoenix [2011-10-30 10:49:57 | 000,000,000 | -H-D | C] – C:\Windows\update.5.0 [2011-10-30 10:45:12 | 000,000,000 | -H-D | C] – C:\Windows\update.2 [2011-10-30 10:41:51 | 000,000,000 | —D | C] – C:\Windows\av_ico [2011-10-30 10:39:02 | 000,000,000 | -H-D | C] – C:\Windows\update.1 [2011-10-30 10:39:00 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0-lnk [2011-10-30 10:39:00 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0 [2011-10-30 10:27:09 | 001,109,504 | ---- | C] (Cronosoft) – C:\Windows\services32.exe [2011-10-31 20:10:00 | 000,001,048 | ---- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011-10-31 16:12:55 | 000,000,734 | ---- | M] () – C:\Windows\SysNative\drivers\etc\hîsts [2011-10-31 11:23:14 | 005,589,370 | ---- | M] () – C:\Windows\phoenix.rar [2011-10-31 11:23:14 | 001,075,284 | ---- | M] () – C:\Windows\rpcminer.rar [2011-10-31 11:23:14 | 000,246,272 | ---- | M] () – C:\Windows\unrar.exe [2011-10-31 11:23:14 | 000,182,617 | ---- | M] () – C:\Windows\ufa.rar [2011-10-30 10:50:57 | 000,000,113 | ---- | M] () – C:\Windows\info1 [2011-10-30 10:44:58 | 000,904,792 | ---- | M] () – C:\Windows\geoiplist.rar [2011-10-30 10:42:45 | 000,000,000 | ---- | M] () – C:\Windows\loader2.exe_ok [2011-10-30 10:41:41 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe [2011-10-30 10:41:41 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe [2011-10-30 10:26:48 | 001,109,504 | ---- | M] (Cronosoft) – C:\Windows\services32.exe [2011-10-30 10:44:59 | 004,636,907 | ---- | C] () – C:\Windows\geoiplist @Alternate Data Stream - 24 bytes -> C:\Windows:94D932B35375251B @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:8CE646EE :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] “AlternateShell”=“cmd.exe” :Commands [RESETHOSTS] [emptytemp]