Jak usunąć win32 trojan-gen{other} i inny syf

Nie chcę robić formata …chciałabym to usunąc jakims sposobem,czy może ktos wtajemniczony w ow problem moze mi pomoc??? :frowning: ![-o<

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:54:26, on 2008-08-15

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\HP\QuickPlay\QPService.exe

C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\Program Files\Alwil Software\Avast4\ashDisp.exe

C:\Program Files\TrojanHunter 5.0\THGuard.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Program Files\Corel\Graphics9\Register\Remind32.exe

C:\WINDOWS\System32\rundll32.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

C:\Windows\system32\conime.exe

C:\Program Files\Internet Explorer\iexplore.exe

c:\program files\winamp toolbar\WinampTbServer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll

O3 - Toolbar: Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O4 - HKLM…\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM…\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM…\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM…\Run: [QPService] “C:\Program Files\HP\QuickPlay\QPService.exe”

O4 - HKLM…\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

O4 - HKLM…\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM…\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

O4 - HKLM…\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

O4 - HKLM…\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe”

O4 - HKLM…\Run: [Adobe Photo Downloader] “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe”

O4 - HKLM…\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM…\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”

O4 - HKLM…\Run: [THGuard] “C:\Program Files\TrojanHunter 5.0\THGuard.exe”

O4 - HKUS\S-1-5-19…\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘USŁUGA LOKALNA’)

O4 - HKUS\S-1-5-19…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘USŁUGA LOKALNA’)

O4 - HKUS\S-1-5-20…\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘USŁUGA SIECIOWA’)

O4 - Startup: Rejestrowanie produktów Corela.lnk = C:\Program Files\Corel\Graphics9\Register\Remind32.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: Przypomnij o aukcji - file://C:\Users\Andzia\AppData\Roaming\Aukcjoner.net\reminder.htm

O8 - Extra context menu item: Upoluj aukcję snajperem - file://C:\Users\Andzia\AppData\Roaming\Aukcjoner.net\sniper.htm

O8 - Extra context menu item: Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: Sprawdź/oceń sprzedającego - file://C:\Users\Andzia\AppData\Roaming\Aukcjoner.net\feedback.htm

O8 - Extra context menu item: Wyślij obraz do urządzenia Bluetooth… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O8 - Extra context menu item: Wyślij stronę do urządzenia Bluetooth… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra ‘Tools’ menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O13 - Gopher Prefix:

O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/conte … ite_EN.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow … eqlab3.cab

O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s … wflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe

O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

End of file - 9766 bytes

wpisy

usuń HijackThisem >> Fix checked

Pobierz HijackThis http://forum.dobreprogramy.pl/viewtopic.php?f=16&t=36654 ale nie włączaj

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri … iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

:slight_smile:

Nie wiem czy dobrze zrobiłam …ale wyszło coś takiego #-o

ComboFix 08-08-14.03 - Andzia 2008-08-15 17:18:35.3 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1045.18.1260 [GMT 2:00]

Running from: C:\Users\Andzia\Desktop\ComboFix.exe

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

C:\Users\Andzia\AppData\Roaming\Microsoft\Windows\Cookies\andzia@nuggad[2].txt

C:\Users\Andzia\AppData\Roaming\Microsoft\Windows\Cookies\andzia@tradedoubler[2].txt

C:\Windows\g32.txt

C:\Windows\system32\actskn43.ocx

.

((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))

.

2008-08-15 15:54 . 2008-08-15 15:54

2008-08-15 14:09 . 2008-08-15 14:09

2008-08-15 13:34 . 2008-08-15 13:34

2008-08-15 13:18 . 2008-08-15 13:18

2008-08-15 13:15 . 2008-08-15 13:15

2008-08-15 13:15 . 2008-08-15 13:15

2008-08-15 11:51 . 2008-08-14 01:54

2008-08-15 10:07 . 2008-08-15 10:07

2008-08-13 23:41 . 2008-08-13 23:41 0 --a------ C:\Users\Andzia\AppData\Roaming\wklnhst.dat

2008-08-04 20:37 . 2008-08-04 20:37

2008-08-04 20:37 . 2008-08-04 20:37

2008-08-04 20:37 . 2008-08-04 20:37

2008-08-04 20:37 . 2008-08-04 20:37

2008-08-04 20:37 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\System32\drivers\mbamswissarmy.sys

2008-08-04 20:37 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\System32\drivers\mbam.sys

2008-08-04 19:59 . 2008-08-04 19:59

2008-08-04 19:59 . 2008-08-04 19:59

2008-08-04 19:42 . 2008-08-04 20:49

2008-08-04 19:42 . 2008-08-04 20:55

2008-08-04 19:17 . 2008-08-15 13:14

2008-08-04 19:17 . 2008-08-15 13:14

2008-07-31 18:27 . 2008-07-31 18:27

2008-07-31 18:13 . 2008-07-31 18:38 10 --a------ C:\s2windir.tmp

2008-07-30 22:44 . 2008-08-04 20:46

2008-07-29 23:29 . 2008-07-30 15:15

2008-07-29 23:29 . 2000-03-15 14:33 151,824 --a------ C:\WINDOWS\System32\temp.000

2008-07-28 09:21 . 2008-07-28 09:21

2008-07-28 09:20 . 2008-07-28 09:20

2008-07-28 09:07 . 2008-07-28 22:25

2008-07-28 09:07 . 2008-07-28 22:25

2008-07-28 09:07 . 2008-07-28 22:25

2008-07-26 21:40 . 2008-07-26 21:40

2008-07-20 12:28 . 2008-07-20 12:28

2008-07-20 12:28 . 2008-07-20 12:28

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-15 14:49 79,478 ----a-w C:\Users\Andzia\AppData\Roaming\nvModes.dat

2008-08-15 11:51 --------- d-----w C:\Users\Andzia\AppData\Roaming\Skype

2008-08-15 11:39 --------- d-----w C:\Program Files\PrivacyIns

2008-08-15 07:49 --------- d-----w C:\Users\Andzia\AppData\Roaming\skypePM

2008-07-28 07:20 --------- d-----w C:\Program Files\Common Files\Adobe

2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys

2008-07-10 01:06 --------- d-----w C:\Program Files\Windows Mail

2008-07-05 12:42 --------- d-----w C:\Users\Andzia\AppData\Roaming\Roxio

2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll

2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll

2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll

2008-06-25 19:03 --------- d-----w C:\Users\Andzia\AppData\Roaming\Corel

2008-06-21 17:43 --------- d-----w C:\Program Files\Odkurzacz

2008-06-21 14:09 --------- d-----w C:\Users\Andzia\AppData\Roaming\Media Player Classic

2008-06-21 14:09 --------- d-----w C:\Program Files\Real Alternative

2008-06-19 12:58 --------- d–h--w C:\Program Files\InstallShield Installation Information

2008-06-18 22:36 --------- d-----w C:\Users\Andzia\AppData\Roaming\TomTom

2008-06-18 22:36 --------- d-----w C:\Program Files\TomTom HOME 2

2008-06-18 22:33 --------- d-----w C:\Program Files\TomTom HOME

2008-06-18 22:00 --------- d-----w C:\ProgramData\TomTom

2008-06-18 21:50 0 —ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-06-17 22:00 --------- d-----w C:\Program Files\MSN Messenger

2008-06-17 21:56 174 --sha-w C:\Program Files\desktop.ini

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Sidebar

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Journal

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Defender

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Collaboration

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Calendar

2008-06-17 21:29 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-06-17 21:29 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-06-07 10:29 446,464 ----a-w C:\Windows\System32\nvuninst.exe

2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll

2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll

2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe

2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll

2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll

2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll

2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll

2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll

2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll

2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll

2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll

2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll

2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll

2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll

2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll

2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin

2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin

2007-12-31 14:15 32 ----a-w C:\Users\All Users\ezsid.dat

2007-12-31 14:15 32 ----a-w C:\ProgramData\ezsid.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

“{3041D03E-FD4B-44E0-B742-2D9B88305F98}”= “C:\Program Files\AskBarDis\bar\bin\askBar.dll” [2008-07-07 15:13 279944]

[HKEY_CLASSES_ROOT\clsid{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“SMSERIAL”=“C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe” [2007-01-16 23:34 634880]

“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-01-13 05:36 827392]

“QPService”=“C:\Program Files\HP\QuickPlay\QPService.exe” [2007-04-23 18:11 176128]

“HP Health Check Scheduler”=“C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe” [2007-03-12 11:54 50696]

“HP Software Update”=“C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe” [2005-02-16 23:11 49152]

“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 05:25 144784]

“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe” [2007-03-09 12:09 63712]

“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-07-19 16:38 78008]

“NvSvc”=“C:\Windows\system32\nvsvc.dll” [2007-05-01 12:27 86016]

“NvCplDaemon”=“C:\Windows\system32\NvCpl.dll” [2007-05-01 12:27 8429568]

“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 02:38 34672]

“THGuard”=“C:\Program Files\TrojanHunter 5.0\THGuard.exe” [2008-08-12 12:28 1056928]

C:\Users\Andzia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Rejestrowanie produkt˘w Corela.lnk - C:\Program Files\Corel\Graphics9\Register\Remind32.exe [2007-12-31 19:14:05 67584]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 13:27:40 719664]

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-22 03:00:00 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

“EnableLUA”= 0 (0x0)

“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

“AppInit_DLLs”=APSHook.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

“MSACM.l3codec”= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

“UacDisableNotify”=dword:00000001

“InternetSettingsDisableNotify”=dword:00000001

“AutoUpdateDisableNotify”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

“DisableMonitoring”=dword:00000001

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

“{DC6B58C1-F27F-46B6-BC49-7F3725435A97}”= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)

“{A7EE9358-BE7C-43D9-B98E-AFFD8596C1B8}”= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play

“{0C2F0C4D-11B0-449B-B2CE-F9DE879042EA}”= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program

“TCP Query User{A4E3460D-EDBA-4461-8954-8596F29DA569}C:\program files\gadu-gadu\gg.exe”= UDP:C:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny

“UDP Query User{5FE68F57-EBBE-426B-B29F-9E85E91375DB}C:\program files\gadu-gadu\gg.exe”= TCP:C:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny

“{DA91E17A-367A-42EA-A21B-AE8F5B482CA1}”= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb

“{B9796EBD-E131-4BF1-B736-5FF2FFAE00AA}”= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb

“{B16CFCB3-89ED-4191-BB3F-8E37899809FB}”= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray

“{A414476C-4ACE-4668-A62C-4F7381E52F93}”= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray

“{32C18C9E-2317-4647-942F-CF4113252FBF}”= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR

“{94DB8010-B0FA-48B0-B620-A87BF8D1E1CD}”= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR

“{EDE676BA-46DA-43B9-A546-7D6E5E73D382}”= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client

“{C55ADEFD-B930-4CCA-8779-F28142700AB1}”= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client

“{74370C0B-8911-4990-89B9-B884CE98A6F8}”= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

“{CC86A6BD-7D3E-4806-B45A-C77E1217241F}”= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

“{EED99883-19AE-4483-BE12-5DB72A74D5F8}”= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 16:35]

R2 ASBroker;Logon Session Broker;C:\Windows\System32\svchost.exe [2008-01-19 09:33]

R2 ASChannel;Local Communication Channel;C:\Windows\System32\svchost.exe [2008-01-19 09:33]

R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 16:36]

R3 btwaudio;Urządzenie dźwiękowe Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-01-02 12:45]

R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-01-02 12:45]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-01-02 12:45]

S2 USBHSB;GeneLink File Transfer Driver;C:\Windows\system32\Drivers\usbhsb.sys [2001-12-17 18:42]

S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\system32\DRIVERS\athrusb.sys [2006-12-22 21:05]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

Cognizance REG_MULTI_SZ ASBroker ASChannel

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{37480347-00bc-11dd-ab03-001e375c6e0d}]

\shell\AutoRun\command - F:\InstallTomTomHOME.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{986b3071-36fd-11dd-bbca-001e375c6e0d}]

\shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b78e9093-e1e0-11dc-9120-001e375c6e0d}]

\shell\AutoRun\command - G:\USBNB.exe

.

Contents of the ‘Scheduled Tasks’ folder

2008-08-01 C:\Windows\Tasks\HPCeeScheduleForAndzia.job

  • C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-03-23 14:23]

2008-08-15 C:\Windows\Tasks\User_Feed_Synchronization-{B7695DE8-E645-418A-ABC7-14FB60798B80}.job

  • C:\Windows\system32\msfeedssync.exe [2008-01-19 09:33]

.

.

------- Supplementary Scan -------

.

FireFox -: Profile - C:\Users\Andzia\AppData\Roaming\Mozilla\Firefox\Profiles\6hhp6n0e.default\

FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-15 17:21:30

Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2008-08-15 17:23:16

ComboFix-quarantined-files.txt 2008-08-15 15:23:03

Pre-Run: 101,730,136,064 bajtów wolnych

Post-Run: 101,693,767,680 bajtów wolnych

212 — E O F — 2008-08-06 07:36:10

Myślałam ,ze już go nie ma a Avast znowu go pokazał win32 trojan-gen{other} pomocy !!

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri … iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

Pobierz System Repair Engineer

http://www.cybertrash.pl/images/tata/System%20Repair/System%20Repair%20Engineer.html

przeskanuj daj log

:slight_smile:

o Jezuuuuu…mam nadzieję ,ze to to

http://up.wklej.org/download.php?id=696 … 71476ec255

do kompletu daj

:slight_smile:

o tak chyba bedzie lepiej :slight_smile:

http://wklej.org/id/218f176871

ComboFix 08-08-14.03 - Andzia 2008-08-15 23:01:32.4 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1045.18.1169 [GMT 2:00]

Running from: C:\Users\Andzia\Desktop\ComboFix.exe

Command switches used :: C:\Users\Andzia\Desktop\CFScript.txt

* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Users\Andzia\AppData\Roaming\Microsoft\Windows\Cookies\andzia@tradedoubler[1].txt

.

((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))

.

No new files created in this timespan

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-15 19:11 79,478 ----a-w C:\Users\Andzia\AppData\Roaming\nvModes.dat

2008-08-15 18:23 --------- d-----w C:\Program Files\Windows Mail

2008-08-15 18:22 --------- d-----w C:\Program Files\Microsoft Works

2008-08-15 18:14 --------- d-----w C:\Program Files\TrojanHunter 5.0

2008-08-15 17:14 --------- d-----w C:\Program Files\PrivacyIns

2008-08-15 13:54 --------- d-----w C:\Program Files\Trend Micro

2008-08-15 11:51 --------- d-----w C:\Users\Andzia\AppData\Roaming\Skype

2008-08-15 11:18 --------- d-----w C:\Users\Andzia\AppData\Roaming\GlarySoft

2008-08-15 11:14 --------- d—a-w C:\ProgramData\TEMP

2008-08-15 07:49 --------- d-----w C:\Users\Andzia\AppData\Roaming\skypePM

2008-08-13 21:41 0 ----a-w C:\Users\Andzia\AppData\Roaming\wklnhst.dat

2008-08-04 18:55 --------- d-----w C:\Program Files\Unlocker

2008-08-04 18:49 --------- d-----w C:\Users\Andzia\AppData\Roaming\Desktopicon

2008-08-04 18:46 --------- d-----w C:\Program Files\Applications

2008-08-04 18:37 --------- d-----w C:\Users\Andzia\AppData\Roaming\Malwarebytes

2008-08-04 18:37 --------- d-----w C:\ProgramData\Malwarebytes

2008-08-04 17:59 --------- d-----w C:\Users\Andzia\AppData\Roaming\Lavasoft

2008-08-04 17:59 --------- d-----w C:\Program Files\Lavasoft

2008-07-28 20:25 --------- d-----w C:\ProgramData\NOS

2008-07-28 20:25 --------- d-----w C:\Program Files\NOS

2008-07-28 07:21 --------- d-----w C:\Program Files\SystemRequirementsLab

2008-07-28 07:20 --------- d-----w C:\Program Files\Common Files\Adobe AIR

2008-07-28 07:20 --------- d-----w C:\Program Files\Common Files\Adobe

2008-07-20 10:28 --------- d-----w C:\ProgramData\WindowsSearch

2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys

2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll

2008-07-05 12:42 --------- d-----w C:\Users\Andzia\AppData\Roaming\Roxio

2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll

2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll

2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll

2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll

2008-06-25 19:03 --------- d-----w C:\Users\Andzia\AppData\Roaming\Corel

2008-06-21 17:43 --------- d-----w C:\Program Files\Odkurzacz

2008-06-21 14:09 --------- d-----w C:\Users\Andzia\AppData\Roaming\Media Player Classic

2008-06-19 12:58 --------- d–h--w C:\Program Files\InstallShield Installation Information

2008-06-19 03:31 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL

2008-06-18 22:36 --------- d-----w C:\Users\Andzia\AppData\Roaming\TomTom

2008-06-18 22:36 --------- d-----w C:\Program Files\TomTom HOME 2

2008-06-18 22:33 --------- d-----w C:\Program Files\TomTom HOME

2008-06-18 22:00 --------- d-----w C:\ProgramData\TomTom

2008-06-18 21:50 0 —ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-06-17 22:00 --------- d-----w C:\Program Files\MSN Messenger

2008-06-17 21:56 174 --sha-w C:\Program Files\desktop.ini

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Sidebar

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Journal

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Defender

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Collaboration

2008-06-17 21:48 --------- d-----w C:\Program Files\Windows Calendar

2008-06-17 21:29 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-06-17 21:29 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-06-07 10:29 446,464 ----a-w C:\Windows\System32\nvuninst.exe

2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll

2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll

2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe

2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll

2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll

2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll

2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll

2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll

2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll

2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll

2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll

2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll

2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll

2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll

2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll

2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin

2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin

2007-12-31 14:15 32 ----a-w C:\Users\All Users\ezsid.dat

2007-12-31 14:15 32 ----a-w C:\ProgramData\ezsid.dat

.

((((((((((((((((((((((((((((( snapshot@2008-08-15_17.22.17.35 )))))))))))))))))))))))))))))))))))))))))

.

  • 2008-08-15 11:52:02 2,484 ----a-w C:\Windows\bthservsdp.dat
  • 2008-08-15 18:25:56 2,484 ----a-w C:\Windows\bthservsdp.dat

  • 2008-08-15 21:01:18 6,295,552 ----a-w C:\Windows\erdnt\Hiv-backup\schema.dat

  • 2005-08-19 12:16:04 225,280 ----a-r C:\Windows\Installer$PatchCache$\Managed\1C09DA9E1826BA54498590D8E27F071A\8.5.822\F20963_wkssole.dll

  • 2005-08-19 12:16:38 2,023,424 ----a-r C:\Windows\Installer$PatchCache$\Managed\1C09DA9E1826BA54498590D8E27F071A\8.5.822\F22194_wksssdb.dll

  • 2007-06-02 08:13:20 65,536 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_3ABBFDC64D00_434D_AE00_E05042B0981A.exe
  • 2008-08-15 18:22:50 65,536 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_3ABBFDC64D00_434D_AE00_E05042B0981A.exe
  • 2007-06-02 08:13:20 65,536 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_44ADD10F9890_494E_B2E6_68F0E2F9BCB3.exe
  • 2008-08-15 18:22:50 65,536 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_44ADD10F9890_494E_B2E6_68F0E2F9BCB3.exe
  • 2007-06-02 08:13:20 184,320 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_5D99329DEC39_4564_8496_164FE5A9398D.exe
  • 2008-08-15 18:22:50 184,320 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_5D99329DEC39_4564_8496_164FE5A9398D.exe
  • 2007-06-02 08:13:20 65,536 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_7B06BE84B790_47C5_B2A6_9D5500437C9B.exe
  • 2008-08-15 18:22:50 65,536 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}_7B06BE84B790_47C5_B2A6_9D5500437C9B.exe
  • 2007-06-02 08:13:20 17,534 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}\gtngstrtd.exe
  • 2008-08-15 18:22:50 17,534 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}\gtngstrtd.exe
  • 2007-06-02 08:13:20 4,710 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}\Win2Kico.exe
  • 2008-08-15 18:22:50 4,710 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}\Win2Kico.exe
  • 2007-06-02 08:13:20 4,710 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}\WSBico.exe
  • 2008-08-15 18:22:50 4,710 ----a-r C:\Windows\Installer{E9AD90C1-6281-45AB-9458-098D2EF770A1}\WSBico.exe
  • 2008-08-15 15:12:05 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  • 2008-08-15 18:27:39 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  • 2008-08-15 15:12:05 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  • 2008-08-15 18:27:39 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  • 2008-08-15 15:13:19 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
  • 2008-08-15 18:28:56 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat

  • 2008-08-15 18:28:56 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

  • 2008-08-15 15:13:19 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
  • 2008-08-15 18:29:01 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat

  • 2008-08-15 18:29:01 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

  • 2008-08-15 15:15:08 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2008-08-15 20:22:51 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2008-08-15 15:15:08 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2008-08-15 20:22:51 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2008-08-15 15:15:08 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2008-08-15 20:22:51 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2008-01-19 07:34:20 262,144 ----a-w C:\Windows\System32\es.dll
  • 2008-04-18 05:48:39 269,312 ----a-w C:\Windows\System32\es.dll
  • 2008-01-19 07:34:31 6,068,736 ----a-w C:\Windows\System32\ieframe.dll
  • 2008-06-27 04:15:23 6,068,736 ----a-w C:\Windows\System32\ieframe.dll
  • 2008-01-19 07:34:34 738,304 ----a-w C:\Windows\System32\inetcomm.dll
  • 2008-04-10 05:12:41 738,304 ----a-w C:\Windows\System32\inetcomm.dll
  • 2008-04-25 04:35:13 28,160 ----a-w C:\Windows\System32\jsproxy.dll
  • 2008-06-27 04:15:24 28,160 ----a-w C:\Windows\System32\jsproxy.dll

  • 2003-09-04 12:14:28 94,208 ----a-w C:\Windows\System32\Macromed\Flash\GetFlash.exe

  • 2008-04-25 04:35:24 64,512 ----a-w C:\Windows\System32\migration\WininetPlugin.dll
  • 2008-06-27 04:15:28 64,512 ----a-w C:\Windows\System32\migration\WininetPlugin.dll
  • 2008-06-25 16:15:46 17,972,344 ----a-w C:\Windows\System32\mrt.exe
  • 2008-08-05 18:11:01 15,888,504 ----a-w C:\Windows\System32\mrt.exe
  • 2008-04-25 04:35:14 3,578,368 ----a-w C:\Windows\System32\mshtml.dll
  • 2008-06-27 04:15:24 3,578,368 ----a-w C:\Windows\System32\mshtml.dll
  • 2008-04-25 04:35:16 671,232 ----a-w C:\Windows\System32\mstime.dll
  • 2008-06-27 04:15:25 671,232 ----a-w C:\Windows\System32\mstime.dll
  • 2008-08-13 06:41:09 6,553,600 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
  • 2008-08-15 18:38:10 6,553,600 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
  • 2008-04-25 04:35:19 1,166,336 ----a-w C:\Windows\System32\urlmon.dll
  • 2008-06-27 04:15:28 1,166,336 ----a-w C:\Windows\System32\urlmon.dll
  • 2008-08-15 15:15:32 12,436 ----a-w C:\Windows\System32\WDI{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3399563553-3779316313-103173775-1000_UserData.bin
  • 2008-08-15 18:29:55 12,696 ----a-w C:\Windows\System32\WDI{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3399563553-3779316313-103173775-1000_UserData.bin
  • 2008-08-15 15:15:31 82,912 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
  • 2008-08-15 18:29:55 82,960 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
  • 2008-08-15 11:55:20 51,812 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
  • 2008-08-15 18:29:53 52,172 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
  • 2008-08-15 13:36:05 303,140 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
  • 2008-08-15 20:47:08 303,718 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
  • 2008-08-13 06:42:08 124,006,514 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
  • 2008-08-15 18:25:41 124,629,407 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin

  • 2008-07-16 04:09:38 124,928 ----a-w C:\Windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16717_none_a9e15ad3f5abc778\advpack.dll

  • 2008-07-18 03:13:52 124,928 ----a-w C:\Windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.20879_none_aa2c18ab0ef84196\advpack.dll

  • 2008-04-19 08:13:07 268,800 ----a-w C:\Windows\winsxs\x86_microsoft-windows-c…complus-eventsystem_31bf3856ad364e35_6.0.6000.16677_none_0ac2b30954c98430\es.dll

  • 2008-04-19 08:27:37 268,800 ----a-w C:\Windows\winsxs\x86_microsoft-windows-c…complus-eventsystem_31bf3856ad364e35_6.0.6000.20818_none_0b8e318c6db592d2\es.dll

  • 2008-04-18 05:48:39 269,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-c…complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_0cbe918751dfdd3f\es.dll

  • 2008-04-18 05:30:29 269,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-c…complus-eventsystem_31bf3856ad364e35_6.0.6001.22162_none_0d385cf46b0a1a47\es.dll

  • 2008-06-27 03:54:48 44,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16711_none_ebd662c7164a156d\pngfilt.dll

  • 2008-06-27 03:49:09 44,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…ablenetworkgraphics_31bf3856ad364e35_6.0.6000.20868_none_ec30f1fc2f89f24d\pngfilt.dll

  • 2008-06-27 03:54:49 1,159,680 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…ersandsecurityzones_31bf3856ad364e35_6.0.6000.16711_none_b2f30b79d9aa8cd1\urlmon.dll

  • 2008-06-27 03:49:41 1,162,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…ersandsecurityzones_31bf3856ad364e35_6.0.6000.20868_none_b34d9aaef2ea69b1\urlmon.dll

  • 2008-06-27 04:15:28 1,166,336 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…ersandsecurityzones_31bf3856ad364e35_6.0.6001.18099_none_b48acb29d70acadb\urlmon.dll

  • 2008-06-27 03:50:29 1,166,848 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…ersandsecurityzones_31bf3856ad364e35_6.0.6001.22212_none_b563e734efedd6e3\urlmon.dll

  • 2008-06-27 03:54:47 671,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16711_none_ded59a427f534c40\mstime.dll

  • 2008-06-27 03:47:51 671,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…mlrenderingadvanced_31bf3856ad364e35_6.0.6000.20868_none_df30297798932920\mstime.dll

  • 2008-06-27 04:15:25 671,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18099_none_e06d59f27cb38a4a\mstime.dll

  • 2008-06-27 03:48:43 671,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22212_none_e14675fd95969652\mstime.dll

  • 2008-07-15 23:48:18 2,048 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6000.16717_none_135d4bd00c6d4a6b\tzres.dll

  • 2008-07-16 04:09:30 18,944 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6000.16717_none_135d4bd00c6d4a6b\tzupd.exe

  • 2008-07-15 23:43:45 2,048 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6000.20878_none_13a7095d25baab32\tzres.dll

  • 2008-07-16 01:28:34 18,944 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6000.20878_none_13a7095d25baab32\tzupd.exe

  • 2008-07-16 01:32:44 2,048 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6001.18108_none_154f5aac098ad8c2\tzres.dll

  • 2008-01-19 07:33:33 18,944 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6001.18108_none_154f5aac098ad8c2\tzupd.exe

  • 2008-07-16 01:27:35 2,048 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6001.22223_none_15be562d22bd31bb\tzres.dll

  • 2008-07-16 01:27:35 18,944 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…rnational-timezones_31bf3856ad364e35_6.0.6001.22223_none_15be562d22bd31bb\tzupd.exe

  • 2008-06-27 03:54:45 27,648 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6000.16711_none_fff8e71ba4b3b364\jsproxy.dll

  • 2008-06-27 03:54:49 826,368 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6000.16711_none_fff8e71ba4b3b364\wininet.dll

  • 2008-06-27 03:54:49 64,512 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6000.16711_none_fff8e71ba4b3b364\WininetPlugin.dll

  • 2008-06-27 03:47:03 27,648 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6000.20868_none_00537650bdf39044\jsproxy.dll

  • 2008-06-27 03:49:46 827,904 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6000.20868_none_00537650bdf39044\wininet.dll

  • 2008-06-27 03:49:46 64,512 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6000.20868_none_00537650bdf39044\WininetPlugin.dll

  • 2008-06-27 04:15:24 28,160 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6001.18099_none_0190a6cba213f16e\jsproxy.dll

  • 2008-06-27 04:15:28 827,392 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6001.18099_none_0190a6cba213f16e\wininet.dll

  • 2008-06-27 04:15:28 64,512 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6001.18099_none_0190a6cba213f16e\WininetPlugin.dll

  • 2008-06-27 03:47:35 28,160 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6001.22212_none_0269c2d6baf6fd76\jsproxy.dll

  • 2008-06-27 03:50:35 827,904 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6001.22212_none_0269c2d6baf6fd76\wininet.dll

  • 2008-06-27 03:50:35 64,512 ----a-w C:\Windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_6.0.6001.22212_none_0269c2d6baf6fd76\WininetPlugin.dll

  • 2008-06-27 03:54:45 383,488 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16711_none_f9a209f56e9f2db7\ieapfltr.dll

  • 2008-06-27 03:46:48 383,488 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.20868_none_f9fc992a87df0a97\ieapfltr.dll

  • 2008-06-27 03:54:44 347,136 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16711_none_95d642ad8484b3e5\dxtmsft.dll

  • 2008-06-27 03:54:44 214,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16711_none_95d642ad8484b3e5\dxtrans.dll

  • 2008-06-27 03:46:25 347,136 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.20868_none_9630d1e29dc490c5\dxtmsft.dll

  • 2008-06-27 03:46:25 214,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.20868_none_9630d1e29dc490c5\dxtrans.dll

  • 2008-06-27 03:54:45 477,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16711_none_4638dd0546456672\mshtmled.dll

  • 2008-06-27 03:47:32 477,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.20868_none_46936c3a5f854352\mshtmled.dll

  • 2008-06-27 03:54:45 3,592,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16711_none_1153063a250a1c9a\mshtml.dll

  • 2008-06-27 03:47:31 3,594,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20868_none_11ad956f3e49f97a\mshtml.dll

  • 2008-06-27 04:15:24 3,578,368 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18099_none_12eac5ea226a5aa4\mshtml.dll

  • 2008-06-27 03:48:28 3,578,880 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22212_none_13c3e1f53b4d66ac\mshtml.dll

  • 2008-06-27 03:54:45 63,488 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16711_none_58ab7304671ea8a3\icardie.dll

  • 2008-06-27 03:46:48 63,488 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.20868_none_59060239805e8583\icardie.dll

  • 2008-06-27 03:54:09 26,624 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\ieUnatt.exe

  • 2008-06-27 03:54:09 625,664 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe

  • 2008-06-27 01:41:11 26,624 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\ieUnatt.exe

  • 2008-06-27 01:41:30 625,664 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe

  • 2008-06-27 03:54:09 70,656 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16711_none_c3e0a8c26159eaec\ie4uinit.exe

  • 2008-06-27 03:54:45 44,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16711_none_c3e0a8c26159eaec\iernonce.dll

  • 2008-06-27 03:54:45 56,320 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16711_none_c3e0a8c26159eaec\iesetup.dll

  • 2008-06-27 01:41:00 70,656 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20868_none_c43b37f77a99c7cc\ie4uinit.exe

  • 2008-06-27 03:46:49 44,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20868_none_c43b37f77a99c7cc\iernonce.dll

  • 2008-06-27 03:46:49 56,320 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20868_none_c43b37f77a99c7cc\iesetup.dll

  • 2008-06-27 03:54:45 52,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16711_none_2a05bf326809c049\iebrshim.dll

  • 2008-06-27 03:46:48 52,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.20868_none_2a604e6781499d29\iebrshim.dll

  • 2008-06-27 03:54:45 6,066,176 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16711_none_62b2603db0ffaac7\ieframe.dll

  • 2008-06-27 03:54:45 180,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16711_none_62b2603db0ffaac7\ieui.dll

  • 2008-06-27 03:46:49 6,068,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.20868_none_630cef72ca3f87a7\ieframe.dll

  • 2008-06-27 03:46:49 180,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.20868_none_630cef72ca3f87a7\ieui.dll

  • 2008-06-27 04:15:23 6,068,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18099_none_644a1fedae5fe8d1\ieframe.dll

  • 2008-06-27 03:47:06 6,070,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22212_none_65233bf8c742f4d9\ieframe.dll

  • 2008-06-27 03:47:06 180,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22212_none_65233bf8c742f4d9\ieui.dll

  • 2008-06-27 03:54:09 263,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16711_none_e6abccbc9482feff\ieinstal.exe

  • 2008-06-27 01:41:23 263,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.20868_none_e7065bf1adc2dbdf\ieinstal.exe

  • 2008-06-27 03:54:09 301,568 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16711_none_0b5401d8d6fdbeb1\ieuser.exe

  • 2008-06-27 01:41:24 301,568 ----a-w C:\Windows\winsxs\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.20868_none_0bae910df03d9b91\ieuser.exe

  • 2008-04-30 05:29:59 454,656 ----a-w C:\Windows\winsxs\x86_microsoft-windows-m…nts-mdac-rds-ce-dll_31bf3856ad364e35_6.0.6000.16683_none_5fb7376b44d6ca52\msadce.dll

  • 2008-04-30 05:19:33 454,656 ----a-w C:\Windows\winsxs\x86_microsoft-windows-m…nts-mdac-rds-ce-dll_31bf3856ad364e35_6.0.6000.20825_none_6083b6385dc1f24b\msadce.dll

  • 2008-04-30 05:36:32 454,656 ----a-w C:\Windows\winsxs\x86_microsoft-windows-m…nts-mdac-rds-ce-dll_31bf3856ad364e35_6.0.6001.18065_none_61b5167d41eb560f\msadce.dll

  • 2008-04-30 05:25:53 454,656 ----a-w C:\Windows\winsxs\x86_microsoft-windows-m…nts-mdac-rds-ce-dll_31bf3856ad364e35_6.0.6001.22169_none_6242b4705b055b35\msadce.dll

  • 2008-04-10 05:01:31 737,792 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6000.16669_none_77930ed65b8e9f2d\inetcomm.dll

  • 2008-04-10 02:43:11 84,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6000.16669_none_77930ed65b8e9f2d\INETRES.dll

  • 2008-04-10 04:56:31 737,792 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6000.20810_none_7849ba89748bcc5a\inetcomm.dll

  • 2008-04-10 02:44:56 84,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6000.20810_none_7849ba89748bcc5a\INETRES.dll

  • 2008-04-10 05:12:41 738,304 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.18049_none_798eed5458a4f83c\inetcomm.dll

  • 2008-04-10 04:59:52 738,304 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.22154_none_7a08b8c171cf3544\inetcomm.dll

  • 2008-04-10 02:51:10 84,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.22154_none_7a08b8c171cf3544\INETRES.dll

  • 2008-06-19 03:25:22 28,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.16705_none_422d3c83eeda2955\FwRemoteSvr.dll

  • 2008-06-19 03:25:22 361,984 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.16705_none_422d3c83eeda2955\IPSECSVC.DLL

  • 2008-06-19 03:25:25 272,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.16705_none_422d3c83eeda2955\polstore.dll

  • 2008-06-19 03:25:26 61,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.16705_none_422d3c83eeda2955\winipsec.dll

  • 2008-06-19 03:11:10 28,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.20861_none_4271f89f082c0b69\FwRemoteSvr.dll

  • 2008-06-19 03:11:28 361,984 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.20861_none_4271f89f082c0b69\IPSECSVC.DLL

  • 2008-06-19 03:13:36 272,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.20861_none_4271f89f082c0b69\polstore.dll

  • 2008-06-19 03:14:12 61,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6000.20861_none_4271f89f082c0b69\winipsec.dll

  • 2008-06-19 03:31:48 361,984 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6001.18094_none_43b129adec4a9f41\IPSECSVC.DLL

  • 2008-06-19 03:12:13 28,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6001.22206_none_449e183f051d7367\FwRemoteSvr.dll

  • 2008-06-19 03:12:58 361,984 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6001.22206_none_449e183f051d7367\IPSECSVC.DLL

  • 2008-06-19 03:15:05 272,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6001.22206_none_449e183f051d7367\polstore.dll

  • 2008-06-19 03:15:48 61,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-n…-domain-clients-svc_31bf3856ad364e35_6.0.6001.22206_none_449e183f051d7367\winipsec.dll

  • 2008-06-30 23:03:49 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16714_none_f09b0ea06e5840aa\OESpamFilter.dat

  • 2008-06-30 22:56:06 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20874_none_f0e3cbe387a6881a\OESpamFilter.dat

  • 2008-07-04 02:02:58 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18104_none_f28c1d326b76b5aa\OESpamFilter.dat

  • 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22218_none_f30eeb398498d6c1\OESpamFilter.dat

.

– Snapshot reset to current date –

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“SMSERIAL”=“C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe” [2007-01-16 23:34 634880]

“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-01-13 05:36 827392]

“QPService”=“C:\Program Files\HP\QuickPlay\QPService.exe” [2007-04-23 18:11 176128]

“HP Health Check Scheduler”=“C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe” [2007-03-12 11:54 50696]

“HP Software Update”=“C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe” [2005-02-16 23:11 49152]

“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 05:25 144784]

“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe” [2007-03-09 12:09 63712]

“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-07-19 16:38 78008]

“NvSvc”=“C:\Windows\system32\nvsvc.dll” [2007-05-01 12:27 86016]

“NvCplDaemon”=“C:\Windows\system32\NvCpl.dll” [2007-05-01 12:27 8429568]

“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 02:38 34672]

C:\Users\Andzia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Rejestrowanie produkt˘w Corela.lnk - C:\Program Files\Corel\Graphics9\Register\Remind32.exe [2007-12-31 19:14:05 67584]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 13:27:40 719664]

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-22 03:00:00 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

“EnableLUA”= 0 (0x0)

“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

“AppInit_DLLs”=APSHook.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

“MSACM.l3codec”= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

“UacDisableNotify”=dword:00000001

“InternetSettingsDisableNotify”=dword:00000001

“AutoUpdateDisableNotify”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

“DisableMonitoring”=dword:00000001

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

“{DC6B58C1-F27F-46B6-BC49-7F3725435A97}”= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)

“{A7EE9358-BE7C-43D9-B98E-AFFD8596C1B8}”= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play

“{0C2F0C4D-11B0-449B-B2CE-F9DE879042EA}”= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program

“TCP Query User{A4E3460D-EDBA-4461-8954-8596F29DA569}C:\program files\gadu-gadu\gg.exe”= UDP:C:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny

“UDP Query User{5FE68F57-EBBE-426B-B29F-9E85E91375DB}C:\program files\gadu-gadu\gg.exe”= TCP:C:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny

“{DA91E17A-367A-42EA-A21B-AE8F5B482CA1}”= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb

“{B9796EBD-E131-4BF1-B736-5FF2FFAE00AA}”= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb

“{B16CFCB3-89ED-4191-BB3F-8E37899809FB}”= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray

“{A414476C-4ACE-4668-A62C-4F7381E52F93}”= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray

“{32C18C9E-2317-4647-942F-CF4113252FBF}”= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR

“{94DB8010-B0FA-48B0-B620-A87BF8D1E1CD}”= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR

“{EDE676BA-46DA-43B9-A546-7D6E5E73D382}”= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client

“{C55ADEFD-B930-4CCA-8779-F28142700AB1}”= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client

“{74370C0B-8911-4990-89B9-B884CE98A6F8}”= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype

“{CC86A6BD-7D3E-4806-B45A-C77E1217241F}”= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

“{EED99883-19AE-4483-BE12-5DB72A74D5F8}”= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 16:35]

R2 ASBroker;Logon Session Broker;C:\Windows\System32\svchost.exe [2008-01-19 09:33]

R2 ASChannel;Local Communication Channel;C:\Windows\System32\svchost.exe [2008-01-19 09:33]

R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 16:36]

R3 btwaudio;Urządzenie dźwiękowe Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-01-02 12:45]

R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-01-02 12:45]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-01-02 12:45]

S2 USBHSB;GeneLink File Transfer Driver;C:\Windows\system32\Drivers\usbhsb.sys [2001-12-17 18:42]

S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\system32\DRIVERS\athrusb.sys [2006-12-22 21:05]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

Cognizance REG_MULTI_SZ ASBroker ASChannel

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{37480347-00bc-11dd-ab03-001e375c6e0d}]

\shell\AutoRun\command - F:\InstallTomTomHOME.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{986b3071-36fd-11dd-bbca-001e375c6e0d}]

\shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b78e9093-e1e0-11dc-9120-001e375c6e0d}]

\shell\AutoRun\command - G:\USBNB.exe

.

Contents of the ‘Scheduled Tasks’ folder

2008-08-01 C:\Windows\Tasks\HPCeeScheduleForAndzia.job

  • C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-03-23 14:23]

2008-08-15 C:\Windows\Tasks\User_Feed_Synchronization-{B7695DE8-E645-418A-ABC7-14FB60798B80}.job

  • C:\Windows\system32\msfeedssync.exe [2008-01-19 09:33]

.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-15 23:05:39

Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2008-08-15 23:07:54

ComboFix-quarantined-files.txt 2008-08-15 21:07:47

ComboFix2.txt 2008-08-15 15:23:17

Pre-Run: System nie może znaleźć komunikatu dla numeru komunikatu 0x2379 w pliku komunikatów dla Application.

Post-Run: 102,982,426,624 bajtów wolnych

358 — E O F — 2008-08-15 18:25:55

Leon$ :lol: …sorry , mam nadzieje ,ze robie wszystko wg Twoich wskazowek …chciałabym tego robala udusic :slight_smile:

uruchom System Repair Engineer zakładka System Repair >> Browser Add-ons >> odszukaj i usuń

zrób optymalizacje uruchamiania

http://cybertrash.netarteria.pl/cyber/i … 378.0.html

usuń ręcznie folder C: \Qoobox usuń instalkę Combofix z dysku.

Wyłącz I włącz przywracanie systemu na wszystkich dyskach.http://support.microsoft.com/kb/310405/pl

przeskanuj obszar Mój komputer http://www.kaspersky.pl/virusscanner.html pokaż raport stronę uruchomić przez IE

lub

Dr.WEB CureIt! http://dobreprogramy.pl/index.php?dz=2& … It!+4.44.5

:slight_smile:

o i zrobiłam i dalej te wirusy są… :frowning:

System operacyjny: Microsoft Windows Vista Home Edition, Service Pack 1 (Build 6001)

Kaspersky Online Scanner wersja: 5.0.98.1

Ostatnia aktualizacja Kaspersky Anti-Virus17/08/2008

Liczba wpisów w bazie danych Kaspersky Anti-Virus1101821

Ustawienia skanowania

Skanowanie przy użyciu następujących baz danych rozszerzone

Skanuj archiwa tak

Skanuj pocztowe bazy danych tak

Obszar skanowania Mój komputer

C:\

D:\

E:\

Statystyki skanowania

Liczba skanowanych obiektów 133550

Liczba wykrytych wirusów 2

Liczba zainfekowanych obiektów 3

Liczba podejrzanych obiektów 0

Czas trwania skanowania 01:24:46

Nazwa zainfekowanego obiektu Nazwa wirusa Ostatnie działanie

C:\boot\bcd Object is locked pominięty

C:\boot\BCD.LOG Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log Object is locked pominięty

C:\Program Files\Alwil Software\Avast4\DATA\report\Osłona rezydentna.txt Object is locked pominięty

C:\ProgramData\CyberLink\TinyDB\EPGSignal Object is locked pominięty

C:\ProgramData\CyberLink\TinyDB\Schedule Object is locked pominięty

C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b66cea100e0da55a93817f6460fe6a11_dbc2dab1-2f49-47ac-a47f-3c4d65a35b60 Object is locked pominięty

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked pominięty

C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.16.Crwl Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.16.gthr Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010014.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001D.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010021.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010023.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010026.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010027.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010029.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001002E.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010034.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001003A.ci Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001003A.wid Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001003A.wsb Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy49.gthr Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked pominięty

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked pominięty

C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked pominięty

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081720080818\index.dat Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\UsrClass.dat{98413a23-b78c-11dc-b7ec-001e375c6e0d}.TM.blf Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\UsrClass.dat{98413a23-b78c-11dc-b7ec-001e375c6e0d}.TMContainer00000000000000000001.regtrans-ms Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows\UsrClass.dat{98413a23-b78c-11dc-b7ec-001e375c6e0d}.TMContainer00000000000000000002.regtrans-ms Object is locked pominięty

C:\Users\Andzia\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\2E6A19B1-000004DA.eml Zainfekowanych: Trojan-Downloader.HTML.Agent.km pominięty

C:\Users\Andzia\AppData\Local\Temp~DFE9A6.tmp Object is locked pominięty

C:\Users\Andzia\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\7536eb4b-22a6a9de/OP.class Zainfekowanych: Trojan-Downloader.Java.OpenStream.ac pominięty

C:\Users\Andzia\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\7536eb4b-22a6a9de ZIP: zainfekowany - 1 pominięty

C:\Users\Andzia\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\call256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\callmember256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chat512.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chatmember256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chatmsg1024.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chatmsg2048.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chatmsg256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chatmsg512.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\chatsync\b1\b19617a73daf640e.dat Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\contactgroup256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\dyncontent\bundle.dat Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\index2.dat Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\profile4096.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\transfer256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\transfer512.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\user1024.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\user16384.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\user256.dbb Object is locked pominięty

C:\Users\Andzia\AppData\Roaming\Skype\tomannkol\voicemail256.dbb Object is locked pominięty

C:\Users\Andzia\ntuser.dat Object is locked pominięty

C:\Users\Andzia\ntuser.dat.LOG1 Object is locked pominięty

C:\Users\Andzia\ntuser.dat.LOG2 Object is locked pominięty

C:\Users\Andzia\ntuser.dat{1d6831fc-e687-11dc-9c87-001e375c6e0d}.TM.blf Object is locked pominięty

C:\Users\Andzia\ntuser.dat{1d6831fc-e687-11dc-9c87-001e375c6e0d}.TMContainer00000000000000000001.regtrans-ms Object is locked pominięty

C:\Users\Andzia\ntuser.dat{1d6831fc-e687-11dc-9c87-001e375c6e0d}.TMContainer00000000000000000002.regtrans-ms Object is locked pominięty

C:\WINDOWS\bthservsdp.dat Object is locked pominięty

C:\WINDOWS\Debug\PASSWD.LOG Object is locked pominięty

C:\WINDOWS\Debug\WIA\wiatrace.log Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\ntuser.dat Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked pominięty

C:\WINDOWS\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked pominięty

C:\WINDOWS\ServiceProfiles\NetworkService\ntuser.dat Object is locked pominięty

C:\WINDOWS\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked pominięty

C:\WINDOWS\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked pominięty

C:\WINDOWS\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked pominięty

C:\WINDOWS\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked pominięty

C:\WINDOWS\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked pominięty

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked pominięty

C:\WINDOWS\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked pominięty

C:\WINDOWS\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked pominięty

C:\WINDOWS\System32\catroot2\edb.log Object is locked pominięty

C:\WINDOWS\System32\catroot2{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked pominięty

C:\WINDOWS\System32\catroot2{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked pominięty

C:\WINDOWS\System32\config\components Object is locked pominięty

C:\WINDOWS\System32\config\COMPONENTS.LOG1 Object is locked pominięty

C:\WINDOWS\System32\config\COMPONENTS.LOG2 Object is locked pominięty

C:\WINDOWS\System32\config\default Object is locked pominięty

C:\WINDOWS\System32\config\DEFAULT.LOG1 Object is locked pominięty

C:\WINDOWS\System32\config\DEFAULT.LOG2 Object is locked pominięty

C:\WINDOWS\System32\config\RegBack\COMPONENTS Object is locked pominięty

C:\WINDOWS\System32\config\RegBack\DEFAULT Object is locked pominięty

C:\WINDOWS\System32\config\RegBack\SAM Object is locked pominięty

C:\WINDOWS\System32\config\RegBack\SECURITY Object is locked pominięty

C:\WINDOWS\System32\config\RegBack\SOFTWARE Object is locked pominięty

C:\WINDOWS\System32\config\RegBack\SYSTEM Object is locked pominięty

C:\WINDOWS\System32\config\sam Object is locked pominięty

C:\WINDOWS\System32\config\SAM.LOG1 Object is locked pominięty

C:\WINDOWS\System32\config\SAM.LOG2 Object is locked pominięty

C:\WINDOWS\System32\config\security Object is locked pominięty

C:\WINDOWS\System32\config\SECURITY.LOG1 Object is locked pominięty

C:\WINDOWS\System32\config\SECURITY.LOG2 Object is locked pominięty

C:\WINDOWS\System32\config\software Object is locked pominięty

C:\WINDOWS\System32\config\SOFTWARE.LOG1 Object is locked pominięty

C:\WINDOWS\System32\config\SOFTWARE.LOG2 Object is locked pominięty

C:\WINDOWS\System32\config\system Object is locked pominięty

C:\WINDOWS\System32\config\SYSTEM.LOG1 Object is locked pominięty

C:\WINDOWS\System32\config\SYSTEM.LOG2 Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\config\TxR{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked pominięty

C:\WINDOWS\System32\LogFiles\Scm\SCM.EVM Object is locked pominięty

C:\WINDOWS\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked pominięty

C:\WINDOWS\System32\Msdtc\KtmRmTm.blf Object is locked pominięty

C:\WINDOWS\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked pominięty

C:\WINDOWS\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked pominięty

C:\WINDOWS\System32\spool\SpoolerETW.etl Object is locked pominięty

C:\WINDOWS\System32\wbem\Logs\WMITracing.log Object is locked pominięty

C:\WINDOWS\System32\wbem\repository\INDEX.BTR Object is locked pominięty

C:\WINDOWS\System32\wbem\repository\MAPPING1.MAP Object is locked pominięty

C:\WINDOWS\System32\wbem\repository\MAPPING2.MAP Object is locked pominięty

C:\WINDOWS\System32\wbem\repository\OBJECTS.DATA Object is locked pominięty

C:\WINDOWS\System32\WDI\LogFiles\WdiContextLog.etl.002 Object is locked pominięty

C:\WINDOWS\System32\wfp\wfpdiag.etl Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Antivirus.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Application.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\DFS Replication.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\HardwareEvents.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Internet Explorer.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Key Management Service.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Media Center.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Security.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\Setup.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\System.evtx Object is locked pominięty

C:\WINDOWS\System32\winevt\Logs\VeriSoft.evtx Object is locked pominięty

C:\WINDOWS\Tasks\SCHEDLGU.TXT Object is locked pominięty

C:\WINDOWS\temp_avast4_\Webshlock.txt Object is locked pominięty

C:\WINDOWS\WindowsUpdate.log Object is locked pominięty

D:\System Volume Information\Desktop.ini Object is locked pominięty

D:\System Volume Information\Folder.htt Object is locked pominięty

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked pominięty

D:\System Volume Information\Protect.ed Object is locked pominięty

Proces skanowania został zakończony.

Nie przejmuj się tego w logach nie było od szukania takich rzeczy są programy antywirusowe

Pobierz i uruchom narzędzie The Avenger Zaznaczasz tekst podany do usunięcia na forum

kopiuj >> klikasz na Paste Script from Clipboard >> Execute >> Potwierdzasz i zgadzasz się na restart klikając OK.

Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt

:slight_smile:

Wyskakuje mi taki komunikat :frowning:

Error: Inwalid script.A valid script must begin with a comand directive

Aborting execution.

wyłącz avangera włącz ponownie i próbuj

jak nie pójdzie usuń podane pliki ręcznie lub użyj Unlockera znajdziesz w programach

:slight_smile:

No nic usunęłam…recznie…skanuje teraz kasperskim :slight_smile: czekam na wynik.

Leon$ wielkie dzieki za pomoc i cierpliwość…Kasperski juz nie pokazuje wirusów ,teraz skanuję jeszcze Avastem…jeszcze raz wielkie dzięki … :smiley: :smiley: :smiley: :smiley: :smiley: :smiley: :smiley: :smiley: :smiley: