:OTL O4 - HKLM…\Run: [Microsoft Defender] C:\WINDOWS\system\winsma32.exe File not found O4 - HKLM…\Run: [QuickTime Task] e:\program files\quicktime\qttask .exe () O4 - HKLM…\Run: [Windows Driver Software] E:\WINDOWS\system32\driversx.exe ( ) O4 - HKCU…\Run: [12CFG214-K641-12SF-N85P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe () O4 - HKCU…\Run: [EVEREST AutoStart] G:\Everest Ultimate 3.50.837 PL\Everest Ultimate 3.50.837 PL\everest.exe File not found O4 - HKCU…\Run: [Twoje TVN24] e:\program files\pasek tvn24\tvn-ustawienia .exe () F3 - HKLM WinNT: Load - (C:\WINDOWS\system\winsma32.exe) - C:\WINDOWS\system\winsma32.exe File not found O20 - AppInit_DLLs: (app_dll.dll) - E:\WINDOWS\System32\app_dll.dll () O20 - HKLM Winlogon: UserInit - (E:\DOCUME~1\KArol\USTAWI~1\Temp\init.exe) - E:\DOCUME~1\KArol\USTAWI~1\Temp\init.exe File not found O20 - HKLM Winlogon: TaskMan - (E:\Documents and Settings\KArol\Dane aplikacji\qwdfl.exe) - E:\Documents and Settings\KArol\Dane aplikacji\qwdfl.exe ( ) O33 - MountPoints2{512ba76c-11cd-11df-9fa5-00030d75ea8b}\Shell\AutoRun\command - “” = I:\ZAPALICU\sveslike.exe – File not found O33 - MountPoints2{512ba76c-11cd-11df-9fa5-00030d75ea8b}\Shell\explore\command - “” = I:\ZAPALICU\sveslike.exe – File not found O33 - MountPoints2{512ba76c-11cd-11df-9fa5-00030d75ea8b}\Shell\open\command - “” = I:\ZAPALICU\sveslike.exe – File not found [2010-02-08 18:04:22 | 000,066,048 | RHS- | C] ( ) – E:\Documents and Settings\KArol\Dane aplikacji\qwdfl.exe [2010-02-07 20:50:00 | 000,066,048 | RHS- | C] ( ) – E:\WINDOWS\System32\driversx.exe [2010-02-07 18:03:02 | 000,066,048 | ---- | C] ( ) – E:\WINDOWS\System32\driversx .exe [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At9.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At8.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At7.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At6.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At5.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At4.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At3.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At24.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At23.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At22.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At21.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At20.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At2.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At19.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At18.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At17.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At16.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At15.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At14.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At13.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At12.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At11.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At10.job [2010-02-09 10:19:26 | 000,000,392 | ---- | M] () – E:\WINDOWS\tasks\At1.job [2010-02-08 19:36:46 | 000,116,224 | ---- | M] () – E:\Documents and Settings\KArol\rundll32 .exe [2010-02-08 19:36:38 | 000,116,224 | ---- | M] () – E:\Documents and Settings\KArol\alcmtr .exe [2010-02-08 19:36:37 | 000,116,224 | ---- | M] () – E:\Documents and Settings\KArol\skytel .exe [2010-02-08 19:36:35 | 000,116,224 | ---- | M] () – E:\Documents and Settings\KArol\rthdcpl .exe [2010-02-08 19:36:33 | 000,116,224 | ---- | M] () – E:\Documents and Settings\KArol\chdaudpropshortcut .exe [2010-02-07 11:55:02 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\rundll32.exe [2010-02-07 11:55:02 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\rundll32 .exe [2010-02-07 11:55:01 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\alcmtr.exe [2010-02-07 11:55:01 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\alcmtr .exe [2010-02-07 11:55:00 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\skytel.exe [2010-02-07 11:55:00 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\skytel .exe [2010-02-07 11:54:59 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\rthdcpl.exe [2010-02-07 11:54:59 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\rthdcpl .exe [2010-02-07 11:54:58 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\chdaudpropshortcut.exe [2010-02-07 11:54:58 | 000,116,224 | ---- | C] () – E:\Documents and Settings\KArol\chdaudpropshortcut .exe [2010-02-07 11:55:57 | 000,069,120 | ---- | C] () – E:\WINDOWS\System32\app_dll.dll.316250.old [2010-02-07 11:55:57 | 000,069,120 | ---- | C] () – E:\WINDOWS\System32\app_dll.dll O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 :Files E:\WINDOWS\System32\alcmtr.exe E:\WINDOWS\System32\skytel.exe E:\WINDOWS\System32\rthdcpl.exe E:\WINDOWS\System32\chdaudpropshortcut.exe :Commands [emptytemp] [Reboot]