:OTL DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\system32\PCANDIS4.SYS – (PCANDIS4) DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\system32\PCAMPR4.SYS – (PCAMPR4) DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Kacper\AppData\Local\Temp\catchme.sys – (catchme) [2013-07-30 07:50:39 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Roaming\mozilla\firefox\profiles\i72c3e2m.default\searchplugins\searchplugins.exe [2012-10-12 19:05:34 | 000,003,915 | ---- | M] () – C:\Users\Kacper\AppData\Roaming\mozilla\firefox\profiles\i72c3e2m.default\searchplugins\sweetim.xml O4 - HKLM…\Run: [cgomq] C:\Windows\System32\cwuicyyqldfnxtjbypgmu.exe () O4 - HKLM…\Run: [ueswgsiqbjb] C:\Users\Kacper\AppData\Local\Temp\asoasmkatjjpxrfvqfu.exe () O4 - HKU\S-1-5-21-2080738008-136213235-3544708513-1001…\Run: [cgomq] C:\Users\Kacper\AppData\Local\Temp\cwuicyyqldfnxtjbypgmu.exe () O4 - HKU\S-1-5-21-2080738008-136213235-3544708513-1001…\Run: [pwhipylq] C:\Windows\System32\zohqfwreuhehmdob.exe () O4 - HKLM…\RunOnce: [nsbafm] C:\Windows\System32\pgbmdwtiapotatgvpd.exe () O4 - HKLM…\RunOnce: [zivyhshoyf] C:\Users\Kacper\AppData\Local\Temp\asoasmkatjjpxrfvqfu.exe . () O4 - HKU\S-1-5-21-2080738008-136213235-3544708513-1001…\RunOnce: [goackuiox] C:\Windows\System32\zohqfwreuhehmdob.exe () O4 - HKU\S-1-5-21-2080738008-136213235-3544708513-1001…\RunOnce: [nsbafm] C:\Users\Kacper\AppData\Local\Temp\gwqaqiesjxvzfxjxq.exe . () O4 - Startup: C:\Users\Kacper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Startup.pif () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: agqqweq = ngdqjeduofgnwrgxtjze.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: twda = C:\Users\Kacper\AppData\Local\Temp\gwqaqiesjxvzfxjxq.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O7 - HKU\S-1-5-21-2080738008-136213235-3544708513-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O32 - AutoRun File - [2013-08-15 19:58:33 | 000,000,805 | RHS- | M] () - C:\autorun.inf – [NTFS] [2013-08-17 22:13:32 | 000,000,280 | -H-- | M] () – C:\Windows\cgomqwginpbtnttvcdeumcuxmxb.hlr [2013-08-17 22:13:32 | 000,000,280 | -H-- | M] () – C:\Users\Kacper\AppData\Local\cgomqwginpbtnttvcdeumcuxmxb.hlr [2013-08-17 22:13:32 | 000,000,280 | -H-- | M] () – C:\Program Files\cgomqwginpbtnttvcdeumcuxmxb.hlr [2013-08-17 22:13:01 | 000,000,280 | -H-- | M] () – C:\Windows\System32\cgomqwginpbtnttvcdeumcuxmxb.hlr [2013-08-17 22:12:53 | 000,614,400 | RHS- | M] () – C:\Windows\toncxuvokdgpaxohfxpwfm.exe [2013-08-17 22:12:53 | 000,614,400 | RHS- | M] () – C:\Windows\pgbmdwtiapotatgvpd.exe [2013-08-17 22:12:53 | 000,614,400 | RHS- | M] () – C:\Windows\ngdqjeduofgnwrgxtjze.exe [2013-08-17 22:12:53 | 000,614,400 | RHS- | M] () – C:\Windows\gwqaqiesjxvzfxjxq.exe [2013-08-15 19:58:12 | 000,614,400 | RHS- | M] () – C:\Windows\System32\toncxuvokdgpaxohfxpwfm.exe [2013-08-15 19:58:12 | 000,614,400 | RHS- | M] () – C:\Windows\System32\ngdqjeduofgnwrgxtjze.exe [2013-08-15 19:58:12 | 000,614,400 | RHS- | M] () – C:\Windows\System32\gwqaqiesjxvzfxjxq.exe [2013-08-15 19:58:04 | 000,614,400 | RHS- | M] () – C:\Windows\System32\pgbmdwtiapotatgvpd.exe [2013-08-15 19:58:04 | 000,614,400 | RHS- | M] () – C:\Windows\System32\cwuicyyqldfnxtjbypgmu.exe [2013-08-14 08:02:06 | 000,573,440 | ---- | M] () – C:\Users\Kacper\Documents\dokumenty.exe [2013-08-14 08:02:04 | 000,573,440 | ---- | M] () – C:\Users\Kacper\Documents\Documents.exe [2013-08-14 07:59:09 | 000,573,440 | ---- | M] () – C:\Users\Kacper\Kacper.pif [2013-08-14 07:59:00 | 000,573,440 | ---- | M] () – C:\ProgramData\Users.exe [2013-08-14 07:59:00 | 000,573,440 | ---- | M] () – C:\ProgramData\Application Data.exe [2013-08-14 07:59:00 | 000,573,440 | ---- | M] () – C:\ProgramData\aplikacji.exe [2013-07-30 07:51:00 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Local\lokalne.scr [2013-07-30 07:50:45 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Roaming\aplikacji.exe [2013-07-30 07:50:38 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Startup.pif [2013-07-30 07:50:21 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Roaming\Roaming.exe [2013-07-30 07:47:21 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Local\aplikacji.exe [2013-07-30 07:47:18 | 000,602,112 | ---- | M] () – C:\Users\Kacper\AppData\Local\Local.exe [2013-07-30 07:47:01 | 000,602,112 | ---- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Startup.pif [2013-07-30 07:46:42 | 000,602,112 | ---- | M] () – C:\Users\Public\Documents\Dokumenty.exe [2013-07-24 07:45:02 | 000,569,344 | ---- | C] () – C:\Users\Kacper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programy.pif [2013-07-24 07:45:01 | 000,569,344 | ---- | C] () – C:\Users\Kacper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programs.pif [2013-07-24 07:41:33 | 000,569,344 | ---- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programy.pif [2013-07-24 07:41:32 | 000,569,344 | ---- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programs.pif :Commands [emptytemp]