Panda wykryła syf

oto log ze skanowania pandą:

; ***********************************************************************************************************************************************************************************

ANALYSIS: 2008-05-17 00:23:08

PROTECTIONS: 1

MALWARE: 2

SUSPECTS: 0

; ***********************************************************************************************************************************************************************************

PROTECTIONS

Description Version Active Updated

;===================================================================================================================================================================================

ZoneAlarm Security Suite Antivirus 7.0.470.000 Yes Yes

;===================================================================================================================================================================================

MALWARE

Id Description Type Active Severity Disinfectable Disinfected Location

;===================================================================================================================================================================================

01176994 Bck/VB.XB Virus/Trojan No 0 No No E:\System Volume Information\_restore{1DE43DAB-2C42-484F-ADF2-F9A6C8C471DE}\RP1078\A0274024.exe[327882R2FWJFW\nircmd.cfexe]

01185375 Application/Psexec.A HackTools No 0 Yes No E:\System Volume Information\_restore{1DE43DAB-2C42-484F-ADF2-F9A6C8C471DE}\RP1079\A0274203.EXE

01185375 Application/Psexec.A HackTools No 0 Yes No E:\System Volume Information\_restore{1DE43DAB-2C42-484F-ADF2-F9A6C8C471DE}\RP1078\A0274063.EXE

;===================================================================================================================================================================================

SUSPECTS

Sent Location B

;===================================================================================================================================================================================

;===================================================================================================================================================================================

VULNERABILITIES

Id Severity Description B

;===================================================================================================================================================================================

;===================================================================================================================================================================================

Jak można to usunąć(skanery offline nic nie wykryły. Poniżej log z hijacka:

Logfile of HijackThis v1.99.1

Scan saved at 00:27, on 2008-05-17

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\WINDOWS\system32\ZoneLabs\vsmon.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\Explorer.EXE

E:\WINDOWS\system32\spoolsv.exe

E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe

E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

E:\Program Files\WordWeb\wweb32.exe

E:\Program Files\Common Files\Real\Update_OB\realsched.exe

E:\WINDOWS\system32\NOTEPAD.EXE

E:\Program Files\Gadu-Gadu\gg.exe

E:\Program Files\Mozilla Firefox\firefox.exe

E:\Program Files\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.41.218.100:3128

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe

O4 - HKLM\..\Run: [ZoneAlarm Client] "E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - Startup: Adobe Gamma.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Startup: WordWeb.lnk = E:\Program Files\WordWeb\wweb32.exe

O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: &Google Search - res://e:\program files\google\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: Append to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Backward Links - res://e:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://e:\program files\google\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Download all links using BitComet - res://E:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download link using &BitComet - res://E:\Program Files\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://e:\program files\google\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://e:\program files\google\GoogleToolbar2.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1122410675328

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - E:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: Adobe LM Service - Adobe Systems - E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Macromedia Licensing Service - Macromedia - E:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: SQL Server FullText Search (SQLEXPRESS) (msftesql$SQLEXPRESS) - Unknown owner - e:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f:SQLEXPRESS (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - e:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: PDEngine - Raxco Software, Inc. - E:\Program Files\Raxco\PerfectDisk\PDEngine.exe

O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - E:\Program Files\Raxco\PerfectDisk\PDSched.exe

O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - E:\WINDOWS\system32\ZoneLabs\vsmon.exe

Wyłącz i Włacz przywracanie systemu na wszystkich dyskach. Instrukcja

Dla pewności przeskanuj jeszcze tym (uruchom przez IE) http://www.kaspersky.pl/virusscanner.html Daj raport z niego na forum

log z kaspersky’ego:

-------------------------------------------------------------------------------

 KASPERSKY ONLINE SCANNER REPORT

 2008-05-17 23:53

 System operacyjny: Microsoft Windows XP Home Edition, Dodatek Service Pack 2 (Build 2600)

 Kaspersky Online Scanner wersja: 5.0.98.0

 Ostatnia aktualizacja Kaspersky Anti-Virus17/05/2008

 Liczba wpisów w bazie danych Kaspersky Anti-Virus781312

-------------------------------------------------------------------------------


Ustawienia skanowania:

	Skanowanie przy użyciu następujących baz danych: rozszerzone

	Skanuj archiwa: tak

	Skanuj pocztowe bazy danych: tak


Obszar skanowania - Mój komputer:

	A:\

	C:\

	D:\

	E:\


Statystyki skanowania:

	Liczba skanowanych obiektów: 137479

	Liczba wykrytych wirusów: 0

	Liczba zainfekowanych obiektów: 0

	Liczba podejrzanych obiektów: 0

	Czas trwania skanowania: 01:38:55


Nazwa zainfekowanego obiektu / Nazwa wirusa / Ostatnie działanie

C:\System Volume Information\MountPointManagerRemoteDatabase	Object is locked	pominięty

E:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Crypto\RSA\MachineKeys\462bc6fe1c0ff8870d72db0e4840eb24_795fcf8c-5381-4195-ab21-b892dd2f0616	Object is locked	pominięty

E:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Crypto\RSA\MachineKeys\6a00cefe36153b54804bfb65d1a317a2_795fcf8c-5381-4195-ab21-b892dd2f0616	Object is locked	pominięty

E:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat	Object is locked	pominięty

E:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Cookies\index.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\cert8.db	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\history.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\key3.db	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\parent.lock	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\search.sqlite	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\urlclassifier2.sqlite	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\ntuser.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\ntuser.dat.LOG	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\Cache\_CACHE_001_	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\Cache\_CACHE_002_	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\Cache\_CACHE_003_	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\s59322hj.default\Cache\_CACHE_MAP_	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Historia\History.IE5\index.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Historia\History.IE5\MSHist012008051720080518\index.dat	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Temp\~DFFA01.tmp	Object is locked	pominięty

E:\Documents and Settings\Jacek Nowak\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat	Object is locked	pominięty

E:\Documents and Settings\LocalService\Cookies\index.dat	Object is locked	pominięty

E:\Documents and Settings\LocalService\NTUSER.DAT	Object is locked	pominięty

E:\Documents and Settings\LocalService\ntuser.dat.LOG	Object is locked	pominięty

E:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat	Object is locked	pominięty

E:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG	Object is locked	pominięty

E:\Documents and Settings\LocalService\Ustawienia lokalne\Historia\History.IE5\index.dat	Object is locked	pominięty

E:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat	Object is locked	pominięty

E:\Documents and Settings\NetworkService\Cookies\index.dat	Object is locked	pominięty

E:\Documents and Settings\NetworkService\NTUSER.DAT	Object is locked	pominięty

E:\Documents and Settings\NetworkService\ntuser.dat.LOG	Object is locked	pominięty

E:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat	Object is locked	pominięty

E:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG	Object is locked	pominięty

E:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia\History.IE5\index.dat	Object is locked	pominięty

E:\Documents and Settings\NetworkService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG	Object is locked	pominięty

E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_122.trc	Object is locked	pominięty

E:\System Volume Information\MountPointManagerRemoteDatabase	Object is locked	pominięty

E:\System Volume Information\_restore{1DE43DAB-2C42-484F-ADF2-F9A6C8C471DE}\RP1112\change.log	Object is locked	pominięty

E:\WINDOWS\Debug\PASSWD.LOG	Object is locked	pominięty

E:\WINDOWS\Internet Logs\fwdbglog.txt	Object is locked	pominięty

E:\WINDOWS\Internet Logs\fwpktlog.txt	Object is locked	pominięty

E:\WINDOWS\Internet Logs\IAMDB.RDB	Object is locked	pominięty

E:\WINDOWS\Internet Logs\JACEK-8F10D5032.ldb	Object is locked	pominięty

E:\WINDOWS\Internet Logs\tvDebug.log	Object is locked	pominięty

E:\WINDOWS\SchedLgU.Txt	Object is locked	pominięty

E:\WINDOWS\SoftwareDistribution\EventCache\{BFF00A2D-50E0-4527-AA38-BEEE6C961DB9}.bin	Object is locked	pominięty

E:\WINDOWS\SoftwareDistribution\ReportingEvents.log	Object is locked	pominięty

E:\WINDOWS\system32\CatRoot2\edb.log	Object is locked	pominięty

E:\WINDOWS\system32\CatRoot2\tmp.edb	Object is locked	pominięty

E:\WINDOWS\system32\config\ACEEvent.evt	Object is locked	pominięty

E:\WINDOWS\system32\config\AppEvent.Evt	Object is locked	pominięty

E:\WINDOWS\system32\config\default	Object is locked	pominięty

E:\WINDOWS\system32\config\default.LOG	Object is locked	pominięty

E:\WINDOWS\system32\config\SAM	Object is locked	pominięty

E:\WINDOWS\system32\config\SAM.LOG	Object is locked	pominięty

E:\WINDOWS\system32\config\SecEvent.Evt	Object is locked	pominięty

E:\WINDOWS\system32\config\SECURITY	Object is locked	pominięty

E:\WINDOWS\system32\config\SECURITY.LOG	Object is locked	pominięty

E:\WINDOWS\system32\config\software	Object is locked	pominięty

E:\WINDOWS\system32\config\software.LOG	Object is locked	pominięty

E:\WINDOWS\system32\config\SysEvent.Evt	Object is locked	pominięty

E:\WINDOWS\system32\config\system	Object is locked	pominięty

E:\WINDOWS\system32\config\system.LOG	Object is locked	pominięty

E:\WINDOWS\system32\drivers\fidbox.dat	Object is locked	pominięty

E:\WINDOWS\system32\drivers\fidbox.idx	Object is locked	pominięty

E:\WINDOWS\system32\h323log.txt	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA	Object is locked	pominięty

E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP	Object is locked	pominięty

E:\WINDOWS\Temp\Perflib_Perfdata_170.dat	Object is locked	pominięty

E:\WINDOWS\Temp\ZLT04550.TMP	Object is locked	pominięty

E:\WINDOWS\Temp\ZLT04553.TMP	Object is locked	pominięty

E:\WINDOWS\WindowsUpdate.log	Object is locked	pominięty


Proces skanowania został zakończony.

Komputer jest wolny od wirusów :slight_smile: