:OTL PRC - [2011-08-22 15:21:11 | 000,137,728 | ---- | M] () – C:\WINDOWS\systemup.exe PRC - [2011-08-22 15:03:26 | 000,355,840 | ---- | M] () – C:\WINDOWS\update.5.0\svchost.exe PRC - [2011-08-22 15:03:26 | 000,355,840 | ---- | M] () – C:\WINDOWS\update.5.0\svchost.exe PRC - [2011-08-21 20:40:14 | 000,634,880 | ---- | M] () – C:\WINDOWS\update.2\svchost.exe PRC - [2011-08-21 20:40:14 | 000,634,880 | ---- | M] () – C:\WINDOWS\update.2\svchost.exe PRC - [2011-08-20 20:11:17 | 000,273,920 | ---- | M] () – C:\WINDOWS\update.3\svchost.exe PRC - [2011-08-19 18:19:00 | 000,232,960 | ---- | M] () – C:\WINDOWS\l1rezerv.exe PRC - [2011-08-19 18:04:23 | 000,382,464 | ---- | M] () – C:\WINDOWS\update.7.1\svchostdriver.exe PRC - [2011-08-19 17:49:47 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32.exe PRC - [2011-08-19 17:22:50 | 001,215,488 | -H-- | M] () – C:\WINDOWS\update.tray-3-0\svchost.exe PRC - [2011-08-19 17:22:50 | 001,215,488 | -H-- | M] () – C:\WINDOWS\update.1\svchost.exe MOD - [2011-08-22 18:17:10 | 000,124,416 | RHS- | M] () – C:\WINDOWS\system32\arking1.dll MOD - [2011-08-22 18:14:07 | 000,112,640 | RHS- | M] () – C:\Documents and Settings\Dariusz\Ustawienia lokalne\Temp\apiqq0.dll MOD - [2011-08-22 15:21:11 | 000,137,728 | ---- | M] () – C:\WINDOWS\systemup.exe MOD - [2011-08-22 15:03:26 | 000,355,840 | ---- | M] () – C:\WINDOWS\update.5.0\svchost.exe MOD - [2011-08-21 20:40:14 | 000,634,880 | ---- | M] () – C:\WINDOWS\update.2\svchost.exe MOD - [2011-08-20 20:11:17 | 000,273,920 | ---- | M] () – C:\WINDOWS\update.3\svchost.exe MOD - [2011-08-19 18:19:00 | 000,232,960 | ---- | M] () – C:\WINDOWS\l1rezerv.exe MOD - [2011-08-19 18:04:23 | 000,382,464 | ---- | M] () – C:\WINDOWS\update.7.1\svchostdriver.exe MOD - [2011-08-19 17:49:47 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32.exe MOD - [2011-08-19 17:22:50 | 001,215,488 | -H-- | M] () – C:\WINDOWS\update.tray-3-0\svchost.exe MOD - [2011-08-19 17:22:50 | 001,215,488 | -H-- | M] () – C:\WINDOWS\update.1\svchost.exe SRV - [2011-08-22 15:03:26 | 000,355,840 | ---- | M] () [Auto | Running] – C:\WINDOWS\update.5.0\svchost.exe – (srvbtcclient) SRV - [2011-08-21 20:40:14 | 000,634,880 | ---- | M] () [Auto | Running] – C:\WINDOWS\update.2\svchost.exe – (srviecheck) SRV - [2011-08-19 18:04:23 | 000,382,464 | ---- | M] () [Auto | Running] – C:\WINDOWS\update.7.1\svchostdriver.exe – (ddservice) SRV - [2011-08-19 17:49:47 | 000,258,048 | ---- | M] () [Auto | Running] – C:\WINDOWS\sysdriver32.exe – (srvsysdriver32) SRV - [2011-08-19 17:22:50 | 001,215,488 | -H-- | M] () [Auto | Running] – C:\WINDOWS\update.1\svchost.exe – (wxpdrivers) IE - HKCU…\URLSearchHook: - Reg Error: Key error. File not found FF - HKLM\Software\MozillaPlugins@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll File not found FF - HKLM\Software\MozillaPlugins@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.17\npGoogleOneClick8.dll File not found [2011-03-22 09:14:51 | 000,000,000 | —D | M] (“DAEMON Tools Toolbar”) – C:\Documents and Settings\Dariusz\Dane aplikacji\Mozilla\Firefox\Profiles\qvsvv9mt.default\extensions\DTToolbar@toolbarnet.com O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - File not found O3 - HKLM…\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU…\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM…\Run: [10723814-loader2.exe] C:\WINDOWS\TEMP\10723814-loader2.exe () O4 - HKLM…\Run: [6131858.exe] C:\WINDOWS\TEMP\6131858.exe () O4 - HKLM…\Run: [7360386.exe] C:\WINDOWS\TEMP\7360386.exe () O4 - HKLM…\Run: [8290831.exe] C:\WINDOWS\TEMP\8290831.exe () O4 - HKLM…\Run: [8521875.exe] C:\Documents and Settings\Dariusz\Ustawienia lokalne\Temp\8521875.exe () O4 - HKLM…\Run: [Cmaudio] File not found O4 - HKLM…\Run: [egui] File not found O4 - HKLM…\Run: [l1rezerv.exe] C:\WINDOWS\l1rezerv.exe () O4 - HKLM…\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe () O4 - HKLM…\Run: [sysdriver32.exe] C:\WINDOWS\sysdriver32.exe () O4 - HKLM…\Run: [sysdriver32_.exe] C:\WINDOWS\sysdriver32_.exe () O4 - HKLM…\Run: [systemup] C:\WINDOWS\systemup.exe () O4 - HKLM…\Run: [tray_ico] File not found O4 - HKLM…\Run: [tray_ico0] C:\WINDOWS\update.tray-3-0\svchost.exe () O4 - HKLM…\Run: [tray_ico1] File not found O4 - HKLM…\Run: [tray_ico2] File not found O4 - HKLM…\Run: [tray_ico3] File not found O4 - HKLM…\Run: [tray_ico4] File not found O4 - HKLM…\Run: [w_distrib.exe] C:\WINDOWS\update.3\svchost.exe () O4 - HKLM…\Run: [wxpdrv] C:\WINDOWS\services32.exe () O4 - HKCU…\Run: [api32] C:\Documents and Settings\Dariusz\Ustawienia lokalne\Temp\apiqq.exe () O4 - HKCU…\Run: [cdoosoft] File not found O4 - HKCU…\Run: [DestopRotator] File not found O4 - HKCU…\Run: [King_ar] C:\WINDOWS\system32\arking.exe () O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - File not found O9 - Extra ‘Tools’ menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - File not found O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - File not found O32 - AutoRun File - [2011-08-22 19:35:12 | 000,000,055 | RHS- | M] () - C:\autorun.inf – [NTFS] O32 - AutoRun File - [2011-08-22 19:35:12 | 000,000,055 | RHS- | M] () - D:\autorun.inf – [NTFS] O32 - AutoRun File - [2011-08-22 19:35:12 | 000,000,055 | RHS- | M] () - E:\autorun.inf – [NTFS] O33 - MountPoints2{09f65fbc-93e2-11df-83c0-000e2e5e6510}\Shell\AutoRun\command - “” = I:\kyme.exe O33 - MountPoints2{09f65fbc-93e2-11df-83c0-000e2e5e6510}\Shell\open\Command - “” = I:\kyme.exe O33 - MountPoints2{09f65fbd-93e2-11df-83c0-000e2e5e6510}\Shell\AutoRun\command - “” = J:\kyme.exe O33 - MountPoints2{09f65fbd-93e2-11df-83c0-000e2e5e6510}\Shell\open\Command - “” = J:\kyme.exe O33 - MountPoints2{2c32be06-579f-11df-829f-000e2e5e6510}\Shell\AutoRun\command - “” = I:\kyme.exe O33 - MountPoints2{2c32be06-579f-11df-829f-000e2e5e6510}\Shell\open\Command - “” = I:\kyme.exe O33 - MountPoints2{7befb3c2-9179-11df-83b4-000e2e5e6510}\Shell - “” = AutoRun O33 - MountPoints2{7befb3c2-9179-11df-83b4-000e2e5e6510}\Shell\AutoRun\command - “” = I:\LGAutoRun.exe O33 - MountPoints2{a1e19772-2058-11df-816f-000e2e5e6510}\Shell\AutoRun\command - “” = I:\kyme.exe O33 - MountPoints2{a1e19772-2058-11df-816f-000e2e5e6510}\Shell\open\Command - “” = I:\kyme.exe O33 - MountPoints2{edff9ef0-2c07-11df-81b5-000e2e5e6510}\Shell\AutoRun\command - “” = I:\kyme.exe O33 - MountPoints2{edff9ef0-2c07-11df-81b5-000e2e5e6510}\Shell\open\Command - “” = I:\kyme.exe O33 - MountPoints2{f76b6fdc-3517-11df-81f1-000e2e5e6510}\Shell\AutoRun\command - “” = H:\zPharaoh.exe O33 - MountPoints2{f76b6fdc-3517-11df-81f1-000e2e5e6510}\Shell\explore\command - “” = H:\zPharaoh.exe O33 - MountPoints2{f76b6fdc-3517-11df-81f1-000e2e5e6510}\Shell\open\command - “” = H:\zPharaoh.exe O33 - MountPoints2{f76ea1ac-0861-11e0-8546-c89d4a0e4b42}\Shell\AutoRun\command - “” = I:\kyme.exe O33 - MountPoints2{f76ea1ac-0861-11e0-8546-c89d4a0e4b42}\Shell\open\Command - “” = I:\kyme.exe O33 - MountPoints2\E\Shell\AutoRun\command - “” = E:\kyme.exe – [2010-10-16 10:28:24 | 000,173,568 | RHS- | M] () O33 - MountPoints2\E\Shell\open\Command - “” = E:\kyme.exe – [2010-10-16 10:28:24 | 000,173,568 | RHS- | M] () SafeBootMin: wxpdrivers - C:\WINDOWS\update.1\svchost.exe () SafeBootNet: wxpdrivers - C:\WINDOWS\update.1\svchost.exe () [2011-08-20 20:11:29 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.3 [2011-08-19 18:25:53 | 000,000,000 | —D | C] – C:\WINDOWS\ufa [2011-08-19 18:25:53 | 000,000,000 | —D | C] – C:\WINDOWS\rpcminer [2011-08-19 18:25:53 | 000,000,000 | —D | C] – C:\WINDOWS\phoenix [2011-08-19 18:13:19 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.5.0 [2011-08-19 18:09:29 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.2 [2011-08-19 18:04:29 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.7.1 [2011-08-19 17:47:33 | 000,000,000 | —D | C] – C:\WINDOWS\av_ico [2011-08-19 17:37:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.1 [2011-08-19 17:37:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.tray-3-0-lnk [2011-08-19 17:37:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.tray-3-0 [2011-08-22 19:40:17 | 000,000,055 | RHS- | M] () – C:\autorun.inf [2011-08-22 18:17:10 | 000,124,416 | RHS- | M] () – C:\WINDOWS\System32\arking1.dll [2011-08-22 18:17:07 | 000,177,664 | RHS- | M] () – C:\WINDOWS\System32\arking.exe [2011-08-22 18:14:10 | 000,124,416 | ---- | M] () – C:\WINDOWS\System32\arking0.dll [2011-08-22 15:21:13 | 000,000,223 | ---- | M] () – C:\WINDOWS\info1 [2011-08-22 15:21:11 | 000,137,728 | ---- | M] () – C:\WINDOWS\systemup.exe [2011-08-19 18:25:52 | 000,246,272 | ---- | M] () – C:\WINDOWS\unrar.exe [2011-08-19 18:25:51 | 005,589,370 | ---- | M] () – C:\WINDOWS\phoenix.rar [2011-08-19 18:25:51 | 000,182,617 | ---- | M] () – C:\WINDOWS\ufa.rar [2011-08-19 18:25:47 | 001,075,284 | ---- | M] () – C:\WINDOWS\rpcminer.rar [2011-08-19 18:19:00 | 000,232,960 | ---- | M] () – C:\WINDOWS\l1rezerv.exe [2011-08-19 17:53:26 | 000,904,792 | ---- | M] () – C:\WINDOWS\geoiplist.rar [2011-08-19 17:51:04 | 000,000,000 | ---- | M] () – C:\WINDOWS\loader2.exe_ok [2011-08-19 17:49:47 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32_.exe [2011-08-19 17:49:47 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32.exe [2011-08-19 17:22:50 | 001,215,488 | ---- | M] () – C:\WINDOWS\services32.exe [2011-08-19 17:53:29 | 004,636,907 | ---- | C] () – C:\WINDOWS\geoiplist [2011-08-14 10:49:30 | 000,177,664 | RHS- | C] () – C:\WINDOWS\System32\arking.exe [2011-08-14 10:49:11 | 000,000,055 | RHS- | C] () – C:\autorun.inf [2011-08-14 10:49:10 | 000,173,568 | RHS- | C] () – C:\kyme.exe [2011-04-30 22:50:11 | 000,124,416 | RHS- | C] () – C:\WINDOWS\System32\arking1.dll :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [CLEARALLRESTOREPOINTS] [RESETHOSTS] [emptytemp]