:OTL PRC - [2011-08-21 21:13:01 | 000,355,840 | ---- | M] () – C:\WINDOWS\update.5.0\svchost.exe PRC - [2011-08-21 21:13:01 | 000,355,840 | ---- | M] () – C:\WINDOWS\update.5.0\svchost.exe PRC - [2011-08-21 18:40:32 | 000,232,960 | ---- | M] () – C:\WINDOWS\l1rezerv.exe PRC - [2011-08-21 18:40:21 | 000,382,464 | ---- | M] () – C:\WINDOWS\update.7.1\svchostdriver.exe PRC - [2011-08-21 18:40:17 | 000,634,880 | ---- | M] () – C:\WINDOWS\update.2\svchost.exe PRC - [2011-08-21 18:40:17 | 000,634,880 | ---- | M] () – C:\WINDOWS\update.2\svchost.exe PRC - [2011-08-21 18:28:44 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32.exe PRC - [2011-08-21 18:09:44 | 001,213,440 | -H-- | M] () – C:\WINDOWS\update.tray-7-0\svchost.exe PRC - [2011-08-21 18:09:44 | 001,213,440 | -H-- | M] () – C:\WINDOWS\update.1\svchost.exe PRC - [2011-06-29 12:20:24 | 000,743,936 | ---- | M] (Ufasoft) – C:\WINDOWS\ufa\ufa.exe MOD - [2011-08-21 21:13:01 | 000,355,840 | ---- | M] () – C:\WINDOWS\update.5.0\svchost.exe MOD - [2011-08-21 18:40:32 | 000,232,960 | ---- | M] () – C:\WINDOWS\l1rezerv.exe MOD - [2011-08-21 18:40:21 | 000,382,464 | ---- | M] () – C:\WINDOWS\update.7.1\svchostdriver.exe MOD - [2011-08-21 18:40:17 | 000,634,880 | ---- | M] () – C:\WINDOWS\update.2\svchost.exe MOD - [2011-08-21 18:28:44 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32.exe MOD - [2011-08-21 18:09:44 | 001,213,440 | -H-- | M] () – C:\WINDOWS\update.tray-7-0\svchost.exe MOD - [2011-08-21 18:09:44 | 001,213,440 | -H-- | M] () – C:\WINDOWS\update.1\svchost.exe SRV - [2011-08-21 21:13:01 | 000,355,840 | ---- | M] () [Auto | Running] – C:\WINDOWS\update.5.0\svchost.exe – (srvbtcclient) SRV - [2011-08-21 18:40:21 | 000,382,464 | ---- | M] () [Auto | Running] – C:\WINDOWS\update.7.1\svchostdriver.exe – (ddservice) SRV - [2011-08-21 18:40:17 | 000,634,880 | ---- | M] () [Auto | Running] – C:\WINDOWS\update.2\svchost.exe – (srviecheck) SRV - [2011-08-21 18:28:44 | 000,258,048 | ---- | M] () [Auto | Running] – C:\WINDOWS\sysdriver32.exe – (srvsysdriver32) SRV - [2011-08-21 18:09:44 | 001,213,440 | -H-- | M] () [Auto | Running] – C:\WINDOWS\update.1\svchost.exe – (wxpdrivers) FF - prefs.js…extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.2.0185 [2011-05-15 15:02:50 | 000,000,000 | —D | M] (“DAEMON Tools Toolbar”) – C:\Documents and Settings\Piter\Dane aplikacji\Mozilla\Firefox\Profiles\itq2451j.default\extensions\DTToolbar@toolbarnet.com [2010-12-19 00:43:08 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Piter\Dane aplikacji\Mozilla\Firefox\Profiles\itq2451j.default\extensions\engine@conduit.com O3 - HKLM…\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKU\S-1-5-21-1292428093-152049171-839522115-1003…\Toolbar\ShellBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found. O3 - HKU\S-1-5-21-1292428093-152049171-839522115-1003…\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM…\Run: [2021556-loader2.exe] File not found O4 - HKLM…\Run: [398376.exe] File not found O4 - HKLM…\Run: [4325732.exe] File not found O4 - HKLM…\Run: [5331862.exe] File not found O4 - HKLM…\Run: [56092600-loader2.exe] File not found O4 - HKLM…\Run: [9181193.exe] File not found O4 - HKLM…\Run: [l1rezerv.exe] C:\WINDOWS\l1rezerv.exe () O4 - HKLM…\Run: [sysdriver32.exe] C:\WINDOWS\sysdriver32.exe () O4 - HKLM…\Run: [sysdriver32_.exe] C:\WINDOWS\sysdriver32_.exe () O4 - HKLM…\Run: [tray_ico] File not found O4 - HKLM…\Run: [tray_ico0] C:\WINDOWS\update.tray-7-0\svchost.exe () O4 - HKLM…\Run: [tray_ico1] File not found O4 - HKLM…\Run: [tray_ico2] File not found O4 - HKLM…\Run: [tray_ico3] File not found O4 - HKLM…\Run: [tray_ico4] File not found O4 - HKLM…\Run: [wxpdrv] C:\WINDOWS\services32.exe () [2011-08-21 18:41:15 | 000,000,000 | —D | C] – C:\WINDOWS\ufa [2011-08-21 18:41:15 | 000,000,000 | —D | C] – C:\WINDOWS\rpcminer [2011-08-21 18:41:15 | 000,000,000 | —D | C] – C:\WINDOWS\phoenix [2011-08-21 18:40:22 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.7.1 [2011-08-21 18:40:18 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.2 [2011-08-21 18:40:14 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.5.0 [2011-08-21 18:15:16 | 000,000,000 | —D | C] – C:\WINDOWS\av_ico [2011-08-21 18:13:26 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.1 [2011-08-21 18:13:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.tray-7-0-lnk [2011-08-21 18:13:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\update.tray-7-0 [2011-08-21 21:13:02 | 000,000,177 | ---- | M] () – C:\WINDOWS\info1 [2011-08-21 20:57:19 | 000,000,734 | ---- | M] () – C:\WINDOWS\System32\drivers\etc\hîsts [2011-08-21 18:41:14 | 000,246,272 | ---- | M] () – C:\WINDOWS\unrar.exe [2011-08-21 18:41:13 | 005,589,370 | ---- | M] () – C:\WINDOWS\phoenix.rar [2011-08-21 18:41:13 | 000,182,617 | ---- | M] () – C:\WINDOWS\ufa.rar [2011-08-21 18:41:06 | 001,075,284 | ---- | M] () – C:\WINDOWS\rpcminer.rar [2011-08-21 18:40:32 | 000,232,960 | ---- | M] () – C:\WINDOWS\l1rezerv.exe [2011-08-21 18:31:30 | 000,904,792 | ---- | M] () – C:\WINDOWS\geoiplist.rar [2011-08-21 18:29:15 | 000,000,000 | ---- | M] () – C:\WINDOWS\loader2.exe_ok [2011-08-21 18:28:44 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32_.exe [2011-08-21 18:28:44 | 000,258,048 | ---- | M] () – C:\WINDOWS\sysdriver32.exe [2011-08-21 18:07:12 | 001,213,440 | ---- | M] () – C:\WINDOWS\services32.exe [2011-08-21 18:31:31 | 004,636,907 | ---- | C] () – C:\WINDOWS\geoiplist :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] “C:\WINDOWS\update.1\svchost.exe”=- “C:\WINDOWS\update.tray-7-0\svchost.exe”=- “C:\WINDOWS\update.2\svchost.exe”=- :Commands [CLEARALLRESTOREPOINTS] [RESETHOSTS] [emptytemp]