UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
:OTL
PRC - [2011-02-03 17:11:30 | 000,032,266 | ---- | M] (GnuPT - Protect Your Data) -- C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2\csrss.exe
SRV - File not found [Auto | Stopped] -- -- (DES2 Service)
O4 - HKU\S-1-5-21-1715567821-299502267-725345543-1003..\Run: [mssend] C:\Documents and Settings\Jurek\Dane aplikacji\x23ejdgnbbageoyipx2nomkr1bkftcio2\svcnost.exe (GnuPT - Protect Your Data)
O20 - HKLM Winlogon: Shell - ("C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2\csrss.exe") - C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2\csrss.exe (GnuPT - Protect Your Data)
[2011-02-03 17:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jurek\Dane aplikacji\xfuhegefcacp2wtpeptflgpo3swvbfgy2
:Files
C:\Documents and Settings\Jurek\Dane aplikacji\x23ejdgnbbageoyipx2nomkr1bkftcio2
C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2
C:\Documents and Settings\Jurekupdate001.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Jurek\Dane aplikacji\xfuhegefcacp2wtpeptflgpo3swvbfgy2\svcnost.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2\csrss.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\x23ejdgnbbageoyipx2nomkr1bkftcio2\svcnost.exe"=-
"C:\Documents and Settings\Jurekupdate001.exe"=-
:Commands
[clearallrestorepoints]
[resethosts]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Jurek\Dane aplikacji\xfuhegefcacp2wtpeptflgpo3swvbfgy2\svcnost.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2\csrss.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\x23ejdgnbbageoyipx2nomkr1bkftcio2\svcnost.exe"=-
"C:\Documents and Settings\Jurekupdate001.exe"=-
Files to delete:
C:\Documents and Settings\Jurekupdate001.exe
Folders to delete:
C:\Documents and Settings\Jurek\Dane aplikacji\xfuhegefcacp2wtpeptflgpo3swvbfgy2
C:\Documents and Settings\Jurek\Dane aplikacji\x23ejdgnbbageoyipx2nomkr1bkftcio2
C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2
Programs to launch on reboot:
C:\FIX.reg
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
Folders to delete:
C:\Documents and Settings\Jurek\Dane aplikacji\xl2rkkkblwncklfajt2h3cmbdfhbonvy2
Drivers to delete:
DES2 Service
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
:OTL
O4 - HKU\S-1-5-21-1715567821-299502267-725345543-1003..\Run: [mssend] File not found
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Jurekupdate001.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\xfuhegefcacp2wtpeptflgpo3swvbfgy2\svcnost.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\knrtymsmioxlh3kl2vbpltgyaahcubm2\csrss.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\x23ejdgnbbageoyipx2nomkr1bkftcio2\svcnost.exe"=-
"C:\Documents and Settings\Jurek\Dane aplikacji\xl2rkkkblwncklfajt2h3cmbdfhbonvy2\svcnost.exe=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
:OTL
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Jurek\Dane aplikacji\xl2rkkkblwncklfajt2h3cmbdfhbonvy2\svcnost.exe"=-
Mam jeszcze taki problem, że nie mogę się zalogować do Gadu-gadu. Może to być powiązane?
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]