18 Lut 2012, 03:06
18 Lut 2012, 09:08
:OTL
FF - prefs.js..browser.search.order.1: "Ask.com"
[2012-01-14 00:17:40 | 000,002,572 | ---- | M] () -- C:\Documents and Settings\Biały\Dane aplikacji\Mozilla\Firefox\Profiles\ueb546bq.default\searchplugins\askcom.xml
O4 - HKU\.DEFAULT..\Run: [sqjuumxa] C:\Documents and Settings\Biały\sqjuumxa.exe File not found
O4 - HKU\.DEFAULT..\Run: [tcpudp] C:\WINDOWS\BN4.tmp ()
O4 - HKU\S-1-5-18..\Run: [sqjuumxa] C:\Documents and Settings\Biały\sqjuumxa.exe File not found
O4 - HKU\S-1-5-18..\Run: [tcpudp] C:\WINDOWS\BN4.tmp ()
O4 - HKLM..\RunOnce: [] File not found
[2012-01-12 23:03:14 | 000,004,998 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\mtbjfghn.xbe
O33 - MountPoints2\{1568f95e-4be2-11e1-a29f-0030058d945e}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[2012-02-17 23:06:02 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1993962763-1606980848-1003UA.job
[2012-02-17 23:06:01 | 000,001,080 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1993962763-1606980848-1003Core.job
[2012-02-18 00:07:37 | 000,067,584 | ---- | C] () -- C:\WINDOWS\System32\sqjuumxa.exe
:Files
Recycler /alldrives
:Reg
[HKEY_USERS\S-1-5-21-1390067357-1993962763-1606980848-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
18 Lut 2012, 12:58
18 Lut 2012, 13:48
:OTL
SRV - [2008-04-14 21:50:36 | 000,161,768 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\lgkva.dll -- (thvfd)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
O4 - HKLM..\Run: [sqjuumxa] C:\WINDOWS\system32\sqjuumxa.exe ()
O4 - HKU\.DEFAULT..\Run: [sqjuumxa] C:\Documents and Settings\Biały\sqjuumxa.exe ()
O4 - HKU\.DEFAULT..\Run: [tcpudp] C:\WINDOWS\BN4.tmp ()
O4 - HKU\S-1-5-18..\Run: [sqjuumxa] C:\Documents and Settings\Biały\sqjuumxa.exe ()
O4 - HKU\S-1-5-18..\Run: [tcpudp] C:\WINDOWS\BN4.tmp ()
O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [tcpudp] C:\WINDOWS\BN2.tmp File not found
:Files
C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update
C:\RECYCLER
C:\UsbFix
C:\Program Files\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
C:\WINDOWS\System32\drivers\mbamswissarmy.sys
C:\WINDOWS\System32\sqjuumxa.exe
C:\Documents and Settings\Biały\sqjuumxa.exe
C:\WINDOWS\System32\drivers\etc\hosts.20120218-003239.backup
C:\UsbFix_Upload_Me_KOMPUTER.zip
C:\WINDOWS\System32\drivers\etc\hosts.20120218-002628.backup
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
18 Lut 2012, 14:03
netsvcs
18 Lut 2012, 16:15
18 Lut 2012, 17:01
:OTL
MOD - [2012-02-18 15:10:52 | 000,196,608 | ---- | M] () -- C:\WINDOWS\Temp\BN3.tmp
IE - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found
O4 - HKLM..\Run: [sqjuumxa] C:\WINDOWS\system32\sqjuumxa.exe ()
O4 - HKU\.DEFAULT..\Run: [sqjuumxa] C:\Documents and Settings\Biały\sqjuumxa.exe ()
O4 - HKU\.DEFAULT..\Run: [tcpudp] C:\WINDOWS\BN3.tmp ()
O4 - HKU\S-1-5-18..\Run: [sqjuumxa] C:\Documents and Settings\Biały\sqjuumxa.exe ()
O4 - HKU\S-1-5-18..\Run: [tcpudp] C:\WINDOWS\BN3.tmp ()
O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [Google Update] "C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c File not found
O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [tcpudp] C:\WINDOWS\BN2.tmp File not found
O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [Google Update] "C:\Documents and Settings\Biały\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c File not found
O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [tcpudp] C:\WINDOWS\BN2.tmp File not found
:Files
Recycler /alldrives
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
"thvfd"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
18 Lut 2012, 17:05
kominekl napisał(a):O4 - HKU\S-1-5-21-1390067357-1993962763-1606980848-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
18 Lut 2012, 17:17
http://zapodaj.net/18ab6051a0a2.jpg.html
18 Lut 2012, 17:26
18 Lut 2012, 17:31
18 Lut 2012, 17:35
18 Lut 2012, 17:38
18 Lut 2012, 17:41
18 Lut 2012, 17:49