UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.19) Gecko/2010031422 Firefox/3.0.19
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
:Processes
killallprocesses
:OTL
MOD - [2011-08-15 08:22:39 | 000,199,168 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Ustawienia lokalne\Temp\csrss.exe
MOD - [2011-08-13 15:11:56 | 000,198,656 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe
MOD - [2011-08-13 15:10:27 | 000,192,512 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Dane aplikacji\Microsoft\conhost.exe
MOD - [2011-08-05 22:40:24 | 000,726,016 | ---- | M] () -- C:\WINDOWS\update.2\svchost.exe
MOD - [2011-08-05 11:17:09 | 000,232,960 | ---- | M] () -- C:\WINDOWS\l1rezerv.exe
MOD - [2011-08-05 11:15:22 | 000,348,672 | ---- | M] () -- C:\WINDOWS\update.5.0\6011.exe
MOD - [2011-08-05 11:06:06 | 000,256,000 | ---- | M] () -- C:\WINDOWS\sysdriver32_.exe
MOD - [2011-08-05 11:06:06 | 000,256,000 | ---- | M] () -- C:\WINDOWS\sysdriver32.exe
MOD - [2011-07-18 11:18:35 | 000,114,176 | ---- | M] () -- C:\WINDOWS\systemup.exe
MOD - [2011-07-18 11:09:14 | 001,170,432 | -H-- | M] () -- C:\WINDOWS\update.1\svchost.exe
MOD - [2010-01-01 01:38:15 | 000,040,960 | ---- | M] () -- C:\WINDOWS\system32\winszd32.dll
SRV - [2011-08-05 22:40:24 | 000,726,016 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.2\svchost.exe -- (srviecheck)
SRV - [2011-08-05 11:15:22 | 000,348,672 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.5.0\6011.exe -- (srvbtcclient)
SRV - [2011-08-05 11:06:06 | 000,256,000 | ---- | M] () [Auto | Running] -- C:\WINDOWS\sysdriver32.exe -- (srvsysdriver32)
SRV - [2011-07-18 11:09:14 | 001,170,432 | -H-- | M] () [Auto | Running] -- C:\WINDOWS\update.1\svchost.exe -- (wxpdrivers)
IE - HKU\S-1-5-21-1060284298-1677128483-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:59273
O4 - HKLM..\Run: [5022439.exe] C:\WINDOWS\TEMP\5022439.exe ()
O4 - HKLM..\Run: [900891.exe] C:\WINDOWS\TEMP\900891.exe ()
O4 - HKLM..\Run: [9634322.exe] C:\WINDOWS\TEMP\9634322.exe ()
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Użytkownik\Dane aplikacji\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [l1rezerv.exe] C:\WINDOWS\l1rezerv.exe ()
O4 - HKLM..\Run: [sysdriver32.exe] C:\WINDOWS\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] C:\WINDOWS\sysdriver32_.exe ()
O4 - HKLM..\Run: [systemup] C:\WINDOWS\systemup.exe ()
O4 - HKLM..\Run: [wxpdrv] C:\WINDOWS\update.1\svchost.exe ()
F3 - HKU\S-1-5-21-1060284298-1677128483-725345543-1003 WinNT: Load - (C:\DOCUME~1\UYTKOW~1\USTAWI~1\Temp\csrss.exe) - C:\Documents and Settings\Użytkownik\Ustawienia lokalne\Temp\csrss.exe ()
O20 - HKU\S-1-5-21-1060284298-1677128483-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe) - C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe ()
O20 - Winlogon\Notify\winszd32: DllName - winszd32.dll - C:\WINDOWS\System32\winszd32.dll ()
[2011-07-18 11:18:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\ufa
[2011-07-18 11:18:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\rpcminer
[2011-07-18 11:18:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\phoenix
[2011-07-18 11:16:39 | 000,000,000 | ---D | C] -- C:\Microsoft
[2011-07-18 11:23:25 | 000,904,792 | ---- | M] () -- C:\WINDOWS\geoiplist.rar
[2011-07-18 11:23:25 | 000,246,272 | ---- | M] () -- C:\WINDOWS\unrar.exe
[2011-07-18 11:18:49 | 005,589,370 | ---- | M] () -- C:\WINDOWS\phoenix.rar
[2011-07-18 11:18:49 | 000,182,617 | ---- | M] () -- C:\WINDOWS\ufa.rar
[2011-07-18 11:18:38 | 001,075,284 | ---- | M] () -- C:\WINDOWS\rpcminer.rar
[2011-07-18 11:18:35 | 000,114,176 | ---- | M] () -- C:\WINDOWS\systemup.exe
[2011-07-18 11:16:28 | 000,169,472 | ---- | M] () -- C:\WINDOWS\gbot111.exe
[2011-07-18 11:15:25 | 000,000,000 | ---- | M] () -- C:\WINDOWS\loader2.exe_ok
[2011-07-17 03:24:20 | 004,636,907 | ---- | M] () -- C:\WINDOWS\geoiplist
[2011-07-18 11:14:22 | 000,015,733 | ---- | C] () -- C:\Documents and Settings\Użytkownik\Dane aplikacji\3696.6C0
:Files
C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe
C:\Documents and Settings\Użytkownik\Ustawienia lokalne\Temp\csrss.exe
C:\Documents and Settings\Użytkownik\Dane aplikacji\Microsoft\conhost.exe
C:\WINDOWS\update.2
C:\WINDOWS\l1rezerv.exe
C:\WINDOWS\update.5.0
C:\WINDOWS\sysdriver32_.exe
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\systemup.exe
C:\WINDOWS\update.1
C:\Documents and Settings\Użytkownik\Dane aplikacji\dwmu.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_USERS\S-1-5-21-1060284298-1677128483-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"=-
"Monitor"=-
"nwiz"=-
"SoundMan"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Użytkownik\Pulpit\Flash-Player.exe"=-
"C:\WINDOWS\update.1\svchost.exe"=-
"C:\WINDOWS\update.2\svchost.exe"=-
"C:\WINDOWS\update.2\4927.exe"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.19) Gecko/2010031422 Firefox/3.0.19
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.19) Gecko/2010031422 Firefox/3.0.19
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.19) Gecko/2010031422 Firefox/3.0.19
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0) Gecko/20100101 Firefox/6.0
:OTL
MOD - [2011-08-16 22:56:53 | 000,209,920 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Ustawienia lokalne\Temp\csrss.exe
MOD - [2011-08-16 22:56:16 | 000,197,632 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe
MOD - [2011-08-16 22:52:21 | 000,195,584 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Dane aplikacji\Microsoft\conhost.exe
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Użytkownik\Dane aplikacji\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico0] File not found
O4 - HKLM..\Run: [tray_ico1] File not found
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
F3 - HKU\S-1-5-21-1060284298-1677128483-725345543-1003 WinNT: Load - (C:\DOCUME~1\UYTKOW~1\USTAWI~1\Temp\csrss.exe) - C:\Documents and Settings\Użytkownik\Ustawienia lokalne\Temp\csrss.exe ()
O20 - HKU\S-1-5-21-1060284298-1677128483-725345543-1003 Winlogon: Shell - (C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe) - C:\Documents and Settings\Użytkownik\Dane aplikacji\dwm.exe ()
O20 - Winlogon\Notify\winszd32: DllName - winszd32.dll - File not found
O31 - SafeBoot: AlternateShell - services32.exe
[2011-08-16 23:49:41 | 000,024,209 | ---- | M] () -- C:\Documents and Settings\Użytkownik\Dane aplikacji\3696.6C0
[2011-07-18 11:14:55 | 000,000,202 | ---- | C] () -- C:\WINDOWS\info1
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_USERS\S-1-5-21-1060284298-1677128483-725345543-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="cmd.exe"
:Commands
[reboot]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.19) Gecko/2010031422 Firefox/3.0.19
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0) Gecko/20100101 Firefox/6.0
Mozilla Firefox (3.0.19)
UA: Mozilla/5.0 (Windows NT 5.1; rv:6.0) Gecko/20100101 Firefox/6.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20100101 Firefox/5.0
Zarejestrowani użytkownicy: Bing [Bot], Google [Bot]