UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O4 - HKLM..\Run: [eekyanvdnqhdaoh] C:\Documents and Settings\All Users\Dane aplikacji\eekyanvdnqhdaohrclhk.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O20 - Winlogon\Notify\rpcc: DllName - (C:\WINDOWS\system32\rpcc.dll) - File not found
O20 - Winlogon\Notify\rpccd: DllName - (C:\WINDOWS\system32\rpccd.dll) - C:\WINDOWS\system32\rpccd.dll ()
[2012-05-18 10:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\phggkreiilekkph
[2012-05-18 10:38:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2012-05-18 10:38:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2012-05-18 10:37:26 | 000,000,448 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\rxgrhrxzqzqpwzv
[2012-05-18 10:37:20 | 000,057,344 | ---- | M] () -- C:\WINDOWS\explorer_new.exe
[2012-05-18 10:37:20 | 000,057,344 | ---- | M] () -- C:\WINDOWS\eekyanvdnqhdaohrclhk.exe
[2012-05-18 10:37:20 | 000,057,344 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\eekyanvdnqhdaohrclhk.exe
[2012-05-17 20:18:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2012-05-17 20:18:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2012-05-16 21:45:55 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2012-05-16 21:45:55 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2012-05-16 13:25:48 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2012-05-16 13:25:48 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2012-05-15 23:15:54 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2012-05-15 23:15:54 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2012-05-14 21:31:58 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2012-05-14 21:31:58 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2012-05-14 17:52:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2012-05-14 17:52:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2012-05-14 11:10:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2012-05-14 11:10:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2012-05-13 21:45:58 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2012-05-13 21:45:58 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2012-05-13 16:25:19 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2012-05-13 16:25:19 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2012-05-12 22:30:15 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2012-05-12 22:30:15 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2012-05-12 19:20:52 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2012-05-12 19:20:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2012-05-11 20:26:34 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2012-05-11 20:26:34 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2012-05-11 12:22:28 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2012-05-11 12:22:28 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2012-05-11 12:17:26 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2012-05-11 12:17:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2012-05-10 20:59:15 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2012-05-10 20:59:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2012-05-10 16:25:15 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2012-05-10 16:25:15 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2012-05-09 20:38:43 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2012-05-09 20:38:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2012-05-09 10:58:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2012-05-09 10:58:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2012-05-08 21:55:01 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2012-05-08 21:55:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
:OTL
IE - HKU\S-1-5-21-1645522239-329068152-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
IE - HKU\S-1-5-21-1645522239-329068152-839522115-1003\..\URLSearchHook: {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Neostrada TP\SearchPageURL.dll ()
FF - prefs.js..browser.startup.homepage: \"http://pl.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pl:official\"
O4 - HKU\S-1-5-21-1645522239-329068152-839522115-1003..\Run: [eekyanvdnqhdaoh] C:\Documents and Settings\All Users\Dane aplikacji\eekyanvdnqhdaohrclhk.exe File not found
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} http://mks.com.pl/skaner/SkanerOnline.cab (MainControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222695610062 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O20 - HKLM Winlogon: Shell - (explorer_new.exe) - File not found
:Files
C:\Documents and Settings\admin\ms.exe
C:\WINDOWS\System32\754782ld.exe
C:\WINDOWS\System32\13369532ld.exe
C:\WINDOWS\System32\17521712ld.exe
C:\WINDOWS\System32\20262182ld.exe
C:\WINDOWS\System32\26198432ld.exe
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
piotrus81 napisał(a):Zrobione.
Czy dobrze rozumuję, że to już wszystko?
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
piotrus81 napisał(a):Wygląda na to, że chyba już wszystko ok. Jednakże nie mam w tym momencie czasu na bardziej dogłębne sprawdzenie. W razie jakichś problemów, dam znać.
Tymczasem gorąco dziękuję za skuteczną i szybką pomoc. Pozdrawiam
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
Zarejestrowani użytkownicy: Bing [Bot]