13 Mar 2012, 19:17
13 Mar 2012, 21:15
:OTL
MOD - [2012-03-06 20:09:50 | 000,025,600 | ---- | M] () -- C:\WINDOWS\system32\crrss.exe
O4 - HKLM..\Run: [crrss] C:\WINDOWS\system32\crrss.exe ()
O4 - HKLM..\Run: [MozillaAgent] C:\WINDOWS\Temp\_ex-68.exe File not found
O4 - HKU\S-1-5-21-606747145-651377827-1177238915-1002..\Run: [04volausvnw7] C:\Documents and Settings\lol2000k\Ustawienia lokalne\Temp\6F30.tmp (KlureIn)
O4 - HKU\S-1-5-21-606747145-651377827-1177238915-1002..\Run: [Antivirus Protection 2012] "C:\Documents and Settings\lol2000k\Dane aplikacji\Antivirus Protection 2012\AntivirusProtection2012.exe" /STARTUP File not found
O4 - HKU\S-1-5-21-606747145-651377827-1177238915-1002..\Run: [Antivirus Protection 2012 SH] C:\Documents and Settings\lol2000k\Dane aplikacji\Antivirus Protection 2012\securityhelper.exe File not found
O4 - HKU\S-1-5-21-606747145-651377827-1177238915-1002..\Run: [Antivirus Protection 2012 SM] C:\Documents and Settings\lol2000k\Dane aplikacji\Antivirus Protection 2012\securitymanager.exe File not found
O4 - HKU\S-1-5-21-606747145-651377827-1177238915-1002..\Run: [DAEMON Tools Pro Agent] "D:\Program Files\DAEMON Tools Pro\DTProAgent.exe" -autorun File not found
O4 - HKU\S-1-5-21-606747145-651377827-1177238915-1002..\Run: [winlogon] C:\Documents and Settings\lol2000k\winlogon.exe ()
[2012-03-13 18:03:00 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-651377827-1177238915-1002UA.job
[2012-03-12 19:03:01 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-651377827-1177238915-1002Core.job
[2012-02-27 17:50:09 | 000,281,104 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\wpcap.dll
[2012-02-27 17:50:09 | 000,100,880 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\Packet.dll
[2012-02-27 17:50:09 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\drivers\npf.sys
[2012-01-20 14:14:28 | 000,017,280 | ---- | M] (Systweak Inc., (http://www.systweak.com)) -- C:\WINDOWS\System32\roboot.exe
:Services
NPF
:Reg
[HKEY_USERS\S-1-5-21-606747145-651377827-1177238915-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=-
"nwiz"=-
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp]
13 Mar 2012, 22:51
13 Mar 2012, 23:01
14 Mar 2012, 17:54
14 Mar 2012, 18:33
14 Mar 2012, 18:38
14 Mar 2012, 19:56
:OTL
DRV - File not found [Kernel | Auto | Stopped] -- -- (VBoxUSBMon)
DRV - File not found [Kernel | Auto | Stopped] -- -- (VBoxDRV)
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alg]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{175F0111-2968-4935-8F70-33108C6A4DE3}"=-
Java(TM) 6 Update 20
15 Mar 2012, 15:58