
Logi OTL:
http://www.wklej.org/hash/e0c08c095f9/
http://www.wklej.org/hash/2eb800e71da/
BTW: W zasadach wstawiania logów nie ma nic o opcji pomiń znane dobre pliki, więc wolałem ją odznaczyć i zeskanować wszystko. Mam nadzieję, że to nie błąd

:OTL
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe File not found
O4 - HKU\S-1-5-21-1898452130-4185415221-3151522218-1000..\Run: [] File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O33 - MountPoints2\{0798ca41-e780-11df-b1cb-fa7bcb434e11}\Shell - "" = AutoRun
O33 - MountPoints2\{0798ca41-e780-11df-b1cb-fa7bcb434e11}\Shell\AutoRun\command - "" = J:\NokiaPCIA_Autorun.exe -- File not found
O33 - MountPoints2\{74e9ffd0-a06d-11df-89a4-00262d9a1daa}\Shell - "" = AutoRun
O33 - MountPoints2\{74e9ffd0-a06d-11df-89a4-00262d9a1daa}\Shell\AutoRun\command - "" = H:\Autorun.exe -- File not found
:Files
C:\Windows\tasks\*.job
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]
C:\Windows\KMService.exe
C:\Windows\SysWOW64\srvany.exe
C:\Windows\SysNative\drivers\SWDUMon.sys
wojtas napisał(a):zmień nazwę na mówiącą o Twoim problemie...
All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\Sidebar deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\Sidebar deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1898452130-4185415221-3151522218-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0798ca41-e780-11df-b1cb-fa7bcb434e11}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0798ca41-e780-11df-b1cb-fa7bcb434e11}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0798ca41-e780-11df-b1cb-fa7bcb434e11}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0798ca41-e780-11df-b1cb-fa7bcb434e11}\ not found.
File J:\NokiaPCIA_Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74e9ffd0-a06d-11df-89a4-00262d9a1daa}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74e9ffd0-a06d-11df-89a4-00262d9a1daa}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74e9ffd0-a06d-11df-89a4-00262d9a1daa}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74e9ffd0-a06d-11df-89a4-00262d9a1daa}\ not found.
File H:\Autorun.exe not found.
========== FILES ==========
C:\Windows\tasks\Google Software Updater.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1898452130-4185415221-3151522218-1000Core.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1898452130-4185415221-3151522218-1000UA.job moved successfully.
C:\Windows\tasks\SlimDrivers Startup.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: rad
->Temp folder emptied: 4054609052 bytes
->Temporary Internet Files folder emptied: 13995729 bytes
->Java cache emptied: 11242630 bytes
->FireFox cache emptied: 100619975 bytes
->Google Chrome cache emptied: 229677918 bytes
->Flash cache emptied: 25273 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 920224205 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50534 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5 084,00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Public
User: rad
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.17.3 log created on 11272010_174816
Files\Folders moved on Reboot...
C:\Users\rad\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\rad\AppData\Local\Temp\WTC034.tmp moved successfully.
C:\Users\rad\AppData\Local\Temp\WTC045.tmp moved successfully.
Registry entries deleted on Reboot...
wojtas napisał(a):te plik/i :
C:\Windows\KMService.exe
C:\Windows\SysWOW64\srvany.exe
C:\Windows\SysNative\drivers\SWDUMon.sys
przeskanuj tu
http://virusscan.jotti.org/
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości