
netsvcs
drivers32 /all
%SYSTEMDRIVE%\*.*
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
c:\windows\system32\userinit.exe
[ArcaVir]
2010-08-11 Trojan.Spy.Wemon.sh
[G DATA]
2010-08-11 Gen:Trojan.Heur.GM.1400048080
[Avast! antivirus]
2010-08-11 Win32:Malware-gen
[Ikarus]
2010-08-11 Trojan-Spy.Win32.Wemon
[Grisoft AVG Anti-Virus]
2010-08-11 Generic2_c.AVDN
[Kaspersky Anti-Virus]
2010-08-11 Trojan-Spy.Win32.Wemon.sg
[Avira AntiVir]
2010-08-11 TR/Spy.38922
[ESET NOD32]
2010-08-11 Win32/Kryptik.FRP
[Softwin BitDefender]
2010-08-11 Gen:Trojan.Heur.GM.1400048080
[Panda Antivirus]
2010-08-10 Nic nie znaleziono
[ClamAV]
2010-08-11 PUA.Packed.PEPack
[Quick Heal]
2010-08-11 TrojanSpy.Wemon.sg
[CPsecure]
2010-08-11 Troj.Spy.W32.Wemon.sg
[Sophos]
2010-08-11 Mal/Generic-L
[Dr.Web]
2010-08-11 Trojan.PWS.Spy.9573
[VirusBlokAda VBA32]
2010-08-10 Malware-Cryptor.Win32.General.6
[Frisk F-Prot Antivirus]
2010-08-10 Nic nie znaleziono
[VirusBuster]
2010-08-10 TrojanSpy.Wemon.GO
[F-Secure Anti-Virus]
2010-08-11 Gen:Trojan.Heur.GM.1400048080
/md5start
userinit.exe
/md5stop
OTL logfile created on: 2010-08-11 12:37:06 - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Lukasz\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1 007,00 Mb Total Physical Memory | 281,00 Mb Available Physical Memory | 28,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 69,00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 199,03 Gb Free Space | 85,47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ROSZCZYNIALSKI
Current User Name: Lukasz
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Custom Scans ==========[/color]
[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2008-04-14 19:21:45 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=2A5B37D520508BE6570A3EA79695F5B5 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2010-07-13 12:59:17 | 000,038,922 | ---- | M] () MD5=A7A44DC5F328717F0D1FAE0D1F4FCF56 -- C:\WINDOWS\system32\userinit.exe
[2006-03-02 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=BD768099B4C44AA631728CB74EB54396 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< End of report >
:PROCESSES
killallprocesses
:FILES
[override]
C:\WINDOWS\system32\userinit.exe|C:\WINDOWS\ServicePackFiles\i386\userinit.exe /replace
[stopoverride]
:COMMANDS
[reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 19 gości