
Logi z OTLa
http://wklej.org/id/627806/
http://wklej.org/id/627808/
Pozdrawiam
:OTL
PRC - [2011-11-15 10:24:49 | 000,217,088 | ---- | M] ( ) -- C:\Documents and Settings\Wiśnia\Application Data\6.exe
PRC - [2011-11-08 16:14:32 | 000,278,528 | ---- | M] ( ) -- C:\Documents and Settings\Wiśnia\Start Menu\Programs\Startup\WINLOGONs.exe
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe" File not found
O4 - HKCU..\Run: [Qnsyso] C:\Documents and Settings\Wiśnia\Application Data\Qnsyso.exe File not found
O4 - Startup: C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\stepx2.exe ()
O4 - Startup: C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\WINLOGONs.exe ( )
O16 - DPF: {32564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab (Reg Error: Key error.)
[2011-11-15 02:27:00 | 000,217,088 | ---- | C] ( ) -- C:\Documents and Settings\Wiśnia\Application Data\7.exe
[2011-11-15 02:24:22 | 000,278,528 | ---- | C] ( ) -- C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\WINLOGONs.exe
[2011-11-15 10:24:49 | 000,217,088 | ---- | M] ( ) -- C:\Documents and Settings\Wiśnia\Application Data\6.exe
[2011-11-15 10:24:36 | 000,344,263 | ---- | M] () -- C:\Documents and Settings\Wiśnia\Application Data\4.exe
[2011-11-15 02:27:00 | 000,217,088 | ---- | M] ( ) -- C:\Documents and Settings\Wiśnia\Application Data\7.exe
[2011-11-15 02:24:21 | 000,344,263 | ---- | M] () -- C:\Documents and Settings\Wiśnia\Application Data\1F3.exe
[2011-11-15 02:01:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011-11-08 16:14:32 | 000,278,528 | ---- | M] ( ) -- C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\WINLOGONs.exe
[2011-11-08 11:55:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[emptyflash]
:OTL
O4 - Startup: C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\stepx2.exe ()
O4 - Startup: C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\WINLOGONs.exe ( )
:Files
C:\Documents and Settings\Wiśnia\Application Data\Xnsysv.exe
C:\Documents and Settings\Wiśnia\Start Menu\Programs\Startup\WINLOGONs.exe
C:\Documents and Settings\Wiśnia\Application Data\1B.exe
C:\Documents and Settings\Wiśnia\Application Data\1C.exe
C:\Documents and Settings\Wiśnia\Application Data\1B.exe
C:\Documents and Settings\Wiśnia\Application Data\1A.exe
C:\Documents and Settings\Wiśnia\Application Data\3.exe
C:\Documents and Settings\Wiśnia\Start Menu\Programs\StartUp\stepx2.exe
:Commands
[emptytemp]
[emptyflash]
Files to delete:
C:\Documents and Settings\Wiśnia\Application Data\Xnsysv.exe
:OTL
O4 - HKCU..\Run: [Xnsysv] C:\Documents and Settings\Wiśnia\Application Data\Xnsysv.exe File not found
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 13 gości