
http://www.wklej.org/id/620557/
http://www.wklej.org/id/620558/
:OTL
PRC - [2011-09-19 15:45:28 | 000,250,888 | RHS- | M] () -- C:\Users\DELL\AppData\Roaming\Firewall Host\cfmmon.exe
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\DELL\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll File not found
O3 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [{117EEB00-ACA0-7E9E-398C-34BA28503AEA}] C:\Users\DELL\AppData\Roaming\Owek\dupy.exe (Copyright (C) 2010-2011 Marvell Semiconductor)
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [{E2A083C1-6B71-DDA8-1457-585416766490}] C:\Users\DELL\AppData\Roaming\Ebik\baac.exe File not found
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [4E3E0230AEBB4E96] C:\Recycle.Bin\Recycle.Bin.exe File not found
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [4W1WVWUV1F7W0VWELAKGVHSLYDPCIVH] C:\Recycle.Bin\B6232F3AFA9.exe (Radialpoint Inc.)
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [4Y3Y0C3A1F7W0VWEUEDF] C:\Recycle.Bin\B6232F3AFA9.exe (Radialpoint Inc.)
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [cfmmon.exe] C:\Users\DELL\AppData\Roaming\Firewall Host\cfmmon.exe ()
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [jwnmvhq] rundll32 C:\Users\DELL\AppData\Roaming\MICROS~1\Protect\hassors.sh, jxyf File not found
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [cfmmon.exe] C:\Users\DELL\AppData\Roaming\Firewall Host\cfmmon.exe ()
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [mssend] C:\Users\DELL\AppData\Roaming\xagps3lqgqvsudhdpdnwp1lwl3submea2\svcnost.exe ()
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [mssrv] C:\Users\DELL\AppData\Local\Temp\mssrv-55FF-44FF-22FF.exe (Opera Software)
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [PID] C:\Users\DELL\AppData\Local\Temp\0.8784439199901866.exe File not found
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [ZE2HUV1WWV9A3H3WGFLOAX] C:\pioasuugahs\B33BA7E8FA9.exe /q File not found
[2011-07-29 21:25:00 | 000,075,776 | ---- | C] (IEInspector.com) -- C:\Users\DELL\AppData\Roaming\1591797.exe
[2011-07-08 20:17:53 | 000,102,912 | ---- | C] (Borland Corporation) -- C:\Users\DELL\AppData\Roaming\3527167.exe
[2011-07-05 20:58:22 | 000,079,872 | ---- | C] (Borland Software Corporation) -- C:\Users\DELL\AppData\Roaming\5895919.exe
[2011-05-26 20:05:12 | 000,051,200 | ---- | C] (GnuPT - Protect Your Data) -- C:\Users\DELL\AppData\Roaming\505172.exe
2011-08-03 20:13:44 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\79090.exe
[2011-08-03 20:13:44 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\7044150.exe
[2011-08-03 20:13:44 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\1010166.exe
[2011-08-03 20:13:41 | 000,095,232 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\7471359.exe
[2011-07-29 21:25:02 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\9230887.exe
[2011-07-29 21:25:02 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\802024.exe
[2011-07-29 21:25:02 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\433634.exe
[2011-07-20 15:07:51 | 000,002,432 | ---- | C] () -- C:\Users\DELL\AppData\Local\TempeLt644.html
[2011-07-20 15:07:51 | 000,002,089 | ---- | C] () -- C:\Users\DELL\AppData\Local\TempwHz644.html
[2011-07-18 16:25:12 | 000,002,432 | ---- | C] () -- C:\Users\DELL\AppData\Local\TempgBu304.html
[2011-07-18 16:25:12 | 000,002,089 | ---- | C] () -- C:\Users\DELL\AppData\Local\TempOKh304.html
[2011-07-08 20:17:55 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\8151575.exe
[2011-07-08 20:17:55 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\6453101.exe
[2011-07-08 20:17:55 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\227781.exe
[2011-07-05 20:58:24 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\729455.exe
[2011-07-05 20:58:24 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\5592355.exe
[2011-07-05 20:58:24 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\4784172.exe
[2011-07-04 19:28:57 | 000,002,432 | ---- | C] () -- C:\Users\DELL\AppData\Local\TempmPL732.html
[2011-07-04 19:28:57 | 000,002,089 | ---- | C] () -- C:\Users\DELL\AppData\Local\TempMyt732.html
[2011-05-31 22:25:22 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\8839908.exe
[2011-05-31 22:25:22 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\4354620.exe
[2011-05-31 22:25:22 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\1253612.exe
[2011-05-31 22:25:17 | 000,068,608 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\2830784.exe
[2011-05-26 20:05:14 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\8250494.exe
[2011-05-26 20:05:14 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\6739157.exe
[2011-05-26 20:05:14 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\1898413.exe
[2011-05-03 18:00:36 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\8950657.exe
[2011-05-03 18:00:36 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\7860435.exe
[2011-05-03 18:00:36 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\6113716.exe
[2011-05-03 18:00:36 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\3960233.exe
[2011-05-03 18:00:35 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\4593378.exe
[2011-05-01 15:33:18 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\4813020.exe
[2011-05-01 15:33:18 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\269828.exe
[2011-05-01 15:33:17 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\678610.exe
[2011-05-01 15:33:17 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\3575404.exe
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:430C6D84
:Files
C:\Users\DELL\AppData\Local\Temp*.html
C:\Users\DELL\AppData\Roaming\Firewall Host\
:Commands
[emptytemp]
[emptyflash]
:OTL
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [{117EEB00-ACA0-7E9E-398C-34BA28503AEA}] C:\Users\DELL\AppData\Roaming\Owek\dupy.exe File not found
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [4W1WVWUV1F7W0VWELAKGVHSLYDPCIVH] C:\Recycle.Bin\B6232F3AFA9.exe File not found
[2011-11-03 12:40:38 | 000,937,984 | ---- | C] (COMODO) -- C:\Users\DELL\AppData\Local\bmfa.exe
[2011-11-05 10:11:25 | 000,003,850 | ---- | M] () -- C:\Users\DELL\AppData\Roaming\wklnhst.dat
[2011-09-22 18:11:34 | 000,000,032 | ---- | C] () -- C:\Users\DELL\AppData\Local\sLT.exf
[2011-08-03 20:13:44 | 000,000,000 | ---- | C] () -- C:\Users\DELL\AppData\Roaming\79090.exe
:Commands
[emptytemp]
[emptyflash]
:OTL
O4 - HKU\S-1-5-21-2232163231-3839073565-2058168333-1000..\Run: [{117EEB00-ACA0-7E9E-398C-34BA28503AEA}] C:\Users\DELL\AppData\Roaming\Owek\dupy.exe File not found
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości