Na razie usuniemy to co należy a potem reszte śmieci, wklej w OTL i naciśnij wykonaj skrypt:
:Processes
killallprocesses
:OTL
O4 - HKLM..\Run: [Bron-Spizaetus] C:\WINDOWS\ShellNew\bronstab.exe ()
O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.8.1\facemoodssrv.exe File not found
O4 - HKLM..\Run: [vilaunch] C:\WINDOWS\system32\vilaunch.exe ()
O4 - HKU\.DEFAULT..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe File not found
O4 - HKU\S-1-5-18..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe File not found
O4 - HKU\S-1-5-20..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [api32] C:\DOCUME~1\krawiec\USTAWI~1\Temp\apiqq.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [cdoosoft] C:\Documents and Settings\krawiec\Ustawienia lokalne\Temp\herss.exe ()
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [King_ar] C:\WINDOWS\system32\arking.exe ()
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [king_mg] C:\windows\System32\mgking.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [KOO9RV9K4Z] C:\DOCUME~1\krawiec\USTAWI~1\Temp\Mq1.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [laqig] C:\Documents and Settings\krawiec\laqig.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [PCSpeedUp] C:\Program Files\Przyspiesz Komputer\PCSpeedUp.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [RegistryBooster] D:\LoopWorx Hip Hop\RegistryBooster\launcher.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [Tok-Cirrhatus] C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\smss.exe ()
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [Wru] D:\LoopWorx Hip Hop\Wru\Wru.exe File not found
O4 - HKU\S-1-5-21-1202660629-2111687655-1801674531-1004..\Run: [wsctf.exe] File not found
O4 - HKU\.DEFAULT..\RunOnce: [_nltide_2] File not found
O4 - HKU\S-1-5-18..\RunOnce: [_nltide_2] File not found
O4 - HKU\S-1-5-20..\RunOnce: [_nltide_2] File not found
O4 - Startup: C:\Documents and Settings\krawiec\Menu Start\Programy\Autostart\Empty.pif ()
O20 - HKLM Winlogon: Shell - ("C:\WINDOWS\eksplorasi.exe") - C:\WINDOWS\eksplorasi.exe ()
O32 - AutoRun File - [2010-10-04 23:16:41 | 000,000,000 | ---D | M] - D:\AutoRun -- [ NTFS ]
O32 - AutoRun File - [2004-10-20 11:29:44 | 000,684,032 | ---- | M] (Electronic Arts Inc.) - D:\AutoRun.exe -- [ NTFS ]
O32 - AutoRun File - [2010-12-19 23:57:41 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-12-19 23:57:41 | 000,000,057 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-12-19 23:57:41 | 000,000,057 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{05fe7aed-e2ad-11df-a143-00235ae1d17f}\Shell\AutoRun\command - "" = I:\ji83j.exe -- File not found
O33 - MountPoints2\{05fe7aed-e2ad-11df-a143-00235ae1d17f}\Shell\open\Command - "" = I:\ji83j.exe -- File not found
O33 - MountPoints2\{0b7c0647-7981-11df-9dc2-00215dbd5bc2}\Shell\AutoRun\command - "" = H:\qhbfqx.exe -- File not found
O33 - MountPoints2\{0b7c0647-7981-11df-9dc2-00215dbd5bc2}\Shell\open\Command - "" = H:\qhbfqx.exe -- File not found
O33 - MountPoints2\{1c10cda9-0ab0-11e0-a231-00235ae1d17f}\Shell\AutoRun\command - "" = G:\ji83j.exe -- File not found
O33 - MountPoints2\{1c10cda9-0ab0-11e0-a231-00235ae1d17f}\Shell\open\Command - "" = G:\ji83j.exe -- File not found
O33 - MountPoints2\{23b6880e-acf7-11df-a092-00235ae1d17f}\Shell - "" = AutoRun
O33 - MountPoints2\{40ecbac4-02d8-11e0-a201-00235ae1d17f}\Shell\AutoRun\command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{40ecbac4-02d8-11e0-a201-00235ae1d17f}\Shell\open\Command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{79672566-ac29-11df-9f91-00235ae1d17f}\Shell\AutoRun\command - "" = G:\9d6resf.exe -- File not found
O33 - MountPoints2\{79672566-ac29-11df-9f91-00235ae1d17f}\Shell\open\Command - "" = G:\9d6resf.exe -- File not found
O33 - MountPoints2\{8112aee6-ee38-11df-a18d-00235ae1d17f}\Shell\AutoRun\command - "" = G:\albkpq3.exe -- File not found
O33 - MountPoints2\{8112aee6-ee38-11df-a18d-00235ae1d17f}\Shell\open\Command - "" = G:\albkpq3.exe -- File not found
O33 - MountPoints2\{8112aee7-ee38-11df-a18d-00235ae1d17f}\Shell\AutoRun\command - "" = H:\albkpq3.exe -- File not found
O33 - MountPoints2\{8112aee7-ee38-11df-a18d-00235ae1d17f}\Shell\open\Command - "" = H:\albkpq3.exe -- File not found
O33 - MountPoints2\{97c87086-0b61-11e0-a236-00235ae1d17f}\Shell\AutoRun\command - "" = G:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{97c87086-0b61-11e0-a236-00235ae1d17f}\Shell\explore\Command - "" = G:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{97c87086-0b61-11e0-a236-00235ae1d17f}\Shell\open\Command - "" = G:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{97c8708a-0b61-11e0-a236-00235ae1d17f}\Shell\AutoRun\command - "" = G:\ji83j.exe -- File not found
O33 - MountPoints2\{97c8708a-0b61-11e0-a236-00235ae1d17f}\Shell\open\Command - "" = G:\ji83j.exe -- File not found
O33 - MountPoints2\{97c8708b-0b61-11e0-a236-00235ae1d17f}\Shell\AutoRun\command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{97c8708b-0b61-11e0-a236-00235ae1d17f}\Shell\open\Command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{9866da0c-81b6-11df-9dde-00235ae1d17f}\Shell\AutoRun\command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{9866da0c-81b6-11df-9dde-00235ae1d17f}\Shell\open\Command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{9fad643c-9979-11df-9eff-00235ae1d17f}\Shell - "" = AutoRun
O33 - MountPoints2\{a469d6fd-f001-11df-a194-00235ae1d17f}\Shell\AutoRun\command - "" = H:\bud3mkqr.exe -- File not found
O33 - MountPoints2\{a469d6fd-f001-11df-a194-00235ae1d17f}\Shell\open\Command - "" = H:\bud3mkqr.exe -- File not found
O33 - MountPoints2\{a7c0eed4-d554-11df-a0ef-00235ae1d17f}\Shell\AutoRun\command - "" = H:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{a7c0eed4-d554-11df-a0ef-00235ae1d17f}\Shell\explore\Command - "" = H:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{a7c0eed4-d554-11df-a0ef-00235ae1d17f}\Shell\open\Command - "" = H:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{d81d44f1-02c9-11e0-a200-00235ae1d17f}\Shell\AutoRun\command - "" = ji83j.exe
O33 - MountPoints2\{d81d44f1-02c9-11e0-a200-00235ae1d17f}\Shell\open\Command - "" = ji83j.exe
O33 - MountPoints2\{dfe659e8-d23e-11df-a0e2-00235ae1d17f}\Shell\AutoRun\command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{dfe659e8-d23e-11df-a0e2-00235ae1d17f}\Shell\open\Command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{e370788e-8822-11df-9e1b-00235ae1d17f}\Shell\AutoRun\command - "" = H:\qhbfqx.exe -- File not found
O33 - MountPoints2\{e370788e-8822-11df-9e1b-00235ae1d17f}\Shell\open\Command - "" = H:\qhbfqx.exe -- File not found
O33 - MountPoints2\{e6365422-08fa-11e0-a21f-00235ae1d17f}\Shell\AutoRun\command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{e6365422-08fa-11e0-a21f-00235ae1d17f}\Shell\open\Command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{ef09528c-8102-11df-9dd3-00215dbd5bc2}\Shell\AutoRun\command - "" = H:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{ef09528c-8102-11df-9dd3-00215dbd5bc2}\Shell\explore\Command - "" = C:\windows\System32\EXPLORER.EXE -- [2006-10-25 08:32:36 | 000,036,864 | RHS- | M] (Microsoft Corporation)
O33 - MountPoints2\{ef09528c-8102-11df-9dd3-00215dbd5bc2}\Shell\open\Command - "" = H:\EXPLORER.EXE -- File not found
O33 - MountPoints2\{fb50f150-b283-11df-9fc5-00235ae1d17f}\Shell\AutoRun\command - "" = G:\egmjjb.exe -- File not found
O33 - MountPoints2\{fb50f150-b283-11df-9fc5-00235ae1d17f}\Shell\open\Command - "" = G:\egmjjb.exe -- File not found
O33 - MountPoints2\{fca45572-994e-11df-9ef7-00235ae1d17f}\Shell - "" = AutoRun
O33 - MountPoints2\{fca45572-994e-11df-9ef7-00235ae1d17f}\Shell\AutoRun\command - "" = H:\AutoRunCardDetector.exe -- File not found
O33 - MountPoints2\{febe1a1c-ea63-11df-a179-00235ae1d17f}\Shell\AutoRun\command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{febe1a1c-ea63-11df-a179-00235ae1d17f}\Shell\open\Command - "" = H:\ji83j.exe -- File not found
O33 - MountPoints2\{febe1a1d-ea63-11df-a179-00235ae1d17f}\Shell\AutoRun\command - "" = I:\w9.exe -- File not found
O33 - MountPoints2\{febe1a1d-ea63-11df-a179-00235ae1d17f}\Shell\open\Command - "" = I:\w9.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\MicroLauncher.exe -- File not found
@Alternate Data Stream - 85 bytes -> C:\Documents and Settings\All Users\Pulpit:$SS_DESCRIPTOR_1VVTV9VTMV8BF1VJWVBH4P6XLVVVPVKVVBVVVVK
@Alternate Data Stream - 85 bytes -> C:\Documents and Settings\All Users\Pulpit:$SS_DESCRIPTOR_1VPTV9VVMVFBFLVJWVBFY46VDVLM05M6RHJLY7TVPPV5VVVV14F5
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:E31B24B8
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:EB2C187A
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A4240191
:Files
C:\windows\ShellNew
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\Ok-SendMail-Bron-tok
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\Loc.Mail.Bron.Tok
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\Bron.tok-10-19
C:\windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
C:\windows\tasks\IMBNNYPTV.job
C:\windows\tasks\IIAJREVDZ.job
C:\windows\System32\arking1.dll
C:\windows\System32\arking.exe
C:\windows\System32\arking0.dll
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\Bron.tok.A10.em.bin
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\Bron.tok.A10.em.bin
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\Kosong.Bron.Tok.txt
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\winlogon.exe
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\smss.exe
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\services.exe
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\lsass.exe
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\inetinfo.exe
C:\Documents and Settings\krawiec\Ustawienia lokalne\Dane aplikacji\csrss.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
[resethosts]
dajesz log z usuwania i nowy log z OTL
//Temat przenoszę do działu Bezpieczeństwo
djkamil09061991