log.txt

Dziwne zachowanie komputera

Witam. Wszystko zaczeło się wczoraj. Internet wolno chodził, więc postanowiłem coś zrobić, pobrałem Malwarebytes anti-malware, zainstalowałem i po chwili samoczynnie zaczęło dodawać pliki do kwarantanny, komputer się zaciął, nic mi nie pozostało, niż restart. Po restarcie, włączam, loguję się i ku zdziwieniu pulpit czysty, tylko tapeta, czekam 4-5 min., aż w końcu załadowują sie inonki, bardzo mocno się laguje. Odpalam Malwarebytes i skanuje w poszukiwaniu intruzów, znalazło 12 plików, usunąłem. Niewiele to pomogło. komputer dalej się wolno włącza, lecz już nie zacina się. Prosze o pomoc! Dodam jeszcze, że jak chcę otworzyć partycje C, D to wyskakuje okienko "otwórz za pomocą"! Logi z ComboFix i OTL poniżej


ComboFix 13-04-20.02 - DOM 2013-04-20 10:45:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.511.15 [GMT 1:00]
Uruchomiony z: c:\documents and settings\DOM\Pulpit\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 080923-0] *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Usuni?to )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\documents and settings\All Users\Dane aplikacji\Download and Sa
c:\documents and settings\All Users\Dane aplikacji\Download and Sa\509394d6db65e.ocx
c:\documents and settings\All Users\Dane aplikacji\Download and Sa\509394d6db697.html
c:\documents and settings\All Users\Dane aplikacji\Download and Sa\509394d6db6d0.js
c:\documents and settings\All Users\Dane aplikacji\Download and Sa\naahdddhhdanfcbjbokabimcliijohnc.crx
c:\documents and settings\All Users\Dane aplikacji\Download and Sa\settings.ini
c:\documents and settings\All Users\Dane aplikacji\TEMP
c:\documents and settings\All Users\Dane aplikacji\TEMP\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe
c:\documents and settings\DOM\Dane aplikacji\PriceGong
c:\documents and settings\DOM\Dane aplikacji\PriceGong\Data\mru.xml
c:\documents and settings\DOM\Dane aplikacji\Quofa
c:\documents and settings\DOM\Dane aplikacji\Quofa\ufsix.cuu
c:\documents and settings\DOM\WINDOWS
C:\install.exe
c:\windows\msmqinst.log
c:\windows\System\iexplore.txt
c:\windows\system32\Cache
c:\windows\system32\Cache\26c630d098e22dd5.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\71954c0a0dbec09a.fb
c:\windows\system32\Cache\95f567698be8a182.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d2fc98fc9a0bcc40.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\d94298792eb13868.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\Cache\fb382620ba875c9d.fb
c:\windows\system32\d3d9.dll.tmp
c:\windows\system32\embedded
c:\windows\system32\embedded\decompressor.dll
c:\windows\system32\embedded\License.txt
c:\windows\system32\embedded\uninstall.exe
c:\windows\system32\embedded\WizardImage.bmp
c:\windows\system32\embedded\WizardSmallImage.bmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
D:\autorun.inf
D:\sq.com
.
.
((((((((((((((((((((((((( Pliki utworzone od 2013-03-20 do 2013-04-20 )))))))))))))))))))))))))))))))
.
.
2013-04-19 19:36 . 2013-04-19 19:36 -------- d-----w- c:\documents and settings\Marcin\Dane aplikacji\Malwarebytes
2013-04-19 18:44 . 2013-04-19 18:44 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\Malwarebytes
2013-04-19 18:44 . 2013-04-19 18:44 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2013-04-12 19:04 . 2013-04-12 19:05 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\Screaming Bee
2013-04-12 19:04 . 2013-04-12 19:04 -------- d-----w- c:\program files\Common Files\Screaming Bee
2013-04-12 19:02 . 2013-04-12 19:08 -------- d-----w- c:\program files\Screaming Bee
2013-04-12 19:02 . 2013-04-12 19:05 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Screaming Bee
2013-04-12 18:52 . 2013-04-12 18:52 -------- d-----w- c:\windows\system32\XPSViewer
2013-04-12 18:52 . 2013-04-12 18:52 -------- d-----w- c:\program files\Reference Assemblies
2013-04-12 18:52 . 2007-03-22 19:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-04-12 18:51 . 2006-06-29 12:07 14048 ------w- c:\windows\system32\spmsg2.dll
2013-04-12 18:45 . 2013-04-12 18:45 -------- d-----w- c:\program files\MSXML 6.0
2013-04-11 14:37 . 2013-04-11 14:37 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\.minecraft_backups
2013-04-07 20:45 . 2013-04-07 20:45 -------- d-----w- c:\program files\BitComet
2013-04-06 22:07 . 2010-10-20 13:14 302720 ----a-w- c:\windows\system32\drivers\V0700Afx.sys
2013-04-06 22:07 . 2011-08-22 14:48 45056 ----a-w- c:\windows\system32\V0700Pin.dll
2013-04-06 22:07 . 2011-08-22 14:48 28672 ----a-w- c:\windows\V0700Mon.exe
2013-04-06 22:07 . 2011-08-22 14:47 102400 ----a-w- c:\windows\system32\V0700Ext.crl
2013-04-06 22:07 . 2011-08-22 14:47 114688 ----a-w- c:\windows\system32\V0700Ext.ax
2013-04-06 22:07 . 2011-05-25 11:05 24576 ----a-w- c:\windows\system32\CtCamPin.crl
2013-04-06 22:07 . 2011-09-07 00:00 322528 ----a-w- c:\windows\system32\drivers\V0700Vid.sys
2013-04-06 18:13 . 2013-04-06 18:13 -------- d-----w- c:\documents and settings\DOM\Ustawienia lokalne\Dane aplikacji\IVONA_INST
2013-04-04 15:26 . 2013-04-04 15:26 -------- d-----w- c:\documents and settings\Marcin\Dane aplikacji\PC Suite
2013-04-03 17:12 . 2013-04-03 17:12 -------- d-----w- c:\program files\Mafia
2013-03-29 15:14 . 2002-06-06 13:38 139264 ----a-w- c:\windows\system32\eax.dll
2013-03-28 14:11 . 2013-03-28 14:11 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-03-28 14:03 . 2004-10-22 01:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2013-03-28 14:03 . 2004-10-22 01:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2013-03-28 14:03 . 2004-10-22 01:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2013-03-28 14:03 . 2004-10-22 01:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2013-03-28 14:03 . 2004-10-22 01:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2013-03-28 14:03 . 2013-03-28 14:03 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2013-03-28 14:03 . 2013-03-28 14:03 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2013-03-24 21:29 . 2013-03-24 21:29 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\CyberLink
2013-03-24 21:27 . 2013-03-24 21:27 -------- d-----w- c:\documents and settings\DOM\Ustawienia lokalne\Dane aplikacji\CyberLink
2013-03-24 21:25 . 2013-03-24 21:25 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\install_clap
2013-03-24 20:28 . 2013-03-24 21:28 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\CyberLink
2013-03-24 08:51 . 2013-03-24 08:51 -------- d-----w- c:\program files\Microsoft Games
2013-03-23 19:38 . 2013-03-23 19:37 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-23 19:38 . 2013-03-23 19:37 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-23 19:37 . 2013-03-23 19:37 -------- d-----w- c:\program files\Java
2013-03-23 17:07 . 2013-03-23 17:07 -------- d-----r- c:\program files\Skype
2013-03-23 16:05 . 2013-04-06 22:07 -------- d-----w- c:\windows\CtDrvInstall
2013-03-23 15:49 . 2011-07-27 18:12 94208 ------w- c:\windows\CtDrvIns.exe
2013-03-23 15:49 . 2013-03-23 15:49 -------- d-----w- C:\Creative Live! Cam
2013-03-23 11:32 . 2004-08-03 21:58 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2013-03-23 11:32 . 2004-08-03 21:58 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2013-03-23 11:32 . 2004-08-03 22:10 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2013-03-23 11:32 . 2004-08-03 22:10 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2013-03-23 11:32 . 2004-08-03 22:10 15360 -c--a-w- c:\windows\system32\dllcache\streamip.sys
2013-03-23 11:32 . 2004-08-03 22:10 15360 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2013-03-23 11:32 . 2004-08-03 23:44 16384 ----a-w- c:\windows\system32\ipsink.ax
2013-03-23 11:32 . 2004-08-03 22:10 11136 -c--a-w- c:\windows\system32\dllcache\slip.sys
2013-03-23 11:32 . 2004-08-03 22:10 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2013-03-23 11:30 . 2004-08-03 22:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-03-23 11:30 . 2004-08-03 22:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-03-22 15:58 . 2013-03-22 19:26 -------- d-----w- c:\program files\TeamSpeak 3 Client
2013-03-22 15:03 . 2013-04-20 09:13 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\Skype
2013-03-22 15:01 . 2013-03-23 17:07 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Skype
2013-03-22 14:55 . 2013-04-13 19:37 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\TS3Client
2013-03-22 14:11 . 2007-02-26 12:30 36864 ----a-r- c:\windows\system32\cmudax3.DLL
2013-03-22 14:11 . 2009-12-01 03:11 1872192 ----a-r- c:\windows\system32\drivers\cmudax3.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-23 19:37 . 2012-08-19 19:52 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-23 19:37 . 2012-08-19 19:52 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-13 14:24 . 2013-01-12 08:45 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-13 14:24 . 2013-01-12 08:45 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyœlne, prawid?owe wpisy nie s? pokazane
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
" {fcbf663e-8530-46f8-a880-ac5abe9d2b23} " = " c:\program files\mobilewitch\tbmobi.dll " [2010-06-13 2734688]
.
[HKEY_CLASSES_ROOT\clsid\{fcbf663e-8530-46f8-a880-ac5abe9d2b23}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
" {fcbf663e-8530-46f8-a880-ac5abe9d2b23} " = " c:\program files\mobilewitch\tbmobi.dll " [2010-06-13 2734688]
.
[HKEY_CLASSES_ROOT\clsid\{fcbf663e-8530-46f8-a880-ac5abe9d2b23}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
" uTorrent " = " c:\program files\uTorrent\uTorrent.exe " [2012-08-13 1022352]
" PC Suite Tray " = " c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe " [2012-06-26 1516632]
" Skype " = " c:\program files\Skype\Phone\Skype.exe " [2011-07-29 17361032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
" avast! " = " c:\progra~1\ALWILS~1\Avast4\ashDisp.exe " [2008-07-19 78008]
" Adobe Reader Speed Launcher " = " c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe " [2010-11-15 35736]
" Adobe ARM " = " c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe " [2012-12-03 946352]
" SoundMan " = " SOUNDMAN.EXE " [2004-01-08 65536]
" NvCplDaemon " = " c:\windows\system32\NvCpl.dll " [2005-12-10 7311360]
" nwiz " = " nwiz.exe " [2005-12-10 1519616]
" NvMediaCenter " = " c:\windows\system32\NvMcTray.dll " [2005-12-10 86016]
" GrooveMonitor " = " c:\program files\Microsoft Office\Office12\GrooveMonitor.exe " [2006-10-26 31016]
" EPSON Stylus C45 Series " = " c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE " [2004-01-14 99840]
" SunJavaUpdateSched " = " c:\program files\Common Files\Java\Java Update\jusched.exe " [2012-07-03 252848]
" V0700Mon.exe " = " c:\windows\V0700Mon.exe " [2011-08-22 28672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
" CTFMON.EXE " = " c:\windows\system32\CTFMON.EXE " [2004-08-04 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
" VF0700Inst " = " c:\windows\system32\V0700Pin.dll " [2011-08-22 45056]
.
c:\documents and settings\DOM\Menu Start\Programy\Autostart\
Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@= " Driver "
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
" %windir%\\system32\\sessmgr.exe " =
" c:\\Program Files\\uTorrent\\uTorrent.exe " =
" c:\\Program Files\\Gadu-Gadu 10\\gg.exe " =
" d:\\Age of empires II\\empires2.exe " =
" c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE " =
" c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE " =
" c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE " =
" c:\\WINDOWS\\system32\\javaw.exe " =
" c:\\Program Files\\BitComet\\BitComet.exe " =
" d:\\Age of empires II\\age2_x1.exe " =
" c:\\Program Files\\Opera\\opera.exe " =
" c:\\WINDOWS\\system32\\java.exe " =
" c:\\Program Files\\Skype\\Phone\\Skype.exe " =
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
" 21939:TCP " = 21939:TCP:BitComet 21939 TCP
" 21939:UDP " = 21939:UDP:BitComet 21939 UDP
.
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2012-08-02 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-08-02 20560]
R3 ip100xp;ASUS NX1001 Network Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [2012-08-02 26752]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2010-07-01 34896]
R3 V0700Afx;Creative Camera VF0700 Audio Effects Driver;c:\windows\system32\drivers\V0700Afx.sys [2013-04-06 302720]
R3 V0700Vid;Creative Live! Cam Chat HD Driver;c:\windows\system32\drivers\V0700Vid.sys [2013-04-06 322528]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys -- & gt; c:\windows\system32\drivers\SBREdrv.sys [?]
S2 MBAMScheduler;MBAMScheduler; " c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe " -- & gt; c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [?]
S2 MBAMService;MBAMService; " c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe " -- & gt; c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [?]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys -- & gt; c:\windows\system32\DRIVERS\clwvd.sys [?]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys -- & gt; c:\windows\system32\drivers\mbam.sys [?]
.
Zawartoœae folderu 'Zaplanowane zadania'
.
2013-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-12 14:25]
.
.
------- Skan uzupe?niaj?cy -------
.
uStart Page = hxxp://www.google.pl/
mStart Page = hxxp://websearch.mocaflix.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: & P & obierz & za pomoc? BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: E & ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pobierz wszystko za pomoc? BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
TCP: Interfaces\{E9A88828-7ED1-4239-BC37-867479F42840}: NameServer = 217.172.224.160 89.231.1.206
.
- - - - USUNI?TO PUSTE WPISY - - - -
.
URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
HKCU-Run-Real Hide IP - c:\program files\RealHideIP\RealHideIP.exe
HKCU-Run-Loympe - c:\documents and settings\DOM\Dane aplikacji\Tualer\hivo.exe
HKLM-Run-YouCam Service - c:\program files\CyberLink\YouCam\YouCamService.exe
AddRemove-Mafia_is1 - c:\program files\Kolekcja Klasyki\Mafia\unins000.exe
AddRemove-Malwarebytes' Anti-Malware_is1 - c:\program files\Malwarebytes' Anti-Malware\unins000.exe
AddRemove-MTA: Race for San Andreas - d:\program files\MTA San Andreas\Uninstall.exe
AddRemove-{9CDBC303-3EED-40b0-8E41-A7C65AA96C26} - d:\program files\EA GAMES\The Sims 2 Szyk i elegancja - Akcesoria\EAUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-20 10:53
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
.
skanowanie ukrytych procesów ...
.
skanowanie ukrytych wpisów autostartu ...
.
skanowanie ukrytych plików ...
.
skanowanie pomyœlnie uko?czone
ukryte pliki: 0
.
**************************************************************************
.
Czas uko?czenia: 2013-04-20 10:56:56
ComboFix-quarantined-files.txt 2013-04-20 09:56
.
Przed: 4 900 352 000 bajtów wolnych
Po: 5 694 197 760 bajtów wolnych
.
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT= " Microsoft Windows Recovery Console " /cmdcons
UnsupportedDebug= " do not select this " /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= " Microsoft Windows XP Professional " /noexecute=optin /fastdetect
.
- - End Of File - - 91F9F9842B2CB4DA8C27FF13CE05B926


Pobierz plik - link do postu