24 Mar 2010, 22:13
24 Mar 2010, 22:28
:OTL
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
MOD - [2010-03-24 20:09:49 | 000,084,992 | RHS- | M] () -- C:\Documents and Settings\acer\Ustawienia lokalne\Temp\cvasds0.dll
O4 - HKLM..\Run: [M3000Mnt] File not found
O4 - HKU\S-1-5-21-3025990876-284587905-4097411637-1005..\Run: [cdoosoft] C:\Documents and Settings\acer\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2010-03-24 20:22:30 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-24 20:22:30 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
:Files
C:\Documents and Settings\acer\Ustawienia lokalne\Temp\cvasds0.dll
C:\Documents and Settings\acer\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan.lnk
C:\ji83j.exe
D:\ji83j.exe
C:\WINDOWS\Tasks\User_Feed_Synchronization-{FBD045EA-00BB-41D9-977F-9C79B39866AE}.job
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"AzMixerSel"=-
"IMJPMIG8.1"=-
"MSPY2002"=-
"PHIME2002A"=-
"PHIME2002ASync"=-
:Commands
[emptytemp]
24 Mar 2010, 23:32
25 Mar 2010, 17:00