26 Lut 2010, 22:14
26 Lut 2010, 22:22
Files to delete:
C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\Oml.exe
C:\WINDOWS\msa.exe
C:\WINDOWS\system32\sshnas21.dll
C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\ihaupd32.exe
C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\sysfgs32.exe
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
C:\WINDOWS\System32\drivers\TVICHW32r.sys
C:\WINDOWS\System32\drivers\TVICHW32q.sys
C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Documents and Settings\Administrator\Dane aplikacji\avdrn.dat
C:\Documents and Settings\Administrator\Dane aplikacji\wiaservg.log
Drivers to delete:
SSHNAS
TVICHW32r
TVICHW32q
Folders to delete:
C:\RECYCLER
E:\RECYCLER
F:\RECYCLER
26 Lut 2010, 22:47
26 Lut 2010, 23:01
:OTL
O4 - HKCU..\Run: [amva] C:\WINDOWS\System32\amvo.exe File not found
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\System32\olhrwef.exe File not found
O4 - HKCU..\Run: [TOY5KNQ8OC] C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\Oml.exe File not found
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-2251296513-6939254038-060758433-6097\nissan.exe) - C:\RECYCLER\S-1-5-21-2251296513-6939254038-060758433-6097\nissan.exe File not found
O20 - HKCU Winlogon: Shell - (C:\RECYCLER\S-1-5-21-2251296513-6939254038-060758433-6097\nissan.exe) - C:\RECYCLER\S-1-5-21-2251296513-6939254038-060758433-6097\nissan.exe File not found
O20 - HKCU Winlogon: Shell - (C:\RECYCLER\S-1-5-21-9218645847-9570870124-061323397-1233\wnzip32.exe) - C:\RECYCLER\S-1-5-21-9218645847-9570870124-061323397-1233\wnzip32.exe File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
:Files
C:\Avenger
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"NeroFilterCheck"=-
"nwiz"=-
"QuickTime Task"=-
"RemoteControl"=-
"RTHDCPL"=-
"SecurDisc"=-
"SunJavaUpdateSched"=-
:Commands
[emptytemp]
[reboot]
26 Lut 2010, 23:31
26 Lut 2010, 23:39
27 Lut 2010, 00:14
27 Lut 2010, 09:34