21 Mar 2010, 23:21
22 Mar 2010, 13:17
:OTL
O32 - AutoRun File - [2010-03-19 00:48:01 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-19 00:42:12 | 000,000,057 | RHS- | M] () - F:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2010-03-21 22:02:37 | 000,000,011 | ---- | M] () - G:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{8004ba36-31fb-11df-8175-806d6172696f}\Shell\AutoRun\command - "" = ji83j.exe
O33 - MountPoints2\{8004ba36-31fb-11df-8175-806d6172696f}\Shell\open\Command - "" = ji83j.exe
O33 - MountPoints2\{bc2985a0-3204-11df-896e-00158307c67b}\Shell\AutoRun\command - "" = G:\ji83j.exe -- File not found
O33 - MountPoints2\{bc2985a0-3204-11df-896e-00158307c67b}\Shell\open\Command - "" = G:\ji83j.exe -- File not found
:Files
C:\D & S\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
C:\D & S\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"ASUS Live Update"=-
"Copy Handler"=-
"SkyTel"=-
"StartCCC"=-
:Commands
[emptytemp]
22 Mar 2010, 21:01
22 Mar 2010, 21:08
22 Mar 2010, 22:18
22 Mar 2010, 23:02
23 Mar 2010, 20:06
23 Mar 2010, 21:11
23 Mar 2010, 21:13
23 Mar 2010, 21:31
23 Mar 2010, 21:45