Witam, komuter wydaje sie obciazony, kilka razy sam sie zrestartowal. W logu OTL zauwazylam kilka podejrzanych linii, ale wolalabym zeby ktos spojrzal na to fachowym okiem:)
OTL:
http://wklej.org/id/253803/
HjT:
http://wklej.org/id/253840/
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
UA: Mozilla/5.0 (Windows; U; Windows NT 6.0; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 (.NET CLR 3.5.30729)
:OTL
PRC - [2007-06-13 14:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
MOD - [2010-01-02 13:31:04 | 00,075,928 | RHS- | M] () -- C:\WINDOWS\system32\nmdfgds0.dll
O4 - HKCU..\Run: [fsm] File not found
O32 - AutoRun File - [2010-01-02 14:18:38 | 00,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-02 14:18:38 | 00,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-02 14:18:38 | 00,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-02 14:18:40 | 00,000,059 | RHS- | M] () - H:\autorun.inf -- [ FAT ]
:Files
C:\WINDOWS\system32\nmdfgds0.dll
C:\WINDOWS\System32\nmdfgds1.dll
C:\WINDOWS\System32\olhrwef.exe
C:\yudald.bat
D:\yudald.bat
E:\yudald.bat
H:\yudald.bat
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"NeroFilterCheck"=-
"nwiz"=-
"RemoteControl"=-
"RTHDCPL"=-
"SkyTel"=-
"SunJavaUpdateSched"=-
"WheelMouse"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[reboot]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
:OTL
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\System32\olhrwef.exe File not found
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
Zarejestrowani użytkownicy: Bing [Bot]