02 Sty 2010, 15:57
02 Sty 2010, 17:27
:OTL
PRC - [2007-06-13 14:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
MOD - [2010-01-02 13:31:04 | 00,075,928 | RHS- | M] () -- C:\WINDOWS\system32\nmdfgds0.dll
O4 - HKCU..\Run: [fsm] File not found
O32 - AutoRun File - [2010-01-02 14:18:38 | 00,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-02 14:18:38 | 00,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-02 14:18:38 | 00,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-02 14:18:40 | 00,000,059 | RHS- | M] () - H:\autorun.inf -- [ FAT ]
:Files
C:\WINDOWS\system32\nmdfgds0.dll
C:\WINDOWS\System32\nmdfgds1.dll
C:\WINDOWS\System32\olhrwef.exe
C:\yudald.bat
D:\yudald.bat
E:\yudald.bat
H:\yudald.bat
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"NeroFilterCheck"=-
"nwiz"=-
"RemoteControl"=-
"RTHDCPL"=-
"SkyTel"=-
"SunJavaUpdateSched"=-
"WheelMouse"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[reboot]
02 Sty 2010, 19:14
02 Sty 2010, 19:36
:OTL
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\System32\olhrwef.exe File not found
02 Sty 2010, 20:16