OTL: http://wklej.org/id/337690/
extras: http://wklej.org/id/337643/
plik ji83j.exe ten jest na dysku C, D i na pendrivie
był również plik eer6ril9 ale usunałęm go ręcznie i się nie pojawił ponownie (był na C i D)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
:OTL
MOD - [2010-05-21 03:14:00 | 000,080,384 | RHS- | M] () -- C:\Documents and Settings\Łukasz\Ustawienia lokalne\Temp\cvasds0.dll
O4 - HKU\S-1-5-21-220523388-1788223648-1801674531-1003..\Run: [cdoosoft] C:\Documents and Settings\Łukasz\Ustawienia lokalne\Temp\herss.exe ()
O4 - HKU\S-1-5-21-220523388-1788223648-1801674531-1003..\Run: [dso32] C:\DOCUME~1\UKASZ~1\USTAWI~1\Temp\dsoqq.exe File not found
32 - AutoRun File - [2010-05-21 03:36:08 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-05-21 03:36:08 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-05-21 03:36:10 | 000,000,057 | RHS- | M] () - F:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{77dadad2-346f-11df-8fa8-485b3903e220}\Shell\AutoRun\command - "" = F:\ji83j.exe -- [2010-03-21 09:52:12 | 000,121,344 | RHS- | M] ()
O33 - MountPoints2\{77dadad2-346f-11df-8fa8-485b3903e220}\Shell\open\Command - "" = F:\ji83j.exe -- [2010-03-21 09:52:12 | 000,121,344 | RHS- | M] ()
O33 - MountPoints2\{f254ba52-3481-11df-a2d5-806d6172696f}\Shell\AutoRun\command - "" = C:\ji83j.exe -- [2010-03-21 09:52:12 | 000,121,344 | RHS- | M] ()
O33 - MountPoints2\{f254ba52-3481-11df-a2d5-806d6172696f}\Shell\open\Command - "" = C:\ji83j.exe -- [2010-03-21 09:52:12 | 000,121,344 | RHS- | M] ()
O33 - MountPoints2\{f254ba53-3481-11df-a2d5-806d6172696f}\Shell\AutoRun\command - "" = D:\ji83j.exe -- [2010-03-21 09:52:12 | 000,121,344 | RHS- | M] ()
O33 - MountPoints2\{f254ba53-3481-11df-a2d5-806d6172696f}\Shell\open\Command - "" = D:\ji83j.exe -- [2010-03-21 09:52:12 | 000,121,344 | RHS- | M] ()
:Files
C:\Documents and Settings\Łukasz\Ustawienia lokalne\Temp\cvasds0.dll
C:\ji83j.exe
D:\ji83j.exe
F:\ji83j.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"nwiz"=-
:Commands
[emptytemp]
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników