UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
UA: Opera/9.80 (Windows NT 6.0; U; pl) Presto/2.2.15 Version/10.10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
UA: Opera/9.80 (Windows NT 6.0; U; pl) Presto/2.2.15 Version/10.10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
:OTL
PRC - [2009-07-17 00:03:00 | 01,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
O4 - HKU\S-1-5-21-1708537768-113007714-1060284298-1003..\Run: [cdoosoft] D:\Documents and Settings\Paulina\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2008-03-20 02:42:34 | 00,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2008-03-20 02:42:34 | 00,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
:Files
D:\Documents and Settings\Paulina\Ustawienia lokalne\Temp\herss.exe
D:\nx.exe
C:\nx.exe
D:\yu3.exe
C:\yu3.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[start explorer]
[Reboot]
UA: Opera/9.80 (Windows NT 6.0; U; pl) Presto/2.2.15 Version/10.10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
Files to delete:
D:\Documents and Settings\Paulina\Ustawienia lokalne\Temp\herss.exe
C:\autorun.inf
D:\autorun.inf
D:\nx.exe
C:\nx.exe
D:\yu3.exe
C:\yu3.exe
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
UA: Opera/9.80 (Windows NT 6.0; U; pl) Presto/2.2.15 Version/10.10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
:OTL
O4 - HKU\S-1-5-21-1708537768-113007714-1060284298-1003..\Run: [cdoosoft] D:\DOCUME~1\Paulina\USTAWI~1\Temp\herss.exe File not found
O32 - AutoRun File - [2008-03-20 17:28:40 | 00,000,051 | RHS- | M] () - F:\autorun.inf -- [ FAT32 ]
:Files
F:\nx.exe
F:\yu3.exe
UA: Opera/9.80 (Windows NT 6.0; U; pl) Presto/2.2.15 Version/10.10
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6
No action taken.
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Zarejestrowani użytkownicy: Bing [Bot]