witam... mam problem z pewnym wirusem(9qqigqwf.exe)
jak na razie mam zablokowany dostęp do dysków jak i menadżera zadań
http://www.wklej.eu/index.php?id=a073160470
proszę o pomoc w "usunięciu usterki":)
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:OTL
O4 - HKU\S-1-5-21-606747145-1682526488-839522115-500..\Run: [cdoosoft] C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\herss.exe ()
O33 - MountPoints2\{1f51ecc2-0aa4-11df-be92-001060d006cb}\Shell\AutoRun\command - "" = F:\1hqup.exe -- File not found
O33 - MountPoints2\{1f51ecc2-0aa4-11df-be92-001060d006cb}\Shell\open\Command - "" = F:\1hqup.exe -- File not found
O33 - MountPoints2\{906885fd-e75d-11de-b09a-806d6172696f}\Shell\AutoRun\command - "" = C:\p3vwxx.exe -- [2010-02-13 14:19:32 | 000,000,000 | RHS- | M] ()
O33 - MountPoints2\{906885fd-e75d-11de-b09a-806d6172696f}\Shell\open\Command - "" = C:\p3vwxx.exe -- [2010-02-13 14:19:32 | 000,000,000 | RHS- | M] ()
O33 - MountPoints2\{906885fe-e75d-11de-b09a-806d6172696f}\Shell\AutoRun\command - "" = D:\p3vwxx.exe -- [2010-02-13 14:19:32 | 000,000,000 | RHS- | M] ()
O33 - MountPoints2\{906885fe-e75d-11de-b09a-806d6172696f}\Shell\open\Command - "" = D:\p3vwxx.exe -- [2010-02-13 14:19:32 | 000,000,000 | RHS- | M] ()
O33 - MountPoints2\{eaf8dbf4-ee6c-11de-be67-001060d006cb}\Shell\AutoRun\command - "" = H:\ws.exe -- File not found
O33 - MountPoints2\{eaf8dbf4-ee6c-11de-be67-001060d006cb}\Shell\open\Command - "" = H:\ws.exe -- File not found
:Files
C:\p3vwxx.exe
C:\9qqigqwf.exe
C:\ws.exe
D:\p3vwxx.exe
D:\9qqigqwf.exe
D:\ws.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"HotKeysCmds"=-
"IgfxTray"=-
"Persistence"=-
"RTHDCPL"=-
"SunJavaUpdateSched"=-
"WinampAgent"=-
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.2) Gecko/20100115 Firefox/3.6
:OTL
O32 - AutoRun File - [2010-02-13 14:26:15 | 000,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-13 14:26:15 | 000,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
Zarejestrowani użytkownicy: Bing [Bot]