24 Mar 2010, 13:11
24 Mar 2010, 13:23
Files to delete:
c:\WINDOWS\system32\EXPLORER.EXE
c:\docume~1\ja\ustawi~1\temp\herss.exe
c:\WINDOWS\system32\wsctf.exe
c:\ji83j.exe
c:\ggpw.exe
c:\2u923g01.exe
C:\fk.exe
c:\k1d.exe
c:\62.exe
c:\s1.exe
C:\tgt.exe
C:\p3vwxx.exe
C:\9qqigqwf.exe
C:\ws.exe
C:\bveijo.exe
C:\9d6tpg.exe
C:\1hqup.exe
C:\mvmdh.exe
C:\y.exe
C:\0fpdq2dw.exe
C:\c2e.exe
C:\qkm.exe
C:\9fo3ar0j.exe
C:\sywyrl0q.exe
C:\9xf8.exe
C:\mh.exe
C:\kmj.exe
C:\8xcrbho6.exe
C:\31lyx.exe
C:\e9naq.exe
C:\h0.exe
C:\anoataly.exe
C:\3exi.exe
C:\wisf1.exe
24 Mar 2010, 13:42
24 Mar 2010, 16:25
:OTL
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-1177238915-1580818891-839522115-1003..\Run: [cdoosoft] C:\DOCUME~1\Ja\USTAWI~1\Temp\herss.exe File not found
O4 - HKU\S-1-5-21-1177238915-1580818891-839522115-1003..\Run: [wsctf.exe] File not found
O32 - AutoRun File - [2010-03-24 12:30:40 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-24 12:30:40 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
:Files
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\ji83j.exe
D:\ggpw.exe
D:\2u923g01.exe
D:\fk.exe
D:\k1d.exe
D:\62.exe
D:\s1.exe
D:\tgt.exe
D:\p3vwxx.exe
D:\9qqigqwf.exe
D:\ws.exe
D:\bveijo.exe
D:\9d6tpg.exe
D:\1hqup.exe
D:\mvmdh.exe
D:\y.exe
D:\0fpdq2dw.exe
D:\c2e.exe
D:\qkm.exe
D:\9fo3ar0j.exe
D:\sywyrl0q.exe
D:\9xf8.exe
D:\mh.exe
D:\kmj.exe
D:\8xcrbho6.exe
D:\31lyx.exe
D:\e9naq.exe
D:\h0.exe
D:\anoataly.exe
D:\3exi.exe
D:\wisf1.exe
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EXPLORER.EXE"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cpqset"=-
"IMJPMIG8.1"=-
"NeroCheck"=-
"PHIME2002A"=-
"PHIME2002ASync"=-
"SoundMAX"=-
"SoundMAXPnP"=-
"SunJavaUpdateSched"=-
"UpdateManager"=-
"WinampAgent"=-
:Commands
[emptytemp]
24 Mar 2010, 18:06
24 Mar 2010, 19:53