10 Lut 2010, 18:07
10 Lut 2010, 18:16
10 Lut 2010, 22:30
w oknie Custom Scans/Fixes wklej::OTL
MOD - [2010-02-10 16:48:12 | 000,092,160 | RHS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Temp\cvasds0.dll
SRV - File not found [Unknown | Stopped] -- -- (idsvc)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60327
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - G:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - H:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - I:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - J:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - K:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-09 15:57:28 | 000,000,053 | RHS- | M] () - O:\autorun.inf -- [ NTFS ]
:Files
C:\c2e.exe
D:\c2e.exe
E:\c2e.exe
F:\c2e.exe
G:\c2e.exe
H:\c2e.exe
I:\c2e.exe
J:\c2e.exe
K:\c2e.exe
O:\c2e.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=-
"hpqSRMon"=-
"NeroFilterCheck"=-
"StartCCC"=-
"SunJavaUpdateSched"=-
"WinampAgent"=-
:Commands
[emptytemp]
10 Lut 2010, 23:54
11 Lut 2010, 16:38
Instrukcja
11 Lut 2010, 18:25
11 Lut 2010, 19:05
25 Mar 2010, 21:20
25 Mar 2010, 21:26
w oknie Custom Scans/Fixes wklej::OTL
O4 - HKU\S-1-5-21-776561741-117609710-725345543-1003..\Run: [] File not found
O4 - HKU\S-1-5-21-776561741-117609710-725345543-1003..\Run: [cdoosoft] C:\DOCUME~1\emil\USTAWI~1\Temp\herss.exe File not found
O32 - AutoRun File - [2010-03-23 19:47:07 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-23 19:47:07 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-21 14:20:53 | 000,000,057 | RHS- | M] () - H:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{e445e25d-eec1-11dc-b2a9-806d6172696f}\Shell\AutoRun\command - "" = pcxis.exe
O33 - MountPoints2\{e445e25d-eec1-11dc-b2a9-806d6172696f}\Shell\open\Command - "" = pcxis.exe
O33 - MountPoints2\{e445e260-eec1-11dc-b2a9-806d6172696f}\Shell\AutoRun\command - "" = pcxis.exe
O33 - MountPoints2\{e445e260-eec1-11dc-b2a9-806d6172696f}\Shell\open\Command - "" = pcxis.exe
O33 - MountPoints2\{f710c304-2ac0-11df-81a9-0015af6ee3ff}\Shell\AutoRun\command - "" = pcxis.exe
O33 - MountPoints2\{f710c304-2ac0-11df-81a9-0015af6ee3ff}\Shell\open\Command - "" = pcxis.exe
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
C:\WINDOWS\tasks\Norton Security Scan for emil.job
C:\WINDOWS\tasks\WebReg Deskjet F4100 series.job
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"NeroFilterCheck"=-
"TkBellExe"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
"Orb"=-
"updateMgr"=-
"IPLA!"=-
:Commands
[emptytemp]
01 Kwi 2010, 21:36
01 Kwi 2010, 21:43
07 Kwi 2010, 21:17
07 Kwi 2010, 21:19