19 Sty 2010, 14:45
19 Sty 2010, 18:57
:OTL
PRC - [2004-08-03 23:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
IE - HKU\S-1-5-21-1606980848-1993962763-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
O4 - HKU\S-1-5-21-1606980848-1993962763-682003330-1003..\Run: [areslite] C:\Program Files\Ares Lite Edition\AresLite.exe File not found
O4 - HKU\S-1-5-21-1606980848-1993962763-682003330-1003..\Run: [cdoosoft] C:\DOCUME~1\GUMI~1\USTAWI~1\Temp\herss.exe File not found
O4 - HKLM..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe ()
O32 - AutoRun File - [2010-01-18 14:33:48 | 00,000,053 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-18 14:33:48 | 00,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{f2902c8a-073f-11de-801b-806d6172696f}\Shell\AutoRun\command - "" = kmj.exe
O33 - MountPoints2\{f2902c8a-073f-11de-801b-806d6172696f}\Shell\open\Command - "" = kmj.exe
O33 - MountPoints2\{f2902c8b-073f-11de-801b-806d6172696f}\Shell\AutoRun\command - "" = kmj.exe
O33 - MountPoints2\{f2902c8b-073f-11de-801b-806d6172696f}\Shell\open\Command - "" = kmj.exe
:Files
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
C:\kmj.exe
D:\kmj.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Cmaudio"=-
"NeroFilterCheck"=-
"QuickTime Task"=-
"SunJavaUpdateSched"=-
:Commands
[emptytemp]
[start explorer]
19 Sty 2010, 21:18
19 Sty 2010, 21:44
20 Sty 2010, 19:02
20 Sty 2010, 19:05