06 Maj 2010, 23:00
06 Maj 2010, 23:15
:OTL
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: userini = C:\WINDOWS\explorer.exe:userini.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\Documents and Settings\Juzer\Dane aplikacji\yxdqln.exe) - C:\Documents and Settings\Juzer\Dane aplikacji\yxdqln.exe (rlogvijd)
O20 - HKU\S-1-5-21-1292428093-1390067357-682003330-1003 Winlogon: Shell - (C:\Documents and Settings\Juzer\Dane aplikacji\yxdqln.exe) - C:\Documents and Settings\Juzer\Dane aplikacji\yxdqln.exe (rlogvijd)
O20 - HKU\S-1-5-21-1292428093-1390067357-682003330-1003 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-8176216235-4320551482-726769815-3940\nissan.exe) - C:\RECYCLER\S-1-5-21-8176216235-4320551482-726769815-3940\nissan.exe ()
O20 - HKU\S-1-5-21-1292428093-1390067357-682003330-1003 Winlogon: Shell - (C:\Documents and Settings\Juzer\Dane aplikacji\irvlna.exe) - C:\Documents and Settings\Juzer\Dane aplikacji\irvlna.exe ()
O33 - MountPoints2\{7c3e37be-2463-11df-8660-000b6a0e9de0}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs
O33 - MountPoints2\{7c3e37be-2463-11df-8660-000b6a0e9de0}\Shell\open\Command - "" = WScript.exe .\`.vbs
O33 - MountPoints2\{b937da0f-1b22-11df-8647-000b6a0e9de0}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs
O33 - MountPoints2\{b937da0f-1b22-11df-8647-000b6a0e9de0}\Shell\open\Command - "" = WScript.exe .\`.vbs
O33 - MountPoints2\{bbc46a49-0809-11df-861c-000b6a0e9de0}\Shell - "" = AutoRun
O33 - MountPoints2\{c2b3749c-0132-11df-860a-000b6a0e9de0}\Shell\AutoRun\command - "" = filesystem/pagefile.exe
O33 - MountPoints2\{c2b3749c-0132-11df-860a-000b6a0e9de0}\Shell\eXpLorE\cOMMand - "" = filesystem/pagefile.exe
O33 - MountPoints2\{c2b3749c-0132-11df-860a-000b6a0e9de0}\Shell\oPen\CoMMAnd - "" = filesystem/pagefile.exe
O33 - MountPoints2\{c2b3749d-0132-11df-860a-000b6a0e9de0}\Shell\AutoRun\command - "" = filesystem/pagefile.exe
O33 - MountPoints2\{c2b3749d-0132-11df-860a-000b6a0e9de0}\Shell\eXpLorE\cOMMand - "" = filesystem/pagefile.exe
O33 - MountPoints2\{c2b3749d-0132-11df-860a-000b6a0e9de0}\Shell\oPen\CoMMAnd - "" = filesystem/pagefile.exe
O33 - MountPoints2\{e718cff3-ec89-11de-85db-000b6a0e9de0}\Shell - "" = AutoRun
:Files
C:\Documents and Settings\Juzer\Dane aplikacji\yxdqln.exe
C:\RECYCLER
D:\RECYCLER
C:\Documents and Settings\Juzer\Dane aplikacji\irvlna.exe
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\Documents and Settings\Juzer\Dane aplikacji\wiaservg.log
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
"userini"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"userini"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"TaskMan"=-
[HKEY_USERS\S-1-5-21-1292428093-1390067357-682003330-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
:Commands
[emptytemp]
06 Maj 2010, 23:36
06 Maj 2010, 23:46
07 Maj 2010, 00:17
07 Maj 2010, 08:53
:Processes
killallprocesses
:OTL
O7 - HKU\S-1-5-21-1292428093-1390067357-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: userini = C:\WINDOWS\explorer.exe:userini.exe (Microsoft Corporation)
07 Maj 2010, 20:51
07 Maj 2010, 21:16
07 Maj 2010, 23:29
08 Maj 2010, 19:11