19 Sty 2010, 22:27
19 Sty 2010, 22:34
19 Sty 2010, 22:52
19 Sty 2010, 23:04
:OTL
PRC - [2007-07-13 23:42:04 | 00,974,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
MOD - [2010-01-19 21:05:44 | 00,086,528 | RHS- | M] () -- C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\cvasds1.dll
IE - HKU\S-1-5-21-1292428093-308236825-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://starter.metacafe.com
IE - HKU\S-1-5-21-1292428093-308236825-725345543-500\..\URLSearchHook: {08C06D61-F1F3-4799-86F8-BE1A89362C85} - Reg Error: Key error. File not found
O4 - HKU\S-1-5-21-1292428093-308236825-725345543-500..\Run: [cdoosoft] C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2010-01-19 21:43:16 | 00,000,063 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-19 21:43:16 | 00,000,063 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-19 21:43:16 | 00,000,063 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-01-19 21:43:16 | 00,000,063 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{8a16599d-371e-11dd-b89c-806d6172696f}\Shell\AutoRun\command - "" = E:\9xf8.exe -- [2010-01-18 16:54:53 | 00,115,712 | RHS- | M] ()
O33 - MountPoints2\{8a16599d-371e-11dd-b89c-806d6172696f}\Shell\open\Command - "" = E:\9xf8.exe -- [2010-01-18 16:54:53 | 00,115,712 | RHS- | M] ()
O33 - MountPoints2\{c66f5c5e-cdb9-11dd-a595-0014852f2aec}\Shell\AutoRun\command - "" = G:\f2kmj.exe -- File not found
O33 - MountPoints2\{c66f5c5e-cdb9-11dd-a595-0014852f2aec}\Shell\open\Command - "" = G:\f2kmj.exe -- File not found
:Files
C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\cvasds1.dll
E:\9xf8.exe
C:\9xf8.exe
D:\9xf8.exe
F:\9xf8.exe
C:\f2kmj.exe
D:\f2kmj.exe
E:\f2kmj.exe
F:\f2kmj.exe
C:\9fo3ar0j.exe
D:\9fo3ar0j.exe
E:\9fo3ar0j.exe
F:\9fo3ar0j.exe
C:\mh.exe
D:\mh.exe
E:\mh.exe
F:\mh.exe
C:\kmj.exe
D:\kmj.exe
E:\kmj.exe
F:\kmj.exe
C:\8xcrbho6.exe
D:\8xcrbho6.exe
E:\8xcrbho6.exe
F:\8xcrbho6.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
:Commands
[emptytemp]
[start explorer]
19 Sty 2010, 23:20
19 Sty 2010, 23:22
21 Sty 2010, 18:17
21 Sty 2010, 18:23
21 Sty 2010, 18:27
No action taken.
21 Sty 2010, 18:36
21 Sty 2010, 18:39
21 Sty 2010, 20:08