
Od kilku dni mam problem z takim czymś Win32:Patched-HN wykrywany jest przez program avast po każdym ponownym uruchomieniu komputera i avast nie może go usunąć. Proszę o pomoc.
logi z OTL
http://wklej.org/id/221540/
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4C4E7CDB-5BFC-4D74-83E2-8AE659B7EDA2} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - No CLSID value found.
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\admin\Ustawienia lokalne\temp\herss.exe ()
O32 - AutoRun File - [2009-12-01 06:24:56 | 00,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-01 06:24:56 | 00,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [1998-12-13 08:43:32 | 00,000,040 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{2b385ebd-1561-11de-aa58-0018f3c0a2df}\Shell - "" = AutoRun
O33 - MountPoints2\{da21daf2-bfa2-11dc-a5ab-0018f3c0a2df}\Shell\AutoRun\command - "" = H:\l61yyp.exe -- File not found
O33 - MountPoints2\{da21daf2-bfa2-11dc-a5ab-0018f3c0a2df}\Shell\open\Command - "" = H:\l61yyp.exe -- File not found
:Files
C:\WINDOWS\System32\TDSSlxwp.dll
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db1b3e60-05ac-11de-a5d3-00001cd72a97}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[start explorer]
[Reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 10 gości