
Mam problem z trojanem win32:patched-hn i Win32:Rootkit-gen [Rtk] , byłbym bardzo wdzięczny za pomoc w pozbyciu się teego paskudztwa.
Z góry dzięki za pomoc
Oto logi z OTLa:
http://wklej.org/id/228156/
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2009-12-05 11:32:29 | 00,000,055 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-05 11:32:29 | 00,000,055 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{4fee10ac-ddbf-11de-a5c9-00241d8fea25}\Shell\AutoRun\command - "" = F:\qcod.exe -- File not found
O33 - MountPoints2\{4fee10ac-ddbf-11de-a5c9-00241d8fea25}\Shell\open\Command - "" = F:\qcod.exe -- File not found
O33 - MountPoints2\{b8556064-d96c-11dd-aed2-806d6172696f}\Shell\AutoRun\command - "" = mbvd.exe
O33 - MountPoints2\{b8556064-d96c-11dd-aed2-806d6172696f}\Shell\open\Command - "" = mbvd.exe
O33 - MountPoints2\{b8556066-d96c-11dd-aed2-806d6172696f}\Shell\AutoRun\command - "" = mbvd.exe
O33 - MountPoints2\{b8556066-d96c-11dd-aed2-806d6172696f}\Shell\open\Command - "" = mbvd.exe
O33 - MountPoints2\{f9e7e666-e006-11de-a5cf-00241d8fea25}\Shell\AutoRun\command - "" = F:\mbvd.exe -- File not found
O33 - MountPoints2\{f9e7e666-e006-11de-a5cf-00241d8fea25}\Shell\open\Command - "" = F:\mbvd.exe -- File not found
:Files
C:\Program Files\Ask.com
C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\herss.exe
C:\autorun.inf
D:\autorun.inf
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db1b3e60-05ac-11de-a5d3-00001cd72a97}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[start explorer]
[Reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 8 gości