
http://wklej.org/id/224807/
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\bEEExx\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2009-12-04 16:59:41 | 00,000,055 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-04 16:59:41 | 00,000,055 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-04 16:59:41 | 00,000,055 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{4e344466-dc31-11de-99d0-00064f44210f}\Shell\AutoRun\command - "" = G:\lhh3v.exe -- File not found
O33 - MountPoints2\{4e344466-dc31-11de-99d0-00064f44210f}\Shell\open\Command - "" = G:\lhh3v.exe -- File not found
O33 - MountPoints2\{70327836-d230-11de-a674-806d6172696f}\Shell\AutoRun\command - "" = C:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\{70327836-d230-11de-a674-806d6172696f}\Shell\open\Command - "" = C:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\{70327837-d230-11de-a674-806d6172696f}\Shell\AutoRun\command - "" = D:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\{70327837-d230-11de-a674-806d6172696f}\Shell\open\Command - "" = D:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\{70327838-d230-11de-a674-806d6172696f}\Shell\AutoRun\command - "" = E:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\{70327838-d230-11de-a674-806d6172696f}\Shell\open\Command - "" = E:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\{762f63dc-d22b-11de-99ad-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{762f63dc-d22b-11de-99ad-806d6172696f}\Shell\AutoRun\command - "" = F:\Nvsetup.exe -- File not found
O33 - MountPoints2\C\Shell\AutoRun\command - "" = C:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\C\Shell\open\Command - "" = C:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\D\Shell\open\Command - "" = D:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
O33 - MountPoints2\E\Shell\open\Command - "" = E:\k8jc.exe -- [2009-12-04 15:23:03 | 00,113,233 | RHS- | M] ()
:Files
C:\Documents and Settings\bEEExx\Ustawienia lokalne\Temp\cvasds0.dll
C:\k8jc.exe
C:\mbvd.exe
C:\mbdm.exe
c:\q3kku.exe
C:\cs6phv6d.exe
C:\wfx062.exe
C:\wu1n.exe
C:\i9bwjpqc.exe
C:\q93fi6kf.exe
d:\k8jc.exe
d:\mbvd.exe
d:\mbdm.exe
d:\q3kku.exe
d:\cs6phv6d.exe
d:\wfx062.exe
d:\wu1n.exe
d:\i9bwjpqc.exe
d:\q93fi6kf.exe
e:\k8jc.exe
e:\mbvd.exe
e:\mbdm.exe
e:\q3kku.exe
e:\cs6phv6d.exe
e:\wfx062.exe
e:\wu1n.exe
e:\i9bwjpqc.exe
e:\q93fi6kf.exe
C:\autorun.inf
d:\autorun.inf
e:\autorun.inf
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db1b3e60-05ac-11de-a5d3-00001cd72a97}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[start explorer]
[Reboot]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 5 gości