
:OTL
O4 - HKU\S-1-5-21-682003330-1563985344-839522115-1004..\Run: [dso32] C:\Documents and Settings\Koczuba\Ustawienia lokalne\Temp\dsoqq.exe ()
O32 - AutoRun File - [2010-06-07 14:45:17 | 000,000,063 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-06-07 14:45:17 | 000,000,063 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{2389ff36-6fd0-11df-b030-00027282a3b8}\Shell\AutoRun\command - "" = K:\cgaqyi.exe -- File not found
O33 - MountPoints2\{2389ff36-6fd0-11df-b030-00027282a3b8}\Shell\open\Command - "" = K:\cgaqyi.exe -- File not found
:Files
C:\Documents and Settings\Koczuba\Ustawienia lokalne\Temp\dsoqq0.dll
C:\cgaqyi.exe
C:\autorun.inf
d:\autorun.inf
C:\yqq8eqil.exe
C:\awb3ryk.exe
d:\cgaqyi.exe
d:\yqq8eqil.exe
d:\awb3ryk.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 8 gości