
http://www.wklej.org/id/328039/Gmer
http://www.wklej.org/id/328052/OTL
z gory dzieki za pomoc
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
http://www.sendspace.com/file/z484xt
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.yahoo.com/search?p=
O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll ()
O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll ()
O20 - Winlogon\Notify\youja_: DllName - youja_.dll - C:\WINDOWS\System32\youja_.dll ()
O20 - HKLM Winlogon: UIHost - (logonui.exe) - File not found
O32 - AutoRun File - [2008-04-24 06:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.) - G:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-11-07 08:41:52 | 000,000,047 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{0b11859f-919f-11de-8b87-0016cf517907}\Shell\PRM\command - "" = Thumbs.exe -start
O33 - MountPoints2\{4c1878bd-3dd4-11df-bcbe-0016cf517907}\Shell - "" = AutoRun
O33 - MountPoints2\{4c1878bd-3dd4-11df-bcbe-0016cf517907}\Shell\AutoRun\command - "" = G:\WD SmartWare.exe -- File not found
O33 - MountPoints2\{6dee659f-f074-11de-bc4c-0016d41c6b5a}\Shell - "" = AutoRun
O33 - MountPoints2\{6dee659f-f074-11de-bc4c-0016d41c6b5a}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2008-04-24 06:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{88e2f4e2-f32f-11de-bc4d-0016d41c6b5a}\Shell - "" = AutoRun
O33 - MountPoints2\{88e2f4e2-f32f-11de-bc4d-0016d41c6b5a}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2008-04-24 06:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{aeda0dac-eec5-11de-bc49-0016d41c6b5a}\Shell\AutoRun\command - "" = H:\PRVA\\\\\STRANA.exe -- File not found
O33 - MountPoints2\{aeda0dac-eec5-11de-bc49-0016d41c6b5a}\Shell\explore\command - "" = H:\PRVA\\\\\\STRANA.exe -- File not found
O33 - MountPoints2\{aeda0dac-eec5-11de-bc49-0016d41c6b5a}\Shell\open\command - "" = H:\PRVA\\\\\\STRANA.exe -- File not found
O33 - MountPoints2\{eb01cb8b-f2ef-11de-bc4f-0016cf517907}\Shell - "" = AutoRun
O33 - MountPoints2\{eb01cb8b-f2ef-11de-bc4f-0016cf517907}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2008-04-24 06:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AutoRun.exe -- File not found
@Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
FF - prefs.js..browser.search.defaultenginename: "BearShare Web Search"
FF - prefs.js..browser.search.order.1: "BearShare Web Search"
FF - prefs.js..keyword.URL: "http://search.bearshare.com/webResults.html?src=ffb&q="
:Files
C:\WINDOWS\System32\youja_.dll
C:\lqyedbfe.exe
C:\jwxfhba.exe
C:\vsosmix.exe
C:\gyid.exe
C:\iymfsrlv.exe
C:\bcgft.exe
C:\-119424514
C:\Program Files\BearShareTb
C:\WINDOWS\System32\DRIVERS\atapi.sys|C:\atapi.sys /replace
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
[resethosts]
[emptyflash]
[clearallrestorepoints]
Fcopy::
c:\atapi.sys| c:\windows\system32\dllcache\atapi.sys
c:\atapi.sys | c:\windows\system32\drivers\atapi.sys
File::
C:\Documents and Settings\Admin\My Documents\Downloads\atapi.sys
FCopy::
c:\atapi.sys | c:\windows\system32\dllcache\atapi.sys
c:\atapi.sys | c:\windows\system32\drivers\atapi.sys
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 28 gości