
Log
http://www.wklej.org/id/241467/
:OTL
PRC - [2008-04-14 18:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Jurecki\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2009-12-20 14:10:16 | 00,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-20 14:10:16 | 00,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-20 14:10:16 | 00,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-20 14:10:16 | 00,000,051 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
:Files
C:\nx.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[purity]
[emptytemp]
[clearrestorepoints]
[start explorer]
[reboot]
C:\*
D:\*
E:\*
F:\*
G:\*
H:\*
%SYSTEMDRIVE%\*.
/md5start
netlogon.dll
ntelogon.dll
eventlog.dll
logevent.dll
atapi.sys
explorer.exe
/md5stop
CREATERESTOREPOINT
a jak nie to normalnego logaC:\*
D:\*
E:\*
F:\*
G:\*
H:\*
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
:Files
D:\k0maw.exe
D:\nx.exe
D:\t8g.exe
D:\yu3.exe
E:\0qw6vege.exe
E:\1a1dndah.exe
E:\2id9.exe
E:\3n8awsyg.exe
E:\6ruaqx.exe
E:\9b9w3.exe
E:\9g86.exe
E:\a2g21.exe
E:\b00ijwpu.exe
E:\cs6phv6d.exe
E:\curqp.exe
E:\eexyv.exe
E:\g12g.exe
E:\gcq6.exe
E:\hjvjte.exe
E:\i9bwjpqc.exe
E:\k0maw.exe
E:\k8jc.exe
E:\l61yyp.exe
E:\lphfa.exe
E:\mbdm.exe
E:\mbvd.exe
E:\mwfubaob.exe
E:\ngp8l.exe
E:\nqdymj.exe
E:\nx.exe
E:\ohd.exe
E:\opdux.exe
E:\pbudsara.exe
E:\q3kku.exe
E:\q93fi6kf.exe
E:\srgo.exe
E:\t8g.exe
E:\uqgvf.exe
E:\v1cbvsmq.exe
E:\vk0w.exe
E:\wfx062.exe
E:\wu1n.exe
E:\xmor.exe
E:\yu3.exe
F:\0qw6vege.exe
F:\1a1dndah.exe
F:\2id9.exe
F:\3n8awsyg.exe
F:\6ruaqx.exe
F:\9b9w3.exe
F:\9g86.exe
F:\a2g21.exe
F:\b00ijwpu.exe
F:\cs6phv6d.exe
F:\curqp.exe
F:\eexyv.exe
F:\g12g.exe
F:\gcq6.exe
F:\hjvjte.exe
F:\i9bwjpqc.exe
F:\k0maw.exe
F:\k8jc.exe
F:\l61yyp.exe
F:\lphfa.exe
F:\mbdm.exe
F:\mbvd.exe
F:\mwfubaob.exe
F:\ngp8l.exe
F:\nqdymj.exe
F:\nx.exe
F:\ohd.exe
F:\opdux.exe
F:\pbudsara.exe
F:\q3kku.exe
F:\q93fi6kf.exe
F:\srgo.exe
F:\t8g.exe
F:\uqgvf.exe
F:\v1cbvsmq.exe
F:\vk0w.exe
F:\wfx062.exe
F:\wu1n.exe
F:\xmor.exe
F:\yu3.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 7 gości