
Poniżej wklejam skan z OTL:
http://wklej.org/id/303487/
Avast wykrywa mi go w plikach
C:\ji... .exe
i taki sam plik na D:
Bądź też na pendrajwie jak jest podłączony.
:OTL
O3 - HKLM\..\Toolbar: (no name) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - No CLSID value found.
O3 - HKU\S-1-5-21-839522115-362288127-1177238915-1002\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-839522115-362288127-1177238915-1002\..\Toolbar\ShellBrowser: (no name) - {63AB4C54-3310-44c9-85D8-AA92C2263D58} - No CLSID value found.
O3 - HKU\S-1-5-21-839522115-362288127-1177238915-1002\..\Toolbar\ShellBrowser: (no name) - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - No CLSID value found.
O4 - HKU\S-1-5-21-839522115-362288127-1177238915-1002..\Run: [cdoosoft] C:\Documents and Settings\MoorPH\Ustawienia lokalne\Temp\herss.exe ()
O4 - HKU\S-1-5-21-839522115-362288127-1177238915-1002..\Run: [fsm] File not found
O4 - Startup: C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\del.exe ()
O4 - Startup: C:\Documents and Settings\Default User\Menu Start\Programy\Autostart\z.cmd ()
O32 - AutoRun File - [2010-03-24 22:47:02 | 000,000,057 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-23 22:12:30 | 000,000,000 | ---D | M] - D:\AUTO -- [ NTFS ]
O32 - AutoRun File - [2010-03-24 22:47:02 | 000,000,057 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2008-04-23 22:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.) - I:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008-07-04 12:03:32 | 000,000,051 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{2868bce1-be62-11de-861c-0013e895e99d}\Shell - "" = AutoRun
O33 - MountPoints2\{2868bce1-be62-11de-861c-0013e895e99d}\Shell\AutoRun\command - "" = I:\AutoRun.exe -- [2008-04-23 22:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{2be42568-be6b-11de-bc54-806d6172696f}\Shell\AutoRun\command - "" = D:\ji83j.exe -- [2010-03-23 20:28:12 | 000,128,512 | RHS- | M] ()
O33 - MountPoints2\{2be42568-be6b-11de-bc54-806d6172696f}\Shell\open\Command - "" = D:\ji83j.exe -- [2010-03-23 20:28:12 | 000,128,512 | RHS- | M] ()
O33 - MountPoints2\{2be4256a-be6b-11de-bc54-806d6172696f}\Shell\AutoRun\command - "" = C:\ji83j.exe -- [2010-03-23 20:28:12 | 000,128,512 | RHS- | M] ()
O33 - MountPoints2\{2be4256a-be6b-11de-bc54-806d6172696f}\Shell\open\Command - "" = C:\ji83j.exe -- [2010-03-23 20:28:12 | 000,128,512 | RHS- | M] ()
:Files
C:\autorun.inf
D:\ey.exe
C:\ey.exe
G:\ey.exe
D:\autorun.inf
G:\autorun.inf
C:\Documents and Settings\MoorPH\Ustawienia lokalne\Temp\cvasds0.dll
C:\Documents and Settings\MoorPH\Ustawienia lokalne\Temp\cvasds1.dll
C:\ji83j.exe
D:\ji83j.exe
G:\ji83j.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[purity]
[emptytemp]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 11 gości