
- Kod: Zaznacz wszystko
http://wklej.org/id/369851/
C:\windows\system32\* /s /lockedfiles
/md5start
ndis.sys
atapi.sys
iastor.sys
msconfig.exe
midimap.dll
tcpip.sys
winlogon.exe
wuauclt.exe
user32.dll
explorer.exe
ctfmon.exe
sfc_os.dll
/md5stop
netsvcs
clearallrestorepoints
http://www.wklej.org/id/370181/
http://www.wklej.org/id/370182/
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\SysOp\USTAWI~1\Temp\cpuz130\cpuz_x32.sys -- (cpuz130)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\G:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\H:) - File not found
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2BE9FEFC
:commands
[emptytemp]
[emptyflash]
[claerallrestorepoints]
http://wklej.to/2sFH
http://wklej.to/LXB9
http://wklej.to/kDg1
www.piotr.home.pl/pulpit.jpg
http://www.speedyshare.com/files/23575381/virusinfo_syscheck.zip
begin
DeleteService('ALSysIO');
SetServiceStart('ALSysIO', 4);
DeleteFile('C:\DOCUME~1\SysOp\USTAWI~1\Temp\ALSysIO.sys');
RebootWindows(true);
end.
http://www.speedyshare.com/files/23584818/virusinfo_syscheck.zip
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 9 gości