|
|
aaaaTrzeba żyć, a nie tylko istnieć.aaaa
Infekcja pendrivowa.
Uruchom OTL i w oknie Custom Scans/Fixes wklej to:
:OTL
[2010-02-16 13:45:41 | 000,000,059 | RHS- | M] () -- C:\autorun.inf
[2010-02-07 11:47:12 | 000,037,376 | -HS- | C] () -- C:\Documents and Settings\Aro\Menu Start\Programy\Autostart\row32.dll
[2010-01-24 16:54:56 | 000,000,000 | -HSD | C] -- C:\RECYCLER
O32 - AutoRun File - [2010-02-16 13:45:41 | 000,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-16 13:45:41 | 000,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-16 13:39:34 | 000,000,059 | RHS- | M] () - G:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{02a8e564-09a5-11df-bc72-00138f8f7851}\Shell\AutoRun\command - "" = H:\rg9g9bgq.exe -- File not found
O33 - MountPoints2\{02a8e564-09a5-11df-bc72-00138f8f7851}\Shell\open\Command - "" = H:\rg9g9bgq.exe -- File not found
O33 - MountPoints2\{03bc2f7e-0900-11df-9970-00138f8f7851}\Shell - "" = AutoRun
O33 - MountPoints2\{03bc2f7f-0900-11df-9970-00138f8f7851}\Shell\AutoRun\command - "" = p3vwxx.exe
O33 - MountPoints2\{03bc2f7f-0900-11df-9970-00138f8f7851}\Shell\open\Command - "" = p3vwxx.exe
O33 - MountPoints2\{c09a1639-0902-11df-b92c-806d6172696f}\Shell\AutoRun\command - "" = p3vwxx.exe
O33 - MountPoints2\{c09a1639-0902-11df-b92c-806d6172696f}\Shell\open\Command - "" = p3vwxx.exe
O33 - MountPoints2\{c09a163b-0902-11df-b92c-806d6172696f}\Shell\AutoRun\command - "" = p3vwxx.exe
O33 - MountPoints2\{c09a163b-0902-11df-b92c-806d6172696f}\Shell\open\Command - "" = p3vwxx.exe
O33 - MountPoints2\{d52a3c95-1a07-11df-bca4-f509b303af52}\Shell\AutoRun\command - "" = H:\rg9g9bgq.exe -- File not found
O33 - MountPoints2\{d52a3c95-1a07-11df-bca4-f509b303af52}\Shell\open\Command - "" = H:\rg9g9bgq.exe -- File not found
O33 - MountPoints2\{ff883866-14e1-11df-bc8b-00138f8f7851}\Shell\AutoRun\command - "" = H:\ws.exe -- File not found
O33 - MountPoints2\{ff883866-14e1-11df-bc8b-00138f8f7851}\Shell\open\Command - "" = H:\ws.exe -- File not found
O33 - MountPoints2\{ff883867-14e1-11df-bc8b-00138f8f7851}\Shell\AutoRun\command - "" = I:\y.exe -- File not found
O33 - MountPoints2\{ff883867-14e1-11df-bc8b-00138f8f7851}\Shell\open\Command - "" = I:\y.exe -- File not found
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[Reboot]
Kliknij w Run Fix. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom OTL ponownie, tym razem kliknij "Run Scan".
Pokaż nowy log OTL.txt oraz raport z usuwania.
.
zanotowane.pldoc.pisz.plpdf.pisz.plbrytfanna.keep.pl
|
|
|