:OTL PRC - [2010-10-09 13:02:33 | 000,411,185 | -HS- | M] ( ) – c:\avmon.com MOD - [2010-11-11 09:37:56 | 000,115,200 | RHS- | M] () – C:\WINDOWS\system32\mgking1.dll MOD - [2010-11-11 09:37:14 | 000,084,480 | RHS- | M] () – C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\dsoqq0.dll O4 - HKLM…\Run: [1] c:\avmon.com ( ) O4 - HKU\S-1-5-21-583907252-1957994488-1417001333-500…\Run: [api32] C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\apiqq.exe () O4 - HKU\S-1-5-21-583907252-1957994488-1417001333-500…\Run: [dso32] C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\dsoqq.exe () O4 - HKU\S-1-5-21-583907252-1957994488-1417001333-500…\Run: [king_mg] C:\WINDOWS\system32\mgking.exe () O4 - HKU\S-1-5-21-583907252-1957994488-1417001333-500…\Run: [wsctf.exe] File not found O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Reg Error: Key error.) O32 - AutoRun File - [2010-11-11 22:59:01 | 000,000,061 | RHS- | M] () - C:\autorun.inf – [NTFS] O32 - AutoRun File - [2010-11-11 22:59:01 | 000,000,061 | RHS- | M] () - D:\autorun.inf – [NTFS] O32 - AutoRun File - [2010-11-11 22:59:01 | 000,000,061 | RHS- | M] () - E:\autorun.inf – [NTFS] O32 - AutoRun File - [2009-10-18 20:37:53 | 000,000,059 | RHS- | M] () - F:\AUTORUN.FCB – [NTFS] O32 - AutoRun File - [2010-11-11 22:59:01 | 000,000,061 | RHS- | M] () - F:\autorun.inf – [NTFS] O32 - AutoRun File - [2009-10-18 20:37:53 | 000,000,059 | RHS- | M] () - G:\AUTORUN.FCB – [NTFS] O32 - AutoRun File - [2010-11-11 22:59:01 | 000,000,061 | RHS- | M] () - G:\autorun.inf – [NTFS] O32 - AutoRun File - [2010-11-11 22:59:04 | 000,000,061 | RHS- | M] () - K:\autorun.inf – [FAT32] O33 - MountPoints2{1d55fd70-61af-11df-8e6c-000feaa188a3}\Shell\AutoRun\command - “” = K:\EXPLORER.EXE – File not found O33 - MountPoints2{1d55fd70-61af-11df-8e6c-000feaa188a3}\Shell\explore\Command - “” = K:\EXPLORER.EXE – File not found O33 - MountPoints2{1d55fd70-61af-11df-8e6c-000feaa188a3}\Shell\open\Command - “” = K:\EXPLORER.EXE – File not found O33 - MountPoints2{23c9e964-4cb9-11df-9f1c-806d6172696f}\Shell\AutoRun\command - “” = D:\cbbw88s.exe – [2010-11-11 09:37:56 | 000,177,664 | RHS- | M] () O33 - MountPoints2{23c9e964-4cb9-11df-9f1c-806d6172696f}\Shell\open\Command - “” = D:\cbbw88s.exe – [2010-11-11 09:37:56 | 000,177,664 | RHS- | M] () O33 - MountPoints2{23c9e967-4cb9-11df-9f1c-806d6172696f}\Shell\AutoRun\command - “” = G:\cbbw88s.exe – [2010-11-11 09:37:56 | 000,177,664 | RHS- | M] () O33 - MountPoints2{23c9e967-4cb9-11df-9f1c-806d6172696f}\Shell\open\Command - “” = G:\cbbw88s.exe – [2010-11-11 09:37:56 | 000,177,664 | RHS- | M] () O33 - MountPoints2{8e9717f5-8689-11df-8e9b-000feaa188a3}\Shell - “” = AutoRun O33 - MountPoints2{8e9717f5-8689-11df-8e9b-000feaa188a3}\Shell\AutoRun\command - “” = K:\USBAutoRun.exe – File not found O33 - MountPoints2\J\Shell - “” = AutoRun O33 - MountPoints2\J\Shell\AutoRun\command - “” = J:\Setup.exe – File not found [2010-11-11 22:59:54 | 000,000,061 | RHS- | M] () – C:\autorun.inf [2010-11-11 09:37:56 | 000,177,664 | RHS- | M] () – C:\WINDOWS\System32\mgking.exe [2010-11-11 09:37:56 | 000,177,664 | RHS- | M] () – C:\cbbw88s.exe [2010-11-11 09:37:56 | 000,115,200 | RHS- | M] () – C:\WINDOWS\System32\mgking1.dll [2010-11-11 09:37:14 | 000,116,224 | ---- | M] () – C:\WINDOWS\System32\mgking0.dll [2010-11-10 16:16:56 | 000,178,176 | RHS- | M] () – C:\dwh.exe [2010-11-07 11:34:18 | 000,174,592 | RHS- | M] () – C:\egmjjb.exe [2010-11-03 16:02:07 | 000,153,088 | RHS- | M] () – C:\9keibj.exe [2010-10-31 09:01:13 | 000,175,616 | RHS- | M] () – C:\apqpm.exe [2010-10-30 07:31:04 | 000,174,592 | RHS- | M] () – C:\albkpq3.exe [2010-10-29 08:00:55 | 000,175,616 | RHS- | M] () – C:\b9v.exe [2010-10-26 19:32:06 | 000,180,224 | RHS- | M] () – C:\lpl.exe [2010-10-25 09:06:06 | 000,139,264 | RHS- | M] () – C:\r3q63rok.exe [2010-10-24 13:12:36 | 000,162,816 | RHS- | M] () – C:\9d6resf.exe [2010-10-21 09:20:30 | 000,162,816 | RHS- | M] () – C:\jofk1wf.exe [2010-10-19 10:08:20 | 000,162,816 | RHS- | M] () – C:\o1o.exe [2010-10-18 09:11:59 | 000,175,104 | RHS- | M] () – C:\wq.exe [2010-10-17 11:08:22 | 000,174,592 | RHS- | M] () – C:\kyme.exe [2010-10-15 07:11:31 | 000,174,592 | RHS- | M] () – C:\h3wp9.exe [2010-10-14 09:01:05 | 000,174,592 | RHS- | M] () – C:\io3yalc.exe [2010-10-09 13:02:33 | 000,411,185 | -HS- | M] ( ) – C:\avmon.com [2010-06-15 12:19:29 | 000,115,712 | RHS- | M] () – C:\2bbi1ax.exe [2010-06-14 14:34:54 | 000,116,224 | RHS- | M] () – C:\2ul.exe [2010-06-02 16:31:54 | 000,115,200 | RHS- | M] () – C:\6mxvohs.exe [2010-05-28 13:28:03 | 000,115,712 | RHS- | M] () – C:\bu8.exe [2010-05-26 13:11:27 | 000,113,152 | RHS- | M] () – C:\f662sjd.exe :Files C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\apiqq.exe C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\dsoqq.exe D:\2bbi1ax.exe D:\2ul.exe D:\6mxvohs.exe D:\9d6resf.exe D:\9keibj.exe D:\albkpq3.exe D:\apqpm.exe D:\autorun.inf D:\avmon.com D:\b9v.exe D:\bu8.exe D:\cbbw88s.exe D:\dwh.exe D:\egmjjb.exe D:\f662sjd.exe D:\h3wp9.exe D:\io3yalc.exe D:\jofk1wf.exe D:\kyme.exe D:\lpl.exe D:\o1o.exe D:\r3q63rok.exe D:\wq.exe E:\2bbi1ax.exe E:\2ul.exe E:\6mxvohs.exe E:\9d6resf.exe E:\9keibj.exe E:\albkpq3.exe E:\apqpm.exe E:\autorun.inf E:\avmon.com E:\b9v.exe E:\bu8.exe E:\cbbw88s.exe E:\dwh.exe E:\egmjjb.exe E:\f662sjd.exe E:\h3wp9.exe E:\io3yalc.exe E:\jofk1wf.exe E:\kyme.exe E:\lpl.exe E:\o1o.exe E:\r3q63rok.exe E:\wq.exe F:\2bbi1ax.exe F:\2ul.exe F:\6mxvohs.exe F:\9d6resf.exe F:\9keibj.exe F:\albkpq3.exe F:\apqpm.exe F:\autorun.inf F:\avmon.com F:\b9v.exe F:\bu8.exe F:\cbbw88s.exe F:\dwh.exe F:\egmjjb.exe F:\f662sjd.exe F:\h3wp9.exe F:\io3yalc.exe F:\jofk1wf.exe F:\kyme.exe F:\lpl.exe F:\o1o.exe F:\r3q63rok.exe F:\wq.exe G:\2bbi1ax.exe G:\2ul.exe G:\6mxvohs.exe G:\9d6resf.exe G:\9keibj.exe G:\albkpq3.exe G:\apqpm.exe G:\autorun.inf G:\avmon.com G:\b9v.exe G:\bu8.exe G:\cbbw88s.exe G:\dwh.exe G:\egmjjb.exe G:\f662sjd.exe G:\h3wp9.exe G:\io3yalc.exe G:\jofk1wf.exe G:\kyme.exe G:\lpl.exe G:\o1o.exe G:\r3q63rok.exe G:\wq.exe K:\2bbi1ax.exe K:\2ul.exe K:\6mxvohs.exe K:\9d6resf.exe K:\9keibj.exe K:\albkpq3.exe K:\apqpm.exe K:\autorun.inf K:\avmon.com K:\b9v.exe K:\bu8.exe K:\cbbw88s.exe K:\dwh.exe K:\egmjjb.exe K:\f662sjd.exe K:\h3wp9.exe K:\io3yalc.exe K:\jofk1wf.exe K:\kyme.exe K:\lpl.exe K:\o1o.exe K:\r3q63rok.exe K:\wq.exe :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] “C:\Program Files\Garena\Garena.exe”=- “C:\Program Files\DotAlicious Gaming Client\client.exe”=- “C:\Documents and Settings\Administrator\Pulpit\Roller Coaster\rct.exe”=- :Commands [emptytemp] [start explorer] [Reboot]