:OTL MOD - [2003-01-01 00:04:30 | 000,093,696 | RHS- | M] () – C:\Documents and Settings\Marcin\Ustawienia lokalne\Temp\cvasds1.dll O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Marcin\Dane aplikacji\Nowe Gadu-Gadu_userdata\ggbho.1.dll File not found O4 - HKLM…\Run: [NPSStartup] File not found O4 - HKLM…\Run: [system32LSBM Agent] C:\windows\System32LSBM.exe File not found O4 - HKU\S-1-5-21-1659004503-2025429265-725345543-1003…\Run: [cdoosoft] C:\Documents and Settings\Marcin\Ustawienia lokalne\Temp\herss.exe () O4 - HKU\S-1-5-21-1659004503-2025429265-725345543-1003…\Run: [dso32] C:\Documents and Settings\Marcin\Ustawienia lokalne\Temp\dsoqq.exe () O32 - AutoRun File - [2003-01-01 05:59:50 | 000,000,051 | RHS- | M] () - C:\autorun.inf – [FAT32] O32 - AutoRun File - [2003-01-01 05:59:50 | 000,000,051 | RHS- | M] () - D:\autorun.inf – [FAT32] O32 - AutoRun File - [2003-01-01 05:59:50 | 000,000,051 | RHS- | M] () - E:\autorun.inf – [FAT32] O32 - AutoRun File - [2003-01-01 05:59:50 | 000,000,051 | RHS- | M] () - F:\autorun.inf – [FAT32] O33 - MountPoints2{379bfca0-abdb-11db-b1ba-806d6172696f}\Shell\AutoRun\command - “” = C:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca0-abdb-11db-b1ba-806d6172696f}\Shell\open\Command - “” = C:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca1-abdb-11db-b1ba-806d6172696f}\Shell\AutoRun\command - “” = D:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca1-abdb-11db-b1ba-806d6172696f}\Shell\open\Command - “” = D:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca2-abdb-11db-b1ba-806d6172696f}\Shell\AutoRun\command - “” = E:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca2-abdb-11db-b1ba-806d6172696f}\Shell\open\Command - “” = E:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca3-abdb-11db-b1ba-806d6172696f}\Shell\AutoRun\command - “” = F:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{379bfca3-abdb-11db-b1ba-806d6172696f}\Shell\open\Command - “” = F:\mh.exe – [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () O33 - MountPoints2{4e709f28-1d65-11d7-a6ec-001109cae853}\Shell\AutoRun\command - “” = jim\carry\jIm.exe O33 - MountPoints2{4e709f28-1d65-11d7-a6ec-001109cae853}\Shell\open\command - “” = jim\carry\jIm.exe O33 - MountPoints2{832166de-1d25-11d7-a611-001109cae853}\Shell\AutoRun\command - “” = J:\2bbi1ax.exe – File not found O33 - MountPoints2{832166de-1d25-11d7-a611-001109cae853}\Shell\open\Command - “” = J:\2bbi1ax.exe – File not found [2003-01-01 06:41:56 | 000,000,000 | -HSD | C] – C:\FOUND.002 [2003-01-01 04:52:52 | 000,000,000 | -HSD | C] – C:\FOUND.008 [2003-01-01 02:49:40 | 000,000,000 | -HSD | C] – C:\FOUND.001 [2003-01-01 00:32:42 | 000,000,000 | -HSD | C] – C:\FOUND.010 [2003-01-01 00:20:50 | 000,000,000 | -HSD | C] – C:\FOUND.016 [2003-01-01 00:15:44 | 000,000,000 | -HSD | C] – C:\FOUND.011 [2003-01-01 00:08:54 | 000,000,000 | -HSD | C] – C:\FOUND.009 [2003-01-01 00:08:20 | 000,000,000 | -HSD | C] – C:\FOUND.000 [2003-01-01 00:04:56 | 000,000,000 | -HSD | C] – C:\FOUND.007 [2003-01-01 00:04:40 | 000,000,000 | -HSD | C] – C:\FOUND.004 [2003-01-01 00:03:52 | 000,000,000 | -HSD | C] – C:\FOUND.005 [2003-01-01 00:03:36 | 000,000,000 | -HSD | C] – C:\FOUND.003 [2003-01-01 12:27:46 | 000,114,688 | RHS- | M] () – C:\33r.exe [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () – C:\mh.exe [2003-01-01 11:10:24 | 000,118,784 | RHS- | M] () – C:\Documents and Settings\Marcin\Pulpit\mh.exe [2003-01-01 09:36:18 | 000,116,224 | RHS- | M] () – C:\xcr.exe [2003-01-01 06:07:58 | 000,000,051 | RHS- | M] () – C:\autorun.inf [2003-01-01 00:06:26 | 000,115,200 | RHS- | M] () – C:\f662sjd.exe :Files autorun.inf /alldrives 33r.exe /alldrives mh.exe /alldrives xcr.exe /alldrives f662sjd.exe /alldrives C:\FOUND.006 C:\FOUND.012 C:\FOUND.013 C:\FOUND.014 C:\FOUND.015 C:\Documents and Settings\Marcin\Ustawienia lokalne\Temp\cvasds1.dll C:\Documents and Settings\Marcin\Ustawienia lokalne\Temp\herss.exe C:\Documents and Settings\Marcin\Ustawienia lokalne\Temp\dsoqq.exe :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp] [start explorer] [Reboot]