:OTL MOD - [2010-07-05 12:36:02 | 000,076,288 | RHS- | M] () – C:\Documents and Settings\laboratorium\Ustawienia lokalne\Temp\dsoqq1.dll O4 - HKU\S-1-5-21-790525478-1284227242-839522115-1004…\Run: [dso32] C:\Documents and Settings\laboratorium\Ustawienia lokalne\Temp\dsoqq.exe () O4 - HKLM…\RunServices: [csrcs] C:\WINDOWS\System32\csrcs.exe File not found O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_11) O20 - HKLM Winlogon: Shell - (csrcs.exe) - File not found O32 - AutoRun File - [2010-07-05 15:10:36 | 000,000,055 | RHS- | M] () - C:\autorun.inf – [NTFS] O32 - AutoRun File - [2010-07-05 15:10:38 | 000,000,055 | RHS- | M] () - D:\autorun.inf – [NTFS] O33 - MountPoints2{022488f4-9b78-11dd-9c49-00112f76555c}\Shell\AutoRun\command - “” = F:\w.com – File not found O33 - MountPoints2{022488f4-9b78-11dd-9c49-00112f76555c}\Shell\open\Command - “” = F:\w.com – File not found O33 - MountPoints2{05da029d-da5e-11dd-9c8e-00112f76555c}\Shell\AutoRun\command - “” = G:\twhvna.exe – File not found O33 - MountPoints2{05da029d-da5e-11dd-9c8e-00112f76555c}\Shell\open\Command - “” = G:\twhvna.exe – File not found O33 - MountPoints2{0654e846-e237-11de-9dcb-00112f76555c}\Shell\AutoRun\command - “” = G:\Toshiba\more4you.exe – File not found O33 - MountPoints2{0654e847-e237-11de-9dcb-00112f76555c}\Shell\AutoRun\command - “” = H:\LuMaTW.exe – File not found O33 - MountPoints2{0654e847-e237-11de-9dcb-00112f76555c}\Shell\OPeN\CommaND - “” = H:\lumatw.exE – File not found O33 - MountPoints2{1526d9ac-4883-11df-9e75-00112f76555c}\Shell\AutoRun\command - “” = G:\12gn6id2.exe – File not found O33 - MountPoints2{1526d9ac-4883-11df-9e75-00112f76555c}\Shell\open\Command - “” = G:\12gn6id2.exe – File not found O33 - MountPoints2{18bc9863-4866-11df-9e73-00112f76555c}\Shell\AutoRun\command - “” = sdfqh.exe O33 - MountPoints2{18bc9863-4866-11df-9e73-00112f76555c}\Shell\open\Command - “” = sdfqh.exe O33 - MountPoints2{18bc9865-4866-11df-9e73-00112f76555c}\Shell\AutoRun\command - “” = F:\wa.exe – File not found O33 - MountPoints2{18bc9865-4866-11df-9e73-00112f76555c}\Shell\open\Command - “” = F:\wa.exe – File not found O33 - MountPoints2{4858c71d-502f-11de-9d1d-00112f76555c}\Shell\AutoRun\command - “” = F:\DIJASPORA\gruda.exe – File not found O33 - MountPoints2{4858c71d-502f-11de-9d1d-00112f76555c}\Shell\open\command - “” = F:\DIJASPORA\gruda.exe – File not found O33 - MountPoints2{4d5a9cea-5914-11df-9e87-00112f76555c}\Shell\AutoRun\command - “” = F:\wyskq6lt.exe – File not found O33 - MountPoints2{4d5a9cea-5914-11df-9e87-00112f76555c}\Shell\open\Command - “” = F:\wyskq6lt.exe – File not found O33 - MountPoints2{4d5a9ceb-5914-11df-9e87-00112f76555c}\Shell\AutoRun\command - “” = F:\wyskq6lt.exe – File not found O33 - MountPoints2{4d5a9ceb-5914-11df-9e87-00112f76555c}\Shell\open\Command - “” = F:\wyskq6lt.exe – File not found O33 - MountPoints2{5695594a-5cf1-11df-9e8a-00112f76555c}\Shell\AutoRun\command - “” = F:\nTEzNl.exe – File not found O33 - MountPoints2{5695594a-5cf1-11df-9e8a-00112f76555c}\Shell\oPen\COMMaND - “” = F:\ntEZnL.exE – File not found O33 - MountPoints2{717b0872-4220-11de-9d0c-00112f76555c}\Shell\AutoRun\command - “” = F:\icxpa.cmd – File not found O33 - MountPoints2{717b0872-4220-11de-9d0c-00112f76555c}\Shell\open\Command - “” = F:\icxpa.cmd – File not found O33 - MountPoints2{760debed-e2f7-11dd-9ca1-00112f76555c}\Shell\AutoRun\command - “” = G:\USBNB.exe – File not found O33 - MountPoints2{9408e6ac-cb57-11dd-9c85-00112f76555c}\Shell - “” = AutoRun O33 - MountPoints2{9408e6ac-cb57-11dd-9c85-00112f76555c}\Shell\AutoRun\command - “” = F:\LaunchU3.exe – File not found O33 - MountPoints2{94235cbc-0982-11de-9cd3-00112f76555c}\Shell\AutoRun\command - “” = F:\1ogf.exe – File not found O33 - MountPoints2{94235cbc-0982-11de-9cd3-00112f76555c}\Shell\open\Command - “” = F:\1ogf.exe – File not found O33 - MountPoints2{aaff29db-77d0-11df-9eab-00112f76555c}\Shell\AutoRun\command - “” = G:\2ul.exe – File not found O33 - MountPoints2{aaff29db-77d0-11df-9eab-00112f76555c}\Shell\open\Command - “” = G:\2ul.exe – File not found O33 - MountPoints2{ab3bf68e-4fa4-11df-9e7a-00112f76555c}\Shell\AutoRun\command - “” = F:\twhvna.exe – File not found O33 - MountPoints2{ab3bf68e-4fa4-11df-9e7a-00112f76555c}\Shell\open\Command - “” = F:\twhvna.exe – File not found O33 - MountPoints2{ae27d06e-abfb-11dd-9c5b-00112f76555c}\Shell - “” = AutoRun O33 - MountPoints2{b54eeaa8-63ff-11df-9e93-00112f76555c}\Shell\AutoRun\command - “” = F:\krwyrv0d.exe – File not found O33 - MountPoints2{b54eeaa8-63ff-11df-9e93-00112f76555c}\Shell\open\Command - “” = F:\krwyrv0d.exe – File not found O33 - MountPoints2{b8e5dd48-082a-11df-9e13-00112f76555c}\Shell\AutoRun\command - “” = F:\q0wfr.exe – File not found O33 - MountPoints2{b8e5dd48-082a-11df-9e13-00112f76555c}\Shell\open\Command - “” = F:\q0wfr.exe – File not found O33 - MountPoints2{d41e1eaa-0f07-11de-9cd6-00112f76555c}\Shell\AutoRun\command - “” = SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe O33 - MountPoints2{d41e1eaa-0f07-11de-9cd6-00112f76555c}\Shell\open\command - “” = SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe O33 - MountPoints2{fd9aa9fe-3d82-11df-9e6c-00112f76555c}\Shell\AutoRun\command - “” = F:\n0qls.exe – File not found O33 - MountPoints2{fd9aa9fe-3d82-11df-9e6c-00112f76555c}\Shell\open\Command - “” = F:\n0qls.exe – File not found O33 - MountPoints2{fe7ec3db-e7fd-11de-9dd9-00112f76555c}\Shell\AutoRun\command - “” = F:\q0wfr.exe – File not found O33 - MountPoints2{fe7ec3db-e7fd-11de-9dd9-00112f76555c}\Shell\open\Command - “” = F:\q0wfr.exe – File not found [2010-07-05 15:13:53 | 000,000,055 | RHS- | M] () – C:\autorun.inf [2010-07-05 12:35:58 | 000,116,736 | RHS- | M] () – C:\g6jk.exe [2010-07-02 09:37:36 | 000,116,224 | RHS- | M] () – C:\rxf.exe [2010-07-01 11:08:20 | 000,117,248 | RHS- | M] () – C:\mk28sp.exe [2010-06-29 10:12:59 | 000,116,736 | RHS- | M] () – C:\1j038ki.exe [2010-06-24 09:37:45 | 000,116,736 | RHS- | M] () – C:\eyruu.exe [2010-06-23 09:28:09 | 000,117,248 | RHS- | M] () – C:\09lf.exe [2010-06-18 08:42:46 | 000,115,712 | RHS- | M] () – C:\1gkbvsni.exe [2010-06-17 11:55:16 | 000,116,224 | RHS- | M] () – C:\xcr.exe [2010-06-15 17:05:22 | 000,114,688 | RHS- | M] () – C:\krwyrv0d.exe [2010-06-15 09:08:18 | 000,115,712 | RHS- | M] () – C:\2bbi1ax.exe [2010-06-14 16:57:42 | 000,116,736 | RHS- | M] () – C:\2ul.exe [2010-06-11 12:02:06 | 000,116,736 | RHS- | M] () – C:\rfg.exe [2010-06-10 11:47:16 | 000,117,248 | RHS- | M] () – C:\n0qls.exe [2010-06-08 09:25:41 | 000,115,200 | RHS- | M] () – C:\yqq8eqil.exe [2010-05-12 13:26:26 | 000,112,128 | RHS- | M] () – C:\12gn6id2.exe [2010-06-18 08:42:46 | 000,115,712 | RHS- | M] () – C:\1gkbvsni.exe [2010-06-29 10:12:59 | 000,116,736 | RHS- | M] () – C:\1j038ki.exe [2010-05-04 10:21:43 | 000,111,104 | RHS- | M] () – C:\1thes92p.exe [2010-05-24 17:04:59 | 000,114,688 | RHS- | M] () – C:\33r.exe [2010-05-10 16:25:37 | 000,111,616 | RHS- | M] () – C:\9rfpp.exe [2010-04-08 09:59:27 | 000,116,224 | RHS- | M] () – C:\ba.exe [2010-05-28 09:26:20 | 000,115,712 | RHS- | M] () – C:\bu8.exe [2010-04-30 09:10:02 | 000,111,104 | RHS- | M] () – C:\ca.exe [2010-05-31 17:02:56 | 000,113,664 | RHS- | M] () – C:\cgaqyi.exe [2010-04-12 13:21:58 | 000,118,784 | RHS- | M] () – C:\chxnxyx.exe [2010-05-20 11:10:54 | 000,114,176 | RHS- | M] () – C:\cobn8w3.exe [2010-05-25 13:40:52 | 000,115,200 | RHS- | M] () – C:\f662sjd.exe [2010-04-26 17:01:35 | 000,128,512 | RHS- | M] () – C:\hc3hvi0.exe [2010-05-07 16:56:31 | 000,111,616 | RHS- | M] () – C:\i8ikdjwt.exe [2010-07-01 11:08:20 | 000,117,248 | RHS- | M] () – C:\mk28sp.exe [2010-05-13 09:58:33 | 000,112,640 | RHS- | M] () – C:\n6eyw.exe [2010-05-17 16:58:01 | 000,112,640 | RHS- | M] () – C:\p6xebrnt.exe [2010-05-22 10:02:54 | 000,114,688 | RHS- | M] () – C:\q0wfr.exe [2010-05-11 13:35:52 | 000,112,640 | RHS- | M] () – C:\qhbfqx.exe [2010-05-02 13:03:38 | 000,110,080 | RHS- | M] () – C:\rpw.exe [2010-04-24 12:08:03 | 000,128,000 | RHS- | M] () – C:\twhvna.exe [2010-04-22 10:21:39 | 000,128,512 | RHS- | M] () – C:\vgyn6ewc.exe [2010-05-27 08:34:48 | 000,114,176 | RHS- | M] () – C:\wa.exe [2010-04-15 09:54:51 | 000,126,976 | RHS- | M] () – C:\wyskq6lt.exe [2010-06-17 11:55:16 | 000,116,224 | RHS- | M] () – C:\xcr.exe :Files D:\autorun.inf D:\g6jk.exe D:\rxf.exe D:\mk28sp.exe D:\1j038ki.exe D:\eyruu.exe DC:\09lf.exe D:\1gkbvsni.exe D:\xcr.exe D:\krwyrv0d.exe D:\2bbi1ax.exe D:\2ul.exe D:\rfg.exe D:\n0qls.exe D:\yqq8eqil.exe D:\12gn6id2.exe D:\1gkbvsni.exe D:\1j038ki.exe D:\1thes92p.exe D:\33r.exe D:\9rfpp.exe D:\ba.exe D:\bu8.exe D:\ca.exe D:\cgaqyi.exe D:\chxnxyx.exe D:\cobn8w3.exe D:\f662sjd.exe D:\hc3hvi0.exe D:\i8ikdjwt.exe D:\mk28sp.exe D:\n6eyw.exe D:\p6xebrnt.exe D:\q0wfr.exe D:\qhbfqx.exe D:\rpw.exe D:\twhvna.exe D:\vgyn6ewc.exe D:\wa.exe D:\wyskq6lt.exe D:\xcr.exe C:\Documents and Settings\laboratorium\Ustawienia lokalne\Temp\dsoqq1.dll :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp] [start explorer] [Reboot]