:OTL MOD - [2010-05-24 11:05:40 | 000,074,752 | RHS- | M] () – C:\Documents and Settings\Davinwest\Ustawienia lokalne\Temp\dsoqq0.dll SRV - File not found [Disabled | Stopped] – -- (BootDrv) O3 - HKCU…\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found. O3 - HKCU…\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O4 - HKCU…\Run: [dso32] C:\Documents and Settings\Davinwest\Ustawienia lokalne\Temp\dsoqq.exe () O32 - AutoRun File - [2010-05-24 12:16:12 | 000,000,057 | RHS- | M] () - C:\autorun.inf – [NTFS] O33 - MountPoints2{016129f8-30d9-11de-9466-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{016129f8-30d9-11de-9466-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{042892ea-b7dd-11dd-93f8-0013d37a7281}\Shell - “” = AutoRun O33 - MountPoints2{042892ea-b7dd-11dd-93f8-0013d37a7281}\Shell\Auto\command - “” = G:\Cn911.exe – File not found O33 - MountPoints2{052bdff0-c924-11dd-9410-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{052bdff0-c924-11dd-9410-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{0a0423aa-c39a-11dd-9407-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{0a0423aa-c39a-11dd-9407-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{0bb2d26c-b7f3-11dd-93f9-0013d37a7281}\Shell - “” = AutoRun O33 - MountPoints2{15ac7c54-ad68-11dd-93eb-0013d37a7281}\Shell\AutoRun\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{15ac7c54-ad68-11dd-93eb-0013d37a7281}\Shell\open\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{15ac7c56-ad68-11dd-93eb-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c56-ad68-11dd-93eb-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c58-ad68-11dd-93eb-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c58-ad68-11dd-93eb-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c59-ad68-11dd-93eb-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c59-ad68-11dd-93eb-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c5b-ad68-11dd-93eb-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c5b-ad68-11dd-93eb-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{15ac7c5d-ad68-11dd-93eb-0013d37a7281}\Shell\AutoRun\command - “” = H:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe – File not found O33 - MountPoints2{258932b8-ada7-11dd-93ed-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{258932b8-ada7-11dd-93ed-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{2a635b4e-dda7-11de-956e-0013d37a7281}\Shell\AutoRun\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\sys32.exe – File not found O33 - MountPoints2{2a635b4e-dda7-11de-956e-0013d37a7281}\Shell\open\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\sys32.exe – File not found O33 - MountPoints2{35f1417a-0591-11de-9453-0013d37a7281}\Shell\AutoRun\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{35f1417a-0591-11de-9453-0013d37a7281}\Shell\open\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{39eab0c2-7fd3-11dc-92be-0013d37a7281}\Shell\Open(&0)\command - “” = Recycled\ctfmon.exe O33 - MountPoints2{4335b912-a9c7-11da-935e-0013d37a7281}\Shell - “” = AutoRun O33 - MountPoints2{50758f0c-f763-11dd-9448-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{50758f0c-f763-11dd-9448-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{51952bea-eef7-11db-91e9-0013d37a7281}\Shell - “” = AutoRun O33 - MountPoints2{51952bea-eef7-11db-91e9-0013d37a7281}\Shell\AutoRun\command - “” = G:\LaunchU3.exe – File not found O33 - MountPoints2{5b1d8b74-553a-11df-961d-0013d37a7281}\Shell\AutoRun\command - “” = H:\gi2ky.exe – File not found O33 - MountPoints2{5b1d8b74-553a-11df-961d-0013d37a7281}\Shell\open\Command - “” = H:\gi2ky.exe – File not found O33 - MountPoints2{69cc4336-bfb1-11dd-9403-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{69cc4336-bfb1-11dd-9403-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{725a57b1-fcce-11dd-944b-0013d37a7281}\Shell\AutoRun\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{725a57b1-fcce-11dd-944b-0013d37a7281}\Shell\open\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{8182bdcc-8679-11de-94e1-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{8182bdcc-8679-11de-94e1-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{87c35a90-d5b4-11de-956a-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{87c35a90-d5b4-11de-956a-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{9f2ef464-86b8-11dc-92ca-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{9f2ef464-86b8-11dc-92ca-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{b1b545dd-5b5d-11df-9624-0013d37a7281}\Shell\AutoRun\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{b1b545dd-5b5d-11df-9624-0013d37a7281}\Shell\open\command - “” = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – File not found O33 - MountPoints2{b487f0b0-e345-11de-9586-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{b487f0b0-e345-11de-9586-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{b6854822-213e-11df-95d0-0013d37a7281}\Shell\AutoRun\command - “” = G:\gi2ky.exe – [2009-02-28 12:35:04 | 000,108,843 | RHS- | M] () O33 - MountPoints2{b6854822-213e-11df-95d0-0013d37a7281}\Shell\open\Command - “” = G:\gi2ky.exe – [2009-02-28 12:35:04 | 000,108,843 | RHS- | M] () O33 - MountPoints2{c92c1c6e-65b6-11df-9632-0013d37a7281}\Shell\AutoRun\command - “” = G:\q0wfr.exe – [2010-05-22 08:27:36 | 000,114,688 | RHS- | M] () O33 - MountPoints2{c92c1c6e-65b6-11df-9632-0013d37a7281}\Shell\open\Command - “” = G:\q0wfr.exe – [2010-05-22 08:27:36 | 000,114,688 | RHS- | M] () O33 - MountPoints2{cf0434fa-a59b-11dd-93e7-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{cf0434fa-a59b-11dd-93e7-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{d10d43fc-5532-11df-961c-0013d37a7281}\Shell\AutoRun\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{d10d43fc-5532-11df-961c-0013d37a7281}\Shell\open\command - “” = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe – [2008-04-25 16:34:48 | 000,031,744 | RHS- | M] () O33 - MountPoints2{d48c42fe-821c-11db-90f9-0013d37a7281}\Shell\Open(&0)\command - “” = Recycled\ctfmon.exe [2010-05-24 12:18:18 | 000,000,057 | RHS- | M] () – C:\autorun.inf [2010-05-22 08:27:36 | 000,114,688 | RHS- | M] () – C:\q0wfr.exe :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] “SuperHidden”=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] “Hidden”=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] “ShowSuperHidden”=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] “CheckedValue”=dword:00000001 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden] @="" :Commands [emptytemp] [Reboot]