


C:\Windows\SysNative\drivers\Rt64win7.sys
Już myślałem że duqu 
C:\Windows\SysNative\drivers\pstrip64.sys:Processes
Killallprocesses
:OTL
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3852200618-2580020882-47754279-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O33 - MountPoints2\{11c12569-f49b-11e0-91a9-0025228dd2fb}\Shell\AutoRun\command - \"\" = E:\AutoRun.exe
O33 - MountPoints2\{11c12585-f49b-11e0-91a9-0025228dd2fb}\Shell - \"\" = AutoRun
O33 - MountPoints2\{11c12585-f49b-11e0-91a9-0025228dd2fb}\Shell\AutoRun\command - \"\" = E:\AutoRun.exe
O33 - MountPoints2\{2222427e-baba-11e0-8fd0-0025228dd2fb}\Shell - \"\" = AutoRun
O33 - MountPoints2\{2222427e-baba-11e0-8fd0-0025228dd2fb}\Shell\AutoRun\command - \"\" = E:\AutoRun.exe
O33 - MountPoints2\{7d3b64cb-1aaf-11e1-89ad-0025228dd2fb}\Shell - \"\" = AutoRun
O33 - MountPoints2\{7d3b64cb-1aaf-11e1-89ad-0025228dd2fb}\Shell\AutoRun\command - \"\" = E:\AutoRun.exe
O33 - MountPoints2\{cfb8d183-b9c1-11e0-9c08-0025228dd2fb}\Shell - \"\" = AutoRun
IE - HKU\S-1-5-21-3852200618-2580020882-47754279-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3852200618-2580020882-47754279-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask):Dir
C:\grldr

Wróć do Pomoc po zainfekowaniu
Użytkownicy przeglądający ten temat: Obecnie na forum nie ma żadnego zarejestrowanego użytkownika i 1 gość