R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {4534FBDD-6B32-11CA-3F8D-3446939FDBCC} - C:\WINDOWS\system32\tbhrwac.dll (file missing)
R3 - URLSearchHook: (no name) - {708A5E2C-C4CE-E560-C894-90FC28F4E5C5} - C:\WINDOWS\system32\ynkc.dll (file missing)
O4 - HKLM\..\Run: [7df138be.exe] C:\WINDOWS\system32\7df138be.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [7df138be.exe] C:\Documents and Settings\Piotrek\Ustawienia lokalne\Dane aplikacji\7df138be.exe
O4 - HKCU\..\Run: [Tuwe] "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt yazr
O4 - HKCU\..\Run: [Vkeh] C:\Documents and Settings\Piotrek\Moje dokumenty\T?sks\?poolsv.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: winbfi32 - winbfi32.dll (file missing)
Usuwasz wpisy + pliki pogrubione ręcznie z dysku (w trybie awaryjnym, z wyłączonym Przywracaniem Systemu wszystko wykonujesz).
==========================================
Później otwierasz Notatnik i wklejasz w nim to :
; DelDomains.inf Š 11-28-04 | Revised 01-15-06
; Created by: Mike Burgess Microsoft MVP
; http://mvps.org/winhelp2002/
;
; Warning: Deletes all entries in the Restricted & Trusted Zone list
; http://mvps.org/winhelp2002/restricted.htm
;
; Revised to include the EscDomains key
;
; To execute this file: in Explorer - right-click (this file)
; Select Install from the Menu.
; Note: you will not see any onscreen action.
[version]
signature="$CHICAGO$"
[DefaultInstall]
DelReg=DelTemps
AddReg=AddTemps
[DelTemps]
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains"
; Recreate the keys to avoid a restart
[AddTemps]
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains"
Plik -> Zapisz jako -> zmieniasz z TXT na wszystkie pliki -> nazwa Red.inf
Klikasz prawym przyciskiem myszki na powstały plik i wybierasz Instaluj. Później reset kompa i dajesz log do kontroli

============================================
Dodatkowo wykonujesz :
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
Ten wpis usuniesz programem Registrar Lite -> http://www.resplendence.com/reglite