przy podpietym dysku:
Uruchom OTL i w oknie Custom Scans/Fixes wklej :
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/intl/
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Renia\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2010-02-03 16:24:51 | 000,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-03 16:24:51 | 000,000,059 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-03 16:24:51 | 000,000,059 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2008-10-26 18:52:16 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.) - G:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008-10-11 12:01:18 | 000,000,049 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [2010-02-03 16:24:52 | 000,000,059 | RHS- | M] () - I:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-02 18:31:06 | 000,000,000 | ---D | M] - J:\Autodiagnostyka -- [ NTFS ]
O32 - AutoRun File - [2010-02-03 16:24:52 | 000,000,059 | RHS- | M] () - J:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-03 16:24:52 | 000,000,059 | RHS- | M] () - K:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{b173b145-0e55-11df-aa5f-806d6172696f}\Shell\AutoRun\command - "" = C:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{b173b145-0e55-11df-aa5f-806d6172696f}\Shell\open\Command - "" = C:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{b173b146-0e55-11df-aa5f-806d6172696f}\Shell\AutoRun\command - "" = D:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{b173b146-0e55-11df-aa5f-806d6172696f}\Shell\open\Command - "" = D:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{b173b147-0e55-11df-aa5f-806d6172696f}\Shell\AutoRun\command - "" = E:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{b173b147-0e55-11df-aa5f-806d6172696f}\Shell\open\Command - "" = E:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{c5926bd4-0e7d-11df-8ce8-ef914f2820b0}\Shell - "" = AutoRun
O33 - MountPoints2\{c5926bd4-0e7d-11df-8ce8-ef914f2820b0}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2008-10-26 18:52:16 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{c5926bd7-0e7d-11df-8ce8-ef914f2820b0}\Shell - "" = AutoRun
O33 - MountPoints2\{c5926bd7-0e7d-11df-8ce8-ef914f2820b0}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2008-10-26 18:52:16 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{f50dc741-0f4c-11df-8cf4-8493a5b87121}\Shell - "" = AutoRun
O33 - MountPoints2\{f50dc741-0f4c-11df-8cf4-8493a5b87121}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2008-10-26 18:52:16 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{fdb49fca-0e4f-11df-8cdb-ac85229ec7b4}\Shell\AutoRun\command - "" = I:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{fdb49fca-0e4f-11df-8cdb-ac85229ec7b4}\Shell\open\Command - "" = I:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{fdb49fcb-0e4f-11df-8cdb-ac85229ec7b4}\Shell\AutoRun\command - "" = J:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{fdb49fcb-0e4f-11df-8cdb-ac85229ec7b4}\Shell\open\Command - "" = J:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{fdb49fcc-0e4f-11df-8cdb-ac85229ec7b4}\Shell\AutoRun\command - "" = K:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
O33 - MountPoints2\{fdb49fcc-0e4f-11df-8cdb-ac85229ec7b4}\Shell\open\Command - "" = K:\9d6tpg.exe -- [2010-02-02 04:17:53 | 000,090,624 | RHS- | M] ()
:Files
C:\Documents and Settings\Renia\Ustawienia lokalne\Temp\cvasds0.dll
C:\1hqup.exe
C:\9d6tpg.exe
C:\autorun.inf
d:\1hqup.exe
d:\9d6tpg.exe
d:\autorun.inf
e:\1hqup.exe
e:\9d6tpg.exe
e:\autorun.inf
i:\1hqup.exe
i:\9d6tpg.exe
i:\autorun.inf
j:\1hqup.exe
j:\9d6tpg.exe
j:\autorun.inf
k:\1hqup.exe
k:\9d6tpg.exe
k:\autorun.inf
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
Kliknij w Run Fix. I potwierdz reset kompa .
Następnie uruchamiasz OTL z opcją Run Scan. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia komputera