Uruchom OTL i w oknie Custom Scans/Fixes wklej :
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2009-12-27 14:30:02 | 00,000,055 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-12-27 14:30:02 | 00,000,055 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2004-08-04 13:00:00 | 00,000,112 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{7aff3146-f2ef-11de-bbd1-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7aff3146-f2ef-11de-bbd1-806d6172696f}\Shell\AutoRun\command - "" = E:\SETUP.EXE -- [2004-08-04 13:00:00 | 02,584,576 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{7aff3147-f2ef-11de-bbd1-806d6172696f}\Shell\AutoRun\command - "" = C:\9ffp.exe -- [2009-12-22 22:44:52 | 00,120,409 | RHS- | M] ()
O33 - MountPoints2\{7aff3147-f2ef-11de-bbd1-806d6172696f}\Shell\open\Command - "" = C:\9ffp.exe -- [2009-12-22 22:44:52 | 00,120,409 | RHS- | M] ()
O33 - MountPoints2\{7aff3148-f2ef-11de-bbd1-806d6172696f}\Shell\AutoRun\command - "" = D:\9ffp.exe -- [2009-12-22 22:44:52 | 00,120,409 | RHS- | M] ()
O33 - MountPoints2\{7aff3148-f2ef-11de-bbd1-806d6172696f}\Shell\open\Command - "" = D:\9ffp.exe -- [2009-12-22 22:44:52 | 00,120,409 | RHS- | M] ()
:Files
C:\9ffp.exe
d:\9ffp.exe
e:\9ffp.exe
C:\autorun.inf
e:\autorun.inf
d:\autorun.inf
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\herss.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[start explorer]
[Reboot]
Kliknij w Run Fix. I potwierdz reset kompa .
Następnie uruchamiasz OTL z opcją Run Scan. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia kompa