dla pewności : odinstalowałeś daemon tools przed użyciem Gmera?
wypakuj to na dysku C :
http://www.sendspace.com/file/gew9cr
Uruchom OTL i w sekcji
własne opcje skanowania / skrypt wklej:
:OTL
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [WinampAgent] File not found
O4 - HKU\S-1-5-21-1325072439-2419310910-506584239-1006..\Run: [FlashGet 3] File not found
O4 - HKU\S-1-5-21-1325072439-2419310910-506584239-1006..\Run: [Orb] File not found
O4 - Startup: C:\Documents and Settings\Winiarski\Menu Start\Programy\Autostart\ubisoft register.lnk = File not found
O33 - MountPoints2\{2b35221e-e340-11df-99be-0011675ee65d}\Shell\AutoRun\command - "" = H:\urDrive.exe
O33 - MountPoints2\{2f007bc2-9095-11de-96c4-0011675ee65d}\Shell - "" = AutoRun
O33 - MountPoints2\{2f007bc2-9095-11de-96c4-0011675ee65d}\Shell\AutoRun\command - "" = H:\Install.exe
O33 - MountPoints2\{5a90e8f0-5633-11dd-94eb-0011675ee65d}\Shell\AutoRun\command - "" = EXPLORER.EXE
O33 - MountPoints2\{5a90e8f0-5633-11dd-94eb-0011675ee65d}\Shell\explore\Command - "" = EXPLORER.EXE
O33 - MountPoints2\{5a90e8f0-5633-11dd-94eb-0011675ee65d}\Shell\open\Command - "" = EXPLORER.EXE
O33 - MountPoints2\{7cac8b18-6256-11dd-9503-0011675ee65d}\Shell\AutoRun\command - "" = \Firefox\FirefoxPortable.exe
O33 - MountPoints2\{bb8b5a54-d2c6-11dd-95a5-0011675ee65d}\Shell\AutoRun\command - "" = H:\EXPLORER.EXE
O33 - MountPoints2\{bb8b5a54-d2c6-11dd-95a5-0011675ee65d}\Shell\explore\Command - "" = H:\EXPLORER.EXE
O33 - MountPoints2\{bb8b5a54-d2c6-11dd-95a5-0011675ee65d}\Shell\open\Command - "" = H:\EXPLORER.EXE
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2B11E0DF
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:CB0AACC9
:Files
C:\Documents and Settings\Winiarski\Dane aplikacji\ESET
C:\Documents and Settings\All Users\Dane aplikacji\ESET
C:\Documents and Settings\Winiarski\Dane aplikacji\Toolbar4
C:\Documents and Settings\Winiarski\Ustawienia lokalne\Temp
C:\Documents and Settings\Winiarski\Dane aplikacji\Mozilla\Firefox\Profiles\03jsg06j.default\searchplugins\daemon-search.xml
C:\Documents and Settings\Winiarski\Dane aplikacji\Mozilla\Firefox\Profiles\03jsg06j.default\searchplugins\web-search.xml
C:\WINDOWS\System32\winlogon.exe|C:\winlogon.exe /replace
C:\WINDOWS\System32\dllcache\winlogon.exe|C:\winlogon.exe /replace
C:\WINDOWS\explorer.exe|C:\explorer.exe /replace
C:\WINDOWS\System32\dllcache\explorer.exe|C:\explorer.exe /replace
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]
Kliknij wykonaj skrypt. I potwierdź reset komputera .
Następnie uruchamiasz OTL z opcją skanuj. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia (zawartość notatnika, która otworzy się po restarcie).