z podlączonym pendrivem :
Uruchom OTL i w oknie Custom Scans/Fixes wklej :
:OTL
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\Admin\Ustawienia lokalne\Temp\herss.exe ()
O32 - AutoRun File - [2010-02-24 23:12:39 | 000,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-24 23:12:39 | 000,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-24 23:12:40 | 000,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-02-24 23:12:40 | 000,000,051 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2008-05-06 11:23:11 | 000,189,808 | R--- | M] (Adobe Systems Incorporated) - H:\AutoPlay.exe -- [ CDFS ]
O32 - AutoRun File - [2008-06-27 18:27:41 | 000,000,000 | R--D | M] - H:\Autoplay -- [ CDFS ]
O32 - AutoRun File - [2006-08-22 12:33:08 | 000,000,055 | R--- | M] () - H:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{1b39de28-d2c1-11dd-9b51-aadcb4013837}\Shell\AutoRun\command - "" = I:\tgt.exe -- File not found
O33 - MountPoints2\{1b39de28-d2c1-11dd-9b51-aadcb4013837}\Shell\open\Command - "" = I:\tgt.exe -- File not found
O33 - MountPoints2\{7251bdc8-f2f5-11de-9b5a-001bfc78f342}\Shell - "" = AutoRun
O33 - MountPoints2\{7251bdc8-f2f5-11de-9b5a-001bfc78f342}\Shell\AutoRun\command - "" = H:\autorun.exe -- File not found
O33 - MountPoints2\{c11f01f5-f56d-11de-9b64-001bfc78f342}\Shell - "" = AutoRun
O33 - MountPoints2\{c11f01f5-f56d-11de-9b64-001bfc78f342}\Shell\AutoRun\command - "" = H:\Autoplay.exe -- [2008-05-06 11:23:11 | 000,189,808 | R--- | M] (Adobe Systems Incorporated)
:Files
C:\Documents and Settings\Admin\Ustawienia lokalne\Temp\cvasds0.dll
C:\s1.exe
C:\62.exe
C:\ws.exe
C:\tgt.exe
C:\Recycled
C:\qfnumt.exe
d:\s1.exe
d:\62.exe
d:\ws.exe
d:\tgt.exe
d:\Recycled
d:\qfnumt.exe
e:\s1.exe
e:\62.exe
e:\ws.exe
e:\tgt.exe
e:\Recycled
e:\qfnumt.exe
f:\s1.exe
f:\62.exe
f:\ws.exe
f:\tgt.exe
f:\Recycled
f:\qfnumt.exe
i:\s1.exe
i:\62.exe
i:\ws.exe
i:\tgt.exe
i:\autorun.inf
i:\Recycled
i:\qfnumt.exe
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
Kliknij w Run Fix. I potwierdz reset kompa .
Następnie uruchamiasz OTL z opcją Run Scan. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia komputera