Jak możesz prosić o następne instrukcje jeśli do jednej z nich się nie zastosowałeś ?
:OTL
MOD - [2011-08-22 19:33:53 | 000,137,728 | ---- | M] () – C:\Windows\systemup.exe
MOD - [2011-08-22 19:19:17 | 001,213,440 | -H-- | M] () – C:\Windows\update.tray-12-0\svchost.exe
O4 - HKLM…\Run: [systemup] C:\Windows\systemup.exe ()
O4 - HKLM…\Run: [tray_ico] File not found
O4 - HKLM…\Run: [tray_ico0] C:\Windows\update.tray-12-0\svchost.exe ()
O4 - HKLM…\Run: [tray_ico1] File not found
O4 - HKLM…\Run: [tray_ico2] File not found
O4 - HKLM…\Run: [tray_ico3] File not found
O4 - HKLM…\Run: [tray_ico4] File not found
O4 - HKLM…\Run: [wxpdrv] C:\Windows\services32.exe ()
O4 - HKCU…\Run: [EA Core] File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O31 - SafeBoot: AlternateShell - services32.exe
[2011-08-23 16:38:58 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-12-0-lnk
[2011-08-23 16:38:58 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-12-0
[2011-08-22 19:59:54 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0-lnk
[2011-08-22 19:59:54 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0
[2011-08-22 19:35:11 | 000,000,000 | —D | C] – C:\Windows\ufa
[2011-08-22 19:35:11 | 000,000,000 | —D | C] – C:\Windows\rpcminer
[2011-08-22 19:35:11 | 000,000,000 | —D | C] – C:\Windows\phoenix
[2011-08-22 19:34:39 | 000,000,000 | -H-D | C] – C:\Windows\update.7.1
[2011-08-22 19:34:22 | 000,000,000 | -H-D | C] – C:\Windows\update.2
[2011-08-22 19:34:07 | 000,000,000 | -H-D | C] – C:\Windows\update.5.0
[2011-08-22 19:31:06 | 000,000,000 | —D | C] – C:\Windows\av_ico
[2011-08-22 19:29:52 | 000,000,000 | -H-D | C] – C:\Windows\update.1
[2011-08-22 19:29:51 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-2-0-lnk
[2011-08-22 19:29:51 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-2-0
[2011-08-24 23:26:16 | 000,017,360 | -H-- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-08-24 23:26:16 | 000,017,360 | -H-- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-08-24 22:01:20 | 000,000,734 | ---- | M] () – C:\Windows\System32\drivers\etc\hîsts
[2011-08-22 19:35:49 | 000,000,202 | ---- | M] () – C:\Windows\info1
[2011-08-22 19:35:10 | 005,589,370 | ---- | M] () – C:\Windows\phoenix.rar
[2011-08-22 19:35:10 | 001,075,284 | ---- | M] () – C:\Windows\rpcminer.rar
[2011-08-22 19:35:10 | 000,246,272 | ---- | M] () – C:\Windows\unrar.exe
[2011-08-22 19:35:10 | 000,182,617 | ---- | M] () – C:\Windows\ufa.rar
[2011-08-22 19:33:53 | 000,137,728 | ---- | M] () – C:\Windows\systemup.exe
[2011-08-22 19:32:41 | 000,904,792 | ---- | M] () – C:\Windows\geoiplist.rar
[2011-08-22 19:32:26 | 000,000,000 | ---- | M] () – C:\Windows\loader2.exe_ok
[2011-08-22 19:31:56 | 000,000,936 | ---- | M] () – C:\Users\Public\Desktop\ESL Wire.lnk
[2011-08-22 19:19:17 | 001,213,440 | ---- | M] () – C:\Windows\services32.exe
[2011-08-22 19:32:42 | 004,636,907 | ---- | C] () – C:\Windows\geoiplist
[2011-08-22 19:32:41 | 000,246,272 | ---- | C] () – C:\Windows\unrar.exe
[2011-08-22 19:20:03 | 001,213,440 | ---- | C] () – C:\Windows\services32.exe
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C39E55C5
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:88050731
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:364682BC
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
“AlternateShell”=“cmd.exe”
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[emptytemp]
[resethosts]