O4 - HKLM…\Run: [hiden.exe] hiden.exe
Usuwasz zarówno wpisy jak i ten plik w trybie awaryjnym i bez netu i po ptokach :lol:
Tak na marginesie to jeszcze to jest do usunięcia:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://best-search.cc/search.php?v=6&aff=7147459
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://allwebsearcher.com/?said=1211
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allwebsearcher.com/?said=1211
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://allwebsearcher.com/?said=1211
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.164 lender-search.com
O1 - Hosts: 82.179.166.165 hot-searches.com
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - HKLM…\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe
O4 - HKLM…\Run: [ErrorGuard] C:\Program Files\ErrorGuard\ErrorGuard.Exe
O4 - HKLM…\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra ‘Tools’ menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Downl … e-c337.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu … .0.0.8.cab
O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\porynt.dll
O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\porynt.dll