W opcje skanowania wklej:
MOD - [2011-08-23 14:55:59 | 000,382,464 | ---- | M] () -- C:\WINDOWS\update.7.1\svchostdriver.exe
SRV - [2011-08-23 14:55:59 | 000,382,464 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.7.1\svchostdriver.exe -- (ddservice)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O31 - SafeBoot: AlternateShell - services32.exe
[2011-08-23 16:39:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\ufa
[2011-08-23 14:56:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.7.1
[2011-08-23 14:55:16 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.5.0
[2011-08-23 14:54:07 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.2
[2011-08-23 14:52:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.1
[2011-08-23 17:05:34 | 000,000,198 | ---- | M] () -- C:\WINDOWS\info1
[2011-08-23 15:08:19 | 005,589,370 | ---- | M] () -- C:\WINDOWS\phoenix.rar
[2011-08-23 15:08:19 | 000,246,272 | ---- | M] () -- C:\WINDOWS\unrar.exe
[2011-08-23 15:08:19 | 000,182,617 | ---- | M] () -- C:\WINDOWS\ufa.rar
[2011-08-23 15:08:17 | 001,075,284 | ---- | M] () -- C:\WINDOWS\rpcminer.rar
[2011-08-23 14:53:48 | 000,904,792 | ---- | M] () -- C:\WINDOWS\geoiplist.rar
[2011-08-23 14:53:13 | 000,000,000 | ---- | M] () -- C:\WINDOWS\loader2.exe_ok
[2011-08-23 15:01:58 | 005,589,370 | ---- | C] () -- C:\WINDOWS\phoenix.rar
[2011-08-23 15:01:58 | 000,182,617 | ---- | C] () -- C:\WINDOWS\ufa.rar
[2011-08-23 15:01:57 | 001,075,284 | ---- | C] () -- C:\WINDOWS\rpcminer.rar
[2011-08-23 14:54:07 | 000,000,198 | ---- | C] () -- C:\WINDOWS\info1
[2011-08-23 14:53:49 | 004,636,907 | ---- | C] () -- C:\WINDOWS\geoiplist
[2011-08-23 14:53:48 | 000,904,792 | ---- | C] () -- C:\WINDOWS\geoiplist.rar
[2011-08-23 14:53:48 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe
[2011-08-23 14:52:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="cmd.exe"
:Commands
[RESETHOSTS]
[emptytemp]
Kliknij wykonaj skrypt, następnie reset komputera i nowy log ;]