Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej to:
:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2406647298-1165066723-1503467061-1002\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
:Reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
[HKEY_USERS\S-1-5-21-2406647298-1165066723-1503467061-1002\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"=-
:Commands
[emptytemp]
Kliknij w Wykonaj Skrypt.
[2014-01-25 17:17:17 | 000,121,840 | ---- | C] (CyberLink) -- C:\windows\SysNative\drivers\wsvd.sys.bak
[2014-01-25 17:17:17 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\WdfLdr.sys.bak
[2014-01-25 17:17:17 | 000,042,392 | ---- | C] (Intel Corporation) -- C:\windows\SysNative\drivers\WDKMD.sys.bak
[2014-01-25 17:17:17 | 000,016,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\wmilib.sys.bak
[2014-01-25 17:17:16 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\watchdog.sys.bak
[2014-01-25 17:17:15 | 000,129,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\videoprt.sys.bak
[2014-01-25 17:17:14 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\usbport.sys.bak
[2014-01-25 17:17:14 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\usbrpm.sys.bak
[2014-01-25 17:17:13 | 000,032,896 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\USBCAMD2.sys.bak
[2014-01-25 17:17:13 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\usb8023.sys.bak
[2014-01-25 17:17:13 | 000,007,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\usbd.sys.bak
W logu OTL jest dużo plików o rozszerzeniu *.bak. - To dziwne.
Zobacz, czy w tych samych lokalizacjach (C:/WINDOWS/system32/drivers) są też pliki o tych samych nazwach, ale bez *.bak.
F.