Wklej do Notatnika:
Kod: Zaznacz cały
File::
c:\windows\system32\wmsoft26355.exe
c:\windows\system32\wmsoft58135.exe
c:\windows\system32\win_88661.exe
c:\windows\wuaucpl.exe
c:\windows\Fonts\wmsncs.exe
c:\documents and settings\All Users\Menu Start\Programy\Autostart\wmsncs.exe
Driver::
Local Service
R4 NET Runtime Optimization Service v2.1.41329_X86
Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Wmsncs Service"=-
"NvidMediaCenter"=-
"Spool Driver Service"=-
"Wins Service"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wmsncs Service"=-
"NvidMediaCenter"=-
"Spool Driver Service"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="explorer.exe \"c:\windows\Fonts\wmsncs.exe\,"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"DEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~???????Š?ŚŤŽŹ????????Š?ŚŤŽŹ ˇ˘Ł¤Ą?§¨?Ş??ŻÄü"=-
"wmsncs.exe"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{103L3C30-C3B3-4130-9363-E59E1375PERM}]
Robisz to samo.
Jeśli log nie będzie teraz czysty to poprostu FORMAT.
==================================================
K.