W białe dolne okno Własne opcje skanowania/skrypt w OTL wklej:
:OTL
SRV - [2011-08-20 22:39:11 | 000,382,464 | ---- | M] () [Auto | Running] -- C:\Windows\update.7.1\svchostdriver.exe -- (ddservice)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [Setwallpaper] File not found
O4 - HKCU..\Run: [Kookos] File not found
O4 - HKCU..\Run: [Real Desktop] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O31 - SafeBoot: AlternateShell - services32.exe
[2011-08-20 22:50:19 | 000,000,000 | ---D | C] -- C:\Windows\ufa
[2011-08-20 22:50:19 | 000,000,000 | ---D | C] -- C:\Windows\phoenix
[2011-08-20 22:39:12 | 000,000,000 | -H-D | C] -- C:\Windows\update.7.1
[2011-08-21 15:52:32 | 000,000,177 | ---- | M] () -- C:\Windows\info1
[2011-08-21 15:04:24 | 000,000,734 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hîsts
[2011-08-20 22:50:18 | 005,589,370 | ---- | M] () -- C:\Windows\phoenix.rar
[2011-08-20 22:50:18 | 001,075,284 | ---- | M] () -- C:\Windows\rpcminer.rar
[2011-08-20 22:50:18 | 000,246,272 | ---- | M] () -- C:\Windows\unrar.exe
[2011-08-20 22:50:18 | 000,182,617 | ---- | M] () -- C:\Windows\ufa.rar
[2011-08-20 22:44:56 | 000,904,792 | ---- | M] () -- C:\Windows\geoiplist.rar
[2011-08-20 22:37:46 | 000,000,000 | ---- | M] () -- C:\Windows\loader2.exe_ok
[2011-08-20 22:43:31 | 004,636,907 | ---- | C] () -- C:\Windows\geoiplist
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:2F370DA6
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:4CF61E54
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:115CEE00
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A724744F
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:3B360415
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:4A0829E0
:Commands
[emptytemp]
[resethosts]
Uruchom to poprzez Wykonaj skrypt i zatwierdź restart.
Po restarcie wykonaj nowy zestaw logów OTL oraz pokaż raport z usuwania OTL powstały po wykonaniu powyższego skryptu.