Masz wykonac WSZYSTKO co podalem w takiej kolejnosci jak podalem, a nie tylko czesc.
Nie wykonales w ogole skanowania, cureit, salitykiller i nadal masz zainfekowany system. Skoncz marnowac moj czas.
Uzyj USBFix, opcja Vaccinate.
Wykonaj skrypt w OTL:
:OTL
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ghggm.sys -- (amsint32)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O33 - MountPoints2\{65967ab2-04e8-11e3-9879-00016c096a7d}\Shell - "" = AutoRun
O33 - MountPoints2\{65967ab2-04e8-11e3-9879-00016c096a7d}\Shell\AutoRun\command - "" = I:\AutoRun.exe -- [2011-03-15 09:27:22 | 000,148,320 | R--- | M] ()
O33 - MountPoints2\{65967ab5-04e8-11e3-9879-00016c096a7d}\Shell - "" = AutoRun
O33 - MountPoints2\{65967ab5-04e8-11e3-9879-00016c096a7d}\Shell\AutoRun\command - "" = I:\AutoRun.exe -- [2011-03-15 09:27:22 | 000,148,320 | R--- | M] ()
O33 - MountPoints2\{65967abc-04e8-11e3-9879-00016c096a7d}\Shell\AUToPLay\ComMand - "" = K:\ijwhg.exe
O33 - MountPoints2\{65967abc-04e8-11e3-9879-00016c096a7d}\Shell\AutoRun\command - "" = K:\ijwhg.exe
O33 - MountPoints2\{65967abc-04e8-11e3-9879-00016c096a7d}\Shell\explorE\CommaNd - "" = K:\ijwhg.exe
O33 - MountPoints2\{65967abc-04e8-11e3-9879-00016c096a7d}\Shell\oPen\commaNd - "" = K:\ijwhg.exe
[2013-08-14 20:36:43 | 000,029,412 | RHS- | C] () -- C:\fuedv.exe
[2013-08-14 20:36:25 | 000,000,210 | RHS- | C] () -- C:\autorun.inf
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"K:\ijwhg.exe" =-
"C:\DOCUME~1\jazda\USTAWI~1\Temp\winncwvsl.exe" =-
"C:\DOCUME~1\jazda\USTAWI~1\Temp\winkqtvbv.exe" =-
"C:\DOCUME~1\jazda\USTAWI~1\Temp\oghs.exe" =-
:Commands
[emptytemp]