Obok frst.exe utworz plik fixlist.txt z zawartoscia:
HKLM\...\Winlogon: [Userinit] C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\All Users\Dane aplikacji\s3nn3p7V\s3nn3p7V.exe -sm,
HKU\.DEFAULT\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
HKU\.DEFAULT\...\RunOnce: [nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Swcwhhbxctxdzjwl.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Swcwhhbxctxdzjwl.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Famqcsgpftuburns.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Famqcsgpftuburns.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Jnzzvnbzatbusson.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Jnzzvnbzatbusson.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Uejffbkblelwuchc.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Uejffbkblelwuchc.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Entelvubibujdhiw.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Entelvubibujdhiw.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Xnujivdmnfscpwul.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Xnujivdmnfscpwul.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Xovpjxslxcjdjkkr.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Xovpjxslxcjdjkkr.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Mjuiwaurgvipfnfo.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Mjuiwaurgvipfnfo.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Ppaltchpmcsnionq.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Ppaltchpmcsnionq.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Rahehkggioxblumg.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Rahehkggioxblumg.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Uqbvuparocdhzsqt.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Uqbvuparocdhzsqt.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Lziepkzmvcvbauyg.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Lziepkzmvcvbauyg.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Lxbdpkbchdyxevke.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Lxbdpkbchdyxevke.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Hbqgwqydpqihlsbn.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Hbqgwqydpqihlsbn.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Undrrejshsapdypc.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Undrrejshsapdypc.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [services.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\services.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Xnkmsiypnjpalycl.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Xnkmsiypnjpalycl.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Fsyqmolxmkwfuoee.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Fsyqmolxmkwfuoee.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Idrseumfpgwwyysc.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Idrseumfpgwwyysc.exe"
HKU\S-1-5-21-1078081533-1960408961-1417001333-1003\...\Run: [Yrstrmncbekpryrh.exe] => "C:\Documents and Settings\RODZICE\Dane aplikacji\Yrstrmncbekpryrh.exe"
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL =
http://websearch.ask.com/redirect?client=ie&tb=VDJ&o=41647960&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^8R&apn_dtid=^YYYYYY^YY^PL&apn_uid=195B0177-8D16-4BFF-9FFD-6E37FD43379E&apn_sauid=69D9A0EB-08CC-41CD-B95F-6F9EA2776931
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S3 catchme; \??\C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\catchme.sys [X]
S3 NVHDA; system32\drivers\nvhda32.sys [X]
2014-08-07 13:57 - 2014-08-07 14:19 - 00000000 ____D () C:\AdwCleaner
C:\Documents and Settings\RODZICE\rthul.exe
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job
C:\Windows\Tasks\At3.job
C:\Windows\Tasks\At4.job
W FRST wybierz Fix.