picasso, to moja pierwsza prośba o pomoc i nie wiedziałem jak zareagować w chwili kiedy mój temat uciekał dalej... przepraszam za problem, ale nie wiedziałem jaki jest background sytuacji...
Przechodząc do tematu, to komputer już jest odblokowany i wysyałm następne załączniki.
Dzięki za pomoc
Nie mogę załączyć jednego pliku, ponieważ wyskakuje mi kumunikat, że nie mam uprawnień do wysyłania tego typu plików - wrzucam poniżej tekst z pliku:
All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1554920091-796931263-1221738049-2010\Software\Microsoft\Windows\CurrentVersion\Run\\termmgr deleted successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\1458\termmgr.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-1554920091-796931263-1221738049-2010\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
Prefs.js: "http://www.daemon-search.com/startpage" removed from browser.startup.homepage
========== FILES ==========
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\1458 folder moved successfully.
C:\Users\mwalewski\AppData\Roaming\hellomoto folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: administrator
->Temp folder emptied: 33907406 bytes
->Temporary Internet Files folder emptied: 61478891 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 57033 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: dkr
->Temp folder emptied: 33854 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: mwalewski
->Temp folder emptied: 2508495072 bytes
->Temporary Internet Files folder emptied: 887100793 bytes
->Java cache emptied: 31525493 bytes
->FireFox cache emptied: 108329305 bytes
->Flash cache emptied: 3128241 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 3682304 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 281911162 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50668 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 3 738,00 mb
OTL by OldTimer - Version 3.2.53.1 log created on 07072012_123433
Files\Folders moved on Reboot...
C:\Users\mwalewski\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZYDYLX9T\9526-ukash-na-komputerze-jest-zainfekowany-win-64-bit-pomocy[1].htm moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MO5NJO37\xd_arbiter[1].htm moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\fastbutton[1].htm moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\fastbutton[2].htm moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\like[2].htm moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\wyniki-wyszukiwania;search,774[1].htm moved successfully.
C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XNC225S\xd_arbiter[1].htm moved successfully.
PendingFileRenameOperations files...
File C:\Users\mwalewski\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZYDYLX9T\9526-ukash-na-komputerze-jest-zainfekowany-win-64-bit-pomocy[1].htm not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MO5NJO37\xd_arbiter[1].htm not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\fastbutton[1].htm not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\fastbutton[2].htm not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\like[2].htm not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QBLQCTS\wyniki-wyszukiwania;search,774[1].htm not found!
File C:\Users\mwalewski\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XNC225S\xd_arbiter[1].htm not found!
Registry entries deleted on Reboot...
OTL.Txt