Najprije izgasi preko TaskManagera:
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\znyqwu.exe
C:\Program Files\WindowsSA\omniscient.exe
Zatim sredi:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://searchcentral.cc/search.php?v=4&aff=3441
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://searchcentral.cc/index.php?v=4&aff=3441
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://searchcentral.cc/index.php?v=4&aff=3441
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 81.211.105.69 lender-search.com
O1 - Hosts: 81.211.105.68 hot-searches.com
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll (file missing)
O4 - HKLM\..\Run: [rtmhaunxu] C:\WINDOWS\System32\znyqwu.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update13.js
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) -
http://www.xxxtoolbar.com/ist/softw...006_regular.cab
O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} -
http://www.stop-sign.com/pub/download/stop-sign_stp.cab