Professional Documents
Culture Documents
Step 2.
1. Open notepad and copy/paste the text present inside the code box
To do this highlight the contents of the box and right click on it.
nto the open notepad.
NOTICE: This script was written specifically for this user, for use
icular machine. Running this on another machine may cause damage to
g system
below.
Paste this i
on that part
the operatin
Code: [Select]
Start
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\Run: [Win-Update] => C:\W
indows\win-update.exe
C:\Windows\win-update.exe
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\Run: [Google Update] => C
:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-11-28] (G
oogle Inc.)
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\MountPoints2: G - G:\Auto
Run.exe
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\MountPoints2: H - H:\Auto
Run.exe
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\MountPoints2: {9b8ce725-c
ef0-11e1-8f5e-441ea1da1c21} - G:\AutoRun.exe
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\MountPoints2: {a8eca616-c
edd-11e1-9604-3859f9eba1b4} - G:\AutoRun.exe
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\MountPoints2: {a8eca627-c
edd-11e1-9604-3859f9eba1b4} - G:\AutoRun.exe
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\MountPoints2: {a8eca68c-c
edd-11e1-9604-001e101f50a4} - G:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\Run: [zADs.exe] => C:\Use
rs\user\AppData\Roaming\zADs.exe [56320 2014-04-23] ()
HKU\S-1-5-21-3465869317-3857268257-4292628261-1000\...\Run: [zAD.exe] => C:\User
s\user\AppData\Roaming\zAD.exe [56832 2014-05-17] ()
C:\Users\user\AppData\Roaming\zADs.exe
C:\Users\user\AppData\Roaming\zAD.exe
HKLM-x32\...\Run: [Yahoo Messenger] => [X]
Task: {16D48B3A-3C0C-4254-A30B-EE20481749B7} - System32\Tasks\GoogleUpdateTaskUs
erS-1-5-21-3465869317-3857268257-4292628261-1000Core => C:\Users\user\AppData\Lo
cal\Google\Update\GoogleUpdate.exe [2012-11-28] (Google Inc.)
Task: {513A382A-3F86-4540-9CFA-922E182F4E44} - System32\Tasks\GoogleUpdateTaskUs
erS-1-5-21-3465869317-3857268257-4292628261-1000UA => C:\Users\user\AppData\Loca
l\Google\Update\GoogleUpdate.exe [2012-11-28] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3465869317-3857268257-429262
8261-1000Core.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3465869317-3857268257-429262
8261-1000UA.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe
Step 3.