Widać, że usługa Sality nadal jest widoczna, spróbujemy ją usunąć i zobaczymy, czy się odtworzy.
Uruchom OTL

:OTL
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc -- (gupdatem)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe /svc -- (gupdate)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\kfdiyfow.sys -- (kfdiyfow)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nihjun.sys -- (amsint32)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O3 - HKU\S-1-5-21-343818398-1788223648-725345543-1004\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-343818398-1788223648-725345543-1004\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O32 - AutoRun File - [2012-12-12 14:53:19 | 000,000,319 | -HS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012-12-12 14:53:19 | 000,000,277 | -HS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012-12-12 14:53:19 | 000,000,251 | -HS- | M] () - E:\autorun.inf -- [ NTFS ]
O4 - HKU\.DEFAULT..\RunOnce: [Second run install] C:\INSTALL\2ndrun.bat File not found
O4 - HKU\S-1-5-18..\RunOnce: [Second run install] C:\INSTALL\2ndrun.bat File not found
O4 - HKU\S-1-5-19..\RunOnce: [Second run install] C:\INSTALL\2ndrun.bat File not found
O4 - HKU\S-1-5-20..\RunOnce: [Second run install] C:\INSTALL\2ndrun.bat File not found
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz Wykonaj skrypt. Dajesz log z usuwania + nowe logi z OTL.