AdwCleaner praktycznie załatwił sprawę. Użyj w nim opcji
OdinstalujW ustawieniach Chrome zmień stronę startową na np. google.pl
Uruchom
OTL w oknie
Własne opcje skanowania/skrypt wklej:
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\xhunter1.sys -- (xhunter1)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\vtany.sys -- (vtany)
IE - HKCU\..\SearchScopes\{4B7999E6-0DA1-492C-82EC-6FF5A6B922B0}: "URL" = http://searchou.com/?q={searchTerms}&id=202f0d74000000000000bc5ff4015446&r=78
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [SmartViewAgent] "C:\Program Files\DeviceVM\SmartView\SmartViewAgent.exe" File not found
O4 - HKCU..\Run: [ASRockIES] File not found
O4 - HKCU..\Run: [ASRockOCTuner] File not found
O4 - HKCU..\Run: [zASRockInstantBoot] File not found
O20 - AppInit_DLLs: (c:\progra~1\magnipic\sprote~1.dll) - File not found
[2013-05-13 20:12:34 | 000,002,432 | ---- | C] () -- C:\Users\Kamil\AppData\Local\TempYd5600.html
[2013-02-03 01:30:33 | 000,002,432 | ---- | C] () -- C:\Users\Kamil\AppData\Local\Tempks3076.html
[2012-12-29 17:20:16 | 000,002,432 | ---- | C] () -- C:\Users\Kamil\AppData\Local\TempHZ5484.html
[2012-10-21 22:20:34 | 000,002,432 | ---- | C] () -- C:\Users\Kamil\AppData\Local\TempIa4520.html
[2012-10-04 15:19:23 | 000,002,432 | ---- | C] () -- C:\Users\Kamil\AppData\Local\Tempzj5956.html
[2012-06-30 14:33:15 | 000,002,432 | ---- | C] () -- C:\Users\Kamil\AppData\Local\TempAS3804.html
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt i podajesz log z usuwania.