Odinstaluj
Akamai NetSession Interface, ElfBot NG (źródło jednej infekcji). Następnie:
Uruchom
OTL 
w oknie
Własne opcje skanowania/skrypt wklej:
:OTL
IE - HKU\S-1-5-21-1935655697-179605362-1801674531-500\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=EF73F56E-21AF-4E5A-A141-3EB7804A5DAE&apn_sauid=7BF9F18E-3A6A-46CB-9AD5-DD195F49435A
IE - HKU\S-1-5-21-1935655697-179605362-1801674531-500\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
FF - prefs.js..browser.search.order.1: "Ask.com"
[2013-03-27 13:40:35 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\gryuk386.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Overwolf\SKYPE4~2.DLL File not found
[2013-05-15 10:12:34 | 000,043,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hqkwrkyy.sys
[2013-04-21 21:46:06 | 000,000,149 | ---- | C] () -- C:\Program Files\Common Files\userInit.dll
[2013-04-15 23:28:33 | 000,027,958 | ---- | C] () -- C:\Program Files\Common Files\logonInit.dll
[2013-05-14 22:55:00 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-179605362-1801674531-500UA.job
[2013-05-14 22:55:00 | 000,001,012 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-179605362-1801674531-500Core.job
[2013-03-17 11:34:07 | 000,533,059 | ---- | C] () -- C:\WINDOWS\winupdater.exe
[2013-03-17 11:34:06 | 000,890,368 | ---- | C] () -- C:\WINDOWS\tplink.exe
[2013-03-12 17:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ask
:Reg
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=-
"RTHDCPL"=-
"SkyTel"=-
"Alcmtr"=-
"SunJavaUpdateSched"=-
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"ALLUpdate"=-
"MSMSGS"=-
"Facebook Update"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt. Podajesz log z usuwania + nowe logi z OTL.
Co masz nie tak z Esetem?? Bo widzę czerwone kółeczko z wykrzyknikiem.