Odinstaluj:
Search.us.com, McAfee Security Scan Plus . W ustawieniach Chrome zmień stronę startową na np. google.pl Poza tym czysto, kosmetycznie wklej w OTL:
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://speedial.com/?f=1&a=spd_ir_14_24_ch&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0EtAtD0FtDyEtA0EtD0AtN0D0Tzu0SzzzytBtN1L2XzutBtFtBtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BzytB0AtByD0BtGyDzz0FtCtGtB0EyCyDtGyD0AyE0AtGtDtBtAyEtAzztBtBzy0AtCyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0ByB0F0AtCyCtCtG0D0FyB0FtGtC0CyDtAtGtB0C0ByCtGyC0CtDyB0EtAyDyCtDzztAzy2Q&cr=1612719076&ir=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://speedial.com/?f=1&a=spd_ir_14_24_ch&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0EtAtD0FtDyEtA0EtD0AtN0D0Tzu0SzzzytBtN1L2XzutBtFtBtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BzytB0AtByD0BtGyDzz0FtCtGtB0EyCyDtGyD0AyE0AtGtDtBtAyEtAzztBtBzy0AtCyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0ByB0F0AtCyCtCtG0D0FyB0FtGtC0CyDtAtGtB0C0ByCtGyC0CtDyB0EtAyDyCtDzztAzy2Q&cr=1612719076&ir=
IE - HKU\S-1-5-21-1569856414-4265663065-2673455373-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/v/2/?guid={AC02FB27-3C3C-49C4-8381-0B14BB2616FE}&serpv=17
IE - HKU\S-1-5-21-1569856414-4265663065-2673455373-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://speedial.com/?f=1&a=spd_ir_14_24_ch&
http://search.us.com/serp?guid={AC02FB27-3C3C-49C4-8381-0B14BB2616FE}&action=default_search&serpv=5&k={searchTerms}
IE - HKU\S-1-5-21-1569856414-4265663065-2673455373-1000\..\SearchScopes\{5B643943-B847-4C1F-B82C-4210934146F2}: "URL" = http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_24_ch&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0EtAtD0FtDyEtA0EtD0AtN0D0Tzu0SzzzytBtN1L2XzutBtFtBtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BzytB0AtByD0BtGyDzz0FtCtGtB0EyCyDtGyD0AyE0AtGtDtBtAyEtAzztBtBzy0AtCyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0ByB0F0AtCyCtCtG0D0FyB0FtGtC0CyDtAtGtB0C0ByCtGyC0CtDyB0EtAyDyCtDzztAzy2Q&cr=1612719076&ir=
O3 - HKU\S-1-5-21-1569856414-4265663065-2673455373-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
[2014/07/25 21:31:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1569856414-4265663065-2673455373-1000UA.job
[2014/07/25 15:31:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1569856414-4265663065-2673455373-1000Core.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt. Podajesz log z usuwania + nowe logi z OTL.