"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"AVG Secure Search" = AVG Security Toolbar
Odinstaluj to oprogramowanie.
Logi.
Uruchom OTL w oknie Własne opcje skanowania/skrypt wklej:
- Kod: Zaznacz wszystko
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=SAMSUNG_HD502HJ_S20BJ9BZA27932&ts=1348429478
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=SAMSUNG_HD502HJ_S20BJ9BZA27932&ts=1348429478
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/home?affID=112763&tt=120912_pcp_3812_7
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=SAMSUNG_HD502HJ_S20BJ9BZA27932&ts=1348429478
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={5D22154A-ECA0-43B7-827D-0468A2C258AF}&mid=fe0f99602f2947d0b1cdcd2623da4cdb-68cc4614dbe090db72cce0baf0b18639ee3168ac&lang=pl&ds=xn011&pr=sa&d=2012-09-07 20:35:38&v=12.2.0.5&sap=hp
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112763&tt=120912_pcp_3812_7&babsrc=SP_def&mntrId=6e4797a100000000000000ffcda01115
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={5D22154A-ECA0-43B7-827D-0468A2C258AF}&mid=fe0f99602f2947d0b1cdcd2623da4cdb-68cc4614dbe090db72cce0baf0b18639ee3168ac&lang=pl&ds=xn011&pr=sa&d=2012-09-07 20:35:38&v=12.2.0.5&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-1267917107-777748536-2660093714-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O4 - HKU\S-1-5-21-1267917107-777748536-2660093714-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
:Files
C:\Users\Jurek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\foobar2000 - Shortcut.lnk
C:\Windows\SysWow64\searchplugins
C:\Windows\SysWow64\Extensions
C:\Users\Jurek\AppData\Roaming\OpenCandy
C:\Users\Jurek\AppData\Local\AVG Secure Search
C:\ProgramData\AVG Secure Search
C:\Windows\SysNative\drivers\avgtpx64.sys
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\AVG Secure Search
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]
Klikasz Wykonaj skrypt. Dajesz log z usuwania. Następnie podaj log z ADWCleaner (z opcji Delete) otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p139531 + log z TDSSKiller otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p120292 + nowe logi z OTL + log z Autoruns otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p138589.