W AdwCleaner

Odinstaluj
W Autoruns usuń:
zakładka
Logon:
rdpclip
ASUS WebStorage
Adobe ARM
Adobe Reader Speed Launcher
CLMLServer
DivXMediaServer
DivXUpdate
HP Software Update
TkBellExe
UpdateP2GoShortCut
Microsoft Windows
Microsoft Windows
DriverScanner
zakładka
Scheduled Tasks:
wszystko oprócz "\Adobe Flash Player Updater"
zakładka
Services (odznacz):
BBUpdate
ose
osppsvc
WinDefend
WMPNetworkSvc
Odinstaluj
Bing Bar, MediaBar.
Następnie wklej w OTL:
:OTL
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms}
IE - HKU\S-1-5-21-2643496333-2295395192-1436295622-1000\..\URLSearchHook: {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} - No CLSID value found
IE - HKU\S-1-5-21-2643496333-2295395192-1436295622-1000\..\SearchScopes\{8DC82E6A-D7D2-4415-8B6D-F9995E687EC3}: "URL" = http://mp3tubetoolbarsearch.com/?tmp=toolbar_Mp3Tube_results&prt=pinballtb01ie&Keywords={searchTerms}&clid=a08ba755abc2422ebf437bf2c8261d78
IE - HKU\S-1-5-21-2643496333-2295395192-1436295622-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms}
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O2:64bit: - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\x64\IEBHO.dll (MusicLab, LLC)
O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2643496333-2295395192-1436295622-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2643496333-2295395192-1436295622-1000\..\Toolbar\WebBrowser: (no name) - {9BB815EB-3F9F-4E11-9150-CB70E29B40FC} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O9:64bit: - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - Reg Error: Key error. File not found
O9:64bit: - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - Reg Error: Key error. File not found
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Reg Error: Key error.)
[2010.11.28 00:33:37 | 000,002,089 | ---- | C] () -- C:\Users\marek\AppData\Local\Tempua2864.html
[2010.11.27 23:18:55 | 000,002,432 | ---- | C] () -- C:\Users\marek\AppData\Local\TempNV5804.html
[2010.11.27 23:18:55 | 000,002,089 | ---- | C] () -- C:\Users\marek\AppData\Local\Tempet5804.html
[2010.11.28 00:33:37 | 000,002,432 | ---- | C] () -- C:\Users\marek\AppData\Local\TempFs2864.html
:Commands
[emptytemp]
Klikasz
Wykonaj skrypt. Podajesz log z usuwania + nowe logi z OTL.