Nic tu nie widać, kosmetyka. Odinstaluj:
SUPERAntiSpyware (masz MBAM i Avasta, więc zbędny),
McAfee Security Scan, SweetIM for Messenger, Internet Explorer Toolbar 4.6 by SweetPacks. Następnie:
Uruchom
OTL w oknie
Własne opcje skanowania/skrypt wklej:
:OTL
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\w29n51.sys -- (w29n51)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\UIUSys.sys -- (UIUSys)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000&st=12&barid={A88D8B65-B48D-11E1-97F9-0010C67E3586}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=12&q={searchTerms}&barid={A88D8B65-B48D-11E1-97F9-0010C67E3586}]
IE - HKU\S-1-5-21-1482476501-854245398-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000&st=12&barid={A88D8B65-B48D-11E1-97F9-0010C67E3586}
IE - HKU\S-1-5-21-1482476501-854245398-1417001333-1003\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=12&q={searchTerms}&barid={A88D8B65-B48D-11E1-97F9-0010C67E3586}
FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
[2012-06-12 14:54:19 | 000,004,002 | ---- | M] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\w8uysuko.default\searchplugins\sweetim.xml
[2012-06-11 23:33:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\pdfforge
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt. Dajesz log z usuwania + nowe logi z OTL.