W logach infekcji nie widać, ale są wpisy, które mogą oznaczać jakiś problem z dyskiem, więc wrzuć screenshot z HD Tune
https://www.instalki.pl/download/programy/windows/narzedzia/testowanie-i-diagnostyka/hd-tune/ z zakładki
HealthUruchom
OTL w oknie
Własne opcje skanowania/skrypt wklej:
:OTL
[2013/07/08 18:54:03 | 000,001,049 | ---- | M] () -- C:\Users\Błaszko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
O4 - Startup: C:\Users\Błaszko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Ad Muncher.lnk = File not found
O4 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-604524677-2708395862-3557633927-1000..\Run: [DU Meter] "C:\Program Files\DU Meter\DUMeter.exe" /autostart File not found
O4 - HKLM..\Run: [Ad Muncher] "C:\Program Files\Ad Muncher\AdMunch.exe" /bt File not found
[2013/02/18 17:07:14 | 000,006,484 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
FF - prefs.js..browser.startup.homepage: "http://www.delta-search.com/?affID=119816&babsrc=HP_ss&mntrId=0abfeff8000000000000002454162a52"
IE - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119816&babsrc=HP_ss&mntrId=0abfeff8000000000000002454162a52
IE - HKU\S-1-5-21-604524677-2708395862-3557633927-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=0abfeff8000000000000002454162a52
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\IT9135BDA.sys -- (IT9135BDA)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\DU Meter\DUMETR32.SYS -- (DUMeterDrv)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Blaze Media Pro\NMSAccess32.exe -- (NMSAccess)
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"Adobe ARM"=-
"APSDaemon"=-
"IndexSearch"=-
"PaperPort PTD"=-
"PPort12reminder"=-
"PDFHook"=-
"QuickTime Task"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
"ISUSPM"=-
:Commands
[emptytemp]
Klikasz
Wykonaj skrypt. Podajesz log z usuwania + nowe logi z OTL.