1. Odinstaluj:
IB Updater Service, AVG Security Toolbar. Następnie wklej w OTL:
:OTL
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&st=17&q={searchTerms}&barid={7B1710B7-98CE-4646-B615-C6FBF772159F}
IE - HKU\S-1-5-21-2000478354-1897051121-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=17&barid={7B1710B7-98CE-4646-B615-C6FBF772159F}
IE - HKU\S-1-5-21-2000478354-1897051121-1417001333-1003\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=1D8DE34D-5C29-4D5F-AE06-CFB203A02F04&apn_sauid=77D2DD09-7E90-471F-A593-2A207719A76E
IE - HKU\S-1-5-21-2000478354-1897051121-1417001333-1003\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid=&
CHR - Extension: SweetPacks Chrome Extension = C:\Documents and Settings\Siora\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.4.0.4_1\
CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\Siora\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\
CHR - Extension: SweetPacks Chrome Extension = C:\Documents and Settings\Siora\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.4.0.4_1\
O3 - HKU\S-1-5-21-2000478354-1897051121-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKU\S-1-5-21-2000478354-1897051121-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
[2013-06-02 12:12:36 | 001,432,368 | ---- | C] () -- C:\WINDOWS\System32\dmwu.exe
[2013-02-03 21:58:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\283A6
[2013-10-26 14:18:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\APN
[2013-02-05 19:58:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ask
[2013-06-27 13:39:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search
[2013-11-30 13:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive
[2012-11-20 16:31:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Siora\Dane aplikacji\AVG Secure Search
:Files
C:\WINDOWS\system32\jmdp
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt. Podajesz log z usuwania + nowe logi z OTL.