Odinstaluj vShare.tv plugin, SweetPacks Toolbar. Następnie:
Uruchom OTL w oknie Własne opcje skanowania/skrypt wklej:
:OTL
IE - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2417076
IE - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - No CLSID value found
IE - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\..\URLSearchHook: {8532a8b7-c06a-41bb-936a-8ce73e4711ed} - No CLSID value found
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..extensions.enabledItems: [email protected]:3.0
IE - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:64162
[2010-09-23 18:52:07 | 000,000,000 | ---D | M] (The Saloon Bar) -- C:\Documents and Settings\Sławek\Dane aplikacji\Mozilla\Firefox\Profiles\7orcsxaq.default\extensions\[email protected]
O3 - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\..\Toolbar\WebBrowser: (no name) - {463DF6D5-BEC1-4D67-B217-59DB692DFC53} - No CLSID value found.
O3 - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\..\Toolbar\WebBrowser: (no name) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No CLSID value found.
O3 - HKU\S-1-5-21-1229272821-842925246-1343024091-1003\..\Toolbar\WebBrowser: (no name) - {8532A8B7-C06A-41BB-936A-8CE73E4711ED} - No CLSID value found.
O4 - HKU\S-1-5-21-1229272821-842925246-1343024091-1003..\Run: [Windows Update Server] C:\Documents and Settings\Ania\462e82b4-5689.exe File not found
O4 - HKU\S-1-5-21-1229272821-842925246-1343024091-1003..\Run: [winlogon] C:\Documents and Settings\Ania\winlogon.exe File not found
[2012-02-26 22:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\v9Soft
[2012-02-26 19:36:00 | 000,000,000 | ---D | C] -- C:\ComboFix_www.INSTALKI.pl_21285C
[2012-02-26 19:26:25 | 000,000,000 | ---D | C] -- C:\ComboFix_www.INSTALKI.pl_
:Reg
[HKEY_USERS\S-1-5-21-1229272821-842925246-1343024091-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz Wykonaj skrypt. Dajesz log z usuwania + nowe logi z OTL.