Serdecznie proszę o pomoc z tym trojanem.
Z góry dziękuję

Oto moje logi OTL :
http://wklejto.pl/index.php?id=131351
i Extras :
http://wklejto.pl/index.php?id=131352
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.75 Safari/537.1 Comodo_Dragon/21.0.2.0
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1340398664_886287
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={21022E0B-F920-4700-AD08-A2C090B86B05}
IE - HKCU\..\URLSearchHook: {8040829d-1177-46e2-9157-8282438b79c7} - No CLSID value found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=110819&tt=120812_bandext_3312_7&babsrc=HP_ss&mntrId=42d834ea0000000000000626b6f2ce8c
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1340398664_886287
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=110819&tt=120812_bandext_3312_7&babsrc=HP_ss&mntrId=42d834ea0000000000000626b6f2ce8c
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&tt=120812_bandext_3312_7&babsrc=SP_ss&mntrId=42d834ea0000000000000626b6f2ce8c
IE - HKCU\..\SearchScopes\{5C40CB18-1DAF-47CC-8C7D-2DFC7560EC68}: "URL" = http://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms}
IE - HKCU\..\SearchScopes\{685617B6-BB2F-440E-823F-956E129178EE}: "URL" = http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKCU\..\SearchScopes\{7677DE92-C781-4DA0-AFF7-026A00E6B9E3}: "URL" = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2
IE - HKCU\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms}
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={21022E0B-F920-4700-AD08-A2C090B86B05}
FF - prefs.js..browser.search.defaultenginename: "GadgetBox"
FF - prefs.js..browser.search.defaulturl: "http://search.gboxapp.com/?q="
FF - prefs.js..browser.search.order.1: "GadgetBox"
FF - prefs.js..browser.startup.homepage: "http://home.mywebsearch.com/index.jhtml?ptb=2ED36B15-487F-404D-9BEA-20F39BA3ED67&n=77edc52b&p2=^GR^xdm025^S01572^pl&si=CK20h6OrjLECFUZd3wodsT5p_g"
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=2ED36B15-487F-404D-9BEA-20F39BA3ED67&n=77edc52b&ind=2012071211&p2=^GR^xdm025^S01572^pl&si=CK20h6OrjLECFUZd3wodsT5p_g&searchfor="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_270.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
[2012-07-17 21:51:52 | 000,000,000 | ---D | M] (wxDfast) -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\mozilla\Firefox\Profiles\jxanisn2.default\extensions\[email protected]
[2012-07-12 11:13:33 | 000,000,000 | ---D | M] (MyWebFace) -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\mozilla\Firefox\Profiles\jxanisn2.default\extensions\5affxtbr@MyWebFace_5a.com
[2012-08-14 11:12:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\mozilla\Firefox\Profiles\jxanisn2.default\extensions\[email protected]
[2012-07-17 21:51:52 | 000,000,000 | ---D | M] (GadgetBox) -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\mozilla\Firefox\Profiles\jxanisn2.default\extensions\gadget@gadgetbox
[2012-06-22 19:27:26 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\mozilla\Firefox\Profiles\jxanisn2.default\extensions\[email protected]
[2012-08-14 11:12:44 | 000,002,227 | ---- | M] () -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\Mozilla\Firefox\Profiles\jxanisn2.default\searchplugins\BabylonMngr.xml
[2012-07-17 21:51:37 | 000,000,440 | ---- | M] () -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\Mozilla\Firefox\Profiles\jxanisn2.default\searchplugins\GadgetBox.xml
[2012-07-12 11:13:37 | 000,009,635 | ---- | M] () -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\Mozilla\Firefox\Profiles\jxanisn2.default\searchplugins\my-web-search.xml
[2012-06-23 18:05:19 | 000,004,113 | ---- | M] () -- C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\Mozilla\Firefox\Profiles\jxanisn2.default\searchplugins\sweetim.xml
[2012-08-14 11:12:22 | 000,002,364 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012-06-22 22:57:45 | 000,002,415 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml
CHR - homepage: http://search.babylon.com/?affID=110819&tt=120812_bandext_3312_7&babsrc=HP_ss&mntrId=42d834ea0000000000000626b6f2ce8c
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [adobeupdate] C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\7 9\l3.lnk ()
O4 - HKCU..\Run: [adobeupdater] "C:\Users\Pysiewicz Mieczyslaw\AppData\Roaming\7 9\rundll32.exe" File not found
O4 - HKCU..\Run: [clqpbkecqywnaxv] C:\ProgramData\clqpbkec.exe (Adtron)
O9 - Extra Button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Users\Pysiewicz Mieczyslaw\Desktop\PartyCasino.lnk File not found
O9 - Extra 'Tools' menuitem : PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Users\Pysiewicz Mieczyslaw\Desktop\PartyCasino.lnk File not found
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Pysiewicz Mieczyslaw\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Pysiewicz Mieczyslaw\Desktop\PartyPoker.lnk File not found
[2012-08-13 22:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\jyuvnlocqfdgjve
[2012-08-13 22:37:14 | 000,087,552 | ---- | C] (Adtron) -- C:\Users\Pysiewicz Mieczyslaw\0.781374787753755.exe
[2012-08-13 23:01:55 | 000,000,380 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterLogonTask.job
[2012-08-13 23:01:55 | 000,000,372 | -H-- | M] () -- C:\Windows\tasks\OptimizerProUpdaterLogonTask.job
[2012-08-13 23:01:55 | 000,000,368 | -H-- | M] () -- C:\Windows\tasks\GboxUpdaterLogonTask.job
[2012-08-13 23:01:52 | 000,000,360 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterRefreshTask.job
[2012-08-13 23:01:52 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\OptimizerProUpdaterRefreshTask.job
[2012-08-13 23:01:52 | 000,000,348 | -H-- | M] () -- C:\Windows\tasks\GboxUpdaterRefreshTask.job
[2012-08-13 22:37:24 | 000,000,051 | ---- | M] () -- C:\ProgramData\gcgccsmpuwuzoko
[2012-08-13 22:37:15 | 000,087,552 | ---- | M] (Adtron) -- C:\Users\Pysiewicz Mieczyslaw\0.781374787753755.exe
[2012-08-11 22:00:40 | 000,000,322 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012-08-08 21:39:27 | 000,000,306 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Bing [Bot]