1. Odinstaluj:
BrowserProtect, Google Toolbar for Internet Explorer, Qtrax Player, Delta toolbar, toolbar, Lollipop2. W Autoruns usuń:
zakładka
Logon:
rdpclip
C:\Users\Wojtek\AppData\Roaming\skype.dat
TCrdMain TOSHIBA Flash Cards Main Module
Toshiba Registration
Toshiba TEMPRO
TosNC
TosWaitSrv
Adobe ARM
Adobe Reader Speed Launcher
NBAgent
ToshibaServiceStation
TSleepSrv
Toshiba Places Icon Utility.lnk
lollipop.lnk Lollipop
Microsoft Windows
Microsoft Windows
TOPI.EXE
WebCake Desktop
zakładka
Scheduled Tasks:
wszystko
zakładka
Services (tylko odznacz):
WMPNetworkSvc
WinDefend
ose
osppsvc
NAUpdate
3. Uruchom
OTL w oknie
Własne opcje skanowania/skrypt wklej:
:OTL
MOD - [2013-06-26 21:20:24 | 000,893,960 | ---- | M] () -- C:\Users\Wojtek\AppData\Local\Lollipop\Lollipop.exe
MOD - [2013-06-03 11:57:49 | 003,085,264 | ---- | M] () -- C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
MOD - [2013-06-03 11:57:01 | 002,521,552 | ---- | M] () -- C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=1372274424
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=1372274424
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=4259917
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=1372274424
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=1372274424
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=4259917
IE - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=119357&tt=gc_&babsrc=HP_ss_din2g&mntrId=50E982CA94D25521
IE - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=1372274424
IE - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=119357&tt=gc_&babsrc=HP_ss_din2g&mntrId=50E982CA94D25521
IE - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=119357&tt=gc_&babsrc=SP_ss_din2g&mntrId=50E982CA94D25521
IE - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=TOSHIBAXMK5075GSX_Z1MLT3ATTXXZ1MLT3ATT&ts=4259917
IE - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000\..\SearchScopes\{9731015C-FF56-4133-BF1D-DFF328339B87}: "URL" = http://searchou.com/?q={searchTerms}&id=50e918a100000000000082ca94d25521&affilt=5&r=405
CHR - Extension: WebCake = C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_0\
O2 - BHO: (WebCake) - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\WebCake\WebCakeIEClient.dll (WebCake LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-2463010172-1726788731-3100462634-1000..\Run: [WebCake Desktop] C:\Users\Wojtek\AppData\Roaming\WebCake\WebCakeDesktop.exe (WebCake LLC)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Wojtek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lollipop.lnk = C:\Users\Wojtek\AppData\Local\Lollipop\Lollipop.exe ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
[2013-06-26 21:20:48 | 000,000,000 | ---D | C] -- C:\Users\Wojtek\AppData\Roaming\WebCake
[2013-06-26 21:21:35 | 000,000,000 | ---D | C] -- C:\Users\Wojtek\AppData\Roaming\337
[2013-06-26 21:20:24 | 000,000,000 | ---D | C] -- C:\Users\Wojtek\AppData\Local\Lollipop
[2013-06-26 21:20:30 | 000,000,360 | ---- | C] () -- C:\Windows\tasks\AmiUpdXp.job
[2013-06-01 17:37:05 | 000,000,290 | ---- | C] () -- C:\Windows\tasks\DSite.job
[2013-05-25 22:03:54 | 000,000,000 | ---D | M] -- C:\Users\Wojtek\AppData\Roaming\0C1I1L1R1J0M1P0I1G
[2013-05-25 22:02:56 | 000,000,000 | ---D | M] -- C:\Users\Wojtek\AppData\Roaming\Delta
[2013-05-25 22:02:32 | 000,000,000 | ---D | M] -- C:\Users\Wojtek\AppData\Roaming\Babylon
:Files
C:\Program Files (x86)\WebCake
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
:Services
WebCake Desktop Updater
:Reg
[HKEY_USERS\S-1-5-21-2463010172-1726788731-3100462634-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[HKEY_USERS\S-1-5-21-2463010172-1726788731-3100462634-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz
Wykonaj skrypt i podajesz log z usuwania.
4. Użyj AdwCleaner
http://forum.instalki.pl/otl-gmer-silent-runners-sdfix-i-inne-poradnik-t13967-15.html#p139531 z opcji
Usuń i podaj utworzony log.
5. Podaj nowe logi z OTL robione opcją
SkanujKolejność jak podałem.