najpierw kliknij na SZUKAJ, a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ, to kliknij na niego.
.txt.
:OTL
SRV - [2014-11-28 12:09:11 | 000,484,352 | ---- | M] (Fuyu LIMITED) [Auto | Running] -- C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -- (WindowsMangerProtect)
SRV - [2014-11-28 12:05:23 | 000,068,608 | ---- | M] (globalUpdate) [On_Demand | Stopped] -- C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdatem)
SRV - [2014-11-28 12:05:23 | 000,068,608 | ---- | M] (globalUpdate) [Auto | Stopped] -- C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdate)
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1417172844&from=obw&uid=ST1000LM024XHN-M101MBB_S32HJ9CF500922&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1417172844&from=obw&uid=ST1000LM024XHN-M101MBB_S32HJ9CF500922&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1417172844&from=obw&uid=ST1000LM024XHN-M101MBB_S32HJ9CF500922&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1417172844&from=obw&uid=ST1000LM024XHN-M101MBB_S32HJ9CF500922&q={searchTerms}
IE - HKU\S-1-5-21-1890577046-1904970765-735041783-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1417172844&from=obw&uid=ST1000LM024XHN-M101MBB_S32HJ9CF500922&q={searchTerms}
IE - HKU\S-1-5-21-1890577046-1904970765-735041783-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1417172844&from=obw&uid=ST1000LM024XHN-M101MBB_S32HJ9CF500922&q={searchTerms}
FF - prefs.js..extensions.enabledAddons: VJKPXI46039420%40JMZUIOB85844870.com:0.95.43
FF - prefs.js..extensions.enabledAddons: EKJVVD29402736%40EUOWKG84927606.com:0.95.54
[2014-11-28 12:03:59 | 000,000,000 | ---D | M] (Shopper-Pro) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
[2014-11-28 12:05:18 | 000,000,000 | ---D | M] ("Ge-Force") -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com
[2014-11-28 12:05:35 | 000,000,000 | ---D | M] ("Sense") -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\ae44639e-43f2-4cd1-aa80-39d5d2e18fa9@gmail.com
[2014-11-28 12:06:06 | 000,000,000 | ---D | M] ("HQ-Video-Pro-2.1cV28.11") -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\EKJVVD29402736@EUOWKG84927606.com
[2014-11-28 12:03:22 | 000,000,000 | ---D | M] ("SavePass 1.1") -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\VJKPXI46039420@JMZUIOB85844870.com
[2014-11-28 12:05:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData
[2014-11-28 12:05:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData\plugins
[2014-11-28 12:05:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData\userCode
[2014-11-28 12:05:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\ae44639e-43f2-4cd1-aa80-39d5d2e18fa9@gmail.com\extensionData
[2014-11-28 12:05:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\ae44639e-43f2-4cd1-aa80-39d5d2e18fa9@gmail.com\extensionData\plugins
[2014-11-28 12:05:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\ae44639e-43f2-4cd1-aa80-39d5d2e18fa9@gmail.com\extensionData\userCode
[2014-11-28 18:10:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\EKJVVD29402736@EUOWKG84927606.com\extensionData
[2014-11-28 12:06:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\EKJVVD29402736@EUOWKG84927606.com\extensionData\plugins
[2014-11-28 18:10:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\EKJVVD29402736@EUOWKG84927606.com\extensionData\userCode
[2014-11-28 18:10:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\VJKPXI46039420@JMZUIOB85844870.com\extensionData
[2014-11-28 18:10:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\VJKPXI46039420@JMZUIOB85844870.com\extensionData\plugins
[2014-11-28 18:10:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\0qzyisfr.default\extensions\VJKPXI46039420@JMZUIOB85844870.com\extensionData\userCode
[2014-10-04 19:45:38 | 000,002,590 | ---- | M] () -- C:\Users\Robert\AppData\Roaming\mozilla\firefox\profiles\0qzyisfr.default\searchplugins\ask-web-search.xml
O2:64bit: - BHO: (Ge-Force) - {11111111-1111-1111-1111-110611191111} - C:\Program Files (x86)\Ge-Force\Ge-Force-bho64.dll (iWebar)
O2:64bit: - BHO: (HQ-Video-Pro-2.1cV28.11) - {11111111-1111-1111-1111-110611311163} - C:\Program Files (x86)\HQ-Video-Pro-2.1cV28.11\HQ-Video-Pro-2.1cV28.11-bho64.dll (HQ-VideoV28.11)
O2:64bit: - BHO: (Sense) - {11111111-1111-1111-1111-110611811153} - C:\Program Files (x86)\Sense\Sense-bho64.dll (Object Browser)
O2 - BHO: (Ge-Force) - {11111111-1111-1111-1111-110611191111} - C:\Program Files (x86)\Ge-Force\Ge-Force-bho.dll (iWebar)
O2 - BHO: (HQ-Video-Pro-2.1cV28.11) - {11111111-1111-1111-1111-110611311163} - C:\Program Files (x86)\HQ-Video-Pro-2.1cV28.11\HQ-Video-Pro-2.1cV28.11-bho.dll (HQ-VideoV28.11)
O2 - BHO: (Sense) - {11111111-1111-1111-1111-110611811153} - C:\Program Files (x86)\Sense\Sense-bho.dll (Object Browser)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\S-1-5-21-1890577046-1904970765-735041783-1001\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
[2014-11-29 18:17:28 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Local\AskToolbar
[2014-11-28 12:09:11 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsMangerProtect
[2014-11-28 12:06:08 | 001,524,696 | ---- | C] (HQ-VideoV28.11) -- C:\Users\Robert\AppData\Roaming\VC.exe
[2014-11-28 12:05:39 | 001,524,696 | ---- | C] (Object Browser) -- C:\Users\Robert\AppData\Roaming\GBCL.exe
[2014-11-28 12:05:31 | 002,006,488 | ---- | C] (HQ-VideoV28.11) -- C:\Users\Robert\AppData\Roaming\ADDN.exe
[2014-11-28 12:05:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HQ-Video-Pro-2.1cV28.11
[2014-11-28 12:04:59 | 002,006,488 | ---- | C] (Object Browser) -- C:\Users\Robert\AppData\Roaming\NMVVUY.exe
[2014-11-28 12:04:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sense
[2014-11-28 12:04:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ge-Force
[2014-11-28 12:03:41 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Local\Installer
[2014-11-28 12:03:05 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Local\globalUpdate
[2014-11-28 12:03:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\globalUpdate
[2014-11-09 08:59:28 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\OpenCandy
[2014-12-02 13:24:24 | 000,000,670 | ---- | M] () -- C:\WINDOWS\tasks\78ac693b-53ad-4b07-b298-9a36b208e2b9.job
[2014-12-02 13:24:16 | 000,004,512 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-3.job
[2014-12-02 13:24:11 | 000,001,346 | ---- | M] () -- C:\WINDOWS\tasks\VC.job
[2014-12-02 13:24:07 | 000,004,476 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-4.job
[2014-12-02 13:24:07 | 000,002,464 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-5_user.job
[2014-12-02 13:24:07 | 000,002,464 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-5.job
[2014-12-02 13:24:06 | 000,005,508 | ---- | M] () -- C:\WINDOWS\tasks\6c3eb155-eb50-4015-8423-0e697ee4b304-11.job
[2014-12-02 13:24:06 | 000,004,856 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-4.job
[2014-12-02 13:24:06 | 000,003,796 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-3.job
[2014-12-02 13:24:06 | 000,001,350 | ---- | M] () -- C:\WINDOWS\tasks\GBCL.job
[2014-12-02 13:24:04 | 000,004,826 | ---- | M] () -- C:\WINDOWS\tasks\6c3eb155-eb50-4015-8423-0e697ee4b304-4.job
[2014-12-02 13:24:04 | 000,003,122 | ---- | M] () -- C:\WINDOWS\tasks\6c3eb155-eb50-4015-8423-0e697ee4b304-5_user.job
[2014-12-02 13:24:04 | 000,003,116 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-5_user.job
[2014-12-02 13:24:04 | 000,002,778 | ---- | M] () -- C:\WINDOWS\tasks\6c3eb155-eb50-4015-8423-0e697ee4b304-5.job
[2014-12-02 13:24:04 | 000,001,354 | ---- | M] () -- C:\WINDOWS\tasks\NMVVUY.job
[2014-12-02 13:24:04 | 000,000,966 | ---- | M] () -- C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job
[2014-12-02 13:24:03 | 000,005,202 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-11.job
[2014-12-02 13:24:02 | 000,002,772 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-5.job
[2014-12-02 13:24:02 | 000,002,434 | ---- | M] () -- C:\WINDOWS\tasks\6c3eb155-eb50-4015-8423-0e697ee4b304-2.job
[2014-12-02 13:24:01 | 000,005,502 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-11.job
[2014-12-02 13:24:01 | 000,003,488 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-1.job
[2014-12-02 13:23:59 | 000,002,428 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-2.job
[2014-12-02 13:23:59 | 000,002,128 | ---- | M] () -- C:\WINDOWS\tasks\7fdf0585-15f6-4903-b5f4-3a1556e73c0d-2.job
[2014-12-02 13:23:58 | 000,003,772 | ---- | M] () -- C:\WINDOWS\tasks\6c3eb155-eb50-4015-8423-0e697ee4b304-1.job
[2014-12-02 13:23:56 | 000,003,760 | ---- | M] () -- C:\WINDOWS\tasks\fd74a172-49f3-4b56-9556-083971d5629d-1.job
[2014-12-02 13:23:56 | 000,001,492 | ---- | M] () -- C:\WINDOWS\tasks\7c9378f4-a66b-4392-b4d5-0e7469b13b3f.job
[2014-12-02 00:15:28 | 000,000,970 | ---- | M] () -- C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job
[2014-11-28 12:06:08 | 001,524,696 | ---- | M] (HQ-VideoV28.11) -- C:\Users\Robert\AppData\Roaming\VC.exe
[2014-11-28 12:05:39 | 001,524,696 | ---- | M] (Object Browser) -- C:\Users\Robert\AppData\Roaming\GBCL.exe
[2014-11-28 12:05:31 | 002,006,488 | ---- | M] (HQ-VideoV28.11) -- C:\Users\Robert\AppData\Roaming\ADDN.exe
[2014-11-28 12:04:59 | 002,006,488 | ---- | M] (Object Browser) -- C:\Users\Robert\AppData\Roaming\NMVVUY.exe
[2014-11-25 21:11:05 | 004,443,312 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstalle
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
[-HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
[-HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
[-HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
:Commands
[emptytemp]
. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.