odinstaluj:
"uTorrentControl_v2 Toolbar" = uTorrentControl_v2 Toolbar
"Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
Spybot - Search & Destroy
Uruchom OTL i w sekcji
własne opcje skanowania / skrypt wklej:
:OTL
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110823&tt=120912_nocpc_3812_5&babsrc=SP_ss&mntrId=c085dc50000000000000000cf6e3a530
IE - HKCU\..\SearchScopes\{7759AAD6-489C-4C5B-B8ED-FAA52E7E6BEF}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKCU\..\SearchScopes\{90123443-34AD-4634-9E04-D2A26BA03F86}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=A7AE21A6-48F9-4EB8-AF61-C0227788F074&apn_sauid=11E3CC44-2F41-42DA-818F-35D9F0CB3591
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=110823&tt=120912_nocpc_3812_5&babsrc=KW_ss&mntrId=c085dc50000000000000000cf6e3a530&q="
[2012-09-21 21:05:23 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\Morfi\AppData\Roaming\Mozilla\Firefox\Profiles\vi7yblef.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2012-09-22 18:48:50 | 000,000,000 | ---D | M] (DealPly) -- C:\Users\Morfi\AppData\Roaming\Mozilla\Firefox\Profiles\vi7yblef.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012-10-21 13:40:32 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Users\Morfi\AppData\Roaming\Mozilla\Firefox\Profiles\vi7yblef.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012-10-06 11:29:10 | 000,002,299 | ---- | M] () -- C:\Users\Morfi\AppData\Roaming\Mozilla\Firefox\Profiles\vi7yblef.default\searchplugins\askcom.xml
[2012-10-14 11:45:56 | 000,000,905 | ---- | M] () -- C:\Users\Morfi\AppData\Roaming\Mozilla\Firefox\Profiles\vi7yblef.default\searchplugins\conduit.xml
[2012-09-20 19:57:56 | 000,002,362 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
[2012-10-21 20:38:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda Security
:Commands
[resethosts]
[emptytemp]
Kliknij
wykonaj skrypt. I potwierdź reset komputera .
Użyj
AdwCleaner i kliknij w nim
Delete (w przypadku Visty/Windows7 uruchom z prawokliku jako Administrator)
Pokaż raport z niego
Następnie uruchamiasz OTL z opcją skanuj. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia (zawartość notatnika, która otworzyła się po restarcie).