Infekcji tu żadnej nie widzę.
Do usunięcia sponsorskie śmieci:
1) Odinstaluj szkodliwy
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager.
2) Odinstaluj niepotrzebny
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02.
3) Odinstaluj szkodliwy
"{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}" = Browse2save.
4) Odinstaluj niepotrzebny
"{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}" = Babylon Chrome Toolbar.
5) Odinstaluj niepotrzebny "Akamai" =
Akamai NetSession Interface.
6) Odinstaluj niepotrzebny
"BabylonToolbar" = Babylon toolbar.
7) Odinstaluj niepotrzebny "delta" =
Delta toolbar.
8) Odinstaluj niepotrzebny
"Delta Chrome Toolbar" = Delta Chrome Toolbar.
9) Odinstaluj niepotrzebny
"Optimizer Pro_is1" = Optimizer Pro v3.0.
10) Odinstaluj niepotrzebny
"OptimizerPro1" = OptimizerPro111) Odinstaluj niepotrzebny
"PC Performer_is1" = PC Performer.
12) Odinstaluj niepotrzebny "Softonic" =
Softonic toolbar on IE.
12) Odinstaluj szkodliwy
"SP_48c708f2" = BrowseToSave 1.74.
13) Odinstaluj niepotrzebny
"SP_b0285714" = Search Assistant WebSearch 1.7414) Odinstaluj niepotrzebny
"StartNow Toolbar" = StartNow Toolbar.
15) Odinstaluj szkodliwy
"TMIPC" = Tibia MULTI-ip changer.
16) Odinstaluj niepotrzebny
"Funmoods Web Search" = Funmoods Web Search.
17) Odinstaluj niepotrzebny
"AVG Secure Search" = AVG Security Toolbar.
18) Użyj >
Adw-cleaner (aby pobrać kliknij na dużą zieloną strzałkę po prawej).
Kliknij w nim
Usuń Pokaż raport z niego C:\AdwCleaner[S1].txt
19) Uruchom
OTL i w oknie
Własne opcje skanowania/Skrypt wklej to:
:OTL
[2012-10-05 07:56:33 | 000,000,000 | -HSD | M] -- C:\Users\Patryk\AppData\Roaming\wyUpdate AU
O4 - HKLM..\Run: [Adobe] C:\ProgramData\Adobe\8FD51C.vbe ()
[2012-08-24 09:46:54 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\StartNow Toolbar
[2011-10-23 10:19:59 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Babylon
[2012-11-12 15:38:29 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\BabylonToolbar
[2012-08-11 15:49:43 | 000,302,425 | ---- | C] () -- C:\Users\Patryk\AppData\Local\funmoods-speeddial.crx
[2012-08-11 15:49:42 | 000,031,470 | ---- | C] () -- C:\Users\Patryk\AppData\Local\funmoods.crx
[2013-03-10 11:11:26 | 000,001,008 | ---- | M] () -- C:\Users\Public\Desktop\PC Performer.lnk
[2013-03-10 11:08:54 | 000,775,664 | ---- | M] () -- C:\Users\Patryk\Desktop\DeltaTB.exe
[2013-03-24 15:02:56 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\PC Performer_DEFAULT.job
[2013-03-25 00:26:31 | 000,000,414 | -H-- | M] () -- C:\Windows\tasks\OptimizerPro1UpdaterTask{5E55010F-18F9-48D3-BC2E-A52D31FEC1DC}.job
[2013-03-10 11:12:55 | 000,000,000 | ---D | C] -- C:\Program Files\Delta
[2013-03-10 11:12:53 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\Delta
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261125~1.80\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.6.1125.80\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.9.2)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O4 - Startup: C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CandyMT2.lnk = File not found
O4 - HKCU..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Patryk\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [btcl] C:\Users\Patryk\AppData\Roaming\dist10\btcl.exe ()
O2 - BHO: (Search Assistant BHO) - {14d02517-c8be-4735-a344-3c8366c77aa0} - C:\Program Files\MyWebFace_5a\bar\1.bin\5aSrcAs.dll (MindSpark)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (Browse2save) - {73E2D8A2-E1EA-BB1A-4A36-- C:\ProgramData\Browse2save\511799aba6069.dll ()
O2 - BHO: (Download and Sa Class) - {84DCBE19-A1E9-DCE5-66FC-3915DC78CA7A} - C:\ProgramData\Download and Sa\5073cb38d5dd8.ocx ()
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Toolbar BHO) - {b1df253a-9e7a-480d-b6a5-7a435b520dbb} - C:\Program Files\MyWebFace_5a\bar\1.bin\5abar.dll (MindSpark)
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
O2 - BHO: (Softonic Helper Object) - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files\Softonic\Softonic\1.5.24.3\bh\Softonic.dll (Softonic.com)
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Hyperionics DB Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Hyperionics DB Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\Hyperionics DB Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Softonic Toolbar) - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\Softonic\1.5.24.3\SoftonicTlbr.dll (Softonic.com)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O4 - HKLM..\Run: [MyWebFace Search Scope Monitor] C:\Program Files\MyWebFace_5a\bar\1.bin\5aSrchMn.exe (MindSpark)
O4 - HKLM..\Run: [MyWebFace_5a Browser Plugin Loader] C:\Program Files\MyWebFace_5a\bar\1.bin\5abrmon.exe (VER_COMPANY_NAME)
[2012-12-01 16:49:15 | 000,000,402 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
[2013-02-18 14:45:38 | 000,003,714 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2013-03-10 11:12:37 | 000,006,484 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2013-03-08 06:36:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\updated\extensions\ffxtlbr@babylon.com
[2013-02-10 13:33:24 | 000,000,000 | ---D | M] (Browse2save) -- C:\Users\Patryk\AppData\Roaming\Mozilla\Firefox\Profiles\9f1wgpb4.default-1359671758395\Extensions\511799aba5ed8@511799aba5f12.com
[2013-03-10 11:12:56 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Patryk\AppData\Roaming\Mozilla\Firefox\Profiles\9f1wgpb4.default-1359671758395\Extensions\ffxtlbr@delta.com
[2013-03-10 11:12:59 | 000,001,294 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\Mozilla\Firefox\Profiles\9f1wgpb4.default-1359671758395\searchplugins\delta.xml
[2013-02-10 13:32:56 | 000,000,626 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\Mozilla\Firefox\Profiles\9f1wgpb4.default-1359671758395\searchplugins\WebSearch.xml
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\5affxtbr@MyWebFace_5a.com: C:\Program Files\MyWebFace_5a\bar\1.bin [2012-03-03 21:44:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.2.0.1 [2013-02-18 14:45:37 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{0F827075-B026-42F3-885D-98981EE7B1AE}: C:\ProgramData\Browser Manager\2.6.1125.80\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2013-03-07 23:14:52 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@Webzen.com/NPBrowserExt: File not found
FF - HKLM\Software\MozillaPlugins\@MyWebFace_5a.com/Plugin: C:\Program Files\MyWebFace_5a\bar\1.bin\NP5aStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll ()
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "WebSearch"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "WebSearch"
FF - prefs.js..browser.startup.homepage: "http://websearch.good-results.info/?pid=34&r=2013/02/10&hid=2374264330&lg=EN&cc=PL"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://websearch.good-results.info/?pid=34&r=2013/02/10&hid=2374264330&lg=EN&cc=PL&l=1&q="
FF - prefs.js..browser.startup.homepage: "http://www.delta-search.com/?affID=119535&babsrc=HP_ss&mntrId=826a342300000000000000ff68a295e1"
:Reg
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{739B008A-6A53-45A0-A8AF-762DFAF74F2E}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{398AEBEC-B5B8-4783-8214-916724F5AF26}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3946A2EB-FB7C-E490-C9B6-05ACC541D042}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
:Commands
[emptytemp]
Kliknij w
Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.
20) Zainstaluj nowszą, bezpieczniejszą wersję Javy:
>
http://www.oracle.com/technetwork/java/javase/downloads/jre7-downloads-1880261.html (wybierz: Windows x86 Offline)
.
Autor postu otrzymał pochwałę