1) Uruchom
OTL i w oknie
Własne opcje skanowania/Skrypt wklej to:
:OTL
[2013/03/20 12:45:33 | 000,000,153 | ---- | C] () -- C:\ProgramData\8973746.reg
[2013/03/20 12:45:33 | 000,000,060 | ---- | C] () -- C:\ProgramData\8973746.bat
[2013/03/20 12:45:19 | 000,001,041 | ---- | C] () -- C:\Users\Kamil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2013/03/20 12:45:13 | 095,023,320 | ---- | C] () -- C:\ProgramData\8973746.pad
[2013/03/20 12:45:12 | 000,102,400 | ---- | C] () -- C:\Users\Kamil\6473798.dll
O20 - HKLM Winlogon: Shell - (C:\PROGRA~3\8973746.bat) - C:\ProgramData\8973746.bat ()
O20 - HKLM Winlogon: GinaDLL - (C:\Windows\SYSTEM32\RtlGina\RtlGina.DLL) - File not found
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found
O4 - HKU\S-1-5-21-3467520611-1501154299-2061691939-1001..\Run: [ChomikBox] C:\Program Files (x86)\ChomikBox\ChomikBox.exe File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3467520611-1501154299-2061691939-1001\..\Toolbar\WebBrowser: (no name) - {B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14} - No CLSID value found.
O3 - HKU\S-1-5-21-3467520611-1501154299-2061691939-1001\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121013014143.dll File not found
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20121013014143.dll File not found
[2012/10/21 19:03:24 | 000,000,935 | ---- | M] () -- C:\Users\Kamil\AppData\Roaming\mozilla\firefox\profiles\m3hu4vu3.default\searchplugins\conduit.xml
IE - HKU\S-1-5-21-3467520611-1501154299-2061691939-1001\..\URLSearchHook: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - No CLSID value found
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[-HKEY_USERS\S-1-5-21-3467520611-1501154299-2061691939-1001\Software\Microsoft\Internet Explorer\SearchScopes\{92A0F7C5-2955-450A-AC47-0960F5EE56EE}]
:Commands
[emptytemp]
Kliknij w
Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.
2) Zainstaluj nowszą, bezpieczniejszą wersję Javy:
>
http://www.oracle.com/technetwork/java/javase/downloads/jre7-downloads-1880261.html (wybierz: Windows x86 Offline)
Być może trzeba też zainstalować nowszą wersję Javy 64 bit >
http://java.com/pl/download/faq/java_win64bit.xml.