odinstaluj:
"OPSWAT Toolbar" = OPSWAT Toolbar
"Quero Toolbar_is1" = Quero Toolbar 7 Build XP, 2000
i jeśli nie znasz to :
"Update Detector" = Update Detector 1.7.0.28
zostaw sobie CCleaner'a z tego zestawu;
Argente - Registry Cleaner 3.1.0.1
CCleaner
Wise Disk Cleaner 7.73
Wise Registry Cleaner 7.62
SlimCleaner
Katerin napisał(a):Chyba nie wszystko usunęłam do dziś, bo wciąż mam komunikat o wielu antywirusach.
możesz pokazać ten komunikat?
Uruchom OTL i w sekcji
własne opcje skanowania / skrypt wklej:
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\..\URLSearchHook: {930e0b10-6818-4828-86b0-07d60af809b6} - C:\Program Files\OPSWAT\prxtbOPSW.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://home.myplaycity.com/results.php?category=web&s={searchTerms}
IE - HKU\S-1-5-21-515967899-606747145-725345543-1005\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3223346&CUI=UN50547199332598180
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3223346&SearchSource=2&CUI=UN31324550791688325&q="
[2012-10-25 07:34:54 | 000,001,999 | ---- | M] () -- C:\Documents and Settings\Domowy\Dane aplikacji\Mozilla\Firefox\Profiles\yfitr7pz.default\searchplugins\myplaycity.xml
[2012-12-02 17:04:16 | 000,003,621 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012-11-19 12:54:10 | 000,003,269 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Web Search.xml
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O3 - HKLM\..\Toolbar: (no name) - {68FF9E0F-2E96-4467-87FA-1A8B9734C7E7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
[2013-02-10 16:00:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2013-02-10 15:59:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Norton
[2013-02-10 15:59:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\NortonInstaller
[2013-02-06 21:55:43 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2013-02-06 21:51:29 | 000,000,000 | ---D | C] -- C:\Program Files\opswatutilities
[2013-02-13 12:42:52 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\KsafeDelay.job
[2013-02-13 12:42:23 | 000,000,332 | ---- | M] () -- C:\WINDOWS\tasks\Protected Search.job
[2013-02-12 19:20:54 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\AutoKMS.job
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:58A5270D
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A29E7570
:Commands
[emptytemp]
Kliknij
wykonaj skrypt. I potwierdź reset komputera .
Użyj
AdwCleaner i kliknij w nim
Usuń (w przypadku Visty/Windows7 uruchom z prawokliku jako Administrator)
Pokaż raport z niego
Następnie uruchamiasz OTL z opcją skanuj. Pokazujesz nowy log OTL.txt
oraz raport z czyszczenia (zawartość notatnika, która otworzyła się po restarcie).