Nie widzę tu żadnej infekcji, no, prawie żadnej, bo jest strumień ADS podpięty pod folder "WINDOWS".
Odinstaluj niepotrzebny C:\Program Files (x86)\
AVG Secure SearchOdinstaluj niepotrzebny C:\Program Files (x86)\
RelevantKnowledgeOdinstaluj niepotrzebny C:\Program Files (x86)\
Ask.comOdinstaluj szkodliwy C:\Program Files (x86)\
Browsers ProtectorUżyj >
Adw-cleaner (aby pobrać kliknij na dużą zieloną strzałkę po prawej).
Kliknij w nim
Usuń Pokaż raport z niego C:\AdwCleaner[S1].txt
Uruchom
OTL i w oknie
Własne opcje skanowania/Skrypt wklej to:
:OTL
@Alternate Data Stream - 24 bytes -> C:\Windows:BEEFEB7FBE01AA74
[2012-04-05 21:36:18 | 000,000,000 | -HSD | M] -- C:\Users\Krecik\AppData\Roaming\.#
[2011-12-07 17:26:23 | 000,000,000 | ---D | M] -- C:\Users\Krecik\AppData\Roaming\OpenCandy
[2012-12-27 15:16:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O4 - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000..\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" File not found
O4 - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [ROC_ROC_NT] C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe ()
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Browsers Protector] C:\Program Files (x86)\Browsers Protector\regmon32.exe ()
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
[2012-11-08 23:04:34 | 000,003,572 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012-04-16 22:33:27 | 000,002,366 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012-12-09 05:31:31 | 000,000,000 | ---D | M] (z) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{6cd09caf-2fff-8022-556e-cfd98ab24442}
[2012-11-05 22:32:07 | 000,189,128 | ---- | M] () (No name found) -- C:\Users\Krecik\AppData\Roaming\mozilla\firefox\profiles\gw93qwzs.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2012-01-03 15:27:44 | 000,002,333 | ---- | M] () -- C:\Users\Krecik\AppData\Roaming\mozilla\firefox\profiles\gw93qwzs.default\searchplugins\askcom.xml
[2012-09-07 19:53:34 | 000,000,792 | ---- | M] () -- C:\Users\Krecik\AppData\Roaming\mozilla\firefox\profiles\gw93qwzs.default\searchplugins\startsear.xml
[2012-04-16 22:20:04 | 000,003,915 | ---- | M] () -- C:\Users\Krecik\AppData\Roaming\mozilla\firefox\profiles\gw93qwzs.default\searchplugins\sweetim.xml
[2010-09-19 12:14:59 | 000,001,196 | ---- | M] () -- C:\Users\Krecik\AppData\Roaming\mozilla\firefox\profiles\gw93qwzs.default\searchplugins\winamp-search.xml
[2012-11-21 23:17:24 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Krecik\AppData\Roaming\mozilla\Firefox\Profiles\gw93qwzs.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012-04-17 15:13:46 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Krecik\AppData\Roaming\mozilla\Firefox\Profiles\gw93qwzs.default\extensions\ffxtlbr@babylon.com
[2012-07-03 18:52:00 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Krecik\AppData\Roaming\mozilla\Firefox\Profiles\gw93qwzs.default\extensions\toolbar@ask.com
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\13.2.0.5 [2012-11-08 23:05:23 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll ()
FF - prefs.js..browser.search.defaultenginename: "error"
FF - prefs.js..browser.search.order.1: "error"
FF - prefs.js..browser.search.selectedEngine: "error"
FF - prefs.js..browser.startup.homepage: "error"
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40babylon.com:1.1.9
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=6be5860e-ea0c-11e0-98d5-0060b306ec0e
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=6be5860e-ea0c-11e0-98d5-0060b306ec0e&q={searchTerms}
IE - HKLM\..\SearchScopes\{5D527354-1DCA-40ef-9DA9-B24C8622F05B}: "URL" = http://startsear.ch/?aff=1&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=6be5860e-ea0c-11e0-98d5-0060b306ec0e
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://startsear.ch/?aff=1
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{0388404D-6072-4CEB-B521-8F090FEAEE57}: "URL" = http://klit.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.3.0&install_country=PL&install_date=20111010&user_guid=BC5312C949B0443E8C724DDB89F6DCAB&machine_id=8c3724bde982f9898bf1ec2331e54cfb&browser=IE&os=win&os_version=6.1-x64-SP1&iesrc={referrer:source}
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=6be5860e-ea0c-11e0-98d5-0060b306ec0e&q={searchTerms}
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{100E4F0B-14BE-45E0-A39F-6317A565F22A}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111304&tt=171011_prot~171011_prot&babsrc=SP_ss&mntrId=9074203d0000000000000060b306ec0e
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=253B4F0A-5772-4DB3-B589-C27E0E3C6B73&apn_sauid=8FCE099A-1BF6-4B08-A990-AF774263CE39
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{5D527354-1DCA-40ef-9DA9-B24C8622F05B}: "URL" = http://startsear.ch/?aff=1&q={searchTerms}
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={BD5A1087-6B56-49FA-AD59-15AF437BAAA6}&mid=bfbbfdaae72045f998d0ef3f909d8ada-3406cff75a240b9dd4ddebbb1b23e33059e889ce&lang=pl&ds=ik011&pr=&d=2012-09-23 12:31:13&v=12.2.5.34&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-3946485956-1001182806-2361197542-1000\..\SearchScopes\{EACF0932-B47E-4189-8A8E-D2DEC65F0514}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=253B4F0A-5772-4DB3-B589-C27E0E3C6B73&apn_sauid=8FCE099A-1BF6-4B08-A990-AF774263CE39
DRV:64bit: - [2012-11-08 23:04:22 | 000,030,568 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
SRV - [2012-11-08 23:04:22 | 000,711,112 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe -- (vToolbarUpdater13.2.0)
SRV - [2012-08-31 20:50:27 | 000,111,664 | ---- | M] (TMRG, Inc.) [Auto | Running] -- C:\Program Files (x86)\RelevantKnowledge\rlservice.exe -- (RelevantKnowledge)
MOD - [2012-11-08 23:04:22 | 000,997,320 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2012-11-08 23:04:22 | 000,566,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\13.2.0\avgdttbx.dll
MOD - [2012-11-08 23:04:22 | 000,134,600 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\SiteSafety.dll
:Commands
[emptytemp]
Kliknij w
Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.