Użyj
Adw-Cleaner http://www.programosy.pl/program,adwcleaner.html
najpierw kliknij na SZUKAJ, a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ, to kliknij na niego.
Daj z tego raport C:\AdwCleaner\AdwCleaner
[S].txt.
Uruchom
OTL i w oknie
Własne opcje skanowania/Skrypt wklej to:
:OTL
SRV - [2014-10-07 18:24:26 | 001,843,736 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe -- (vToolbarUpdater3.2.0)
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
IE - HKU\S-1-5-21-2743163429-1848081243-3276263930-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133
IE - HKU\S-1-5-21-2743163429-1848081243-3276263930-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133
IE - HKU\S-1-5-21-2743163429-1848081243-3276263930-1000\..\SearchScopes\{1E77E124-C82E-40A2-A95B-BD7AEFCEBADE}: "URL" = https://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=888596&p={searchTerms}
IE - HKU\S-1-5-21-2743163429-1848081243-3276263930-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?type=ds&ts=1415132514&from=ild&uid=WDCXWD3200AAJS-00L7A0_WD-WCAV2A67413374133&q={searchTerms}
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\3.2.0\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
O4 - HKU\S-1-5-21-2743163429-1848081243-3276263930-1000..\Run: [Easy-Hide-IP] C:\Program Files\Easy-Hide-IP\easy-hide-ip.exe File not found
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes]
[-HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes]
[-HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes]
[-HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes]
:Commands
[emptytemp]
Kliknij w
Wykonaj Skrypt. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania Skryptem.
Napisz, czy to pomogło?
.
Autor postu otrzymał pochwałę