Odinstaluj:
Bing Bar
Adobe Reader 9, zmien na Foxit
DAEMON Tools Toolbar
Mozilla Firefox 8.0 (x86 pl), zmien na 10.
Norton
Wykonaj skrypt w OTL:
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://qooqlle.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421
FF - prefs.js..browser.startup.homepage: "http://www.qooqlle.com/"
FF - prefs.js..keyword.URL: "http://startsear.ch/?q="
FF - prefs.js..network.proxy.http: "c-66-56-57-136.hsd1.ga.comcast.net"
FF - prefs.js..network.proxy.http_port: 8909
[2011-06-12 10:20:01 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Don Hash\AppData\Roaming\mozilla\Firefox\Profiles\vh47p5di.default\extensions\DTToolbar@toolbarnet.com
[2011-07-30 14:25:50 | 000,002,055 | ---- | M] () -- C:\Users\Don Hash\AppData\Roaming\Mozilla\Firefox\Profiles\vh47p5di.default\searchplugins\daemon-search.xml
[2011-09-10 14:34:27 | 000,001,565 | ---- | M] () -- C:\Users\Don Hash\AppData\Roaming\Mozilla\Firefox\Profiles\vh47p5di.default\searchplugins\web-search.xml
O2:
64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:
64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O4:
64bit: - HKLM..\Run: [ProxyCap] C:\PROGRA~1\Proxy Labs\ProxyCap\pcapui.exe File not found
O4 - HKCU..\Run: [AdobeReader] C:\Users\Don Hash\AppData\Roaming\Microsoft\Windows\reader_sl.exe ()
Daj log z TDSSKiller, zrob skan przy pomocy mbam oraz cureit.