Odinstaluj:
McAfee Security Scan Plus
SweetIM for Messenger 3.7
Internet Explorer Toolbar 4.6 by SweetPacks
Update Manager for SweetPacks 1.0
Wykonaj skrypt w OTL:
:OTL
PRC - [2014-02-26 22:02:16 | 000,729,600 | ---- | M] () -- c:\ProgramData\SafeSoft\WS-Booster\WS-Booster.exe
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q= {searchTerms}&barid={67A1CC60-D1D5-11E1-8379-50E549D812B5}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.buenosearch.com/?babsrc=HP_ss&mntrId=C2A550E549D812B5&affID=128235&tsp=5159
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://www.buenosearch.com/?q= {searchTerms}&babsrc=SP_ss&mntrId=C2A550E549D812B5&affID=128235&tsp=5159
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q= {searchTerms}&barid={67A1CC60-D1D5-11E1-8379-50E549D812B5}
FF - prefs.js..browser.startup.homepage: "http://www.wp.pl/"
FF - prefs.js..extensions.6yjelR.scode: "(function(){try{var url=(window.self.location.href
FF - prefs.js..extensions.enabledAddons: ext%40MediaViewV1alpha6311.net:1.1
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ext@MediaViewV1alpha6311.net: C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6311\ff [2014-03-04 07:38:45 | 000,000,000 | ---D | M]
[2012-12-09 20:41:04 | 000,000,000 | ---D | M] (Complitly - Speed up your search with your personal search suggestions tool) -- C:\Users\Właściciel\AppData\Roaming\mozilla\Firefox\Profiles\b4gmeu2p.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2012-09-19 16:04:15 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\Właściciel\AppData\Roaming\mozilla\Firefox\Profiles\b4gmeu2p.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2014-02-26 22:03:23 | 000,000,000 | ---D | M] (YoutubeAdblocker) -- C:\Users\Właściciel\AppData\Roaming\mozilla\Firefox\Profiles\b4gmeu2p.default\extensions\aaoidn-iiuu@eyxskza.co.uk
[2014-02-26 22:03:23 | 000,000,000 | ---D | M] (waebbseave) -- C:\Users\Właściciel\AppData\Roaming\mozilla\Firefox\Profiles\b4gmeu2p.default\extensions\etqyaea@bwt-aoy.com
[2014-03-06 19:06:33 | 000,000,000 | ---D | M] (NNeaXtCoUUp) -- C:\Users\Właściciel\AppData\Roaming\mozilla\Firefox\Profiles\b4gmeu2p.default\extensions\nemasjaaous@jwg-qtq.net
[2014-03-06 15:01:06 | 000,000,000 | ---D | M] (MiNiMumPrice) -- C:\Users\Właściciel\AppData\Roaming\mozilla\Firefox\Profiles\b4gmeu2p.default\extensions\uyi-ii@iiaobmbwpk.net
[2014-03-06 19:24:19 | 000,957,290 | ---- | M] () (No name found) -- C:\Users\Właściciel\AppData\Roaming\mozilla\firefox\profiles\b4gmeu2p.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013-01-06 16:19:29 | 000,190,000 | ---- | M] () (No name found) -- C:\Users\Właściciel\AppData\Roaming\mozilla\firefox\profiles\b4gmeu2p.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2012-10-31 19:24:50 | 000,002,536 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\mozilla\firefox\profiles\b4gmeu2p.default\searchplugins\browsemngr.xml
[2014-02-15 14:04:17 | 000,006,226 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\mozilla\firefox\profiles\b4gmeu2p.default\searchplugins\buenosearch.xml
[2012-09-13 17:05:24 | 000,002,519 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\mozilla\firefox\profiles\b4gmeu2p.default\searchplugins\Search_Results.xml
[2012-07-19 20:10:36 | 000,003,915 | ---- | M] () -- C:\Users\Właściciel\AppData\Roaming\mozilla\firefox\profiles\b4gmeu2p.default\searchplugins\sweetim.xml
[2014-03-04 07:38:45 | 000,000,000 | ---D | M] (Media View) -- C:\PROGRAM FILES (X86)\MEDIAVIEWV1\MEDIAVIEWV1ALPHA6311\FF
O2:
64bit: - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Właściciel\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen)
O2:
64bit: - BHO: (MiNiMumPrice) - {29C15817-3424-359C-CC83-DA364B5ADF57} - C:\ProgramData\MiNiMumPrice\g.x64.dll ()
O2:
64bit: - BHO: (NNeaXtCoUUp) - {DD8CA56B-1E7F-30F6-E7BD-E6AB6C6FE58D} - C:\Program Files (x86)\NNeaXtCoUUp\RKRxxoOz.x64.dll ()
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Właściciel\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (MiNiMumPrice) - {29C15817-3424-359C-CC83-DA364B5ADF57} - C:\ProgramData\MiNiMumPrice\g.dll ()
O2 - BHO: (NNeaXtCoUUp) - {DD8CA56B-1E7F-30F6-E7BD-E6AB6C6FE58D} - C:\Program Files (x86)\NNeaXtCoUUp\RKRxxoOz.dll ()
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKLM..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe File not found
O4 - HKLM..\Run: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe File not found
O4 - HKCU..\Run: [NextLive] C:\Users\Właściciel\AppData\Roaming\newnext.me\nengine.dll (NewNextDotMe)
O20:
64bit: - AppInit_DLLs: (C:\PROGRA~2\WS-BOO~1\ASSIST~2.DLL) - C:\PROGRA~2\WS-BOO~1\ASSIST~2.DLL ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~2\ws-boo~1\assist~1.dll) - c:\progra~2\ws-boo~1\assist~1.dll ()
[2014-03-06 19:00:25 | 000,000,000 | ---D | C] -- C:\ProgramData\NNeaXtCoUUp
[2014-03-06 19:00:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NNeaXtCoUUp
[2014-03-06 15:01:05 | 000,000,000 | ---D | C] -- C:\ProgramData\MiNiMumPrice
[2014-03-04 07:38:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MediaViewV1
[2014-02-26 22:02:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SafeSoft
[2014-02-26 22:02:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WS-Booster
[2014-02-26 22:02:00 | 000,000,000 | ---D | C] -- C:\ProgramData\YoutubeAdblocker
[2014-02-26 22:01:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YoutubeAdblocker
[2014-02-26 22:01:54 | 000,000,000 | ---D | C] -- C:\ProgramData\weBsavue
[2014-02-26 22:01:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\weBsavue
[2014-02-26 22:01:54 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\Packages
[2014-02-26 22:01:50 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\Torch
[2014-02-26 22:01:50 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\Comodo
[2014-02-26 22:01:50 | 000,000,000 | ---D | C] -- C:\ProgramData\1c1983ff73407b10
[2014-02-26 22:01:04 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2014-02-15 14:04:54 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\SwvUpdater
[2014-02-15 14:04:51 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\.android
[2014-02-15 14:04:49 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Roaming\newnext.me
[2014-02-15 14:04:49 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\Documents\Mobogenie
[2014-02-15 14:04:49 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\Mobogenie
[2014-02-15 14:04:49 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\genienext
[2014-02-15 14:04:49 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Local\cache
[2014-02-15 14:04:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobogenie
[2014-02-15 14:04:02 | 000,000,000 | ---D | C] -- C:\Users\Właściciel\AppData\Roaming\YourFileDownloader
[2014-02-26 22:02:16 | 000,000,446 | -H-- | C] () -- C:\Windows\tasks\WS-Booster-S-46480778.job
[2014-02-15 14:04:54 | 000,000,376 | ---- | C] () -- C:\Windows\tasks\AmiUpdXp.job
Wykonaj:
http://support.mozilla.org/pl/kb/przywracanie-domyslnych-ustawien-firefoksa-latwe-r
Zrob pelny skan przy pomocy Mbam:
http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
oraz
http://ftp.drweb.com/pub/drweb/cureit/launch.exe
Po wykonaniu daj nowy log z OTL, ze skanowania.