Logi.
Uruchom OTL -> w oknie Własne opcje skanowania/skrypt wklej:
:OTL
IE - HKU\S-1-5-21-842925246-1614895754-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Dostępne tylko dla zarejestrowanych użytkowników{979CDB61-D9C1-4C5C-8895-0073A0887D41}&mid=2ac67468652347d0a425bdb90f4dcd18-9836c45af29b8910c1f7085f0cb63819b1743bd4&lang=pl&ds=xn011&pr=sa&d=2012-11-20 15:46:52&v=13.2.0.4&sap=hp
IE - HKU\S-1-5-21-842925246-1614895754-682003330-1004\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-842925246-1614895754-682003330-1004\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{979CDB61-D9C1-4C5C-8895-0073A0887D41}&mid=2ac67468652347d0a425bdb90f4dcd18-9836c45af29b8910c1f7085f0cb63819b1743bd4&lang=pl&ds=xn011&pr=sa&d=2012-11-20 15:46:52&v=13.2.0.4&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-842925246-1614895754-682003330-1004\..\SearchScopes\{B15DE3AE-ED95-4e6e-A51E-1A93965E54B2}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4067623346
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid={979CDB61-D9C1-4C5C-8895-0073A0887D41}&mid=2ac67468652347d0a425bdb90f4dcd18-9836c45af29b8910c1f7085f0cb63819b1743bd4&lang=pl&ds=xn011&pr=sa&d=2012-11-20 15:46:52&v=13.2.0.4&sap=ku&q="
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
[2012-11-20 15:46:38 | 000,003,546 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
[2012-11-20 15:47:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\AVG Secure Search
[2012-11-20 15:47:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search
[2012-11-20 15:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Justyna\Dane aplikacji\AVG Secure Search
[2012-11-20 15:46:49 | 000,026,984 | ---- | C] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys
[2012-11-20 15:46:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2012-11-15 00:03:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\TEMP
:Files
RECYCLER /alldrives
C:\WINDOWS\tasks\*.*
C:\Program Files\Google\Update
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[clearallrestorepoints]
[emptytemp]
Klikasz Wykonaj skrypt. Dajesz log z usuwania. Następnie podajesz nowe logi z OTL.