Komputer się tnie i wyskakują dziwne strony na Google Chrome

Po 1:

Komputer strasznie się tnie od wczoraj skanowałem go dziś CCleaner’em i Anti-Virusem Rising Anti-Virus (nadal skanuje). Komputer był oczyszczany z kurzu 12.01.2014 (Niedziela).

Sprzęt:

Procesor AMD FX- 6100 Six-Core Processor  3.30 GHz

8 GB RAM

64 bity

Win 7 SP 1

Karta Graficzna nie pamiętam 1 GB

Po 2:

Strony na przeglądarce (Google Chrome) same się włączają co 2-5 minut jest to bardzo denerwujące (włącza się tu już od 1 miesiąca) nwm co zrobić pomóżcie.

Google Chrome startuje z ask search.com czy coś takiego.

Wstaw logi z OTL http://forum.dobreprogramy.pl/temat/402063-analiza-i-dezynfekcja-zestaw-narz%C4%99dzi-nieingerencyjnych/ i czekaj na pomoc fachowców.

rozwiń skrót OTL po jestem nieogarem troszke :smiley:

xProblematycznYx , zapoznaj się, proszę, z tym tematem, a następnie - korzystając z przycisku Edytuj (na dole pierwszego posta po prawej stronie) i opcji Użyj pełnego edytora - popraw tytuł wątku tak, by mówił konkretnie o problemie. Poprawnie zatytułowany wątek zwiększa szansę na uzyskanie szybkiej pomocy. Zignorowanie tej prośby będzie skutkować przeniesieniem tematu do kosza.

Przecież grabkamy podał linka - jak w niego wejdziesz, wszystkiego się dowiesz.

Pozdrawiam,

Dimatheus

A może mi ktoś powiedzieć o co chodzie że te strony się same otwierają ?

Jak dasz logi to dostaniesz odpowiedź.

file:///C:/Users/Jenga/Desktop/OTL.Txt

file:///C:/Users/Jenga/Desktop/Extras.Txt

Jak to mamy przeczytać? Logi umieść na wklej .org

http://www.wklej.org/id/1241655/

http://www.wklej.org/id/1241662/

Rekord śmieciowy.Odinstaluj BrowseToSave,Web-Cake 3.00,OptimizerPro,Soearch-NewaTaba,Update Manager for SweetPacks 1.1,Babylon Chrome Toolbar,

Bundled software uninstaller,Discount Dragon,FilesFrog Update Checker,fst_pl_19,fst_pl_7,Movies Toolbar for Chrome (Dist. by Bandoo Media, Inc.),Movies Toolbar for Internet Explorer (Dist. by Bandoo Media, Inc.),Mobogenie,My Web Search (Cursor Mania),nationzoom Browser Protecter,Optimizer Pro v3.0,Search Assistant 1.74,Search Assistant SimpleSpeedy 1.74,ContinueToSave 1.74,SpeedUpMyComputer,Deinstalator Strony V9,Akamai NetSession Interface.Użyj AdwCleaner http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner z funkcji Skan(Szukaj) a następnie Clean(usuń) (w przypadku Visty/Windows7 uruchom z prawokliku jako Administrator).

Pokaż nowy OTL.txt

Już się robi :smiley:

Zrób to co masz do zrobienia i zobaczysz efekt.

ok :smiley:

pousuwałem i reklam nie ma :smiley:

Pokaż nowy OTL.txt

jeszcze ten AdwCleaner nie przeskanował :slight_smile:

Dodane

http://www.wklej.org/id/1241834/

___________________________________________________________________________________________

Proszę korzystać z opcji Edytuj, zamiast pisać post pod postem.

Pozdrawiam,

Dimatheus

Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:

:OTL
SRV - [2013-08-22 07:51:33 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search.ask.com/sr?src=iebgct=dsappid=362systemid=406v=a10781-116apn_uid=4050103051134247apn_dtid=BND406o=APN10645apn_ptnrs=AG6q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCYYYYYYYYPLptnrS=ZCYYYYYYYYPLptb=IBW.gspGte0vE_aapJ55LQind=2012122205n=77ee8c5dpsa=st=sbsearchfor={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search.ask.com/sr?src=iebgct=dsappid=362systemid=406v=a10781-116apn_uid=4050103051134247apn_dtid=BND406o=APN10645apn_ptnrs=AG6q={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.searchingissme.info/?unqvl=23l=1q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6st=17q={searchTerms}barid={476F12F2-C94C-48FA-BEB5-4BC9DC4E7829}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=dsts=1389227628from=tt4uuid=WDCXWD10EARS-00Y5B1_WD-WCAV5W35575655756q={searchTerms}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTerms}affID=122123tt=gc_babsrc=SP_ssmntrId=683F5404A6F27095
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCYYYYYYYYPLptnrS=ZCYYYYYYYYPLptb=IBW.gspGte0vE_aapJ55LQind=2012122205n=77ee8c5dpsa=st=sbsearchfor={searchTerms}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{7BDB6B13-6244-4D09-B7C7-EFCABA2D07AE}: "URL" = http://www.burstfiles.com/cse.html?q={searchTerms}utm_source=lcutm_medium=opensearchutm_campaign=search
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/adlock2/{8A878EC2-B45E-46D5-84CD-2FA86D7A1DF0}?q={searchTerms}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search.ask.com/sr?src=iebgct=dsappid=362systemid=406v=a10781-116apn_uid=4050103051134247apn_dtid=BND406o=APN10645apn_ptnrs=AG6q={searchTerms}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.searchingissme.info/?unqvl=23l=1q={searchTerms}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6st=17q={searchTerms}barid={476F12F2-C94C-48FA-BEB5-4BC9DC4E7829}
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\FDAF807D2EF24225BA8420AF512B7243: "URL" = http://websearch.coolwebsearch.info/?unqvl=19l=1q={searchTerms}
FF - prefs.js..browser.search.defaulturl: "http://websearch.searchingissme.info/?unqvl=23l=1q="
FF - prefs.js..extensions.enabledAddons: m3ffxtbr@mywebsearch.com:1.3
[2012-07-17 07:58:32 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\Jenga\AppData\Roaming\mozilla\Firefox\Profiles\3g6e2zog.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2013-05-05 20:40:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenga\AppData\Roaming\mozilla\Firefox\Profiles\3g6e2zog.default\extensions\ffxtlbr@babylon.com
[2014-01-03 14:26:57 | 000,002,664 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\Ask.xml
[2013-05-18 07:23:59 | 000,006,505 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\babylon.xml
[2013-05-18 07:23:59 | 000,006,505 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\BrowserProtect.xml
[2012-09-12 15:44:09 | 000,002,285 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\burst-files.xml
[2013-05-18 07:24:22 | 000,001,294 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\delta.xml
[2012-12-22 21:04:47 | 000,009,897 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\mywebsearch.xml
[2013-01-30 13:31:15 | 000,003,984 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\sweetim.xml
[2013-06-24 13:03:56 | 000,000,578 | ---- | M] () -- C:\Users\Jenga\AppData\Roaming\mozilla\firefox\profiles\3g6e2zog.default\searchplugins\WebSearch.xml
[2014-01-03 14:26:57 | 000,002,664 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Ask.xml
[2013-05-05 20:38:38 | 000,006,503 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (ccontinnuetosAve) - {285910AB-28F0-1510-CA4C-D3A9C563E2D2} - C:\ProgramData\ccontinnuetosAve\51864a659ff52.dll ()
O2 - BHO: (coonttinnuietosAvue) - {2911D03D-EA6E-3CE5-718B-A901152530F5} - C:\ProgramData\coonttinnuietosAvue\51b198d3596b4.dll ()
O2 - BHO: (DealPly Shopping) - {4B6ACEA2-308A-4876-AD36-57CEC5B4FCC7} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly)
O2 - BHO: (SearchNewTab) - {50BD4484-1273-CF82-CA9F-809D921F3395} - C:\ProgramData\SearchNewTab\519f952e9d72e.dll ()
O2 - BHO: (SearchNewTab) - {54B3F474-B7C3-B327-34BC-2AF99A6955D9} - C:\ProgramData\SearchNewTab\519a8db2ae9ac.dll ()
O2 - BHO: (ccooNttinuetosave) - {5545BB6E-8117-5FA8-8559-54150FC45F97} - C:\ProgramData\ccooNttinuetosave\51b2ecd5e25e1.dll ()
O2 - BHO: (SearchNewTab) - {BB60E2C7-76D5-B305-F9F8-0BE0663CB8CA} - C:\ProgramData\SearchNewTab\51864ab0b3c77.dll ()
O2 - BHO: (coontinueetosavee) - {C4DB4D87-8370-8E93-54FB-4269A0DA9C3A} - C:\ProgramData\coontinueetosavee\519a8da79e479.dll ()
O2 - BHO: (coNtoinauettoosavE) - {DC5062DB-12E1-42A2-0771-8E8FB4B4465E} - C:\ProgramData\coNtoinauettoosavE\51a22287cf5a6.dll ()
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ec2bae47-25af-4ce9-9e78-10627a49c9ea} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [fst_pl_19] File not found
O4 - HKLM..\Run: [fst_pl_7] File not found
O4 - HKU\S-1-5-21-823906149-1270610366-2261379693-1000..\Run: [Akamai NetSession Interface] "C:\Users\Jenga\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKU\S-1-5-21-823906149-1270610366-2261379693-1000..\Run: [MSIDLL] C:\Windows\SysWOW64\rundll32.exe msiygv32.dll,LMamKalSU File not found
O4 - HKU\S-1-5-21-823906149-1270610366-2261379693-1000..\Run: [Scrypt] C:\Users\Jenga\AppData\Roaming\Scrypt\nircmd.exe (NirSoft)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O27:64bit: - HKLM IFEO\bitguard.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\bprotect.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\bpsvc.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\browsemngr.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\browserdefender.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\browsermngr.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\browserprotect.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\browsersafeguard.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\bundlesweetimsetup.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\cltmngsvc.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\delta babylon.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\delta tb.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\delta2.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\deltainstaller.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\deltasetup.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\deltatb.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\deltatb_2501-c733154b.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\iminentsetup.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\protectedsearch.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\rjatydimofu.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\searchprotection.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\snapdo.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\stinst32.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\stinst64.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\sweetimsetup.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\tbdelta.exetoolbar783881609.exe: Debugger - C:\Windows\SysNative\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bitguard.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bprotect.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsemngr.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserdefender.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsermngr.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserprotect.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bundlesweetimsetup.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\cltmngsvc.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\delta babylon.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\delta tb.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\delta2.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltainstaller.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltasetup.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltatb.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltatb_2501-c733154b.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\iminentsetup.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\rjatydimofu.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\snapdo.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\sweetimsetup.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\tbdelta.exetoolbar783881609.exe: Debugger - C:\Windows\SysWow64\tasklist.exe (Microsoft Corporation)
[2014-01-19 12:12:13 | 000,834,832 | ---- | C] (MyWebSearch.com) -- C:\Program Files (x86)\Uninstall Fun Web Products.dll
[2014-01-19 11:22:00 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-01-18 22:50:23 | 000,000,000 | ---D | C] -- C:\Users\Jenga\AppData\Roaming\Scrypt
[2013-09-24 08:30:57 | 000,365,568 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\000245D5.exe
[2013-09-20 15:20:25 | 000,361,984 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\00A7F04A.exe
[2013-09-20 14:20:21 | 000,361,984 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0070F181.exe
[2013-09-20 13:20:16 | 000,361,984 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0039EF8D.exe
[2013-09-20 12:20:11 | 000,361,984 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0002EDA8.exe
[2013-09-13 19:39:53 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\03B8674D.exe
[2013-09-13 18:39:49 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0381697E.exe
[2013-09-13 07:23:11 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0115EDAD.exe
[2013-09-13 06:23:09 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\00DEF74D.exe
[2013-09-13 05:23:07 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\00A7FFE4.exe
[2013-09-13 04:23:04 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0071088A.exe
[2013-09-13 03:23:02 | 000,362,496 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\003A0EA1.exe
[2013-09-07 16:31:33 | 000,297,472 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\01F03655.exe
[2013-09-07 09:31:28 | 000,297,472 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\006F9C02.exe
[2013-09-07 08:31:26 | 000,297,472 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0038A4A8.exe
[2013-09-05 19:36:59 | 000,360,960 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\00A68307.exe
[2013-09-05 16:36:55 | 000,360,960 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\0001A6F8.exe
[2013-09-05 09:55:33 | 000,360,960 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\00A66FF4.exe
[2013-09-05 07:55:31 | 000,360,960 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\00388B3F.exe
[2013-08-25 22:28:26 | 000,366,592 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\02C15638.exe
[2013-08-25 20:28:21 | 000,356,864 | ---- | C] () -- C:\Users\Jenga\AppData\Roaming\02536736.exe

:Commands
[emptytemp]

Kliknij Wykonaj skrypt.  Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie. Następnie uruchom OTL ponownie, tym razem kliknij (Skanuj).

Skrypt:

http://www.wklej.org/id/1242306/

OTL:

http://www.wklej.org/id/1242316/

Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:

:OTL
IE - HKU\S-1-5-21-823906149-1270610366-2261379693-1000\..\SearchScopes\FDAF807D2EF24225BA8420AF512B7243: "URL" = http://websearch.coolwebsearch.info/?unqvl=19l=1q={searchTerms}
O2 - BHO: (conotiNuetosave) - {A84D740E-5AC9-B6C6-7221-CCFB330F2D36} - C:\ProgramData\conotiNuetosave\519f95266f596.dll File not found
O2 - BHO: (Show-Password) - {faad048e-33d6-4151-8988-532ef9a2d064} - C:\Program Files (x86)\Show-Password\150.dll File not found
O4 - HKLM..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe File not found
[2014-01-19 17:17:00 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\bench-sys.job
[2014-01-19 17:02:50 | 000,000,372 | ---- | M] () -- C:\Windows\tasks\PC SpeedUp Service Deactivator.job
[2014-01-19 16:35:08 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\bench-Updater removing.job
[2014-01-19 16:34:47 | 000,000,404 | ---- | M] () -- C:\Windows\tasks\Show-Password Update.job

:Commands
[emptytemp]

Kliknij Wykonaj skrypt.

Przeskanuj progr.Malwarebytes Anti-Malware http://www.malwarebytes.org/products/malwarebytes_free/

Nie dodawać tu już OTL?