Więc tak.
Zrobiłam wszystko krok po kroku, lecz niestety nie udało mi się znaleźć menedżera dodatków Firefox i menedżera rozszerzeń Google Chrome.
Oto logi, które wygenerowałam:
(niestety nie udało mi się inaczej przesłać loga z punku 1, jak tylko za pomocą serwera)
All processes killed
========== OTL ==========
Service rwinq stopped successfully!
Service rwinq deleted successfully!
C:\Windows\SysNative\rwinq.exe moved successfully.
Error: No service named rwinq was found to stop!
Service\Driver key rwinq not found.
C:\Windows\SysWOW64\rwinq.exe moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E1955163-95BD-4D14-A481-3DE04E67A5BC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E1955163-95BD-4D14-A481-3DE04E67A5BC}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC3D30EF-7582-467E-B464-5F4750E75B7D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CC3D30EF-7582-467E-B464-5F4750E75B7D}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E1955163-95BD-4D14-A481-3DE04E67A5BC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E1955163-95BD-4D14-A481-3DE04E67A5BC}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hxikvsl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft Windows System deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Explorer deleted successfully.
C:\Users\Agata\AppData\Roaming\explorer.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Primary Login deleted successfully.
C:\Users\Public\R-344233-5553-2-32\update32.exe moved successfully.
64bit-Registry delete failed. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Agata\LOCALS~1\Temp\msauaewvv.exe scheduled to be deleted on reboot.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Agata\LOCALS~1\Temp\msauaewvv.exe deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C962D98-7E08-4df4-BC99-060644D7CA60}\ deleted successfully.
========== FILES ==========
C:\Users\Agata\AppData\Roaming\svchost64.exe moved successfully.
C:\Users\Agata\AppData\LocalLow\Microńoft folder moved successfully.
C:\Users\Agata\P-7-78-8964-9648-3874 folder moved successfully.
C:\Users\Public\R-344233-5553-2-32 folder moved successfully.
========== REGISTRY ==========
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\\"Start Page"|"about:blank" /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"|"{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: Agata
->Temp folder emptied: 32625473 bytes
->Temporary Internet Files folder emptied: 34231787 bytes
->Java cache emptied: 5288701 bytes
->FireFox cache emptied: 90277272 bytes
->Google Chrome cache emptied: 283408995 bytes
->Flash cache emptied: 288811 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 310097023 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36045935 bytes
RecycleBin emptied: 508939869 bytes
Total Files Cleaned = 1,241.00 mb
OTL by OldTimer - Version 3.2.53.1 log created on 07102012_170342
Files\Folders moved on Reboot...
File\Folder C:\Users\Agata\AppData\Local\Temp\OICE_A4233992-B59B-48EC-BE33-AD69E92A3AFC.0\8E33285F. not found!
File\Folder C:\Users\Agata\AppData\Local\Temp\etilqs_KQvj7jFl6dgyexWZ2ZmF not found!
File move failed. C:\Users\Agata\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
PendingFileRenameOperations files...
File C:\Users\Agata\AppData\Local\Temp\OICE_A4233992-B59B-48EC-BE33-AD69E92A3AFC.0\8E33285F. not found!
File C:\Users\Agata\AppData\Local\Temp\etilqs_KQvj7jFl6dgyexWZ2ZmF not found!
[2010/01/16 18:55:18 | 000,000,000 | ---- | M] () C:\Users\Agata\AppData\Local\Temp\FXSAPIDebugLogFile.txt : Unable to obtain MD5
Registry entries deleted on Reboot...
64bit-Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Agata\LOCALS~1\Temp\msauaewvv.exe deleted successfully.
FSS.txt
OTL.Txt
AdwCleanerS1.txt