:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 515 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A8ADE5D8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer.com/rdr.aspx?b=ACA ... 5w4481t27p
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACA ... 5w4481t27p
IE - HKLM\..\URLSearchHook: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files (x86)\Ashampoo_PO\tbAsha.dll (Conduit Ltd.)
FF - prefs.js..browser.search.defaultthis.engineName: "Ashampoo US Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2481032&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Ashampoo US Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
[2010/03/14 22:08:47 | 000,000,000 | ---D | M] (Ashampoo PO Toolbar) -- C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\bktv3j3l.default\extensions\{d43723ae-1ae1-4a25-a6a4-bf0929273cab}
[2010/04/06 19:09:14 | 000,000,000 | ---D | M] -- C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\bktv3j3l.default\extensions\DTToolbar@toolbarnet.com
[2010/03/15 03:01:50 | 000,000,000 | ---D | M] -- C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\bktv3j3l.default\extensions\toolbar@ask.com
[2010/06/17 22:23:47 | 000,000,000 | ---D | M] (Ashampoo US Toolbar) -- C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\od3zs6av.default\extensions\{124d001a-bdcb-472f-aa59-bbe7e4bc3204}
[2010/06/08 11:35:22 | 000,000,925 | ---- | M] () -- C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\od3zs6av.default\searchplugins\conduit.xml
O2 - BHO: (no name) - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ashampoo PO Toolbar) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files (x86)\Ashampoo_PO\tbAsha.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ashampoo PO Toolbar) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files (x86)\Ashampoo_PO\tbAsha.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O13 - gopher Prefix: missing
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - Reg Error: Key error. File not found
:files
C:\Windows\tasks\{236B8EA1-2D6D-4E0F-BE2C-641172D766CC}.job
C:\Windows\tasks\{6AD3627C-9DC6-4641-9B8D-E5544634363C}.job
C:\Windows\tasks\{718E4052-0981-4C91-B908-A7E905A2E543}.job
C:\Windows\tasks\{C9D8AB89-E36E-49A9-AAF1-797021FFF41E}.job
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Users\Roman\AppData\Roaming\inst.exe
C:\Users\Roman\AppData\Roaming\inst.exe
C:\Windows\jestertb.dll
C:\ProgramData\ezsidmv.dat
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d43723ae-1ae1-4a25-a6a4-bf0929273cab}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}]
:COMMANDS
[emptytemp]
[EMPTYFLASH]
[reboot]
Tak toto tam nakopíruju do toho spodního rámečku OTL a kliknu na Opravit, dole pak běhá zelený proužek a pak když to skončí, tak mi to poručí restartovat pc, ale nyní si uvědomuji, že na to Opravit musím kliknout 2x, napoprvé se nic neděje a navíc tam má 2 možnosti, tu co jsi mi řekla, Pro všechny uživatela a pod tím je ještě Pro 64 bitové OS, já mám 64 bitový OS, ale označím ten Por všechny.