wejdz w tryb awaryjny i usun to w hijacku(napewno bedzie wiecej, ale narazie zobaczmy to):
O4 - HKLM\..\Run: [Microsoft Inet Xp..] teekids*****
O23 - Service: Smart Card Updater (SCardUpd) - Unknown owner - C:\WINDOWS\system32\scardupd***** (file missing)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://195.95.218.172/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://195.95.218.172/index.php
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache*****" --ntservice (file missing)
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt (file missing)