Crazy Score Ads - jak usunąć?

Prosiłbym o pomoc w usunięciu

 

 

FRST

http://wklej.org/id/1721770/

 

Addition

http://wklej.org/id/1721771/

 

Odinstaluj Akamai NetSession Interface.Otwórz notatnik systemowy i wklej:

HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-4052029431-485474638-3316540699-1001\...\Run: [Akamai NetSession Interface] = C:\Users\Dominik\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4052029431-485474638-3316540699-1001\...\Policies\Explorer: []
HKU\S-1-5-18\...\RunOnce: [{90150000-006E-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-0016-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-012B-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-0018-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-001A-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-0090-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-001B-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-00A1-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-0019-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-00BA-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-0015-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
HKU\S-1-5-18\...\RunOnce: [{90150000-0044-0415-1000-0000000FF1CE}] = C:\Windows\system32\cmd.exe /C del "C:\ProgramData\Microsoft Help\Rgstrtn.lck" /Q /A:H
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
HKU\S-1-5-21-4052029431-485474638-3316540699-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
HKU\S-1-5-21-4052029431-485474638-3316540699-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
FF Homepage: hxxp://do-search.com/?type=hpts=1432581266z=6e8d6fc200b54accc136371g1z2c9o4w2b4gbo8qdwfrom=coruid=ST9750420AS_6WS2GW9RXXXX6WS2GW9R
FF Extension: Web Protector - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\nx5uobdj.default\Extensions\{8a167a0d-2593-78be-dffa-baa301a8d989} [2015-05-25]
FF Extension: Crazy Score - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\nx5uobdj.default\Extensions\{57e43d23-8d3b-4b8e-8db3-ab1ea2cb82ad}.xpi [2015-05-25]
CHR Extension: (Crazy Score) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbodcokijpkmonfpjmgdknkodebiejol [2015-05-26]
CHR HKU\S-1-5-21-4052029431-485474638-3316540699-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4052029431-485474638-3316540699-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - http://clients2.google.com/service/update2/crx
OPR Extension: (Crazy Score) - C:\Users\Dominik\AppData\Roaming\Opera Software\Opera Stable\Extensions\hbodcokijpkmonfpjmgdknkodebiejol [2015-05-25]
2015-05-26 11:11 - 2015-05-26 11:11 - 00000000 ____ D () C:\Users\Dominik\Downloads\FRST-OlderVersion
2015-05-25 20:03 - 2015-05-25 20:13 - 00000000 ____ D () C:\Program Files (x86)\WebProtectorPlus
2015-05-25 20:03 - 2015-05-25 20:03 - 00003200 _____ () C:\Windows\System32\Tasks\Web Protector Plus Server
2015-05-25 20:03 - 2015-05-25 20:03 - 00003170 _____ () C:\Windows\System32\Tasks\Web Protector Plus
2015-05-25 20:03 - 2015-05-25 20:03 - 00000000 ____ D () C:\Users\Dominik\AppData\Roaming\WebExtend
2015-05-25 20:03 - 2015-05-25 20:03 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Web Protector Plus
2015-05-25 20:03 - 2015-05-25 20:03 - 00000000 ____ D () C:\Program Files (x86)\WebProtector
2015-05-25 20:03 - 2015-05-25 20:03 - 00000000 ____ D () C:\Program Files (x86)\LiveUpdateWPP
2015-05-25 20:02 - 2015-05-25 20:02 - 00709248 _____ (Installer ) C:\Users\Dominik\Downloads\Codec-Pack-Advanced(12951)-dp.exe
2015-05-25 20:02 - 2015-05-25 20:02 - 00709248 _____ (Installer ) C:\Users\Dominik\Downloads\ALLPlayer(13217)-dp (2).exe
2015-05-25 20:00 - 2015-05-25 20:00 - 00709248 _____ (Installer ) C:\Users\Dominik\Downloads\ALLPlayer(13217)-dp (1).exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.