Ad by unisales i wolne ładowanie się stron

Witam,

Odinstaluj McAfee Security Scan Plus.

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.

McAfee usunięte a oto raporty z FRST

Odinstaluj IncludeEngine.Otwórz notatnik systemowy i wklej:

HKLM\...\Run: [] = [X]
HKU\S-1-5-21-1393353077-2935873281-2611161710-1000\...\Policies\Explorer: []
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hpts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0US
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dsts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hpts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0US
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dsts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
HKU\S-1-5-21-1393353077-2935873281-2611161710-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1395266497from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
HKU\S-1-5-21-1393353077-2935873281-2611161710-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hpts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0US
HKU\S-1-5-21-1393353077-2935873281-2611161710-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1395266497from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
HKU\S-1-5-21-1393353077-2935873281-2611161710-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hpts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0US
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dsts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dsts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
SearchScopes: HKU\S-1-5-21-1393353077-2935873281-2611161710-1000 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dsts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
SearchScopes: HKU\S-1-5-21-1393353077-2935873281-2611161710-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dsts=1422429870from=wpcuid=TOSHIBAXMK2555GSX_69ILSI0USXX69ILSI0USq={searchTerms}
S2 Util BringStar; "C:\Program Files\BringStar\bin\utilBringStar.exe" [X]
S2 Util Mega Browse; "C:\Program Files\Mega Browse\bin\utilMegaBrowse.exe" [X] ==== ATTENTION
R1 wStLib; C:\Windows\System32\drivers\wStLib.sys [52928 2014-03-20] (StdLib)
U3 akg8ne5l; C:\Windows\system32\Drivers\akg8ne5l.sys [0] (Microsoft Corporation) ==== ATTENTION (zero size file/folder)
U4 Schuinahvbip; No ImagePath
2015-01-30 18:47 - 2015-01-30 18:47 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-01-28 08:23 - 2015-01-28 08:23 - 00000000 ____ D () C:\ProgramData\aoonjoghokdhfogemajcpacomhjcjikl
2015-01-28 08:23 - 2015-01-28 08:23 - 00000000 ____ D () C:\ProgramData\9717148509941786961
2015-01-28 08:22 - 2015-01-28 15:18 - 00000000 ____ D () C:\ProgramData\{4c9740ff-1c18-bc47-4c97-740ff1c103fc}
2015-02-07 11:31 - 2014-01-24 15:00 - 00000000 ____ D () C:\Program Files\McAfee Security Scan
2015-02-07 10:23 - 2014-06-09 20:17 - 00000441 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.