Ads by browser extension

Mój komputer został zarażony wirusem ads by browser extension, który sam otwiera nowe okna przeglądarki z reklamami. Próbowałem się go pozbyć takimi programami jak: adwcleaner i spyhunter. Nic nie dało rady i wirus cały czas jest na moim komputerze. Nie wiem  jak się go pozbyć bo sposoby znalezione w internecie też nie dają rady. Ktoś może wie jak sie go pozbyć?

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.

To chyba to.

FRST_30-06-2014_16-22-00.txt

Addition.txt

Odinstaluj Media Buzz,PC Data App,Rich Media View,SpyHunter.Otwórz Notatnik i wklej:

Task: {2A308CB3-90ED-4737-9FD3-65F5C5111AF7} - System32\Tasks\SpyHunter4Startup = C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2014-01-09] (Enigma Software Group USA, LLC.)
Task: {4B9CE5FE-7E17-47B5-B731-9F56DB2F5178} - \AmiUpdXp No Task File ==== ATTENTION
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=hpfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=hpfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=hpfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=hpfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=hpfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=hpfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=scfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=dsfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497type=defaultq={searchTerms}
BHO-x32: Media Buzz - {797e4872-8671-457a-b80c-b4d189989b3e} - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode5310\ie\MediaBuzzV1mode5310.dll ()
BHO-x32: Rich Media View - {ddbd92ee-6709-4e3d-9faa-2ae2ce123517} - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release7567\ie\RichMediaViewV1release7567.dll ()
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode5310.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode5310\ff
FF Extension: Media Buzz - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode5310\ff [2014-04-25]
FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release7567.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release7567\ff
FF Extension: Rich Media View - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release7567\ff [2014-05-15]
CHR HKLM-x32\...\Chrome\Extension: [ainbkicbloikcngphmjfpjdemblcojdd] - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\slidebar.crx [2014-06-12]
CHR HKLM-x32\...\Chrome\Extension: [locigocghgdangkfldnelogkpnnelhbk] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode5310\ch\MediaBuzzV1mode5310.crx [2014-04-24]
CHR HKLM-x32\...\Chrome\Extension: [odkphpblclakgpkbdglkacgcgdmgolma] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release7567\ch\RichMediaViewV1release7567.crx [2014-05-14]
CHR HKLM-x32\...\Chrome\Extension: [ogfjmhfnldnajmfaofeiaepghjenbgjo] - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ep.crx [2014-05-14]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-05-14]
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.delta-homes.com/?utm_source=butm_medium=wpm0613utm_campaign=installerutm_content=scfrom=wpm0613uid=WDCXWD6400BPVT-55HXZT3_WD-WX51E32X1609X1609ts=1402579497
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [761968 2014-06-12] (Cherished Technololgy LIMITED)
R2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe [591776 2014-06-11] (Fuyu LIMITED)
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()
R1 {b99c8534-7800-48fa-bd71-519a46cdc7e1}Gw64; C:\Windows\System32\drivers\{b99c8534-7800-48fa-bd71-519a46cdc7e1}Gw64.sys [61120 2014-04-24] (StdLib)
R1 {b99c8534-7800-48fa-bd71-519a46cdc7e1}w64; C:\Windows\System32\drivers\{b99c8534-7800-48fa-bd71-519a46cdc7e1}w64.sys [61120 2014-05-13] (StdLib)
S3 EagleX64; \\C:\Windows\system32\drivers\EagleX64.sys [X]
2014-06-30 14:46 - 2014-06-30 14:46 - 00003324 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2014-06-30 14:46 - 2014-06-30 14:46 - 00002256 _____ () C:\Users\Home\SpyHunter.lnk
2014-06-30 14:46 - 2014-06-30 14:46 - 00000000 ____ D () C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-06-30 14:45 - 2014-06-30 14:46 - 00000000 ____ D () C:\sh4ldr
2014-06-30 14:45 - 2014-06-30 14:45 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2014-06-30 14:43 - 2014-06-30 16:16 - 00000000 ____ D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-30 14:31 - 2014-06-30 14:31 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Home\Downloads\SpyHunter-installer (1).exe
2014-06-26 15:09 - 2014-06-26 15:10 - 00000000 ___SD () C:\ComboFix
2014-06-26 15:09 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-26 15:09 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-26 15:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-26 15:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-26 15:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-26 15:09 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-26 15:09 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-26 15:09 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-26 15:08 - 2014-06-26 15:09 - 00000000 ____ D () C:\Qoobox
2014-06-25 13:55 - 2014-06-25 13:55 - 00721592 _____ (Elex do Brasil Participações Ltda) C:\Users\Home\Downloads\yet_another_cleaner_mmac.exe
2014-06-12 15:26 - 2014-06-30 14:48 - 00000000 ____ D () C:\Program Files (x86)\SupTab
2014-06-12 15:26 - 2014-06-13 19:33 - 00000000 ____ D () C:\ProgramData\IePluginServices
C:\Users\Home\TeamSpeak3-Client-win32-3-0-13-1.exe

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Dzęki chyba już po problemie.

Skasuj folder C:\FRST

Użyj http://www.bleepingcomputer.com/download/tfc/ (uruchom TFC i kliknij Start).

Coś jescze?

To wszystko.

Dzieki