Denerwujace reklamy wyskakujące okna

Witam jak w temacie. przesylam logi:

FRST: http://wklej.org/id/1774825/

ADD: http://wklej.org/id/1774826/

SHORT: http://wklej.org/id/1774827/

Odinstaluj adblocker,bestadblocker,iCloud Bookmarks,StatMonitor.Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan i później Cleaning.

Pokaż nowe logi z FRST.

skan z adw: http://wklej.org/id/1774908/

FRST: http://wklej.org/id/1774909/

ADD: http://wklej.org/id/1774910/

Otwórz notatnik systemowy i wklej:

globalupdate Helper (Version: 1.3.25.0 - globalupdate Inc.) Hidden ==== ATTENTION
Task: {0D9F43E4-2EC9-4FF7-BBBC-F3C7DCDF78C8} - System32\Tasks\JKRXFGIV1 = C:\ProgramData\EpsanDrive\EpsanDrive.exe [2015-08-09] (EpsanDrive) ==== ATTENTION
Task: {0DA4CCBA-311F-4CC9-9B29-965321CCB2FA} - System32\Tasks\4w7fghPoRJAf = C:\Users\Adrian\AppData\Roaming\4w7fghPoRJAf.exe [2015-04-20] () ==== ATTENTION
Task: {1ADC7798-B9DE-4C14-A137-05466FAA62DF} - System32\Tasks\Superclean = c:\programdata\{6ae42206-915f-b04f-6ae4-42206915881a}\hqghumeaylnlf.exe [2014-08-14] (Super PC Tools Ltd) ==== ATTENTION
Task: {246C5601-FF1D-43E6-9CC4-DBFB48C4DC74} - System32\Tasks\globalUpdateUpdateTaskMachineUA = C:\Program Files\globalUpdate\Update\globalupdate.exe [2015-08-14] (globalUpdate) ==== ATTENTION
Task: {39D37585-61D5-4338-9AA9-34EAA2EB2895} - System32\Tasks\nProtect GameGuard Service 1.57.14 = C:\Windows\system32\config\systemprofile\AppData\Local\nProtectGameGuard\nprotect.exe [2015-08-14] ()
Task: {832EB2A8-881C-4AF6-81FF-57CC440CBF4B} - System32\Tasks\globalUpdateUpdateTaskMachineCore = C:\Program Files\globalUpdate\Update\globalupdate.exe [2015-08-14] (globalUpdate) ==== ATTENTION
Task: {88C3B29A-3EB5-443D-B4AB-38699EE91D1B} - System32\Tasks\Bidaily Synchronize Task[973b] = c:\programdata\{77b83940-d7df-ae4f-77b8-83940d7de503}\setup_product_27840.exe [2014-08-14] () ==== ATTENTION
Task: {9FC7CCCC-508B-46B7-BA32-30091745B32F} - System32\Tasks\SmartWeb Upgrade Trigger Task = C:\Users\Adrian\AppData\Local\SmartWeb\SmartWebHelper.exe ==== ATTENTION
Task: {B1BF6718-753E-4162-A4E9-D1B6C2B9E512} - System32\Tasks\Tempo Runner seap6ro = C:\ProgramData\JulShf\seaparo.exe
Task: {BF3FFB0B-0382-474E-BF19-E29EFB2CCFBB} - System32\Tasks\erLA5O6JjemIMD = C:\Users\Adrian\AppData\Roaming\erLA5O6JjemIMD.exe [2015-04-20] () ==== ATTENTION
Task: {E5196A33-6461-460D-962B-356D224CF10A} - System32\Tasks\VQPBBPEMFXCYIYQX = C:\ProgramData\Service1198\Service1198.exe [2015-08-09] () ==== ATTENTION
Task: C:\Windows\Tasks\4w7fghPoRJAf.job = C:\Users\Adrian\AppData\Roaming\4w7fghPoRJAf.exe ==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[973b].job = c:\programdata\{77b83940-d7df-ae4f-77b8-83940d7de503}\setup_product_27840.exe ==== ATTENTION
Task: C:\Windows\Tasks\erLA5O6JjemIMD.job = C:\Users\Adrian\AppData\Roaming\erLA5O6JjemIMD.exe ==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job = C:\Program Files\globalUpdate\Update\globalupdate.exe ==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job = C:\Program Files\globalUpdate\Update\globalupdate.exe ==== ATTENTION
Task: C:\Windows\Tasks\JKRXFGIV1.job = C:\ProgramData\EpsanDrive\EpsanDrive.exe ==== ATTENTION
Task: C:\Windows\Tasks\Superclean.job = c:\programdata\{6ae42206-915f-b04f-6ae4-42206915881a}\hqghumeaylnlf.exe ==== ATTENTION
Task: C:\Windows\Tasks\Tempo Runner seap6ro.job = C:\ProgramData\JulShf\seaparo.exe*/dgad C:\ProgramData\JulShf\seap6ro.exe
Task: C:\Windows\Tasks\VQPBBPEMFXCYIYQX.job = C:\ProgramData\Service1198\Service1198.exe ==== ATTENTION
HKLM\...\Run: [HP Software Update] = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [gpuminer] = C:\Users\Adrian\AppData\Roaming\cpuminer\sgminer\sgminer.cmd [96 2015-05-02] ()
HKLM\...\Run: [gmsd_nl_005010060] = [X]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
ProxyEnable: [.DEFAULT] = Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] = http=127.0.0.1:58296;https=127.0.0.1:58296
SearchScopes: HKLM - DefaultScope value is missing
SearchScopes: HKLM - {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.hotsearches.info/?l=1q={searchTerms}pid=24475r=2015/08/14hid=9858799554332978354lg=ENcc=NLunqvl=90
SearchScopes: HKU\S-1-5-21-476298179-380137543-1004116917-1000 - {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.hotsearches.info/?l=1q={searchTerms}pid=24475r=2015/08/14hid=9858799554332978354lg=ENcc=NLunqvl=90
R2 fchk32; C:\Program Files\fchk32\fchk32.exe [379904 2015-08-10] () [File not signed] ==== ATTENTION
S2 globalUpdate; C:\Program Files\globalUpdate\Update\globalupdate.exe [68608 2015-08-14] (globalUpdate) [File not signed] ==== ATTENTION
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\globalupdate.exe [68608 2015-08-14] (globalUpdate) [File not signed] ==== ATTENTION
R2 xudefusi; C:\Program Files\490AD377-1439559896-E111-BF67-B888E377102A\knsjAA66.tmp [652800 2015-08-14] () [File not signed]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
2015-08-14 19:00 - 2015-08-14 19:00 - 00000000 __SHD C:\Users\Adrian\AppData\Roaming\AnyProtectEx
2015-08-14 19:00 - 2015-08-14 19:00 - 00000000 ____ D C:\Program Files\AnyProtectEx
2015-08-14 18:59 - 2015-08-14 18:59 - 00000000 ____ D C:\ProgramData\a36c9bdc000041a4
2015-08-14 18:57 - 2015-08-14 18:57 - 00000000 ____ D C:\Program Files\predm
2015-08-14 18:37 - 2015-08-14 18:37 - 00000217 _____ C:\task.vbs
2015-08-14 18:37 - 2015-08-14 18:37 - 00000000 ____ D C:\Program Files\Crossbrowse
2015-08-14 18:36 - 2015-08-14 18:58 - 00000000 ____ D C:\Users\Adrian\AppData\Local\SmartWeb
2015-08-14 18:36 - 2015-08-14 18:56 - 00000000 ____ D C:\Users\Adrian\AppData\Roaming\cpuminer
2015-08-14 18:00 - 2015-08-14 18:00 - 00000000 ____ D C:\Program Files\DisiCountExteNsi
2015-08-14 18:00 - 2015-08-14 18:00 - 00000000 ____ D C:\Program Files\DiscountEXtenSI
2015-08-14 15:51 - 2015-08-14 18:00 - 00000000 ____ D C:\Program Files\CutThePrice
2015-08-14 15:51 - 2015-08-14 18:00 - 00000000 ____ D C:\Program Files\bestadblocker
2015-08-14 15:45 - 2015-08-14 15:45 - 00000000 ____ D C:\Users\Adrian\AppData\Local\globalUpdate
2015-08-14 15:45 - 2015-08-14 15:45 - 00000000 ____ D C:\Program Files\globalUpdate
2015-07-22 18:13 - 2015-07-22 18:15 - 00000000 ____ D C:\AdwCleaner
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Adrian\AppData\Roaming\4w7fghPoRJAf
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Adrian\AppData\Roaming\4w7fghPoRJAf.exe
2015-08-14 17:58 - 2015-08-14 18:53 - 0000024 _____ () C:\Users\Adrian\AppData\Roaming\appdataFr25.bin
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Adrian\AppData\Roaming\erLA5O6JjemIMD
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\Adrian\AppData\Roaming\erLA5O6JjemIMD.exe
2015-08-14 19:00 - 2015-08-14 19:00 - 0613255 _____ (CMI Limited) C:\Users\Adrian\AppData\Local\nsaBF09.tmp
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Odinstaluj Chrome zaznaczając usunięcie danych przeglądania.