Jak pozbyć się Round World?


(Anitag1) #1

Męczę się z tym i męczę... czy ktoś byłby w stanie mi pomóc?


(Acorus) #2

Odinstaluj AVG 2012,McAfee Security Scan Plus,Qtrax Player,SFT_Polska Toolbar,SpeedAnalysis.com.Otwórz notatnik systemowy i wklej:

Task: {2F1C5FCB-EA12-40F3-9120-AB52405E6FDB} - System32\Tasks\{8E2AE4FC-88F3-470E-B232-2743C4671597} = pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge
Task: {310960AF-8E25-46A1-844B-3AB74551CB7D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-245511830-2331656098-4223385844-1000UA = C:\Users\Anita\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-08-18] (Facebook Inc.)
Task: {5CFB757A-24FC-4035-84F1-9CA4E76ED510} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-245511830-2331656098-4223385844-1000Core = C:\Users\Anita\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-08-18] (Facebook Inc.)
Task: {7433EA73-C536-4985-8004-9C8FC8CEF716} - System32\Tasks\{2F96B4DE-8BAB-4D70-8B10-6A1AB66A26CC} = Firefox.exe http://ui.skype.com/ui/0/5.6.0.110/pl/abandoninstall?page=tsDownloadamp;installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-245511830-2331656098-4223385844-1000Core.job = C:\Users\Anita\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-245511830-2331656098-4223385844-1000UA.job = C:\Users\Anita\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKLM\...\Run: [AVG_UI] = C:\Program Files\AVG\AVG2013\avgui.exe [3147384 2012-12-11] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Adobe ARM] = C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [NeroFilterCheck] = C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [HDD Regenerator] = C:\Program Files\HDD Regenerator\Shell.exe [90336 2013-05-08] ()
HKLM\...\Run: [SunJavaUpdateSched] = C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-245511830-2331656098-4223385844-1000\...\Run: [Facebook Update] = C:\Users\Anita\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-08-18] (Facebook Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
URLSearchHook: HKLM - (No Name) - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - No File
URLSearchHook: HKLM - (No Name) - {178f4c0b-0457-45ba-8ec5-942db8fd1f22} - No File
URLSearchHook: HKU\S-1-5-21-245511830-2331656098-4223385844-1000 - (No Name) - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - No File
URLSearchHook: HKU\S-1-5-21-245511830-2331656098-4223385844-1000 - (No Name) - {178f4c0b-0457-45ba-8ec5-942db8fd1f22} - No File
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-245511830-2331656098-4223385844-1003 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: No Name - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - No File
BHO: No Name - {178f4c0b-0457-45ba-8ec5-942db8fd1f22} - No File
BHO: No Name - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - No File
Toolbar: HKLM - No Name - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - No File
Toolbar: HKLM - No Name - {178f4c0b-0457-45ba-8ec5-942db8fd1f22} - No File
Toolbar: HKU\S-1-5-21-245511830-2331656098-4223385844-1000 - No Name - {178F4C0B-0457-45BA-8EC5-942DB8FD1F22} - No File
Toolbar: HKU\S-1-5-21-245511830-2331656098-4223385844-1000 - No Name - {5C5B9468-D672-4EB7-B52F-B5AFABF28C5B} - No File
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\key-find.xml
FF Extension: Roll Around - C:\Users\Anita\AppData\Roaming\Mozilla\Firefox\Profiles\ypug2hnt.default\Extensions\{bec0d06e-c92d-48a7-bc8b-4f7ee342b2ad}.xpi [2015-02-23]
FF HKLM\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files\AVG\AVG2012\Firefox4
FF HKU\S-1-5-21-245511830-2331656098-4223385844-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
CHR HomePage: Default - hxxp://www.key-find.com/?type=hpts=1424279835from=coruid=HitachiXHTS543225L9A300_080919FB0E06LKH4YZGCX
CHR StartupUrls: Default - "hxxp://www.key-find.com/?type=hpts=1424279835from=coruid=HitachiXHTS543225L9A300_080919FB0E06LKH4YZGCX"
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 Service Mgr RollAround; C:\ProgramData\2a617352-d396-46a3-a71b-5d89535356cf\plugincontainer.exe [577264 2015-02-23] ()
R2 Update Mgr RollAround; C:\Program Files\Common Files\2a617352-d396-46a3-a71b-5d89535356cf\updater.exe [384752 2015-02-23] ()
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2015-02-23 00:16 - 2015-02-23 00:16 - 00000000 ____ D () C:\Program Files\Roll Around
2015-02-18 18:20 - 2015-02-23 00:36 - 00000000 ____ D () C:\AdwCleaner
2015-02-23 11:36 - 2013-07-01 11:16 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
C:\ProgramData\1doc2pdf.dll
C:\ProgramData\hpeF8F2.dll
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.