Jak usunąć Strong Signal?


(Mikolajx15) #1

Jak w temacie, ten wirus mnie bardzo denerwuje, poniżej logi.

FRST: http://wklej.org/id/1655493/

Addition: http://wklej.org/id/1655498/

 


(Atis) #2

W panelu sterowania odinstaluj STOPzilla AntiVirus.

Pobierz i uruchom AdwCleaner Kliknij Scan i później Cleaning.

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150222
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150222
HKU\S-1-5-21-2892684270-2662760911-2235671873-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150222
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
FF DefaultSearchEngine: key-find
FF Extension: Strong Signal - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\oecnt8nj.default\Extensions\{6dc74982-0c33-45a3-aaec-8285d2089296}.xpi [2015-02-19]
FF SearchPlugin: C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\oecnt8nj.default\searchplugins\key-find.xml
CHR Extension: (Strong Signal) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdidplnlbafiijjfbomlfokdppebnhpc [2015-02-20]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
2015-03-01 13:12 - 2015-03-01 13:12 - 00000000 ____ D () C:\ProgramData\APN
2015-02-19 21:35 - 2015-02-20 14:40 - 00000000 ____ D () C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
Task: {26F61E30-2EC2-4B98-9C84-DBD5A6B5E884} - System32\Tasks\{B7E253A1-6D5E-4773-B175-03379764519B} => pcalua.exe -a E:\Sims3Setup.exe -d E:\
Task: {C04B3010-387E-4C0F-81F9-3C90E2D6C48A} - System32\Tasks\{89FD906E-EF3D-4AB2-82F1-D01E4430F9A8} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}\setup.exe" -c -runfromtemp -l0x0015 -removeonly
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.


(Mikolajx15) #3

Fixlog: http://wklej.org/id/1655824/

FRST: http://wklej.org/id/1655826/

Wszystko dobrze zrobiłem?


(Atis) #4

Wkleiłeś dwa razy ten sam raport z usuwania.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.


(Mikolajx15) #5

FRST: http://wklej.org/id/1656578/


(Atis) #6

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

HKU\S-1-5-21-2892684270-2662760911-2235671873-1000\...\Run: [EpicScale] => C:\ProgramData\EpicScale\0\EpicScale.exe EpicScale StartMinimized
FF Homepage: www.wp.pl/?src01=dp120150222
2015-03-05 21:35 - 2015-03-06 11:04 - 00000000 ____ D () C:\AdwCleaner
2015-03-05 19:50 - 2015-03-06 11:02 - 00000000 ____ D () C:\Program Files (x86)\STOPzilla
2015-03-05 19:50 - 2015-03-06 11:01 - 00000000 ____ D () C:\ProgramData\STOPzilla!
2015-02-05 10:54 - 2015-01-15 18:44 - 00001740 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\EPIC_SCALE.lnk
C:\ProgramData\EpicScale
DeleteQuarantine:

Uruchom FRST i kliknij Fix. Skasuj folder C:\FRST

Usuń stare punkty przywracania: Aby usunąć wszystkie punkty przywracania

Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK - KLIK

Odinstaluj Adobe Flash Player ActiveX i zainstaluj Flash Player 16.0.0.305 ActiveX