OMIGA-PLUS co z tym zrobić?

Witam,

jak w temacie. Dzisiaj nie wiadomo skąd pojawiła się ta Omiga :confused:

Co zrobić, żeby sie tego pozbyć?

http://www.wklejto.pl/221201

http://www.wklejto.pl/221202

 

Bardzo, bardzo proszę o pomoc i z góry dziękuję

Odinstaluj Spybot - Search & Destroy,SpyHunter 4.Logi nie mają ukośników.Umieść na wklej.org

http://wklej.org/id/1611481/

http://wklej.org/id/1611485/

 

nie wiem czy dobrze to zrobiłam :slight_smile:

Otwórz notatnik systemowy i wklej:

Task: C:\WINDOWS\Tasks\EPUpdater.job = C:\DOCUME~1\1\DANEAP~1\BABSOL~1\Shared\BabMaint.exe ==== ATTENTION
Task: C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job = C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job = C:\WINDOWS\system32\xp_eos.exe
HKLM\...\Run: [RTHDCPL] = C:\WINDOWS\RTHDCPL.EXE [16857600 2008-02-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [GEST] = =
HKLM\...\Run: [NeroFilterCheck] = C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [SecurDisc] = C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [1628208 2007-05-15] (Nero AG)
HKLM\...\Run: [InCD] = C:\Program Files\Nero\Nero 7\InCD\InCD.exe [1057328 2007-05-15] (Nero AG)
HKLM\...\Run: [SunJavaUpdateSched] = C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [NPSStartup] = [X]
HKLM\...\Run: [Adobe ARM] = C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SpyHunter Security Suite] = C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [6463360 2015-01-27] (Enigma Software Group USA, LLC.)
HKU\S-1-5-21-796845957-117609710-1801674531-1004\...\Run: [ALLUpdate] = "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep"
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browsemngr.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browsermngr.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe
IFEO\cltmngsvc.exe: [Debugger] tasklist.exe
IFEO\delta babylon.exe: [Debugger] tasklist.exe
IFEO\delta tb.exe: [Debugger] tasklist.exe
IFEO\delta2.exe: [Debugger] tasklist.exe
IFEO\deltainstaller.exe: [Debugger] tasklist.exe
IFEO\deltasetup.exe: [Debugger] tasklist.exe
IFEO\deltatb.exe: [Debugger] tasklist.exe
IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\iminentsetup.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\rjatydimofu.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\sweetimsetup.exe: [Debugger] tasklist.exe
IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\S-1-5-21-796845957-117609710-1801674531-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=dsts=1422345492from=coruid=SAMSUNGXHD322HJ_S17AJ9CQ600896q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=dsts=1422345492from=coruid=SAMSUNGXHD322HJ_S17AJ9CQ600896q={searchTerms}
HKU\S-1-5-21-796845957-117609710-1801674531-1004\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?affID=121845tt=120613_ndtbabsrc=HP_ssmntrId=B078001D7D7FE994
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = http://www.default-search.net/search?sid=498aid=109itype=aver=15005tm=307src=dsp={searchTerms}
SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=dsq={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}affID=121845tt=120613_ndtbabsrc=SP_ss_din2gmntrId=B078001D7D7FE994
SearchScopes: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = http://www.default-search.net/search?sid=498aid=109itype=aver=13551tm=307src=dsp={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=dsq={searchTerms}
Toolbar: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
Toolbar: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-796845957-117609710-1801674531-1004 - No Name - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
FF DefaultSearchEngine: webssearches
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: webssearches
FF Keyword.URL: hxxp://www.default-search.net/search?sid=498aid=109itype=aver=15005tm=307src=dsp=
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\BrowserDefender.xml
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\daemon-search.xml
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\default-search.xml
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\delta.xml
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\omiga-plus.xml
FF SearchPlugin: C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\searchplugins\webssearches.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\default-search.xml
FF Extension: FF Toolbar - C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\Extensions\fftoolbar2014@etech.com [2015-01-27]
FF Extension: Internet Program - C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\Extensions\{565c1cb8-774a-4f83-a69b-10826891d3f6}.xpi [2015-01-27]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} [2015-01-27]
FF HKLM\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Documents and Settings\1\Dane aplikacji\Mozilla\Firefox\Profiles\z5lfqp70.default\extensions\fftoolbar2014@etech.com
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [770944 2015-01-27] (Enigma Software Group USA, LLC.)
R2 Update Mgr InternetProgram; C:\Program Files\Common Files\6fb1f30a-cea7-4ccf-bff8-acbecbfe46f9\updater.exe [351992 2015-01-27] ()
R2 WindowsMangerProtect; C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-01-27] (SysTool PasSame LIMITED) [File not signed]
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-01-27] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2015-01-27] ()
U3 a08haymk; C:\WINDOWS\system32\Drivers\a08haymk.sys [0] (Microsoft Corporation) ==== ATTENTION (zero size file/folder)
S3 catchme; \\C:\DOCUME~1\1\USTAWI~1\Temp\catchme.sys [X]
S4 IntelIde; No ImagePath
U3 TlntSvr; No ImagePath
2015-01-27 10:03 - 2015-01-27 10:03 - 00000000 ____ D () C:\sh4ldr
2015-01-27 10:03 - 2015-01-27 10:03 - 00000000 ____ D () C:\Documents and Settings\1\Dane aplikacji\Enigma Software Group
2015-01-27 09:58 - 2015-01-27 09:58 - 00019984 _____ () C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-01-27 09:58 - 2015-01-27 09:58 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-01-27 08:58 - 2015-01-27 10:01 - 00000000 ____ D () C:\Documents and Settings\1\Dane aplikacji\omiga-plus
2015-01-27 08:58 - 2015-01-27 08:58 - 00000000 ____ D () C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Bardzo dziękuję za pomoc, jutro w pracy spóbuje się z tym uporać. Najgorsze, że w domu na lapku też to mam :confused: Rozumiem,że ten plik co jest w poście wyzej zadziała tylko na tym kompie w pracy?

Tak .Muszą być logi z drugiego komputera.

Logi z mojego lapka:

http://wklej.org/id/1611821/

http://wklej.org/id/1611830/

 

jeżeli nie będzie problemem to proszę o pomoc

Odinstaluj omiga-plus uninstall,Solution Real,Winamp Toolbar for Firefox.Otwórz notatnik systemowy i wklej:

Task: {033EA682-3205-4FA2-A522-D80B57A94845} - System32\Tasks\{559191CE-8BFA-4C21-B255-420200C38B5D} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {15FEC679-2268-41BF-A59A-8B0E4A157D9F} - System32\Tasks\{57DC6B40-A18D-4CA8-B3B7-529D932C4FA2} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {57549035-1CE5-4520-97B5-A20F3E1FF42E} - System32\Tasks\{05CA45D5-79BF-42AA-921B-3F12A3DD4458} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {5ADE17B6-1956-4E12-8777-068DC64BDCF5} - System32\Tasks\{93E48B04-3FFA-42CF-965E-1CAF0C2F39CB} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {5C08C790-4E3E-4670-9859-12FA7B3A3059} - System32\Tasks\{19CAE39A-4F15-46F1-B340-D5FE39E5D2DB} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {E1099968-3585-4126-9024-FAE1C98CDF08} - System32\Tasks\{2092A9A3-52FF-40C5-B2A9-FF17764AF14C} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {F2C37C05-4333-4465-81EA-3C981FE54B96} - System32\Tasks\{53ED327F-BC94-4CFF-9AAA-8164C5B0DA02} = Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
HKU\S-1-5-21-2555796947-544180426-1259784141-1000\...\Run: [EpicScale] = [X]
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hpts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GT
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=dsts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=dsts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTq={searchTerms}
HKU\S-1-5-21-2555796947-544180426-1259784141-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hpts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GT
HKU\S-1-5-21-2555796947-544180426-1259784141-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GT
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dsts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTq={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dsts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTq={searchTerms}
SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=dsq={searchTerms}
SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685query={searchTerms}invocationType=tb50winampie7
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {AB3C6B04-FD5B-47F4-9E93-8D96F5C94F3E} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GTts=1422297322type=defaultq={searchTerms}
BHO: Solution Real 1.0.0.7 - {1bb456da-878f-44a5-b013-4bfe0ae02fce} - C:\Program Files\Solution Real\SolutionRealBHO.dll (Solution Real)
BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\XTab\SupTab.dll (Thinknice Co. Limited)
Toolbar: HKLM - Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
Toolbar: HKU\S-1-5-21-2555796947-544180426-1259784141-1000 - Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
FF DefaultSearchEngine: omiga-plus
FF SelectedSearchEngine: omiga-plus
FF SearchPlugin: C:\Users\Ania_Marian\AppData\Roaming\Mozilla\Firefox\Profiles\780z6ofn.default\searchplugins\omiga-plus.xml
FF Extension: Fast Start - C:\Users\Ania_Marian\AppData\Roaming\Mozilla\Firefox\Profiles\780z6ofn.default\Extensions\faststartff@gmail.com [2015-01-26]
FF Extension: FF Toolbar - C:\Users\Ania_Marian\AppData\Roaming\Mozilla\Firefox\Profiles\780z6ofn.default\Extensions\fftoolbar2014@etech.com [2015-01-26]
FF Extension: Solution Real 1.0.1 - C:\Users\Ania_Marian\AppData\Roaming\Mozilla\Firefox\Profiles\780z6ofn.default\Extensions\{1d7d694e-604c-4da2-9100-b2601d3a1c57}.xpi [2015-01-26]
FF HKLM\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Ania_Marian\AppData\Roaming\Mozilla\Firefox\Profiles\780z6ofn.default\extensions\fftoolbar2014@etech.com
FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Ania_Marian\AppData\Roaming\Mozilla\Firefox\Profiles\780z6ofn.default\extensions\faststartff@gmail.com
CHR StartupUrls: Default - "hxxp://isearch.omiga-plus.com/?type=hpts=1422297232from=coruid=TOSHIBAXMK1637GSX_Y77OWF0GTXXY77OWF0GT"
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Solution Real) - C:\Users\Ania_Marian\AppData\Local\Google\Chrome\User Data\Default\Extensions\obemdemamldcfdmhlohodidgomlchimk [2015-01-27]
R2 IHProtect Service; C:\Program Files\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
R2 Update Solution Real; C:\Program Files\Solution Real\updateSolutionReal.exe [681208 2015-01-27] ()
R2 Util Solution Real; C:\Program Files\Solution Real\bin\utilSolutionReal.exe [681208 2015-01-27] ()
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-01-26] (SysTool PasSame LIMITED) [File not signed]
R1 {1d7d694e-604c-4da2-9100-b2601d3a1c57}Gt; C:\Windows\System32\drivers\{1d7d694e-604c-4da2-9100-b2601d3a1c57}Gt.sys [55832 2015-01-26] (StdLib)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz132; \\C:\Users\ANIA_M~1\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [X]
S3 TpChoice; system32\DRIVERS\TpChoice.sys [X]
2015-01-26 19:35 - 2015-01-26 19:35 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-01-26 19:35 - 2015-01-26 19:35 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-01-26 19:35 - 2015-01-26 19:35 - 00000000 ____ D () C:\Program Files\XTab
2015-01-26 19:32 - 2015-01-27 17:43 - 00000000 ____ D () C:\Program Files\Solution Real
2014-02-25 11:05 - 2014-02-25 11:05 - 49940480 _____ () C:\Program Files\GUT44FC.tmp
2014-11-16 19:09 - 2014-11-16 19:09 - 6000640 _____ () C:\Program Files\GUT732D.tmp
C:\ProgramData\ezsid.dat
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

No jednak za głupia jestem, nie wychodzi. Wyskakuje komunikat, że fixlist.txt ma być w tym samym folderze. No chyba jest :slight_smile: Zapisałam go na dysku C w folderze FRST i nie działa :(, potem próbowałam w podfolderze Logs i tez nie działa.

Ma być tam gdzie FRST czyli C:\Users\Ania_Marian\Downloads

chyba się udało :slight_smile:

Wyskoczyło mi takie “coś”.

http://wklej.org/id/1612091/

To dobrze czy źle?

Skasuj folder C:\FRST