Pomoc w usunięciu Stron Signal


(Justynaborowska Vd) #1

Witam,

Bardzo proszę o pomoc w usunięciu wyskakujących ciągle reklam Strong Signal.

Proszę o jak najprostsze wyjaśnienie ponieważ jestem zielona w tym temacie.

Z góry dziękuję.


(Giiixxxx6) #2

http://forum.dobreprogramy.pl/farbar-recovery-scan-tool-raport-obowi%C4%85zkowy-t478727/


(Justynaborowska Vd) #3

Addition: http://www.wklej.org/id/1704002/

FRST: http://www.wklej.org/id/1704003/

Shortcut: http://www.wklej.org/id/1704005/


(Atis) #4

W panelu sterowania odinstaluj Strong Signal i McAfee Security Scan Plus.

Usuń szkodliwe rozszerzenia w przeglądarce Firefox i Chrome

Opera w pasek adresu wpisz: opera:extensions

Pobierz i uruchom AdwCleaner Kliknij Scan i później Cleaning.

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Justynaborowska Vd) #5

Raport po nowym skanie

 

FRST: http://www.wklej.org/id/1704595/


(Justynaborowska Vd) #6

Raport po nowym skanie

 

FRST: http://www.wklej.org/id/1704595/


(Atis) #7

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0
HKU\S-1-5-21-2612670305-2425920923-3750339402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
SearchScopes: HKLM -> {E24C31C0-2D34-4675-9D87-84D5AD4CA8D4} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2612670305-2425920923-3750339402-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2612670305-2425920923-3750339402-1001 -> {E24C31C0-2D34-4675-9D87-84D5AD4CA8D4} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
FF NewTab: hxxp://search.yahoo.com/?fr=hp-ddc-bd-tab&type=bg_616_bl-is-19 __alt__ ddc_dsssyctab_bd_com
FF DefaultSearchEngine: Yahoo! Search
FF SelectedSearchEngine: Yahoo! Search
FF Homepage: hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-19 __alt__ ddc_dsssyc_bd_com
FF Keyword.URL: hxxp://search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bg_616_bl-is-19 __alt__ ddc_dss_bd_com&p={searchTerms}
CHR RestoreOnStartup: Default -> "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-19 __alt__ ddc_dsssyc_bd_com"
CHR StartupUrls: Default -> "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-19 __alt__ ddc_dsssyc_bd_com"
CHR DefaultSearchKeyword: Default -> yahoo.com
CHR DefaultNewTabURL: Default -> http://search.yahoo.com/?fr=hp-ddc-bd-tab&type=bg_616_bl-is-19 __alt__ ddc_dsssyctab_bd_com
CHR Extension: (Bookmark Manager) - C:\Users\justynaborowska\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-05]
OPR StartupUrls: "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-19 __alt__ ddc_dsssyc_bd_com"
R2 Update Mgr StrongSignal; C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe [478992 2015-05-06] ()
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce
2015-05-04 17:33 - 2015-05-05 12:14 - 00000000 ____ D () C:\WINDOWS\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2015-05-04 17:34 - 2015-05-04 17:34 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-05-04 17:32 - 2015-05-04 17:32 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\justynaborowska\Downloads\SpyHunter-installer.exe
2015-05-04 17:07 - 2015-05-06 10:40 - 00000000 ____ D () C:\AdwCleaner
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
2015-02-26 00:02 - 2015-05-06 10:42 - 0147633 _____ () C:\Users\justynaborowska\AppData\Local\BTServer.log
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Justynaborowska Vd) #8

Fixlog: http://www.wklej.org/id/1704728/

FRST: http://www.wklej.org/id/1704732/


(Atis) #9

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2612670305-2425920923-3750339402-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2612670305-2425920923-3750339402-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_8a455fc6-8b19-4bbd-855b-b39959b4b6d0&q={searchTerms}
FF DefaultSearchEngine: Yahoo! Search
FF Extension: Strong Signal - C:\Users\justynaborowska\AppData\Roaming\Mozilla\Firefox\Profiles\s89r5xr8.default\Extensions\{cf2e72d6-ff45-4f2e-8c1a-e2f060b90cec}.xpi [2015-05-06]
CHR Extension: (Strong Signal) - C:\Users\justynaborowska\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmkmbmnjmjbophpmmnimpiaoifmknph [2015-05-06]
OPR Extension: (Strong Signal) - C:\Users\justynaborowska\AppData\Roaming\Opera Software\Opera Stable\Extensions\jmmkmbmnjmjbophpmmnimpiaoifmknph [2015-05-06]
S2 Service Mgr StrongSignal; "C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.exe" [X]
2015-05-06 13:24 - 2015-05-06 13:24 - 00001657 _____ () C:\Users\justynaborowska\AppData\Local\BTServer.log
2015-05-06 10:48 - 2015-05-06 10:48 - 00000000 ____ D () C:\Program Files (x86)\Strong Signal
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Justynaborowska Vd) #10

Fixlog: http://www.wklej.org/id/1704821/

FRST: http://www.wklej.org/id/1704827/


(Atis) #11

Skasuj folder C:\FRST

Usuń stare punkty przywracania: Przywracanie systemu i kopie w tle

Dysk przeskanuj Malwarebytes Anti-Malware

Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.

http://wstaw.org/m/2014/03/25/2014-03-25_123039.png

Język PL > Settings > General Settings > Language > Polish

Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK - KLIK

Odinstaluj Adobe Reader 9.5.0 i zainstaluj Adobe Reader XI 11.0.10