Positive Finds Ads - jak to usunąć? proszę o poradę dla laika

Witam, mam ogromny problem z reklamami Positive Finds Ads, są bardzo irytujące, a nie mam pojęcia jak się ich pozbyć :frowning: Przekopałam już internet w poszukiwaniu rozwiązania, ale nie doszukałam się jasnej odpowiedzi, a jako że jestem kompletnie zielona w tych komputerowych sprawach, chciałam bardzo poprosić o pomoc :) 

Nie wiem co jest istotne, ale z tego co wiem: używam Windowsa 7 i Chroma/Firefoxa, na obu występuje ten sam problem.

http://forum.dobreprogramy.pl/nowy-log-obowi%C4%85zkowy-farbar-recovery-scan-tool-t478727/

http://wklej.to/thfVo

http://wklej.to/lS60Y

 

Mam nadzieję, że to o to chodziło :slight_smile:

Odinstaluj SpyHunter 4,WindowsMangerProtect20.0.0.1277.Otwórz notatnik systemowy i wklej:

Task: {7600FB67-AB31-422A-9BB2-20772E866D37} - System32\Tasks\SpyHunter4Startup = C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-04-05] (Enigma Software Group USA, LLC.)
Task: {D581DB12-6BF0-44BB-99C2-31493D386E30} - System32\Tasks\{C9A4F449-52B9-4154-987C-B9F2C777AA49} = pcalua.exe -a C:\Users\User\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/#utm_source=instalkiutm_medium=installerutm_campaign=instalki
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/#utm_source=instalkiutm_medium=installerutm_campaign=instalki
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hpts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hpts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTB
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
HKU\S-1-5-21-1032470872-2234703871-1446661362-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/#utm_source=instalkiutm_medium=installerutm_campaign=instalki
HKU\S-1-5-21-1032470872-2234703871-1446661362-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hpts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTB
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
SearchScopes: HKU\S-1-5-21-1032470872-2234703871-1446661362-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1417390372from=coruid=ST500LT012-1DG142_S3P6QTTBXXXXS3P6QTTBq={searchTerms}
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Positive Finds - {30c85a3d-1d96-4589-b63f-91fb7ef45a41} - C:\Program Files (x86)\Positive Finds\Extensions\30c85a3d-1d96-4589-b63f-91fb7ef45a41.dll [2015-02-02] ()
FF Extension: Positive Finds - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\aluvkgwg.default\Extensions\{b9ab7498-1e31-4884-8c62-ad464d8cf7aa}.xpi [2015-03-07]
FF HKU\S-1-5-21-1032470872-2234703871-1446661362-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 Service Mgr PositiveFinds; C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe [639224 2015-04-05] ()
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-04-05] (Enigma Software Group USA, LLC.)
R2 Update Mgr PositiveFinds; C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe [559864 2015-04-03] ()
S2 51cdb72; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro 3.11\OptProCrash.dll",ENT
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-04-05] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-04-05] ()
2015-04-05 21:58 - 2015-04-05 21:58 - 00003332 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2015-04-05 21:58 - 2015-04-05 21:58 - 00001087 _____ () C:\Users\User\Desktop\SpyHunter.lnk
2015-04-05 21:58 - 2015-04-05 21:58 - 00000000 ____ D () C:\Users\User\AppData\Roaming\Enigma Software Group
2015-04-05 21:58 - 2015-04-05 21:58 - 00000000 ____ D () C:\sh4ldr
2015-04-05 21:48 - 2015-04-05 21:48 - 00022704 _____ () C:\Windows\system32\Drivers\EsgScanner.sys
2015-03-21 11:16 - 2015-03-21 11:16 - 00003152 _____ () C:\Windows\System32\Tasks\{C9A4F449-52B9-4154-987C-B9F2C777AA49}
2015-03-18 17:54 - 2015-04-05 21:48 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-03-18 17:53 - 2015-03-18 17:53 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\User\Downloads\SpyHunter-Installer.exe
2015-03-29 09:53 - 2015-02-02 23:23 - 00000000 ____ D () C:\Users\User\AppData\Roaming\OpenCandy
2015-03-28 09:34 - 2014-12-01 01:33 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-03-21 11:16 - 2015-02-02 23:23 - 00000000 ____ D () C:\Program Files (x86)\Positive Finds
2015-03-21 11:16 - 2014-12-01 01:32 - 00000000 ____ D () C:\Users\User\AppData\Roaming\sweet-page
2015-03-15 19:43 - 2014-12-01 01:32 - 00000000 ____ D () C:\Program Files (x86)\Optimizer Pro 3.11
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Zrobiłam wszystko, niestety nie pomogło :frowning:

Usuń szkodliwe rozszerzenia w przeglądarce Firefox i Chrome

Jeżeli problem będzie nadal występować to zresetuj ustawienia przeglądarki:

Resetowanie ustawień przeglądarki Chrome

W pasek adresu wpisz: about:support Kliknij Odśwież program Firefox.