Problem z PHD-V1.4

Tak jak w temacie robiłem już skan AdwCleaner i FRST tutaj są logi addition: http://wklej.org/id/1507921/ i FRST: http://wklej.org/id/1507920/

Odinstaluj omiga-plus uninstall.Otwórz Notatnik i wklej:

Task: {38F41F80-EAEE-4F3B-BBFB-3ADDD822F5AE} - System32\Tasks\{7519CE1C-4527-4F73-8770-C4CA3632AEAB} = Firefox.exe http://ui.skype.com/ui/0/6.0.0.126/pl/go/help.faq.installer?LastError=1603
Task: {6D8D492D-F9B2-4DBD-8AA0-781DC5C64999} - System32\Tasks\{03DBD988-8A63-481E-8BB6-910484B948A7} = Firefox.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {76094CB4-D9E5-4F91-A546-DF97ACD4CFB8} - System32\Tasks\{955FDEB2-E7A6-4313-914B-2BC5EC022850} = Firefox.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsProgressBar
Task: {7EEEBAD0-8A6A-4D84-8EC2-890AC3869507} - System32\Tasks\AutoKMS = C:\Windows\AutoKMS.exe
Task: {84F34861-DD0F-4248-A8AE-7B193DBE311F} - System32\Tasks\{19A937B5-97B9-434F-956C-EF099391B411} = Firefox.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/go/help.faq.installer?LastError=1603
Task: {A34A95B2-B0BE-4CC8-86D3-2BD58C5B98DE} - System32\Tasks\{7BF077BB-034A-4257-8833-3D2954F20526} = Firefox.exe http://ui.skype.com/ui/0/6.1.60.129/pl/go/help.faq.installer?LastError=1603
Task: {CCBADFA8-1A84-4C28-A41D-C5816780F700} - System32\Tasks\{CD07C667-F290-4BD6-968F-36734100B2E8} = Firefox.exe http://ui.skype.com/ui/0/6.1.60.129/pl/go/help.faq.installer?LastError=1603
Task: {D6BE17EC-409D-4061-A2D4-E12FAFCA7AE7} - System32\Tasks\{43DA04E3-4935-414B-9557-66BDF894D7A9} = Chrome.exe http://ui.skype.com/ui/0/6.9.0.106/pl/abandoninstall?page=tsProgressBar
Task: {E0437EC1-F664-4AA3-8607-A5CDE842F720} - System32\Tasks\Norton Security Scan for Krzysiek = C:\PROGRA~1\NORTON~2\Engine\372~1.5\Nss.exe
Task: C:\Windows\Tasks\Norton Security Scan for Krzysiek.job = C:\PROGRA~1\NORTON~2\Engine\372~1.5\Nss.exe
HKLM\...\Run: [] = [X]
HKU\S-1-5-21-1991266834-2192364194-3553995823-1000\...\Run: [] = [X]
HKU\S-1-5-21-1991266834-2192364194-3553995823-1000\...\Policies\Explorer: []
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
SearchScopes: HKCU - C697B4BCC1944BFA8B644F92CB907E97 URL = http://search.qvo6.com/web/?utm_source=butm_medium=corutm_campaign=eXQutm_content=dsfrom=coruid=WDCXWD10EARX-00N0YB0_WD-WMC0T076263362633ts=1380365417type=defaultq={searchTerms}
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\omiga-plus.xml
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebmimfiebnacmhoefflfhekoibleadi [2014-01-30]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgjkhjdcljddbedokogakmmdjgnbeanf [2013-10-13]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\eapokaddieafomfoodnjinegahmemooi [2014-06-08]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebimcjblbgpkoljekjlhohbolakebceo [2014-02-28]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj [2014-01-18]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jigepcnhplclilmbjlpdhjljdonhoebd [2014-05-25]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kggidbdkggadcaegcegndbppjplcgbfe [2013-12-31]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\legocaboiicfjgofnmlgnogcngeokmga [2014-09-15]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocblcnaofikinigmceddfghppkkjbog [2013-10-13]
CHR Extension: (No Name) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-07-12]
CHR Extension: (PHD-V1.4) - C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pofekaindcmmojfnfgbpklepkjfilcep [2014-07-17]
CHR Extension: (GGoSave) - C:\ProgramData\onfaodkngoiopaijlnaggjajodcalhoa\ [2014-07-17]
S2 892cc6a3; "C:\Windows\system32\rundll32.exe" "c:\progra~2\perfor~1\PerformanceOptimizerSvc.dll",service
S3 EagleXNt; \\C:\Windows\system32\drivers\EagleXNt.sys [X]
S2 LMIInfo; \\D:\Programy\LogMeIn\x86\RaInfo.sys [X]
S4 LMIRfsClientNP; No ImagePath
S3 massfilter_lte; \\C:\Windows\system32\drivers\massfilter_lte.sys [X]
S1 MpKsldd6fa70b; \\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{12F39F26-D003-4D83-935C-D06DCF9A3730}\MpKsldd6fa70b.sys [X]
S3 zgdcat; system32\DRIVERS\zgdcat.sys [X]
S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [X]
S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [X]
S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [X]
S3 zgdcnmea; system32\DRIVERS\zgdcnmea.sys [X]
2014-11-03 17:38 - 2014-11-03 17:44 - 00000000 ____ D () C:\AdwCleaner
2014-10-26 17:14 - 2014-10-26 17:14 - 00000000 ____ D () C:\ProgramData\onfaodkngoiopaijlnaggjajodcalhoa
C:\Users\Krzysiek\jagex_cl_runescape_LIVE.dat
C:\Users\Krzysiek\jagex_cl_runescape_LIVE1.dat
C:\Users\Krzysiek\random.dat
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Dzięki wielkie za pomoc.

Skasuj folder C:\FRST

Ok jeszcze raz dzięki