Problem z reklamami w przeglądarce. Strong Signal


(Radekbrb) #1

Witam tak jak w temacie mam poważny problem z wyskakującymi reklamami w przeglądarce. Jest to do tego stopnia uciążliwe że nawet nie potrafię dodać postu na forum. Ale do rzeczy ja jestem w tym zielony dlatego też proszę o pomoc kogoś doświadczonego. Z tego co wyczytalem to powinienem zrobic skan FRST więc zamieszczam.

 

FRST http://wklej.org/id/1704028/

 

Addition http://wklej.org/id/1704029/

 

Jeżeli jest ktoś chętny mi pomóc to proszę opisać co dokładnie mam zrobić.

 

Z góry dziękuje.


(Atis) #2

Usuń szkodliwe rozszerzenie. W pasek adresu wpisz: opera:extensions

Pobierz i uruchom AdwCleaner Kliknij Scan i później Cleaning.

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Radekbrb) #3

Zrobiłem tak jak mówiłeś.

 

FRST http://www.wklej.org/id/1704184/


(Atis) #4

Miałeś usunąć rozszerzenie.

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM\...\Policies\Explorer: [NoControlPanel] 0
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044
HKU\S-1-5-21-714452950-1732405030-2511647881-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044
HKU\S-1-5-21-714452950-1732405030-2511647881-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> {A0932614-200E-485F-A55A-492CC500ADC4} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\Sony\MSS\3.8.141\McAfeeMSS_IE.dll [2014-01-16] (McAfee, Inc.)
BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
OPR StartupUrls: "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-19 __alt__ ddc_dsssyc_bd_com"
OPR Extension: (Strong Signal) - C:\Users\Radoslaw\AppData\Roaming\Opera Software\Opera Stable\Extensions\fhenmccifbacmpkimjenglmplcpiehke [2015-05-05]
S3 McComponentHostServiceSony; C:\Program Files\Sony\MSS\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 Update Mgr StrongSignal; C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\Updater.exe [478992 2015-05-05] ()
S2 McAPExe; "C:\Program Files\McAfee\MSC\McAPExe.exe" [X]
S2 vstor2; \??\C:\Program Files (x86)\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys [X]
2015-05-05 19:56 - 2015-05-05 20:01 - 00000000 ____ D () C:\AdwCleaner
2015-05-04 11:17 - 2015-05-05 17:22 - 00000000 ____ D () C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\Program Files\Sony\MSS
Task: {32016645-F5AB-4847-81D3-27A2EE7416B8} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
AlternateDataStreams: C:\ProgramData:3f80b7866a646e
AlternateDataStreams: C:\ProgramData:fe93a19e34e9a
AlternateDataStreams: C:\Users\All Users:3f80b7866a646e
AlternateDataStreams: C:\Users\All Users:fe93a19e34e9a
AlternateDataStreams: C:\Users\Radoslaw:eea8e2b8b52ca8e
AlternateDataStreams: C:\ProgramData\Application Data:3f80b7866a646e
AlternateDataStreams: C:\ProgramData\Application Data:fe93a19e34e9a
AlternateDataStreams: C:\ProgramData\Dane aplikacji:3f80b7866a646e
AlternateDataStreams: C:\ProgramData\Dane aplikacji:fe93a19e34e9a
AlternateDataStreams: C:\Users\Radoslaw\Dane aplikacji:6c5309881
AlternateDataStreams: C:\Users\Radoslaw\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\Radoslaw\Ustawienia lokalne:7555b3712bbd2b
AlternateDataStreams: C:\Users\Radoslaw\AppData\Local:7555b3712bbd2b
AlternateDataStreams: C:\Users\Radoslaw\AppData\Roaming:6c5309881
AlternateDataStreams: C:\Users\Radoslaw\AppData\Local\Dane aplikacji:7555b3712bbd2b
AlternateDataStreams: C:\Users\Radoslaw\AppData\Local\Historia:36e22acb38d42
AlternateDataStreams: C:\Users\Radoslaw\AppData\Local\Temp:e5aa6c37b
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Radekbrb) #5

Rozszerzenie usunąłem zaraz na początku jak napisałeś.

Fixlog http://www.wklej.org/id/1704780/

FRST http://www.wklej.org/id/1704786/


(Atis) #6

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

HKU\S-1-5-21-714452950-1732405030-2511647881-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> {A0932614-200E-485F-A55A-492CC500ADC4} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
S2 Service Mgr StrongSignal; "C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.exe" [X]
2015-05-05 20:10 - 2015-05-05 20:10 - 00000000 ____ D () C:\Program Files (x86)\Strong Signal
2015-05-06 14:36 - 2015-05-06 14:36 - 00000000 ____ D () C:\Users\Radoslaw\Downloads\FRST-OlderVersion
HKU\S-1-5-21-714452950-1732405030-2511647881-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1001 -> {A0932614-200E-485F-A55A-492CC500ADC4} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
SearchScopes: HKU\S-1-5-21-714452950-1732405030-2511647881-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_03db4eb8-9dfa-4cb1-bec1-f885da98b044&q={searchTerms}
S2 Service Mgr StrongSignal; "C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\PluginContainer.exe" [X]
2015-05-05 20:10 - 2015-05-05 20:10 - 00000000 ____ D () C:\Program Files (x86)\Strong Signal
2015-05-06 14:36 - 2015-05-06 14:36 - 00000000 ____ D () C:\Users\Radoslaw\Downloads\FRST-OlderVersion
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
DeleteQuarantine:

Uruchom FRST i kliknij Fix. Skasuj folder C:\FRST

Usuń stare punkty przywracania: Przywracanie systemu i kopie w tle

Dysk przeskanuj Malwarebytes Anti-Malware

Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.

http://wstaw.org/m/2014/03/25/2014-03-25_123039.png

Język PL > Settings > General Settings > Language > Polish

Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK - KLIK

Odinstaluj:

Adobe Reader XI

Java 7 Update 13

Java 7 Update 65

Zainstaluj:

Adobe Reader XI 11.0.10

Java 8 Update 45


(Radekbrb) #7

Zrobiłem tak jak pisałeś. Bardzo dziekuję za pomoc :wink: