Prośba o pomoc - wyskakujące reklamy

Dzień Dobry,

Proszę o pomoc, ponieważ czasami wyskakują mi niechciane reklamy dotyczące np. gier erotycznych, przede wszystkim z racji, że komputer służy dla najmłodszych. Poniżej logi:

FRST: http://www.wklej.org/id/3086363/
Addition: http://www.wklej.org/id/3086364/
Shortcut: http://www.wklej.org/id/3086365/

To są logi z poziomu użytkownika, na którym dzieci pracują. Z poziomu Administratora wygląda to tak:

FRST: http://www.wklej.org/id/3086367/
Addition: http://www.wklej.org/id/3086368/
Shortcut: http://www.wklej.org/id/3086370/

Dziękuję z góry za wszelką pomoc i pozdrawiam.

Odinstaluj Java 7 Update 67,McAfee Security Scan Plus,McAfee WebAdvisor,Microsoft Security Essentials.Otwórz notatnik systemowy i wklej:

CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Brak pliku
Task: {33935573-CED8-45EE-B77B-5AEBF0807176} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3110997775-1424972971-571119436-1000UA => C:\Users\orange\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-05-21] (Facebook Inc.)
Task: {602B6BA2-45EA-4851-B29D-7C984CF9C22F} - System32\Tasks\marcinBrowniesShingledV2 => Rundll32.exe AssureBicentennial.dll,main 7 1 <==== UWAGA
Task: {8AAD03D6-42EF-4503-8805-B088B9F4936C} - System32\Tasks{B3A39B9E-3454-4879-96F4-609787BB06F5} => pcalua.exe -a D:\setup.exe -d D:
Task:
{8D9EF16A-8091-4754-A097-7FF5216A0992} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3110997775-1424972971-571119436-1000Core => C:\Users\orange\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-05-21] (Facebook Inc.)
Task: {A5BFE381-71BC-4F1A-AD9E-F7FC129648AC} - System32\Tasks{4F50BAF6-6515-4622-8B7E-58CBB8800F69} => pcalua.exe -a “D:\KARAOKE program i teksty\vkaraoke.exe” -d "D:\KARAOKE program i teksty"
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3110997775-1424972971-571119436-1000Core.job => C:\Users\orange\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3110997775-1424972971-571119436-1000UA.job => C:\Users\orange\AppData\Local\Facebook\Update\FacebookUpdate.exe
ShortcutWithArgument: C:\Users\marcin\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> {9D6B0768-E83D-4038-92F2-8BECC069254F} "C:\Users\marcin\AppData\Local\Google\Chrome\Application\chrome.exe"
ShortcutWithArgument: C:\Users\marcin\Desktop\WorldofTanks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://go.playmmogames.com/aff_c?offer_id=174&aff_id=1034 --app-window-size=1600,900
ShortcutWithArgument: C:\Users\marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks\WorldofTanks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://go.playmmogames.com/aff_c?offer_id=174&aff_id=1034 --app-window-size=1600,900
ShortcutWithArgument: C:\Users\marcin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://go.playmmogames.com/aff_c?offer_id=174&aff_id=1034 --app-window-size=1600,900
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-03-30]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.523\SSScheduler.exe (McAfee, Inc.)
GroupPolicy\User: Ograniczenia <======= UWAGA
GroupPolicyUsers\S-1-5-21-3110997775-1424972971-571119436-1000\User: Ograniczenia <======= UWAGA
GroupPolicyScripts: Ograniczenia <======= UWAGA
GroupPolicyScripts\User: Ograniczenia <======= UWAGA
HKU.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-3110997775-1424972971-571119436-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKLM -> DefaultScope {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3110997775-1424972971-571119436-1004 -> DefaultScope {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3110997775-1424972971-571119436-1004 -> {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
CHR DefaultSearchURL: Default -> hxxp://www.yessearches.com/chrome.php?q={searchTerms}&ts=AHEpBH8kBX4nC0…&v=20160202&uid=A0579672B49B6D5D8DB591689D142FD4&ptid=ior&mode=nnnb
CHR DefaultSearchKeyword: Default -> yessearches
S2 InstallerService; “C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe” [X]
S3 EagleX64; ??\C:\Windows\system32\drivers\EagleX64.sys [X]
2017-04-14 09:52 - 2017-04-14 10:11 - 00000000 ____D C:\AdwCleaner
C:\Users\orange\CS1.6_v32 - by -=Lukasz=-.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Uruchom jako administrator FRST i kliknij w Fix/Napraw.
Przeskanuj progr. Malwarebytes Anti-Malware http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/

Po odinstalowaniu programów i naprawie wrzucam logi:

FRST: http://www.wklej.org/id/3086427/
Fixlog: http://www.wklej.org/id/3086428/

Dziękuję za pomoc i życzę radosnych Świąt Zmartwychwstania Pańskiego.

Pobierz >>>DelFix<<< http://www.bleepingcomputer.com/download/delfix/dl/281/
Zaznacz opcje:
Remove disinfection tools
Kliknij przycisk Run.

Na moim drugim komputerze (mam nadzieję, że też nie na trzecim) pojawił się podobny problem. Proszę o pomoc. Wklejam logi z konta Administratora (dostęp do wszystkiego), natomiast problemy pojawiają się na koncie użytkownika (czy na adminie to nie wiem, ponieważ użytkuję w razie konieczności).

FRST: http://wklej.org/id/3086545/
Addition: http://wklej.org/id/3086546/
Shortcut: http://wklej.org/id/3086547/

Pozdrawiam.

Odinstaluj IB Updater Service,Internet Explorer Toolbar 4.6 by SweetPacks,Java 7 Update 45,SweetIM for Messenger 3.7,Video Converter,WorldofTanks.Otwórz notatnik systemowy i wklej:

CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-3110997775-1424972971-571119436-1004_Classes\CLSID{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\marcin\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Brak pliku
Task: {64B5F385-BCD8-409D-B3BE-06BDF92C8A2E} - System32\Tasks{32E6B085-6B2D-47BD-BDC6-00BAE3475B7E} => C:\gryT\GameforgeLive\GameforgeLive.exe
Task: {99FCBEC1-2343-46C9-8B4B-A8F39BF3E1E3} - System32\Tasks\orangeSuckledSensiblesV2 => Rundll32.exe BreadbasketGerontotherapy.dll,main 7 1 <==== UWAGA
Task: {E93932DF-E9C5-4699-9D96-86C5E469A451} - \WinTaske -> Brak pliku <==== UWAGA
Task: {EA6181C3-E26D-4F2F-8671-0732CBD3BB01} - System32\Tasks\marcinBrowniesShingledV2 => Rundll32.exe AssureBicentennial.dll,main 7 1 <==== UWAGA
ShortcutWithArgument: C:\Users\marcin\Desktop\WorldofTanks.lnk -> C:\Users\marcin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://go.playmmogames.com/aff_c?offer_id=174&aff_id=1034 --app-window-size=1600,900
ShortcutWithArgument: C:\Users\marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks\WorldofTanks.lnk -> C:\Users\marcin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://go.playmmogames.com/aff_c?offer_id=174&aff_id=1034 --app-window-size=1600,900
ShortcutWithArgument: C:\Users\marcin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk -> C:\Users\marcin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://go.playmmogames.com/aff_c?offer_id=174&aff_id=1034 --app-window-size=1600,900
MSCONFIG\Services: IBUpdaterService => 2
FirewallRules: [{AACC8F15-9D31-43B3-8D86-60FB9C8B5266}] => (Allow) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
FirewallRules: [{15DBB568-A8E0-40FD-A93F-80F2C0D17950}] => (Allow) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup$McRebootA5E6DEAA56$.lnk [2017-04-14]
ShortcutTarget: $McRebootA5E6DEAA56$.lnk -> (Brak pliku)
Startup: C:\Users\orange\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2017-03-28]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\marcin\AppData\Local\Facebook\Games\FacebookGameroom.exe (Brak pliku)
GroupPolicy: Ograniczenia <======= UWAGA
GroupPolicy\User: Ograniczenia <======= UWAGA
GroupPolicyUsers\S-1-5-21-3110997775-1424972971-571119436-1000\User: Ograniczenia <======= UWAGA
GroupPolicyScripts: Ograniczenia <======= UWAGA
GroupPolicyScripts\User: Ograniczenia <======= UWAGA
HKU.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-3110997775-1424972971-571119436-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
SearchScopes: HKLM -> DefaultScope {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0D0C2EAE-AFEC-4F2B-9319-D31709085457} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3110997775-1424972971-571119436-1004 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3110997775-1424972971-571119436-1004 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-3110997775-1424972971-571119436-1004 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.00000&barid={C3192426-2D45-4176-9E87-7AD5B137F03D}
Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04] (SweetIM Technologies Ltd.)
Toolbar: HKU\S-1-5-21-3110997775-1424972971-571119436-1004 -> Brak nazwy - {EEE6C35B-6118-11DC-9C72-001320C79847} - Brak pliku
CHR HomePage: Default -> hxxp://www.yessearches.com/?mode=nnnb&ptid=ior&uid=D865D434B8CEADB9B1AD5A87FDCBBDCB&v=20160202&ts=AHEpBH8kBX4kAU…
CHR StartupUrls: Default -> "hxxp://www.yessearches.com/?mode=nnnb&ptid=ior&uid=D865D434B8CEADB9B1AD5A87FDCBBDCB&v=20160202&ts=AHEpBH8kBX4kAU…"
CHR DefaultSearchURL: Default -> hxxp://www.yessearches.com/chrome.php?q={searchTerms}&ts=AHEpBH8kBX4kAU…&v=20160202&uid=D865D434B8CEADB9B1AD5A87FDCBBDCB&ptid=ior&mode=nnnb
CHR DefaultSearchKeyword: Default -> yessearches
S2 0140041492173927mcinstcleanup; C:\Users\marcin\AppData\Local\Temp\014004~1.EXE [883024 2017-04-06] (McAfee, Inc.) <==== UWAGA
S4 IBUpdaterService; C:\Windows\system32\dmwu.exe [3039536 2015-01-05] ()
S3 EagleX64; ??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 xhunter1; ??\C:\Windows\xhunter1.sys [X]
C:\Users\orange\CS1.6_v32 - by -=Wolanicki=-.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Uruchom jako administrator FRST i kliknij w Fix/Napraw.
Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść).

Wklejam logi:

FRST: http://wklej.org/id/3086612/
Fixlog: http://wklej.org/id/3086615/

Pozdrawiam.

Otwórz notatnik systemowy i wklej:

C:\Users\marcin\AppData\Local\Temp\DeleteOnReboot.bat
DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Uruchom jako administrator FRST i kliknij w Fix/Napraw.
Pobierz >>>DelFix<<< http://www.bleepingcomputer.com/download/delfix/dl/281/
Zaznacz opcje:
Remove disinfection tools
Kliknij przycisk Run.

Dzień Dobry,

Pomogliście mi ostatnio przy dwóch komputerach. Mam do was prośbę, abyście sprawdzili mi również trzeci komputer. To dla mnie ważne, ponieważ to komputery służbowe w placówce wychowawczej dla dzieci. Wysyłam logi.

FRST: http://wklej.org/id/3088983/
Addition: http://wklej.org/id/3088984/
Shortcut: http://wklej.org/id/3088985/

Pozdrawiam.

Odinstaluj WarThunder,WorldofTanks.Otwórz notatnik systemowy i wklej:

http://wklej.org/id/3089133/
Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Uruchom jako administrator FRST i kliknij w Fix/Napraw.

Wklejam logi:

FRST: http://wklej.org/id/3089155/
Fixlog: http://wklej.org/id/3089154/

Dziękuję.

Pobierz >>>DelFix<<< http://www.bleepingcomputer.com/download/delfix/dl/281/
Zaznacz opcje:
Remove disinfection tools
Kliknij przycisk Run.