Reklamy GetPrivate pomoc w usunięciu


(PB94) #1

Witam

Jak w temacie wyskakują mi często reklamy oznaczone GetPrivate.

Mógłby mi ktoś pomóc się tego pozbyć?

 

frst  http://www.wklej.org/id/1760779/

addition  http://www.wklej.org/id/1760780/


(Acorus) #2

Odinstaluj Akamai NetSession Interface.Otwórz notatnik systemowy i wklej:

Task: {9AE044AB-C71E-4EA1-BB22-5BDC3F7F4FD1} - System32\Tasks\IT Viewer Uninstaller = C:\Program Files (x86)\IT Viewer\astask.exe [2015-07-19] (SecureSoft)
Task: {C9E4D81D-FC1B-4115-8257-73C9786F678A} - System32\Tasks\Windows Software = C:\Users\Przemek\AppData\Roaming\Updater\winupd.exe [2015-07-19] () ==== ATTENTION
Task: {CF055BA5-9528-43E1-92F5-C630926AFD13} - System32\Tasks\Malware Cleaner = C:\Users\Przemek\AppData\Roaming\6DBF.tmp.exe [2015-07-19] () ==== ATTENTION
HKLM-x32\...\Run: [HP Software Update] = C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] = [X]
HKU\S-1-5-21-4000385815-2871953458-3254372676-1000\...\Policies\Explorer: []
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKU\S-1-5-21-4000385815-2871953458-3254372676-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://gosearch.me/?u=cd6d0eaf50f19233cdbe5b019ee46dadc=up1src=hpinst=1437313061
SearchScopes: HKLM-x32 - DefaultScope {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL =
SearchScopes: HKU\S-1-5-21-4000385815-2871953458-3254372676-1000 - DefaultScope {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL =
SearchScopes: HKU\S-1-5-21-4000385815-2871953458-3254372676-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHDP725050GLA360_GEA534RF0KG21A0KG21AXts=1422362696type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4000385815-2871953458-3254372676-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHDP725050GLA360_GEA534RF0KG21A0KG21AXts=1422362696type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4000385815-2871953458-3254372676-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHDP725050GLA360_GEA534RF0KG21A0KG21AXts=1422362696type=defaultq={searchTerms}
FF Plugin-x32: yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1 - C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll No File
FF Plugin HKU\S-1-5-21-4000385815-2871953458-3254372676-1000: @onlive.com/OnLiveGameClientDetector,version=1.0.0 - C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll No File
CHR Extension: (ace race) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl [2015-01-27]
CHR Extension: (ace race) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdohfcdfbmkplifgaijhgccjenbcfjop [2015-01-30]
CHR Extension: (ace race) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nofipaokfpfmoiijkdjolhcjhamjccgb [2015-02-10]
CHR Extension: (Bookmark Manager) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21]
R2 PrivoxyService; C:\Program Files (x86)\IT Viewer\privoxy.exe [371200 2015-07-19] (The Privoxy team - www.privoxy.org) [File not signed] ==== ATTENTION
U3 azcy4ra4; C:\Windows\System32\Drivers\azcy4ra4.sys [0] (Microsoft Corporation) ==== ATTENTION (zero byte File/Folder)
2015-07-19 15:37 - 2015-07-19 15:37 - 0000000 _____ () C:\Users\Przemek\AppData\Roaming\6DBF.tmp
2015-07-19 15:37 - 2015-07-19 15:37 - 0803840 _____ () C:\Users\Przemek\AppData\Roaming\6DBF.tmp.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(PB94) #3

Ok, zrobione. Wrzucam fixlog dla pewności

 

fixlog http://www.wklej.org/id/1760804/


(Acorus) #4

Jak wszystko gra to skasuj folder C:\FRST.