Reklamy i mulenie komputera


(Saperwojtek) #1

Potrzebuje pomocy w sprawie reklam z którymi juz nie daję sobie rady. Dosłownie po kazdym kliknięciu na ekranie komputera otwiera się ich multum. Kolejna rzecz to zamulanie. Proszę o pomoc.

 

http://wklej.to/zR0zn

http://wklej.to/AvPwc

 


(Acorus) #2

Odinstaluj Update for PriceFountain.Otwórz notatnik systemowy i wklej:

Task: {4D3448A6-F544-49E8-AA3F-DC74C4C81266} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-583252620-3674122615-3486878418-1001Core = C:\Users\piootrki\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-29] (Facebook Inc.)
Task: {7CC8A8D8-C623-4A4B-8067-A373AC562E47} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-583252620-3674122615-3486878418-1001UA = C:\Users\piootrki\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-11-29]
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-583252620-3674122615-3486878418-1001Core.job = C:\Users\piootrki\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-583252620-3674122615-3486878418-1001UA.job = C:\Users\piootrki\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKLM\...\Run: [SpywareTerminatorShield] = C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM\...\Run: [SpywareTerminatorUpdater] = C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM-x32\...\Run: [] = [X]
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-583252620-3674122615-3486878418-1001\...\Run: [Facebook Update] = C:\Users\piootrki\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-11-29] (Facebook Inc.)
HKU\S-1-5-21-583252620-3674122615-3486878418-1001\...\Run: [pricefountainw.exe] = C:\Users\piootrki\AppData\Local\PriceFountain\pricefountainw.exe HKEY_CURRENT_USER Software\PriceFountain
ShellIconOverlayIdentifiers: [00avast] - {472083B0-C522-11CF-8763-00608CC02F24} = No File
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKU\S-1-5-21-583252620-3674122615-3486878418-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKLM - {48083557-22B5-41F6-AE38-7D89ACD77705} URL = http://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8tag=hp-de2-vsb-21link%5Fcode=qsindex=apsfield-keywords={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: unisalees - {7e067e9d-1007-44f2-a178-be6999960b1b} - C:\Program Files (x86)\unisalees\GWzLMLDpdS2Tl6.x64.dll ()
BHO: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
BHO-x32: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.thesearchpage.info/?pid=2921r=2015/01/17hid=17548815540167768463lg=ENcc=DEunqvl=74l=1q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml
FF Extension: youtubeadblocker - C:\Users\piootrki\AppData\Roaming\Mozilla\Firefox\Profiles\fu8d3chi.default\Extensions\FrPJCYoO@pu.org [2015-01-17]
FF Extension: unisaless - C:\Users\piootrki\AppData\Roaming\Mozilla\Firefox\Profiles\fu8d3chi.default\Extensions\Nm@nk.com [2015-01-17]
FF Extension: xmldeveloperritedu - C:\Users\piootrki\AppData\Roaming\Mozilla\Firefox\Profiles\fu8d3chi.default\Extensions\xmldeveloper@rit.edu [2014-12-07]
FF Extension: PriceFountain - C:\Users\piootrki\AppData\Roaming\Mozilla\Firefox\Profiles\fu8d3chi.default\Extensions\{b6a94784-0ffb-4121-88c6-435139067ee2}.xpi [2014-12-28]
CHR Extension: (Bookolio) - C:\Users\piootrki\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbgmbgopjppdjfopndcniomnhpodajba [2015-01-17]
CHR Extension: (YouTube Unblocker) - C:\Users\piootrki\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2015-02-06]
CHR Extension: (unisaless) - C:\ProgramData\epdjcilhoghnleoookmbamjnmhcpaocn\ [2014-12-28]
OPR Extension: (YouTube Unblocker) - C:\Users\piootrki\AppData\Roaming\Opera Software\Opera Stable\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2015-02-07]
2015-01-17 01:02 - 2015-01-24 17:44 - 00000000 ____ D () C:\Program Files (x86)\unisalees
2015-01-17 01:02 - 2015-01-24 17:44 - 00000000 ____ D () C:\Program Files (x86)\Bookolio
2015-01-17 01:01 - 2015-01-24 17:44 - 00000000 ____ D () C:\Program Files (x86)\unisaless
2015-01-17 01:01 - 2015-01-17 01:01 - 00000000 ____ D () C:\ProgramData\epdjcilhoghnleoookmbamjnmhcpaocn
2015-01-17 01:01 - 2015-01-17 01:01 - 00000000 ____ D () C:\ProgramData\15345593214688701746
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.