Reklamy, nie mogę usunąć


(Mirenowa89) #1

Witam serdecznie. Jestem bezradny w sprawie reklam wyskakujących na każdej nowo otwartej stronie, oprócz tego, pojawiają się na stronach małe prostokątne reklamy których pozbyć się nie mogę. Mam również problem z otwieraniem nie których stron np. seansik.pl gdzie wyskakuje info DOMENA NA SPRZEDAŻ. Proszę pomóżcie. Z góry wielkie dzięki, pozdrawiam.


(Atronics) #2

to wykonaj jak tutaj opisane 

http://forum.dobreprogramy.pl/farbar-recovery-scan-tool-raport-obowiązkowy-t478727/


(Mirenowa89) #3

http://wklej.to/72EQr

http://wklej.to/tAQyt

 

Proszę o dalsze instrukcje. Dzięki pozdrawiam. 


(Atis) #4

Przestań pobierać szkodliwe pliki.

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-11-08]
Startup: C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\the settlers 7 paths to a kingdom deluxe gold edition tinyiso t7138721.lnk [2015-04-29]
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX&q={searchTerms}
HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX
HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX&q={searchTerms}
HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX
HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1430313231&from=wpc&uid=HitachiXHTS545050A7E380_TE854349CASD5RCASD5RX&q={searchTerms}
SearchScopes: HKLM -> {23DDE2A0-6475-44C2-90D9-198BB738B1B1} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/1185-154363-12092-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://es.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-4284688938-1998401333-4194139215-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = 
BHO: bestadblocker -> {06bbf236-c250-46c1-9d41-d6e76f09e0a8} -> C:\Program Files (x86)\bestadblocker\7or0xsr3tmxVOg.x64.dll [2015-04-29] ()
BHO: CuliCkForSalee -> {0891b570-854b-413b-9034-8d925378e67c} -> C:\Program Files (x86)\CuliCkForSalee\GDXaIdmQ8Ob59V.x64.dll No File
BHO: SalesMaGNeet -> {5a60a0bf-960e-4d03-8a62-05187c26b4f2} -> C:\Program Files (x86)\SalesMaGNeet\uhtrgES7kuLGve.x64.dll No File
BHO: SuaverAADDon -> {862d35fa-3578-4788-a33b-b86ea5565a1b} -> C:\Program Files (x86)\SuaverAADDon\P9PkLxnhrJZOVx.x64.dll No File
BHO: PrriincaeCCoUpeon -> {dbdafdb6-2897-4b48-ac72-81f3bab709f9} -> C:\Program Files (x86)\PrriincaeCCoUpeon\4LTeud02bAOt21.x64.dll No File
BHO-x32: bestadblocker -> {06bbf236-c250-46c1-9d41-d6e76f09e0a8} -> C:\Program Files (x86)\bestadblocker\7or0xsr3tmxVOg.dll [2015-04-29] ()
FF Extension: jid1vhLR6vkMUx9cswjetpack - C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\w5x7depi.default\Extensions\jid1-vhLR6vkMUx9csw@jetpack [2014-10-26]
FF HKU\S-1-5-21-4284688938-1998401333-4194139215-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
U4 BthAvrcpTg; No ImagePath
U4 BthHFEnum; No ImagePath
U4 bthhfhid; No ImagePath
2015-04-29 15:18 - 2015-04-29 15:18 - 00000000 _____ () C:\Users\PC1\AppData\Local\Temp.dat
2015-04-29 15:17 - 2015-04-29 15:17 - 00000000 ____ D () C:\ProgramData\9a6a096800001c64
2015-04-29 15:15 - 2015-04-29 15:15 - 00000000 ____ D () C:\Users\PC1\AppData\Roaming\EZDownloader
2015-04-29 15:11 - 2015-04-29 15:11 - 00000000 ____ D () C:\ProgramData\ocppkomgpaebecgmjbohfjejfpacaogl
2015-04-29 15:11 - 2015-04-29 15:11 - 00000000 ____ D () C:\Program Files (x86)\bestadblocker
2015-04-29 15:10 - 2015-04-29 15:10 - 00301568 _____ () C:\Users\PC1\Downloads\the settlers 7 paths to a kingdom deluxe gold edition tinyiso t7138721.exe
2015-04-29 15:10 - 2015-04-29 15:10 - 00000000 ____ D () C:\ProgramData\{e7b6f241-6adb-872d-e7b6-6f2416adc905}
2015-04-22 12:41 - 2015-04-22 13:36 - 00000000 ____ D () C:\AdwCleaner
2015-04-08 20:29 - 2015-04-09 20:29 - 00000000 ____ D () C:\ProgramData\T122078ED
2015-04-22 14:24 - 2015-01-21 22:26 - 00000000 ____ D () C:\ProgramData\FLoaosshCouupon
2015-04-22 14:24 - 2015-01-06 10:38 - 00000000 ____ D () C:\ProgramData\reaaldEAl
2015-04-22 14:24 - 2015-01-01 09:50 - 00000000 ____ D () C:\ProgramData\QueeenCouPonu
2015-04-22 14:24 - 2014-10-28 21:55 - 00000000 ____ D () C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2
2015-04-22 14:24 - 2014-10-15 21:51 - 00000000 ____ D () C:\ProgramData\savereboX
2015-04-22 14:24 - 2014-09-23 16:52 - 00000000 ____ D () C:\Users\PC1\AppData\Local\com
2015-04-22 13:26 - 2014-09-23 16:50 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-03-04 23:42 - 2015-03-04 23:42 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-02-01 22:22 - 2015-03-10 23:56 - 0000020 _____ () C:\Users\PC1\AppData\Roaming\appdataFr3.bin
2015-04-29 15:18 - 2015-04-29 15:18 - 0000796 _____ () C:\Users\PC1\AppData\Local\Temp-log.txt
2015-04-29 15:18 - 2015-04-29 15:18 - 0000000 _____ () C:\Users\PC1\AppData\Local\Temp.dat
Task: {0E90AADD-86AA-4D22-9523-D88F70C18FA6} - System32\Tasks\7862C8D9-066E-4051-A850-CEFDAE4E2322{24B4626E-51D0-424A-9A22-8EBE917A2DC7} => C:\Program Files\Shop For Rewards\PrefHelper.exe <==== ATTENTION
Task: {6CD88508-B4CD-43E8-BA44-CE1314CB3808} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {785D2760-5648-49EC-96D8-14146A633479} - System32\Tasks\OlacaritaUpdateTaskMachineUA => C:\Program Files (x86)\Olacarita\Update\OlacaritaUpdate.exe
Task: {A00D5BD1-E420-40A7-B5D7-8C6867D27FF2} - System32\Tasks\{5965A123-B7D6-455A-A2A8-941192E47B78} => pcalua.exe -a C:\Users\PC1\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {BC577C00-8BB2-4B11-8C64-BA91DA10A9F1} - System32\Tasks\Bidaily Synchronize Task => C:\ProgramData\{e7b6f241-6adb-872d-e7b6-6f2416adc905}\the settlers 7 paths to a kingdom deluxe gold edition tinyiso t7138721.exe [2014-04-29] ()
Task: {C1F7C5E8-6E64-45FA-931C-7B88DB616F98} - System32\Tasks\{B3A8FD9F-4971-47BB-A944-ED2A33345116} => pcalua.exe -a "C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe"
Task: C:\WINDOWS\Tasks\7862C8D9-066E-4051-A850-CEFDAE4E2322{24B4626E-51D0-424A-9A22-8EBE917A2DC7}.job => C:\Program Files\Shop For Rewards\PrefHelper.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Bidaily Synchronize Task.job => C:\ProgramData\{e7b6f241-6adb-872d-e7b6-6f2416adc905}\the settlers 7 paths to a kingdom deluxe gold edition tinyiso t7138721.exe
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Odinstaluj Chrome zaznaczając usunięcie danych przeglądania.

Najpierw możesz wyeksportować zakładki: KLIK

Geek Uninstaller Free: KLIK

Później zainstaluj stabilną wersję: KLIK

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Mirenowa89) #5

http://wklej.to/4VRC8     Fixlog raport

http://wklej.to/J6D6q      FRST raport

 

Proszę o dalsze instrukcje, pozdrawiam.


(Atis) #6

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

2015-04-29 15:12 - 2014-12-13 19:30 - 00000000 ____ D () C:\ProgramData\11629609185299030720
2015-04-22 12:54 - 2014-09-23 13:23 - 00001095 _____ () C:\Users\PC1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
DeleteQuarantine:

Uruchom FRST i kliknij Fix. Skasuj folder C:\FRST

Usuń stare punkty przywracania: Przywracanie systemu i kopie w tle

Dysk przeskanuj ESET Online Scanner

Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK - KLIK