Reklamy sale charger

Witam, mój problem polega na tym, że ostatnio wyskakuje mi wiele niechcianych reklam by sale charger (czym kolwiek to jest). Szukałem już pomocy w internetach i polecano mi abym zainstalował jakiś program antyspyware. żaden nic nie wykrył. żadnych podejrzanych rozszerzeń w przeglądarce też nie widzę (google chrome). odrazu mówię, że jestem zielony w tych sprawach i serdecznie proszę o pomoc! 

brainwave Wymagane są raporty FRST wykonane zgodnie z instrukcją http://forum.dobreprogramy.pl/farbar-recovery-scan-tool-raport-obowi%C4%85zkowy-t478727/

ohh dziękuję: 

addition: http://www.wklej.org/id/1712416/

frst: http://www.wklej.org/id/1712420/

 z góry dziękuję za pomoc

Odinstaluj Adobe Reader 9.5.0 - Polish,Spybot - Search & Destroy.Otwórz notatnik systemowy i wklej:

Task: {47F35DEE-457B-4F72-8259-C3A2E92CF9C2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system = C:\Program Files (x86)\Spybot - Search Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {5940F195-2186-475B-864C-59DF47F59E64} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization = C:\Program Files (x86)\Spybot - Search Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {752B3027-DE03-4B28-B80D-85CECBF9A14C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates = C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] = C:\Program Files (x86)\Spybot - Search Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=dsts=1431627652z=7087a190ddf1a3be93056b7gfz9c8gbqdoam3q5z2bfrom=coruid=ST9320325AS_5VEPSYRSXXXX5VEPSYRSq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=dsts=1431627652z=7087a190ddf1a3be93056b7gfz9c8gbqdoam3q5z2bfrom=coruid=ST9320325AS_5VEPSYRSXXXX5VEPSYRSq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=dsts=1431627652z=7087a190ddf1a3be93056b7gfz9c8gbqdoam3q5z2bfrom=coruid=ST9320325AS_5VEPSYRSXXXX5VEPSYRSq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=dsts=1431627652z=7087a190ddf1a3be93056b7gfz9c8gbqdoam3q5z2bfrom=coruid=ST9320325AS_5VEPSYRSXXXX5VEPSYRSq={searchTerms}
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HomePage: Default - hxxp://do-search.com/?type=hpts=1430642774from=coruid=ST9320325AS_5VEPSYRSXXXX5VEPSYRS
CHR DefaultSearchURL: Default - http://do-search.com/web/?type=dsts=1431627652z=7087a190ddf1a3be93056b7gfz9c8gbqdoam3q5z2bfrom=coruid=ST9320325AS_5VEPSYRSXXXX5VEPSYRSq={searchTerms}
CHR Extension: (Bookmark Manager) - C:\Users\8\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 a2acc; \\C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [X]
R1 A2DDA; \\C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [X]
2015-05-14 21:14 - 2015-05-14 21:14 - 00000000 ____ D () C:\Windows\System32\Tasks\Safer-Networking
2015-05-14 21:13 - 2015-05-14 22:42 - 00000000 ____ D () C:\ProgramData\Spybot - Search Destroy
2015-05-14 21:13 - 2015-05-14 21:19 - 00000000 ____ D () C:\Program Files (x86)\Spybot - Search Destroy 2
2015-05-14 21:13 - 2015-05-14 21:13 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-SD Start Center.lnk
2015-05-14 21:13 - 2015-05-14 21:13 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-SD Start Center.lnk
2015-05-14 21:13 - 2015-05-14 21:13 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search Destroy 2
2015-05-14 21:13 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-05-14 21:12 - 2015-05-14 21:12 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\8\Downloads\spybot-2.4.exe
2015-05-14 21:08 - 2015-05-14 21:08 - 00741672 _____ (Web software ) C:\Users\8\Downloads\Spybot-Search-Destroy(12546)-dp.exe
2015-05-14 20:21 - 2015-05-14 20:21 - 21901888 _____ (SUPERAntiSpyware) C:\Users\8\Downloads\SUPERAntiSpyware.exe
2015-05-14 20:18 - 2015-05-14 20:19 - 00741672 _____ (Web software ) C:\Users\8\Downloads\SUPERAntiSpyware-Free-Edition(13150)-dp.exe
2015-05-14 20:12 - 2015-05-14 20:13 - 08402592 _____ (Crawler Group ) C:\Users\8\Downloads\SpywareTerminatorSetup.exe
2015-05-14 19:27 - 2015-05-14 19:27 - 00000000 _____ () C:\autoexec.bat
2015-05-14 19:21 - 2015-05-14 19:22 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\8\Downloads\sh-remover.exe
2015-05-13 12:40 - 2015-05-13 18:10 - 00000000 ____ D () C:\AdwCleaner
2015-05-03 10:43 - 2015-05-03 10:43 - 00741672 _____ (Web software ) C:\Users\8\Downloads\GPL-Ghostscript(13112)-dp.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

w folderze logs?

Tam gdzie masz FRST czyli C:\Users\8\Downloads

dziękuje najmocniej. problem rozwiązany :slight_smile: