Reklamy w przeglądarkach i nowe karty w chrome to zawsze reklamy... "wygraj srajfon 6 itp"


(Juras10) #1

Panowie (i Panie) pomocy, bo combofix na mojej windzie nie działa, a ADWcleaner nie pomógł. Zamieszczam logi dla tych co nie balują dzisiaj i spać nie mogą :wink:

 

http://wklej.to/UI95G

http://wklej.to/2AgIq

 

 

z góry dziękuje


(Atis) #2

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390670114&from=cor&uid=ST500LT012-9WS142_W0VCJCCBXXXXW0VCJCCB&q={searchTerms}
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKU\S-1-5-21-3501941515-2390801579-2987974521-1002 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Extension: ep - C:\Users\LENOVO\AppData\Roaming\Mozilla\Firefox\Profiles\z501p8ad.default\Extensions\jid1-0xtMKhXFEs4jIg@jetpack.xpi [2014-02-22]
FF SearchPlugin: C:\Users\LENOVO\AppData\Roaming\Mozilla\Firefox\Profiles\z501p8ad.default\searchplugins\keepmysearch.xml
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: No Name - C:\Users\LENOVO\AppData\Roaming\Mozilla\Firefox\Profiles\z501p8ad.default\extensions\{58aaf827-6246-4d80-8213-f02005f6345c}.xpi [Not Found]
CHR Extension: (RightSurf) - C:\Users\LENOVO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajjpgnlpolfpnebjjaciccmmjnmjfjkl [2015-01-12]
2015-01-24 22:17 - 2015-01-24 22:26 - 00000000 ____ D () C:\AdwCleaner
2015-01-24 21:44 - 2015-01-24 21:44 - 05609462 _____ (Swearware) C:\Users\LENOVO\Downloads\ComboFix.exe
2015-01-20 15:26 - 2015-01-20 15:26 - 00730528 _____ ( ) C:\Users\LENOVO\Downloads\WinRAR(12398)-dp.exe
2015-01-24 20:33 - 2014-11-05 16:05 - 00000000 ____ D () C:\ProgramData\f4e5cafa-041c-4d83-9f44-9e0fef4a1387
2013-06-27 23:02 - 2013-06-27 23:02 - 0000000 ____ H () C:\ProgramData\DP45977C.lfl
Task: {B818F1E9-9354-4DE6-A4B4-AAA8B9E7D666} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.