Round World

Poddaje się. Nie potrafię bez waszej pomocy usunąć tego ustrojstwa

 

Logi

FRST - http://wklej.to/VH4lA

Addition - http://wklej.to/SA792

Odinstaluj Adobe Reader 9.1 - Polish,Round World,Spybot - Search & Destroy.Otwórz notatnik systemowy i wklej:

Task: {2AA3B6FD-DFC3-4199-8C77-3BE226CE114E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization = C:\Program Files (x86)\Spybot - Search amp; Destroy 2\SDImmunize.exe
Task: {4518C06A-F6E3-4A89-A5D0-13B76E069074} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system = C:\Program Files (x86)\Spybot - Search amp; Destroy 2\SDScan.exe
Task: {DC9372FF-F713-4BBE-B409-6D9363C8EF66} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates = C:\Program Files (x86)\Spybot - Search amp; Destroy 2\SDUpdate.exe
HKLM-x32\...\Run: [] = [X]
HKLM-x32\...\Run: [SDTray] = C:\Program Files (x86)\Spybot - Search Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2579310559-4214741109-428214017-1001\...\Run: [ALLUpdate] = C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2765256 2014-11-03] (ALLPlayer Group Ltd.)
HKU\S-1-5-21-2579310559-4214741109-428214017-1001\...\Run: [ALLPlayer WiFi Remote] = C:\Program Files (x86)\ALLPlayer Remote\ALLPlayerRemoteControl.exe [5182896 2014-07-23] (ALLPlayer Group Ltd.)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\S-1-5-21-2579310559-4214741109-428214017-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Round World 1.0.0.7 - {78549bde-b964-4d2a-b7b1-c4ac15ddff64} - C:\Program Files (x86)\Round World\RoundWorldbho.dll (Round World)
Toolbar: HKU\S-1-5-21-2579310559-4214741109-428214017-1001 - No Name - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File
FF Extension: Round World 1.0.1 - C:\Users\Kamil\AppData\Roaming\Mozilla\Firefox\Profiles\ym1bexed.default\Extensions\{d0194130-21b3-4618-b5c8-b6dfe1e0bb88}.xpi [2015-02-12]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 Update Round World; C:\Program Files (x86)\Round World\updateRoundWorld.exe [405232 2015-02-20] ()
R2 Util Round World; C:\Program Files (x86)\Round World\bin\utilRoundWorld.exe [405232 2015-02-20] ()
R1 {d0194130-21b3-4618-b5c8-b6dfe1e0bb88}Gw64; C:\Windows\System32\drivers\{d0194130-21b3-4618-b5c8-b6dfe1e0bb88}Gw64.sys [48784 2015-02-11] (StdLib)
U4 eabfiltr; No ImagePath
2015-02-13 17:43 - 2015-02-13 17:43 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-SD Start Center.lnk
2015-02-13 17:43 - 2015-02-13 17:43 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-SD Start Center.lnk
2015-02-13 17:43 - 2015-02-13 17:43 - 00000000 ____ D () C:\Windows\System32\Tasks\Safer-Networking
2015-02-13 17:43 - 2015-02-13 17:43 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search Destroy 2
2015-02-13 17:42 - 2015-02-14 05:30 - 00000000 ____ D () C:\ProgramData\Spybot - Search Destroy
2015-02-13 17:42 - 2015-02-13 17:53 - 00000000 ____ D () C:\Program Files (x86)\Spybot - Search Destroy 2
2015-02-13 17:42 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-02-13 17:39 - 2015-02-13 17:39 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Kamil\Downloads\spybot-2.4.exe
2015-02-13 17:38 - 2015-02-13 17:38 - 00728784 _____ (Web ) C:\Users\Kamil\Downloads\Spybot-Search-Destroy(12546)-dp.exe
2015-02-12 15:38 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-12 15:38 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-12 15:38 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-12 15:38 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-12 15:38 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-12 15:38 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-12 15:38 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-12 15:38 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-12 15:36 - 2015-02-12 15:55 - 00000000 ____ D () C:\Qoobox
2015-02-12 15:22 - 2015-02-20 18:11 - 00000000 ____ D () C:\Program Files (x86)\Round World
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Its done.

Pomogło. Dzieki wielkie!

Skasuj folder C:\FRST