S.coldsearch google chrome


(pinkman) #1

Witam,


(Atis) #2

Pobierz i uruchom AdwCleaner

Kliknij Skanuj (Scan) i pokaż nowy raport  FRST i Addition.

 


(pinkman) #3

FRST: http://wklej.org/id/1916060/

 


(Atis) #4

Odinstaluj SpyHunter.

HKU\S-1-5-21-2575825379-2885212958-1622368239-1000\...\Run: [{CA54CA00-2414-4C76-82B9-2D99476D0618}] = powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\IUVVKRWZB').bQrWwttG)));
CHR HKU\S-1-5-21-2575825379-2885212958-1622368239-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
S2 HuaweiHiSuiteService64.exe; "C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service [X]
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [327064 2010-05-18] (Enigma Software Group USA, LLC.)
S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [5248 2010-01-27] () [Brak podpisu cyfrowego]
2016-01-23 16:01 - 2016-01-23 16:02 - 00000000 ____ D C:\AdwCleaner
2016-01-23 14:52 - 2016-01-23 14:52 - 00003334 _____ C:\Windows\System32\Tasks\SpyHunter4Startup
2016-01-23 14:52 - 2016-01-23 14:52 - 00000000 ____ D C:\Users\Mariusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2016-01-23 14:52 - 2016-01-23 14:52 - 00000000 ____ D C:\sh4ldr
2016-01-23 14:52 - 2016-01-23 14:52 - 00000000 ____ D C:\Program Files (x86)\Enigma Software Group
2016-01-23 14:51 - 2016-01-23 14:52 - 00000000 ____ D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2016-01-02 20:42 - 2016-01-02 20:42 - 00000000 _____ C:\autoexec.bat
2015-07-15 17:19 - 2015-06-15 22:42 - 90434432 ___SH () C:\ProgramData\mspcsvn.exe
Task: {E00594D1-B76E-4B2A-AA51-84C860490B9B} - System32\Tasks\SpyHunter4Startup = C:\Program Files (x86)\Enigma Software Group\SpyHunter\Spyhunter4.exe [2016-01-23] (Enigma Software Group USA, LLC.)
DeleteKey: HKCU\Software\Classes\IUVVKRWZB
EmptyTemp:

Uruchom FRST i kliknij Napraw (Fix). Pokaż raport z usuwania Fixlog.

 


(pinkman) #5

FRST: http://wklej.org/id/1916136/


(Atis) #6

Skasuj folder C:\FRST


(pinkman) #7

Ogromne dzięki za pomoc.