Safesaver - problem

Witam, jak wyżej mam problem z tym pieroństwem, durś reklamy na yt, google, ponad to jeszcze te rozszerzenie do google chrome (nazwa: RandoomPrice 6.1), które jak wyłączę i/lub usunę z listy rozszerzeń to nie ma tychże reklam, jednak po ponownym włączeniu przeglądarki owo dalej figuruje na liście i działa. Pomóżcie ;/

 

 

 

OTL: http://www.wklej.org/id/1227280/

Extras: http://www.wklej.org/id/1227282/

 

Z góry dziękuję

Odinstaluj:

McAfee Security Scan Plus

AlaleChheuapPrice

RandoomPrice

Intelewin filter

Do okna Własne opcje skanowania / skrypt wklej:

:OTL
IE - HKU\S-1-5-21-590465607-256760969-226401697-1000\..\SearchScopes\{57EEC3DB-29F4-44C7-BA4C-5D11D25C351B}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=4D7E1C9A-7565-4154-83CB-855AA546EEBF&apn_sauid=8DF740CE-1804-4A7F-AE71-F5F3F24DF47C
O2:64bit: - BHO: (RandoomPrice) - {70E87601-B92C-A55C-095B-8B85FB9FD726} - C:\ProgramData\RandoomPrice\_2fmyq8Ign.x64.dll ()
O2:64bit: - BHO: (AlaleChheuapPrice) - {9478C8A2-CE09-C728-FBEE-A7541FD94B30} - C:\ProgramData\AlaleChheuapPrice\wzBv5P.x64.dll ()
O2 - BHO: (RandoomPrice) - {70E87601-B92C-A55C-095B-8B85FB9FD726} - C:\ProgramData\RandoomPrice\_2fmyq8Ign.dll ()
O2 - BHO: (AlaleChheuapPrice) - {9478C8A2-CE09-C728-FBEE-A7541FD94B30} - C:\ProgramData\AlaleChheuapPrice\wzBv5P.dll ()
O4:64bit: - HKLM..\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] "C:\Users\user\AppData\Local\Temp\cis93F8.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} File not found
O4 - HKU\S-1-5-21-590465607-256760969-226401697-1000..\Run: [EPSON SX125 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE /FU "C:\Windows\TEMP\E_SBCDB.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-590465607-256760969-226401697-1000..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-590465607-256760969-226401697-1230..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~3\INTELE~1\INTELE~2.DLL) - C:\ProgramData\Intelewin filter\Intelewinfilter_x64.dll ()
O20 - AppInit_DLLs: (c:\progra~3\intele~1\intele~1.dll) - c:\ProgramData\Intelewin filter\Intelewinfilter.dll ()
[2014-01-01 12:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\RandoomPrice
[2014-01-01 12:29:32 | 000,000,000 | ---D | C] -- C:\ProgramData\fhpiaelaoadfekjglemmdpnhbcgolaln
[2014-01-01 12:29:20 | 000,000,000 | ---D | C] -- C:\ProgramData\AlaleChheuapPrice
[2013-12-28 21:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Intelewin filter
:Commands
[emptytemp]

Kliknij Wykonaj skrypt i zatwierdź restart.

Pokaż raport z usuwania i nowy log Skanuj.

Odinstaluj McAfee Security Scan Plus,AlaleChheuapPrice.Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:

:OTL
IE - HKU\S-1-5-21-590465607-256760969-226401697-1000\..\SearchScopes\{57EEC3DB-29F4-44C7-BA4C-5D11D25C351B}: "URL" = http://websearch.ask.com/redirect?client=ietb=ORJo=100000027src=crmq={searchTerms}locale=en_USapn_ptnrs=U3apn_dtid=OSJ000YYPLapn_uid=4D7E1C9A-7565-4154-83CB-855AA546EEBFapn_sauid=8DF740CE-1804-4A7F-AE71-F5F3F24DF47C
O2:64bit: - BHO: (RandoomPrice) - {70E87601-B92C-A55C-095B-8B85FB9FD726} - C:\ProgramData\RandoomPrice\_2fmyq8Ign.x64.dll ()
O2:64bit: - BHO: (AlaleChheuapPrice) - {9478C8A2-CE09-C728-FBEE-A7541FD94B30} - C:\ProgramData\AlaleChheuapPrice\wzBv5P.x64.dll ()
O2 - BHO: (RandoomPrice) - {70E87601-B92C-A55C-095B-8B85FB9FD726} - C:\ProgramData\RandoomPrice\_2fmyq8Ign.dll ()
O2 - BHO: (AlaleChheuapPrice) - {9478C8A2-CE09-C728-FBEE-A7541FD94B30} - C:\ProgramData\AlaleChheuapPrice\wzBv5P.dll ()
O4:64bit: - HKLM..\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] "C:\Users\user\AppData\Local\Temp\cis93F8.exe" --PostUninstall {81EFDD93-DBBE-415B-BE6E-49B9664E3E82} File not found
O4 - HKU\S-1-5-21-590465607-256760969-226401697-1000..\Run: [EPSON SX125 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE /FU "C:\Windows\TEMP\E_SBCDB.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-590465607-256760969-226401697-1000..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-590465607-256760969-226401697-1230..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
[2014-01-04 02:24:38 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-01-01 12:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\RandoomPrice
[2014-01-01 12:29:32 | 000,000,000 | ---D | C] -- C:\ProgramData\fhpiaelaoadfekjglemmdpnhbcgolaln
[2014-01-01 12:29:20 | 000,000,000 | ---D | C] -- C:\ProgramData\AlaleChheuapPrice

:Commands
[emptytemp]

Kliknij Wykonaj skrypt.

Dziękuję wam, i pierwszemu, i drugiemu, fakt że ten pierwszy był pierwszy to zrobiłem tak jak on, i dziękuję wam :wink: :wink: :wink:

 

I to chyba jest ten raportu usuwania, c’nie? : http://www.wklej.org/id/1227343/