Strong Signal Ads - prośba o pomoc w usunięciu

Witam serdecznie,

 

Prośba jak w temacie. Z góry dzięki za pomoc!

 

Raporty poniżej (mam nadzieję, że wszystko jest)

 

http://www.wklej.org/id/1645626/

http://www.wklej.org/id/1645628/

Odinstaluj Akamai NetSession Interface,McAfee Security Scan Plus,Microsoft Security Essentials,YTD Video Downloader 4.0.Otwórz notatnik systemowy i wklej:

HKLM\...\Run: [] = [X]
HKU\S-1-5-21-2017259883-1034630344-2383776842-1000\...\Run: [Akamai NetSession Interface] = C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\S-1-5-21-2017259883-1034630344-2383776842-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2017259883-1034630344-2383776842-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dsppts=1422908249from=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dsppts=1422908249from=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dsppts=1422908249from=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dsppts=1422908249from=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117q={searchTerms}
SearchScopes: HKU\S-1-5-21-2017259883-1034630344-2383776842-1000 - DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117ts=1422908302type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2017259883-1034630344-2383776842-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117ts=1422908302type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2017259883-1034630344-2383776842-1000 - {19C1DB53-DC44-46A7-940B-957B44ECC429} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117ts=1422908302type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2017259883-1034630344-2383776842-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117ts=1422908302type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2017259883-1034630344-2383776842-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117ts=1422908302type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2017259883-1034630344-2383776842-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD3200BEVT-75ZCT2_WD-WXF0A997411774117ts=1422908302type=defaultq={searchTerms}
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Strong Signal - {c723a437-2eaf-466d-a95b-3fa0966bf88c} - C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
FF DefaultSearchEngine: omiga-plus
FF SelectedSearchEngine: omiga-plus
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmmffirn.default\searchplugins\omiga-plus.xml
FF Extension: FF Toolbar - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmmffirn.default\Extensions\fftoolbar2014@etech.com [2015-02-02]
FF Extension: Strong Signal - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmmffirn.default\Extensions\{9d204d90-67ed-4674-ad22-ac0bd52d6ba6}.xpi [2015-02-09]
FF Extension: Strong Signal - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmmffirn.default\Extensions\{9ee10050-a207-4c90-b7d8-9d3059940ab5}.xpi [2015-02-02]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmmffirn.default\extensions\fftoolbar2014@etech.com
FF HKU\S-1-5-21-2017259883-1034630344-2383776842-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
CHR Plugin: (Shockwave Flash) - C:\Users\Admin\AppData\Local\Google\Chrome\Application\40.0.2214.115\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Extension: (Strong Signal) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepampipjplnigjhkaijlbeppicakggl [2015-02-10]
S3 catchme; \\C:\ComboFix\catchme.sys [X]
2015-02-02 22:19 - 2015-02-02 22:19 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-02 21:18 - 2015-02-02 22:58 - 00000000 ____ D () C:\Program Files (x86)\XTab
2015-02-02 21:18 - 2015-02-02 21:18 - 00000000 ____ D () C:\Users\Admin\AppData\Roaming\OpenCandy
2011-09-22 12:47 - 2011-09-22 12:47 - 0000000 _____ () C:\Users\Admin\AppData\Roaming\wklnhst.dat
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Dzięki wielkie! Pozdrawiam

Skasuj folder C:\FRST