Strong Signal...bezdradna :/


(Martfa Pl1) #1

Witam, prosze o pomoc w usunięciu tego "cuda"

 

 

http://wklej.org/id/1646594/

http://wklej.org/id/1646613/

http://wklej.org/id/1646616/

 

Dziękuję


(Acorus) #2

Otwórz notatnik systemowy i wklej:

HKLM\...\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] = C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
CHR HKU\S-1-5-21-2110313843-1654076277-3636816008-1000\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
CHR HKU\S-1-5-21-2110313843-1654076277-3636816008-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF Extension: Strong Signal - C:\Users\Guma\AppData\Roaming\Mozilla\Firefox\Profiles\nrtiyvcs.default\Extensions\{6dc74982-0c33-45a3-aaec-8285d2089296}.xpi [2015-02-18]
CHR HomePage: Default - hxxp://www.key-find.com/?type=hpts=1424292331from=coruid=ST9120822AS_5LZ6FSKKXXXX5LZ6FSKK
CHR StartupUrls: Default - "hxxp://www.key-find.com/?type=hpts=1424292331from=coruid=ST9120822AS_5LZ6FSKKXXXX5LZ6FSKK"
CHR DefaultSearchKeyword: Default - key-find
CHR DefaultSearchURL: Default - http://www.key-find.com/web/?type=dsts=1424292331from=coruid=ST9120822AS_5LZ6FSKKXXXX5LZ6FSKKq={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Extension: (Strong Signal) - C:\Users\Guma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdidplnlbafiijjfbomlfokdppebnhpc [2015-02-20]
2015-02-24 16:05 - 2015-02-24 16:05 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-02-24 22:37 - 2014-02-27 23:25 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Martfa Pl1) #3

Jesteście fantastyczni


(Acorus) #4

Skasuj folder C:\FRST