Strong Signal - jak usunąć


(Devik83) #1

Witam,

 

Przypętało się do mnie coś niedobrego,  otóż walczę z wyskakującymi okienkami ze Strong Signal. Niestety walka jest nierówna. Bardzo proszę o pomoc....

Poniżej logi...

 

 

FRST: http://wklej.to/fTHti

Addition: http://wklej.to/4BdsP

 

Z góry dziękuję


(Atis) #2

W panelu sterowania odinstaluj SpyHunter 4.

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
FF Extension: Strong Signal - C:\Users\Paweł\AppData\Roaming\Mozilla\Firefox\Profiles\iu8grpiq.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-22]
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-02-22] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-02-22] ()
2015-02-22 22:44 - 2015-02-22 22:44 - 00003320 _____ () C:\WINDOWS\System32\Tasks\SpyHunter4Startup
2015-02-22 22:44 - 2015-02-22 22:44 - 00001114 _____ () C:\Users\Paweł\Desktop\SpyHunter.lnk
2015-02-22 22:44 - 2015-02-22 22:44 - 00000000 ____ D () C:\Users\Paweł\AppData\Roaming\Enigma Software Group
2015-02-22 22:43 - 2015-02-22 22:44 - 00000000 ____ D () C:\sh4ldr
2015-02-22 22:43 - 2015-02-22 22:43 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\Paweł\Downloads\SpyHunter-installer.exe
2015-02-22 22:43 - 2015-02-22 22:43 - 00022704 _____ () C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-02-22 22:43 - 2015-02-22 22:43 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-02-22 20:42 - 2015-02-22 22:05 - 00000000 ____ D () C:\AdwCleaner
2014-08-31 20:37 - 2014-08-31 20:37 - 0000005 _____ () C:\Program Files (x86)\is.dat
2014-08-31 20:38 - 2014-08-31 20:38 - 0016384 _____ () C:\Program Files (x86)\uik.dat
Task: {0C233375-A568-43EF-B7B2-EF82B7152673} - System32\Tasks\{607236F3-9F19-4574-B62C-5F9F9ECC3097} => pcalua.exe -a C:\Users\Paweł\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=smt
Task: {55D4F4C1-2F0C-48E4-803B-694185EDC55D} - System32\Tasks\{811777D2-D18E-4A0D-A2B2-C792F34B745A} => pcalua.exe -a E:\setup.EXE -d E:\ -c /AUTORUN
Task: {E0236AB6-DBE5-4CF6-82AE-5726D92CEE9B} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-02-22] (Enigma Software Group USA, LLC.)
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.


(Acorus) #3

Otwórz notatnik systemowy i wklej:

Task: {0C233375-A568-43EF-B7B2-EF82B7152673} - System32\Tasks\{607236F3-9F19-4574-B62C-5F9F9ECC3097} = pcalua.exe -a C:\Users\Paweł\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=smt
Task: {0FAF06B9-84BD-44BA-82A2-D5E7BB0CE7C6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2681439763-3479487828-2170396968-1001UA = C:\Users\Paweł\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-05-05] (Facebook Inc.)
Task: {B54FAA70-5559-41C1-9257-A35E3921EA4E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2681439763-3479487828-2170396968-1001Core = C:\Users\Paweł\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-05-05] (Facebook Inc.)
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2681439763-3479487828-2170396968-1001Core.job = C:\Users\PaweB\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2681439763-3479487828-2170396968-1001UA.job = C:\Users\PaweB\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKLM-x32\...\Run: [QuickTime Task] = C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [] = [X]
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2681439763-3479487828-2170396968-1001\...\Run: [Facebook Update] = C:\Users\Paweł\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-05-05] (Facebook Inc.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\S-1-5-21-2681439763-3479487828-2170396968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Extension: Strong Signal - C:\Users\Paweł\AppData\Roaming\Mozilla\Firefox\Profiles\iu8grpiq.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-22]
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025920 2015-02-22] (Enigma Software Group USA, LLC.)
2015-02-22 22:44 - 2015-02-22 22:44 - 00003320 _____ () C:\WINDOWS\System32\Tasks\SpyHunter4Startup
2015-02-22 22:44 - 2015-02-22 22:44 - 00001114 _____ () C:\Users\Paweł\Desktop\SpyHunter.lnk
2015-02-22 22:44 - 2015-02-22 22:44 - 00000000 ____ D () C:\Users\Paweł\AppData\Roaming\Enigma Software Group
2015-02-22 22:43 - 2015-02-22 22:44 - 00000000 ____ D () C:\sh4ldr
2015-02-22 22:43 - 2015-02-22 22:43 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\Paweł\Downloads\SpyHunter-installer.exe
2015-02-22 22:43 - 2015-02-22 22:43 - 00022704 _____ () C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-02-22 22:43 - 2015-02-22 22:43 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-02-22 20:42 - 2015-02-22 22:05 - 00000000 ____ D () C:\AdwCleaner
2014-08-31 20:37 - 2014-08-31 20:37 - 0000005 _____ () C:\Program Files (x86)\is.dat
2014-08-31 20:38 - 2014-08-31 20:38 - 0016384 _____ () C:\Program Files (x86)\uik.dat
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Devik83) #4

fixlog: http://wklej.to/NtEI0

 

FRST: http://wklej.to/bxpwy


(Atis) #5

Skasuj folder C:\FRST

Usuń stare punkty przywracania: Przywracanie systemu i kopie w tle

Dysk przeskanuj Malwarebytes Anti-Malware

Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.

http://wstaw.org/m/2014/03/25/2014-03-25_123039.png

Język PL > Settings > General Settings > Language > Polish

Przeczytaj w jaki sposób należy instalować programy: KLIK - KLIK - KLIK - KLIK


(Devik83) #6

Dziękuję raz jeszcze za pomoc

Pozdrawiam