Strong Signal - Pomoc


(Joachimiak Marcin) #1

Witam,

Wklejam FRST jak i AUDITION, gdyż mam problem z reklamami strong signal ads.

Proszę o pomoc.

Pozdrawiam

 

http://wklej.to/6HI0z

http://wklej.to/lTl67


(Acorus) #2

Odinstaluj Akamai NetSession Interface,Update for PDF Creator,Update for PDF Writer.Otwórz notatnik systemowy i wklej:

Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job = C:\windows\TEMP\{69C7086F-C6C3-4CC3-AC74-E6909F99D625}.exe ==== ATTENTION
Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job = C:\windows\TEMP\{99C3D803-F49F-4F3F-A426-62175A9CA610}.exe ==== ATTENTION
Task: C:\windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job = C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe ==== ATTENTION
HKLM-x32\...\Run: [] = [X]
HKLM-x32\...\Run: [Adobe ARM] = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-2011543208-3617150356-1090793174-1001\...\Run: [Akamai NetSession Interface] = C:\Users\Pieszko\AppData\Local\Akamai\netsession_win.exe [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2011543208-3617150356-1090793174-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2011543208-3617150356-1090793174-1001\...\MountPoints2: {fcec1d66-496e-11e1-95c7-90004eaae1a1} - H:\SETUP.EXE
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
HKU\S-1-5-21-2011543208-3617150356-1090793174-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://services.freshy.com/general/newhometab.php?hometab=homepartner=11147guid={F0987A3C-B9E4-4B10-90CC-B46587C39B5E}i=
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=dsts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEXq={searchTerms}
SearchScopes: HKU\.DEFAULT - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\.DEFAULT - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-2011543208-3617150356-1090793174-1001 - DefaultScope {C6C1270A-E9CA-4125-AA3B-030347B86A88} URL = http://search.findwide.com/serp?guid={F0987A3C-B9E4-4B10-90CC-B46587C39B5E}action=default_searchk={searchTerms}
SearchScopes: HKU\S-1-5-21-2011543208-3617150356-1090793174-1001 - {1CB7F8F4-8A96-4E5D-A604-7F71E6EC8708} URL = http://websearch.ask.com/redirect?client=ietb=ORJo=src=kwq={searchTerms}locale=apn_ptnrs=U3apn_dtid=OSJ000YYPLapn_uid=61D17A8F-E966-466C-8E7A-C8C9028E6CE5apn_sauid=5C3A0733-5C0D-4D3E-A38B-980575A61F96
SearchScopes: HKU\S-1-5-21-2011543208-3617150356-1090793174-1001 - {9FCFAC63-2452-4182-AEB4-727C8300DD8A} URL = http://search.yahoo.com/search?p={searchTerms}fr=tightropetbtype=11147
SearchScopes: HKU\S-1-5-21-2011543208-3617150356-1090793174-1001 - {C6C1270A-E9CA-4125-AA3B-030347B86A88} URL = http://search.findwide.com/serp?guid={F0987A3C-B9E4-4B10-90CC-B46587C39B5E}action=default_searchk={searchTerms}
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: No Name - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - FindWide Toolbar - {B7A53D59-F231-4213-8801-CE53962ABCE2} - C:\Program Files (x86)\TNT2\Profiles\11147\passport64.dll (Freshy.com)
Toolbar: HKLM-x32 - FindWide Toolbar - {B7A53D59-F231-4213-8801-CE53962ABCE2} - C:\Program Files (x86)\TNT2\Profiles\11147\passport.dll (Freshy.com)
Toolbar: HKU\S-1-5-21-2011543208-3617150356-1090793174-1001 - FindWide Toolbar - {B7A53D59-F231-4213-8801-CE53962ABCE2} - C:\Program Files (x86)\TNT2\Profiles\11147\passport64.dll (Freshy.com)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=scts=1392148527from=coruid=HITACHIXHTS545050B9A300_110111PBN403171G9XUEX
FF SearchPlugin: C:\Users\Pieszko\AppData\Roaming\Mozilla\Profiles\nk8djsvi.Pieszko\searchplugins\babylon.xml
FF HKU\S-1-5-21-2011543208-3617150356-1090793174-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
CHR Extension: (Strong Signal) - C:\Users\Pieszko\AppData\Local\Google\Chrome\User Data\Default\Extensions\iofiplankempicdeegfcodkmgchcdmom [2015-02-16]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
U2 CLKMSVC10_3A60B698; No ImagePath
U2 CLKMSVC10_C3B3B687; No ImagePath
U2 DriverService; No ImagePath
U2 idealife Update Service; No ImagePath
U3 IGRS; No ImagePath
U2 IviRegMgr; No ImagePath
U2 nvUpdatusService; No ImagePath
U2 Oasis2Service; No ImagePath
U2 PCCarerServic; No ImagePath
U2 ReadyComm.DirectRouter; No ImagePath
U2 RichVideo; No ImagePath
U2 RtLedService; No ImagePath
U2 SoftwareService; No ImagePath
U2 Stereo Service; No ImagePath
2015-02-19 17:33 - 2013-11-14 21:16 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.