Strong signal- pomocy!


(Olione) #1

Cześć, już od jakiegoś czasu borykam się z problemem Strong Signala... Próbowałam załatwić to sama, szperałam, ale nie dałam rady :frowning:

 FRST : http://wklej.org/id/1657335/

jestem w tym zielona, więc prosze o dokładne wyjaśnienie co robić, z góry serdecznie dziękuję! :slight_smile:


(Giiixxxx6) #2

Cześć

Potrzebne są logi FRST, Addition oraz Shortcut, wszystkie te 3 pliki znajdziesz w tym samym miejscu z którego uruchamiała pani program.

 

Pozdrawiam i miłego dnia,

Giiixxxx6


(Olione) #3

FRST: http://wklej.org/id/1657422/

Addition: http://wklej.org/id/1657424/

Shortcut: http://wklej.org/id/1657425/

 

Mam nadzieję, że wszystko zrobiłam tak jak trzeba :slight_smile:


(Acorus) #4

Odinstaluj Remote Desktop Access (VuuPC),SavePass 1.1 .Otwórz notatnik systemowy i wklej:

Task: {3793F4E3-9D3B-49C4-8459-AB6978EEAC07} - System32\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-6 = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-6.exe [2015-02-15] (OB) ==== ATTENTION
Task: {3C2054BC-C3D2-4155-A18A-5359E2320229} - System32\Tasks\globalUpdateUpdateTaskMachineCore = C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2015-02-15] (globalUpdate) ==== ATTENTION
Task: {7EE3F600-6445-4A02-97EF-AA8D7E2D6927} - System32\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-7 = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-7.exe [2015-02-15] (OB) ==== ATTENTION
Task: {8DAD54E3-6330-469C-A549-EFCCB6AEC71A} - System32\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-10_user = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-10.exe [2015-02-15] (OB) ==== ATTENTION
Task: {B702DB26-886F-41D5-968F-3DE456D8E200} - System32\Tasks\globalUpdateUpdateTaskMachineUA = C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2015-02-15] (globalUpdate) ==== ATTENTION
Task: {F4146264-80EB-4127-8368-3E6B46F11508} - System32\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-4 = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-4.exe [2015-02-15] (OB) ==== ATTENTION
Task: C:\Windows\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-10_user.job = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-10.exe ==== ATTENTION
Task: C:\Windows\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-4.job = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-4.exe ==== ATTENTION
Task: C:\Windows\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-6.job = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-6.exe ==== ATTENTION
Task: C:\Windows\Tasks\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-7.job = C:\Program Files\SavePass 1.1\1c3415e6-ed4f-47cb-a72b-3c8750edcfa5-7.exe ==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job = C:\Program Files\globalUpdate\Update\GoogleUpdate.exe ==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job = C:\Program Files\globalUpdate\Update\GoogleUpdate.exe ==== ATTENTION
HKU\S-1-5-21-3106353087-2667883550-3902548754-1000\...\Run: [AdobeBridge] = [X]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813q={searchTerms}
HKU\S-1-5-21-3106353087-2667883550-3902548754-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3106353087-2667883550-3902548754-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813q={searchTerms}
SearchScopes: HKU\S-1-5-21-3106353087-2667883550-3902548754-1000 - DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813ts=1424621116type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3106353087-2667883550-3902548754-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813ts=1424621116type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3106353087-2667883550-3902548754-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813ts=1424621116type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3106353087-2667883550-3902548754-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813ts=1424621116type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3106353087-2667883550-3902548754-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813ts=1424621116type=defaultq={searchTerms}
BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\XTab\SupTab.dll [2015-01-16] (Thinknice Co. Limited)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.omniboxes.com/?type=scts=1424027158from=obwuid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813
FF DefaultSearchEngine: key-find
FF SelectedSearchEngine: key-find
FF SearchPlugin: C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\searchplugins\key-find.xml [2015-03-08]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\omniboxes.xml [2015-02-15]
FF Extension: SavePass v2.2 - C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\Extensions\389579c4-efa9-4d96-a1dd-3c86f7bd1a51@gmail.com [2015-02-22]
FF Extension: Fast Start - C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\Extensions\faststartff@gmail.com [2015-02-22]
FF Extension: Search Enginer - C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\Extensions\searchengine@gmail.com [2015-02-22]
FF Extension: Strong Signal - C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\Extensions\{1c00b031-52f0-4616-bdcf-2e1a2c46eb7a}.xpi [2015-02-28]
FF HKLM\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\extensions\searchengine@gmail.com
FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Oliwia\AppData\Roaming\Mozilla\Firefox\Profiles\0h81fwrb.default\extensions\faststartff@gmail.com
FF HKU\S-1-5-21-3106353087-2667883550-3902548754-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
CHR HomePage: Default - hxxp://www.key-find.com/?type=hpts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813
CHR StartupUrls: Default - "hxxp://www.key-find.com/?type=hpts=1424621029from=coruid=WDCXWD800BB-00JHC0_WD-WMAM9H25581355813"
CHR DefaultSearchKeyword: Default - key-find
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2015-02-15] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2015-02-15] (globalUpdate) [File not signed]
R2 IHProtect Service; C:\Program Files\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 Service Mgr StrongSignal; C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugincontainer.exe [581368 2015-03-08] ()
R2 Update Mgr StrongSignal; C:\Program Files\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe [388856 2015-03-08] ()
S3 MBAMSwissArmy; \\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
2015-02-28 20:16 - 2015-02-28 20:16 - 00000000 ____ D () C:\Program Files\Strong Signal
2015-02-22 17:04 - 2015-02-22 17:04 - 00000000 ____ D () C:\Users\Oliwia\AppData\Roaming\key-find
2015-02-15 20:09 - 2015-03-08 11:07 - 00000870 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-02-15 20:09 - 2015-02-15 20:10 - 00000000 ____ D () C:\Program Files\SavePass 1.1
2015-02-15 20:09 - 2015-02-15 20:10 - 00000000 ____ D () C:\Program Files\91ba821a-8681-4f2a-b91e-44b3faf15d74
2015-02-15 20:09 - 2015-02-15 20:09 - 00000000 ____ D () C:\Users\Oliwia\AppData\Local\globalUpdate
2015-02-15 20:09 - 2015-02-15 20:09 - 00000000 ____ D () C:\Program Files\globalUpdate
2015-02-15 20:07 - 2015-02-22 17:05 - 00000000 ____ D () C:\Program Files\XTab
2015-02-15 20:07 - 2015-02-15 20:07 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-15 20:06 - 2015-02-15 20:06 - 00000000 ____ D () C:\Users\Oliwia\AppData\Roaming\omniboxes
2015-02-15 20:06 - 2015-02-15 20:06 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
C:\Windows\System32\atimuixx.dll
C:\Windows\System32\atitmmxx.dll
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.