Wyskakujące okna reklamowe w IE

Witam.

OLE- http://wklej.org/id/1578218/

Extras- http://wklej.org/id/1578228/

Proszę o pomoc.

Odinstaluj ConvertAd,Remote Desktop Access (VuuPC),Host App Service.Pobierz i uruchom AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Szukaj i później Usuń.

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.

Uruchom FRST i kliknij Scan. Pokaż raport FRST i Addition.

FRST - http://wklej.org/id/1578269/

 

Addition- http://wklej.org/id/1578273/

Otwórz notatnik systemowy i wklej:

HKLM-x32\...\Run: [rec_pl_1] = C:\Program Files (x86)\rec_pl_1\rec_pl_1.exe [3977384 2014-12-16] ()
HKLM-x32\...\Run: [rec_pl_2] = C:\Program Files (x86)\rec_pl_2\rec_pl_2.exe [3979432 2014-12-24] ()
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3725397679-1270234878-573821343-1002\...\MountPoints2: H - "H:\AutoRun.exe"
HKU\S-1-5-21-3725397679-1270234878-573821343-1002\...\MountPoints2: {631091f6-8227-11e4-826e-303a64b2b7db} - "H:\AutoRun.exe"
HKU\S-1-5-21-3725397679-1270234878-573821343-1002\...\MountPoints2: {63109246-8227-11e4-826e-303a64b2b7db} - "H:\AutoRun.exe"
HKU\S-1-5-21-3725397679-1270234878-573821343-1002\...\MountPoints2: {631092c3-8227-11e4-826e-303a64b2b7db} - "H:\AutoRun.exe"
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
URLSearchHook: [S-1-5-21-3725397679-1270234878-573821343-1001] ATTENTION == Default URLSearchHook is missing.
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3725397679-1270234878-573821343-1001 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3725397679-1270234878-573821343-1002 - {1260EB0E-53A9-4799-94E1-69EB67FCFC1C} URL =
FF Extension: No Name - C:\Users\i\AppData\Roaming\Mozilla\Firefox\Profiles\6xq2r600.default\extensions\{2bf1e193-df72-4e3c-9f15-d1dc6e2f810f}.xpi [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR HomePage: Default - hxxp://isearch.omiga-plus.com/?type=hpts=1419783534from=coruid=TOSHIBAXMQ01ABD100_8482P2YRTXX8482P2YRT
CHR StartupUrls: Default - "hxxp://isearch.omiga-plus.com/?type=hpts=1419783534from=coruid=TOSHIBAXMQ01ABD100_8482P2YRTXX8482P2YRT"
CHR DefaultSearchKeyword: Default - omiga-plus
S1 wpnfd_1_10_0_2; system32\drivers\wpnfd_1_10_0_2.sys [X]
2014-12-28 17:25 - 2014-12-28 17:30 - 00000000 ____ D () C:\AdwCleaner
2014-12-27 16:08 - 2014-12-28 16:08 - 00000000 ____ D () C:\Program Files (x86)\rec_pl_2
2014-12-27 16:08 - 2014-12-27 16:08 - 00000000 ____ D () C:\Users\i\AppData\Local\rec_pl_2
2014-12-26 16:04 - 2014-12-26 16:04 - 00554224 _____ () C:\Users\i\Downloads\HoldPageUninstaller.exe
2014-12-22 21:06 - 2014-12-22 21:06 - 00000000 ____ D () C:\Users\i\AppData\Local\rec_pl_1
2014-12-22 21:06 - 2014-12-22 21:06 - 00000000 ____ D () C:\Program Files (x86)\rec_pl_1
2014-12-14 11:38 - 2014-12-14 11:39 - 00000000 ____ D () C:\Users\i\AppData\Roaming\EurekaLog
2014-12-28 17:25 - 2014-12-28 17:30 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Pomogło, dziękuję bardzo.

Skasuj folder C:\FRST