Wyskakujące okno z reklamą


(Bul30) #1

Cześć.


(Atis) #2

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
HKU\S-1-5-21-3816791333-1415251164-2087949957-1000\...\Run: [winlogon] => wscript.exe //B "C:\Users\PawelL\AppData\Roaming\winlogon.vbs"
Startup: C:\Users\PawelL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ARCHIVER.lnk [2015-07-28]
ShortcutTarget: ARCHIVER.lnk -> C:\Users\PawelL\AppData\Roaming\ARCHIVER.exe (ARCHIVER ARCHIVE COMPANY)
Startup: C:\Users\PawelL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winlogon.vbs [2015-07-21] ()
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
CHR HKU\S-1-5-21-3816791333-1415251164-2087949957-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - http://clients2.google.com/service/update2/crx
2015-07-21 19:55 - 2015-07-21 19:55 - 04370680 _____ C:\Users\PawelL\AppData\Roaming\winlogon.vbs
2015-06-16 19:41 - 2015-06-16 19:41 - 0000003 _____ () C:\Users\PawelL\AppData\Local\updater.log
2015-06-16 19:41 - 2015-06-16 23:04 - 0000424 _____ () C:\Users\PawelL\AppData\Local\UserProducts.xml
Task: {24403BA7-E95B-4DF1-B161-23A5A763EA69} - System32\Tasks\{C9299658-E3C7-4B15-996D-82E9D30A9178} => C:\Users\PawelL\Downloads\Ijemptno\CrackNocd.exe [2003-03-27] ()
Task: {34497493-5DD8-48DD-BA46-94115F0E19A4} - System32\Tasks\{B16B4F07-01AF-4B20-B5EB-949068E73DEC} => pcalua.exe -a J:\OriginInstaller.exe -d J:\
Task: {562B35DD-A7C3-4DDD-805F-41922825F332} - System32\Tasks\{B1ECE896-4D41-4426-A3B9-E8C92C31B52D} => pcalua.exe -a H:\resources\FairLight\Install.exe -d H:\resources\FairLight
Task: {621F2D15-012B-4394-B47C-C208E6ABAA8F} - System32\Tasks\{217FA09A-9680-497C-A330-4D383B021AFD} => C:\Users\PawelL\Downloads\Ijemptno\CrackNocd.exe [2003-03-27] ()
Task: {B343C7EC-8CD4-49D4-A518-A49A41F47E74} - System32\Tasks\{5120509B-9996-417F-A0A3-A4A5972D8A7B} => pcalua.exe -a "f:\Program Files (x86)\TeamSpeak 3 Client\package_inst.exe" -d "F:\Program Files (x86)\TeamSpeak 3 Client\translations" -c "F:\Program Files (x86)\TeamSpeak 3 Client\translations\polish.ts3_translation"
EmptyTemp:

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition i Shortcut.


(Bul30) #3

FIXLOG:

 

http://www.wklej.org/id/1765515/

 

FRST:

 

http://www.wklej.org/id/1765517/


(Atis) #4

Skasuj folder C:\FRST

Usuń stare punkty przywracania: Aby usunąć wszystkie punkty przywracania

Dysk przeskanuj ESET Online Scanner

Odinstaluj:

Adobe Flash Player 15 ActiveX

Adobe Shockwave Player

Microsoft Silverlight

Zainstaluj:

Flash Player 18.0.0.209 ActiveX

Silverlight 5.1.40620.0


(Bul30) #5

Wykonane.

ESET wykrył 19 zagrożeń.

 

 

Dziękuję za pomoc.