Wyskakujące reklamy oraz strony w przeglądarkach


(Tomek570) #1

Witam, tak jak w temacie ostatnio pojawiło się u mnie w przeglądarce mnóstwo wyskakujących reklam, czasem też otwiera się zakładka z jakąś stroną, Pomożecie ? :wink:

 

 

Extras: http://wklejto.pl/215842

OTL: http://www.wklej.org/id/1530030/


(Acorus) #2

Odinstaluj YAC(Yet Another Cleaner!),Tibia MULTI-ip changer,Akamai NetSession Interface.Pobierz i uruchom AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Szukaj i później Usuń.

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.

Uruchom FRST i kliknij Scan. Pokaż raport FRST i Addition.

Raporty umieść na http://wklej.org/ i podaj link.


(Tomek570) #3

FRST: http://wklej.org/id/1530076/

Additions: http://wklej.org/id/1530078/


(Acorus) #4

Otwórz Notatnik i wklej:

Hosts:
Task: {480FBFA4-3364-46F9-8D13-CB584B71FE0B} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1292469835-3904043757-2447316924-1002UA = C:\Users\Ewa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-31] (Facebook Inc.)
Task: {A6473CC7-F8C8-442D-A05E-D2EC21447811} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1292469835-3904043757-2447316924-1002Core = C:\Users\Ewa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-31] (Facebook Inc.)
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1292469835-3904043757-2447316924-1002Core.job = C:\Users\Ewa\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1292469835-3904043757-2447316924-1002UA.job = C:\Users\Ewa\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\...\Run: [Akamai NetSession Interface] = "C:\Users\Tomekk\AppData\Local\Akamai\netsession_win.exe"
SearchScopes: HKU\.DEFAULT - DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=hitachixhts547575a9e384_j1140021dmthgjdmthgjxts=1416476681
SearchScopes: HKU\.DEFAULT - {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=hitachixhts547575a9e384_j1140021dmthgjdmthgjxts=1416476681
SearchScopes: HKU\S-1-5-19 - DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=hitachixhts547575a9e384_j1140021dmthgjdmthgjxts=1416476681
SearchScopes: HKU\S-1-5-19 - {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=hitachixhts547575a9e384_j1140021dmthgjdmthgjxts=1416476681
SearchScopes: HKU\S-1-5-20 - DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=hitachixhts547575a9e384_j1140021dmthgjdmthgjxts=1416476681
SearchScopes: HKU\S-1-5-20 - {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://search.yac.mx/web/?q={searchTerms}type=dsfrom=yacuid=hitachixhts547575a9e384_j1140021dmthgjdmthgjxts=1416476681
SearchScopes: HKU\S-1-5-21-1292469835-3904043757-2447316924-1001 - DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
SearchScopes: HKU\S-1-5-21-1292469835-3904043757-2447316924-1001 - {F2E48B17-78B7-406A-BE47-7FB63603E514} URL =
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF DefaultSearchEngine: YAC Safe Search
FF SearchEngineOrder.1: YAC Safe Search
FF SelectedSearchEngine: YAC Safe Search
R2 MaintainerSvc4.00.5030318; C:\ProgramData\e25f457c-9287-4f2d-b5a8-8cd714c55009\maintainer.exe [123632 2014-11-20] ()
S3 esgiguard; \\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 massfilter_lte; \\C:\windows\system32\drivers\massfilter_lte.sys [X]
S3 zgdcat; \SystemRoot\system32\DRIVERS\zgdcat.sys [X]
S3 zgdcdiag; \SystemRoot\system32\DRIVERS\zgdcdiag.sys [X]
S3 zgdcmdm; \SystemRoot\system32\DRIVERS\zgdcmdm.sys [X]
S3 zgdcnet; \SystemRoot\system32\DRIVERS\zgdcnet.sys [X]
S3 zgdcnmea; \SystemRoot\system32\DRIVERS\zgdcnmea.sys [X]
2014-11-19 15:18 - 2014-11-19 15:19 - 00912928 _____ (Elex do Brasil Participações Ltda) C:\Users\Tomekk\Downloads\yet_another_cleaner_aed.exe
2014-11-20 10:58 - 2014-08-06 17:00 - 00000000 ____ D () C:\AdwCleaner
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Tomek570) #5

Ok, zrobione, co teraz?


(Acorus) #6

Jak jest dobrze to skasuj folder C:\FRST


(Tomek570) #7

Wszystko gra, dzięki za pomoc :wink: