Wyskakujące reklamy - prośba o pomoc


(Tomaszek25) #1

Witam,

mam nadzieję, że wykonałem logi zgodnie z instrukcją.

Poniżej linki:

http://www.wklej.org/id/1710765/

http://www.wklej.org/id/1710767/

 

Dziękuję za pomoc.


(Acorus) #2

Odinstaluj Ad-Aware Antivirus,Spybot - Search & Destroy.Otwórz notatnik systemowy i wklej:

Task: {1343FBE3-D393-42D7-96B3-D931D0AEFD24} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates = C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {53429C54-B6E1-4305-8EFE-C0975F907E42} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system = C:\Program Files (x86)\Spybot - Search Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {62C7E886-C083-444A-A322-A4EFD88E75EA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization = C:\Program Files (x86)\Spybot - Search Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {B117201F-7F89-44BF-AFA0-CEC5D9889342} - System32\Tasks\ROC_JAN2013_TB_rmv = C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
HKLM\...\Run: [] = [X]
HKLM\...\Run: [AdAwareTray] = C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.6.306.7947\AdAwareTray.exe [9566192 2015-03-10] ()
HKLM-x32\...\Run: [QuickTime Task] = C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] = C:\Program Files (x86)\Spybot - Search Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\S-1-5-21-959407847-4203133325-2678805752-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
OPR Extension: (Roll Around) - C:\Users\TOM\AppData\Roaming\Opera Software\Opera Stable\Extensions\hephlipnhkfgdgamhnkjenhcbnnfgeoe [2015-05-12]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 Update Mgr RollAround; "C:\Program Files (x86)\Common Files\2a617352-d396-46a3-a71b-5d89535356cf\updater.exe" [X]
S3 andnetndis; system32\DRIVERS\lgandnetndis64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2015-05-13 13:04 - 2015-05-13 13:04 - 00000000 ____ D () C:\Spybot - Search Destroy
2015-05-13 11:45 - 2015-05-13 11:45 - 00741672 _____ (Web software ) C:\Users\TOM\Downloads\Spybot-Search-Destroy(12546)-dp (1).exe
2015-05-13 11:38 - 2015-05-13 11:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\TOM\Downloads\spybot-2.4.exe
2015-05-13 11:38 - 2015-05-13 11:38 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-SD Start Center.lnk
2015-05-13 11:38 - 2015-05-13 11:38 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-SD Start Center.lnk
2015-05-13 11:38 - 2015-05-13 11:38 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search Destroy 2
2015-05-13 11:38 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-05-13 11:37 - 2015-05-13 11:37 - 00741672 _____ (Web software ) C:\Users\TOM\Downloads\Spybot-Search-Destroy(12546)-dp.exe
2015-05-13 11:19 - 2015-05-13 18:02 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Tomaszek25) #3

Serdecznie dziękuję za pomoc. Wszystko wróciło do normy. Miło jest mieć wsparcie na Waszym forum. Jeszcze raz dziękuję Acorus.

 

Temat do zamknięcia.