Wyskakujące reklamy prośba o sprawdzenie logów

Witam,

proszę o pomoc w usunięciu wyskakujących reklam na komputerze.

 

FRST - http://wklejto.pl/226051

 

Additional - http://wklejto.pl/226052

 

Dziękuję z góry za pomoc.

 

Odinstaluj Contextual Tool Extrafind,Foxtab,SpyHunter.Otwórz notatnik systemowy i wklej:

CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 - C:\Users\Tomek\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{44EC053A-400F-11D0-9DCD-00A0C90391D3}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{B9BE6250-1199-40C5-9F70-4CCC9D2A717B}\InprocServer32 - C:\Users\Tomek\Documents\GameShadow\gmsAPI.dll (GameShadow Ltd)
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\InprocServer32 - No File Path
CustomCLSID: HKU\S-1-5-21-592451617-1550328129-2101807649-1001_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 - C:\Users\Tomek\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File
HKLM\...\Run: [Onet.pl AutoUpdate] = C:\Program Files\Common Files\Onet.pl\AutoUpdate.exe [260096 2005-07-27] (Onet.pl)
HKLM\...\Run: [Adobe ARM] = C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] = C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS6ServiceManager] = C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] = C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\Run: [PowerDVD14Agent] = C:\Program Files\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795672 2014-11-04] (CyberLink Corp.)
HKU\S-1-5-21-592451617-1550328129-2101807649-1001\...\Run: [ALLUpdate] = C:\Program Files\ALLPlayer\ALLUpdate.exe [2765256 2015-01-24] (ALLPlayer Group Ltd.)
HKU\S-1-5-21-592451617-1550328129-2101807649-1001\...\Run: [AVG-Secure-Search-Update_1213b] = C:\Users\Tomek\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=aadd7436173047d08c26208bc37ca51f-ad1491be2ce6c122f6b66faa90e70c2decf7d34c /CMPID=1213b
AppInit_DLLs: ,C:\PROGRA~1\NVIDIA~1\3DVISI~1\nvStInit.dll = C:\PROGRA~1\NVIDIA~1\3DVISI~1\nvStInit.dll File Not Found
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
CHR HKU\S-1-5-21-592451617-1550328129-2101807649-1001\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKU\S-1-5-21-592451617-1550328129-2101807649-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-592451617-1550328129-2101807649-1001 - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={CD69C684-48ED-40AC-A3A3-4CEE43A215A9}mid=aadd7436173047d08c26208bc37ca51f-ad1491be2ce6c122f6b66faa90e70c2decf7d34clang=plds=AVGcoid=avgtbavgcmpid=pr=frd=2014-11-06 14:01:07v=4.0.0.19pid=wtusg=sap=dspq={searchTerms}
FF Extension: EnterDigital - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\nmxk4qof.default\Extensions\{f1d7e225-e39d-4bcb-8a90-eaa4181b222b}.xpi [2014-11-02]
FF HKLM\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox
CHR HKLM\...\Chrome\Extension: [bildoibdboopgomcbiplincneeicgipj] - C:\Program Files\StartSearch plugin\startsplg.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [ccpanhmngcjhhdgmdmmhplabphdelnpo] - C:\Program Files\OApps\chrome-sl.crx [Not Found]
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2014-01-09] (Enigma Software Group USA, LLC.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-11-06] (AVG Technologies)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
U3 idsvc; No ImagePath
2015-04-20 21:10 - 2014-11-03 17:20 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Wielkie dzięki, pomogło :slight_smile:

Skasuj folder C:\FRST