Wyświetlające się reklamy - skan otl

Witam

 

Potrzebuję pomocy w usunięciu badziewia który wyświetla mi reklamy.

 

Początkowo pobrał się razem z programem (niestety stąd) search protect który został odinstalowany + usunięty przez 360 total security.

Niestety, problem nie zniknął. Poniżej dołączam skany z OTL.

Odinstaluj Adobe Reader 9.5.0 - Polish.

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.

Adobe został odinstalowany. Wklejam raporty

Otwórz notatnik systemowy i wklej:

ShellIconOverlayIdentifiers: [00avast] - {472083B0-C522-11CF-8763-00608CC02F24} = No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKU\S-1-5-21-2343504291-231088005-2091949997-1002 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKU\S-1-5-21-2343504291-231088005-2091949997-1002 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bts=1424467753type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2343504291-231088005-2091949997-1002 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bts=1424467753type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2343504291-231088005-2091949997-1002 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424467737from=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bq={searchTerms}
SearchScopes: HKU\S-1-5-21-2343504291-231088005-2091949997-1002 - {49B07062-A0C3-4F63-8058-DB8E206A5F22} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bts=1424467753type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2343504291-231088005-2091949997-1002 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=CrucialXCT256MX100SSD1_14490DF3DE2B0DF3DE2Bts=1424467753type=defaultq={searchTerms}
S1 {3788502c-c1e8-40a8-8914-655def81ee5b}Gw64; system32\drivers\{3788502c-c1e8-40a8-8914-655def81ee5b}Gw64.sys [X]
2015-02-20 22:29 - 2015-02-21 11:55 - 00000000 ____ D () C:\Program Files (x86)\XTab
2015-02-20 22:29 - 2015-02-20 22:29 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-20 22:28 - 2015-02-21 11:55 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-02-20 17:23 - 2015-02-20 17:23 - 00003208 _____ () C:\WINDOWS\System32\Tasks\{A9B49748-F42B-4537-9599-C669A5213600}
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Zrobione, dzięki wielkie za pomoc. Mam nadzieję, że nie pojawi się już żaden badziew. Pozdrawiam

Skasuj folder C:\FRST