Zamulanie, reklamy i bezradność (LOG)

Witam. Niestety, ale w instalacje jakiegoś programu było zamieszczone złośliwe oprogramowanie. Skan zrobiłem (antyvir Comodo), przeskanowałem również Malwarebytes Anti-Malvare i SpyBot. Coś tam znalazło i pousuwało jednakże spadek wydajności dalej jest zauważalny.

 

Zamieszczam logi.

 

Tutaj log z OTLa

http://wklej.org/id/1556965/

 

a tutaj z FRST

 

http://wklej.org/id/1556968/

 

Addition

 

http://wklej.org/id/1557644/

 

Jakby ktoś mógł spojrzeć to byłbym wdzięczny :slight_smile:

Brak loga Addition.txt

Już dodałem :slight_smile:

Odinstaluj ASUS WebStorage,GeekBuddy.Otwórz Notatnik i wklej:

Hosts:
Task: {32E0478B-969D-4B17-ABA2-A90E89B188E1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates = C:\Program Files (x86)\Spybot - Search amp; Destroy 2\SDUpdate.exe
Task: {4D901F93-BC3D-4014-AA31-65267EF2C8BF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization = C:\Program Files (x86)\Spybot - Search amp; Destroy 2\SDImmunize.exe
Task: {8D9EDA91-8968-430D-97DF-CFB4AD8B4729} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system = C:\Program Files (x86)\Spybot - Search amp; Destroy 2\SDScan.exe
HKLM-x32\...\Run: [Adobe ARM] = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSWebStorage] = C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [tvncontrol] = C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-07-25] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [SDTray] = C:\Program Files (x86)\Spybot - Search Destroy 2\SDTray.exe [4101576 2014-12-11] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1074697864-3398204489-2569474986-1001\...\Run: [ISUSPM] = C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2014-12-09] (Acresso Corporation)
HKU\S-1-5-21-1074697864-3398204489-2569474986-1001\...\Run: [ALLUpdate] = C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2765256 2014-12-09] (ALLPlayer Group Ltd.)
BootExecute: autocheck autochk * sdnclean64.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\S-1-5-21-1074697864-3398204489-2569474986-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
SearchScopes: HKU\S-1-5-21-1074697864-3398204489-2569474986-1001 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1074697864-3398204489-2569474986-1001 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-07-25] (Comodo Security Solutions, Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDFSSvc.exe [1738168 2014-12-11] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
2014-12-11 21:14 - 2014-12-11 21:14 - 00000000 ____ D () C:\Windows\System32\Tasks\Safer-Networking
2014-12-11 21:13 - 2014-12-12 13:07 - 00000000 ____ D () C:\ProgramData\Spybot - Search Destroy
2014-12-11 21:13 - 2014-12-11 21:13 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-12-11 21:13 - 2014-12-11 21:13 - 00001397 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-SD Start Center.lnk
2014-12-11 21:13 - 2014-12-11 21:13 - 00001385 _____ () C:\Users\Public\Desktop\Spybot-SD Start Center.lnk
2014-12-11 21:13 - 2014-12-11 21:13 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search Destroy 2
2014-12-11 21:12 - 2014-12-11 21:20 - 00000000 ____ D () C:\Program Files (x86)\Spybot - Search Destroy 2
2014-12-11 21:09 - 2014-12-11 21:11 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\AD\Downloads\spybot-2.4.exe
2014-12-11 19:15 - 2014-12-11 19:15 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\AD\Downloads\SpyHunter-Installer.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.