Witam, proszę o pomoc w usunięciu tego ścierwa.
FRST http://www.wklej.org/id/1632157/
Addition http://www.wklej.org/id/1632158/
Witam, proszę o pomoc w usunięciu tego ścierwa.
FRST http://www.wklej.org/id/1632157/
Addition http://www.wklej.org/id/1632158/
Otwórz notatnik systemowy i wklej:
Task: {C3206910-F41B-49B3-A3FE-40DC27D53B8B} - System32\Tasks\{6E4AF94B-3D07-4B82-8CC0-5B84F700979C} = pcalua.exe -a C:\Users\Kamil\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
SearchScopes: HKU\S-1-5-21-3166236700-3475680827-4226387908-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD5000BEVT-22A0RT0_WD-WXD1A20Y9829Y9829ts=1423653497type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3166236700-3475680827-4226387908-1000 - {56F510E6-6D5C-40D9-9B22-D05A703BCCBC} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD5000BEVT-22A0RT0_WD-WXD1A20Y9829Y9829ts=1423653497type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3166236700-3475680827-4226387908-1000 - {75DC00C3-53B5-458E-84D2-759017E59444} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD5000BEVT-22A0RT0_WD-WXD1A20Y9829Y9829ts=1423653497type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3166236700-3475680827-4226387908-1000 - {D0E48F52-C9BA-4B3C-995C-2FCAD7A840A5} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD5000BEVT-22A0RT0_WD-WXD1A20Y9829Y9829ts=1423653497type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-3166236700-3475680827-4226387908-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=WDCXWD5000BEVT-22A0RT0_WD-WXD1A20Y9829Y9829ts=1423653497type=defaultq={searchTerms}
BHO-x32: Strong Signal - {c723a437-2eaf-466d-a95b-3fa0966bf88c} - C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
BHO-x32: No Name - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-3166236700-3475680827-4226387908-1000 - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF DefaultSearchEngine: key-find
FF SearchPlugin: C:\Users\Kamil\AppData\Roaming\Mozilla\Firefox\Profiles\xghkbx9t.default-1419509017554\searchplugins\key-find.xml
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Kamil\AppData\Roaming\Mozilla\Firefox\Profiles\xghkbx9t.default-1419509017554\extensions\fftoolbar2014@etech.com
S2 Update Framed Display; "C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe" [X]
S2 Util Framed Display; "C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe" [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
2015-02-11 14:12 - 2015-02-11 14:12 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\Kamil\Downloads\sh-remover.exe
2015-02-11 12:18 - 2015-02-11 12:18 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-11 14:36 - 2014-09-25 21:28 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.