Uruchom Fix it i przywróć domyślny plik Hosts:
http://support.microsoft.com/kb/972034/pl
W panelu sterowania odinstaluj:
YoutubeAdblocker
ss Supporter 1.80
SaveNewaAppz
AutocompletePro
FileHippo.com Update Checker
uTorrentBar Toolbar
Usuń rozszerzenie Greatsaver, AutocompletePro, SaveNewaAppz, YoutubeAdblocker:
Odinstalowywanie rozszerzeń
Pobierz i uruchom AdwCleaner Kliknij Szukaj i później Usuń.
Do okna Własne opcje skanowania / skrypt wklej:
:OTL
SRV - [2014-03-17 15:02:14 | 000,117,928 | ---- | M] (Elex do Brasil Participações Ltda) [Auto | Running] -- C:\Program Files\iSafe\iSafeSvc.exe -- (iSafeService)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV - [2014-03-17 15:04:25 | 000,039,424 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | System | Unknown] -- C:\Program Files\iSafe\iSafeNetFilter.sys -- (iSafeNetFilter)
DRV - [2014-03-17 15:04:16 | 000,186,752 | ---- | M] (Elex do Brasil Participações Ltda) [File_System | On_Demand | Running] -- C:\Program Files\iSafe\iSafeKrnl.sys -- (iSafeKrnl)
[2014-04-05 00:24:53 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Users\Sylwia\AppData\Roaming\mozilla\Firefox\Profiles\gkiiast6.default-1396648887251\extensions\cacaoweb@cacaoweb.org
O2 - BHO: (no name) - {C18A689F-EEEE-C9D6-D9CA-BC72D9F274CC} - No CLSID value found.
O3 - HKU\S-1-5-21-2571174151-4129804676-3139327224-1000\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKU\S-1-5-21-2571174151-4129804676-3139327224-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKU\S-1-5-21-2571174151-4129804676-3139327224-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-2571174151-4129804676-3139327224-1000..\Run: [BackgroundContainer] C:\Users\Sylwia\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll (Conduit Ltd.)
O4 - HKU\S-1-5-21-2571174151-4129804676-3139327224-1000..\Run: [cacaoweb] C:\Users\Sylwia\AppData\Roaming\cacaoweb\cacaoweb.exe ()
O4 - Startup: C:\Users\Sylwia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Torpedo.lnk = File not found
O20 - AppInit_DLLs: (c:\progra~1\sssupp~1\assist~1.dll) - c:\Program Files\ss Supporter\Assistant.dll ()
[2014-04-04 23:28:17 | 000,000,000 | ---D | C] -- C:\Users\Sylwia\AppData\Roaming\eCyber
[2014-04-04 23:27:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
[2014-04-04 23:26:46 | 000,000,000 | ---D | C] -- C:\Program Files\iSafe
[2014-04-04 23:17:17 | 000,000,000 | ---D | C] -- C:\Users\Sylwia\AppData\Roaming\iSafe
[2014-03-08 16:19:02 | 000,000,000 | ---D | C] -- C:\Users\Sylwia\AppData\Roaming\OpenCandy
[2014-03-08 16:17:34 | 000,000,000 | ---D | C] -- C:\ProgramData\SaveNewaAppz
[2014-03-08 10:19:14 | 000,000,000 | -HSD | C] -- C:\found.001
[2014-04-06 10:38:41 | 000,000,466 | -H-- | M] () -- C:\Windows\tasks\GS.Enabler-S-1824435291.job
:Files
C:\Users\Sylwia\AppData\Local\Temp*.html
:Commands
[emptytemp]
Kliknij Wykonaj skrypt i zatwierdź restart.
Pokaż raport z usuwania i nowy log Skanuj.
Pobierz Farbar Recovery Scan Tool 32-Bit Version
Uruchom FRST i kliknij Scan. Pokaż raport FRST i Addition.