
Zgodnie z instrukcjami znalezionymi na forum zrobiłem co następuje:
1 Użyłem Adw-cleaner
2 Zrobiłem logi z FRST w załącznikach podaję raporty.
Czekam na instrukcje w celu pozbycia się tego śmiecia.
C:\Users\marchewkowy\AppData\Roaming\mystartsearch
Task: C:\Windows\Tasks\schedule!3036567561.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\{5B4FFFED-1283-4E12-A4B6-7A865434D348}.job => C:\ProgramData\BetterSoft\ContinueToSave\ContinueToSave.exe <==== ATTENTION
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
HKLM\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
HKLM\...\Run: [ROC_ROC_NT] => "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-858350963-701885483-4211334611-1000\...\MountPoints2: {9e05d034-3f00-11de-a63f-806e6f6e6963} - m9ma.exe
HKU\S-1-5-21-858350963-701885483-4211334611-1000\...\MountPoints2: {a9135fa4-073d-11de-afba-002243a29a5b} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
HKU\S-1-5-18\...\RunOnce: [] => [X]
SearchScopes: HKLM - {2486BFBA-0EAC-47D2-785B-286B33D8EF36} URL = http://search.searchonme.com/?q={searchTerms}
BHO: IEPluginBHO Class -> {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} -> C:\Users\marchewkowy\AppData\Roaming\Gadu-Gadu 10\_userdata\ggbho.2.dll No File
Toolbar: HKCU - No Name - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No File
CHR HKLM\...\Chrome\Extension: [djbbefdegofnpgnbnmhkglcbhpgidpad] - C:\ProgramData\SaveAs\djbbefdegofnpgnbnmhkglcbhpgidpad.crx []
S2 Update PodoWeb; "C:\Program Files\PodoWeb\updatePodoWeb.exe" [X]
S3 cpuz135; \??\C:\Users\MARCHE~1\AppData\Local\Temp\cpuz135\cpuz135_x32.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 lvupdtio; \??\C:\Program Files\ASUS\ASUS Live Update\SYS\lvupdtio.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
C:\Windows\Tasks\{5B4FFFED-1283-4E12-A4B6-7A865434D348}.job
EmptyTemp:
mystartsearch uninstall (HKLM\...\mystartsearch uninstall) (Version: - mystartsearch) <==== ATTENTION
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall" /f
ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.mystartsearch.com/?type=sc&ts=1415295880&from=smt&uid=HitachiXHTS543232L9A300_080905FB2400LEGVBTUAX
EmptyTemp:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 9 gości