1) Użyj
Adw-Cleaner http://www.programosy.pl/program,adwcleaner.html
najpierw kliknij na SKANUJ (SCAN), a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ (CLEANING), to kliknij na niego.
Pokaż raport z niego "C"
2) Otwórz Notatnik i wklej w nim:
Task: {6ECA6577-11C4-4720-8814-449DDD54837A} - System32\Tasks\LuckyBrowse => C:\Program Files\LuckyBrowse\app\luckybrowse.exe [2016-04-20] () <==== ATTENTION
Task: {8956D9B4-51CF-4617-B2C2-A1BEAFA607CE} - System32\Tasks\SalsarezDreamlessThriftinessV2 => Rundll32.exe ComfitSnootily.dll,main 7 1 <==== ATTENTION
Task: {0CF62C02-CFC1-4CED-824D-4238257C41F8} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2013\bdproductdata.exe
ShortcutWithArgument: C:\Users\Salsarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1461184845&a=1008083&src=sh&uuid=6fe0f3c1-4fa5-4836-8cb3-89404057eeda"
ShortcutWithArgument: C:\Users\Salsarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1461184845&a=1008083&src=sh&uuid=6fe0f3c1-4fa5-4836-8cb3-89404057eeda"
ShortcutWithArgument: C:\Users\Salsarez\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1461184845&a=1008083&src=sh&uuid=6fe0f3c1-4fa5-4836-8cb3-89404057eeda"
ShortcutWithArgument: C:\Users\Salsarez\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "hxxp://trustedsurf.com/?ssid=1461184845&a=1008083&src=sh&uuid=6fe0f3c1-4fa5-4836-8cb3-89404057eeda"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1461184845&a=1008083&src=sh&uuid=6fe0f3c1-4fa5-4836-8cb3-89404057eeda"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "hxxp://trustedsurf.com/?ssid=1461184845&a=1008083&src=sh&uuid=6fe0f3c1-4fa5-4836-8cb3-89404057eeda"
C:\Program Files\LuckyBrowse
2015-11-04 23:49 - 2015-11-04 23:49 - 0000098 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2016-04-20 22:43 - 2016-04-20 22:43 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-04-20 22:41 - 2016-04-25 18:43 - 00000000 ____D C:\Users\Salsarez\AppData\Roaming\SpringFiles
2016-04-20 22:41 - 2016-04-25 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\LuckyBrowse
2016-04-20 22:41 - 2016-04-25 18:43 - 00000000 ____D C:\Program Files\LuckyBrowse
2016-04-20 22:41 - 2016-04-20 22:41 - 00000000 ____D C:\ProgramData\LuckyBrowse
C:\Users\Salsarez\Downloads\Icecream-Screen-Recorder-58975-dp.exe
2016-05-11 22:59 - 2016-05-11 22:59 - 00000000 ____D C:\Users\Salsarez\AppData\Local\BedsoresHoofbeats
2016-05-11 23:58 - 2016-05-11 23:58 - 00980199 _____ (Sonepopi ) C:\Users\Salsarez\Downloads\VidShot-Capturer-31862-dp.exe
2016-05-11 23:58 - 2016-05-11 23:58 - 00980199 _____ (Sonepopi ) C:\Users\Salsarez\Downloads\SCREEN2EXE-33511-dp.exe
2016-05-11 23:57 - 2016-05-11 23:57 - 00980199 _____ (Sonepopi ) C:\Users\Salsarez\Downloads\Open-Broadcaster-Software-58008-dp.exe
2016-05-11 23:57 - 2016-05-11 23:57 - 00980199 _____ (Sonepopi ) C:\Users\Salsarez\Downloads\LoiLo-Game-Recorder-68580-dp.exe
S3 catchme; \??\C:\Users\Salsarez\AppData\Local\Temp\catchme.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
CHR HomePage: Default -> hxxp://www.istartsurf.com/?type=hp&ts=1446673743&z=de1baea5f23f427127e1bf6gfz6z3q7qfm7c7z4q0b&from=cor&uid=WDCXWD3200BEVT-60ZCT1_WD-WXG0A594581445814
CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1446673743&z=de1baea5f23f427127e1bf6gfz6z3q7qfm7c7z4q0b&from=cor&uid=WDCXWD3200BEVT-60ZCT1_WD-WXG0A594581445814"
FF HKLM\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Salsarez\AppData\Roaming\Mozilla\Firefox\Profiles\j0shm3vu.default\extensions\defsearchp@gmail.com => not found
FF HKLM\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Salsarez\AppData\Roaming\Mozilla\Firefox\Profiles\j0shm3vu.default\extensions\deskCutv2@gmail.com
FF Extension: FirefixTab - C:\Users\Salsarez\AppData\Roaming\Mozilla\Firefox\Profiles\j0shm3vu.default\Extensions\deskCutv2@gmail.com [2015-12-16] [not signed]
FF NewTab: chrome://quick_start/content/index.html
FF SelectedSearchEngine: istartsurf
URLSearchHook: HKLM - (No Name) - {96f454ea-9d38-474f-b504-56193e00c1a5} - No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1957755764-4067128848-3553440476-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
ManualProxies: 0hxxp://unstops.net/wpad.dat?23eb387e9e457a75de38d8aaf27db2449143850
EmptyTemp:
Plik zapisz pod nazwą
fixlist.txt i umieść obok FRST.exe
Uruchom
FRST i kliknij przycisk
Fix (NAPRAW).
3) Napisz,czy problem znikł?
.