Otwórz Notatnik i wklej w nim:
ShortcutWithArgument: C:\Users\Kryzac\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1451944735&z=f1f690c413f86481e2ec6a0g5z3wag3tczcz8m9cfq&from=face&uid=ST500LM012XHN-M500MBB_S2U3J9AC430344
HKLM-x32\...\Run: [gmsd_pl_005010197] => [X]
HKU\S-1-5-21-3692589925-2062225798-887492315-1000\...\Run: [svchost.exe] => C:\Windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe [55632 2010-11-05] (Microsoft Corporation)
HKU\S-1-5-21-3692589925-2062225798-887492315-1000\...\Policies\Explorer: []
HKU\S-1-5-21-3692589925-2062225798-887492315-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.protectedio.com/?u=5bfb9c3dde7f20c559c30dd77eae9fa9&c=p1&src=hp&inst=1451242259
SearchScopes: HKLM-x32 -> DefaultScope {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL =
SearchScopes: HKLM-x32 -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL =
SearchScopes: HKU\S-1-5-21-3692589925-2062225798-887492315-1000 -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL =
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.yoursearching.com/?type=sc&ts=1451932448&z=bbe9292c90b637470831461g5zfw2g3t4ceo7z7z5b&from=face&uid=ST500LM012XHN-M500MBB_S2U3J9AC430344
FF SearchPlugin: C:\Users\Kryzac\AppData\Roaming\Mozilla\Firefox\Profiles\j4dbqeau.default\searchplugins\search.xml [2016-01-04]
FF Extension: Firefox Helper - C:\Users\Kryzac\AppData\Roaming\Mozilla\Firefox\Profiles\j4dbqeau.default\Extensions\firefox@helper [2016-01-04] [Brak podpisu cyfrowego]
CHR HomePage: Default -> hxxp://www.yoursearching.com/?type=hp&ts=1451944735&z=f1f690c413f86481e2ec6a0g5z3wag3tczcz8m9cfq&from=face&uid=ST500LM012XHN-M500MBB_S2U3J9AC430344
CHR StartupUrls: Default -> "hxxp://www.yoursearching.com/?type=hp&ts=1451944735&z=f1f690c413f86481e2ec6a0g5z3wag3tczcz8m9cfq&from=face&uid=ST500LM012XHN-M500MBB_S2U3J9AC430344"
S2 PrivoxyService; "C:\Program Files (x86)\Softcomp Software\privoxy.exe" --service [X] <==== UWAGA
S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
C:\Windows\Minidump\*.dmp
DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\tylejipuzbt
CustomCLSID: HKU\S-1-5-21-3692589925-2062225798-887492315-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe => Brak pliku
CustomCLSID: HKU\S-1-5-21-3692589925-2062225798-887492315-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe /Automation => Brak pliku
CustomCLSID: HKU\S-1-5-21-3692589925-2062225798-887492315-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe /Automation => Brak pliku
CustomCLSID: HKU\S-1-5-21-3692589925-2062225798-887492315-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2014\en-US\acadficn.dll => Brak pliku
Task: {035C0263-5C54-4687-A943-E3871C713EE4} - System32\Tasks\{B1B1BCAB-1101-4B1D-8FE0-0AA04B7B6138} => pcalua.exe -a G:\DataCard_Setup.exe -d G:\
Task: {09C19F61-AC47-409F-8C35-2E41E28BBB67} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== UWAGA
Task: {1494809C-1343-49D8-98B6-262E3467422E} - System32\Tasks\Softcomp Software Viewer => C:\Program Files (x86)\Softcomp Software\swjob.exe <==== UWAGA
C:\Program Files (x86)\Softcomp Software
C:\Program Files (x86)\globalUpdate
Task: {2D791A47-0D19-4486-B461-80CED477B0B5} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5 => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5.exe <==== UWAGA
C:\Program Files (x86)\SavePass 1.1
Task: {3EAA2037-4A30-4B91-B218-1914D85E6CC1} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-7 => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-7.exe <==== UWAGA
Task: {57553D98-A7F7-41EE-B937-77C616EACD99} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-3 => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-3.exe <==== UWAGA
Task: {58BD5988-ED3F-4845-9BEF-2371DC44D878} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5_user => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5.exe <==== UWAGA
Task: {5D8F2ABE-A9E3-46F2-BF95-56485541C6EA} - System32\Tasks\System Installer => C:\Users\Kryzac\AppData\Roaming\System Installer\System Installer.exe <==== UWAGA
Task: {6DEA88C0-F829-4088-B57B-6B92CBCCBB76} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== UWAGA
Task: {74E877DB-8706-481C-8B9F-ACEE88463B07} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-7 => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-7.exe <==== UWAGA
Task: {947963C4-B19A-46F5-A053-5B31FC9C2FA7} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-6 => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-6.exe <==== UWAGA
Task: {977D51B1-062D-4551-8DF4-B8DBF76CC430} - System32\Tasks\{0D8ECA36-8434-41D8-A711-CBBEB5906F51} => pcalua.exe -a C:\Users\Kryzac\Downloads\SoftonicDownloader_dla_vanity-remover.exe -d C:\Users\Kryzac\Downloads <==== UWAGA
Task: {9F6193C8-E165-48BF-8FC5-255FC66499FB} - System32\Tasks\Price Fountain => C:\Users\Kryzac\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
C:\Users\Kryzac\AppData\Roaming\PRICEF~1
Task: {D8FF2B4C-919B-4305-A20B-3E95D0611D9E} - System32\Tasks\{FE6101DB-3A29-423C-9B3B-DDD1596056AF} => pcalua.exe -a "C:\Program Files (x86)\MPC Cleaner\Uninstall.exe"
Task: {DE9ECF09-807B-4D68-9F22-28ABBF4367C0} - System32\Tasks\{EAE772C2-D16C-44D8-BC30-DBB6E07B8BA8} => pcalua.exe -a C:\Users\Kryzac\Downloads\vcredist_x86.exe -d C:\Users\Kryzac\Downloads
Task: {E0A15E62-8DD1-4A0D-A83F-D6B2096BEF10} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-6 => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-6.exe <==== UWAGA
Task: {E8BD798F-B965-48F9-9896-E443D5DCA440} - System32\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-10_user => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-10.exe <==== UWAGA
Task: {FA32A539-56CF-4F4B-91BE-22016507B4D4} - System32\Tasks\Video Security Viewer => C:\Program Files (x86)\Video Security\VideoSecurity.exe <==== UWAGA
C:\Program Files (x86)\Video Security
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-6.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-6.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-7.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-1-7.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-10_user.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-10.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-3.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-3.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5_user.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-5.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-6.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-6.exe <==== UWAGA
Task: C:\Windows\Tasks\d980ca88-d29a-4f69-991c-e1e2ac7932f7-7.job => C:\Program Files (x86)\SavePass 1.1\d980ca88-d29a-4f69-991c-e1e2ac7932f7-7.exe <==== UWAGA
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== UWAGA
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== UWAGA
2016-01-04 19:38 - 2016-01-05 14:51 - 00000000 ____D C:\Users\Kryzac\AppData\Local\Touch Web
2016-01-04 19:38 - 2016-01-04 19:38 - 00003110 _____ C:\Windows\System32\Tasks\{FE6101DB-3A29-423C-9B3B-DDD1596056AF}
2016-01-04 19:37 - 2015-11-20 19:27 - 00019888 _____ () C:\Windows\system32\roboot64.exe
2016-01-04 19:36 - 2016-01-04 19:43 - 00000000 ____D C:\Users\Kryzac\AppData\Local\gmsd_pl_005010197
2016-01-04 18:45 - 2016-01-04 23:26 - 00003296 _____ C:\spyhunter.fix
2016-01-04 18:08 - 2016-01-04 23:00 - 00000008 _____ C:\END
2016-01-04 18:00 - 2016-01-04 19:34 - 00000000 ____D C:\ProgramData\kingsoft
2016-01-04 17:59 - 2016-01-04 20:37 - 00000000 ____D C:\Program Files (x86)\baidu
C:\Program Files\StatSoft
EmptyTemp:
Plik zapisz pod nazwą
fixlist.txt i umieść obok FRST.exe
Uruchom
FRST i kliknij przycisk
Fix (NAPRAW).
----------------------
Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:
DeleteQuarantine:
Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).
przez SHIFT+DEL usuń pozostały folder C:\FRST.
W Adw-Cleaner kliknij na przycisk
Odinstaluj (
UNINSTALL).
Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie.
.