
FRST: http://wklej.org/id/1660051/
Addition: http://wklej.org/id/1660053/
Z góry dzięki

BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
C:\Program Files (x86)\Strong Signal
FF Extension: Strong Signal - C:\Users\Karolina\AppData\Roaming\Mozilla\Firefox\Profiles\hhrvnkix.default\Extensions\{02df6ed9-d89d-425c-afc3-3a79ad6ce5ef}.xpi [2015-03-08]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Karolina\AppData\Roaming\Mozilla\Firefox\Profiles\hhrvnkix.default\extensions\fftoolbar2014@etech.com
CHR HKLM\...\Chrome\Extension: [noajmlkipclmeolfcnflkjhijkigpfjh] - C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [noajmlkipclmeolfcnflkjhijkigpfjh] - C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx [Not Found]
FF Extension: FF Toolbar - C:\Users\Karolina\AppData\Roaming\Mozilla\Firefox\Profiles\hhrvnkix.default\Extensions\fftoolbar2014@etech.com [2015-03-11]
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
C:\Program Files (x86)\Elex-tech
C:\Program Files (x86)\WinZipper
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1415215570&from=smt&uid=ST9500325AS_6VE7JFD6XXXX6VE7JFD6&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1415215570&from=smt&uid=ST9500325AS_6VE7JFD6XXXX6VE7JFD6&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1415215570&from=smt&uid=ST9500325AS_6VE7JFD6XXXX6VE7JFD6&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1415215570&from=smt&uid=ST9500325AS_6VE7JFD6XXXX6VE7JFD6&q={searchTerms}
HKU\S-1-5-21-2850603902-3714071968-266101394-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1418203011&from=wpm12103&uid=ST9500325AS_6VE7JFD6XXXX6VE7JFD6&q={searchTerms}
HKU\S-1-5-21-2850603902-3714071968-266101394-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1418203011&from=wpm12103&uid=ST9500325AS_6VE7JFD6XXXX6VE7JFD6&q={searchTerms}
FF SearchEngineOrder.1: V9
FF SelectedSearchEngine: V9
R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2015-03-11] (Elex do Brasil cenzura!ções Ltda)
R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [426160 2015-03-05] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [249000 2015-03-11] (Elex do Brasil cenzura!ções Ltda)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [45224 2015-03-11] (Elex do Brasil cenzura!ções Ltda)
R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [99496 2015-03-11] (Elex do Brasil cenzura!ções Ltda)
R1 iSafeKrnlMon; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [42152 2015-03-11] (Elex do Brasil cenzura!ções Ltda)
R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [93352 2015-03-11] (Elex do Brasil cenzura!ções Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [52392 2015-02-17] (Elex do Brasil cenzura!ções Ltda)
C:\Windows\System32\DRIVERS\iSafeNetFilter.sys
C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys
R1 {d274785e-a122-4588-b510-cd4d0fe10348}Gw64; C:\Windows\System32\drivers\{d274785e-a122-4588-b510-cd4d0fe10348}Gw64.sys [48792 2014-12-12] (StdLib)
C:\Windows\System32\drivers\{d274785e-a122-4588-b510-cd4d0fe10348}Gw64.sys
C:\Users\Karolina\Downloads\SpyHunter-Installer.exe
C:\Users\Public\Desktop\YAC.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
C:\Users\Karolina\Downloads\yet_another_cleaner_avae_setup_10629726427.exe
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\Users\Karolina\Downloads\Silverlight(17716)-dp.exe
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 19 gości