
mam problem z Strong Signal ads. Proszę o pomoc.
http://www.wklej.org/id/1709589/ GMER
http://www.wklej.org/id/1709620/ OTL
http://www.wklej.org/id/1709622/ EXTRAS
http://www.wklej.org/id/1709626/ FRST
http://www.wklej.org/id/1709628/ ADDITION
BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
C:\Program Files (x86)\Strong Signal
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{5EC9566F-2D94-4183-8E78-1834B26C29EB}.exe <==== ATTENTION
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{B694DB1F-62F0-4159-B5F0-F9F73573EDC0}.exe <==== ATTENTION
Task: {FC15D84D-0564-43B8-AF98-92B431AB195E} - System32\Tasks\Your File Updater => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION
Task: {E312449F-2F00-47B3-ADF2-E3C3F000C47B} - System32\Tasks\{B7538B1C-1C3A-4F98-96B6-E041D0570AB0} => C:\Users\Michał\Downloads\358\358.exe
C:\Users\Michał\Downloads\358
Task: {7DDD0221-CA18-48D6-9516-C3F88723B807} - System32\Tasks\{543C942F-34F3-49E3-9DFE-0EE091BEE2C0} => C:\Users\Michał\Downloads\358\358.exe
Task: {08821625-5B46-4C0E-ACC5-37A20732EDF8} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
C:\Users\Michał\AppData\Local\Temp*.html
C:\ProgramData\boost_interprocess
C:\Users\Michał\Downloads\SpyHunter-Installer.exe
S3 cpuz132; \??\C:\Users\MICHA~1\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [X]
S4 sfdrv01; System32\drivers\sfdrv01.sys [X]
S4 sfhlp02; System32\drivers\sfhlp02.sys [X]
R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys [61120 2014-05-22] (StdLib)
S2 MSK80Service; "C:\Program Files (x86)\McAfee\MSK\MskSrver.exe" [X]
S2 Update Rock Turner; "C:\Program Files (x86)\Rock Turner\updateRockTurner.exe" [X]
S2 Util Rock Turner; "C:\Program Files (x86)\Rock Turner\bin\utilRockTurner.exe" [X]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
C:\Program Files (x86)\XTab
CHR HKLM-x32\...\Chrome\Extension: [jhjjdgbhohaallcimgcmakfiobacimkm] - C:\Program Files (x86)\BuzzSearch\jhjjdgbhohaallcimgcmakfiobacimkm.crx [Not Found]
C:\Program Files (x86)\BuzzSearch
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll No File
CHR Plugin: (BonanzaDealsLive Update) - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll No File
CHR StartupUrls: Default -> "hxxp://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470"
FF Extension: Strong Signal - C:\Users\Michał\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\{629ac51d-702d-4c48-8a56-6d6a5061a41f}.xpi [2015-02-05]
FF Extension: Babylon - C:\Users\Michał\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\ffxtlbr@babylon.com [2012-07-24]
FF DefaultSearchEngine: key-find
FF SelectedSearchEngine: key-find
FF Homepage: hxxp://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
Toolbar: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll No File
Toolbar: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> No Name - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No File
Toolbar: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File
Toolbar: HKLM-x32 - vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll [2010-09-06] ()
Toolbar: HKLM-x32 - StartSearchToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll [2011-11-24] (StartSearch Inc.)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: BuzzSearch -> {5cf5a690-c8f4-488e-9d20-f21aef602d41} -> C:\Program Files (x86)\BuzzSearch\BuzzSearchBHO.dll No File
BHO-x32: AC-Pro -> {0FB6A909-6086-458F-BD92-1F8EE10042A0} -> C:\Program Files (x86)\AutocompletePro\AutocompletePro.dll [2010-07-14] (SimplyGen)
BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~2\mcafee\msk\mskapbho.dll No File
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll [2015-01-16] (Thinknice Co. Limited)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: vShare Plugin -> {043C5167-00BB-4324-AF7E-62013FAEDACF} -> C:\Program Files (x86)\vShare\vshare_toolbar.dll [2010-09-06] ()
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2530240
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dspp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> bProtectorDefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> Moikrug URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> Yandex URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {043C5167-00BB-4324-AF7E-62013FAEDACF} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dspp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {5C198F82-0BD0-4EFC-9869-F7106466866F} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {89110237-ECC4-437A-BAFA-6A1A615A7427} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2059011784-56926361-251635567-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&ts=1423128341&type=default&q={searchTerms}
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~2\mcafee\msk\MSKAPB~1.DLL No File
SearchScopes: HKLM-x32 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://startsear.ch/?aff=2&src=sp&cf=3c3c0a0e-549a-11e1-b83e-705ab62a8e44&q={searchTerms}
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=ds&ts=1423128302&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=ds&ts=1423128302&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=ds&ts=1423128302&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=ds&ts=1423128302&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
HKU\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
HKU\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hppp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470
HKU\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dspp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
HKU\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://isearch.babylon.com/?babsrc=HP_ss_Btisdt5&mntrId=0886C417FE242CAC&affID=119357&tt=150913_ctrl&tsp=5008
HKU\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dspp&ts=1423128311&from=cor&uid=WDCXWD5000BEVT-22A0RT0_WD-WX10AC9V9470V9470&q={searchTerms}
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll File Not Found
HKU\S-1-5-21-2059011784-56926361-251635567-1000\...\Run: [Rubin] => C:\Users\Michał\AppData\Local\Rubin\rubin.exe silent
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
C:\Program Files (x86)\Mobogenie
HKLM-x32\...\Run: [NWEReboot] => [X]
EmptyTemp:
*strong*.*
Strong
C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_strongsignal-a.akamaihd.net_0.localstorage
C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_strongsignal-a.akamaihd.net_0.localstorage-journal
Reg: reg delete HKLM\SOFTWARE\Classes\Interface\{BA6EB888-8424-4C93-8E71-6050C714CFBE} /f
Reg: reg delete HKLM\SOFTWARE\Classes\TypeLib\{E806AC01-E7A5-4949-AF7C-7E6E5775035B} /f
Reg: reg delete HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{BA6EB888-8424-4C93-8E71-6050C714CFBE} /f
Reg: reg delete HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{E806AC01-E7A5-4949-AF7C-7E6E5775035B} /f
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BA6EB888-8424-4C93-8E71-6050C714CFBE} /f
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{E806AC01-E7A5-4949-AF7C-7E6E5775035B} /f
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BA6EB888-8424-4C93-8E71-6050C714CFBE} /f
C:\Program Files (x86)\Strong Signal
Reg: reg delete "HKEY_USERS\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\strongsignal-a.akamaihd.net"
EmptyTemp:
StrongSignal*.*
StrongSignal;
Strong Signal
Windows Registry Editor Version 5.00
[-HKEY_USERS\S-1-5-21-2059011784-56926361-251635567-1000\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\strongsignal-a.akamaihd.net]
Tworzenie własnego tematu:
Gdy mamy problem z komputerem tworzymy swój własny temat, nie dopisujemy się do tematów innych osób.
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości