
Bardzo proszę o pomoc w usunięciu paskudztwa o nazwie Strong Signal.
W załączniku przesyłam logi.
Z góry dzięki.
Update for PriceFountain (HKU\S-1-5-21-725345543-2111687655-1343024091-1003\...\Price Fountain) (Version: - Update for PriceFountain) <==== ATTENTION
FF Extension: Strong Signal - C:\Documents and Settings\xzy666\Dane aplikacji\Mozilla\Firefox\Profiles\e9sgjhqj.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-21]
CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hp&ts=1424865517&from=exp&uid=TOSHIBAXMK4032GAX_26ED5674SXX26ED5674S
R2 pysucode; C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\010413BD-1424869487-CB11-BE16-E4D09EFD8B2B\snsuB1.tmp [179712 2015-02-25] () [File not signed]
R2 sucoweti; C:\Documents and Settings\xzy666\Dane aplikacji\010413BD-1424869306-CB11-BE16-E4D09EFD8B2B\nsy7C.tmpfs [X]
S2 ATE_PROCMON; \??\d:\Program Files\Anti Trojan Elite\ATEPMon.sys [X]
CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1424865517&from=exp&uid=TOSHIBAXMK4032GAX_26ED5674SXX26ED5674S"
CHR DefaultSearchKeyword: Default -> webssearches
S2 8f9aa86c; c:\Program Files\ReactorSubs\ReactorSubs.dll [1677824 2015-02-25] () [File not signed]
R2 cizydoje; C:\Documents and Settings\xzy666\Dane aplikacji\010413BD-1424869306-CB11-BE16-E4D09EFD8B2B\jnsh88.tmp
CHR DefaultSearchURL: Default -> http://istart.webssearches.com/web/?type=ds&ts=1424865517&from=exp&uid=TOSHIBAXMK4032GAX_26ED5674SXX26ED5674S&q={searchTerms}
CustomCLSID: HKU\S-1-5-21-725345543-2111687655-1343024091-1003_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\DOCUME~1\xzy666\USTAWI~1\Temp\DDC0\temp\Spyhunter 4 Email and password plus Crack download.exe No (the data entry has 5 more characters).
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gmsd_pl_56" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\LuckyTab" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ROC_roc_ssl_v12" /f
C:\Documents and Settings\xzy666\Dane aplikacji\010413BD-1424869306-CB11-BE16-E4D09EFD8B2B\jnsh88.tmp
C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\010413BD-1424869487-CB11-BE16-E4D09EFD8B2B\snsuB1.tmp
C:\Documents and Settings\xzy666\Dane aplikacji\010413BD-1424869306-CB11-BE16-E4D09EFD8B2B\nsy7C.tmpfs
C:\Program Files\AVG Secure Search
C:\Program Files\LuckyTab
C:\Program Files\gmsd_pl_56
C:\Documents and Settings\xzy666\Dane aplikacji\010413BD-1424869306-CB11-BE16-E4D09EFD8B2B
Toolbar: HKU\S-1-5-21-725345543-2111687655-1343024091-1003 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
BHO: Box Rock 1.0.0.7 -> {464deeb8-b74f-4117-b8ec-e42f4028f3d1} -> C:\Program Files\Box Rock\BoxRockbho.dll No File
C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\nsw5F5.tmp
C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\nsk9E.tmp
C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\nsw52B.tmp
C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\nsf129.tmp
C:\Program Files\QuickRef_1.10.0.9
C:\Documents and Settings\xzy666\Ustawienia lokalne\Dane aplikacji\010413BD-1424869487-CB11-BE16-E4D09EFD8B2B
C:\Documents and Settings\xzy666\Dane aplikacji\010413BD-1424869306-CB11-BE16-E4D09EFD8B2B
C:\Documents and Settings\All Users\Menu Start\YourFileDownloader
C:\Program Files\ReactorSubs
C:\Documents and Settings\All Users\Dane aplikacji\{d0924e3a-b2a1-6c54-d092-24e3ab2a38ea}
C:\Documents and Settings\All Users\Dane aplikacji\Simply Super Software
C:\Program Files\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\Documents and Settings\All Users\Dane aplikacji\0780f478-67ce-4ec3-98db-39a65f4618ce
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 3 gości