Otwórz Notatnik i wklej w nim:
FF Extension: Strong Signal - C:\Users\Grzegorz\AppData\Roaming\Mozilla\Firefox\Profiles\3bpt4w7n.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-21]
BHO-x32: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> C:\Users\test\AppData\Local\PriceFountain\PriceFountainIE.dll No File
BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
C:\Program Files (x86)\Strong Signal
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml
FF Extension: Strong Signal - C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\0khsj43r.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-20]
HKLM\...\Run: [] => [X]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [714624 2015-01-03] (Cherished Technololgy LIMITED)
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Task: {20CE4635-0C72-4975-95E2-7951EA60C634} - System32\Tasks\Price Fountain => C:\Users\test\AppData\Roaming\PriceFountain\UpdateProc\UpdateTask.exe [2015-01-03] () <==== ATTENTION
C:\Users\test\AppData\Roaming\PriceFountain
Task: C:\WINDOWS\Tasks\Price Fountain.job => C:\Users\test\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\ProgramData\IePluginServices\PluginService.exe
C:\ProgramData\IePluginServices
HKLM-x32\...\Run: [] => [X]
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1420322148&from=cor&uid=ST1000LM024XHN-M101MBB_S2SMJ9CD104317&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1420322148&from=cor&uid=ST1000LM024XHN-M101MBB_S2SMJ9CD104317&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1420322148&from=cor&uid=ST1000LM024XHN-M101MBB_S2SMJ9CD104317&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1420322148&from=cor&uid=ST1000LM024XHN-M101MBB_S2SMJ9CD104317&q={searchTerms}
URLSearchHook: [S-1-5-21-258006932-2837254710-3905018190-1001] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\S-1-5-21-258006932-2837254710-3905018190-1002 -> {2AC17796-8AA2-4EE9-B785-08C9DD59A823} URL =
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1420322148&from=cor&uid=ST1000LM024XHN-M101MBB_S2SMJ9CD104317
FF HKLM-x32\...\Firefox\Extensions: [lightningnewtab@gmail.com] - C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\0khsj43r.default\extensions\lightningnewtab@gmail.com.xpi
CHR Extension: (No Name) - C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla [2013-11-21]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2015-01-03] (Fuyu LIMITED) [File not signed]
R1 {ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64; C:\Windows\System32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys [48792 2015-01-03] (StdLib)
EmptyTemp:
Plik zapisz pod nazwą
fixlist.txt i umieść obok
FRST. Uruchom
FRST i kliknij przycisk
Fix.
Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:
DeleteQuarantine:
Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix.
przez SHIFT+DEL usuń pozostały folder C:\FRST
W Adw-Cleaner kliknij na przycisk
Odinstaluj (
UNINSTALL).