
i mnie dopadło....
jak poczytałem w poprzednich postach, pierwsze uruchomiłem AdwCleaner
http://www.wklejto.pl/222805
FRST:
http://wklejto.pl/222809
http://wklejto.pl/222810
http://wklejto.pl/222811
http://wklejto.pl/222812
Proszę o pomoc

BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll ()
C:\Program Files (x86)\Strong Signal
R2 Service Mgr StrongSignal; C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugincontainer.exe [577272 2015-02-23] ()
R2 Update Mgr StrongSignal; C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe [384760 2015-02-23] ()
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugincontainer.exe
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Strong Signal" /f
CHR Extension: (Strong Signal) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdidplnlbafiijjfbomlfokdppebnhpc [2015-02-21]
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3\plugin.exe
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3\f3d65cf3-ad98-4362-b4f3-cb3a55e3881c.dll
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ&q={searchTerms}
HKU\S-1-5-21-2819753486-3370579920-3938749151-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ&q={searchTerms}
HKU\S-1-5-21-2819753486-3370579920-3938749151-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1418469201&from=cor&uid=ST500LT012-1DG142_S3P9MVLQXXXXS3P9MVLQ
FF Extension: Strong Signal - C:\Users\Zbigniew\AppData\Roaming\Mozilla\Firefox\Profiles\ux9fv6xs.default-1424463555243\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-21]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [485888 2014-12-13] (Fuyu LIMITED) [File not signed]
C:\ProgramData\WindowsMangerProtect
S2 Update Hold Page; "C:\Program Files (x86)\Hold Page\updateHoldPage.exe" [X]
C:\Program Files (x86)\Hold Page
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
EmptyTemp:
DeleteQuarantine:
Running from C:\Users\Zbigniew\Downloads
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 2 gości