Proszę o pomoc w usunięciu szkodliwego oprogramowania. Nowiutki laptop pracuje jak złów ;/
BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll ()
C:\Program Files (x86)\Strong Signal
FF Extension: Strong Signal - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\rhanpdkr.default\Extensions\{d53d402a-1b39-4020-8066-3e40f3b55121}.xpi [2015-02-23]
R2 Update Mgr StrongSignal; C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce\updater.exe [388856 2015-02-25] ()
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
C:\Program Files (x86)\Common Files\0780f478-67ce-4ec3-98db-39a65f4618ce
Task: C:\Windows\Tasks\Binkiland.job => C:\Users\Patrycja\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Patrycja\AppData\Roaming\BINKIL~1
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Task: {8B654146-7A30-4FAB-972D-0AFD2137AB15} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-11-25] (MyPC Backup) <==== ATTENTION
C:\Program Files (x86)\MyPC Backup
Task: {21B48C04-6141-4E42-95A8-A468C3CF58EE} - System32\Tasks\Binkiland => C:\Users\Patrycja\AppData\Roaming\Binkiland\UpdateProc\UpdateTask.exe [2015-02-10] () <==== ATTENTION
C:\Users\Patrycja\AppData\Roaming\Binkiland
HKLM-x32\...\RunOnce: [Binkiland] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Patrycja\AppData\Roaming\Binkiland\UpdateProc\bkup.dat"
HKU\S-1-5-21-36004211-339696290-1626793974-1001\...\Run: [GoogleChromeAutoLaunch_97BA51ED85875E588E5A8018F9CB6CD2] => C:\Users\Patrycja\AppData\Local\Binkiland\Application\binkiland.exe [1014272 2015-02-01] ()
HKU\S-1-5-21-36004211-339696290-1626793974-1001\...\RunOnce: [Binkiland] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Patrycja\AppData\Roaming\Binkiland\UpdateProc\bkup.dat"
Startup: C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-36004211-339696290-1626793974-1001 -> {7296EC0E-ACB6-4BA4-99B7-37AB247BA990} URL = http://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_ir_15_06&cd=2XzuyEtN2Y1L1QzuyDzztB0CzztDtCtAzytByCtAzztC0BtDtN0D0Tzu0StCtCtAtDtN1L2XzutAtFyBtFyBtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StByCtDyCtCtAtA0CtG0CtA0EtBtGzytCyD0CtGtByC0AtBtGtA0B0AtC0ByEtA0AtDzy0D0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtAtCyDtAtB0F0FtG0ByBzz0BtGyEtB0EtCtG0Bzy0CtAtG0D0C0ByB0DzyyB0E0C0FzztD2Q&cr=1658268917&ir=
R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION
R2 Service Mgr StrongSignal; C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugincontainer.exe [581368 2015-02-25] ()
S3 OATool; \??\C:\Users\ADMINI~1\AppData\Local\Temp\OAToolx64.sys [X]
C:\ProgramData\CouponFactory
C:\Program Files (x86)\TurboStrength
C:\Program Files (x86)\MyPC Backup
C:\Users\Patrycja\Desktop\MyPC Backup.lnk
C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
C:\Program Files (x86)\PC Speed Maximizer
C:\Windows\System32\Tasks\PC Speed Maximizer Schedule
C:\Users\Patrycja\Documents\PC Speed Maximizer
C:\Users\Patrycja\AppData\Roaming\PC Speed Maximizer
C:\ProgramData\63a5226800004fb9
C:\Users\Patrycja\Documents\Optimizer Pro
2015-02-04 21:41 - 2015-02-26 00:07 - 00000000 ____D () C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce
2015-02-04 21:41 - 2015-02-04 21:41 - 00000000 ____D () C:\Program Files (x86)\Strong Signal
2015-02-04 21:39 - 2015-02-10 18:44 - 00002258 _____ () C:\Users\Patrycja\Desktop\Binkiland.lnk
2015-02-04 21:39 - 2015-02-04 21:39 - 00000000 ____D () C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Binkiland
2015-02-04 21:38 - 2015-02-22 20:41 - 00000000 ____D () C:\Users\Patrycja\AppData\Local\Binkiland
2015-02-04 21:36 - 2015-02-26 10:41 - 00000314 _____ () C:\Windows\Tasks\Binkiland.job
2015-02-04 21:36 - 2015-02-10 18:41 - 00002652 _____ () C:\Windows\System32\Tasks\Binkiland
2015-02-04 21:36 - 2015-02-04 21:36 - 00000000 ____D () C:\Users\Patrycja\AppData\Roaming\Binkiland
2015-02-04 21:36 - 2015-02-04 21:36 - 00000000 ____D () C:\ProgramData\{D6BE3E7D-863C-EFFB-37BA-9F79E7384CF7}
2015-02-04 21:36 - 2015-02-04 21:36 - 00000000 ____D () C:\Program Files (x86)\WSE_Binkiland
2015-02-04 21:34 - 2015-02-04 21:34 - 00728784 _____ (Web ) C:\Users\Patrycja\Downloads\PDFCreator(12691)-dp.exe
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 30 gości